diff --git a/advisories/unreviewed/2024/03/GHSA-7chf-chrh-74q7/GHSA-7chf-chrh-74q7.json b/advisories/unreviewed/2024/03/GHSA-7chf-chrh-74q7/GHSA-7chf-chrh-74q7.json new file mode 100644 index 00000000000..ee97b15fba2 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-7chf-chrh-74q7/GHSA-7chf-chrh-74q7.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7chf-chrh-74q7", + "modified": "2024-03-26T15:30:51Z", + "published": "2024-03-26T15:30:51Z", + "aliases": [ + "CVE-2024-22356" + ], + "details": "IBM App Connect Enterprise 11.0.0.1 through 11.0.0.23, 12.0.1.0 through 12.0.9.0 and IBM Integration Bus for z/OS 10.1 through 10.1.0.2store potentially sensitive information in log or trace files that could be read by a privileged user. IBM X-Force ID: 280893.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22356" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/280893" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7145144" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-117" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T15:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-7mhp-79q4-v3j9/GHSA-7mhp-79q4-v3j9.json b/advisories/unreviewed/2024/03/GHSA-7mhp-79q4-v3j9/GHSA-7mhp-79q4-v3j9.json new file mode 100644 index 00000000000..124ad627d94 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-7mhp-79q4-v3j9/GHSA-7mhp-79q4-v3j9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7mhp-79q4-v3j9", + "modified": "2024-03-26T15:30:49Z", + "published": "2024-03-26T15:30:49Z", + "aliases": [ + "CVE-2024-2906" + ], + "details": "Missing Authorization vulnerability in SoftLab Radio Player.This issue affects Radio Player: from n/a through 2.0.73.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2906" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/radio-player/wordpress-radio-player-plugin-2-0-73-unauthenticated-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T13:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-7pfr-rxmf-5m47/GHSA-7pfr-rxmf-5m47.json b/advisories/unreviewed/2024/03/GHSA-7pfr-rxmf-5m47/GHSA-7pfr-rxmf-5m47.json new file mode 100644 index 00000000000..6eff24c40fe --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-7pfr-rxmf-5m47/GHSA-7pfr-rxmf-5m47.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7pfr-rxmf-5m47", + "modified": "2024-03-26T15:30:48Z", + "published": "2024-03-26T15:30:48Z", + "aliases": [ + "CVE-2023-52214" + ], + "details": "Missing Authorization vulnerability in voidCoders Void Contact Form 7 Widget For Elementor Page Builder.This issue affects Void Contact Form 7 Widget For Elementor Page Builder: from n/a through 2.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52214" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/cf7-widget-elementor/wordpress-void-contact-form-7-widget-for-elementor-page-builder-plugin-2-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T13:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-7x4x-j7vx-3p29/GHSA-7x4x-j7vx-3p29.json b/advisories/unreviewed/2024/03/GHSA-7x4x-j7vx-3p29/GHSA-7x4x-j7vx-3p29.json new file mode 100644 index 00000000000..795badcb05c --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-7x4x-j7vx-3p29/GHSA-7x4x-j7vx-3p29.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7x4x-j7vx-3p29", + "modified": "2024-03-26T15:30:51Z", + "published": "2024-03-26T15:30:51Z", + "aliases": [ + "CVE-2024-23722" + ], + "details": "In Fluent Bit 2.1.8 through 2.2.1, a NULL pointer dereference can be caused via an invalid HTTP payload with the content type of x-www-form-urlencoded. It crashes and does not restart. This could result in logs not being delivered properly.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23722" + }, + { + "type": "WEB", + "url": "https://github.com/fluent/fluent-bit/compare/v2.2.1...v2.2.2" + }, + { + "type": "WEB", + "url": "https://medium.com/%40adurands82/fluent-bit-dos-vulnerability-cve-2024-23722-4e3e74af9d00" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T15:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-7x8p-3pr3-73hp/GHSA-7x8p-3pr3-73hp.json b/advisories/unreviewed/2024/03/GHSA-7x8p-3pr3-73hp/GHSA-7x8p-3pr3-73hp.json new file mode 100644 index 00000000000..6c4b716f852 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-7x8p-3pr3-73hp/GHSA-7x8p-3pr3-73hp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7x8p-3pr3-73hp", + "modified": "2024-03-26T15:30:50Z", + "published": "2024-03-26T15:30:50Z", + "aliases": [ + "CVE-2024-30234" + ], + "details": "Missing Authorization vulnerability in Wholesale Team WholesaleX.This issue affects WholesaleX: from n/a through 1.3.