From 94f1efca1b0b640e36c56976298e56707af176cf Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 29 Apr 2024 09:33:01 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-5667-3wch-7q7w.json | 6 ++- .../GHSA-9ph3-v2vh-3qx7.json | 6 ++- .../GHSA-ppfv-9rmx-jjrq.json | 2 +- .../GHSA-2gcm-q5j8-5j8g.json | 2 +- .../GHSA-pwp8-rv27-qh29.json | 2 +- .../GHSA-xv4r-44qp-78wm.json | 6 ++- .../GHSA-2fhr-94vx-gjwj.json | 54 +++++++++++++++++++ .../GHSA-2v33-23h8-f74g.json | 54 +++++++++++++++++++ .../GHSA-3cjh-h2h5-qjc2.json | 38 +++++++++++++ .../GHSA-4359-2h7h-5jm3.json | 38 +++++++++++++ .../GHSA-4wch-q26f-448q.json | 38 +++++++++++++ .../GHSA-5xxc-3cwr-rgj7.json | 38 +++++++++++++ .../GHSA-6393-6w3w-9w86.json | 38 +++++++++++++ .../GHSA-6gjj-j8cj-v7v3.json | 54 +++++++++++++++++++ .../GHSA-75mr-qv3c-5mmf.json | 38 +++++++++++++ .../GHSA-7m76-8vv9-hcqm.json | 38 +++++++++++++ .../GHSA-8f29-7cmc-83vw.json | 38 +++++++++++++ .../GHSA-992x-5q5j-jmp5.json | 38 +++++++++++++ .../GHSA-994v-8mpg-9f54.json | 38 +++++++++++++ .../GHSA-9xqh-c85q-wvfr.json | 38 +++++++++++++ .../GHSA-c63r-p9j6-xm6r.json | 38 +++++++++++++ .../GHSA-fj75-q86h-2r5g.json | 54 +++++++++++++++++++ .../GHSA-fwrh-xmxv-qj39.json | 38 +++++++++++++ .../GHSA-gr5j-xcqm-p2ph.json | 38 +++++++++++++ .../GHSA-gv7p-f5gp-mj9q.json | 38 +++++++++++++ .../GHSA-j3xx-xw6j-f8q3.json | 38 +++++++++++++ .../GHSA-j6m3-4fcr-hq62.json | 38 +++++++++++++ .../GHSA-mp8f-xwf5-rv6v.json | 38 +++++++++++++ .../GHSA-qqfg-7xr5-8hvg.json | 54 +++++++++++++++++++ .../GHSA-vfj7-w3gq-g683.json | 38 +++++++++++++ .../GHSA-w6gm-jg83-rm6w.json | 38 +++++++++++++ .../GHSA-x7gc-r4xg-v7c2.json | 38 +++++++++++++ .../GHSA-xmgc-h398-rg8w.json | 54 +++++++++++++++++++ 33 files changed, 1140 insertions(+), 6 deletions(-) create mode 100644 advisories/unreviewed/2024/04/GHSA-2fhr-94vx-gjwj/GHSA-2fhr-94vx-gjwj.json create mode 100644 advisories/unreviewed/2024/04/GHSA-2v33-23h8-f74g/GHSA-2v33-23h8-f74g.json create mode 100644 advisories/unreviewed/2024/04/GHSA-3cjh-h2h5-qjc2/GHSA-3cjh-h2h5-qjc2.json create mode 100644 advisories/unreviewed/2024/04/GHSA-4359-2h7h-5jm3/GHSA-4359-2h7h-5jm3.json create mode 100644 advisories/unreviewed/2024/04/GHSA-4wch-q26f-448q/GHSA-4wch-q26f-448q.json create mode 100644 advisories/unreviewed/2024/04/GHSA-5xxc-3cwr-rgj7/GHSA-5xxc-3cwr-rgj7.json create mode 100644 advisories/unreviewed/2024/04/GHSA-6393-6w3w-9w86/GHSA-6393-6w3w-9w86.json create mode 100644 advisories/unreviewed/2024/04/GHSA-6gjj-j8cj-v7v3/GHSA-6gjj-j8cj-v7v3.json create mode 100644 advisories/unreviewed/2024/04/GHSA-75mr-qv3c-5mmf/GHSA-75mr-qv3c-5mmf.json create mode 100644 advisories/unreviewed/2024/04/GHSA-7m76-8vv9-hcqm/GHSA-7m76-8vv9-hcqm.json create mode 100644 advisories/unreviewed/2024/04/GHSA-8f29-7cmc-83vw/GHSA-8f29-7cmc-83vw.json create mode 100644 advisories/unreviewed/2024/04/GHSA-992x-5q5j-jmp5/GHSA-992x-5q5j-jmp5.json create mode 100644 advisories/unreviewed/2024/04/GHSA-994v-8mpg-9f54/GHSA-994v-8mpg-9f54.json create mode 100644 advisories/unreviewed/2024/04/GHSA-9xqh-c85q-wvfr/GHSA-9xqh-c85q-wvfr.json create mode 100644 advisories/unreviewed/2024/04/GHSA-c63r-p9j6-xm6r/GHSA-c63r-p9j6-xm6r.json create mode 100644 advisories/unreviewed/2024/04/GHSA-fj75-q86h-2r5g/GHSA-fj75-q86h-2r5g.json create mode 100644 advisories/unreviewed/2024/04/GHSA-fwrh-xmxv-qj39/GHSA-fwrh-xmxv-qj39.json create mode 100644 advisories/unreviewed/2024/04/GHSA-gr5j-xcqm-p2ph/GHSA-gr5j-xcqm-p2ph.json create mode 100644 advisories/unreviewed/2024/04/GHSA-gv7p-f5gp-mj9q/GHSA-gv7p-f5gp-mj9q.json create mode 100644 advisories/unreviewed/2024/04/GHSA-j3xx-xw6j-f8q3/GHSA-j3xx-xw6j-f8q3.json create mode 100644 advisories/unreviewed/2024/04/GHSA-j6m3-4fcr-hq62/GHSA-j6m3-4fcr-hq62.json create mode 100644 advisories/unreviewed/2024/04/GHSA-mp8f-xwf5-rv6v/GHSA-mp8f-xwf5-rv6v.json create mode 100644 advisories/unreviewed/2024/04/GHSA-qqfg-7xr5-8hvg/GHSA-qqfg-7xr5-8hvg.json create mode 100644 advisories/unreviewed/2024/04/GHSA-vfj7-w3gq-g683/GHSA-vfj7-w3gq-g683.json create mode 100644 advisories/unreviewed/2024/04/GHSA-w6gm-jg83-rm6w/GHSA-w6gm-jg83-rm6w.json create mode 100644 advisories/unreviewed/2024/04/GHSA-x7gc-r4xg-v7c2/GHSA-x7gc-r4xg-v7c2.json create mode 100644 advisories/unreviewed/2024/04/GHSA-xmgc-h398-rg8w/GHSA-xmgc-h398-rg8w.json diff --git a/advisories/github-reviewed/2024/03/GHSA-5667-3wch-7q7w/GHSA-5667-3wch-7q7w.json