diff --git a/advisories/unreviewed/2023/10/GHSA-9rvp-jg33-mp8v/GHSA-9rvp-jg33-mp8v.json b/advisories/unreviewed/2023/10/GHSA-9rvp-jg33-mp8v/GHSA-9rvp-jg33-mp8v.json index d9a44345a12..a71c9345aa1 100644 --- a/advisories/unreviewed/2023/10/GHSA-9rvp-jg33-mp8v/GHSA-9rvp-jg33-mp8v.json +++ b/advisories/unreviewed/2023/10/GHSA-9rvp-jg33-mp8v/GHSA-9rvp-jg33-mp8v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9rvp-jg33-mp8v", - "modified": "2023-10-28T00:30:30Z", + "modified": "2024-03-28T09:31:12Z", "published": "2023-10-25T18:32:23Z", "aliases": [ "CVE-2023-45754" @@ -30,7 +30,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-10-25T18:17:33Z" diff --git a/advisories/unreviewed/2024/02/GHSA-gfq7-h592-v3xj/GHSA-gfq7-h592-v3xj.json b/advisories/unreviewed/2024/02/GHSA-gfq7-h592-v3xj/GHSA-gfq7-h592-v3xj.json index 7af0e6e397a..b95d8d57109 100644 --- a/advisories/unreviewed/2024/02/GHSA-gfq7-h592-v3xj/GHSA-gfq7-h592-v3xj.json +++ b/advisories/unreviewed/2024/02/GHSA-gfq7-h592-v3xj/GHSA-gfq7-h592-v3xj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gfq7-h592-v3xj", - "modified": "2024-02-24T00:30:20Z", + "modified": "2024-03-28T09:31:12Z", "published": "2024-02-24T00:30:20Z", "aliases": [ "CVE-2024-24681" @@ -18,6 +18,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24681" }, + { + "type": "WEB", + "url": "https://github.com/gitaware/CVE/tree/main/CVE-2024-24681" + }, + { + "type": "WEB", + "url": "https://seclists.org/fulldisclosure/2024/Feb/22" + }, { "type": "WEB", "url": "https://www.reddit.com/r/VOIP/comments/ys9mel/what_are_some_of_the_good_white_label_voip" diff --git a/advisories/unreviewed/2024/03/GHSA-27mx-r8cm-2rx5/GHSA-27mx-r8cm-2rx5.json b/advisories/unreviewed/2024/03/GHSA-27mx-r8cm-2rx5/GHSA-27mx-r8cm-2rx5.json new file mode 100644 index 00000000000..781dc6a5690 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-27mx-r8cm-2rx5/GHSA-27mx-r8cm-2rx5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-27mx-r8cm-2rx5", + "modified": "2024-03-28T09:31:13Z", + "published": "2024-03-28T09:31:13Z", + "aliases": [ + "CVE-2024-29241" + ], + "details": "Missing authorization vulnerability in System webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to bypass security constraints via unspecified vectors.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29241" + }, + { + "type": "WEB", + "url": "https://www.synology.com/en-global/security/advisory/Synology_SA_24_04" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T07:16:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-2r57-8pgj-h27p/GHSA-2r57-8pgj-h27p.json b/advisories/unreviewed/2024/03/GHSA-2r57-8pgj-h27p/GHSA-2r57-8pgj-h27p.json new file mode 100644 index 00000000000..ff91f20c97f --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-2r57-8pgj-h27p/GHSA-2r57-8pgj-h27p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2r57-8pgj-h27p", + "modified": "2024-03-28T09:31:13Z", + "published": "2024-03-28T09:31:13Z", + "aliases": [ + "CVE-2024-2818" + ], + "details": "An issue has been discovered in GitLab CE/EE affecting all versions before 16.8.5, all versions starting from 16.9 before 16.9.3, all versions starting from 16.10 before 16.10.1. It was possible for an attacker to cause a denial of service using malicious crafted description parameter for labels.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2818" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/434803" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T08:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-3cvx-3rj3-cchm/GHSA-3cvx-3rj3-cchm.json b/advisories/unreviewed/2024/03/GHSA-3cvx-3rj3-cchm/GHSA-3cvx-3rj3-cchm.json new file mode 100644 index 00000000000..6f0cb1149bb --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-3cvx-3rj3-cchm/GHSA-3cvx-3rj3-cchm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3cvx-3rj3-cchm", + "modified": "2024-03-28T09:31:12Z", + "published": "2024-03-28T09:31:12Z", + "aliases": [ + "CVE-2023-52231" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Booster Booster Plus for WooCommerce.This issue affects Booster Plus for WooCommerce: from n/a before 7.1.