diff --git a/advisories/github-reviewed/2023/03/GHSA-g2j6-57v7-gm8c/GHSA-g2j6-57v7-gm8c.json b/advisories/github-reviewed/2023/03/GHSA-g2j6-57v7-gm8c/GHSA-g2j6-57v7-gm8c.json index 6faca93ff81..9eb41ee7cef 100644 --- a/advisories/github-reviewed/2023/03/GHSA-g2j6-57v7-gm8c/GHSA-g2j6-57v7-gm8c.json +++ b/advisories/github-reviewed/2023/03/GHSA-g2j6-57v7-gm8c/GHSA-g2j6-57v7-gm8c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g2j6-57v7-gm8c", - "modified": "2023-03-30T20:20:23Z", + "modified": "2024-12-06T15:31:17Z", "published": "2023-03-30T20:20:23Z", "aliases": [ "CVE-2023-28642" @@ -51,6 +51,10 @@ { "type": "PACKAGE", "url": "https://github.com/opencontainers/runc" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241206-0005" } ], "database_specific": { diff --git a/advisories/github-reviewed/2023/03/GHSA-vpvm-3wq2-2wvm/GHSA-vpvm-3wq2-2wvm.json b/advisories/github-reviewed/2023/03/GHSA-vpvm-3wq2-2wvm/GHSA-vpvm-3wq2-2wvm.json index befe72e79ee..a4ef876dcee 100644 --- a/advisories/github-reviewed/2023/03/GHSA-vpvm-3wq2-2wvm/GHSA-vpvm-3wq2-2wvm.json +++ b/advisories/github-reviewed/2023/03/GHSA-vpvm-3wq2-2wvm/GHSA-vpvm-3wq2-2wvm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vpvm-3wq2-2wvm", - "modified": "2024-07-03T20:30:48Z", + "modified": "2024-12-06T15:31:17Z", "published": "2023-03-03T21:30:19Z", "aliases": [ "CVE-2023-27561" @@ -52,6 +52,10 @@ "type": "WEB", "url": "https://github.com/opencontainers/runc/pull/3785" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241206-0004" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/I6BF24VCZRFTYBTT3T7HDZUOTKOTNPLZ" diff --git a/advisories/github-reviewed/2024/05/GHSA-8xfc-gm6g-vgpv/GHSA-8xfc-gm6g-vgpv.json b/advisories/github-reviewed/2024/05/GHSA-8xfc-gm6g-vgpv/GHSA-8xfc-gm6g-vgpv.json index 99b87676bc2..1e063e8bc7b 100644 --- a/advisories/github-reviewed/2024/05/GHSA-8xfc-gm6g-vgpv/GHSA-8xfc-gm6g-vgpv.json +++ b/advisories/github-reviewed/2024/05/GHSA-8xfc-gm6g-vgpv/GHSA-8xfc-gm6g-vgpv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8xfc-gm6g-vgpv", - "modified": "2024-09-09T21:32:53Z", + "modified": "2024-12-06T15:31:20Z", "published": "2024-05-14T15:32:54Z", "aliases": [ "CVE-2024-29857" @@ -231,6 +231,10 @@ "type": "WEB", "url": "https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902024%E2%80%9029857" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241206-0008" + }, { "type": "WEB", "url": "https://www.bouncycastle.org/latest_releases.html" diff --git a/advisories/github-reviewed/2024/06/GHSA-fwhr-88qx-h9g7/GHSA-fwhr-88qx-h9g7.json b/advisories/github-reviewed/2024/06/GHSA-fwhr-88qx-h9g7/GHSA-fwhr-88qx-h9g7.json index 45f0bcd047a..42fd3a84e55 100644 --- a/advisories/github-reviewed/2024/06/GHSA-fwhr-88qx-h9g7/GHSA-fwhr-88qx-h9g7.json +++ b/advisories/github-reviewed/2024/06/GHSA-fwhr-88qx-h9g7/GHSA-fwhr-88qx-h9g7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fwhr-88qx-h9g7", - "modified": "2024-06-05T21:54:36Z", + "modified": "2024-12-06T15:31:19Z", "published": "2024-06-04T22:26:24Z", "aliases": [ "CVE-2024-28103" @@ -115,6 +115,10 @@ { "type": "WEB", "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/actionpack/CVE-2024-28103.yml" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241206-0002" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/05/GHSA-2hpj-v4f4-7g4j/GHSA-2hpj-v4f4-7g4j.json b/advisories/unreviewed/2022/05/GHSA-2hpj-v4f4-7g4j/GHSA-2hpj-v4f4-7g4j.json index 371ba92df0e..8d30d30719a 100644 --- a/advisories/unreviewed/2022/05/GHSA-2hpj-v4f4-7g4j/GHSA-2hpj-v4f4-7g4j.json +++ b/advisories/unreviewed/2022/05/GHSA-2hpj-v4f4-7g4j/GHSA-2hpj-v4f4-7g4j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2hpj-v4f4-7g4j", - "modified": "2024-04-04T00:55:12Z", + "modified": "2024-12-06T15:31:17Z", "published": "2022-05-24T16:47:45Z", "aliases": [ "CVE-2019-12749" @@ -55,6 +55,10 @@ "type": "WEB", "url": "https://security.gentoo.org/glsa/201909-08" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241206-0010" + }, { "type": "WEB", "url": "https://usn.ubuntu.com/4015-1" diff --git a/advisories/unreviewed/2023/06/GHSA-68g3-2p3g-w9pq/GHSA-68g3-2p3g-w9pq.json b/advisories/unreviewed/2023/06/GHSA-68g3-2p3g-w9pq/GHSA-68g3-2p3g-w9pq.json index 641387dd5dd..03c4ba6beb7 100644 --- a/advisories/unreviewed/2023/06/GHSA-68g3-2p3g-w9pq/GHSA-68g3-2p3g-w9pq.json +++ b/advisories/unreviewed/2023/06/GHSA-68g3-2p3g-w9pq/GHSA-68g3-2p3g-w9pq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-68g3-2p3g-w9pq", - "modified": "2023-11-25T12:30:22Z", + "modified": "2024-12-06T15:31:17Z", "published": "2023-06-08T21:30:27Z", "aliases": [ "CVE-2023-29405" @@ -46,6 +46,10 @@ { "type": "WEB", "url": "https://security.gentoo.org/glsa/202311-09" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241206-0003" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/11/GHSA-2vjj-r39q-gvxr/GHSA-2vjj-r39q-gvxr.json b/advisories/unreviewed/2023/11/GHSA-2vjj-r39q-gvxr/GHSA-2vjj-r39q-gvxr.json index 91bdd4f60ab..f712d46bfcb 100644 --- a/advisories/unreviewed/2023/11/GHSA-2vjj-r39q-gvxr/GHSA-2vjj-r39q-gvxr.json +++ b/advisories/unreviewed/2023/11/GHSA-2vjj-r39q-gvxr/GHSA-2vjj-r39q-gvxr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2vjj-r39q-gvxr", - "modified": "2023-11-30T06:33:24Z", + "modified": "2024-12-06T15:31:17Z", "published": "2023-11-28T00:30:33Z", "aliases": [ "CVE-2023-42366" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://bugs.busybox.net/show_bug.cgi?id=15874" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241206-0007" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-28cg-r647-j4cw/GHSA-28cg-r647-j4cw.json b/advisories/unreviewed/2024/02/GHSA-28cg-r647-j4cw/GHSA-28cg-r647-j4cw.json index 16b3d76fcbd..6beabf261dd 100644 --- a/advisories/unreviewed/2024/02/GHSA-28cg-r647-j4cw/GHSA-28cg-r647-j4cw.json +++ b/advisories/unreviewed/2024/02/GHSA-28cg-r647-j4cw/GHSA-28cg-r647-j4cw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-28cg-r647-j4cw", - "modified": "2024-02-28T09:30:37Z", + "modified": "2024-12-06T15:31:19Z", "published": "2024-02-28T09:30:37Z", "aliases": [ "CVE-2021-46998" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nethernet:enic: Fix a use after free bug in enic_hard_start_xmit\n\nIn enic_hard_start_xmit, it calls enic_queue_wq_skb(). Inside\nenic_queue_wq_skb, if some error happens, the skb will be freed\nby dev_kfree_skb(skb). But the freed skb is still used in\nskb_tx_timestamp(skb).\n\nMy patch makes enic_queue_wq_skb() return error and goto spin_unlock()\nincase of error. The solution is provided by Govind.\nSee https://lkml.org/lkml/2021/4/30/961.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T09:15:38Z" diff --git a/advisories/unreviewed/2024/02/GHSA-2cmc-x892-vrfq/GHSA-2cmc-x892-vrfq.json b/advisories/unreviewed/2024/02/GHSA-2cmc-x892-vrfq/GHSA-2cmc-x892-vrfq.json index 7d2c52b02ec..ff7c6f30b30 100644 --- a/advisories/unreviewed/2024/02/GHSA-2cmc-x892-vrfq/GHSA-2cmc-x892-vrfq.json +++ b/advisories/unreviewed/2024/02/GHSA-2cmc-x892-vrfq/GHSA-2cmc-x892-vrfq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2cmc-x892-vrfq", - "modified": "2024-02-21T09:31:00Z", + "modified": "2024-12-06T15:31:18Z", "published": "2024-02-21T09:31:00Z", "aliases": [ "CVE-2023-42836" ], "details": "A logic issue was addressed with improved checks. This issue is fixed in iOS 17.1 and iPadOS 17.1, macOS Ventura 13.6.3, macOS Sonoma 14.1, macOS Monterey 12.7.2. An attacker may be able to access connected network volumes mounted in the home directory.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -33,7 +38,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-21T07:15:48Z" diff --git a/advisories/unreviewed/2024/02/GHSA-4q6w-gxhv-h434/GHSA-4q6w-gxhv-h434.json b/advisories/unreviewed/2024/02/GHSA-4q6w-gxhv-h434/GHSA-4q6w-gxhv-h434.json index 63677b4cd46..ef515892634 100644 --- a/advisories/unreviewed/2024/02/GHSA-4q6w-gxhv-h434/GHSA-4q6w-gxhv-h434.json +++ b/advisories/unreviewed/2024/02/GHSA-4q6w-gxhv-h434/GHSA-4q6w-gxhv-h434.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4q6w-gxhv-h434", - "modified": "2024-02-28T09:30:37Z", + "modified": "2024-12-06T15:31:19Z", "published": "2024-02-28T09:30:37Z", "aliases": [ "CVE-2021-46996" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nftables: Fix a memleak from userdata error path in new objects\n\nRelease object name if userdata allocation fails.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T09:15:38Z" diff --git a/advisories/unreviewed/2024/02/GHSA-4qp7-5rvw-5428/GHSA-4qp7-5rvw-5428.json b/advisories/unreviewed/2024/02/GHSA-4qp7-5rvw-5428/GHSA-4qp7-5rvw-5428.json index e5bfb0ef629..78cbf2387c4 100644 --- a/advisories/unreviewed/2024/02/GHSA-4qp7-5rvw-5428/GHSA-4qp7-5rvw-5428.json +++ b/advisories/unreviewed/2024/02/GHSA-4qp7-5rvw-5428/GHSA-4qp7-5rvw-5428.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4qp7-5rvw-5428", - "modified": "2024-02-28T09:30:37Z", + "modified": "2024-12-06T15:31:18Z", "published": "2024-02-28T09:30:37Z", "aliases": [ "CVE-2021-46984" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nkyber: fix out of bounds access when preempted\n\n__blk_mq_sched_bio_merge() gets the ctx and hctx for the current CPU and\npasses the hctx to ->bio_merge(). kyber_bio_merge() then gets the ctx\nfor the current CPU again and uses that to get the corresponding Kyber\ncontext in the passed hctx. However, the thread may be preempted between\nthe two calls to blk_mq_get_ctx(), and the ctx returned the second time\nmay no longer correspond to the passed hctx. This \"works\" accidentally\nmost of the time, but it can cause us to read garbage if the second ctx\ncame from an hctx with more ctx's than the first one (i.e., if\nctx->index_hw[hctx->type] > hctx->nr_ctx).