Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-04-29 09:33:01 +00:00
parent 9f00223e30
commit 94f1efca1b
33 changed files with 1140 additions and 6 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5667-3wch-7q7w",
"modified": "2024-04-09T12:30:44Z",
"modified": "2024-04-29T09:31:52Z",
"published": "2024-03-27T09:30:40Z",
"aliases": [
"CVE-2024-1023"
@@ -87,6 +87,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1706"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:2088"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-1023"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9ph3-v2vh-3qx7",
"modified": "2024-04-18T18:30:40Z",
"modified": "2024-04-29T09:31:52Z",
"published": "2024-04-02T09:30:42Z",
"aliases": [
"CVE-2024-1300"
@@ -91,6 +91,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1923"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:2088"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-1300"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ppfv-9rmx-jjrq",
"modified": "2024-04-04T05:34:35Z",
"modified": "2024-04-29T09:31:51Z",
"published": "2023-07-06T19:24:11Z",
"aliases": [
"CVE-2021-36821"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2gcm-q5j8-5j8g",
"modified": "2024-04-04T07:59:57Z",
"modified": "2024-04-29T09:31:51Z",
"published": "2023-10-02T09:30:27Z",
"aliases": [
"CVE-2023-41728"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pwp8-rv27-qh29",
"modified": "2024-04-04T08:05:03Z",
"modified": "2024-04-29T09:31:51Z",
"published": "2023-10-03T12:30:19Z",
"aliases": [
"CVE-2023-37998"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xv4r-44qp-78wm",
"modified": "2024-03-21T18:32:03Z",
"modified": "2024-04-29T09:31:52Z",
"published": "2024-03-21T18:32:03Z",
"aliases": [
"CVE-2024-27956"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27956"
},
{
"type": "WEB",
"url": "https://patchstack.com/articles/critical-vulnerabilities-patched-in-wordpress-automatic-plugin?_s_id=cve"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/wp-automatic/wordpress-automatic-plugin-3-92-0-unauthenticated-arbitrary-sql-execution-vulnerability?_s_id=cve"
@@ -0,0 +1,54 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2fhr-94vx-gjwj",
"modified": "2024-04-29T09:31:52Z",
"published": "2024-04-29T09:31:52Z",
"aliases": [
"CVE-2024-3191"
],
"details": "A vulnerability, which was classified as critical, has been found in MailCleaner up to 2023.03.14. This issue affects some unknown processing of the component Email Handler. The manipulation leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-262307.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3191"
},
{
"type": "WEB",
"url": "https://github.com/MailCleaner/MailCleaner/pull/601"
},
{
"type": "WEB",
"url": "https://modzero.com/en/advisories/mz-24-01-mailcleaner"
},
{
"type": "WEB",
"url": "https://modzero.com/static/MZ-24-01_modzero_MailCleaner.pdf"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.262307"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.262307"
}
],
"database_specific": {
"cwe_ids": [
"CWE-78"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-29T07:15:07Z"
}
}
@@ -0,0 +1,54 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2v33-23h8-f74g",
"modified": "2024-04-29T09:31:52Z",
"published": "2024-04-29T09:31:52Z",
"aliases": [
"CVE-2024-3194"
],
"details": "A vulnerability was found in MailCleaner up to 2023.03.14 and classified as problematic. Affected by this issue is some unknown functionality of the component Log File Endpoint. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. VDB-262310 is the identifier assigned to this vulnerability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3194"
},
{
"type": "WEB",
"url": "https://github.com/MailCleaner/MailCleaner/pull/601"
},
{
"type": "WEB",
"url": "https://modzero.com/en/advisories/mz-24-01-mailcleaner"
},
{
"type": "WEB",
"url": "https://modzero.com/static/MZ-24-01_modzero_MailCleaner.pdf"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.262310"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.262310"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-29T07:15:08Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3cjh-h2h5-qjc2",
"modified": "2024-04-29T09:31:52Z",
"published": "2024-04-29T09:31:52Z",
"aliases": [
"CVE-2024-33641"
],
"details": "Deserialization of Untrusted Data vulnerability in Team Yoast Custom field finder.This issue affects Custom field finder: from n/a through 0.3.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33641"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/custom-field-finder/wordpress-custom-field-finder-plugin-0-3-php-object-injection-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-502"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-29T08:15:08Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4359-2h7h-5jm3",
"modified": "2024-04-29T09:31:52Z",
"published": "2024-04-29T09:31:52Z",
"aliases": [
"CVE-2024-33627"
],
"details": "Server-Side Request Forgery (SSRF) vulnerability in Cusmin Absolutely Glamorous Custom Admin.This issue affects Absolutely Glamorous Custom Admin: from n/a through 7.2.2.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33627"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/ag-custom-admin/wordpress-agca-custom-dashboard-login-page-plugin-7-2-2-server-side-request-forgery-ssrf-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-918"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-29T08:15:07Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4wch-q26f-448q",
"modified": "2024-04-29T09:31:53Z",
"published": "2024-04-29T09:31:53Z",
"aliases": [
"CVE-2024-3375"
],
"details": "Incorrect Permission Assignment for Critical Resource vulnerability in Havelsan Inc. Dialogue allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Dialogue: from v1.83 before v1.83.1 or v1.84.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3375"
},
{
"type": "WEB",
"url": "https://www.usom.gov.tr/bildirim/tr-24-0363"
}
],
"database_specific": {
"cwe_ids": [
"CWE-732"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-29T09:15:09Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5xxc-3cwr-rgj7",
"modified": "2024-04-29T09:31:52Z",
"published": "2024-04-29T09:31:52Z",
"aliases": [
"CVE-2024-33575"
],