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52231" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/booster-plus-for-woocommerce/wordpress-booster-plus-for-woocommerce-plugin-7-1-2-authenticated-arbitrary-order-information-disclosure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T07:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-556m-hx4g-v68m/GHSA-556m-hx4g-v68m.json b/advisories/unreviewed/2024/03/GHSA-556m-hx4g-v68m/GHSA-556m-hx4g-v68m.json new file mode 100644 index 00000000000..f97ef1a6def --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-556m-hx4g-v68m/GHSA-556m-hx4g-v68m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-556m-hx4g-v68m", + "modified": "2024-03-28T09:31:12Z", + "published": "2024-03-28T09:31:12Z", + "aliases": [ + "CVE-2024-22138" + ], + "details": "Insertion of Sensitive Information into Log File vulnerability in Seraphinite Solutions Seraphinite Accelerator.This issue affects Seraphinite Accelerator: from n/a through 2.20.47.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22138" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/seraphinite-accelerator/wordpress-seraphinite-accelerator-plugin-2-20-44-sensitive-data-exposure-via-log-file-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T07:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-59v7-w7j8-rgqm/GHSA-59v7-w7j8-rgqm.json b/advisories/unreviewed/2024/03/GHSA-59v7-w7j8-rgqm/GHSA-59v7-w7j8-rgqm.json new file mode 100644 index 00000000000..5fae9890bf8 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-59v7-w7j8-rgqm/GHSA-59v7-w7j8-rgqm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-59v7-w7j8-rgqm", + "modified": "2024-03-28T09:31:13Z", + "published": "2024-03-28T09:31:13Z", + "aliases": [ + "CVE-2024-29236" + ], + "details": "Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in AudioPattern.Delete webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to inject SQL commands via unspecified vectors.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29236" + }, + { + "type": "WEB", + "url": "https://www.synology.com/en-global/security/advisory/Synology_SA_24_04" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T07:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-69fm-ffh7-6h57/GHSA-69fm-ffh7-6h57.json b/advisories/unreviewed/2024/03/GHSA-69fm-ffh7-6h57/GHSA-69fm-ffh7-6h57.json new file mode 100644 index 00000000000..110f62bbdc5 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-69fm-ffh7-6h57/GHSA-69fm-ffh7-6h57.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-69fm-ffh7-6h57", + "modified": "2024-03-28T09:31:12Z", + "published": "2024-03-28T09:31:12Z", + "aliases": [ + "CVE-2023-52234" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Booster Booster Elite for WooCommerce.This issue affects Booster Elite for WooCommerce: from n/a before 7.1.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52234" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/booster-elite-for-woocommerce/wordpress-booster-elite-for-woocommerce-plugin-7-1-2-authenticated-arbitrary-order-information-disclosure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T07:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-6h4j-9hpq-prqw/GHSA-6h4j-9hpq-prqw.json b/advisories/unreviewed/2024/03/GHSA-6h4j-9hpq-prqw/GHSA-6h4j-9hpq-prqw.json new file mode 100644 index 00000000000..86ce1060b39 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-6h4j-9hpq-prqw/GHSA-6h4j-9hpq-prqw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6h4j-9hpq-prqw", + "modified": "2024-03-28T09:31:14Z", + "published": "2024-03-28T09:31:14Z", + "aliases": [ + "CVE-2024-30422" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPVibes Elementor Addon Elements allows Stored XSS.This issue affects Elementor Addon Elements: from n/a through 1.13.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30422" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/addon-elements-for-elementor-page-builder/wordpress-elementor-addon-elements-plugin-1-13-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-6r42-gm3x-9xx3/GHSA-6r42-gm3x-9xx3.json b/advisories/unreviewed/2024/03/GHSA-6r42-gm3x-9xx3/GHSA-6r42-gm3x-9xx3.json new file mode 100644 index 00000000000..0a78ec8ad2d --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-6r42-gm3x-9xx3/GHSA-6r42-gm3x-9xx3.