diff --git a/advisories/unreviewed/2024/03/GHSA-2c59-9ffj-f3h3/GHSA-2c59-9ffj-f3h3.json b/advisories/unreviewed/2024/03/GHSA-2c59-9ffj-f3h3/GHSA-2c59-9ffj-f3h3.json new file mode 100644 index 00000000000..b9a0a651249 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-2c59-9ffj-f3h3/GHSA-2c59-9ffj-f3h3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2c59-9ffj-f3h3", + "modified": "2024-03-26T12:31:28Z", + "published": "2024-03-26T12:31:28Z", + "aliases": [ + "CVE-2024-24711" + ], + "details": "Missing Authorization vulnerability in weDevs WooCommerce Conversion Tracking.This issue affects WooCommerce Conversion Tracking: from n/a through 2.0.11.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24711" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/woocommerce-conversion-tracking/wordpress-woocommerce-conversion-tracking-plugin-2-0-11-broken-access-control-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T12:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-67vv-3f58-75qw/GHSA-67vv-3f58-75qw.json b/advisories/unreviewed/2024/03/GHSA-67vv-3f58-75qw/GHSA-67vv-3f58-75qw.json new file mode 100644 index 00000000000..c5f7a099deb --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-67vv-3f58-75qw/GHSA-67vv-3f58-75qw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-67vv-3f58-75qw", + "modified": "2024-03-26T12:31:28Z", + "published": "2024-03-26T12:31:28Z", + "aliases": [ + "CVE-2024-24799" + ], + "details": "Missing Authorization vulnerability in WooCommerce WooCommerce Box Office.This issue affects WooCommerce Box Office: from n/a through 1.2.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24799" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/woocommerce-box-office/wordpress-woocommerce-box-office-plugin-1-2-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T12:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-8rr6-29c9-2mpq/GHSA-8rr6-29c9-2mpq.json b/advisories/unreviewed/2024/03/GHSA-8rr6-29c9-2mpq/GHSA-8rr6-29c9-2mpq.json new file mode 100644 index 00000000000..58236b27f01 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-8rr6-29c9-2mpq/GHSA-8rr6-29c9-2mpq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8rr6-29c9-2mpq", + "modified": "2024-03-26T12:31:27Z", + "published": "2024-03-26T12:31:27Z", + "aliases": [ + "CVE-2024-2904" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Extend Themes Calliope.This issue affects Calliope: from n/a through 1.0.33.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2904" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/calliope/wordpress-calliope-theme-1-0-33-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T10:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-8v7g-v34f-jv8p/GHSA-8v7g-v34f-jv8p.json b/advisories/unreviewed/2024/03/GHSA-8v7g-v34f-jv8p/GHSA-8v7g-v34f-jv8p.json new file mode 100644 index 00000000000..6bba21ab825 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-8v7g-v34f-jv8p/GHSA-8v7g-v34f-jv8p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8v7g-v34f-jv8p", + "modified": "2024-03-26T12:31:29Z", + "published": "2024-03-26T12:31:29Z", + "aliases": [ + "CVE-2024-30231" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in WebToffee Product Import Export for WooCommerce.This issue affects Product Import Export for WooCommerce: from n/a through 2.4.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30231" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/product-import-export-for-woo/wordpress-product-import-export-for-woocommerce-plugin-2-4-1-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T12:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-gmc8-q8c9-x758/GHSA-gmc8-q8c9-x758.json b/advisories/unreviewed/2024/03/GHSA-gmc8-q8c9-x758/GHSA-gmc8-q8c9-x758.json new file mode 100644 index 00000000000..daab523700c --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-gmc8-q8c9-x758/GHSA-gmc8-q8c9-x758.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gmc8-q8c9-x758", + "modified": "2024-03-26T12:31:27Z", + "published": "2024-03-26T12:31:27Z", + "aliases": [ + "CVE-2024-28131" + ], + "details": "EasyRange Ver 1.41 contains an issue with the executable file search path when displaying an extracted file on Explorer, which may lead to loading an executable file resides in the same folder where the extracted file is placed. If this vulnerability is exploited, arbitrary code may be executed with the privilege of the running program. Note that the developer was unreachable, therefore, users should consider stop using EasyRange Ver 1.41.\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28131" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN13113728/index.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T10:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-gmxf-67jf-rrf4/GHSA-gmxf-67jf-rrf4.json b/advisories/unreviewed/2024/03/GHSA-gmxf-67jf-rrf4/GHSA-gmxf-67jf-rrf4.json new file mode 100644 index 00000000000..6db9927e2c0 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-gmxf-67jf-rrf4/GHSA-gmxf-67jf-rrf4.