b/advisories/github-reviewed/2024/03/GHSA-5667-3wch-7q7w/GHSA-5667-3wch-7q7w.json index f662d46c86f..a185ea9e0da 100644 --- a/advisories/github-reviewed/2024/03/GHSA-5667-3wch-7q7w/GHSA-5667-3wch-7q7w.json +++ b/advisories/github-reviewed/2024/03/GHSA-5667-3wch-7q7w/GHSA-5667-3wch-7q7w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5667-3wch-7q7w", - "modified": "2024-04-09T12:30:44Z", + "modified": "2024-04-29T09:31:52Z", "published": "2024-03-27T09:30:40Z", "aliases": [ "CVE-2024-1023" @@ -87,6 +87,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:1706" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:2088" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-1023" diff --git a/advisories/github-reviewed/2024/04/GHSA-9ph3-v2vh-3qx7/GHSA-9ph3-v2vh-3qx7.json b/advisories/github-reviewed/2024/04/GHSA-9ph3-v2vh-3qx7/GHSA-9ph3-v2vh-3qx7.json index 243679f9a1b..a218ed528dd 100644 --- a/advisories/github-reviewed/2024/04/GHSA-9ph3-v2vh-3qx7/GHSA-9ph3-v2vh-3qx7.json +++ b/advisories/github-reviewed/2024/04/GHSA-9ph3-v2vh-3qx7/GHSA-9ph3-v2vh-3qx7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9ph3-v2vh-3qx7", - "modified": "2024-04-18T18:30:40Z", + "modified": "2024-04-29T09:31:52Z", "published": "2024-04-02T09:30:42Z", "aliases": [ "CVE-2024-1300" @@ -91,6 +91,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:1923" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:2088" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-1300" diff --git a/advisories/unreviewed/2023/07/GHSA-ppfv-9rmx-jjrq/GHSA-ppfv-9rmx-jjrq.json b/advisories/unreviewed/2023/07/GHSA-ppfv-9rmx-jjrq/GHSA-ppfv-9rmx-jjrq.json index 31c0c905306..13999de6899 100644 --- a/advisories/unreviewed/2023/07/GHSA-ppfv-9rmx-jjrq/GHSA-ppfv-9rmx-jjrq.json +++ b/advisories/unreviewed/2023/07/GHSA-ppfv-9rmx-jjrq/GHSA-ppfv-9rmx-jjrq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ppfv-9rmx-jjrq", - "modified": "2024-04-04T05:34:35Z", + "modified": "2024-04-29T09:31:51Z", "published": "2023-07-06T19:24:11Z", "aliases": [ "CVE-2021-36821" diff --git a/advisories/unreviewed/2023/10/GHSA-2gcm-q5j8-5j8g/GHSA-2gcm-q5j8-5j8g.json b/advisories/unreviewed/2023/10/GHSA-2gcm-q5j8-5j8g/GHSA-2gcm-q5j8-5j8g.json index 83c7c23d07b..2386b7e4840 100644 --- a/advisories/unreviewed/2023/10/GHSA-2gcm-q5j8-5j8g/GHSA-2gcm-q5j8-5j8g.json +++ b/advisories/unreviewed/2023/10/GHSA-2gcm-q5j8-5j8g/GHSA-2gcm-q5j8-5j8g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2gcm-q5j8-5j8g", - "modified": "2024-04-04T07:59:57Z", + "modified": "2024-04-29T09:31:51Z", "published": "2023-10-02T09:30:27Z", "aliases": [ "CVE-2023-41728" diff --git a/advisories/unreviewed/2023/10/GHSA-pwp8-rv27-qh29/GHSA-pwp8-rv27-qh29.json b/advisories/unreviewed/2023/10/GHSA-pwp8-rv27-qh29/GHSA-pwp8-rv27-qh29.json index a323b96442a..cbc90b1f111 100644 --- a/advisories/unreviewed/2023/10/GHSA-pwp8-rv27-qh29/GHSA-pwp8-rv27-qh29.json +++ b/advisories/unreviewed/2023/10/GHSA-pwp8-rv27-qh29/GHSA-pwp8-rv27-qh29.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pwp8-rv27-qh29", - "modified": "2024-04-04T08:05:03Z", + "modified": "2024-04-29T09:31:51Z", "published": "2023-10-03T12:30:19Z", "aliases": [ "CVE-2023-37998" diff --git a/advisories/unreviewed/2024/03/GHSA-xv4r-44qp-78wm/GHSA-xv4r-44qp-78wm.json b/advisories/unreviewed/2024/03/GHSA-xv4r-44qp-78wm/GHSA-xv4r-44qp-78wm.json index 391791af8ce..1b4807b3c69 100644 --- a/advisories/unreviewed/2024/03/GHSA-xv4r-44qp-78wm/GHSA-xv4r-44qp-78wm.json +++ b/advisories/unreviewed/2024/03/GHSA-xv4r-44qp-78wm/GHSA-xv4r-44qp-78wm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xv4r-44qp-78wm", - "modified": "2024-03-21T18:32:03Z", + "modified": "2024-04-29T09:31:52Z", "published": "2024-03-21T18:32:03Z", "aliases": [ "CVE-2024-27956" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27956" }, + { + "type": "WEB", + "url": "https://patchstack.com/articles/critical-vulnerabilities-patched-in-wordpress-automatic-plugin?_s_id=cve" + }, { "type": "WEB", "url": "https://patchstack.com/database/vulnerability/wp-automatic/wordpress-automatic-plugin-3-92-0-unauthenticated-arbitrary-sql-execution-vulnerability?_s_id=cve" diff --git a/advisories/unreviewed/2024/04/GHSA-2fhr-94vx-gjwj/GHSA-2fhr-94vx-gjwj.json b/advisories/unreviewed/2024/04/GHSA-2fhr-94vx-gjwj/GHSA-2fhr-94vx-gjwj.json new file mode 100644 index 00000000000..8994b09413e --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-2fhr-94vx-gjwj/GHSA-2fhr-94vx-gjwj.