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6r42-gm3x-9xx3", + "modified": "2024-03-28T09:31:13Z", + "published": "2024-03-28T09:31:13Z", + "aliases": [ + "CVE-2023-52628" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nftables: exthdr: fix 4-byte stack OOB write\n\nIf priv->len is a multiple of 4, then dst[len / 4] can write past\nthe destination array which leads to stack corruption.\n\nThis construct is necessary to clean the remainder of the register\nin case ->len is NOT a multiple of the register size, so make it\nconditional just like nft_payload.c does.\n\nThe bug was added in 4.1 cycle and then copied/inherited when\ntcp/sctp and ip option support was added.\n\nBug reported by Zero Day Initiative project (ZDI-CAN-21950,\nZDI-CAN-21951, ZDI-CAN-21961).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52628" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1ad7b189cc1411048434e8595ffcbe7873b71082" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a7d86a77c33ba1c357a7504341172cc1507f0698" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c8f292322ff16b9a2272a67de396c09a50e09dce" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d9ebfc0f21377690837ebbd119e679243e0099cc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fd94d9dadee58e09b49075240fe83423eb1dcd36" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T08:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-7jxv-w3wx-fc48/GHSA-7jxv-w3wx-fc48.json b/advisories/unreviewed/2024/03/GHSA-7jxv-w3wx-fc48/GHSA-7jxv-w3wx-fc48.json new file mode 100644 index 00000000000..bbdc648a53b --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-7jxv-w3wx-fc48/GHSA-7jxv-w3wx-fc48.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7jxv-w3wx-fc48", + "modified": "2024-03-28T09:31:12Z", + "published": "2024-03-28T09:31:12Z", + "aliases": [ + "CVE-2024-25924" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Trustindex.Io WP Testimonials.This issue affects WP Testimonials: from n/a through 1.4.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25924" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/testimonial-widgets/wordpress-wp-testimonials-plugin-1-4-3-admin-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T07:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-837v-6g69-x4q5/GHSA-837v-6g69-x4q5.json b/advisories/unreviewed/2024/03/GHSA-837v-6g69-x4q5/GHSA-837v-6g69-x4q5.json new file mode 100644 index 00000000000..bc806ef2274 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-837v-6g69-x4q5/GHSA-837v-6g69-x4q5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-837v-6g69-x4q5", + "modified": "2024-03-28T09:31:13Z", + "published": "2024-03-28T09:31:13Z", + "aliases": [ + "CVE-2024-29230" + ], + "details": "Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in SnapShot.CountByCategory webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to inject SQL commands via unspecified vectors.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29230" + }, + { + "type": "WEB", + "url": "https://www.synology.com/en-global/security/advisory/Synology_SA_24_04" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T07:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-cff4-mgrp-gmqw/GHSA-cff4-mgrp-gmqw.json b/advisories/unreviewed/2024/03/GHSA-cff4-mgrp-gmqw/GHSA-cff4-mgrp-gmqw.json new file mode 100644 index 00000000000..ff002f7bbf8 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-cff4-mgrp-gmqw/GHSA-cff4-mgrp-gmqw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cff4-mgrp-gmqw", + "modified": "2024-03-28T09:31:13Z", + "published": "2024-03-28T09:31:13Z", + "aliases": [ + "CVE-2024-29239" + ], + "details": "Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Recording.CountByCategory webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to inject SQL commands via unspecified vectors.