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30234" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wholesalex/wordpress-wholesalex-plugin-1-3-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T13:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-8p64-f589-46g5/GHSA-8p64-f589-46g5.json b/advisories/unreviewed/2024/03/GHSA-8p64-f589-46g5/GHSA-8p64-f589-46g5.json new file mode 100644 index 00000000000..a070f65b3da --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-8p64-f589-46g5/GHSA-8p64-f589-46g5.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8p64-f589-46g5", + "modified": "2024-03-26T15:30:50Z", + "published": "2024-03-26T15:30:50Z", + "aliases": [ + "CVE-2021-36759" + ], + "details": "Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-35342. Reason: This candidate is a reservation duplicate of CVE-2021-35342. Notes: All CVE users should reference CVE-2021-35342 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-36759" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T15:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-98fg-qw7m-42fj/GHSA-98fg-qw7m-42fj.json b/advisories/unreviewed/2024/03/GHSA-98fg-qw7m-42fj/GHSA-98fg-qw7m-42fj.json new file mode 100644 index 00000000000..731039ac21c --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-98fg-qw7m-42fj/GHSA-98fg-qw7m-42fj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-98fg-qw7m-42fj", + "modified": "2024-03-26T15:30:50Z", + "published": "2024-03-26T15:30:50Z", + "aliases": [ + "CVE-2024-30235" + ], + "details": "Missing Authorization vulnerability in Themeisle Multiple Page Generator Plugin – MPG.This issue affects Multiple Page Generator Plugin – MPG: from n/a through 3.4.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30235" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/multiple-pages-generator-by-porthas/wordpress-multiple-page-generator-plugin-mpg-plugin-3-4-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T13:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-9q9g-6mgq-4cf7/GHSA-9q9g-6mgq-4cf7.json b/advisories/unreviewed/2024/03/GHSA-9q9g-6mgq-4cf7/GHSA-9q9g-6mgq-4cf7.json new file mode 100644 index 00000000000..31b4be4531f --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-9q9g-6mgq-4cf7/GHSA-9q9g-6mgq-4cf7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9q9g-6mgq-4cf7", + "modified": "2024-03-26T15:30:50Z", + "published": "2024-03-26T15:30:50Z", + "aliases": [ + "CVE-2023-41973" + ], + "details": "ZSATray passes the previousInstallerName as a config parameter to TrayManager, and TrayManager constructs the path and appends previousInstallerName to get the full path of the exe. Fixed Version: Win ZApp 4.3.0.121 and later.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41973" + }, + { + "type": "WEB", + "url": "https://help.zscaler.com/client-connector/client-connector-app-release-summary-2023?applicable_category=Windows&applicable_version=4.3.0.121&deployment_date=2023-09-01&id=1463196" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T15:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-gwqv-mxv2-3769/GHSA-gwqv-mxv2-3769.json b/advisories/unreviewed/2024/03/GHSA-gwqv-mxv2-3769/GHSA-gwqv-mxv2-3769.json new file mode 100644 index 00000000000..693db71899f --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-gwqv-mxv2-3769/GHSA-gwqv-mxv2-3769.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gwqv-mxv2-3769", + "modified": "2024-03-26T15:30:50Z", + "published": "2024-03-26T15:30:50Z", + "aliases": [ + "CVE-2024-29684" + ], + "details": "DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /src/dede/makehtml_homepage.php allowing a remote attacker to execute arbitrary code.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29684" + }, + { + "type": "WEB", + "url": "https://github.com/iimiss/cms/blob/main/1.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-hm28-v8c8-qx5x/GHSA-hm28-v8c8-qx5x.json b/advisories/unreviewed/2024/03/GHSA-hm28-v8c8-qx5x/GHSA-hm28-v8c8-qx5x.json new file mode 100644 index 00000000000..474bf1a87c6 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-hm28-v8c8-qx5x/GHSA-hm28-v8c8-qx5x.