From fec948a9e818e5a719d084f2e000ff384919112d Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 29 Mar 2024 15:31:53 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-rggv-cv7r-mw98.json | 6 +- .../GHSA-3q5r-g7hx-jv3c.json | 6 +- .../GHSA-25gv-85m9-qg67.json | 38 ++++++++++++ .../GHSA-2m33-2vvh-2jjh.json | 35 +++++++++++ .../GHSA-2mw2-pgcq-48mv.json | 35 +++++++++++ .../GHSA-327x-6c4p-8g25.json | 38 ++++++++++++ .../GHSA-32ch-6x54-q4h9.json | 6 +- .../GHSA-35gq-67f6-phh5.json | 38 ++++++++++++ .../GHSA-3cp6-m65f-qhcw.json | 43 ++++++++++++++ .../GHSA-3q2c-pvp5-3cqp.json | 6 +- .../GHSA-3q4w-x69r-v77m.json | 35 +++++++++++ .../GHSA-3rwq-vmr7-cggq.json | 35 +++++++++++ .../GHSA-3v5f-9v4j-m9m3.json | 35 +++++++++++ .../GHSA-3vxf-c798-m86j.json | 38 ++++++++++++ .../GHSA-4jhg-h526-7c6c.json | 38 ++++++++++++ .../GHSA-4pv2-2786-vqxj.json | 38 ++++++++++++ .../GHSA-52mm-25mr-346r.json | 35 +++++++++++ .../GHSA-59hg-3x57-2mwj.json | 38 ++++++++++++ .../GHSA-5gxc-9wh2-99f9.json | 54 +++++++++++++++++ .../GHSA-5jvh-2rg4-779c.json | 38 ++++++++++++ .../GHSA-5v3g-553g-mcmp.json | 35 +++++++++++ .../GHSA-5wqc-p6hx-3xmx.json | 38 ++++++++++++ .../GHSA-626j-hx4w-85m6.json | 35 +++++++++++ .../GHSA-637c-qr5f-c3c8.json | 38 ++++++++++++ .../GHSA-67vq-67qp-cqw3.json | 38 ++++++++++++ .../GHSA-6r3q-8mcr-xqjw.json | 35 +++++++++++ .../GHSA-78f3-c7qw-mjg4.json | 35 +++++++++++ .../GHSA-7hr8-mwm4-3323.json | 39 +++++++++++++ .../GHSA-7r49-q3rj-9q6c.json | 38 ++++++++++++ .../GHSA-8j8v-w647-795g.json | 35 +++++++++++ .../GHSA-8vhr-7rgv-5fc9.json | 2 +- .../GHSA-93v4-m245-8mrg.json | 38 ++++++++++++ .../GHSA-9gfr-w8rg-7vc8.json | 38 ++++++++++++ .../GHSA-9pvw-c3qw-6hwh.json | 38 ++++++++++++ .../GHSA-9qhm-743f-cwmp.json | 38 ++++++++++++ .../GHSA-9qr6-r6j4-qfxh.json | 38 ++++++++++++ .../GHSA-cg9v-63jx-v8q2.json | 38 ++++++++++++ .../GHSA-f37h-g74v-g4mp.json | 38 ++++++++++++ .../GHSA-fc9p-94fp-8jcw.json | 38 ++++++++++++ .../GHSA-fgq5-q76c-gx78.json | 6 +- .../GHSA-frh3-73v3-rg46.json | 38 ++++++++++++ .../GHSA-fw8f-f5ww-mpr8.json | 35 +++++++++++ .../GHSA-g692-j8f5-g9xf.json | 35 +++++++++++ .../GHSA-g6j9-fwc6-jmgq.json | 38 ++++++++++++ .../GHSA-gvf4-7544-2wh5.json | 35 +++++++++++ .../GHSA-j65j-7f2j-mh39.json | 35 +++++++++++ .../GHSA-j6m3-gc37-6r6q.json | 6 +- .../GHSA-j9x8-g52g-pq89.json | 38 ++++++++++++ .../GHSA-jr6v-9h7h-qrjx.json | 35 +++++++++++ .../GHSA-jr8p-29pq-j5wf.json | 38 ++++++++++++ .../GHSA-mqch-c6jh-g9xj.json | 38 ++++++++++++ .../GHSA-mw2p-r2fm-9p6g.json | 38 ++++++++++++ .../GHSA-mw2v-7qj3-3qrq.json | 38 ++++++++++++ .../GHSA-p2c5-vphq-jrxg.json | 38 ++++++++++++ .../GHSA-p2vw-f9rr-2m2r.json | 42 ++++++++++++++ .../GHSA-p9gp-6wp2-9v5c.json | 38 ++++++++++++ .../GHSA-pg97-9w9c-rx2j.json | 38 ++++++++++++ .../GHSA-pprg-rj4x-j7w4.json | 58 +++++++++++++++++++ .../GHSA-q3m8-4vff-qr66.json | 38 ++++++++++++ .../GHSA-q766-xpmm-4999.json | 38 ++++++++++++ .../GHSA-qxgj-php7-wrw3.json | 38 ++++++++++++ .../GHSA-r2xx-gprx-q489.json | 38 ++++++++++++ .../GHSA-rr6r-cfgf-gc6h.json | 6 +- .../GHSA-vf75-q6vr-4464.json | 35 +++++++++++ .../GHSA-vrgq-j293-jcx7.json | 38 ++++++++++++ .../GHSA-vxq6-3hh5-mcjj.json | 38 ++++++++++++ .../GHSA-w63w-2c2h-qpxw.json | 35 +++++++++++ .../GHSA-x73g-5x4f-9mqr.json | 42 ++++++++++++++ .../GHSA-x75q-8m6m-8c94.json | 38 ++++++++++++ .../GHSA-xcvp-xvv5-6298.json | 42 ++++++++++++++ .../GHSA-xrjx-pr69-2frv.json | 35 +++++++++++ 71 files changed, 2427 insertions(+), 8 deletions(-) create mode 100644 advisories/unreviewed/2024/03/GHSA-25gv-85m9-qg67/GHSA-25gv-85m9-qg67.json create mode 100644 advisories/unreviewed/2024/03/GHSA-2m33-2vvh-2jjh/GHSA-2m33-2vvh-2jjh.json create mode 100644 advisories/unreviewed/2024/03/GHSA-2mw2-pgcq-48mv/GHSA-2mw2-pgcq-48mv.json create mode 100644 advisories/unreviewed/2024/03/GHSA-327x-6c4p-8g25/GHSA-327x-6c4p-8g25.json create mode 100644 advisories/unreviewed/2024/03/GHSA-35gq-67f6-phh5/GHSA-35gq-67f6-phh5.json create mode 100644 advisories/unreviewed/2024/03/GHSA-3cp6-m65f-qhcw/GHSA-3cp6-m65f-qhcw.json create mode 100644 advisories/unreviewed/2024/03/GHSA-3q4w-x69r-v77m/GHSA-3q4w-x69r-v77m.json create mode 100644 advisories/unreviewed/2024/03/GHSA-3rwq-vmr7-cggq/GHSA-3rwq-vmr7-cggq.json create mode 100644 advisories/unreviewed/2024/03/GHSA-3v5f-9v4j-m9m3/GHSA-3v5f-9v4j-m9m3.json create mode 100644 advisories/unreviewed/2024/03/GHSA-3vxf-c798-m86j/GHSA-3vxf-c798-m86j.json create mode 100644 advisories/unreviewed/2024/03/GHSA-4jhg-h526-7c6c/GHSA-4jhg-h526-7c6c.json create mode 100644 advisories/unreviewed/2024/03/GHSA-4pv2-2786-vqxj/GHSA-4pv2-2786-vqxj.json create mode 100644 advisories/unreviewed/2024/03/GHSA-52mm-25mr-346r/GHSA-52mm-25mr-346r.json create mode 100644 advisories/unreviewed/2024/03/GHSA-59hg-3x57-2mwj/GHSA-59hg-3x57-2mwj.json create mode 100644 advisories/unreviewed/2024/03/GHSA-5gxc-9wh2-99f9/GHSA-5gxc-9wh2-99f9.json create mode 100644 advisories/unreviewed/2024/03/GHSA-5jvh-2rg4-779c/GHSA-5jvh-2rg4-779c.json create mode 100644 advisories/unreviewed/2024/03/GHSA-5v3g-553g-mcmp/GHSA-5v3g-553g-mcmp.json create mode 100644 advisories/unreviewed/2024/03/GHSA-5wqc-p6hx-3xmx/GHSA-5wqc-p6hx-3xmx.json create mode 100644 advisories/unreviewed/2024/03/GHSA-626j-hx4w-85m6/GHSA-626j-hx4w-85m6.json create mode 100644 advisories/unreviewed/2024/03/GHSA-637c-qr5f-c3c8/GHSA-637c-qr5f-c3c8.json create mode 100644 advisories/unreviewed/2024/03/GHSA-67vq-67qp-cqw3/GHSA-67vq-67qp-cqw3.json create mode 100644 advisories/unreviewed/2024/03/GHSA-6r3q-8mcr-xqjw/GHSA-6r3q-8mcr-xqjw.json create mode 100644 advisories/unreviewed/2024/03/GHSA-78f3-c7qw-mjg4/GHSA-78f3-c7qw-mjg4.json create mode 100644 advisories/unreviewed/2024/03/GHSA-7hr8-mwm4-3323/GHSA-7hr8-mwm4-3323.json create mode 100644 advisories/unreviewed/2024/03/GHSA-7r49-q3rj-9q6c/GHSA-7r49-q3rj-9q6c.json create mode 100644 advisories/unreviewed/2024/03/GHSA-8j8v-w647-795g/GHSA-8j8v-w647-795g.json create mode 100644 advisories/unreviewed/2024/03/GHSA-93v4-m245-8mrg/GHSA-93v4-m245-8mrg.json create mode 100644 advisories/unreviewed/2024/03/GHSA-9gfr-w8rg-7vc8/GHSA-9gfr-w8rg-7vc8.json create mode 100644 advisories/unreviewed/2024/03/GHSA-9pvw-c3qw-6hwh/GHSA-9pvw-c3qw-6hwh.json create mode 100644 advisories/unreviewed/2024/03/GHSA-9qhm-743f-cwmp/GHSA-9qhm-743f-cwmp.json create mode 100644 advisories/unreviewed/2024/03/GHSA-9qr6-r6j4-qfxh/GHSA-9qr6-r6j4-qfxh.json create mode 100644 advisories/unreviewed/2024/03/GHSA-cg9v-63jx-v8q2/GHSA-cg9v-63jx-v8q2.json create mode 100644 advisories/unreviewed/2024/03/GHSA-f37h-g74v-g4mp/GHSA-f37h-g74v-g4mp.json create mode 100644 advisories/unreviewed/2024/03/GHSA-fc9p-94fp-8jcw/GHSA-fc9p-94fp-8jcw.json create mode 100644 advisories/unreviewed/2024/03/GHSA-frh3-73v3-rg46/GHSA-frh3-73v3-rg46.json create mode 100644 advisories/unreviewed/2024/03/GHSA-fw8f-f5ww-mpr8/GHSA-fw8f-f5ww-mpr8.json create mode 100644 advisories/unreviewed/2024/03/GHSA-g692-j8f5-g9xf/GHSA-g692-j8f5-g9xf.json create mode 100644 advisories/unreviewed/2024/03/GHSA-g6j9-fwc6-jmgq/GHSA-g6j9-fwc6-jmgq.json create mode 100644 advisories/unreviewed/2024/03/GHSA-gvf4-7544-2wh5/GHSA-gvf4-7544-2wh5.json create mode 100644 advisories/unreviewed/2024/03/GHSA-j65j-7f2j-mh39/GHSA-j65j-7f2j-mh39.json create mode 100644 advisories/unreviewed/2024/03/GHSA-j9x8-g52g-pq89/GHSA-j9x8-g52g-pq89.json create mode 100644 advisories/unreviewed/2024/03/GHSA-jr6v-9h7h-qrjx/GHSA-jr6v-9h7h-qrjx.json create mode 100644 advisories/unreviewed/2024/03/GHSA-jr8p-29pq-j5wf/GHSA-jr8p-29pq-j5wf.json create mode 100644 advisories/unreviewed/2024/03/GHSA-mqch-c6jh-g9xj/GHSA-mqch-c6jh-g9xj.json create mode 100644 advisories/unreviewed/2024/03/GHSA-mw2p-r2fm-9p6g/GHSA-mw2p-r2fm-9p6g.json create mode 100644 advisories/unreviewed/2024/03/GHSA-mw2v-7qj3-3qrq/GHSA-mw2v-7qj3-3qrq.json create mode 100644 advisories/unreviewed/2024/03/GHSA-p2c5-vphq-jrxg/GHSA-p2c5-vphq-jrxg.json create mode 100644 advisories/unreviewed/2024/03/GHSA-p2vw-f9rr-2m2r/GHSA-p2vw-f9rr-2m2r.json create mode 100644 advisories/unreviewed/2024/03/GHSA-p9gp-6wp2-9v5c/GHSA-p9gp-6wp2-9v5c.json create mode 100644 advisories/unreviewed/2024/03/GHSA-pg97-9w9c-rx2j/GHSA-pg97-9w9c-rx2j.json create mode 100644 advisories/unreviewed/2024/03/GHSA-pprg-rj4x-j7w4/GHSA-pprg-rj4x-j7w4.json create mode 100644 advisories/unreviewed/2024/03/GHSA-q3m8-4vff-qr66/GHSA-q3m8-4vff-qr66.json create mode 100644 advisories/unreviewed/2024/03/GHSA-q766-xpmm-4999/GHSA-q766-xpmm-4999.json create mode 100644 advisories/unreviewed/2024/03/GHSA-qxgj-php7-wrw3/GHSA-qxgj-php7-wrw3.json create mode 100644 advisories/unreviewed/2024/03/GHSA-r2xx-gprx-q489/GHSA-r2xx-gprx-q489.json create mode 100644 advisories/unreviewed/2024/03/GHSA-vf75-q6vr-4464/GHSA-vf75-q6vr-4464.json create mode 100644 advisories/unreviewed/2024/03/GHSA-vrgq-j293-jcx7/GHSA-vrgq-j293-jcx7.json create mode 100644 advisories/unreviewed/2024/03/GHSA-vxq6-3hh5-mcjj/GHSA-vxq6-3hh5-mcjj.json create mode 100644 advisories/unreviewed/2024/03/GHSA-w63w-2c2h-qpxw/GHSA-w63w-2c2h-qpxw.json create mode 100644 advisories/unreviewed/2024/03/GHSA-x73g-5x4f-9mqr/GHSA-x73g-5x4f-9mqr.json create mode 100644 advisories/unreviewed/2024/03/GHSA-x75q-8m6m-8c94/GHSA-x75q-8m6m-8c94.json create mode 100644 advisories/unreviewed/2024/03/GHSA-xcvp-xvv5-6298/GHSA-xcvp-xvv5-6298.json create mode 100644 advisories/unreviewed/2024/03/GHSA-xrjx-pr69-2frv/GHSA-xrjx-pr69-2frv.json diff --git a/advisories/github-reviewed/2024/02/GHSA-rggv-cv7r-mw98/GHSA-rggv-cv7r-mw98.json b/advisories/github-reviewed/2024/02/GHSA-rggv-cv7r-mw98/GHSA-rggv-cv7r-mw98.json index d77bf0ed756..936459b5c04 100644 --- a/advisories/github-reviewed/2024/02/GHSA-rggv-cv7r-mw98/GHSA-rggv-cv7r-mw98.json +++ b/advisories/github-reviewed/2024/02/GHSA-rggv-cv7r-mw98/GHSA-rggv-cv7r-mw98.