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29239" + }, + { + "type": "WEB", + "url": "https://www.synology.com/en-global/security/advisory/Synology_SA_24_04" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T07:16:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-ch4r-pfrr-4fj5/GHSA-ch4r-pfrr-4fj5.json b/advisories/unreviewed/2024/03/GHSA-ch4r-pfrr-4fj5/GHSA-ch4r-pfrr-4fj5.json new file mode 100644 index 00000000000..fb5b04bf33d --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-ch4r-pfrr-4fj5/GHSA-ch4r-pfrr-4fj5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ch4r-pfrr-4fj5", + "modified": "2024-03-28T09:31:13Z", + "published": "2024-03-28T09:31:13Z", + "aliases": [ + "CVE-2024-2890" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Tumult Inc. Tumult Hype Animations.This issue affects Tumult Hype Animations: from n/a through 1.9.12.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2890" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/tumult-hype-animations/wordpress-tumult-hype-animations-plugin-1-9-12-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T07:16:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-f357-4jg5-3c72/GHSA-f357-4jg5-3c72.json b/advisories/unreviewed/2024/03/GHSA-f357-4jg5-3c72/GHSA-f357-4jg5-3c72.json new file mode 100644 index 00000000000..ec8a01641ad --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-f357-4jg5-3c72/GHSA-f357-4jg5-3c72.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f357-4jg5-3c72", + "modified": "2024-03-28T09:31:12Z", + "published": "2024-03-28T09:31:12Z", + "aliases": [ + "CVE-2024-25599" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Castos Seriously Simple Podcasting allows Reflected XSS.This issue affects Seriously Simple Podcasting: from n/a through 3.0.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25599" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/seriously-simple-podcasting/wordpress-seriously-simple-podcasting-plugin-3-0-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T07:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-fhpq-7g7c-xh6j/GHSA-fhpq-7g7c-xh6j.json b/advisories/unreviewed/2024/03/GHSA-fhpq-7g7c-xh6j/GHSA-fhpq-7g7c-xh6j.json new file mode 100644 index 00000000000..22bf5892821 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-fhpq-7g7c-xh6j/GHSA-fhpq-7g7c-xh6j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fhpq-7g7c-xh6j", + "modified": "2024-03-28T09:31:13Z", + "published": "2024-03-28T09:31:13Z", + "aliases": [ + "CVE-2024-29231" + ], + "details": "Improper validation of array index vulnerability in UserPrivilege.Enum webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to bypass security constraints via unspecified vectors.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29231" + }, + { + "type": "WEB", + "url": "https://www.synology.com/en-global/security/advisory/Synology_SA_24_04" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-129" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T07:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-fp3v-8f7x-27x6/GHSA-fp3v-8f7x-27x6.json b/advisories/unreviewed/2024/03/GHSA-fp3v-8f7x-27x6/GHSA-fp3v-8f7x-27x6.json new file mode 100644 index 00000000000..fa26acd0bc6 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-fp3v-8f7x-27x6/GHSA-fp3v-8f7x-27x6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fp3v-8f7x-27x6", + "modified": "2024-03-28T09:31:13Z", + "published": "2024-03-28T09:31:13Z", + "aliases": [ + "CVE-2024-29240" + ], + "details": "Missing authorization vulnerability in LayoutSave webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to conduct denial-of-service attacks via unspecified vectors.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29240" + }, + { + "type": "WEB", + "url": "https://www.synology.com/en-global/security/advisory/Synology_SA_24_04" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T07:16:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-g77p-w9vp-8chh/GHSA-g77p-w9vp-8chh.json b/advisories/unreviewed/2024/03/GHSA-g77p-w9vp-8chh/GHSA-g77p-w9vp-8chh.json new file mode 100644 index 00000000000..20f848db97f --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-g77p-w9vp-8chh/GHSA-g77p-w9vp-8chh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g77p-w9vp-8chh", + "modified": "2024-03-28T09:31:13Z", + "published": "2024-03-28T09:31:13Z", + "aliases": [ + "CVE-2024-29227" + ], + "details": "Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Layout.LayoutSave webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to inject SQL commands via unspecified vectors.