"details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in User Meta user-meta.This issue affects User Meta: from n/a through 3.0.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33575"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/user-meta/wordpress-user-meta-plugin-3-0-sensitive-data-exposure-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-200"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-29T08:15:06Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6393-6w3w-9w86",
"modified": "2024-04-29T09:31:52Z",
"published": "2024-04-29T09:31:52Z",
"aliases": [
"CVE-2024-33637"
],
"details": "Insertion of Sensitive Information into Log File vulnerability in Solid Plugins Solid Affiliate.This issue affects Solid Affiliate: from n/a through 1.9.1.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33637"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/solid-affiliate/wordpress-solid-affiliate-plugin-1-9-1-sensitive-data-exposure-via-log-file-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-532"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-29T08:15:08Z"
}
}
@@ -0,0 +1,54 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6gjj-j8cj-v7v3",
"modified": "2024-04-29T09:31:52Z",
"published": "2024-04-29T09:31:52Z",
"aliases": [
"CVE-2024-3196"
],
"details": "A vulnerability was found in MailCleaner up to 2023.03.14. It has been declared as critical. This vulnerability affects unknown code of the file /mailcleaner.php/getStats of the component SOAP Service. The manipulation leads to os command injection. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-262312.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3196"
},
{
"type": "WEB",
"url": "https://github.com/MailCleaner/MailCleaner/pull/601"
},
{
"type": "WEB",
"url": "https://modzero.com/en/advisories/mz-24-01-mailcleaner"
},
{
"type": "WEB",
"url": "https://modzero.com/static/MZ-24-01_modzero_MailCleaner.pdf"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.262312"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.262312"
}
],
"database_specific": {
"cwe_ids": [
"CWE-78"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-29T07:15:08Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-75mr-qv3c-5mmf",
"modified": "2024-04-29T09:31:53Z",
"published": "2024-04-29T09:31:52Z",
"aliases": [
"CVE-2024-28961"
],
"details": "Dell OpenManage Enterprise, versions 4.0.0 and 4.0.1, contains a sensitive information disclosure vulnerability. A local low privileged malicious user could potentially exploit this vulnerability to obtain credentials leading to unauthorized access with elevated privileges. This could lead to further attacks, thus Dell recommends customers to upgrade at the earliest opportunity.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28961"
},
{
"type": "WEB",
"url": "https://www.dell.com/support/kbdoc/en-us/000224251/dsa-2024-184-security-update-for-dell-openmanage-enterprise-vulnerability"
}
],
"database_specific": {
"cwe_ids": [
"CWE-256"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-29T09:15:07Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7m76-8vv9-hcqm",
"modified": "2024-04-29T09:31:53Z",
"published": "2024-04-29T09:31:52Z",
"aliases": [
"CVE-2024-33652"
],
"details": "Missing Authorization vulnerability in Real Big Plugins Client Dash.This issue affects Client Dash: from n/a through 2.2.1.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33652"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/client-dash/wordpress-client-dash-plugin-2-2-1-broken-access-control-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-862"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-29T08:15:08Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8f29-7cmc-83vw",
"modified": "2024-04-29T09:31:53Z",
"published": "2024-04-29T09:31:53Z",
"aliases": [
"CVE-2024-33596"
],
"details": "Missing Authorization vulnerability in Five Star Plugins Five Star Restaurant Reservations.This issue affects Five Star Restaurant Reservations: from n/a through 2.6.16.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33596"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/restaurant-reservations/wordpress-five-star-restaurant-reservations-plugin-2-6-16-broken-access-control-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-862"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-29T09:15:08Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-992x-5q5j-jmp5",
"modified": "2024-04-29T09:31:52Z",
"published": "2024-04-29T09:31:52Z",
"aliases": [
"CVE-2024-33538"
],
"details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Fastline Media LLC Assistant Every Day Productivity Apps.This issue affects Assistant Every Day Productivity Apps: from n/a through 1.4.9.1.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33538"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/assistant/wordpress-assistant-every-day-productivity-apps-plugin-1-4-9-1-sensitive-data-exposure-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-200"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-29T08:15:06Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-994v-8mpg-9f54",
"modified": "2024-04-29T09:31:52Z",
"published": "2024-04-29T09:31:52Z",
"aliases": [
"CVE-2024-33584"
],
"details": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Deepen Bajracharya Video Conferencing with Zoom.This issue affects Video Conferencing with Zoom: from n/a through 4.4.4.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33584"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/video-conferencing-with-zoom-api/wordpress-video-conferencing-with-zoom-plugin-4-4-4-open-redirection-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-601"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-29T08:15:07Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9xqh-c85q-wvfr",
"modified": "2024-04-29T09:31:52Z",
"published": "2024-04-29T09:31:52Z",
"aliases": [
"CVE-2024-33546"
],
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team WZone allows SQL Injection.This issue affects WZone: from n/a through 14.0.10.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33546"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/woozone/wordpress-wzone-plugin-14-0-10-arbitrary-sql-update-execution-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-29T07:15:06Z"
}
}

Some files were not shown because too many files have changed in this diff Show More