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2fhr-94vx-gjwj", + "modified": "2024-04-29T09:31:52Z", + "published": "2024-04-29T09:31:52Z", + "aliases": [ + "CVE-2024-3191" + ], + "details": "A vulnerability, which was classified as critical, has been found in MailCleaner up to 2023.03.14. This issue affects some unknown processing of the component Email Handler. The manipulation leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-262307.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3191" + }, + { + "type": "WEB", + "url": "https://github.com/MailCleaner/MailCleaner/pull/601" + }, + { + "type": "WEB", + "url": "https://modzero.com/en/advisories/mz-24-01-mailcleaner" + }, + { + "type": "WEB", + "url": "https://modzero.com/static/MZ-24-01_modzero_MailCleaner.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.262307" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.262307" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T07:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-2v33-23h8-f74g/GHSA-2v33-23h8-f74g.json b/advisories/unreviewed/2024/04/GHSA-2v33-23h8-f74g/GHSA-2v33-23h8-f74g.json new file mode 100644 index 00000000000..b1f88b39a76 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-2v33-23h8-f74g/GHSA-2v33-23h8-f74g.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2v33-23h8-f74g", + "modified": "2024-04-29T09:31:52Z", + "published": "2024-04-29T09:31:52Z", + "aliases": [ + "CVE-2024-3194" + ], + "details": "A vulnerability was found in MailCleaner up to 2023.03.14 and classified as problematic. Affected by this issue is some unknown functionality of the component Log File Endpoint. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. VDB-262310 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3194" + }, + { + "type": "WEB", + "url": "https://github.com/MailCleaner/MailCleaner/pull/601" + }, + { + "type": "WEB", + "url": "https://modzero.com/en/advisories/mz-24-01-mailcleaner" + }, + { + "type": "WEB", + "url": "https://modzero.com/static/MZ-24-01_modzero_MailCleaner.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.262310" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.262310" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T07:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-3cjh-h2h5-qjc2/GHSA-3cjh-h2h5-qjc2.json b/advisories/unreviewed/2024/04/GHSA-3cjh-h2h5-qjc2/GHSA-3cjh-h2h5-qjc2.json new file mode 100644 index 00000000000..06aed46cff5 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-3cjh-h2h5-qjc2/GHSA-3cjh-h2h5-qjc2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3cjh-h2h5-qjc2", + "modified": "2024-04-29T09:31:52Z", + "published": "2024-04-29T09:31:52Z", + "aliases": [ + "CVE-2024-33641" + ], + "details": "Deserialization of Untrusted Data vulnerability in Team Yoast Custom field finder.This issue affects Custom field finder: from n/a through 0.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33641" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/custom-field-finder/wordpress-custom-field-finder-plugin-0-3-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T08:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4359-2h7h-5jm3/GHSA-4359-2h7h-5jm3.json b/advisories/unreviewed/2024/04/GHSA-4359-2h7h-5jm3/GHSA-4359-2h7h-5jm3.json new file mode 100644 index 00000000000..6b8576a4976 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4359-2h7h-5jm3/GHSA-4359-2h7h-5jm3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4359-2h7h-5jm3", + "modified": "2024-04-29T09:31:52Z", + "published": "2024-04-29T09:31:52Z", + "aliases": [ + "CVE-2024-33627" + ], + "details": "Server-Side Request Forgery (SSRF) vulnerability in Cusmin Absolutely Glamorous Custom Admin.This issue affects Absolutely Glamorous Custom Admin: from n/a through 7.2.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33627" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ag-custom-admin/wordpress-agca-custom-dashboard-login-page-plugin-7-2-2-server-side-request-forgery-ssrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T08:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4wch-q26f-448q/GHSA-4wch-q26f-448q.json b/advisories/unreviewed/2024/04/GHSA-4wch-q26f-448q/GHSA-4wch-q26f-448q.json new file mode 100644 index 00000000000..391a636ae37 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4wch-q26f-448q/GHSA-4wch-q26f-448q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4wch-q26f-448q", + "modified": "2024-04-29T09:31:53Z", + "published": "2024-04-29T09:31:53Z", + "aliases": [ + "CVE-2024-3375" + ], + "details": "Incorrect Permission Assignment for Critical Resource vulnerability in Havelsan Inc. Dialogue allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Dialogue: from v1.83 before v1.83.1 or v1.84.