\n\nThis manifested as this UBSAN array index out of bounds error reported\nby Jakub:\n\nUBSAN: array-index-out-of-bounds in ../kernel/locking/qspinlock.c:130:9\nindex 13106 is out of range for type 'long unsigned int [128]'\nCall Trace:\n dump_stack+0xa4/0xe5\n ubsan_epilogue+0x5/0x40\n __ubsan_handle_out_of_bounds.cold.13+0x2a/0x34\n queued_spin_lock_slowpath+0x476/0x480\n do_raw_spin_lock+0x1c2/0x1d0\n kyber_bio_merge+0x112/0x180\n blk_mq_submit_bio+0x1f5/0x1100\n submit_bio_noacct+0x7b0/0x870\n submit_bio+0xc2/0x3a0\n btrfs_map_bio+0x4f0/0x9d0\n btrfs_submit_data_bio+0x24e/0x310\n submit_one_bio+0x7f/0xb0\n submit_extent_page+0xc4/0x440\n __extent_writepage_io+0x2b8/0x5e0\n __extent_writepage+0x28d/0x6e0\n extent_write_cache_pages+0x4d7/0x7a0\n extent_writepages+0xa2/0x110\n do_writepages+0x8f/0x180\n __writeback_single_inode+0x99/0x7f0\n writeback_sb_inodes+0x34e/0x790\n __writeback_inodes_wb+0x9e/0x120\n wb_writeback+0x4d2/0x660\n wb_workfn+0x64d/0xa10\n process_one_work+0x53a/0xa80\n worker_thread+0x69/0x5b0\n kthread+0x20b/0x240\n ret_from_fork+0x1f/0x30\n\nOnly Kyber uses the hctx, so fix it by passing the request_queue to\n->bio_merge() instead. BFQ and mq-deadline just use that, and Kyber can\nmap the queues itself to avoid the mismatch.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-129" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T09:15:37Z" diff --git a/advisories/unreviewed/2024/02/GHSA-5vm6-785f-3cj3/GHSA-5vm6-785f-3cj3.json b/advisories/unreviewed/2024/02/GHSA-5vm6-785f-3cj3/GHSA-5vm6-785f-3cj3.json index 0cb976c1aa4..8a69dd206b0 100644 --- a/advisories/unreviewed/2024/02/GHSA-5vm6-785f-3cj3/GHSA-5vm6-785f-3cj3.json +++ b/advisories/unreviewed/2024/02/GHSA-5vm6-785f-3cj3/GHSA-5vm6-785f-3cj3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5vm6-785f-3cj3", - "modified": "2024-02-28T09:30:37Z", + "modified": "2024-12-06T15:31:19Z", "published": "2024-02-28T09:30:37Z", "aliases": [ "CVE-2021-46995" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: mcp251xfd: mcp251xfd_probe(): fix an error pointer dereference in probe\n\nWhen we converted this code to use dev_err_probe() we accidentally\nremoved a return. It means that if devm_clk_get() it will lead to an\nOops when we call clk_get_rate() on the next line.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T09:15:37Z" diff --git a/advisories/unreviewed/2024/02/GHSA-73pj-jqmg-pmr5/GHSA-73pj-jqmg-pmr5.json b/advisories/unreviewed/2024/02/GHSA-73pj-jqmg-pmr5/GHSA-73pj-jqmg-pmr5.json index 5feb0635e53..b08977f0f6a 100644 --- a/advisories/unreviewed/2024/02/GHSA-73pj-jqmg-pmr5/GHSA-73pj-jqmg-pmr5.json +++ b/advisories/unreviewed/2024/02/GHSA-73pj-jqmg-pmr5/GHSA-73pj-jqmg-pmr5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-73pj-jqmg-pmr5", - "modified": "2024-02-28T09:30:37Z", + "modified": "2024-12-06T15:31:19Z", "published": "2024-02-28T09:30:37Z", "aliases": [ "CVE-2021-46991" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ni40e: Fix use-after-free in i40e_client_subtask()\n\nCurrently the call to i40e_client_del_instance frees the object\npf->cinst, however pf->cinst->lan_info is being accessed after\nthe free. Fix this by adding the missing return.\n\nAddresses-Coverity: (\"Read from pointer after free\")", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T09:15:37Z" diff --git a/advisories/unreviewed/2024/02/GHSA-7896-9859-h9rc/GHSA-7896-9859-h9rc.json b/advisories/unreviewed/2024/02/GHSA-7896-9859-h9rc/GHSA-7896-9859-h9rc.json index 3922d0f3613..94d6d1392e6 100644 --- a/advisories/unreviewed/2024/02/GHSA-7896-9859-h9rc/GHSA-7896-9859-h9rc.json +++ b/advisories/unreviewed/2024/02/GHSA-7896-9859-h9rc/GHSA-7896-9859-h9rc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7896-9859-h9rc", - "modified": "2024-02-28T09:30:37Z", + "modified": "2024-12-06T15:31:18Z", "published": "2024-02-28T09:30:37Z", "aliases": [ "CVE-2021-46985" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nACPI: scan: Fix a memory leak in an error handling path\n\nIf 'acpi_device_set_name()' fails, we must free\n'acpi_device_bus_id->bus_id' or there is a (potential) memory leak.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T09:15:37Z" diff --git a/advisories/unreviewed/2024/02/GHSA-85xw-cv8g-9227/GHSA-85xw-cv8g-9227.json b/advisories/unreviewed/2024/02/GHSA-85xw-cv8g-9227/GHSA-85xw-cv8g-9227.json index 7337cb79b84..b9cd2d70d9d 100644 --- a/advisories/unreviewed/2024/02/GHSA-85xw-cv8g-9227/GHSA-85xw-cv8g-9227.json +++ b/advisories/unreviewed/2024/02/GHSA-85xw-cv8g-9227/GHSA-85xw-cv8g-9227.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-85xw-cv8g-9227", - "modified": "2024-02-28T09:30:37Z", + "modified": "2024-12-06T15:31:19Z", "published": "2024-02-28T09:30:37Z", "aliases": [ "CVE-2021-46987" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix deadlock when cloning inline extents and using qgroups\n\nThere are a few exceptional cases where cloning an inline extent needs to\ncopy the inline extent data into a page of the destination inode.\n\nWhen this happens, we end up starting a transaction while having a dirty\npage for the destination inode and while having the range locked in the\ndestination's inode iotree too. Because when reserving metadata space\nfor a transaction we may need to flush existing delalloc in case there is\nnot enough free space, we have a mechanism in place to prevent a deadlock,\nwhich was introduced in commit 3d45f221ce627d (\"btrfs: fix deadlock when\ncloning inline extent and low on free metadata space\").\n\nHowever when using qgroups, a transaction also reserves metadata qgroup\nspace, which can also result in flushing delalloc in case there is not\nenough available space at the moment. When this happens we deadlock, since\nflushing delalloc requires locking the file range in the inode's iotree\nand the range was already locked at the very beginning of the clone\noperation, before attempting to start the transaction.\n\nWhen this issue happens, stack traces like the following are reported:\n\n [72747.556262] task:kworker/u81:9 state:D stack: 0 pid: 225 ppid: 2 flags:0x00004000\n [72747.556268] Workqueue: writeback wb_workfn (flush-btrfs-1142)\n [72747.556271] Call Trace:\n [72747.556273] __schedule+0x296/0x760\n [72747.556277] schedule+0x3c/0xa0\n [72747.556279] io_schedule+0x12/0x40\n [72747.556284] __lock_page+0x13c/0x280\n [72747.556287] ? generic_file_readonly_mmap+0x70/0x70\n [72747.556325] extent_write_cache_pages+0x22a/0x440 [btrfs]\n [72747.556331] ? __set_page_dirty_nobuffers+0xe7/0x160\n [72747.556358] ? set_extent_buffer_dirty+0x5e/0x80 [btrfs]\n [72747.556362] ? update_group_capacity+0x25/0x210\n [72747.556366] ? cpumask_next_and+0x1a/0x20\n [72747.556391] extent_writepages+0x44/0xa0 [btrfs]\n [72747.556394] do_writepages+0x41/0xd0\n [72747.556398] __writeback_single_inode+0x39/0x2a0\n [72747.556403] writeback_sb_inodes+0x1ea/0x440\n [72747.556407] __writeback_inodes_wb+0x5f/0xc0\n [72747.556410] wb_writeback+0x235/0x2b0\n [72747.556414] ? get_nr_inodes+0x35/0x50\n [72747.556417] wb_workfn+0x354/0x490\n [72747.556420] ? newidle_balance+0x2c5/0x3e0\n [72747.556424] process_one_work+0x1aa/0x340\n [72747.556426] worker_thread+0x30/0x390\n [72747.556429] ? create_worker+0x1a0/0x1a0\n [72747.556432] kthread+0x116/0x130\n [72747.556435] ? kthread_park+0x80/0x80\n [72747.556438] ret_from_fork+0x1f/0x30\n\n [72747.566958] Workqueue: btrfs-flush_delalloc btrfs_work_helper [btrfs]\n [72747.566961] Call Trace:\n [72747.566964] __schedule+0x296/0x760\n [72747.566968] ? finish_wait+0x80/0x80\n [72747.566970] schedule+0x3c/0xa0\n [72747.566995] wait_extent_bit.constprop.68+0x13b/0x1c0 [btrfs]\n [72747.566999] ? finish_wait+0x80/0x80\n [72747.567024] lock_extent_bits+0x37/0x90 [btrfs]\n [72747.567047] btrfs_invalidatepage+0x299/0x2c0 [btrfs]\n [72747.567051] ? find_get_pages_range_tag+0x2cd/0x380\n [72747.567076] __extent_writepage+0x203/0x320 [btrfs]\n [72747.567102] extent_write_cache_pages+0x2bb/0x440 [btrfs]\n [72747.567106] ? update_load_avg+0x7e/0x5f0\n [72747.567109] ? enqueue_entity+0xf4/0x6f0\n [72747.567134] extent_writepages+0x44/0xa0 [btrfs]\n [72747.567137] ? enqueue_task_fair+0x93/0x6f0\n [72747.567140] do_writepages+0x41/0xd0\n [72747.567144] __filemap_fdatawrite_range+0xc7/0x100\n [72747.567167] btrfs_run_delalloc_work+0x17/0x40 [btrfs]\n [72747.567195] btrfs_work_helper+0xc2/0x300 [btrfs]\n [72747.567200] process_one_work+0x1aa/0x340\n [72747.567202] worker_thread+0x30/0x390\n [72747.567205] ? create_worker+0x1a0/0x1a0\n [72747.567208] kthread+0x116/0x130\n [72747.567211] ? kthread_park+0x80/0x80\n [72747.567214] ret_from_fork+0x1f/0x30\n\n [72747.569686] task:fsstress state:D stack: \n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T09:15:37Z" diff --git a/advisories/unreviewed/2024/02/GHSA-9h3w-jq64-m799/GHSA-9h3w-jq64-m799.json b/advisories/unreviewed/2024/02/GHSA-9h3w-jq64-m799/GHSA-9h3w-jq64-m799.json index 557ee5d0d71..bdd3fea273e 100644 --- a/advisories/unreviewed/2024/02/GHSA-9h3w-jq64-m799/GHSA-9h3w-jq64-m799.json +++ b/advisories/unreviewed/2024/02/GHSA-9h3w-jq64-m799/GHSA-9h3w-jq64-m799.