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rggv-cv7r-mw98", - "modified": "2024-02-26T20:13:46Z", + "modified": "2024-03-29T15:30:27Z", "published": "2024-02-26T20:13:46Z", "aliases": [ "CVE-2024-22201" @@ -198,6 +198,10 @@ { "type": "PACKAGE", "url": "https://github.com/jetty/jetty.project" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240329-0001" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-3q5r-g7hx-jv3c/GHSA-3q5r-g7hx-jv3c.json b/advisories/unreviewed/2024/02/GHSA-3q5r-g7hx-jv3c/GHSA-3q5r-g7hx-jv3c.json index 376827cfc8c..d03cdf97c66 100644 --- a/advisories/unreviewed/2024/02/GHSA-3q5r-g7hx-jv3c/GHSA-3q5r-g7hx-jv3c.json +++ b/advisories/unreviewed/2024/02/GHSA-3q5r-g7hx-jv3c/GHSA-3q5r-g7hx-jv3c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3q5r-g7hx-jv3c", - "modified": "2024-02-20T03:30:57Z", + "modified": "2024-03-29T15:30:27Z", "published": "2024-02-20T03:30:57Z", "aliases": [ "CVE-2024-21896" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://hackerone.com/reports/2218653" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240329-0002" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/03/GHSA-25gv-85m9-qg67/GHSA-25gv-85m9-qg67.json b/advisories/unreviewed/2024/03/GHSA-25gv-85m9-qg67/GHSA-25gv-85m9-qg67.json new file mode 100644 index 00000000000..e6ad89f7bb5 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-25gv-85m9-qg67/GHSA-25gv-85m9-qg67.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-25gv-85m9-qg67", + "modified": "2024-03-29T15:30:28Z", + "published": "2024-03-29T15:30:28Z", + "aliases": [ + "CVE-2024-30457" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF).This issue affects WordPress Meta Data and Taxonomies Filter (MDTF): from n/a through 1.3.3.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30457" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-meta-data-filter-and-taxonomy-filter/wordpress-mdtf-plugin-1-3-3-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T13:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-2m33-2vvh-2jjh/GHSA-2m33-2vvh-2jjh.json b/advisories/unreviewed/2024/03/GHSA-2m33-2vvh-2jjh/GHSA-2m33-2vvh-2jjh.json new file mode 100644 index 00000000000..64062d9f0ec --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-2m33-2vvh-2jjh/GHSA-2m33-2vvh-2jjh.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2m33-2vvh-2jjh", + "modified": "2024-03-29T15:30:32Z", + "published": "2024-03-29T15:30:32Z", + "aliases": [ + "CVE-2024-30639" + ], + "details": "Tenda F1202 v1.2.0.20(408) has a stack overflow vulnerability in the page parameter of fromAddressNat function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30639" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/F/F1202/fromAddressNat_page.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T14:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-2mw2-pgcq-48mv/GHSA-2mw2-pgcq-48mv.json b/advisories/unreviewed/2024/03/GHSA-2mw2-pgcq-48mv/GHSA-2mw2-pgcq-48mv.json new file mode 100644 index 00000000000..9ca4a3f7f70 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-2mw2-pgcq-48mv/GHSA-2mw2-pgcq-48mv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2mw2-pgcq-48mv", + "modified": "2024-03-29T15:30:30Z", + "published": "2024-03-29T15:30:30Z", + "aliases": [ + "CVE-2024-30629" + ], + "details": "Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the list1 parameter from fromDhcpListClient function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30629" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/FH/FH1205/fromDhcpListClient_list1.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T13:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-327x-6c4p-8g25/GHSA-327x-6c4p-8g25.json b/advisories/unreviewed/2024/03/GHSA-327x-6c4p-8g25/GHSA-327x-6c4p-8g25.json new file mode 100644 index 00000000000..1863e2f06ba --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-327x-6c4p-8g25/GHSA-327x-6c4p-8g25.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-327x-6c4p-8g25", + "modified": "2024-03-29T15:30:28Z", + "published": "2024-03-29T15:30:28Z", + "aliases": [ + "CVE-2024-30503" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EverPress Mailster allows Reflected XSS.This issue affects Mailster: from n/a through 4.0.6.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30503" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/mailster/wordpress-mailster-plugin-4-0-6-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T13:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-32ch-6x54-q4h9/GHSA-32ch-6x54-q4h9.json b/advisories/unreviewed/2024/03/GHSA-32ch-6x54-q4h9/GHSA-32ch-6x54-q4h9.json index c0d1f18e2ac..4370dc52900 100644 --- a/advisories/unreviewed/2024/03/GHSA-32ch-6x54-q4h9/GHSA-32ch-6x54-q4h9.json +++ b/advisories/unreviewed/2024/03/GHSA-32ch-6x54-q4h9/GHSA-32ch-6x54-q4h9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-32ch-6x54-q4h9", - "modified": "2024-03-06T00:31:26Z", + "modified": "2024-03-29T15:30:27Z", "published": "2024-03-06T00:31:26Z", "aliases": [ "CVE-2023-45289" @@ -33,6 +33,10 @@ { "type": "WEB", "url": "https://pkg.go.dev/vuln/GO-2024-2600" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240329-0006" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/03/GHSA-35gq-67f6-phh5/GHSA-35gq-67f6-phh5.json b/advisories/unreviewed/2024/03/GHSA-35gq-67f6-phh5/GHSA-35gq-67f6-phh5.json new file mode 100644 index 00000000000..aa72896032c --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-35gq-67f6-phh5/GHSA-35gq-67f6-phh5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-35gq-67f6-phh5", + "modified": "2024-03-29T15:30:33Z", + "published": "2024-03-29T15:30:33Z", + "aliases": [ + "CVE-2024-30508" + ], + "details": "Missing Authorization vulnerability in ThimPress WP Hotel Booking.This issue affects WP Hotel Booking: from n/a through 2.0.9.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30508" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-hotel-booking/wordpress-wp-hotel-booking-plugin-2-0-9-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-3cp6-m65f-qhcw/GHSA-3cp6-m65f-qhcw.json b/advisories/unreviewed/2024/03/GHSA-3cp6-m65f-qhcw/GHSA-3cp6-m65f-qhcw.json new file mode 100644 index 00000000000..95772abb7d7 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-3cp6-m65f-qhcw/GHSA-3cp6-m65f-qhcw.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3cp6-m65f-qhcw", + "modified": "2024-03-29T15:30:32Z", + "published": "2024-03-29T15:30:32Z", + "aliases": [ + "CVE-2024-27619" + ], + "details": "Dlink Dir-3040us A1 1.20b03a hotfix is vulnerable to Buffer Overflow. Any user having read/write access to ftp server can write directly to ram causing buffer overflow if file or files uploaded are greater than available ram. Ftp server allows change of directory to root which is one level up than root of usb flash directory. During upload ram is getting filled and causing system resource exhaustion (no free memory) which causes system to crash and reboot.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27619" + }, + { + "type": "WEB", + "url": "https://github.com/ioprojecton/dir-3040_dos" + }, + { + "type": "WEB", + "url": "https://www.dlink.com/en/security-bulletin" + }, + { + "type": "WEB", + "url": "http://dir-3040us.