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3375" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-24-0363" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-5xxc-3cwr-rgj7/GHSA-5xxc-3cwr-rgj7.json b/advisories/unreviewed/2024/04/GHSA-5xxc-3cwr-rgj7/GHSA-5xxc-3cwr-rgj7.json new file mode 100644 index 00000000000..8ed22be0b09 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-5xxc-3cwr-rgj7/GHSA-5xxc-3cwr-rgj7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5xxc-3cwr-rgj7", + "modified": "2024-04-29T09:31:52Z", + "published": "2024-04-29T09:31:52Z", + "aliases": [ + "CVE-2024-33575" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in User Meta user-meta.This issue affects User Meta: from n/a through 3.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33575" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/user-meta/wordpress-user-meta-plugin-3-0-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T08:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-6393-6w3w-9w86/GHSA-6393-6w3w-9w86.json b/advisories/unreviewed/2024/04/GHSA-6393-6w3w-9w86/GHSA-6393-6w3w-9w86.json new file mode 100644 index 00000000000..7a7e00134ea --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-6393-6w3w-9w86/GHSA-6393-6w3w-9w86.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6393-6w3w-9w86", + "modified": "2024-04-29T09:31:52Z", + "published": "2024-04-29T09:31:52Z", + "aliases": [ + "CVE-2024-33637" + ], + "details": "Insertion of Sensitive Information into Log File vulnerability in Solid Plugins Solid Affiliate.This issue affects Solid Affiliate: from n/a through 1.9.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33637" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/solid-affiliate/wordpress-solid-affiliate-plugin-1-9-1-sensitive-data-exposure-via-log-file-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T08:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-6gjj-j8cj-v7v3/GHSA-6gjj-j8cj-v7v3.json b/advisories/unreviewed/2024/04/GHSA-6gjj-j8cj-v7v3/GHSA-6gjj-j8cj-v7v3.json new file mode 100644 index 00000000000..2d9efd039fb --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-6gjj-j8cj-v7v3/GHSA-6gjj-j8cj-v7v3.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6gjj-j8cj-v7v3", + "modified": "2024-04-29T09:31:52Z", + "published": "2024-04-29T09:31:52Z", + "aliases": [ + "CVE-2024-3196" + ], + "details": "A vulnerability was found in MailCleaner up to 2023.03.14. It has been declared as critical. This vulnerability affects unknown code of the file /mailcleaner.php/getStats of the component SOAP Service. The manipulation leads to os command injection. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-262312.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3196" + }, + { + "type": "WEB", + "url": "https://github.com/MailCleaner/MailCleaner/pull/601" + }, + { + "type": "WEB", + "url": "https://modzero.com/en/advisories/mz-24-01-mailcleaner" + }, + { + "type": "WEB", + "url": "https://modzero.com/static/MZ-24-01_modzero_MailCleaner.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.262312" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.262312" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T07:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-75mr-qv3c-5mmf/GHSA-75mr-qv3c-5mmf.json b/advisories/unreviewed/2024/04/GHSA-75mr-qv3c-5mmf/GHSA-75mr-qv3c-5mmf.json new file mode 100644 index 00000000000..73392ae2189 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-75mr-qv3c-5mmf/GHSA-75mr-qv3c-5mmf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-75mr-qv3c-5mmf", + "modified": "2024-04-29T09:31:53Z", + "published": "2024-04-29T09:31:52Z", + "aliases": [ + "CVE-2024-28961" + ], + "details": "Dell OpenManage Enterprise, versions 4.0.0 and 4.0.1, contains a sensitive information disclosure vulnerability. A local low privileged malicious user could potentially exploit this vulnerability to obtain credentials leading to unauthorized access with elevated privileges. This could lead to further attacks, thus Dell recommends customers to upgrade at the earliest opportunity.