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29227" + }, + { + "type": "WEB", + "url": "https://www.synology.com/en-global/security/advisory/Synology_SA_24_04" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T07:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-gfrg-rfm6-xh56/GHSA-gfrg-rfm6-xh56.json b/advisories/unreviewed/2024/03/GHSA-gfrg-rfm6-xh56/GHSA-gfrg-rfm6-xh56.json new file mode 100644 index 00000000000..32b3aaac2c8 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-gfrg-rfm6-xh56/GHSA-gfrg-rfm6-xh56.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gfrg-rfm6-xh56", + "modified": "2024-03-28T09:31:12Z", + "published": "2024-03-28T09:31:12Z", + "aliases": [ + "CVE-2022-45850" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Nickys Image Map Pro allows Stored XSS.This issue affects Image Map Pro: from n/a before 5.6.9.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45850" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/image-map-pro-wordpress/wordpress-image-map-pro-premium-plugin-5-5-0-cross-site-request-forgery-csrf-leading-to-stored-cross-site-scripting-xss?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T07:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-h79h-c7qx-243v/GHSA-h79h-c7qx-243v.json b/advisories/unreviewed/2024/03/GHSA-h79h-c7qx-243v/GHSA-h79h-c7qx-243v.json new file mode 100644 index 00000000000..c39e8b28cc9 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-h79h-c7qx-243v/GHSA-h79h-c7qx-243v.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h79h-c7qx-243v", + "modified": "2024-03-28T09:31:13Z", + "published": "2024-03-28T09:31:13Z", + "aliases": [ + "CVE-2023-6371" + ], + "details": "An issue has been discovered in GitLab CE/EE affecting all versions before 16.8.5, all versions starting from 16.9 before 16.9.3, all versions starting from 16.10 before 16.10.1. A wiki page with a crafted payload may lead to a Stored XSS, allowing attackers to perform arbitrary actions on behalf of victims.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6371" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2257080" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/433021" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T08:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-h7gm-vmp6-5rfg/GHSA-h7gm-vmp6-5rfg.json b/advisories/unreviewed/2024/03/GHSA-h7gm-vmp6-5rfg/GHSA-h7gm-vmp6-5rfg.json new file mode 100644 index 00000000000..0f7948281fd --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-h7gm-vmp6-5rfg/GHSA-h7gm-vmp6-5rfg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h7gm-vmp6-5rfg", + "modified": "2024-03-28T09:31:13Z", + "published": "2024-03-28T09:31:13Z", + "aliases": [ + "CVE-2024-30421" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Pixelite Events Manager.This issue affects Events Manager: from n/a through 6.4.7.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30421" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/events-manager/wordpress-events-manager-plugin-6-4-7-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-jr67-rvwm-64hr/GHSA-jr67-rvwm-64hr.json b/advisories/unreviewed/2024/03/GHSA-jr67-rvwm-64hr/GHSA-jr67-rvwm-64hr.json new file mode 100644 index 00000000000..8ef57f9de4b --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-jr67-rvwm-64hr/GHSA-jr67-rvwm-64hr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jr67-rvwm-64hr", + "modified": "2024-03-28T09:31:12Z", + "published": "2024-03-28T09:31:12Z", + "aliases": [ + "CVE-2023-23649" + ], + "details": "Deserialization of Untrusted Data vulnerability in MainWP MainWP Links Manager Extension.This issue affects MainWP Links Manager Extension: from n/a through 2.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23649" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/mainwp-links-manager-extension/wordpress-mainwp-links-manager-extension-plugin-2-1-unauthenticated-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T07:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-m4cf-5m9h-j563/GHSA-m4cf-5m9h-j563.json b/advisories/unreviewed/2024/03/GHSA-m4cf-5m9h-j563/GHSA-m4cf-5m9h-j563.json new file mode 100644 index 00000000000..3faf909f9c4 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-m4cf-5m9h-j563/GHSA-m4cf-5m9h-j563.