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-3q2c-pvp5-3cqp/GHSA-3q2c-pvp5-3cqp.json b/advisories/unreviewed/2024/03/GHSA-3q2c-pvp5-3cqp/GHSA-3q2c-pvp5-3cqp.json index 4d4ff444a18..cb3c7ea7e29 100644 --- a/advisories/unreviewed/2024/03/GHSA-3q2c-pvp5-3cqp/GHSA-3q2c-pvp5-3cqp.json +++ b/advisories/unreviewed/2024/03/GHSA-3q2c-pvp5-3cqp/GHSA-3q2c-pvp5-3cqp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3q2c-pvp5-3cqp", - "modified": "2024-03-06T00:31:26Z", + "modified": "2024-03-29T15:30:28Z", "published": "2024-03-06T00:31:26Z", "aliases": [ "CVE-2024-24783" @@ -33,6 +33,10 @@ { "type": "WEB", "url": "https://pkg.go.dev/vuln/GO-2024-2598" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240329-0005" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/03/GHSA-3q4w-x69r-v77m/GHSA-3q4w-x69r-v77m.json b/advisories/unreviewed/2024/03/GHSA-3q4w-x69r-v77m/GHSA-3q4w-x69r-v77m.json new file mode 100644 index 00000000000..df3a9f8fb51 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-3q4w-x69r-v77m/GHSA-3q4w-x69r-v77m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3q4w-x69r-v77m", + "modified": "2024-03-29T15:30:32Z", + "published": "2024-03-29T15:30:32Z", + "aliases": [ + "CVE-2024-30638" + ], + "details": "Tenda F1202 v1.2.0.20(408) has a stack overflow vulnerability via the entrys parameter in the fromAddressNat function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30638" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/F/F1202/fromAddressNat_entrys.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T14:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-3rwq-vmr7-cggq/GHSA-3rwq-vmr7-cggq.json b/advisories/unreviewed/2024/03/GHSA-3rwq-vmr7-cggq/GHSA-3rwq-vmr7-cggq.json new file mode 100644 index 00000000000..8dc8dd64f0d --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-3rwq-vmr7-cggq/GHSA-3rwq-vmr7-cggq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3rwq-vmr7-cggq", + "modified": "2024-03-29T15:30:32Z", + "published": "2024-03-29T15:30:32Z", + "aliases": [ + "CVE-2024-30636" + ], + "details": "Tenda F1202 v1.2.0.20(408) has a stack overflow vulnerability via the PPPOEPassword parameter in the formQuickIndex function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30636" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/F/F1202/formQuickIndex.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T14:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-3v5f-9v4j-m9m3/GHSA-3v5f-9v4j-m9m3.json b/advisories/unreviewed/2024/03/GHSA-3v5f-9v4j-m9m3/GHSA-3v5f-9v4j-m9m3.json new file mode 100644 index 00000000000..e65ee3ee81b --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-3v5f-9v4j-m9m3/GHSA-3v5f-9v4j-m9m3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3v5f-9v4j-m9m3", + "modified": "2024-03-29T15:30:29Z", + "published": "2024-03-29T15:30:29Z", + "aliases": [ + "CVE-2024-30624" + ], + "details": "Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the urls parameter from saveParentControlInfo function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30624" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/FH/FH1205/saveParentControlInfo_urls.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T13:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-3vxf-c798-m86j/GHSA-3vxf-c798-m86j.json b/advisories/unreviewed/2024/03/GHSA-3vxf-c798-m86j/GHSA-3vxf-c798-m86j.json new file mode 100644 index 00000000000..e8ae637fcf4 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-3vxf-c798-m86j/GHSA-3vxf-c798-m86j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3vxf-c798-m86j", + "modified": "2024-03-29T15:30:32Z", + "published": "2024-03-29T15:30:32Z", + "aliases": [ + "CVE-2024-30510" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Salon Booking System Salon booking system.This issue affects Salon booking system: from n/a through 9.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30510" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/salon-booking-system/wordpress-salon-booking-system-plugin-9-5-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T14:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-4jhg-h526-7c6c/GHSA-4jhg-h526-7c6c.json b/advisories/unreviewed/2024/03/GHSA-4jhg-h526-7c6c/GHSA-4jhg-h526-7c6c.json new file mode 100644 index 00000000000..fd92641466e --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-4jhg-h526-7c6c/GHSA-4jhg-h526-7c6c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4jhg-h526-7c6c", + "modified": "2024-03-29T15:30:33Z", + "published": "2024-03-29T15:30:33Z", + "aliases": [ + "CVE-2024-30506" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vsourz Digital All In One Redirection allows Stored XSS.This issue affects All In One Redirection: from n/a through 2.2.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30506" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/all-in-one-redirection-404-pages-list/wordpress-all-in-one-redirection-plugin-2-2-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T15:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-4pv2-2786-vqxj/GHSA-4pv2-2786-vqxj.json b/advisories/unreviewed/2024/03/GHSA-4pv2-2786-vqxj/GHSA-4pv2-2786-vqxj.json new file mode 100644 index 00000000000..75b5dc9f7c1 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-4pv2-2786-vqxj/GHSA-4pv2-2786-vqxj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4pv2-2786-vqxj", + "modified": "2024-03-29T15:30:31Z", + "published": "2024-03-29T15:30:31Z", + "aliases": [ + "CVE-2024-30491" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.8.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30491" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/profilegrid-user-profiles-groups-and-communities/wordpress-profilegrid-user-profiles-memberships-groups-and-communities-plugin-5-7-8-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-52mm-25mr-346r/GHSA-52mm-25mr-346r.json b/advisories/unreviewed/2024/03/GHSA-52mm-25mr-346r/GHSA-52mm-25mr-346r.json new file mode 100644 index 00000000000..9c3703eba29 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-52mm-25mr-346r/GHSA-52mm-25mr-346r.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-52mm-25mr-346r", + "modified": "2024-03-29T15:30:31Z", + "published": "2024-03-29T15:30:31Z", + "aliases": [ + "CVE-2024-30632" + ], + "details": "Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the security_5g parameter from formWifiBasicSet function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30632" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/FH/FH1205/formWifiBasicSet_security_5g.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T13:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-59hg-3x57-2mwj/GHSA-59hg-3x57-2mwj.json b/advisories/unreviewed/2024/03/GHSA-59hg-3x57-2mwj/GHSA-59hg-3x57-2mwj.json new file mode 100644 index 00000000000..ad1770397fa --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-59hg-3x57-2mwj/GHSA-59hg-3x57-2mwj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-59hg-3x57-2mwj", + "modified": "2024-03-29T15:30:28Z", + "published": "2024-03-29T15:30:28Z", + "aliases": [ + "CVE-2024-30458" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOOCS – WooCommerce Currency Switcher.This issue affects WOOCS – WooCommerce Currency Switcher: from n/a through 1.4.1.7.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30458" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/woocommerce-currency-switcher/wordpress-fox-currency-switcher-professional-for-woocommerce-plugin-1-4-1-7-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T13:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-5gxc-9wh2-99f9/GHSA-5gxc-9wh2-99f9.json b/advisories/unreviewed/2024/03/GHSA-5gxc-9wh2-99f9/GHSA-5gxc-9wh2-99f9.json new file mode 100644 index 00000000000..cff427abe8a --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-5gxc-9wh2-99f9/GHSA-5gxc-9wh2-99f9.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5gxc-9wh2-99f9", + "modified": "2024-03-29T15:30:31Z", + "published": "2024-03-29T15:30:31Z", + "aliases": [ + "CVE-2024-3078" + ], + "details": "A vulnerability was found in Qdrant up to 1.6.1/1.7.4/1.8.2 and classified as critical. This issue affects some unknown processing of the file lib/collection/src/collection/snapshots.rs of the component Full Snapshot REST API. The manipulation leads to path traversal. Upgrading to version 1.8.3 is able to address this issue. The patch is named 3ab5172e9c8f14fa1f7b24e7147eac74e2412b62. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-258611.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3078" + }, + { + "type": "WEB", + "url": "https://github.com/qdrant/qdrant/pull/3856" + }, + { + "type": "WEB", + "url": "https://github.com/qdrant/qdrant/commit/3ab5172e9c8f14fa1f7b24e7147eac74e2412b62" + }, + { + "type": "WEB", + "url": "https://github.com/qdrant/qdrant/releases/tag/v1.8.3" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.258611" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.258611" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T13:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-5jvh-2rg4-779c/GHSA-5jvh-2rg4-779c.json b/advisories/unreviewed/2024/03/GHSA-5jvh-2rg4-779c/GHSA-5jvh-2rg4-779c.json new file mode 100644 index 00000000000..8f9f2dd6f48 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-5jvh-2rg4-779c/GHSA-5jvh-2rg4-779c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5jvh-2rg4-779c", + "modified": "2024-03-29T15:30:32Z", + "published": "2024-03-29T15:30:32Z", + "aliases": [ + "CVE-2024-30499" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks CRM Perks Forms.This issue affects CRM Perks Forms: from n/a through 1.1.4.