diff --git a/advisories/unreviewed/2024/11/GHSA-2m53-6p59-jfh3/GHSA-2m53-6p59-jfh3.json b/advisories/unreviewed/2024/11/GHSA-2m53-6p59-jfh3/GHSA-2m53-6p59-jfh3.json index 9432061b03e..0f15321e5cc 100644 --- a/advisories/unreviewed/2024/11/GHSA-2m53-6p59-jfh3/GHSA-2m53-6p59-jfh3.json +++ b/advisories/unreviewed/2024/11/GHSA-2m53-6p59-jfh3/GHSA-2m53-6p59-jfh3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2m53-6p59-jfh3", - "modified": "2024-11-30T03:32:09Z", + "modified": "2024-12-02T00:34:01Z", "published": "2024-11-30T03:32:09Z", "aliases": [ "CVE-2024-43702" ], "details": "Software installed and run as a non-privileged user may conduct improper GPU system calls to allow unprivileged access to arbitrary physical memory page.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-280" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-30T03:15:13Z" diff --git a/advisories/unreviewed/2024/11/GHSA-cv39-r3v5-92vv/GHSA-cv39-r3v5-92vv.json b/advisories/unreviewed/2024/11/GHSA-cv39-r3v5-92vv/GHSA-cv39-r3v5-92vv.json index a09125edd29..1373fb5df1b 100644 --- a/advisories/unreviewed/2024/11/GHSA-cv39-r3v5-92vv/GHSA-cv39-r3v5-92vv.json +++ b/advisories/unreviewed/2024/11/GHSA-cv39-r3v5-92vv/GHSA-cv39-r3v5-92vv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cv39-r3v5-92vv", - "modified": "2024-11-30T03:32:09Z", + "modified": "2024-12-02T00:34:01Z", "published": "2024-11-30T03:32:09Z", "aliases": [ "CVE-2024-43703" ], "details": "Software installed and run as a non-privileged user may conduct improper GPU system calls to achieve unauthorised reads and writes of physical memory from the GPU HW.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-30T03:15:14Z" diff --git a/advisories/unreviewed/2024/12/GHSA-2chg-mq5v-5gqp/GHSA-2chg-mq5v-5gqp.json b/advisories/unreviewed/2024/12/GHSA-2chg-mq5v-5gqp/GHSA-2chg-mq5v-5gqp.json new file mode 100644 index 00000000000..4731aedae37 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-2chg-mq5v-5gqp/GHSA-2chg-mq5v-5gqp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2chg-mq5v-5gqp", + "modified": "2024-12-02T00:34:02Z", + "published": "2024-12-02T00:34:02Z", + "aliases": [ + "CVE-2024-53752" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Berg Informatik Stripe Donation allows Stored XSS.This issue affects Stripe Donation: from n/a through 1.2.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53752" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bin-stripe-donation/vulnerability/wordpress-stripe-donation-plugin-1-2-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-01T22:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-fr57-5xm9-fpgw/GHSA-fr57-5xm9-fpgw.json b/advisories/unreviewed/2024/12/GHSA-fr57-5xm9-fpgw/GHSA-fr57-5xm9-fpgw.json new file mode 100644 index 00000000000..795ed5c2006 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-fr57-5xm9-fpgw/GHSA-fr57-5xm9-fpgw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fr57-5xm9-fpgw", + "modified": "2024-12-02T00:34:02Z", + "published": "2024-12-02T00:34:02Z", + "aliases": [ + "CVE-2024-53746" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FlickDevs Elementor Button Plus allows Stored XSS.This issue affects Elementor Button Plus: from n/a through 1.3.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53746" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/fd-elementor-button-plus/vulnerability/wordpress-elementor-button-plus-plugin-1-3-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-01T22:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-g3c7-wp5g-pgpj/GHSA-g3c7-wp5g-pgpj.json b/advisories/unreviewed/2024/12/GHSA-g3c7-wp5g-pgpj/GHSA-g3c7-wp5g-pgpj.json new file mode 100644 index 00000000000..81ad6a0fced --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-g3c7-wp5g-pgpj/GHSA-g3c7-wp5g-pgpj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g3c7-wp5g-pgpj", + "modified": "2024-12-02T00:34:02Z", + "published": "2024-12-02T00:34:02Z", + "aliases": [ + "CVE-2024-53749" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Plugin Devs Post Carousel Slider for Elementor allows Stored XSS.This issue affects Post Carousel Slider for Elementor: from n/a through 1.4.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53749" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/post-carousel-slider-for-elementor/vulnerability/wordpress-post-carousel-slider-for-elementor-plugin-1-4-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-01T22:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-j3fm-79v8-r639/GHSA-j3fm-79v8-r639.json b/advisories/unreviewed/2024/12/GHSA-j3fm-79v8-r639/GHSA-j3fm-79v8-r639.json new file mode 100644 index 00000000000..64a5d6b0621 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-j3fm-79v8-r639/GHSA-j3fm-79v8-r639.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j3fm-79v8-r639", + "modified": "2024-12-02T00:34:01Z", + "published": "2024-12-02T00:34:01Z", + "aliases": [ + "CVE-2024-53744" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Skybootstrap Elementor Image Gallery Plugin allows Stored XSS.This issue affects Elementor Image Gallery Plugin: from n/a through 1.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53744" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/skyboot-portfolio-gallery/vulnerability/wordpress-elementor-image-gallery-plugin-1-0-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-01T22:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-jgx2-w5g8-5xh3/GHSA-jgx2-w5g8-5xh3.json b/advisories/unreviewed/2024/12/GHSA-jgx2-w5g8-5xh3/GHSA-jgx2-w5g8-5xh3.json new file mode 100644 index 00000000000..350b621ad3f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-jgx2-w5g8-5xh3/GHSA-jgx2-w5g8-5xh3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jgx2-w5g8-5xh3", + "modified": "2024-12-02T00:34:01Z", + "published": "2024-12-02T00:34:01Z", + "aliases": [ + "CVE-2024-53742" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Prism I.T. Systems Multilevel Referral Affiliate Plugin for WooCommerce allows Reflected XSS.This issue affects Multilevel Referral Affiliate Plugin for WooCommerce: from n/a through 2.27.