diff --git a/advisories/unreviewed/2022/05/GHSA-7q5w-8wg2-xwr7/GHSA-7q5w-8wg2-xwr7.json b/advisories/unreviewed/2022/05/GHSA-7q5w-8wg2-xwr7/GHSA-7q5w-8wg2-xwr7.json index 559aa846c30..d9c3dea796d 100644 --- a/advisories/unreviewed/2022/05/GHSA-7q5w-8wg2-xwr7/GHSA-7q5w-8wg2-xwr7.json +++ b/advisories/unreviewed/2022/05/GHSA-7q5w-8wg2-xwr7/GHSA-7q5w-8wg2-xwr7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7q5w-8wg2-xwr7", - "modified": "2022-05-24T19:09:41Z", + "modified": "2024-10-17T18:31:30Z", "published": "2022-05-24T19:09:41Z", "aliases": [ "CVE-2017-18113" ], "details": "The DefaultOSWorkflowConfigurator class in Jira Server and Jira Data Center before version 8.18.1 allows remote attackers who can trick a system administrator to import their malicious workflow to execute arbitrary code via a Remote Code Execution (RCE) vulnerability. The vulnerability allowed for various problematic OSWorkflow classes to be used as part of workflows. The fix for this issue blocks usage of unsafe conditions, validators, functions and registers that are build-in into OSWorkflow library and other Jira dependencies. Atlassian-made functions or functions provided by 3rd party plugins are not affected by this fix.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-jxv7-5f9p-6rg2/GHSA-jxv7-5f9p-6rg2.json b/advisories/unreviewed/2022/05/GHSA-jxv7-5f9p-6rg2/GHSA-jxv7-5f9p-6rg2.json index 000e05c6be8..4126dc247d8 100644 --- a/advisories/unreviewed/2022/05/GHSA-jxv7-5f9p-6rg2/GHSA-jxv7-5f9p-6rg2.json +++ b/advisories/unreviewed/2022/05/GHSA-jxv7-5f9p-6rg2/GHSA-jxv7-5f9p-6rg2.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-863" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/08/GHSA-8262-vqgw-h22m/GHSA-8262-vqgw-h22m.json b/advisories/unreviewed/2023/08/GHSA-8262-vqgw-h22m/GHSA-8262-vqgw-h22m.json index aeda479ecfe..b4d97c62a5e 100644 --- a/advisories/unreviewed/2023/08/GHSA-8262-vqgw-h22m/GHSA-8262-vqgw-h22m.json +++ b/advisories/unreviewed/2023/08/GHSA-8262-vqgw-h22m/GHSA-8262-vqgw-h22m.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/08/GHSA-c8rw-rc58-gq7x/GHSA-c8rw-rc58-gq7x.json b/advisories/unreviewed/2023/08/GHSA-c8rw-rc58-gq7x/GHSA-c8rw-rc58-gq7x.json index 3974a1fcb6b..b38fcc67c57 100644 --- a/advisories/unreviewed/2023/08/GHSA-c8rw-rc58-gq7x/GHSA-c8rw-rc58-gq7x.json +++ b/advisories/unreviewed/2023/08/GHSA-c8rw-rc58-gq7x/GHSA-c8rw-rc58-gq7x.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-116", "CWE-20" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/10/GHSA-5f5r-qwxj-xhxq/GHSA-5f5r-qwxj-xhxq.json b/advisories/unreviewed/2023/10/GHSA-5f5r-qwxj-xhxq/GHSA-5f5r-qwxj-xhxq.json index dd3f4d83881..df894335364 100644 --- a/advisories/unreviewed/2023/10/GHSA-5f5r-qwxj-xhxq/GHSA-5f5r-qwxj-xhxq.json +++ b/advisories/unreviewed/2023/10/GHSA-5f5r-qwxj-xhxq/GHSA-5f5r-qwxj-xhxq.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-78" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-54qf-h346-xgmg/GHSA-54qf-h346-xgmg.json b/advisories/unreviewed/2024/02/GHSA-54qf-h346-xgmg/GHSA-54qf-h346-xgmg.json index 07201cc035b..402deee36be 100644 --- a/advisories/unreviewed/2024/02/GHSA-54qf-h346-xgmg/GHSA-54qf-h346-xgmg.json +++ b/advisories/unreviewed/2024/02/GHSA-54qf-h346-xgmg/GHSA-54qf-h346-xgmg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-54qf-h346-xgmg", - "modified": "2024-02-13T21:30:29Z", + "modified": "2024-10-17T18:31:31Z", "published": "2024-02-13T21:30:29Z", "aliases": [ "CVE-2024-1082" diff --git a/advisories/unreviewed/2024/02/GHSA-hwq5-wx3r-8r5g/GHSA-hwq5-wx3r-8r5g.json b/advisories/unreviewed/2024/02/GHSA-hwq5-wx3r-8r5g/GHSA-hwq5-wx3r-8r5g.json index 343768bda57..36f3c486ec4 100644 --- a/advisories/unreviewed/2024/02/GHSA-hwq5-wx3r-8r5g/GHSA-hwq5-wx3r-8r5g.json +++ b/advisories/unreviewed/2024/02/GHSA-hwq5-wx3r-8r5g/GHSA-hwq5-wx3r-8r5g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hwq5-wx3r-8r5g", - "modified": "2024-02-13T21:30:29Z", + "modified": "2024-10-17T18:31:31Z", "published": "2024-02-13T21:30:29Z", "aliases": [ "CVE-2024-1084" diff --git a/advisories/unreviewed/2024/03/GHSA-jpgh-f7hm-pwmf/GHSA-jpgh-f7hm-pwmf.json b/advisories/unreviewed/2024/03/GHSA-jpgh-f7hm-pwmf/GHSA-jpgh-f7hm-pwmf.json index f8534ad7333..d02a936eb49 100644 --- a/advisories/unreviewed/2024/03/GHSA-jpgh-f7hm-pwmf/GHSA-jpgh-f7hm-pwmf.json +++ b/advisories/unreviewed/2024/03/GHSA-jpgh-f7hm-pwmf/GHSA-jpgh-f7hm-pwmf.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-280" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-4qvc-c86c-g9qp/GHSA-4qvc-c86c-g9qp.json b/advisories/unreviewed/2024/06/GHSA-4qvc-c86c-g9qp/GHSA-4qvc-c86c-g9qp.json index deab8b6560c..6df1579ea2a 100644 --- a/advisories/unreviewed/2024/06/GHSA-4qvc-c86c-g9qp/GHSA-4qvc-c86c-g9qp.json +++ b/advisories/unreviewed/2024/06/GHSA-4qvc-c86c-g9qp/GHSA-4qvc-c86c-g9qp.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-36" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/06/GHSA-5wv7-58x2-44rh/GHSA-5wv7-58x2-44rh.json b/advisories/unreviewed/2024/06/GHSA-5wv7-58x2-44rh/GHSA-5wv7-58x2-44rh.json index 248c29ba7c2..845e31e28ff 100644 --- a/advisories/unreviewed/2024/06/GHSA-5wv7-58x2-44rh/GHSA-5wv7-58x2-44rh.json +++ b/advisories/unreviewed/2024/06/GHSA-5wv7-58x2-44rh/GHSA-5wv7-58x2-44rh.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-36" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2024/06/GHSA-67rj-2wcw-78m5/GHSA-67rj-2wcw-78m5.json b/advisories/unreviewed/2024/06/GHSA-67rj-2wcw-78m5/GHSA-67rj-2wcw-78m5.json index 82de0161036..bb69e44e390 100644 --- a/advisories/unreviewed/2024/06/GHSA-67rj-2wcw-78m5/GHSA-67rj-2wcw-78m5.json +++ b/advisories/unreviewed/2024/06/GHSA-67rj-2wcw-78m5/GHSA-67rj-2wcw-78m5.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-29" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2024/06/GHSA-rcm3-8wq2-rcc2/GHSA-rcm3-8wq2-rcc2.json b/advisories/unreviewed/2024/06/GHSA-rcm3-8wq2-rcc2/GHSA-rcm3-8wq2-rcc2.json index 6a9edf02dd9..b39568e7d2a 100644 --- a/advisories/unreviewed/2024/06/GHSA-rcm3-8wq2-rcc2/GHSA-rcm3-8wq2-rcc2.json +++ b/advisories/unreviewed/2024/06/GHSA-rcm3-8wq2-rcc2/GHSA-rcm3-8wq2-rcc2.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-755" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-2239-h2rh-5fp9/GHSA-2239-h2rh-5fp9.json b/advisories/unreviewed/2024/10/GHSA-2239-h2rh-5fp9/GHSA-2239-h2rh-5fp9.json new file mode 100644 index 00000000000..04515f50633 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-2239-h2rh-5fp9/GHSA-2239-h2rh-5fp9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2239-h2rh-5fp9", + "modified": "2024-10-17T18:31:36Z", + "published": "2024-10-17T18:31:36Z", + "aliases": [ + "CVE-2024-49220" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Cookie Scanner – Nikel Schubert Cookie Scanner allows Stored XSS.This