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30499" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/crm-perks-forms/wordpress-crm-perks-forms-plugin-1-1-4-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T14:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-5v3g-553g-mcmp/GHSA-5v3g-553g-mcmp.json b/advisories/unreviewed/2024/03/GHSA-5v3g-553g-mcmp/GHSA-5v3g-553g-mcmp.json new file mode 100644 index 00000000000..6c5b3a364ad --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-5v3g-553g-mcmp/GHSA-5v3g-553g-mcmp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5v3g-553g-mcmp", + "modified": "2024-03-29T15:30:31Z", + "published": "2024-03-29T15:30:31Z", + "aliases": [ + "CVE-2024-30630" + ], + "details": "Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the time parameter from saveParentControlInfo function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30630" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/FH/FH1205/saveParentControlInfo_time.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T13:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-5wqc-p6hx-3xmx/GHSA-5wqc-p6hx-3xmx.json b/advisories/unreviewed/2024/03/GHSA-5wqc-p6hx-3xmx/GHSA-5wqc-p6hx-3xmx.json new file mode 100644 index 00000000000..bde43be7dfc --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-5wqc-p6hx-3xmx/GHSA-5wqc-p6hx-3xmx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5wqc-p6hx-3xmx", + "modified": "2024-03-29T15:30:32Z", + "published": "2024-03-29T15:30:32Z", + "aliases": [ + "CVE-2024-30500" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in CubeWP CubeWP – All-in-One Dynamic Content Framework.This issue affects CubeWP – All-in-One Dynamic Content Framework: from n/a through 1.1.12.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30500" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/cubewp-framework/wordpress-cubewp-plugin-1-1-12-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T14:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-626j-hx4w-85m6/GHSA-626j-hx4w-85m6.json b/advisories/unreviewed/2024/03/GHSA-626j-hx4w-85m6/GHSA-626j-hx4w-85m6.json new file mode 100644 index 00000000000..c8a9d0452bc --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-626j-hx4w-85m6/GHSA-626j-hx4w-85m6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-626j-hx4w-85m6", + "modified": "2024-03-29T15:30:30Z", + "published": "2024-03-29T15:30:30Z", + "aliases": [ + "CVE-2024-30627" + ], + "details": "Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the deviceId parameter from saveParentControlInfo function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30627" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/FH/FH1205/saveParentControlInfo_deviceId.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T13:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-637c-qr5f-c3c8/GHSA-637c-qr5f-c3c8.json b/advisories/unreviewed/2024/03/GHSA-637c-qr5f-c3c8/GHSA-637c-qr5f-c3c8.json new file mode 100644 index 00000000000..5969e9da488 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-637c-qr5f-c3c8/GHSA-637c-qr5f-c3c8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-637c-qr5f-c3c8", + "modified": "2024-03-29T15:30:31Z", + "published": "2024-03-29T15:30:31Z", + "aliases": [ + "CVE-2024-30430" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Email Newsletter Team - FluentCRM Fluent CRM allows Stored XSS.This issue affects Fluent CRM: from n/a through 2.8.44.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30430" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/fluent-crm/wordpress-fluentcrm-plugin-2-8-44-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T14:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-67vq-67qp-cqw3/GHSA-67vq-67qp-cqw3.json b/advisories/unreviewed/2024/03/GHSA-67vq-67qp-cqw3/GHSA-67vq-67qp-cqw3.json new file mode 100644 index 00000000000..9a9cb76b5ba --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-67vq-67qp-cqw3/GHSA-67vq-67qp-cqw3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-67vq-67qp-cqw3", + "modified": "2024-03-29T15:30:32Z", + "published": "2024-03-29T15:30:32Z", + "aliases": [ + "CVE-2024-30496" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BdThemes Element Pack Elementor Addons.This issue affects Element Pack Elementor Addons: from n/a through 5.5.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30496" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/bdthemes-element-pack-lite/wordpress-element-pack-lite-plugin-5-5-3-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-6r3q-8mcr-xqjw/GHSA-6r3q-8mcr-xqjw.json b/advisories/unreviewed/2024/03/GHSA-6r3q-8mcr-xqjw/GHSA-6r3q-8mcr-xqjw.json new file mode 100644 index 00000000000..dee9e17eb37 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-6r3q-8mcr-xqjw/GHSA-6r3q-8mcr-xqjw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6r3q-8mcr-xqjw", + "modified": "2024-03-29T15:30:30Z", + "published": "2024-03-29T15:30:30Z", + "aliases": [ + "CVE-2024-30626" + ], + "details": "Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the schedEndTime parameter from setSchedWifi function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30626" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/FH/FH1205/setSchedWifi_end.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T13:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-78f3-c7qw-mjg4/GHSA-78f3-c7qw-mjg4.json b/advisories/unreviewed/2024/03/GHSA-78f3-c7qw-mjg4/GHSA-78f3-c7qw-mjg4.json new file mode 100644 index 00000000000..d7ca0751fe4 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-78f3-c7qw-mjg4/GHSA-78f3-c7qw-mjg4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-78f3-c7qw-mjg4", + "modified": "2024-03-29T15:30:30Z", + "published": "2024-03-29T15:30:30Z", + "aliases": [ + "CVE-2024-30628" + ], + "details": "Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the page parameter from fromAddressNat function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30628" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/FH/FH1205/fromAddressNat_page.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T13:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-7hr8-mwm4-3323/GHSA-7hr8-mwm4-3323.json b/advisories/unreviewed/2024/03/GHSA-7hr8-mwm4-3323/GHSA-7hr8-mwm4-3323.json new file mode 100644 index 00000000000..73967174f91 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-7hr8-mwm4-3323/GHSA-7hr8-mwm4-3323.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7hr8-mwm4-3323", + "modified": "2024-03-29T15:30:32Z", + "published": "2024-03-29T15:30:32Z", + "aliases": [ + "CVE-2024-28405" + ], + "details": "SEMCMS 4.8 is vulnerable to Incorrect Access Control. The code installs SEMCMS_Funtion.php before checking if the admin is a valid user in the admin page because authentication function is called from there, users gain admin privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28405" + }, + { + "type": "WEB", + "url": "https://github.com/turabiaslan/semcms" + }, + { + "type": "WEB", + "url": "https://github.com/turabiaslan/semcms/blob/main/README.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-7r49-q3rj-9q6c/GHSA-7r49-q3rj-9q6c.json b/advisories/unreviewed/2024/03/GHSA-7r49-q3rj-9q6c/GHSA-7r49-q3rj-9q6c.json new file mode 100644 index 00000000000..7140ace6ebd --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-7r49-q3rj-9q6c/GHSA-7r49-q3rj-9q6c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7r49-q3rj-9q6c", + "modified": "2024-03-29T15:30:31Z", + "published": "2024-03-29T15:30:31Z", + "aliases": [ + "CVE-2024-30423" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BetterAddons Better Elementor Addons allows Stored XSS.This issue affects Better Elementor Addons: from n/a through 1.3.7.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30423" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/better-elementor-addons/wordpress-better-elementor-addons-plugin-1-3-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-8j8v-w647-795g/GHSA-8j8v-w647-795g.json b/advisories/unreviewed/2024/03/GHSA-8j8v-w647-795g/GHSA-8j8v-w647-795g.json new file mode 100644 index 00000000000..b72343236f3 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-8j8v-w647-795g/GHSA-8j8v-w647-795g.