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hm28-v8c8-qx5x", + "modified": "2024-03-26T15:30:50Z", + "published": "2024-03-26T15:30:50Z", + "aliases": [ + "CVE-2023-47150" + ], + "details": "IBM Common Cryptographic Architecture (CCA) 7.0.0 through 7.5.36 could allow a remote user to cause a denial of service due to incorrect data handling for certain types of AES operations. IBM X-Force ID: 270602.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47150" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/270602" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7145168" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-j4mm-f543-fj92/GHSA-j4mm-f543-fj92.json b/advisories/unreviewed/2024/03/GHSA-j4mm-f543-fj92/GHSA-j4mm-f543-fj92.json new file mode 100644 index 00000000000..9a952d1f850 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-j4mm-f543-fj92/GHSA-j4mm-f543-fj92.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j4mm-f543-fj92", + "modified": "2024-03-26T15:30:49Z", + "published": "2024-03-26T15:30:49Z", + "aliases": [ + "CVE-2024-1933" + ], + "details": "Insecure UNIX Symbolic Link (Symlink) Following in TeamViewer Remote Client prior Version 15.52 for macOS allows an attacker with unprivileged access, to potentially elevate privileges or conduct a denial-of-service-attack by overwriting the symlink.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1933" + }, + { + "type": "WEB", + "url": "https://www.teamviewer.com/de/resources/trust-center/security-bulletins/tv-2024-1002" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-61" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T13:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-j8r5-8r3h-439x/GHSA-j8r5-8r3h-439x.json b/advisories/unreviewed/2024/03/GHSA-j8r5-8r3h-439x/GHSA-j8r5-8r3h-439x.json new file mode 100644 index 00000000000..0f263f9e307 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-j8r5-8r3h-439x/GHSA-j8r5-8r3h-439x.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j8r5-8r3h-439x", + "modified": "2024-03-26T15:30:50Z", + "published": "2024-03-26T15:30:50Z", + "aliases": [ + "CVE-2023-50895" + ], + "details": "In Janitza GridVis through 9.0.66, exposed dangerous methods in the de.janitza.pasw.project.server.ServerDatabaseProject project load functionality allow remote authenticated administrative users to execute arbitrary Groovy code.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50895" + }, + { + "type": "WEB", + "url": "https://code-white.com" + }, + { + "type": "WEB", + "url": "https://code-white.com/public-vulnerability-list" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T15:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-jpgh-f7hm-pwmf/GHSA-jpgh-f7hm-pwmf.json b/advisories/unreviewed/2024/03/GHSA-jpgh-f7hm-pwmf/GHSA-jpgh-f7hm-pwmf.json new file mode 100644 index 00000000000..f8534ad7333 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-jpgh-f7hm-pwmf/GHSA-jpgh-f7hm-pwmf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jpgh-f7hm-pwmf", + "modified": "2024-03-26T15:30:50Z", + "published": "2024-03-26T15:30:50Z", + "aliases": [ + "CVE-2023-41972" + ], + "details": "In some rare cases, there is a password type validation missing in Revert Password check and for some features it could be disabled. Fixed Version: Win ZApp 4.3.0.121 and later.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41972" + }, + { + "type": "WEB", + "url": "https://help.zscaler.com/client-connector/client-connector-app-release-summary-2023?applicable_category=Windows&applicable_version=4.3.0.121&deployment_date=2023-09-01&id=1463196" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T15:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-jwr6-j6qm-w9jv/GHSA-jwr6-j6qm-w9jv.json b/advisories/unreviewed/2024/03/GHSA-jwr6-j6qm-w9jv/GHSA-jwr6-j6qm-w9jv.json new file mode 100644 index 00000000000..e40482b16dd --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-jwr6-j6qm-w9jv/GHSA-jwr6-j6qm-w9jv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jwr6-j6qm-w9jv", + "modified": "2024-03-26T15:30:51Z", + "published": "2024-03-26T15:30:51Z", + "aliases": [ + "CVE-2024-29401" + ], + "details": "xzs-mysql 3.8 is vulnerable to Insufficient Session Expiration, which allows attackers to use the session of a deleted admin to do anything.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29401" + }, + { + "type": "WEB", + "url": "https://github.com/menghaining/PoC/blob/main/xzs-mysql/xzs-mysql%20--%20PoC.