issue affects Cookie Scanner: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49220" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/cookie-scanner/wordpress-cookie-scanner-plugin-1-1-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-2289-64mg-g86w/GHSA-2289-64mg-g86w.json b/advisories/unreviewed/2024/10/GHSA-2289-64mg-g86w/GHSA-2289-64mg-g86w.json new file mode 100644 index 00000000000..605ffe2d194 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-2289-64mg-g86w/GHSA-2289-64mg-g86w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2289-64mg-g86w", + "modified": "2024-10-17T18:31:37Z", + "published": "2024-10-17T18:31:37Z", + "aliases": [ + "CVE-2024-49297" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zoho CRM Zoho CRM Lead Magnet allows SQL Injection.This issue affects Zoho CRM Lead Magnet: from n/a through 1.7.9.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49297" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/zoho-crm-forms/wordpress-zoho-crm-lead-magnet-plugin-1-7-9-0-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-22c8-79jr-rvwg/GHSA-22c8-79jr-rvwg.json b/advisories/unreviewed/2024/10/GHSA-22c8-79jr-rvwg/GHSA-22c8-79jr-rvwg.json new file mode 100644 index 00000000000..145192eadaa --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-22c8-79jr-rvwg/GHSA-22c8-79jr-rvwg.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-22c8-79jr-rvwg", + "modified": "2024-10-17T18:31:36Z", + "published": "2024-10-17T18:31:36Z", + "aliases": [ + "CVE-2024-48633" + ], + "details": "D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain multiple command injection vulnerabilities via the ExternalPort, InternalPort, ProtocolNumber, and LocalIPAddress parameters in the SetVirtualServerSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48633" + }, + { + "type": "WEB", + "url": "https://github.com/pjqwudi1/my_vuln/blob/main/D-link4/vuln_40/40.md" + }, + { + "type": "WEB", + "url": "https://www.dlink.com/en/security-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-35hv-j72m-jmfm/GHSA-35hv-j72m-jmfm.json b/advisories/unreviewed/2024/10/GHSA-35hv-j72m-jmfm/GHSA-35hv-j72m-jmfm.json index 9ad80e3235f..e8cf78953c0 100644 --- a/advisories/unreviewed/2024/10/GHSA-35hv-j72m-jmfm/GHSA-35hv-j72m-jmfm.json +++ b/advisories/unreviewed/2024/10/GHSA-35hv-j72m-jmfm/GHSA-35hv-j72m-jmfm.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-37gm-h5wr-pf25/GHSA-37gm-h5wr-pf25.json b/advisories/unreviewed/2024/10/GHSA-37gm-h5wr-pf25/GHSA-37gm-h5wr-pf25.json index ba7640a2a5b..520d50657f6 100644 --- a/advisories/unreviewed/2024/10/GHSA-37gm-h5wr-pf25/GHSA-37gm-h5wr-pf25.json +++ b/advisories/unreviewed/2024/10/GHSA-37gm-h5wr-pf25/GHSA-37gm-h5wr-pf25.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-37gm-h5wr-pf25", - "modified": "2024-10-16T21:31:09Z", + "modified": "2024-10-17T18:31:35Z", "published": "2024-10-16T21:31:09Z", "aliases": [ "CVE-2024-46212" ], "details": "An issue in the component /index.php?page=backup/export of REDAXO CMS v5.17.1 allows attackers to execute a directory traversal.