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8j8v-w647-795g", + "modified": "2024-03-29T15:30:28Z", + "published": "2024-03-29T15:30:28Z", + "aliases": [ + "CVE-2024-30613" + ], + "details": "Tenda AC15 v15.03.05.18 has a stack overflow vulnerability in the time parameter from the setSmartPowerManagement function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30613" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/AC15/V15.03.05.18/setSmartPowerManagement.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T13:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-8vhr-7rgv-5fc9/GHSA-8vhr-7rgv-5fc9.json b/advisories/unreviewed/2024/03/GHSA-8vhr-7rgv-5fc9/GHSA-8vhr-7rgv-5fc9.json index f5cdaa6d8ea..576af96917d 100644 --- a/advisories/unreviewed/2024/03/GHSA-8vhr-7rgv-5fc9/GHSA-8vhr-7rgv-5fc9.json +++ b/advisories/unreviewed/2024/03/GHSA-8vhr-7rgv-5fc9/GHSA-8vhr-7rgv-5fc9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8vhr-7rgv-5fc9", - "modified": "2024-03-29T12:30:41Z", + "modified": "2024-03-29T15:30:28Z", "published": "2024-03-29T12:30:41Z", "aliases": [ "CVE-2023-6047" diff --git a/advisories/unreviewed/2024/03/GHSA-93v4-m245-8mrg/GHSA-93v4-m245-8mrg.json b/advisories/unreviewed/2024/03/GHSA-93v4-m245-8mrg/GHSA-93v4-m245-8mrg.json new file mode 100644 index 00000000000..4b1277e0263 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-93v4-m245-8mrg/GHSA-93v4-m245-8mrg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-93v4-m245-8mrg", + "modified": "2024-03-29T15:30:31Z", + "published": "2024-03-29T15:30:31Z", + "aliases": [ + "CVE-2024-30427" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins Spiffy Calendar allows Reflected XSS.This issue affects Spiffy Calendar: from n/a through 4.9.7.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30427" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/spiffy-calendar/wordpress-spiffy-calendar-plugin-4-9-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-9gfr-w8rg-7vc8/GHSA-9gfr-w8rg-7vc8.json b/advisories/unreviewed/2024/03/GHSA-9gfr-w8rg-7vc8/GHSA-9gfr-w8rg-7vc8.json new file mode 100644 index 00000000000..67be790670d --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-9gfr-w8rg-7vc8/GHSA-9gfr-w8rg-7vc8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9gfr-w8rg-7vc8", + "modified": "2024-03-29T15:30:31Z", + "published": "2024-03-29T15:30:31Z", + "aliases": [ + "CVE-2024-30487" + ], + "details": "Missing Authorization vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 5.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30487" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/mp3-music-player-by-sonaar/wordpress-mp3-audio-player-for-music-radio-podcast-by-sonaar-plugin-5-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T14:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-9pvw-c3qw-6hwh/GHSA-9pvw-c3qw-6hwh.json b/advisories/unreviewed/2024/03/GHSA-9pvw-c3qw-6hwh/GHSA-9pvw-c3qw-6hwh.json new file mode 100644 index 00000000000..f20f90ebe3a --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-9pvw-c3qw-6hwh/GHSA-9pvw-c3qw-6hwh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9pvw-c3qw-6hwh", + "modified": "2024-03-29T15:30:31Z", + "published": "2024-03-29T15:30:31Z", + "aliases": [ + "CVE-2024-30478" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bulletin WordPress Announcement & Notification Banner Plugin – Bulletin.This issue affects WordPress Announcement & Notification Banner Plugin – Bulletin: from n/a through 3.8.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30478" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/bulletin-announcements/wordpress-announcement-notification-banner-bulletin-plugin-3-8-5-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T14:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-9qhm-743f-cwmp/GHSA-9qhm-743f-cwmp.json b/advisories/unreviewed/2024/03/GHSA-9qhm-743f-cwmp/GHSA-9qhm-743f-cwmp.json new file mode 100644 index 00000000000..f65fd46bf6a --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-9qhm-743f-cwmp/GHSA-9qhm-743f-cwmp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qhm-743f-cwmp", + "modified": "2024-03-29T15:30:33Z", + "published": "2024-03-29T15:30:33Z", + "aliases": [ + "CVE-2024-30502" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel Engine.This issue affects WP Travel Engine: from n/a through 5.7.9.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30502" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-travel-engine/wordpress-wp-travel-engine-plugin-5-7-9-unauth-blind-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T15:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-9qr6-r6j4-qfxh/GHSA-9qr6-r6j4-qfxh.json b/advisories/unreviewed/2024/03/GHSA-9qr6-r6j4-qfxh/GHSA-9qr6-r6j4-qfxh.json new file mode 100644 index 00000000000..14feaa51176 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-9qr6-r6j4-qfxh/GHSA-9qr6-r6j4-qfxh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qr6-r6j4-qfxh", + "modified": "2024-03-29T15:30:28Z", + "published": "2024-03-29T15:30:28Z", + "aliases": [ + "CVE-2024-30456" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WPCS.This issue affects WPCS: from n/a through 1.2.0.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30456" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/currency-switcher/wordpress-wpcs-wordpress-currency-switcher-professional-plugin-1-2-0-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T13:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-cg9v-63jx-v8q2/GHSA-cg9v-63jx-v8q2.json b/advisories/unreviewed/2024/03/GHSA-cg9v-63jx-v8q2/GHSA-cg9v-63jx-v8q2.json new file mode 100644 index 00000000000..1c4c709286b --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-cg9v-63jx-v8q2/GHSA-cg9v-63jx-v8q2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cg9v-63jx-v8q2", + "modified": "2024-03-29T15:30:31Z", + "published": "2024-03-29T15:30:31Z", + "aliases": [ + "CVE-2024-30425" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in The Beaver Builder Team Beaver Builder allows Stored XSS.This issue affects Beaver Builder: from n/a through 2.7.4.4.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30425" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/beaver-builder-lite-version/wordpress-beaver-builder-wordpress-page-builder-plugin-2-7-4-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-f37h-g74v-g4mp/GHSA-f37h-g74v-g4mp.json b/advisories/unreviewed/2024/03/GHSA-f37h-g74v-g4mp/GHSA-f37h-g74v-g4mp.json new file mode 100644 index 00000000000..2be3bf1d275 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-f37h-g74v-g4mp/GHSA-f37h-g74v-g4mp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f37h-g74v-g4mp", + "modified": "2024-03-29T15:30:31Z", + "published": "2024-03-29T15:30:31Z", + "aliases": [ + "CVE-2024-30486" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Max Foundry Media Library Folders.This issue affects Media Library Folders: from n/a through 8.1.7.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30486" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/media-library-plus/wordpress-media-library-folders-plugin-8-1-7-author-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T14:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-fc9p-94fp-8jcw/GHSA-fc9p-94fp-8jcw.json b/advisories/unreviewed/2024/03/GHSA-fc9p-94fp-8jcw/GHSA-fc9p-94fp-8jcw.json new file mode 100644 index 00000000000..bc2de995569 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-fc9p-94fp-8jcw/GHSA-fc9p-94fp-8jcw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fc9p-94fp-8jcw", + "modified": "2024-03-29T15:30:32Z", + "published": "2024-03-29T15:30:32Z", + "aliases": [ + "CVE-2024-30495" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Faboba Falang multilanguage.This issue affects Falang multilanguage: from n/a through 1.3.47.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30495" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/falang/wordpress-falang-multilanguage-for-wordpress-plugin-1-3-47-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-fgq5-q76c-gx78/GHSA-fgq5-q76c-gx78.json b/advisories/unreviewed/2024/03/GHSA-fgq5-q76c-gx78/GHSA-fgq5-q76c-gx78.json index be5d44a8eb3..ec3e1bbf3a4 100644 --- a/advisories/unreviewed/2024/03/GHSA-fgq5-q76c-gx78/GHSA-fgq5-q76c-gx78.json +++ b/advisories/unreviewed/2024/03/GHSA-fgq5-q76c-gx78/GHSA-fgq5-q76c-gx78.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fgq5-q76c-gx78", - "modified": "2024-03-06T00:31:26Z", + "modified": "2024-03-29T15:30:28Z", "published": "2024-03-06T00:31:26Z", "aliases": [ "CVE-2024-24784" @@ -33,6 +33,10 @@ { "type": "WEB", "url": "https://pkg.go.dev/vuln/GO-2024-2609" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240329-0007" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/03/GHSA-frh3-73v3-rg46/GHSA-frh3-73v3-rg46.json b/advisories/unreviewed/2024/03/GHSA-frh3-73v3-rg46/GHSA-frh3-73v3-rg46.json new file mode 100644 index 00000000000..dad3397a72a --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-frh3-73v3-rg46/GHSA-frh3-73v3-rg46.