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T15:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-m22v-j3fw-2m27/GHSA-m22v-j3fw-2m27.json b/advisories/unreviewed/2024/03/GHSA-m22v-j3fw-2m27/GHSA-m22v-j3fw-2m27.json new file mode 100644 index 00000000000..2d6c7dd3b74 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-m22v-j3fw-2m27/GHSA-m22v-j3fw-2m27.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m22v-j3fw-2m27", + "modified": "2024-03-26T15:30:50Z", + "published": "2024-03-26T15:30:50Z", + "aliases": [ + "CVE-2024-2891" + ], + "details": "A vulnerability, which was classified as critical, was found in Tenda AC7 15.03.06.44. Affected is the function formQuickIndex of the file /goform/QuickIndex. The manipulation of the argument PPPOEPassword leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-257934 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2891" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/AC7/v1/formQuickIndex.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.257934" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.257934" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.300354" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-mf3p-gmch-hc8x/GHSA-mf3p-gmch-hc8x.json b/advisories/unreviewed/2024/03/GHSA-mf3p-gmch-hc8x/GHSA-mf3p-gmch-hc8x.json index 38cee6afee7..01566e8cc81 100644 --- a/advisories/unreviewed/2024/03/GHSA-mf3p-gmch-hc8x/GHSA-mf3p-gmch-hc8x.json +++ b/advisories/unreviewed/2024/03/GHSA-mf3p-gmch-hc8x/GHSA-mf3p-gmch-hc8x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mf3p-gmch-hc8x", - "modified": "2024-03-26T12:31:27Z", + "modified": "2024-03-26T15:30:48Z", "published": "2024-03-26T12:31:27Z", "aliases": [ "CVE-2024-28034" diff --git a/advisories/unreviewed/2024/03/GHSA-p2c2-qg2f-h65h/GHSA-p2c2-qg2f-h65h.json b/advisories/unreviewed/2024/03/GHSA-p2c2-qg2f-h65h/GHSA-p2c2-qg2f-h65h.json new file mode 100644 index 00000000000..aad4eadd0e4 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-p2c2-qg2f-h65h/GHSA-p2c2-qg2f-h65h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p2c2-qg2f-h65h", + "modified": "2024-03-26T15:30:49Z", + "published": "2024-03-26T15:30:49Z", + "aliases": [ + "CVE-2024-22156" + ], + "details": "Missing Authorization vulnerability in SNP Digital SalesKing.This issue affects SalesKing: from n/a through 1.6.15.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22156" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/salesking/wordpress-salesking-plugin-1-6-15-unauthenticated-plugin-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T13:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-q84m-rmw3-4382/GHSA-q84m-rmw3-4382.json b/advisories/unreviewed/2024/03/GHSA-q84m-rmw3-4382/GHSA-q84m-rmw3-4382.json new file mode 100644 index 00000000000..94c5d8cc9a0 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-q84m-rmw3-4382/GHSA-q84m-rmw3-4382.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q84m-rmw3-4382", + "modified": "2024-03-26T15:30:50Z", + "published": "2024-03-26T15:30:50Z", + "aliases": [ + "CVE-2024-1455" + ], + "details": "The XMLOutputParser in LangChain uses the etree module from the XML parser in the standard python library which has some XML vulnerabilities; see: https://docs.python.org/3/library/xml.html\n\nThis primarily affects users that combine an LLM (or agent) with the `XMLOutputParser` and expose the component via an endpoint on a web-service. \n\nThis would allow a malicious party to attempt to manipulate the LLM to produce a malicious payload for the parser that would compromise the availability of the service.\n\nA successful attack is predicated on:\n\n1. Usage of XMLOutputParser\n2. Passing of malicious input into the XMLOutputParser either directly or by trying to manipulate an LLM to do so on the users behalf\n3. Exposing the component via a web-service", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1455" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/4353571f-c70d-4bfd-ac08-3a89cecb45b6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-776" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-rjx9-ww7j-9fvr/GHSA-rjx9-ww7j-9fvr.json b/advisories/unreviewed/2024/03/GHSA-rjx9-ww7j-9fvr/GHSA-rjx9-ww7j-9fvr.json new file mode 100644 index 00000000000..cdd436fdb72 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-rjx9-ww7j-9fvr/GHSA-rjx9-ww7j-9fvr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rjx9-ww7j-9fvr", + "modified": "2024-03-26T15:30:50Z", + "published": "2024-03-26T15:30:50Z", + "aliases": [ + "CVE-2024-30233" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wholesale Team WholesaleX.This issue affects WholesaleX: from n/a through 1.3.