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9h3w-jq64-m799", - "modified": "2024-02-28T09:30:37Z", + "modified": "2024-12-06T15:31:19Z", "published": "2024-02-28T09:30:37Z", "aliases": [ "CVE-2021-46994" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: mcp251x: fix resume from sleep before interface was brought up\n\nSince 8ce8c0abcba3 the driver queues work via priv->restart_work when\nresuming after suspend, even when the interface was not previously\nenabled. This causes a null dereference error as the workqueue is only\nallocated and initialized in mcp251x_open().\n\nTo fix this we move the workqueue init to mcp251x_can_probe() as there\nis no reason to do it later and repeat it whenever mcp251x_open() is\ncalled.\n\n[mkl: fix error handling in mcp251x_stop()]", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T09:15:37Z" diff --git a/advisories/unreviewed/2024/02/GHSA-frg3-hm7v-3rpf/GHSA-frg3-hm7v-3rpf.json b/advisories/unreviewed/2024/02/GHSA-frg3-hm7v-3rpf/GHSA-frg3-hm7v-3rpf.json index 03fd3be8a02..714631dd99b 100644 --- a/advisories/unreviewed/2024/02/GHSA-frg3-hm7v-3rpf/GHSA-frg3-hm7v-3rpf.json +++ b/advisories/unreviewed/2024/02/GHSA-frg3-hm7v-3rpf/GHSA-frg3-hm7v-3rpf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-frg3-hm7v-3rpf", - "modified": "2024-02-26T18:30:28Z", + "modified": "2024-12-06T15:31:18Z", "published": "2024-02-21T06:30:32Z", "aliases": [ "CVE-2024-1671" ], "details": "Inappropriate implementation in Site Isolation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -33,7 +38,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-21T04:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-rj5v-wjwr-jxjq/GHSA-rj5v-wjwr-jxjq.json b/advisories/unreviewed/2024/02/GHSA-rj5v-wjwr-jxjq/GHSA-rj5v-wjwr-jxjq.json index 51514f7789b..e54e37496ab 100644 --- a/advisories/unreviewed/2024/02/GHSA-rj5v-wjwr-jxjq/GHSA-rj5v-wjwr-jxjq.json +++ b/advisories/unreviewed/2024/02/GHSA-rj5v-wjwr-jxjq/GHSA-rj5v-wjwr-jxjq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rj5v-wjwr-jxjq", - "modified": "2024-02-21T09:31:00Z", + "modified": "2024-12-06T15:31:18Z", "published": "2024-02-21T09:31:00Z", "aliases": [ "CVE-2023-42839" ], "details": "This issue was addressed with improved state management. This issue is fixed in tvOS 17.1, watchOS 10.1, macOS Sonoma 14.1, iOS 17.1 and iPadOS 17.1. An app may be able to access sensitive user data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-922" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-21T07:15:48Z" diff --git a/advisories/unreviewed/2024/02/GHSA-wqqw-j26h-m6w3/GHSA-wqqw-j26h-m6w3.json b/advisories/unreviewed/2024/02/GHSA-wqqw-j26h-m6w3/GHSA-wqqw-j26h-m6w3.json index 1ea029b7f44..6da1d15b9b8 100644 --- a/advisories/unreviewed/2024/02/GHSA-wqqw-j26h-m6w3/GHSA-wqqw-j26h-m6w3.json +++ b/advisories/unreviewed/2024/02/GHSA-wqqw-j26h-m6w3/GHSA-wqqw-j26h-m6w3.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-9v4g-5w22-xh84/GHSA-9v4g-5w22-xh84.json b/advisories/unreviewed/2024/03/GHSA-9v4g-5w22-xh84/GHSA-9v4g-5w22-xh84.json index 56477773c6f..f27a978d81a 100644 --- a/advisories/unreviewed/2024/03/GHSA-9v4g-5w22-xh84/GHSA-9v4g-5w22-xh84.json +++ b/advisories/unreviewed/2024/03/GHSA-9v4g-5w22-xh84/GHSA-9v4g-5w22-xh84.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9v4g-5w22-xh84", - "modified": "2024-03-14T00:31:05Z", + "modified": "2024-12-06T15:31:19Z", "published": "2024-03-08T03:31:24Z", "aliases": [ "CVE-2024-23239" ], "details": "A race condition was addressed with improved state handling. This issue is fixed in tvOS 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, watchOS 10.4. An app may be able to leak sensitive user information.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-362" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-08T02:15:48Z" diff --git a/advisories/unreviewed/2024/03/GHSA-pm93-x7pc-g8qx/GHSA-pm93-x7pc-g8qx.json b/advisories/unreviewed/2024/03/GHSA-pm93-x7pc-g8qx/GHSA-pm93-x7pc-g8qx.json index fb95c2cb90b..ac16de9a018 100644 --- a/advisories/unreviewed/2024/03/GHSA-pm93-x7pc-g8qx/GHSA-pm93-x7pc-g8qx.json +++ b/advisories/unreviewed/2024/03/GHSA-pm93-x7pc-g8qx/GHSA-pm93-x7pc-g8qx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pm93-x7pc-g8qx", - "modified": "2024-03-14T00:31:05Z", + "modified": "2024-12-06T15:31:19Z", "published": "2024-03-08T03:31:25Z", "aliases": [ "CVE-2024-23257" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.7.4, macOS Ventura 13.6.5, macOS Sonoma 14.4, visionOS 1.1, iOS 16.7.6 and iPadOS 16.7.6. Processing an image may result in disclosure of process memory.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -53,7 +58,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-08T02:15:48Z" diff --git a/advisories/unreviewed/2024/11/GHSA-5rq6-q8gw-qqpr/GHSA-5rq6-q8gw-qqpr.json b/advisories/unreviewed/2024/11/GHSA-5rq6-q8gw-qqpr/GHSA-5rq6-q8gw-qqpr.json index 9065a12575f..aecfe0e3128 100644 --- a/advisories/unreviewed/2024/11/GHSA-5rq6-q8gw-qqpr/GHSA-5rq6-q8gw-qqpr.json +++ b/advisories/unreviewed/2024/11/GHSA-5rq6-q8gw-qqpr/GHSA-5rq6-q8gw-qqpr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5rq6-q8gw-qqpr", - "modified": "2024-11-23T21:30:47Z", + "modified": "2024-12-06T15:31:19Z", "published": "2024-11-12T00:30:36Z", "aliases": [ "CVE-2024-52533" @@ -35,6 +35,10 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2024/11/msg00020.html" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241206-0009" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/11/12/11" diff --git a/advisories/unreviewed/2024/12/GHSA-24px-m2q8-87hf/GHSA-24px-m2q8-87hf.json b/advisories/unreviewed/2024/12/GHSA-24px-m2q8-87hf/GHSA-24px-m2q8-87hf.json new file mode 100644 index 00000000000..25ac90afc48 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-24px-m2q8-87hf/GHSA-24px-m2q8-87hf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-24px-m2q8-87hf", + "modified": "2024-12-06T15:31:20Z", + "published": "2024-12-06T15:31:20Z", + "aliases": [ + "CVE-2024-53806" + ], + "details": "Missing Authorization vulnerability in WpMaspik Maspik – Spam blacklist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Maspik – Spam blacklist: from n/a through 2.2.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53806" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/contact-forms-anti-spam/vulnerability/wordpress-maspik-plugin-2-2-7-csrf-to-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T14:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-252q-qph8-r7q3/GHSA-252q-qph8-r7q3.json b/advisories/unreviewed/2024/12/GHSA-252q-qph8-r7q3/GHSA-252q-qph8-r7q3.json new file mode 100644 index 00000000000..af8fc050116 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-252q-qph8-r7q3/GHSA-252q-qph8-r7q3.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-252q-qph8-r7q3", + "modified": "2024-12-06T15:31:19Z", + "published": "2024-12-06T15:31:19Z", + "aliases": [ + "CVE-2024-10771" + ], + "details": "Due to missing input validation during one step of the firmware update process, the product\nis vulnerable to remote code execution. With network access and the user level ”Service”, an attacker\ncan execute arbitrary system commands in the root user’s contexts.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10771" + }, + { + "type": "WEB", + "url": "https://cdn.sick.com/media/docs/1/11/411/Special_information_CYBERSECURITY_BY_SICK_en_IM0084411.PDF" + }, + { + "type": "WEB", + "url": "https://sick.com/psirt" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" + }, + { + "type": "WEB", + "url": "https://www.first.org/cvss/calculator/3.1" + }, + { + "type": "WEB", + "url": "https://www.sick.com/.well-known/csaf/white/2024/sca-2024-0006.json" + }, + { + "type": "WEB", + "url": "https://www.sick.com/.well-known/csaf/white/2024/sca-2024-0006.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T13:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-25cw-w9h4-7x54/GHSA-25cw-w9h4-7x54.json b/advisories/unreviewed/2024/12/GHSA-25cw-w9h4-7x54/GHSA-25cw-w9h4-7x54.json new file mode 100644 index 00000000000..31c67677b1f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-25cw-w9h4-7x54/GHSA-25cw-w9h4-7x54.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-25cw-w9h4-7x54", + "modified": "2024-12-06T15:31:20Z", + "published": "2024-12-06T15:31:20Z", + "aliases": [ + "CVE-2024-51615" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Owen Cutajar & Hyder Jaffari WordPress Auction Plugin allows SQL Injection.This issue affects WordPress Auction Plugin: from n/a through 3.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51615" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-auctions/vulnerability/wordpress-wordpress-auction-plugin-plugin-3-7-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T14:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-2c82-59ww-vx6g/GHSA-2c82-59ww-vx6g.json b/advisories/unreviewed/2024/12/GHSA-2c82-59ww-vx6g/GHSA-2c82-59ww-vx6g.json new file mode 100644 index 00000000000..3ed8a57b9c8 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-2c82-59ww-vx6g/GHSA-2c82-59ww-vx6g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2c82-59ww-vx6g", + "modified": "2024-12-06T15:31:21Z", + "published": "2024-12-06T15:31:21Z", + "aliases": [ + "CVE-2024-54216" + ], + "details": "Path Traversal vulnerability in NotFound ARForms allows Path Traversal.This issue affects ARForms: from n/a through 6.4.