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-frh3-73v3-rg46", + "modified": "2024-03-29T15:30:31Z", + "published": "2024-03-29T15:30:31Z", + "aliases": [ + "CVE-2024-30426" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HashThemes Hash Elements allows Stored XSS.This issue affects Hash Elements: from n/a through 1.3.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30426" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/hash-elements/wordpress-hash-elements-plugin-1-3-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-fw8f-f5ww-mpr8/GHSA-fw8f-f5ww-mpr8.json b/advisories/unreviewed/2024/03/GHSA-fw8f-f5ww-mpr8/GHSA-fw8f-f5ww-mpr8.json new file mode 100644 index 00000000000..9ff87d9188e --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-fw8f-f5ww-mpr8/GHSA-fw8f-f5ww-mpr8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fw8f-f5ww-mpr8", + "modified": "2024-03-29T15:30:32Z", + "published": "2024-03-29T15:30:32Z", + "aliases": [ + "CVE-2024-30637" + ], + "details": "Tenda F1202 v1.2.0.20(408) has a command injection vulnerablility in the formWriteFacMac function in the mac parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30637" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/F/F1202/formWriteFacMac.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T14:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-g692-j8f5-g9xf/GHSA-g692-j8f5-g9xf.json b/advisories/unreviewed/2024/03/GHSA-g692-j8f5-g9xf/GHSA-g692-j8f5-g9xf.json new file mode 100644 index 00000000000..c1a6e54b9b3 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-g692-j8f5-g9xf/GHSA-g692-j8f5-g9xf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g692-j8f5-g9xf", + "modified": "2024-03-29T15:30:29Z", + "published": "2024-03-29T15:30:29Z", + "aliases": [ + "CVE-2024-30622" + ], + "details": "Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the mitInterface parameter from fromAddressNat function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30622" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/FH/FH1205/fromAddressNat_mitInterface.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T13:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-g6j9-fwc6-jmgq/GHSA-g6j9-fwc6-jmgq.json b/advisories/unreviewed/2024/03/GHSA-g6j9-fwc6-jmgq/GHSA-g6j9-fwc6-jmgq.json new file mode 100644 index 00000000000..b368a71ab69 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-g6j9-fwc6-jmgq/GHSA-g6j9-fwc6-jmgq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g6j9-fwc6-jmgq", + "modified": "2024-03-29T15:30:32Z", + "published": "2024-03-29T15:30:32Z", + "aliases": [ + "CVE-2024-30494" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 沈唁 OSS Aliyun.This issue affects OSS Aliyun: from n/a through 1.4.10.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30494" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/oss-aliyun/wordpress-oss-aliyun-plugin-1-4-10-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-gvf4-7544-2wh5/GHSA-gvf4-7544-2wh5.json b/advisories/unreviewed/2024/03/GHSA-gvf4-7544-2wh5/GHSA-gvf4-7544-2wh5.json new file mode 100644 index 00000000000..44d44f92aea --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-gvf4-7544-2wh5/GHSA-gvf4-7544-2wh5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gvf4-7544-2wh5", + "modified": "2024-03-29T15:30:29Z", + "published": "2024-03-29T15:30:29Z", + "aliases": [ + "CVE-2024-30623" + ], + "details": "Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the page parameter from fromDhcpListClient function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30623" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/FH/FH1205/fromDhcpListClient_page.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T13:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-j65j-7f2j-mh39/GHSA-j65j-7f2j-mh39.json b/advisories/unreviewed/2024/03/GHSA-j65j-7f2j-mh39/GHSA-j65j-7f2j-mh39.json new file mode 100644 index 00000000000..380b878c2c9 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-j65j-7f2j-mh39/GHSA-j65j-7f2j-mh39.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j65j-7f2j-mh39", + "modified": "2024-03-29T15:30:29Z", + "published": "2024-03-29T15:30:29Z", + "aliases": [ + "CVE-2024-30625" + ], + "details": "Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the entrys parameter from fromAddressNat function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30625" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/FH/FH1205/fromAddressNat_entrys.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T13:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-j6m3-gc37-6r6q/GHSA-j6m3-gc37-6r6q.json b/advisories/unreviewed/2024/03/GHSA-j6m3-gc37-6r6q/GHSA-j6m3-gc37-6r6q.json index 67792fac31d..95ac76029f7 100644 --- a/advisories/unreviewed/2024/03/GHSA-j6m3-gc37-6r6q/GHSA-j6m3-gc37-6r6q.json +++ b/advisories/unreviewed/2024/03/GHSA-j6m3-gc37-6r6q/GHSA-j6m3-gc37-6r6q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j6m3-gc37-6r6q", - "modified": "2024-03-06T00:31:27Z", + "modified": "2024-03-29T15:30:28Z", "published": "2024-03-06T00:31:27Z", "aliases": [ "CVE-2024-24785" @@ -33,6 +33,10 @@ { "type": "WEB", "url": "https://pkg.go.dev/vuln/GO-2024-2610" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240329-0008" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/03/GHSA-j9x8-g52g-pq89/GHSA-j9x8-g52g-pq89.json b/advisories/unreviewed/2024/03/GHSA-j9x8-g52g-pq89/GHSA-j9x8-g52g-pq89.json new file mode 100644 index 00000000000..8047c013807 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-j9x8-g52g-pq89/GHSA-j9x8-g52g-pq89.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j9x8-g52g-pq89", + "modified": "2024-03-29T15:30:31Z", + "published": "2024-03-29T15:30:31Z", + "aliases": [ + "CVE-2024-30490" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.8.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30490" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/profilegrid-user-profiles-groups-and-communities/wordpress-profilegrid-plugin-5-7-8-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-jr6v-9h7h-qrjx/GHSA-jr6v-9h7h-qrjx.json b/advisories/unreviewed/2024/03/GHSA-jr6v-9h7h-qrjx/GHSA-jr6v-9h7h-qrjx.json new file mode 100644 index 00000000000..9c3c248afe8 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-jr6v-9h7h-qrjx/GHSA-jr6v-9h7h-qrjx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jr6v-9h7h-qrjx", + "modified": "2024-03-29T15:30:32Z", + "published": "2024-03-29T15:30:32Z", + "aliases": [ + "CVE-2024-30635" + ], + "details": "Tenda F1202 v1.2.0.20(408) has a stack overflow vulnerability located in the funcpara1 parameter in the formSetCfm function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30635" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/F/F1202/formSetCfm.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T14:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-jr8p-29pq-j5wf/GHSA-jr8p-29pq-j5wf.json b/advisories/unreviewed/2024/03/GHSA-jr8p-29pq-j5wf/GHSA-jr8p-29pq-j5wf.json new file mode 100644 index 00000000000..43ba16d863e --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-jr8p-29pq-j5wf/GHSA-jr8p-29pq-j5wf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jr8p-29pq-j5wf", + "modified": "2024-03-29T15:30:28Z", + "published": "2024-03-29T15:30:28Z", + "aliases": [ + "CVE-2024-30520" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Labib Ahmed Carousel Anything For WPBakery Page Builder allows Stored XSS.This issue affects Carousel Anything For WPBakery Page Builder: from n/a through 2.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30520" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/carousel-anything/wordpress-carousel-anything-for-wpbakery-page-builder-plugin-2-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T13:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-mqch-c6jh-g9xj/GHSA-mqch-c6jh-g9xj.json b/advisories/unreviewed/2024/03/GHSA-mqch-c6jh-g9xj/GHSA-mqch-c6jh-g9xj.json new file mode 100644 index 00000000000..0a97265f939 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-mqch-c6jh-g9xj/GHSA-mqch-c6jh-g9xj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mqch-c6jh-g9xj", + "modified": "2024-03-29T15:30:32Z", + "published": "2024-03-29T15:30:32Z", + "aliases": [ + "CVE-2024-30497" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in I Thirteen Web Solution WP Responsive Tabs horizontal vertical and accordion Tabs.This issue affects WP Responsive Tabs horizontal vertical and accordion Tabs: from n/a through 1.1.17.