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30233" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wholesalex/wordpress-wholesalex-plugin-1-3-1-sensitive-data-exposure-on-user-export-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T13:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-vrpp-jrqv-4gj2/GHSA-vrpp-jrqv-4gj2.json b/advisories/unreviewed/2024/03/GHSA-vrpp-jrqv-4gj2/GHSA-vrpp-jrqv-4gj2.json new file mode 100644 index 00000000000..69de12f0550 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-vrpp-jrqv-4gj2/GHSA-vrpp-jrqv-4gj2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vrpp-jrqv-4gj2", + "modified": "2024-03-26T15:30:50Z", + "published": "2024-03-26T15:30:50Z", + "aliases": [ + "CVE-2023-41969" + ], + "details": "\nAn arbitrary file deletion in ZSATrayManager where it protects the temporary encrypted ZApp issue reporting file from the unprivileged end user access and modification. Fixed version: Win ZApp 4.3.0 and later.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41969" + }, + { + "type": "WEB", + "url": "https://help.zscaler.com/client-connector/client-connector-app-release-summary-2023" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T15:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-vw2x-qjjw-279v/GHSA-vw2x-qjjw-279v.json b/advisories/unreviewed/2024/03/GHSA-vw2x-qjjw-279v/GHSA-vw2x-qjjw-279v.json new file mode 100644 index 00000000000..3768454a83e --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-vw2x-qjjw-279v/GHSA-vw2x-qjjw-279v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vw2x-qjjw-279v", + "modified": "2024-03-26T15:30:51Z", + "published": "2024-03-26T15:30:51Z", + "aliases": [ + "CVE-2024-23482" + ], + "details": "The ZScaler service is susceptible to a local privilege escalation vulnerability found in the ZScalerService process. Fixed Version: Mac ZApp 4.2.0.241 and later.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23482" + }, + { + "type": "WEB", + "url": "https://help.zscaler.com/client-connector/client-connector-app-release-summary-2024" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T15:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-w33g-cw2w-4vrq/GHSA-w33g-cw2w-4vrq.json b/advisories/unreviewed/2024/03/GHSA-w33g-cw2w-4vrq/GHSA-w33g-cw2w-4vrq.json new file mode 100644 index 00000000000..cbbe238b2fe --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-w33g-cw2w-4vrq/GHSA-w33g-cw2w-4vrq.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w33g-cw2w-4vrq", + "modified": "2024-03-26T15:30:50Z", + "published": "2024-03-26T15:30:50Z", + "aliases": [ + "CVE-2023-50894" + ], + "details": "In Janitza GridVis through 9.0.66, use of hard-coded credentials in the de.janitza.pasw.feature.impl.activators.PasswordEncryption password encryption function allows remote authenticated administrative users to discover cleartext database credentials contained in error report information.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50894" + }, + { + "type": "WEB", + "url": "https://code-white.com" + }, + { + "type": "WEB", + "url": "https://code-white.com/public-vulnerability-list" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T15:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-wwrv-f6v4-m66r/GHSA-wwrv-f6v4-m66r.json b/advisories/unreviewed/2024/03/GHSA-wwrv-f6v4-m66r/GHSA-wwrv-f6v4-m66r.json new file mode 100644 index 00000000000..927ce5ef936 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-wwrv-f6v4-m66r/GHSA-wwrv-f6v4-m66r.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wwrv-f6v4-m66r", + "modified": "2024-03-26T15:30:50Z", + "published": "2024-03-26T15:30:50Z", + "aliases": [ + "CVE-2023-33855" + ], + "details": "Under certain conditions, RSA operations performed by IBM Common Cryptographic Architecture (CCA) 7.0.0 through 7.5.36 may exhibit non-constant-time behavior. This could allow a remote attacker to obtain sensitive information using a timing-based attack. IBM X-Force ID: 257676.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33855" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/257676" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7145168" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-385" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T14:15:07Z" + } +} \ No newline at end of file