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54216" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/arforms/vulnerability/wordpress-arforms-plugin-6-4-1-subscriber-arbitrary-file-read-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-35" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T14:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-35r4-377q-pc5v/GHSA-35r4-377q-pc5v.json b/advisories/unreviewed/2024/12/GHSA-35r4-377q-pc5v/GHSA-35r4-377q-pc5v.json index e93300563cb..7b3fc13746c 100644 --- a/advisories/unreviewed/2024/12/GHSA-35r4-377q-pc5v/GHSA-35r4-377q-pc5v.json +++ b/advisories/unreviewed/2024/12/GHSA-35r4-377q-pc5v/GHSA-35r4-377q-pc5v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-35r4-377q-pc5v", - "modified": "2024-12-05T15:31:02Z", + "modified": "2024-12-06T15:31:19Z", "published": "2024-12-05T15:31:02Z", "aliases": [ "CVE-2024-54679" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://cyberpanel.net" + }, + { + "type": "WEB", + "url": "https://github.com/hotplugin0x01/CVE-2024-54679" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/12/GHSA-3p7v-5rxq-8fw3/GHSA-3p7v-5rxq-8fw3.json b/advisories/unreviewed/2024/12/GHSA-3p7v-5rxq-8fw3/GHSA-3p7v-5rxq-8fw3.json new file mode 100644 index 00000000000..5abd8a4df18 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-3p7v-5rxq-8fw3/GHSA-3p7v-5rxq-8fw3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3p7v-5rxq-8fw3", + "modified": "2024-12-06T15:31:20Z", + "published": "2024-12-06T15:31:20Z", + "aliases": [ + "CVE-2024-54205" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Paloma Paloma Widget allows Cross Site Request Forgery.This issue affects Paloma Widget: from n/a through 1.14.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54205" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/postman-widget/vulnerability/wordpress-paloma-widget-plugin-1-14-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T14:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-3ppq-5wmg-wx3m/GHSA-3ppq-5wmg-wx3m.json b/advisories/unreviewed/2024/12/GHSA-3ppq-5wmg-wx3m/GHSA-3ppq-5wmg-wx3m.json new file mode 100644 index 00000000000..88118835e5d --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-3ppq-5wmg-wx3m/GHSA-3ppq-5wmg-wx3m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3ppq-5wmg-wx3m", + "modified": "2024-12-06T15:31:20Z", + "published": "2024-12-06T15:31:20Z", + "aliases": [ + "CVE-2024-54206" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in URBAN BASE Z-Downloads allows Stored XSS.This issue affects Z-Downloads: from n/a through 1.11.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54206" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/z-downloads/vulnerability/wordpress-z-downloads-plugin-1-11-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T14:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-3vjq-pfvj-cq2x/GHSA-3vjq-pfvj-cq2x.json b/advisories/unreviewed/2024/12/GHSA-3vjq-pfvj-cq2x/GHSA-3vjq-pfvj-cq2x.json new file mode 100644 index 00000000000..3f652be04b7 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-3vjq-pfvj-cq2x/GHSA-3vjq-pfvj-cq2x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3vjq-pfvj-cq2x", + "modified": "2024-12-06T15:31:20Z", + "published": "2024-12-06T15:31:20Z", + "aliases": [ + "CVE-2024-53801" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldThemes Bold Page Builder allows Stored XSS.This issue affects Bold Page Builder: from n/a through 5.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53801" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bold-page-builder/vulnerability/wordpress-bold-page-builder-plugin-5-2-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T14:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-3xg5-7p4x-v3wx/GHSA-3xg5-7p4x-v3wx.json b/advisories/unreviewed/2024/12/GHSA-3xg5-7p4x-v3wx/GHSA-3xg5-7p4x-v3wx.json new file mode 100644 index 00000000000..14ce054b591 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-3xg5-7p4x-v3wx/GHSA-3xg5-7p4x-v3wx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3xg5-7p4x-v3wx", + "modified": "2024-12-06T15:31:20Z", + "published": "2024-12-06T15:31:20Z", + "aliases": [ + "CVE-2024-53807" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in brandtoss WP Mailster allows Blind SQL Injection.This issue affects WP Mailster: from n/a through 1.8.16.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53807" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-mailster/vulnerability/wordpress-wp-mailster-plugin-1-8-16-0-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T14:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-4fh9-x6rv-736m/GHSA-4fh9-x6rv-736m.json b/advisories/unreviewed/2024/12/GHSA-4fh9-x6rv-736m/GHSA-4fh9-x6rv-736m.json new file mode 100644 index 00000000000..47e33acb18e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-4fh9-x6rv-736m/GHSA-4fh9-x6rv-736m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4fh9-x6rv-736m", + "modified": "2024-12-06T15:31:21Z", + "published": "2024-12-06T15:31:21Z", + "aliases": [ + "CVE-2024-42196" + ], + "details": "HCL Launch stores potentially sensitive information in log files that could be read by a local user with access to HTTP request logs.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42196" + }, + { + "type": "WEB", + "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0117910" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-4gp2-7xvm-2w2j/GHSA-4gp2-7xvm-2w2j.json b/advisories/unreviewed/2024/12/GHSA-4gp2-7xvm-2w2j/GHSA-4gp2-7xvm-2w2j.json new file mode 100644 index 00000000000..a781e5115f2 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-4gp2-7xvm-2w2j/GHSA-4gp2-7xvm-2w2j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4gp2-7xvm-2w2j", + "modified": "2024-12-06T15:31:20Z", + "published": "2024-12-06T15:31:20Z", + "aliases": [ + "CVE-2024-53794" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LOOS,Inc. Arkhe Blocks allows Stored XSS.This issue affects Arkhe Blocks: from n/a through 2.27.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53794" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/arkhe-blocks/vulnerability/wordpress-arkhe-blocks-plugin-2-27-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T14:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-4jvf-xwmx-r87h/GHSA-4jvf-xwmx-r87h.json b/advisories/unreviewed/2024/12/GHSA-4jvf-xwmx-r87h/GHSA-4jvf-xwmx-r87h.json new file mode 100644 index 00000000000..bc7b455937c --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-4jvf-xwmx-r87h/GHSA-4jvf-xwmx-r87h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4jvf-xwmx-r87h", + "modified": "2024-12-06T15:31:20Z", + "published": "2024-12-06T15:31:20Z", + "aliases": [ + "CVE-2024-53803" + ], + "details": "Missing Authorization vulnerability in brandtoss WP Mailster allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Mailster: from n/a through 1.8.16.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53803" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-mailster/vulnerability/wordpress-wp-mailster-plugin-1-8-16-0-broken-access-control-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T14:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-4wpm-wj3c-mr8r/GHSA-4wpm-wj3c-mr8r.json b/advisories/unreviewed/2024/12/GHSA-4wpm-wj3c-mr8r/GHSA-4wpm-wj3c-mr8r.json new file mode 100644 index 00000000000..5d35794421b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-4wpm-wj3c-mr8r/GHSA-4wpm-wj3c-mr8r.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4wpm-wj3c-mr8r", + "modified": "2024-12-06T15:31:19Z", + "published": "2024-12-06T15:31:19Z", + "aliases": [ + "CVE-2024-10516" + ], + "details": "The Swift Performance Lite plugin for WordPress is vulnerable to Local PHP File Inclusion in all versions up to, and including, 2.3.7.1 via the 'ajaxify' function. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10516" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/swift-performance-lite/trunk/includes/classes/class.ajax.php#L795" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/swift-performance-lite/trunk/includes/classes/class.ajax.php#L824" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3201933" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/4921f41a-a9b1-4ae2-a903-c14ed22dcc15?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T14:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-54rh-52xj-qhxm/GHSA-54rh-52xj-qhxm.json b/advisories/unreviewed/2024/12/GHSA-54rh-52xj-qhxm/GHSA-54rh-52xj-qhxm.json new file mode 100644 index 00000000000..554e5fab788 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-54rh-52xj-qhxm/GHSA-54rh-52xj-qhxm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-54rh-52xj-qhxm", + "modified": "2024-12-06T15:31:20Z", + "published": "2024-12-06T15:31:20Z", + "aliases": [ + "CVE-2024-53804" + ], + "details": "Insertion of Sensitive Information Into Sent Data vulnerability in brandtoss WP Mailster allows Retrieve Embedded Sensitive Data.This issue affects WP Mailster: from n/a through 1.8.16.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53804" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-mailster/vulnerability/wordpress-wp-mailster-plugin-1-8-16-0-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-201" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T14:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-5fmx-vhp4-m6xv/GHSA-5fmx-vhp4-m6xv.json b/advisories/unreviewed/2024/12/GHSA-5fmx-vhp4-m6xv/GHSA-5fmx-vhp4-m6xv.json new file mode 100644 index 00000000000..4b6a5875e33 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-5fmx-vhp4-m6xv/GHSA-5fmx-vhp4-m6xv.