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m4cf-5m9h-j563", + "modified": "2024-03-28T09:31:13Z", + "published": "2024-03-28T09:31:13Z", + "aliases": [ + "CVE-2024-28001" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Archetyped Favicon Rotator allows Reflected XSS.This issue affects Favicon Rotator: from n/a through 1.2.10.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28001" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/favicon-rotator/wordpress-favicon-rotator-plugin-1-2-10-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T07:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-mp83-mf85-hm8w/GHSA-mp83-mf85-hm8w.json b/advisories/unreviewed/2024/03/GHSA-mp83-mf85-hm8w/GHSA-mp83-mf85-hm8w.json new file mode 100644 index 00000000000..13a44e32257 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-mp83-mf85-hm8w/GHSA-mp83-mf85-hm8w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mp83-mf85-hm8w", + "modified": "2024-03-28T09:31:12Z", + "published": "2024-03-28T09:31:12Z", + "aliases": [ + "CVE-2024-27999" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Digamber Pradhan Preview E-mails for WooCommerce allows Reflected XSS.This issue affects Preview E-mails for WooCommerce: from n/a through 2.2.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27999" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/woo-preview-emails/wordpress-preview-e-mails-for-woocommerce-plugin-2-2-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T07:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-pmpm-rfmv-4qfw/GHSA-pmpm-rfmv-4qfw.json b/advisories/unreviewed/2024/03/GHSA-pmpm-rfmv-4qfw/GHSA-pmpm-rfmv-4qfw.json new file mode 100644 index 00000000000..0b333f08c66 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-pmpm-rfmv-4qfw/GHSA-pmpm-rfmv-4qfw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pmpm-rfmv-4qfw", + "modified": "2024-03-28T09:31:13Z", + "published": "2024-03-28T09:31:13Z", + "aliases": [ + "CVE-2024-29232" + ], + "details": "Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Alert.Enum webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to inject SQL commands via unspecified vectors.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29232" + }, + { + "type": "WEB", + "url": "https://www.synology.com/en-global/security/advisory/Synology_SA_24_04" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T07:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-pv3w-w9gj-7hf3/GHSA-pv3w-w9gj-7hf3.json b/advisories/unreviewed/2024/03/GHSA-pv3w-w9gj-7hf3/GHSA-pv3w-w9gj-7hf3.json new file mode 100644 index 00000000000..ae7ca591c9c --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-pv3w-w9gj-7hf3/GHSA-pv3w-w9gj-7hf3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pv3w-w9gj-7hf3", + "modified": "2024-03-28T09:31:12Z", + "published": "2024-03-28T09:31:12Z", + "aliases": [ + "CVE-2023-39309" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThemeFusion Fusion Builder.This issue affects Fusion Builder: from n/a through 3.11.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39309" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/fusion-builder/wordpress-avada-builder-plugin-3-11-1-authenticated-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T07:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-q5gr-4pxm-mggp/GHSA-q5gr-4pxm-mggp.json b/advisories/unreviewed/2024/03/GHSA-q5gr-4pxm-mggp/GHSA-q5gr-4pxm-mggp.json new file mode 100644 index 00000000000..7de61f6612f --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-q5gr-4pxm-mggp/GHSA-q5gr-4pxm-mggp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q5gr-4pxm-mggp", + "modified": "2024-03-28T09:31:13Z", + "published": "2024-03-28T09:31:13Z", + "aliases": [ + "CVE-2024-28002" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Archetyped Cornerstone allows Reflected XSS.This issue affects Cornerstone: from n/a through 0.8.