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28961" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000224251/dsa-2024-184-security-update-for-dell-openmanage-enterprise-vulnerability" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-256" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T09:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-7m76-8vv9-hcqm/GHSA-7m76-8vv9-hcqm.json b/advisories/unreviewed/2024/04/GHSA-7m76-8vv9-hcqm/GHSA-7m76-8vv9-hcqm.json new file mode 100644 index 00000000000..793399cb149 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-7m76-8vv9-hcqm/GHSA-7m76-8vv9-hcqm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7m76-8vv9-hcqm", + "modified": "2024-04-29T09:31:53Z", + "published": "2024-04-29T09:31:52Z", + "aliases": [ + "CVE-2024-33652" + ], + "details": "Missing Authorization vulnerability in Real Big Plugins Client Dash.This issue affects Client Dash: from n/a through 2.2.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33652" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/client-dash/wordpress-client-dash-plugin-2-2-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T08:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-8f29-7cmc-83vw/GHSA-8f29-7cmc-83vw.json b/advisories/unreviewed/2024/04/GHSA-8f29-7cmc-83vw/GHSA-8f29-7cmc-83vw.json new file mode 100644 index 00000000000..24cead2c200 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-8f29-7cmc-83vw/GHSA-8f29-7cmc-83vw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8f29-7cmc-83vw", + "modified": "2024-04-29T09:31:53Z", + "published": "2024-04-29T09:31:53Z", + "aliases": [ + "CVE-2024-33596" + ], + "details": "Missing Authorization vulnerability in Five Star Plugins Five Star Restaurant Reservations.This issue affects Five Star Restaurant Reservations: from n/a through 2.6.16.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33596" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/restaurant-reservations/wordpress-five-star-restaurant-reservations-plugin-2-6-16-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-992x-5q5j-jmp5/GHSA-992x-5q5j-jmp5.json b/advisories/unreviewed/2024/04/GHSA-992x-5q5j-jmp5/GHSA-992x-5q5j-jmp5.json new file mode 100644 index 00000000000..bdb4340f747 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-992x-5q5j-jmp5/GHSA-992x-5q5j-jmp5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-992x-5q5j-jmp5", + "modified": "2024-04-29T09:31:52Z", + "published": "2024-04-29T09:31:52Z", + "aliases": [ + "CVE-2024-33538" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Fastline Media LLC Assistant – Every Day Productivity Apps.This issue affects Assistant – Every Day Productivity Apps: from n/a through 1.4.9.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33538" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/assistant/wordpress-assistant-every-day-productivity-apps-plugin-1-4-9-1-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T08:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-994v-8mpg-9f54/GHSA-994v-8mpg-9f54.json b/advisories/unreviewed/2024/04/GHSA-994v-8mpg-9f54/GHSA-994v-8mpg-9f54.json new file mode 100644 index 00000000000..bfb4b8f0006 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-994v-8mpg-9f54/GHSA-994v-8mpg-9f54.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-994v-8mpg-9f54", + "modified": "2024-04-29T09:31:52Z", + "published": "2024-04-29T09:31:52Z", + "aliases": [ + "CVE-2024-33584" + ], + "details": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Deepen Bajracharya Video Conferencing with Zoom.This issue affects Video Conferencing with Zoom: from n/a through 4.4.4.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33584" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/video-conferencing-with-zoom-api/wordpress-video-conferencing-with-zoom-plugin-4-4-4-open-redirection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T08:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-9xqh-c85q-wvfr/GHSA-9xqh-c85q-wvfr.json b/advisories/unreviewed/2024/04/GHSA-9xqh-c85q-wvfr/GHSA-9xqh-c85q-wvfr.json new file mode 100644 index 00000000000..d6b02bd5698 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-9xqh-c85q-wvfr/GHSA-9xqh-c85q-wvfr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9xqh-c85q-wvfr", + "modified": "2024-04-29T09:31:52Z", + "published": "2024-04-29T09:31:52Z", + "aliases": [ + "CVE-2024-33546" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team WZone allows SQL Injection.This issue affects WZone: from n/a through 14.0.10.