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53742" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/multilevel-referral-plugin-for-woocommerce/vulnerability/wordpress-multilevel-referral-affiliate-plugin-for-woocommerce-plugin-2-27-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-01T22:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-jh59-42v7-vvqq/GHSA-jh59-42v7-vvqq.json b/advisories/unreviewed/2024/12/GHSA-jh59-42v7-vvqq/GHSA-jh59-42v7-vvqq.json new file mode 100644 index 00000000000..ac68074d230 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-jh59-42v7-vvqq/GHSA-jh59-42v7-vvqq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jh59-42v7-vvqq", + "modified": "2024-12-02T00:34:01Z", + "published": "2024-12-02T00:34:01Z", + "aliases": [ + "CVE-2024-53743" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FlickDevs Countdown Timer for Elementor allows Stored XSS.This issue affects Countdown Timer for Elementor: from n/a through 1.3.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53743" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/countdown-timer-for-elementor/vulnerability/wordpress-countdown-timer-for-elementor-plugin-1-3-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-01T22:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-jv96-rr8x-2pr7/GHSA-jv96-rr8x-2pr7.json b/advisories/unreviewed/2024/12/GHSA-jv96-rr8x-2pr7/GHSA-jv96-rr8x-2pr7.json new file mode 100644 index 00000000000..5fe57ac19f0 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-jv96-rr8x-2pr7/GHSA-jv96-rr8x-2pr7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jv96-rr8x-2pr7", + "modified": "2024-12-02T00:34:02Z", + "published": "2024-12-02T00:34:02Z", + "aliases": [ + "CVE-2024-53747" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NuttTaro Video Player for WPBakery allows Stored XSS.This issue affects Video Player for WPBakery: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53747" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/video-player-for-wpbakery/vulnerability/wordpress-video-player-for-wpbakery-plugin-1-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-01T22:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-mgpq-q8xw-q46c/GHSA-mgpq-q8xw-q46c.json b/advisories/unreviewed/2024/12/GHSA-mgpq-q8xw-q46c/GHSA-mgpq-q8xw-q46c.json new file mode 100644 index 00000000000..61841dd2db9 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-mgpq-q8xw-q46c/GHSA-mgpq-q8xw-q46c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mgpq-q8xw-q46c", + "modified": "2024-12-02T00:34:02Z", + "published": "2024-12-02T00:34:02Z", + "aliases": [ + "CVE-2024-53748" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Terry Lin WP Mermaid allows Stored XSS.This issue affects WP Mermaid: from n/a through 1.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53748" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-mermaid/vulnerability/wordpress-wp-mermaid-plugin-1-0-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-01T22:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-pfqj-879c-5293/GHSA-pfqj-879c-5293.json b/advisories/unreviewed/2024/12/GHSA-pfqj-879c-5293/GHSA-pfqj-879c-5293.json new file mode 100644 index 00000000000..604ef979312 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-pfqj-879c-5293/GHSA-pfqj-879c-5293.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pfqj-879c-5293", + "modified": "2024-12-02T00:34:02Z", + "published": "2024-12-02T00:34:02Z", + "aliases": [ + "CVE-2024-12007" + ], + "details": "A vulnerability, which was classified as critical, was found in code-projects Farmacia 1.0. This affects an unknown part of the file /visualizar-produto.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12007" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/LamentXU123/cve/blob/main/cve-l.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.286491" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.286491" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.454715" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-01T23:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-v747-g8g4-6c8h/GHSA-v747-g8g4-6c8h.json b/advisories/unreviewed/2024/12/GHSA-v747-g8g4-6c8h/GHSA-v747-g8g4-6c8h.json new file mode 100644 index 00000000000..1fbc1c30702 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-v747-g8g4-6c8h/GHSA-v747-g8g4-6c8h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v747-g8g4-6c8h", + "modified": "2024-12-02T00:34:01Z", + "published": "2024-12-02T00:34:01Z", + "aliases": [ + "CVE-2024-53745" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 코스모스팜 – Cosmosfarm 소셜 공유 버튼 By 코스모스팜 allows Stored XSS.This issue affects 소셜 공유 버튼 By 코스모스팜: from n/a through 1.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53745" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cosmosfarm-share-buttons/vulnerability/wordpress-social-sharing-buttons-by-cosmos-farm-plugin-1-9-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-01T22:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-w9mh-fv5p-8h8q/GHSA-w9mh-fv5p-8h8q.json b/advisories/unreviewed/2024/12/GHSA-w9mh-fv5p-8h8q/GHSA-w9mh-fv5p-8h8q.json new file mode 100644 index 00000000000..ddc54b04ae4 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-w9mh-fv5p-8h8q/GHSA-w9mh-fv5p-8h8q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w9mh-fv5p-8h8q", + "modified": "2024-12-02T00:34:02Z", + "published": "2024-12-02T00:34:02Z", + "aliases": [ + "CVE-2024-53750" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Maeve Lander PayPal Responder allows Stored XSS.This issue affects PayPal Responder: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53750" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/paypal-responder/vulnerability/wordpress-paypal-responder-plugin-1-2-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-01T22:15:06Z" + } +} \ No newline at end of file