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28002" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/cornerstone/wordpress-cornerstone-plugin-0-8-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T07:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-qr9h-3x95-xj25/GHSA-qr9h-3x95-xj25.json b/advisories/unreviewed/2024/03/GHSA-qr9h-3x95-xj25/GHSA-qr9h-3x95-xj25.json new file mode 100644 index 00000000000..76d6825b239 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-qr9h-3x95-xj25/GHSA-qr9h-3x95-xj25.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qr9h-3x95-xj25", + "modified": "2024-03-28T09:31:13Z", + "published": "2024-03-28T09:31:13Z", + "aliases": [ + "CVE-2024-29233" + ], + "details": "Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Emap.Delete webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to inject SQL commands via unspecified vectors.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29233" + }, + { + "type": "WEB", + "url": "https://www.synology.com/en-global/security/advisory/Synology_SA_24_04" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T07:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-rm46-6hhw-pcff/GHSA-rm46-6hhw-pcff.json b/advisories/unreviewed/2024/03/GHSA-rm46-6hhw-pcff/GHSA-rm46-6hhw-pcff.json new file mode 100644 index 00000000000..1530e3178be --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-rm46-6hhw-pcff/GHSA-rm46-6hhw-pcff.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rm46-6hhw-pcff", + "modified": "2024-03-28T09:31:13Z", + "published": "2024-03-28T09:31:13Z", + "aliases": [ + "CVE-2024-29238" + ], + "details": "Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log.CountByCategory webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to inject SQL commands via unspecified vectors.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29238" + }, + { + "type": "WEB", + "url": "https://www.synology.com/en-global/security/advisory/Synology_SA_24_04" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T07:16:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-v39g-wrm7-w5p9/GHSA-v39g-wrm7-w5p9.json b/advisories/unreviewed/2024/03/GHSA-v39g-wrm7-w5p9/GHSA-v39g-wrm7-w5p9.json new file mode 100644 index 00000000000..7be9f920158 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-v39g-wrm7-w5p9/GHSA-v39g-wrm7-w5p9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v39g-wrm7-w5p9", + "modified": "2024-03-28T09:31:12Z", + "published": "2024-03-28T09:31:12Z", + "aliases": [ + "CVE-2024-25923" + ], + "details": "Insertion of Sensitive Information into Log File vulnerability in PeepSo Community by PeepSo.This issue affects Community by PeepSo: from n/a through 6.2.7.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25923" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/peepso-core/wordpress-community-by-peepso-plugin-6-2-7-0-sensitive-data-exposure-via-log-file-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T07:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-v474-9fch-f5gf/GHSA-v474-9fch-f5gf.json b/advisories/unreviewed/2024/03/GHSA-v474-9fch-f5gf/GHSA-v474-9fch-f5gf.json new file mode 100644 index 00000000000..853e674fbd1 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-v474-9fch-f5gf/GHSA-v474-9fch-f5gf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v474-9fch-f5gf", + "modified": "2024-03-28T09:31:13Z", + "published": "2024-03-28T09:31:13Z", + "aliases": [ + "CVE-2024-29234" + ], + "details": "Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Group.Save webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to inject SQL commands via unspecified vectors.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29234" + }, + { + "type": "WEB", + "url": "https://www.synology.com/en-global/security/advisory/Synology_SA_24_04" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T07:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-vcrj-9gmf-8p66/GHSA-vcrj-9gmf-8p66.json b/advisories/unreviewed/2024/03/GHSA-vcrj-9gmf-8p66/GHSA-vcrj-9gmf-8p66.json new file mode 100644 index 00000000000..561c47386eb --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-vcrj-9gmf-8p66/GHSA-vcrj-9gmf-8p66.