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33546" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/woozone/wordpress-wzone-plugin-14-0-10-arbitrary-sql-update-execution-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T07:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-c63r-p9j6-xm6r/GHSA-c63r-p9j6-xm6r.json b/advisories/unreviewed/2024/04/GHSA-c63r-p9j6-xm6r/GHSA-c63r-p9j6-xm6r.json new file mode 100644 index 00000000000..e6978a6962c --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-c63r-p9j6-xm6r/GHSA-c63r-p9j6-xm6r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c63r-p9j6-xm6r", + "modified": "2024-04-29T09:31:53Z", + "published": "2024-04-29T09:31:53Z", + "aliases": [ + "CVE-2024-33597" + ], + "details": "Missing Authorization vulnerability in ProFaceOff SSU.This issue affects SSU: from n/a through 1.5.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33597" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-s3-smart-upload/wordpress-ssu-plugin-1-5-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-fj75-q86h-2r5g/GHSA-fj75-q86h-2r5g.json b/advisories/unreviewed/2024/04/GHSA-fj75-q86h-2r5g/GHSA-fj75-q86h-2r5g.json new file mode 100644 index 00000000000..33f7b44ea28 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-fj75-q86h-2r5g/GHSA-fj75-q86h-2r5g.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fj75-q86h-2r5g", + "modified": "2024-04-29T09:31:52Z", + "published": "2024-04-29T09:31:52Z", + "aliases": [ + "CVE-2024-3195" + ], + "details": "A vulnerability was found in MailCleaner up to 2023.03.14. It has been classified as critical. This affects an unknown part of the component Admin Endpoints. The manipulation leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-262311.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3195" + }, + { + "type": "WEB", + "url": "https://github.com/MailCleaner/MailCleaner/pull/601" + }, + { + "type": "WEB", + "url": "https://modzero.com/en/advisories/mz-24-01-mailcleaner" + }, + { + "type": "WEB", + "url": "https://modzero.com/static/MZ-24-01_modzero_MailCleaner.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.262311" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.262311" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T07:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-fwrh-xmxv-qj39/GHSA-fwrh-xmxv-qj39.json b/advisories/unreviewed/2024/04/GHSA-fwrh-xmxv-qj39/GHSA-fwrh-xmxv-qj39.json new file mode 100644 index 00000000000..6ebbf0cfaaa --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-fwrh-xmxv-qj39/GHSA-fwrh-xmxv-qj39.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fwrh-xmxv-qj39", + "modified": "2024-04-29T09:31:52Z", + "published": "2024-04-29T09:31:52Z", + "aliases": [ + "CVE-2024-33553" + ], + "details": "Deserialization of Untrusted Data vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33553" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/et-core-plugin/wordpress-xstore-core-plugin-5-3-5-unauthenticated-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T08:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-gr5j-xcqm-p2ph/GHSA-gr5j-xcqm-p2ph.json b/advisories/unreviewed/2024/04/GHSA-gr5j-xcqm-p2ph/GHSA-gr5j-xcqm-p2ph.json new file mode 100644 index 00000000000..dfa73b1c803 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-gr5j-xcqm-p2ph/GHSA-gr5j-xcqm-p2ph.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gr5j-xcqm-p2ph", + "modified": "2024-04-29T09:31:52Z", + "published": "2024-04-29T09:31:52Z", + "aliases": [ + "CVE-2024-33634" + ], + "details": "Server-Side Request Forgery (SSRF) vulnerability in Piotnet Piotnet Addons For Elementor Pro.This issue affects Piotnet Addons For Elementor Pro: from n/a through 7.1.17.