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-16T21:15:12Z" diff --git a/advisories/unreviewed/2024/10/GHSA-3hqc-72mc-jjr3/GHSA-3hqc-72mc-jjr3.json b/advisories/unreviewed/2024/10/GHSA-3hqc-72mc-jjr3/GHSA-3hqc-72mc-jjr3.json index 29692e28d65..496321b3deb 100644 --- a/advisories/unreviewed/2024/10/GHSA-3hqc-72mc-jjr3/GHSA-3hqc-72mc-jjr3.json +++ b/advisories/unreviewed/2024/10/GHSA-3hqc-72mc-jjr3/GHSA-3hqc-72mc-jjr3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3hqc-72mc-jjr3", - "modified": "2024-10-15T21:30:39Z", + "modified": "2024-10-17T18:31:35Z", "published": "2024-10-15T21:30:39Z", "aliases": [ "CVE-2024-48779" ], "details": "An issue in Wanxing Technology's Yitu project Management Software 3.2.2 allows a remote attacker to execute arbitrary code via the platformpluginpath parameter to specify that the qt plugin loads the directory.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-15T21:15:11Z" diff --git a/advisories/unreviewed/2024/10/GHSA-3p3h-5g54-qmc8/GHSA-3p3h-5g54-qmc8.json b/advisories/unreviewed/2024/10/GHSA-3p3h-5g54-qmc8/GHSA-3p3h-5g54-qmc8.json index e8297458dbc..3539435ef96 100644 --- a/advisories/unreviewed/2024/10/GHSA-3p3h-5g54-qmc8/GHSA-3p3h-5g54-qmc8.json +++ b/advisories/unreviewed/2024/10/GHSA-3p3h-5g54-qmc8/GHSA-3p3h-5g54-qmc8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3p3h-5g54-qmc8", - "modified": "2024-10-16T21:31:09Z", + "modified": "2024-10-17T18:31:35Z", "published": "2024-10-16T21:31:09Z", "aliases": [ "CVE-2024-48180" ], "details": "ClassCMS <=4.8 is vulnerable to file inclusion in the nowView method in/class/cms/cms.php, which can include a file uploaded to the/class/template directory to execute PHP code.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-16T21:15:13Z" diff --git a/advisories/unreviewed/2024/10/GHSA-4hrr-fjm6-xq9f/GHSA-4hrr-fjm6-xq9f.json b/advisories/unreviewed/2024/10/GHSA-4hrr-fjm6-xq9f/GHSA-4hrr-fjm6-xq9f.json new file mode 100644 index 00000000000..5b1340c7f97 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-4hrr-fjm6-xq9f/GHSA-4hrr-fjm6-xq9f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4hrr-fjm6-xq9f", + "modified": "2024-10-17T18:31:36Z", + "published": "2024-10-17T18:31:36Z", + "aliases": [ + "CVE-2024-49398" + ], + "details": "The affected product is vulnerable to unrestricted file uploads, which may allow an attacker to remotely execute code.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49398" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-291-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-55qw-wgp7-hpxm/GHSA-55qw-wgp7-hpxm.json b/advisories/unreviewed/2024/10/GHSA-55qw-wgp7-hpxm/GHSA-55qw-wgp7-hpxm.json new file mode 100644 index 00000000000..06b5f15f0a8 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-55qw-wgp7-hpxm/GHSA-55qw-wgp7-hpxm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-55qw-wgp7-hpxm", + "modified": "2024-10-17T18:31:37Z", + "published": "2024-10-17T18:31:37Z", + "aliases": [ + "CVE-2024-49287" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Marco Heine PDF-Rechnungsverwaltung allows PHP Local File Inclusion.This issue affects PDF-Rechnungsverwaltung: from n/a through 0.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49287" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/pdf-rechnungsverwaltung/wordpress-pdf-rechnungsverwaltung-plugin-0-0-1-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-58w4-g495-7x87/GHSA-58w4-g495-7x87.json b/advisories/unreviewed/2024/10/GHSA-58w4-g495-7x87/GHSA-58w4-g495-7x87.json new file mode 100644 index 00000000000..a9fa209655c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-58w4-g495-7x87/GHSA-58w4-g495-7x87.