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5fmx-vhp4-m6xv", + "modified": "2024-12-06T15:31:19Z", + "published": "2024-12-06T15:31:19Z", + "aliases": [ + "CVE-2024-11022" + ], + "details": "The authentication process to the web server uses a challenge response procedure which\ninludes the nonce and additional information. This challenge can be used several times for login and is\ntherefore vulnerable for a replay attack.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11022" + }, + { + "type": "WEB", + "url": "https://cdn.sick.com/media/docs/1/11/411/Special_information_CYBERSECURITY_BY_SICK_en_IM0084411.PDF" + }, + { + "type": "WEB", + "url": "https://sick.com/psirt" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" + }, + { + "type": "WEB", + "url": "https://www.first.org/cvss/calculator/3.1" + }, + { + "type": "WEB", + "url": "https://www.sick.com/.well-known/csaf/white/2024/sca-2024-0006.json" + }, + { + "type": "WEB", + "url": "https://www.sick.com/.well-known/csaf/white/2024/sca-2024-0006.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-323" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T13:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-67vc-4xc5-53x7/GHSA-67vc-4xc5-53x7.json b/advisories/unreviewed/2024/12/GHSA-67vc-4xc5-53x7/GHSA-67vc-4xc5-53x7.json new file mode 100644 index 00000000000..dac1e6621a6 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-67vc-4xc5-53x7/GHSA-67vc-4xc5-53x7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-67vc-4xc5-53x7", + "modified": "2024-12-06T15:31:20Z", + "published": "2024-12-06T15:31:20Z", + "aliases": [ + "CVE-2024-53824" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AREOI All Bootstrap Blocks allows PHP Local File Inclusion.This issue affects All Bootstrap Blocks: from n/a through 1.3.19.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53824" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/all-bootstrap-blocks/vulnerability/wordpress-all-bootstrap-blocks-plugin-1-3-20-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T14:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-6w93-crhf-283q/GHSA-6w93-crhf-283q.json b/advisories/unreviewed/2024/12/GHSA-6w93-crhf-283q/GHSA-6w93-crhf-283q.json new file mode 100644 index 00000000000..510cf82069e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-6w93-crhf-283q/GHSA-6w93-crhf-283q.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6w93-crhf-283q", + "modified": "2024-12-06T15:31:19Z", + "published": "2024-12-06T15:31:19Z", + "aliases": [ + "CVE-2024-10776" + ], + "details": "Lua apps can be deployed, removed, started, reloaded or stopped without authorization via\nAppManager. This allows an attacker to remove legitimate apps creating a DoS attack, read and write\nfiles or load apps that use all features of the product available to a customer.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10776" + }, + { + "type": "WEB", + "url": "https://cdn.sick.com/media/docs/1/11/411/Special_information_CYBERSECURITY_BY_SICK_en_IM0084411.PDF" + }, + { + "type": "WEB", + "url": "https://sick.com/psirt" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" + }, + { + "type": "WEB", + "url": "https://www.first.org/cvss/calculator/3.1" + }, + { + "type": "WEB", + "url": "https://www.sick.com/.well-known/csaf/white/2024/sca-2024-0006.json" + }, + { + "type": "WEB", + "url": "https://www.sick.com/.well-known/csaf/white/2024/sca-2024-0006.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T13:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-7jrc-cqc8-pcqm/GHSA-7jrc-cqc8-pcqm.json b/advisories/unreviewed/2024/12/GHSA-7jrc-cqc8-pcqm/GHSA-7jrc-cqc8-pcqm.json new file mode 100644 index 00000000000..9f31c1ec211 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-7jrc-cqc8-pcqm/GHSA-7jrc-cqc8-pcqm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7jrc-cqc8-pcqm", + "modified": "2024-12-06T15:31:20Z", + "published": "2024-12-06T15:31:20Z", + "aliases": [ + "CVE-2024-53802" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FuturioWP Futurio Extra allows Stored XSS.This issue affects Futurio Extra: from n/a through 2.0.14.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53802" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/futurio-extra/vulnerability/wordpress-futurio-extra-plugin-2-0-14-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T14:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-7x9g-hpvh-hwph/GHSA-7x9g-hpvh-hwph.json b/advisories/unreviewed/2024/12/GHSA-7x9g-hpvh-hwph/GHSA-7x9g-hpvh-hwph.json new file mode 100644 index 00000000000..a0a43160d97 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-7x9g-hpvh-hwph/GHSA-7x9g-hpvh-hwph.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7x9g-hpvh-hwph", + "modified": "2024-12-06T15:31:20Z", + "published": "2024-12-06T15:31:20Z", + "aliases": [ + "CVE-2024-53817" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Acowebs Product Labels For Woocommerce allows Blind SQL Injection.This issue affects Product Labels For Woocommerce: from n/a through 1.5.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53817" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/aco-product-labels-for-woocommerce/vulnerability/wordpress-acowebs-product-labels-for-woocommerce-plugin-1-5-8-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T14:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-83hw-j99p-2rr2/GHSA-83hw-j99p-2rr2.json b/advisories/unreviewed/2024/12/GHSA-83hw-j99p-2rr2/GHSA-83hw-j99p-2rr2.json new file mode 100644 index 00000000000..ebd257e0bd8 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-83hw-j99p-2rr2/GHSA-83hw-j99p-2rr2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-83hw-j99p-2rr2", + "modified": "2024-12-06T15:31:20Z", + "published": "2024-12-06T15:31:20Z", + "aliases": [ + "CVE-2024-53815" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PINPOINT.WORLD Pinpoint Booking System allows Blind SQL Injection.This issue affects Pinpoint Booking System: from n/a through 2.9.9.5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53815" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/booking-system/vulnerability/wordpress-pinpoint-booking-system-plugin-2-9-9-5-2-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T14:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-9fhv-36q2-hmq8/GHSA-9fhv-36q2-hmq8.json b/advisories/unreviewed/2024/12/GHSA-9fhv-36q2-hmq8/GHSA-9fhv-36q2-hmq8.json new file mode 100644 index 00000000000..9c09adf510e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-9fhv-36q2-hmq8/GHSA-9fhv-36q2-hmq8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9fhv-36q2-hmq8", + "modified": "2024-12-06T15:31:20Z", + "published": "2024-12-06T15:31:20Z", + "aliases": [ + "CVE-2024-54207" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Owen Cutajar & Hyder Jaffari WordPress Auction Plugin allows Stored XSS.This issue affects WordPress Auction Plugin: from n/a through 3.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54207" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-auctions/vulnerability/wordpress-wordpress-auction-plugin-plugin-3-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T14:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-9fvw-m753-cp9f/GHSA-9fvw-m753-cp9f.json b/advisories/unreviewed/2024/12/GHSA-9fvw-m753-cp9f/GHSA-9fvw-m753-cp9f.json new file mode 100644 index 00000000000..578d1891326 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-9fvw-m753-cp9f/GHSA-9fvw-m753-cp9f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9fvw-m753-cp9f", + "modified": "2024-12-06T15:31:20Z", + "published": "2024-12-06T15:31:20Z", + "aliases": [ + "CVE-2024-53810" + ], + "details": "Missing Authorization vulnerability in Najeeb Ahmad Simple User Registration allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Simple User Registration: from n/a through 5.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53810" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-registration/vulnerability/wordpress-simple-user-registration-plugin-5-5-broken-access-control-on-user-deletion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T14:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-cf6c-548r-42f5/GHSA-cf6c-548r-42f5.json b/advisories/unreviewed/2024/12/GHSA-cf6c-548r-42f5/GHSA-cf6c-548r-42f5.json new file mode 100644 index 00000000000..e09c1a2323b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-cf6c-548r-42f5/GHSA-cf6c-548r-42f5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cf6c-548r-42f5", + "modified": "2024-12-06T15:31:19Z", + "published": "2024-12-06T15:31:19Z", + "aliases": [ + "CVE-2024-21571" + ], + "details": "Snyk has identified a remote code execution (RCE) vulnerability in all versions of Code Agent. The vulnerability enables an attacker to execute arbitrary code within the Code Agent container. Exploiting this vulnerability would require an attacker to have network access to the Code Agent within the deployment environment. External exploitation of this vulnerability is unlikely and depends on both misconfigurations of the cluster and/or chaining with another vulnerability. However, internal exploitation (with a cluster misconfiguration) could still be possible.