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30497" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/responsive-horizontal-vertical-and-accordion-tabs/wordpress-wp-responsive-tabs-horizontal-vertical-and-accordion-tabs-plugin-1-1-17-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-mw2p-r2fm-9p6g/GHSA-mw2p-r2fm-9p6g.json b/advisories/unreviewed/2024/03/GHSA-mw2p-r2fm-9p6g/GHSA-mw2p-r2fm-9p6g.json new file mode 100644 index 00000000000..b7b3d6a9c53 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-mw2p-r2fm-9p6g/GHSA-mw2p-r2fm-9p6g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mw2p-r2fm-9p6g", + "modified": "2024-03-29T15:30:32Z", + "published": "2024-03-29T15:30:32Z", + "aliases": [ + "CVE-2024-30501" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.9.4.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30501" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/download-monitor/wordpress-download-monitor-theme-4-9-4-admin-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T14:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-mw2v-7qj3-3qrq/GHSA-mw2v-7qj3-3qrq.json b/advisories/unreviewed/2024/03/GHSA-mw2v-7qj3-3qrq/GHSA-mw2v-7qj3-3qrq.json new file mode 100644 index 00000000000..a82208f4e18 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-mw2v-7qj3-3qrq/GHSA-mw2v-7qj3-3qrq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mw2v-7qj3-3qrq", + "modified": "2024-03-29T15:30:31Z", + "published": "2024-03-29T15:30:31Z", + "aliases": [ + "CVE-2024-30428" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Contest Gallery allows Reflected XSS.This issue affects Contest Gallery: from n/a through 21.3.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30428" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/contest-gallery/wordpress-contest-gallery-plugin-21-3-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-p2c5-vphq-jrxg/GHSA-p2c5-vphq-jrxg.json b/advisories/unreviewed/2024/03/GHSA-p2c5-vphq-jrxg/GHSA-p2c5-vphq-jrxg.json new file mode 100644 index 00000000000..d0993c85fae --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-p2c5-vphq-jrxg/GHSA-p2c5-vphq-jrxg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p2c5-vphq-jrxg", + "modified": "2024-03-29T15:30:31Z", + "published": "2024-03-29T15:30:31Z", + "aliases": [ + "CVE-2024-30488" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Katie Seaborn Zotpress.This issue affects Zotpress: from n/a through 7.3.7.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30488" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/zotpress/wordpress-zotpress-plugin-7-3-7-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-p2vw-f9rr-2m2r/GHSA-p2vw-f9rr-2m2r.json b/advisories/unreviewed/2024/03/GHSA-p2vw-f9rr-2m2r/GHSA-p2vw-f9rr-2m2r.json new file mode 100644 index 00000000000..abdfaa0fe54 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-p2vw-f9rr-2m2r/GHSA-p2vw-f9rr-2m2r.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p2vw-f9rr-2m2r", + "modified": "2024-03-29T15:30:32Z", + "published": "2024-03-29T15:30:32Z", + "aliases": [ + "CVE-2024-23539" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5.\n\nUsers are recommended to upgrade to version 1.8.5 or 1.9.0, which fix the issue.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23539" + }, + { + "type": "WEB", + "url": "https://cwiki.apache.org/confluence/display/FINERACT/Apache+Fineract+Security+Report" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/g8sv1gnjv716lx2h89jbvjdgtrrjmy7h" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-p9gp-6wp2-9v5c/GHSA-p9gp-6wp2-9v5c.json b/advisories/unreviewed/2024/03/GHSA-p9gp-6wp2-9v5c/GHSA-p9gp-6wp2-9v5c.json new file mode 100644 index 00000000000..8c8b04b7438 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-p9gp-6wp2-9v5c/GHSA-p9gp-6wp2-9v5c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p9gp-6wp2-9v5c", + "modified": "2024-03-29T15:30:33Z", + "published": "2024-03-29T15:30:33Z", + "aliases": [ + "CVE-2024-30505" + ], + "details": "Missing Authorization vulnerability in Andy Moyle Church Admin.This issue affects Church Admin: from n/a through 4.1.18.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30505" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/church-admin/wordpress-church-admin-plugin-4-1-18-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T15:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-pg97-9w9c-rx2j/GHSA-pg97-9w9c-rx2j.json b/advisories/unreviewed/2024/03/GHSA-pg97-9w9c-rx2j/GHSA-pg97-9w9c-rx2j.json new file mode 100644 index 00000000000..8d51b61c271 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-pg97-9w9c-rx2j/GHSA-pg97-9w9c-rx2j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pg97-9w9c-rx2j", + "modified": "2024-03-29T15:30:31Z", + "published": "2024-03-29T15:30:31Z", + "aliases": [ + "CVE-2022-47153" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPJobBoard Jobeleon Theme allows Reflected XSS.This issue affects Jobeleon Theme: from n/a through 1.9.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47153" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/jobeleon-wpjobboard/wordpress-jobeleon-theme-1-9-1-cross-site-scripting-xss?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-pprg-rj4x-j7w4/GHSA-pprg-rj4x-j7w4.json b/advisories/unreviewed/2024/03/GHSA-pprg-rj4x-j7w4/GHSA-pprg-rj4x-j7w4.json new file mode 100644 index 00000000000..0c64c20e821 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-pprg-rj4x-j7w4/GHSA-pprg-rj4x-j7w4.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pprg-rj4x-j7w4", + "modified": "2024-03-29T15:30:33Z", + "published": "2024-03-29T15:30:33Z", + "aliases": [ + "CVE-2024-3081" + ], + "details": "A vulnerability was found in EasyCorp EasyAdmin up to 4.8.9. It has been declared as problematic. Affected by this vulnerability is the function Autocomplete of the file assets/js/autocomplete.js of the component Autocomplete. The manipulation of the argument item leads to cross site scripting. The attack can be launched remotely. Upgrading to version 4.8.10 is able to address this issue. The identifier of the patch is 127436e4c3f56276d548070f99e61b7234200a11. It is recommended to upgrade the affected component. The identifier VDB-258613 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3081" + }, + { + "type": "WEB", + "url": "https://github.com/EasyCorp/EasyAdminBundle/pull/5971" + }, + { + "type": "WEB", + "url": "https://github.com/EasyCorp/EasyAdminBundle/pull/6067" + }, + { + "type": "WEB", + "url": "https://github.com/EasyCorp/EasyAdminBundle/commit/127436e4c3f56276d548070f99e61b7234200a11" + }, + { + "type": "WEB", + "url": "https://github.com/EasyCorp/EasyAdminBundle/releases/tag/v4.8.10" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.258613" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.258613" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-q3m8-4vff-qr66/GHSA-q3m8-4vff-qr66.json b/advisories/unreviewed/2024/03/GHSA-q3m8-4vff-qr66/GHSA-q3m8-4vff-qr66.json new file mode 100644 index 00000000000..4ebac95f67f --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-q3m8-4vff-qr66/GHSA-q3m8-4vff-qr66.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q3m8-4vff-qr66", + "modified": "2024-03-29T15:30:32Z", + "published": "2024-03-29T15:30:32Z", + "aliases": [ + "CVE-2024-30498" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks CRM Perks Forms.This issue affects CRM Perks Forms: from n/a through 1.1.4.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30498" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/crm-perks-forms/wordpress-crm-perks-forms-plugin-1-1-4-unauthenticated-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T14:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-q766-xpmm-4999/GHSA-q766-xpmm-4999.json b/advisories/unreviewed/2024/03/GHSA-q766-xpmm-4999/GHSA-q766-xpmm-4999.json new file mode 100644 index 00000000000..cc53a8899a0 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-q766-xpmm-4999/GHSA-q766-xpmm-4999.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q766-xpmm-4999", + "modified": "2024-03-29T15:30:32Z", + "published": "2024-03-29T15:30:32Z", + "aliases": [ + "CVE-2024-30493" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Andy Moyle Church Admin.This issue affects Church Admin: from n/a through 4.1.7.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30493" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/church-admin/wordpress-church-admin-plugin-4-1-7-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-qxgj-php7-wrw3/GHSA-qxgj-php7-wrw3.json b/advisories/unreviewed/2024/03/GHSA-qxgj-php7-wrw3/GHSA-qxgj-php7-wrw3.json new file mode 100644 index 00000000000..26d37db5ba6 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-qxgj-php7-wrw3/GHSA-qxgj-php7-wrw3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qxgj-php7-wrw3", + "modified": "2024-03-29T15:30:28Z", + "published": "2024-03-29T15:30:28Z", + "aliases": [ + "CVE-2024-30483" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Simple Sponsorships Sponsors allows Stored XSS.This issue affects Sponsors: from n/a through 3.5.