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33634" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/piotnet-addons-for-elementor-pro/wordpress-piotnet-addons-for-elementor-pro-plugin-7-1-17-unauthenticated-server-side-request-forgery-ssrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T08:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-gv7p-f5gp-mj9q/GHSA-gv7p-f5gp-mj9q.json b/advisories/unreviewed/2024/04/GHSA-gv7p-f5gp-mj9q/GHSA-gv7p-f5gp-mj9q.json new file mode 100644 index 00000000000..cd020184394 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-gv7p-f5gp-mj9q/GHSA-gv7p-f5gp-mj9q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gv7p-f5gp-mj9q", + "modified": "2024-04-29T09:31:53Z", + "published": "2024-04-29T09:31:52Z", + "aliases": [ + "CVE-2024-33558" + ], + "details": "Missing Authorization vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33558" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/et-core-plugin/wordpress-xstore-core-plugin-5-3-5-limited-arbitrary-file-download-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T09:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-j3xx-xw6j-f8q3/GHSA-j3xx-xw6j-f8q3.json b/advisories/unreviewed/2024/04/GHSA-j3xx-xw6j-f8q3/GHSA-j3xx-xw6j-f8q3.json new file mode 100644 index 00000000000..74198c3cc25 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-j3xx-xw6j-f8q3/GHSA-j3xx-xw6j-f8q3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j3xx-xw6j-f8q3", + "modified": "2024-04-29T09:31:52Z", + "published": "2024-04-29T09:31:52Z", + "aliases": [ + "CVE-2024-33566" + ], + "details": "Missing Authorization vulnerability in N-Media OrderConvo allows OS Command Injection.This issue affects OrderConvo: from n/a through 12.4.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33566" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/admin-and-client-message-after-order-for-woocommerce/wordpress-orderconvo-plugin-12-4-unauthenticated-api-access-to-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T08:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-j6m3-4fcr-hq62/GHSA-j6m3-4fcr-hq62.json b/advisories/unreviewed/2024/04/GHSA-j6m3-4fcr-hq62/GHSA-j6m3-4fcr-hq62.json new file mode 100644 index 00000000000..c526b0d3452 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-j6m3-4fcr-hq62/GHSA-j6m3-4fcr-hq62.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6m3-4fcr-hq62", + "modified": "2024-04-29T09:31:53Z", + "published": "2024-04-29T09:31:53Z", + "aliases": [ + "CVE-2024-33636" + ], + "details": "Missing Authorization vulnerability in Mahesh Vora WP Page Post Widget Clone.This issue affects WP Page Post Widget Clone: from n/a through 1.0.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33636" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-page-post-widget-clone/wordpress-wp-page-post-widget-clone-plugin-1-0-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-mp8f-xwf5-rv6v/GHSA-mp8f-xwf5-rv6v.json b/advisories/unreviewed/2024/04/GHSA-mp8f-xwf5-rv6v/GHSA-mp8f-xwf5-rv6v.json new file mode 100644 index 00000000000..c562616d89f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-mp8f-xwf5-rv6v/GHSA-mp8f-xwf5-rv6v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mp8f-xwf5-rv6v", + "modified": "2024-04-29T09:31:52Z", + "published": "2024-04-29T09:31:52Z", + "aliases": [ + "CVE-2024-33629" + ], + "details": "Server-Side Request Forgery (SSRF) vulnerability in Creative Motion Auto Featured Image (Auto Post Thumbnail).This issue affects Auto Featured Image (Auto Post Thumbnail): from n/a through 4.0.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33629" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/auto-post-thumbnail/wordpress-auto-featured-image-auto-post-thumbnail-plugin-4-0-0-server-side-request-forgery-ssrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T08:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-qqfg-7xr5-8hvg/GHSA-qqfg-7xr5-8hvg.json b/advisories/unreviewed/2024/04/GHSA-qqfg-7xr5-8hvg/GHSA-qqfg-7xr5-8hvg.json new file mode 100644 index 00000000000..460d1492053 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-qqfg-7xr5-8hvg/GHSA-qqfg-7xr5-8hvg.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qqfg-7xr5-8hvg", + "modified": "2024-04-29T09:31:52Z", + "published": "2024-04-29T09:31:52Z", + "aliases": [ + "CVE-2024-3193" + ], + "details": "A vulnerability has been found in MailCleaner up to 2023.03.14 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Admin Endpoints. The manipulation leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The identifier VDB-262309 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3193" + }, + { + "type": "WEB", + "url": "https://github.com/MailCleaner/MailCleaner/pull/601" + }, + { + "type": "WEB", + "url": "https://modzero.com/en/advisories/mz-24-01-mailcleaner" + }, + { + "type": "WEB", + "url": "https://modzero.com/static/MZ-24-01_modzero_MailCleaner.