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vcrj-9gmf-8p66", + "modified": "2024-03-28T09:31:12Z", + "published": "2024-03-28T09:31:12Z", + "aliases": [ + "CVE-2023-50374" + ], + "details": "Server-Side Request Forgery (SSRF) vulnerability in NiteoThemes CMP – Coming Soon & Maintenance.This issue affects CMP – Coming Soon & Maintenance: from n/a through 4.1.10.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50374" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/cmp-coming-soon-maintenance/wordpress-cmp-coming-soon-maintenance-plugin-by-niteothemes-plugin-4-1-10-server-side-request-forgery-ssrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T07:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-vq86-gxf4-q6gh/GHSA-vq86-gxf4-q6gh.json b/advisories/unreviewed/2024/03/GHSA-vq86-gxf4-q6gh/GHSA-vq86-gxf4-q6gh.json new file mode 100644 index 00000000000..38471761e2a --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-vq86-gxf4-q6gh/GHSA-vq86-gxf4-q6gh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vq86-gxf4-q6gh", + "modified": "2024-03-28T09:31:13Z", + "published": "2024-03-28T09:31:13Z", + "aliases": [ + "CVE-2024-29228" + ], + "details": "Missing authorization vulnerability in GetStmUrlPath webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to obtain sensitive information via unspecified vectors.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29228" + }, + { + "type": "WEB", + "url": "https://www.synology.com/en-global/security/advisory/Synology_SA_24_04" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T07:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-vvwv-623p-wcgq/GHSA-vvwv-623p-wcgq.json b/advisories/unreviewed/2024/03/GHSA-vvwv-623p-wcgq/GHSA-vvwv-623p-wcgq.json new file mode 100644 index 00000000000..54077832728 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-vvwv-623p-wcgq/GHSA-vvwv-623p-wcgq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vvwv-623p-wcgq", + "modified": "2024-03-28T09:31:13Z", + "published": "2024-03-28T09:31:13Z", + "aliases": [ + "CVE-2024-29229" + ], + "details": "Missing authorization vulnerability in GetLiveViewPath webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to obtain sensitive information via unspecified vectors.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29229" + }, + { + "type": "WEB", + "url": "https://www.synology.com/en-global/security/advisory/Synology_SA_24_04" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T07:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-w87c-p927-5whf/GHSA-w87c-p927-5whf.json b/advisories/unreviewed/2024/03/GHSA-w87c-p927-5whf/GHSA-w87c-p927-5whf.json new file mode 100644 index 00000000000..4383ebfc41f --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-w87c-p927-5whf/GHSA-w87c-p927-5whf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w87c-p927-5whf", + "modified": "2024-03-28T09:31:13Z", + "published": "2024-03-28T09:31:13Z", + "aliases": [ + "CVE-2024-29235" + ], + "details": "Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in IOModule.EnumLog webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to inject SQL commands via unspecified vectors.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29235" + }, + { + "type": "WEB", + "url": "https://www.synology.com/en-global/security/advisory/Synology_SA_24_04" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T07:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-whq5-gmv6-9878/GHSA-whq5-gmv6-9878.json b/advisories/unreviewed/2024/03/GHSA-whq5-gmv6-9878/GHSA-whq5-gmv6-9878.json new file mode 100644 index 00000000000..b226621057e --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-whq5-gmv6-9878/GHSA-whq5-gmv6-9878.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-whq5-gmv6-9878", + "modified": "2024-03-28T09:31:13Z", + "published": "2024-03-28T09:31:13Z", + "aliases": [ + "CVE-2024-29237" + ], + "details": "Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in ActionRule.Delete webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to inject SQL commands via unspecified vectors.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29237" + }, + { + "type": "WEB", + "url": "https://www.synology.com/en-global/security/advisory/Synology_SA_24_04" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T07:16:09Z" + } +} \ No newline at end of file