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30483" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-sponsors/wordpress-sponsors-plugin-3-5-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T13:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-r2xx-gprx-q489/GHSA-r2xx-gprx-q489.json b/advisories/unreviewed/2024/03/GHSA-r2xx-gprx-q489/GHSA-r2xx-gprx-q489.json new file mode 100644 index 00000000000..b64c644799e --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-r2xx-gprx-q489/GHSA-r2xx-gprx-q489.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r2xx-gprx-q489", + "modified": "2024-03-29T15:30:33Z", + "published": "2024-03-29T15:30:33Z", + "aliases": [ + "CVE-2024-30507" + ], + "details": "Authorization Bypass Through User-Controlled Key vulnerability in Molongui.This issue affects Molongui: from n/a through 4.7.7.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30507" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/molongui-authorship/wordpress-molongui-authorship-plugin-4-7-7-insecure-direct-object-references-idor-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-rr6r-cfgf-gc6h/GHSA-rr6r-cfgf-gc6h.json b/advisories/unreviewed/2024/03/GHSA-rr6r-cfgf-gc6h/GHSA-rr6r-cfgf-gc6h.json index a2ea46d08e1..ce84341daad 100644 --- a/advisories/unreviewed/2024/03/GHSA-rr6r-cfgf-gc6h/GHSA-rr6r-cfgf-gc6h.json +++ b/advisories/unreviewed/2024/03/GHSA-rr6r-cfgf-gc6h/GHSA-rr6r-cfgf-gc6h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rr6r-cfgf-gc6h", - "modified": "2024-03-06T00:31:26Z", + "modified": "2024-03-29T15:30:27Z", "published": "2024-03-06T00:31:26Z", "aliases": [ "CVE-2023-45290" @@ -33,6 +33,10 @@ { "type": "WEB", "url": "https://pkg.go.dev/vuln/GO-2024-2599" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240329-0004" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/03/GHSA-vf75-q6vr-4464/GHSA-vf75-q6vr-4464.json b/advisories/unreviewed/2024/03/GHSA-vf75-q6vr-4464/GHSA-vf75-q6vr-4464.json new file mode 100644 index 00000000000..209607c360d --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-vf75-q6vr-4464/GHSA-vf75-q6vr-4464.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vf75-q6vr-4464", + "modified": "2024-03-29T15:30:32Z", + "published": "2024-03-29T15:30:32Z", + "aliases": [ + "CVE-2024-30634" + ], + "details": "Tenda F1202 v1.2.0.20(408) has a stack overflow vulnerability via the mitInterface parameter in the fromAddressNat function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30634" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/F/F1202/fromAddressNat_mitInterface.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T14:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-vrgq-j293-jcx7/GHSA-vrgq-j293-jcx7.json b/advisories/unreviewed/2024/03/GHSA-vrgq-j293-jcx7/GHSA-vrgq-j293-jcx7.json new file mode 100644 index 00000000000..05cb07df0bf --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-vrgq-j293-jcx7/GHSA-vrgq-j293-jcx7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vrgq-j293-jcx7", + "modified": "2024-03-29T15:30:33Z", + "published": "2024-03-29T15:30:33Z", + "aliases": [ + "CVE-2024-30504" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel Engine.This issue affects WP Travel Engine: from n/a through 5.7.9.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30504" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-travel-engine/wordpress-wp-travel-engine-plugin-5-7-9-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T15:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-vxq6-3hh5-mcjj/GHSA-vxq6-3hh5-mcjj.json b/advisories/unreviewed/2024/03/GHSA-vxq6-3hh5-mcjj/GHSA-vxq6-3hh5-mcjj.json new file mode 100644 index 00000000000..567736497b2 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-vxq6-3hh5-mcjj/GHSA-vxq6-3hh5-mcjj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vxq6-3hh5-mcjj", + "modified": "2024-03-29T15:30:28Z", + "published": "2024-03-29T15:30:28Z", + "aliases": [ + "CVE-2024-30519" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lordicon Lordicon Animated Icons allows Stored XSS.This issue affects Lordicon Animated Icons: from n/a through 2.0.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30519" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/lordicon-interactive-icons/wordpress-lordicon-animated-icons-plugin-2-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T13:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-w63w-2c2h-qpxw/GHSA-w63w-2c2h-qpxw.json b/advisories/unreviewed/2024/03/GHSA-w63w-2c2h-qpxw/GHSA-w63w-2c2h-qpxw.json new file mode 100644 index 00000000000..3a0793e3028 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-w63w-2c2h-qpxw/GHSA-w63w-2c2h-qpxw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w63w-2c2h-qpxw", + "modified": "2024-03-29T15:30:31Z", + "published": "2024-03-29T15:30:31Z", + "aliases": [ + "CVE-2024-30633" + ], + "details": "Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the security parameter from the formWifiBasicSet function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30633" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/FH/FH1205/formWifiBasicSet_security.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T13:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-x73g-5x4f-9mqr/GHSA-x73g-5x4f-9mqr.json b/advisories/unreviewed/2024/03/GHSA-x73g-5x4f-9mqr/GHSA-x73g-5x4f-9mqr.json new file mode 100644 index 00000000000..da88f3bf73b --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-x73g-5x4f-9mqr/GHSA-x73g-5x4f-9mqr.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x73g-5x4f-9mqr", + "modified": "2024-03-29T15:30:32Z", + "published": "2024-03-29T15:30:32Z", + "aliases": [ + "CVE-2024-23538" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5.\n\nUsers are recommended to upgrade to version 1.8.5 or 1.9.0, which fix the issue.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23538" + }, + { + "type": "WEB", + "url": "https://cwiki.apache.org/confluence/display/FINERACT/Apache+Fineract+Security+Report" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/by32w2dylzgbqm5940x3wj7519wolqxs" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-x75q-8m6m-8c94/GHSA-x75q-8m6m-8c94.json b/advisories/unreviewed/2024/03/GHSA-x75q-8m6m-8c94/GHSA-x75q-8m6m-8c94.json new file mode 100644 index 00000000000..ce7de734958 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-x75q-8m6m-8c94/GHSA-x75q-8m6m-8c94.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x75q-8m6m-8c94", + "modified": "2024-03-29T15:30:31Z", + "published": "2024-03-29T15:30:31Z", + "aliases": [ + "CVE-2024-30429" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hans Matzen allows Stored XSS.This issue affects wp-forecast: from n/a through 9.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30429" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-forecast/wordpress-wp-forecast-plugin-9-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-xcvp-xvv5-6298/GHSA-xcvp-xvv5-6298.json b/advisories/unreviewed/2024/03/GHSA-xcvp-xvv5-6298/GHSA-xcvp-xvv5-6298.json new file mode 100644 index 00000000000..625c9a0d278 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-xcvp-xvv5-6298/GHSA-xcvp-xvv5-6298.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xcvp-xvv5-6298", + "modified": "2024-03-29T15:30:32Z", + "published": "2024-03-29T15:30:32Z", + "aliases": [ + "CVE-2024-23537" + ], + "details": "Improper Privilege Management vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5.\n\nUsers are recommended to upgrade to version 1.9.0, which fixes the issue.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23537" + }, + { + "type": "WEB", + "url": "https://cwiki.apache.org/confluence/display/FINERACT/Apache+Fineract+Security+Report" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/fq1ns4nprw2vqpkwwj9sw45jkwxmt9f1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-xrjx-pr69-2frv/GHSA-xrjx-pr69-2frv.json b/advisories/unreviewed/2024/03/GHSA-xrjx-pr69-2frv/GHSA-xrjx-pr69-2frv.json new file mode 100644 index 00000000000..79d2dc52f4b --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-xrjx-pr69-2frv/GHSA-xrjx-pr69-2frv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xrjx-pr69-2frv", + "modified": "2024-03-29T15:30:31Z", + "published": "2024-03-29T15:30:31Z", + "aliases": [ + "CVE-2024-30631" + ], + "details": "Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the schedStartTime parameter from setSchedWifi function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30631" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/FH/FH1205/setSchedWifi_start.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T13:15:16Z" + } +} \ No newline at end of file