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21571" + }, + { + "type": "WEB", + "url": "https://www.cve.org/CVERecord?id=CVE-2024-21571" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T14:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-f7j8-7c7g-3h29/GHSA-f7j8-7c7g-3h29.json b/advisories/unreviewed/2024/12/GHSA-f7j8-7c7g-3h29/GHSA-f7j8-7c7g-3h29.json new file mode 100644 index 00000000000..5841da0fa9e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-f7j8-7c7g-3h29/GHSA-f7j8-7c7g-3h29.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f7j8-7c7g-3h29", + "modified": "2024-12-06T15:31:20Z", + "published": "2024-12-06T15:31:20Z", + "aliases": [ + "CVE-2024-53799" + ], + "details": "Missing Authorization vulnerability in BAKKBONE Australia FloristPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FloristPress: from n/a through 7.3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53799" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bakkbone-florist-companion/vulnerability/wordpress-floristpress-plugin-7-3-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T14:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-f9rf-87q8-mcm5/GHSA-f9rf-87q8-mcm5.json b/advisories/unreviewed/2024/12/GHSA-f9rf-87q8-mcm5/GHSA-f9rf-87q8-mcm5.json new file mode 100644 index 00000000000..ecea296b96c --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-f9rf-87q8-mcm5/GHSA-f9rf-87q8-mcm5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f9rf-87q8-mcm5", + "modified": "2024-12-06T15:31:20Z", + "published": "2024-12-06T15:31:20Z", + "aliases": [ + "CVE-2024-53813" + ], + "details": "Missing Authorization vulnerability in WP Travel WP Travel allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Travel: from n/a through 9.6.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53813" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-travel/vulnerability/wordpress-wp-travel-plugin-9-6-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T14:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-fc75-978w-cw6p/GHSA-fc75-978w-cw6p.json b/advisories/unreviewed/2024/12/GHSA-fc75-978w-cw6p/GHSA-fc75-978w-cw6p.json new file mode 100644 index 00000000000..fbad1dc67aa --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-fc75-978w-cw6p/GHSA-fc75-978w-cw6p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fc75-978w-cw6p", + "modified": "2024-12-06T15:31:20Z", + "published": "2024-12-06T15:31:20Z", + "aliases": [ + "CVE-2024-53820" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Captivate Audio Ltd Captivate Sync allows Stored XSS.This issue affects Captivate Sync: from n/a through 2.0.22.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53820" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/captivatesync-trade/vulnerability/wordpress-captivate-sync-plugin-2-0-22-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T14:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-fggw-qcx2-vr8w/GHSA-fggw-qcx2-vr8w.json b/advisories/unreviewed/2024/12/GHSA-fggw-qcx2-vr8w/GHSA-fggw-qcx2-vr8w.json new file mode 100644 index 00000000000..fff792a25b8 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-fggw-qcx2-vr8w/GHSA-fggw-qcx2-vr8w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fggw-qcx2-vr8w", + "modified": "2024-12-06T15:31:20Z", + "published": "2024-12-06T15:31:20Z", + "aliases": [ + "CVE-2024-53805" + ], + "details": "Missing Authorization vulnerability in brandtoss WP Mailster allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Mailster: from n/a through 1.8.16.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53805" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-mailster/vulnerability/wordpress-wp-mailster-plugin-1-8-16-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T14:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-fj85-3hpv-97rg/GHSA-fj85-3hpv-97rg.json b/advisories/unreviewed/2024/12/GHSA-fj85-3hpv-97rg/GHSA-fj85-3hpv-97rg.json new file mode 100644 index 00000000000..7bcef9fa64b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-fj85-3hpv-97rg/GHSA-fj85-3hpv-97rg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fj85-3hpv-97rg", + "modified": "2024-12-06T15:31:20Z", + "published": "2024-12-06T15:31:20Z", + "aliases": [ + "CVE-2024-51815" + ], + "details": "Improper Control of Generation of Code ('Code Injection') vulnerability in WP Sharks s2Member Pro allows Code Injection.This issue affects s2Member Pro: from n/a through 241114.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51815" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/s2member/vulnerability/wordpress-s2member-excellent-for-all-kinds-of-memberships-content-restriction-paywalls-member-access-subscriptions-plugin-241114-remote-code-execution-rce-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T14:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-fp23-h56v-c55g/GHSA-fp23-h56v-c55g.json b/advisories/unreviewed/2024/12/GHSA-fp23-h56v-c55g/GHSA-fp23-h56v-c55g.json new file mode 100644 index 00000000000..63917e63c79 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-fp23-h56v-c55g/GHSA-fp23-h56v-c55g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fp23-h56v-c55g", + "modified": "2024-12-06T15:31:21Z", + "published": "2024-12-06T15:31:21Z", + "aliases": [ + "CVE-2024-54210" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexShaper Advanced Element Bucket Addons for Elementor allows Stored XSS.This issue affects Advanced Element Bucket Addons for Elementor: from n/a through 1.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54210" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cs-element-bucket/vulnerability/wordpress-advanced-element-bucket-addons-for-elementor-plugin-1-0-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T14:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-g8f8-c79p-f44c/GHSA-g8f8-c79p-f44c.json b/advisories/unreviewed/2024/12/GHSA-g8f8-c79p-f44c/GHSA-g8f8-c79p-f44c.json new file mode 100644 index 00000000000..c807db21e58 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-g8f8-c79p-f44c/GHSA-g8f8-c79p-f44c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g8f8-c79p-f44c", + "modified": "2024-12-06T15:31:21Z", + "published": "2024-12-06T15:31:21Z", + "aliases": [ + "CVE-2024-54209" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Awesome Shortcodes allows Reflected XSS.This issue affects Awesome Shortcodes: from n/a through 1.7.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54209" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/awesome-shortcodes/vulnerability/wordpress-awesome-shortcodes-plugin-1-7-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T14:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-h4j8-v47m-2gc3/GHSA-h4j8-v47m-2gc3.json b/advisories/unreviewed/2024/12/GHSA-h4j8-v47m-2gc3/GHSA-h4j8-v47m-2gc3.json new file mode 100644 index 00000000000..a8e706c1206 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-h4j8-v47m-2gc3/GHSA-h4j8-v47m-2gc3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h4j8-v47m-2gc3", + "modified": "2024-12-06T15:31:20Z", + "published": "2024-12-06T15:31:20Z", + "aliases": [ + "CVE-2024-53811" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in POSIMYTH WDesignkit allows Upload a Web Shell to a Web Server.This issue affects WDesignkit: from n/a through 1.0.40.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53811" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wdesignkit/vulnerability/wordpress-wdesignkit-plugin-1-0-40-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T14:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-jgq7-824c-7pf2/GHSA-jgq7-824c-7pf2.json b/advisories/unreviewed/2024/12/GHSA-jgq7-824c-7pf2/GHSA-jgq7-824c-7pf2.json new file mode 100644 index 00000000000..17d069bddbe --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-jgq7-824c-7pf2/GHSA-jgq7-824c-7pf2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jgq7-824c-7pf2", + "modified": "2024-12-06T15:31:21Z", + "published": "2024-12-06T15:31:21Z", + "aliases": [ + "CVE-2024-54212" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor alam Magical Addons For Elementor allows Stored XSS.This issue affects Magical Addons For Elementor: from n/a through 1.2.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54212" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/magical-addons-for-elementor/vulnerability/wordpress-magical-addons-for-elementor-plugin-1-2-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T14:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-jpp3-g63p-46vv/GHSA-jpp3-g63p-46vv.json b/advisories/unreviewed/2024/12/GHSA-jpp3-g63p-46vv/GHSA-jpp3-g63p-46vv.json new file mode 100644 index 00000000000..55456c87ca4 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-jpp3-g63p-46vv/GHSA-jpp3-g63p-46vv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jpp3-g63p-46vv", + "modified": "2024-12-06T15:31:20Z", + "published": "2024-12-06T15:31:20Z", + "aliases": [ + "CVE-2024-53821" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Pie Register Premium allows Reflected XSS.This issue affects Pie Register Premium: from n/a through n/a.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53821" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/pie-register-premium/vulnerability/wordpress-pie-register-premium-plugin-3-8-3-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T14:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-m74c-c3qx-pxjq/GHSA-m74c-c3qx-pxjq.json b/advisories/unreviewed/2024/12/GHSA-m74c-c3qx-pxjq/GHSA-m74c-c3qx-pxjq.json new file mode 100644 index 00000000000..0758265fc31 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-m74c-c3qx-pxjq/GHSA-m74c-c3qx-pxjq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m74c-c3qx-pxjq", + "modified": "2024-12-06T15:31:20Z", + "published": "2024-12-06T15:31:20Z", + "aliases": [ + "CVE-2024-54208" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joni Halabi Block Controller allows Reflected XSS.This issue affects Block Controller: from n/a through 1.4.