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gmxf-67jf-rrf4", + "modified": "2024-03-26T12:31:28Z", + "published": "2024-03-26T12:31:28Z", + "aliases": [ + "CVE-2024-28093" + ], + "details": "The TELNET service of AdTran NetVanta 3120 18.01.01.00.E devices is enabled by default, and has default credentials for a root-level account.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28093" + }, + { + "type": "WEB", + "url": "https://github.com/actuator/cve/blob/main/AdTran/CVE-2024-28093" + }, + { + "type": "WEB", + "url": "https://github.com/actuator/cve/blob/main/AdTran/CWE-287" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T12:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-hjpq-vr77-qp94/GHSA-hjpq-vr77-qp94.json b/advisories/unreviewed/2024/03/GHSA-hjpq-vr77-qp94/GHSA-hjpq-vr77-qp94.json new file mode 100644 index 00000000000..5960f1d2a0e --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-hjpq-vr77-qp94/GHSA-hjpq-vr77-qp94.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hjpq-vr77-qp94", + "modified": "2024-03-26T12:31:27Z", + "published": "2024-03-26T12:31:27Z", + "aliases": [ + "CVE-2024-28048" + ], + "details": "OS command injection vulnerability exists in ffBull ver.4.11, which may allow a remote unauthenticated attacker to execute an arbitrary OS command with the privilege of the running web server. Note that the developer was unreachable, therefore, users should consider stop using ffBull ver.4.11.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28048" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN17176449" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T10:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-m6hg-jwrh-92jj/GHSA-m6hg-jwrh-92jj.json b/advisories/unreviewed/2024/03/GHSA-m6hg-jwrh-92jj/GHSA-m6hg-jwrh-92jj.json new file mode 100644 index 00000000000..73b9d9353b0 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-m6hg-jwrh-92jj/GHSA-m6hg-jwrh-92jj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m6hg-jwrh-92jj", + "modified": "2024-03-26T12:31:29Z", + "published": "2024-03-26T12:31:29Z", + "aliases": [ + "CVE-2024-30232" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Exclusive Addons Exclusive Addons Elementor allows Stored XSS.This issue affects Exclusive Addons Elementor: from n/a through 2.6.9.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30232" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/exclusive-addons-for-elementor/wordpress-exclusive-addons-for-elementor-plugin-2-6-9-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T12:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-m94j-rfcg-99c7/GHSA-m94j-rfcg-99c7.json b/advisories/unreviewed/2024/03/GHSA-m94j-rfcg-99c7/GHSA-m94j-rfcg-99c7.json new file mode 100644 index 00000000000..4c63ab26d88 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-m94j-rfcg-99c7/GHSA-m94j-rfcg-99c7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m94j-rfcg-99c7", + "modified": "2024-03-26T12:31:28Z", + "published": "2024-03-26T12:31:28Z", + "aliases": [ + "CVE-2024-23520" + ], + "details": "Missing Authorization vulnerability in AccessAlly PopupAlly.This issue affects PopupAlly: from n/a through 2.1.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23520" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/popupally/wordpress-popupally-plugin-2-1-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T12:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-mf3p-gmch-hc8x/GHSA-mf3p-gmch-hc8x.json b/advisories/unreviewed/2024/03/GHSA-mf3p-gmch-hc8x/GHSA-mf3p-gmch-hc8x.json new file mode 100644 index 00000000000..38cee6afee7 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-mf3p-gmch-hc8x/GHSA-mf3p-gmch-hc8x.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mf3p-gmch-hc8x", + "modified": "2024-03-26T12:31:27Z", + "published": "2024-03-26T12:31:27Z", + "aliases": [ + "CVE-2024-28034" + ], + "details": "Cross-site scripting vulnerability exists in Mini Thread Version 3.33βi. An arbitrary script may be executed on the web browser of the user accessing the website that uses the product. Note that the developer was unreachable, therefore, users should consider stop using Mini Thread Version 3.33βi.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28034" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN40523785" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T10:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-mr24-cf69-5chq/GHSA-mr24-cf69-5chq.json b/advisories/unreviewed/2024/03/GHSA-mr24-cf69-5chq/GHSA-mr24-cf69-5chq.json new file mode 100644 index 00000000000..2a388f2767f --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-mr24-cf69-5chq/GHSA-mr24-cf69-5chq.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mr24-cf69-5chq", + "modified": "2024-03-26T12:31:28Z", + "published": "2024-03-26T12:31:28Z", + "aliases": [ + "CVE-2024-29644" + ], + "details": "Cross Site Scripting vulnerability in dcat-admin v.2.1.3 and before allows a remote attacker to execute arbitrary code via a crafted script to the user login box.