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.262309" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.262309" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T07:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-vfj7-w3gq-g683/GHSA-vfj7-w3gq-g683.json b/advisories/unreviewed/2024/04/GHSA-vfj7-w3gq-g683/GHSA-vfj7-w3gq-g683.json new file mode 100644 index 00000000000..64b4e22c881 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-vfj7-w3gq-g683/GHSA-vfj7-w3gq-g683.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vfj7-w3gq-g683", + "modified": "2024-04-29T09:31:53Z", + "published": "2024-04-29T09:31:53Z", + "aliases": [ + "CVE-2024-33684" + ], + "details": "Missing Authorization vulnerability in Pdfcrowd Save as PDF plugin by Pdfcrowd allows Stored XSS.This issue affects Save as PDF plugin by Pdfcrowd: from n/a through 3.2.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33684" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/save-as-pdf-by-pdfcrowd/wordpress-save-as-pdf-plugin-by-pdfcrowd-plugin-3-2-0-broken-access-control-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-w6gm-jg83-rm6w/GHSA-w6gm-jg83-rm6w.json b/advisories/unreviewed/2024/04/GHSA-w6gm-jg83-rm6w/GHSA-w6gm-jg83-rm6w.json new file mode 100644 index 00000000000..d49dbbaa6e0 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-w6gm-jg83-rm6w/GHSA-w6gm-jg83-rm6w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w6gm-jg83-rm6w", + "modified": "2024-04-29T09:31:52Z", + "published": "2024-04-29T09:31:52Z", + "aliases": [ + "CVE-2024-33544" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team WZone allows SQL Injection.This issue affects WZone: from n/a through 14.0.10.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33544" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/woozone/wordpress-wzone-plugin-14-0-10-unauthenticated-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T07:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-x7gc-r4xg-v7c2/GHSA-x7gc-r4xg-v7c2.json b/advisories/unreviewed/2024/04/GHSA-x7gc-r4xg-v7c2/GHSA-x7gc-r4xg-v7c2.json new file mode 100644 index 00000000000..21f85f6fd47 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-x7gc-r4xg-v7c2/GHSA-x7gc-r4xg-v7c2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x7gc-r4xg-v7c2", + "modified": "2024-04-29T09:31:53Z", + "published": "2024-04-29T09:31:53Z", + "aliases": [ + "CVE-2024-33635" + ], + "details": "Missing Authorization vulnerability in Piotnet Piotnet Addons For Elementor Pro.This issue affects Piotnet Addons For Elementor Pro: from n/a through 7.1.17.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33635" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/piotnet-addons-for-elementor-pro/wordpress-piotnet-addons-for-elementor-pro-plugin-7-1-17-unauthenticated-arbitrary-post-page-deletion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-xmgc-h398-rg8w/GHSA-xmgc-h398-rg8w.json b/advisories/unreviewed/2024/04/GHSA-xmgc-h398-rg8w/GHSA-xmgc-h398-rg8w.json new file mode 100644 index 00000000000..17b7a965839 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-xmgc-h398-rg8w/GHSA-xmgc-h398-rg8w.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xmgc-h398-rg8w", + "modified": "2024-04-29T09:31:52Z", + "published": "2024-04-29T09:31:52Z", + "aliases": [ + "CVE-2024-3192" + ], + "details": "A vulnerability, which was classified as problematic, was found in MailCleaner up to 2023.03.14. Affected is an unknown function of the component Admin Interface. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-262308.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3192" + }, + { + "type": "WEB", + "url": "https://github.com/MailCleaner/MailCleaner/pull/601" + }, + { + "type": "WEB", + "url": "https://modzero.com/en/advisories/mz-24-01-mailcleaner" + }, + { + "type": "WEB", + "url": "https://modzero.com/static/MZ-24-01_modzero_MailCleaner.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.262308" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.262308" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T07:15:07Z" + } +} \ No newline at end of file