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54208" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/block-controller/vulnerability/wordpress-block-controller-plugin-1-4-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T14:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-mj32-rr2c-j468/GHSA-mj32-rr2c-j468.json b/advisories/unreviewed/2024/12/GHSA-mj32-rr2c-j468/GHSA-mj32-rr2c-j468.json new file mode 100644 index 00000000000..99bc75eb30d --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-mj32-rr2c-j468/GHSA-mj32-rr2c-j468.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mj32-rr2c-j468", + "modified": "2024-12-06T15:31:20Z", + "published": "2024-12-06T15:31:20Z", + "aliases": [ + "CVE-2024-52335" + ], + "details": "A vulnerability has been identified in syngo.plaza VB30E (All versions < VB30E_HF05). The affected application do not properly sanitize input data before sending it to the SQL server. This could allow an attacker with access to the application could use this vulnerability to execute malicious SQL commands to compromise the whole database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52335" + }, + { + "type": "WEB", + "url": "https://www.siemens-healthineers.com/en-us/support-documentation/cybersecurity/shsa-160244" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T14:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-p53w-4276-mx6q/GHSA-p53w-4276-mx6q.json b/advisories/unreviewed/2024/12/GHSA-p53w-4276-mx6q/GHSA-p53w-4276-mx6q.json new file mode 100644 index 00000000000..d8137689bed --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-p53w-4276-mx6q/GHSA-p53w-4276-mx6q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p53w-4276-mx6q", + "modified": "2024-12-06T15:31:20Z", + "published": "2024-12-06T15:31:20Z", + "aliases": [ + "CVE-2024-53809" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Kiboko Labs Namaste! LMS allows Cross Site Request Forgery.This issue affects Namaste! LMS: from n/a through 2.6.4.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53809" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/namaste-lms/vulnerability/wordpress-namaste-lms-plugin-2-6-4-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T14:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-q2r2-qcp6-8r5j/GHSA-q2r2-qcp6-8r5j.json b/advisories/unreviewed/2024/12/GHSA-q2r2-qcp6-8r5j/GHSA-q2r2-qcp6-8r5j.json new file mode 100644 index 00000000000..915b085f92f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-q2r2-qcp6-8r5j/GHSA-q2r2-qcp6-8r5j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q2r2-qcp6-8r5j", + "modified": "2024-12-06T15:31:20Z", + "published": "2024-12-06T15:31:20Z", + "aliases": [ + "CVE-2024-53826" + ], + "details": "Missing Authorization vulnerability in WPSight WPCasa allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPCasa: from n/a through 1.2.13.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53826" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpcasa/vulnerability/wordpress-wpcasa-plugin-1-2-13-insecure-direct-object-references-idor-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T14:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-q44m-hgj6-jq7m/GHSA-q44m-hgj6-jq7m.json b/advisories/unreviewed/2024/12/GHSA-q44m-hgj6-jq7m/GHSA-q44m-hgj6-jq7m.json new file mode 100644 index 00000000000..1390e93a309 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-q44m-hgj6-jq7m/GHSA-q44m-hgj6-jq7m.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q44m-hgj6-jq7m", + "modified": "2024-12-06T15:31:19Z", + "published": "2024-12-06T15:31:19Z", + "aliases": [ + "CVE-2024-10774" + ], + "details": "Unauthenticated CROWN APIs allow access to critical functions. This leads to the accessibility of large parts of the web application without authentication.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10774" + }, + { + "type": "WEB", + "url": "https://cdn.sick.com/media/docs/1/11/411/Special_information_CYBERSECURITY_BY_SICK_en_IM0084411.PDF" + }, + { + "type": "WEB", + "url": "https://sick.com/psirt" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" + }, + { + "type": "WEB", + "url": "https://www.first.org/cvss/calculator/3.1" + }, + { + "type": "WEB", + "url": "https://www.sick.com/.well-known/csaf/white/2024/sca-2024-0006.json" + }, + { + "type": "WEB", + "url": "https://www.sick.com/.well-known/csaf/white/2024/sca-2024-0006.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T13:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-q96x-v8cx-4pmm/GHSA-q96x-v8cx-4pmm.json b/advisories/unreviewed/2024/12/GHSA-q96x-v8cx-4pmm/GHSA-q96x-v8cx-4pmm.json new file mode 100644 index 00000000000..570e390f95b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-q96x-v8cx-4pmm/GHSA-q96x-v8cx-4pmm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q96x-v8cx-4pmm", + "modified": "2024-12-06T15:31:21Z", + "published": "2024-12-06T15:31:21Z", + "aliases": [ + "CVE-2024-54211" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visualmodo Borderless allows Cross-Site Scripting (XSS).This issue affects Borderless: from n/a through 1.5.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54211" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/borderless/vulnerability/wordpress-borderless-widgets-elements-templates-and-toolkit-for-elementor-gutenberg-plugin-1-5-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T14:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-r445-hj7p-4m84/GHSA-r445-hj7p-4m84.json b/advisories/unreviewed/2024/12/GHSA-r445-hj7p-4m84/GHSA-r445-hj7p-4m84.json new file mode 100644 index 00000000000..3eb6711c9b4 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-r445-hj7p-4m84/GHSA-r445-hj7p-4m84.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r445-hj7p-4m84", + "modified": "2024-12-06T15:31:20Z", + "published": "2024-12-06T15:31:20Z", + "aliases": [ + "CVE-2024-53823" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH The Plus Addons for Elementor Page Builder Lite allows DOM-Based XSS.This issue affects The Plus Addons for Elementor Page Builder Lite: from n/a through 5.6.14.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53823" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/the-plus-addons-for-elementor-page-builder/vulnerability/wordpress-the-plus-addons-for-elementor-plugin-5-6-14-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T14:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-r5xc-6chv-hc86/GHSA-r5xc-6chv-hc86.json b/advisories/unreviewed/2024/12/GHSA-r5xc-6chv-hc86/GHSA-r5xc-6chv-hc86.json new file mode 100644 index 00000000000..f8c922c851f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-r5xc-6chv-hc86/GHSA-r5xc-6chv-hc86.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r5xc-6chv-hc86", + "modified": "2024-12-06T15:31:20Z", + "published": "2024-12-06T15:31:20Z", + "aliases": [ + "CVE-2024-53795" + ], + "details": "Missing Authorization vulnerability in Andy Moyle Church Admin allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Church Admin: from n/a through 5.0.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53795" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/church-admin/vulnerability/wordpress-church-admin-plugin-5-0-8-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T14:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-r97p-4233-hch5/GHSA-r97p-4233-hch5.json b/advisories/unreviewed/2024/12/GHSA-r97p-4233-hch5/GHSA-r97p-4233-hch5.json new file mode 100644 index 00000000000..360d1793378 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-r97p-4233-hch5/GHSA-r97p-4233-hch5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r97p-4233-hch5", + "modified": "2024-12-06T15:31:20Z", + "published": "2024-12-06T15:31:20Z", + "aliases": [ + "CVE-2024-53825" + ], + "details": "Missing Authorization vulnerability in Ninja Team Filebird allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Filebird: from n/a through 6.3.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53825" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/filebird/vulnerability/wordpress-filebird-lite-plugin-6-3-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T14:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-v844-f5wm-8pvv/GHSA-v844-f5wm-8pvv.json b/advisories/unreviewed/2024/12/GHSA-v844-f5wm-8pvv/GHSA-v844-f5wm-8pvv.json new file mode 100644 index 00000000000..4b8c56425f2 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-v844-f5wm-8pvv/GHSA-v844-f5wm-8pvv.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v844-f5wm-8pvv", + "modified": "2024-12-06T15:31:20Z", + "published": "2024-12-06T15:31:20Z", + "aliases": [ + "CVE-2024-4633" + ], + "details": "The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘addExtraMimeType’ function in versions up to, and including, 3.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4633" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/depicter/tags/2.1.11/app/src/WordPress/SVGServiceProvider.php#L52" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3134888" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/965cacd3-1786-4e7d-8209-eea293b161d3?