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29644" + }, + { + "type": "WEB", + "url": "https://github.com/jqhph/dcat-admin" + }, + { + "type": "WEB", + "url": "https://www.yuque.com/yangtu-swjrh/oc6nqi/epcbz5y1grl4il1m" + }, + { + "type": "WEB", + "url": "http://dcat-admin.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T12:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-p29f-v46f-qrx3/GHSA-p29f-v46f-qrx3.json b/advisories/unreviewed/2024/03/GHSA-p29f-v46f-qrx3/GHSA-p29f-v46f-qrx3.json new file mode 100644 index 00000000000..e036423db44 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-p29f-v46f-qrx3/GHSA-p29f-v46f-qrx3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p29f-v46f-qrx3", + "modified": "2024-03-26T12:31:28Z", + "published": "2024-03-26T12:31:28Z", + "aliases": [ + "CVE-2024-24718" + ], + "details": "Missing Authorization vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.6.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24718" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/propertyhive/wordpress-propertyhive-plugin-2-0-6-missing-authorization-to-non-arbitrary-plugin-installation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T12:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-pqvp-7fm6-8x84/GHSA-pqvp-7fm6-8x84.json b/advisories/unreviewed/2024/03/GHSA-pqvp-7fm6-8x84/GHSA-pqvp-7fm6-8x84.json new file mode 100644 index 00000000000..257eb65e36e --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-pqvp-7fm6-8x84/GHSA-pqvp-7fm6-8x84.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pqvp-7fm6-8x84", + "modified": "2024-03-26T12:31:27Z", + "published": "2024-03-26T12:31:27Z", + "aliases": [ + "CVE-2024-28126" + ], + "details": "Cross-site scripting vulnerability exists in 0ch BBS Script ver.4.00. An arbitrary script may be executed on the web browser of the user accessing the website that uses the product. Note that the developer was unreachable, therefore, users should consider stop using 0ch BBS Script ver.4.00.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28126" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN46874970" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T10:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-qp3h-5pr9-v3f3/GHSA-qp3h-5pr9-v3f3.json b/advisories/unreviewed/2024/03/GHSA-qp3h-5pr9-v3f3/GHSA-qp3h-5pr9-v3f3.json new file mode 100644 index 00000000000..c1edd6580d1 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-qp3h-5pr9-v3f3/GHSA-qp3h-5pr9-v3f3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qp3h-5pr9-v3f3", + "modified": "2024-03-26T12:31:28Z", + "published": "2024-03-26T12:31:28Z", + "aliases": [ + "CVE-2024-24719" + ], + "details": "Missing Authorization vulnerability in Uriahs Victor Location Picker at Checkout for WooCommerce.This issue affects Location Picker at Checkout for WooCommerce: from n/a through 1.8.9.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24719" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/map-location-picker-at-checkout-for-woocommerce/wordpress-kikote-plugin-1-8-9-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T12:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-r2h5-w9vh-xvx2/GHSA-r2h5-w9vh-xvx2.json b/advisories/unreviewed/2024/03/GHSA-r2h5-w9vh-xvx2/GHSA-r2h5-w9vh-xvx2.json new file mode 100644 index 00000000000..643376cf3e2 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-r2h5-w9vh-xvx2/GHSA-r2h5-w9vh-xvx2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r2h5-w9vh-xvx2", + "modified": "2024-03-26T12:31:27Z", + "published": "2024-03-26T12:31:27Z", + "aliases": [ + "CVE-2024-26018" + ], + "details": "Cross-site scripting vulnerability exists in TvRock 0.9t8a. An arbitrary script may be executed on the web browser of the user accessing the website that uses the product. Note that the developer was unreachable, therefore, users should consider stop using TvRock 0.9t8a.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26018" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN69107517" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-x23x-5mrc-48fh/GHSA-x23x-5mrc-48fh.json b/advisories/unreviewed/2024/03/GHSA-x23x-5mrc-48fh/GHSA-x23x-5mrc-48fh.json new file mode 100644 index 00000000000..1042aef5c43 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-x23x-5mrc-48fh/GHSA-x23x-5mrc-48fh.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x23x-5mrc-48fh", + "modified": "2024-03-26T12:31:27Z", + "published": "2024-03-26T12:31:27Z", + "aliases": [ + "CVE-2024-28033" + ], + "details": "OS command injection vulnerability exists in WebProxy 1.7.8 and 1.7.9, which may allow a remote unauthenticated attacker to execute an arbitrary OS command with the privilege of the running web server. Note that the developer was unreachable, therefore, users should consider stop using WebProxy 1.7.8 and 1.7.9.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28033" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN22376992" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T10:15:09Z" + } +} \ No newline at end of file