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T14:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-w6g7-8frf-qg2g/GHSA-w6g7-8frf-qg2g.json b/advisories/unreviewed/2024/12/GHSA-w6g7-8frf-qg2g/GHSA-w6g7-8frf-qg2g.json new file mode 100644 index 00000000000..18f064caa23 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-w6g7-8frf-qg2g/GHSA-w6g7-8frf-qg2g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w6g7-8frf-qg2g", + "modified": "2024-12-06T15:31:20Z", + "published": "2024-12-06T15:31:20Z", + "aliases": [ + "CVE-2024-53797" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in The Beaver Builder Team Beaver Builder allows Stored XSS.This issue affects Beaver Builder: from n/a through 2.8.4.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53797" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/beaver-builder-lite-version/vulnerability/wordpress-beaver-builder-wordpress-page-builder-plugin-2-8-4-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T14:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-wjcf-9gjx-gf27/GHSA-wjcf-9gjx-gf27.json b/advisories/unreviewed/2024/12/GHSA-wjcf-9gjx-gf27/GHSA-wjcf-9gjx-gf27.json new file mode 100644 index 00000000000..e942e57bcf6 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-wjcf-9gjx-gf27/GHSA-wjcf-9gjx-gf27.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wjcf-9gjx-gf27", + "modified": "2024-12-06T15:31:21Z", + "published": "2024-12-06T15:31:21Z", + "aliases": [ + "CVE-2024-54214" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in NotFound Revy allows Upload a Web Shell to a Web Server.This issue affects Revy: from n/a through 1.18.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54214" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/revy/vulnerability/wordpress-revy-plugin-1-18-unauthenticated-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T14:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-wpfg-9fq6-2279/GHSA-wpfg-9fq6-2279.json b/advisories/unreviewed/2024/12/GHSA-wpfg-9fq6-2279/GHSA-wpfg-9fq6-2279.json new file mode 100644 index 00000000000..86f018daaae --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-wpfg-9fq6-2279/GHSA-wpfg-9fq6-2279.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wpfg-9fq6-2279", + "modified": "2024-12-06T15:31:20Z", + "published": "2024-12-06T15:31:20Z", + "aliases": [ + "CVE-2024-53812" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jacques Malgrange WP GeoNames allows Reflected XSS.This issue affects WP GeoNames: from n/a through 1.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53812" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-geonames/vulnerability/wordpress-wp-geonames-plugin-1-8-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T14:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-x446-9q7v-mqrc/GHSA-x446-9q7v-mqrc.json b/advisories/unreviewed/2024/12/GHSA-x446-9q7v-mqrc/GHSA-x446-9q7v-mqrc.json new file mode 100644 index 00000000000..35687ec190d --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-x446-9q7v-mqrc/GHSA-x446-9q7v-mqrc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x446-9q7v-mqrc", + "modified": "2024-12-06T15:31:21Z", + "published": "2024-12-06T15:31:21Z", + "aliases": [ + "CVE-2024-54213" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zionbuilder.io WordPress Page Builder – Zion Builder allows Stored XSS.This issue affects WordPress Page Builder – Zion Builder: from n/a through 3.6.12.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54213" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/zionbuilder/vulnerability/wordpress-wordpress-page-builder-zion-builder-plugin-3-6-12-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T14:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-x46h-g6vh-9qm7/GHSA-x46h-g6vh-9qm7.json b/advisories/unreviewed/2024/12/GHSA-x46h-g6vh-9qm7/GHSA-x46h-g6vh-9qm7.json new file mode 100644 index 00000000000..e3ea82d210b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-x46h-g6vh-9qm7/GHSA-x46h-g6vh-9qm7.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x46h-g6vh-9qm7", + "modified": "2024-12-06T15:31:19Z", + "published": "2024-12-06T15:31:19Z", + "aliases": [ + "CVE-2024-10773" + ], + "details": "The product is vulnerable to pass-the-hash attacks in combination with hardcoded credentials of hidden user levels. This means that an attacker can log in with the hidden user levels and gain\nfull access to the device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10773" + }, + { + "type": "WEB", + "url": "https://cdn.sick.com/media/docs/1/11/411/Special_information_CYBERSECURITY_BY_SICK_en_IM0084411.PDF" + }, + { + "type": "WEB", + "url": "https://sick.com/psirt" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" + }, + { + "type": "WEB", + "url": "https://www.first.org/cvss/calculator/3.1" + }, + { + "type": "WEB", + "url": "https://www.sick.com/.well-known/csaf/white/2024/sca-2024-0006.json" + }, + { + "type": "WEB", + "url": "https://www.sick.com/.well-known/csaf/white/2024/sca-2024-0006.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-912" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T13:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-x758-w7gj-hvxf/GHSA-x758-w7gj-hvxf.json b/advisories/unreviewed/2024/12/GHSA-x758-w7gj-hvxf/GHSA-x758-w7gj-hvxf.json new file mode 100644 index 00000000000..1d083152746 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-x758-w7gj-hvxf/GHSA-x758-w7gj-hvxf.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x758-w7gj-hvxf", + "modified": "2024-12-06T15:31:19Z", + "published": "2024-12-06T15:31:19Z", + "aliases": [ + "CVE-2024-10772" + ], + "details": "Since the firmware update is not validated, an attacker can install modified firmware on the\ndevice. This has a high impact on the availabilty, integrity and confidentiality up to the complete compromise of the device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10772" + }, + { + "type": "WEB", + "url": "https://cdn.sick.com/media/docs/1/11/411/Special_information_CYBERSECURITY_BY_SICK_en_IM0084411.PDF" + }, + { + "type": "WEB", + "url": "https://sick.com/psirt" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" + }, + { + "type": "WEB", + "url": "https://www.first.org/cvss/calculator/3.1" + }, + { + "type": "WEB", + "url": "https://www.sick.com/.well-known/csaf/white/2024/sca-2024-0006.json" + }, + { + "type": "WEB", + "url": "https://www.sick.com/.well-known/csaf/white/2024/sca-2024-0006.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-649" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T13:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-x9fc-mm98-wwj6/GHSA-x9fc-mm98-wwj6.json b/advisories/unreviewed/2024/12/GHSA-x9fc-mm98-wwj6/GHSA-x9fc-mm98-wwj6.json new file mode 100644 index 00000000000..12870be6f4f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-x9fc-mm98-wwj6/GHSA-x9fc-mm98-wwj6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x9fc-mm98-wwj6", + "modified": "2024-12-06T15:31:19Z", + "published": "2024-12-06T15:31:19Z", + "aliases": [ + "CVE-2024-11321" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Hi e-learning Learning Management System (LMS) allows Reflected XSS.This issue affects Learning Management System (LMS): before 06.12.2024.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11321" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-24-1878" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T14:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-xr6j-9xr6-9xr7/GHSA-xr6j-9xr6-9xr7.json b/advisories/unreviewed/2024/12/GHSA-xr6j-9xr6-9xr7/GHSA-xr6j-9xr6-9xr7.json new file mode 100644 index 00000000000..bf713ebf6ee --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-xr6j-9xr6-9xr7/GHSA-xr6j-9xr6-9xr7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xr6j-9xr6-9xr7", + "modified": "2024-12-06T15:31:20Z", + "published": "2024-12-06T15:31:20Z", + "aliases": [ + "CVE-2024-53796" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themesflat Themesflat Addons For Elementor allows DOM-Based XSS.This issue affects Themesflat Addons For Elementor: from n/a through 2.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53796" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/themesflat-addons-for-elementor/vulnerability/wordpress-themesflat-addons-for-elementor-plugin-2-2-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T14:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-xvwr-jcvg-47ph/GHSA-xvwr-jcvg-47ph.json b/advisories/unreviewed/2024/12/GHSA-xvwr-jcvg-47ph/GHSA-xvwr-jcvg-47ph.json new file mode 100644 index 00000000000..0990efef5f0 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-xvwr-jcvg-47ph/GHSA-xvwr-jcvg-47ph.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xvwr-jcvg-47ph", + "modified": "2024-12-06T15:31:20Z", + "published": "2024-12-06T15:31:20Z", + "aliases": [ + "CVE-2024-53808" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Basix NEX-Forms – Ultimate Form Builder allows SQL Injection.This issue affects NEX-Forms – Ultimate Form Builder: from n/a through 8.7.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53808" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/nex-forms-express-wp-form-builder/vulnerability/wordpress-nex-forms-plugin-8-7-8-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-06T14:15:23Z" + } +} \ No newline at end of file