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-58w4-g495-7x87", + "modified": "2024-10-17T18:31:36Z", + "published": "2024-10-17T18:31:36Z", + "aliases": [ + "CVE-2024-49221" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Julian Weinert // cs&m cSlider allows Stored XSS.This issue affects cSlider: from n/a through 2.4.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49221" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/cslider/wordpress-cslider-plugin-2-4-2-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-5c84-42gq-x4pj/GHSA-5c84-42gq-x4pj.json b/advisories/unreviewed/2024/10/GHSA-5c84-42gq-x4pj/GHSA-5c84-42gq-x4pj.json new file mode 100644 index 00000000000..a48d96f7ff9 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-5c84-42gq-x4pj/GHSA-5c84-42gq-x4pj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5c84-42gq-x4pj", + "modified": "2024-10-17T18:31:36Z", + "published": "2024-10-17T18:31:36Z", + "aliases": [ + "CVE-2024-49219" + ], + "details": "Incorrect Privilege Assignment vulnerability in themexpo RS-Members allows Privilege Escalation.This issue affects RS-Members: from n/a through 1.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49219" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/rs-members/wordpress-rs-members-plugin-1-0-3-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-5f8q-vgg5-cxmm/GHSA-5f8q-vgg5-cxmm.json b/advisories/unreviewed/2024/10/GHSA-5f8q-vgg5-cxmm/GHSA-5f8q-vgg5-cxmm.json new file mode 100644 index 00000000000..0cacc688b8b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-5f8q-vgg5-cxmm/GHSA-5f8q-vgg5-cxmm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5f8q-vgg5-cxmm", + "modified": "2024-10-17T18:31:37Z", + "published": "2024-10-17T18:31:37Z", + "aliases": [ + "CVE-2024-49313" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in RudeStan VKontakte Wall Post allows Stored XSS.This issue affects VKontakte Wall Post: from n/a through 2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49313" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/vkontakte-wall-post/wordpress-vkontakte-wall-post-plugin-2-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-5g64-w7g9-m6pp/GHSA-5g64-w7g9-m6pp.json b/advisories/unreviewed/2024/10/GHSA-5g64-w7g9-m6pp/GHSA-5g64-w7g9-m6pp.json new file mode 100644 index 00000000000..6e54ddc984c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-5g64-w7g9-m6pp/GHSA-5g64-w7g9-m6pp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5g64-w7g9-m6pp", + "modified": "2024-10-17T18:31:36Z", + "published": "2024-10-17T18:31:36Z", + "aliases": [ + "CVE-2024-49223" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Shibu Lijack a.K.A CyberJack CJ Change Howdy allows Stored XSS.This issue affects CJ Change Howdy: from n/a through 3.3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49223" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/cj-change-howdy/wordpress-cj-change-howdy-plugin-3-3-1-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-5m2m-2m7m-2w3p/GHSA-5m2m-2m7m-2w3p.json b/advisories/unreviewed/2024/10/GHSA-5m2m-2m7m-2w3p/GHSA-5m2m-2m7m-2w3p.json new file mode 100644 index 00000000000..68a7d171a32 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-5m2m-2m7m-2w3p/GHSA-5m2m-2m7m-2w3p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5m2m-2m7m-2w3p", + "modified": "2024-10-17T18:31:36Z", + "published": "2024-10-17T18:31:36Z", + "aliases": [ + "CVE-2024-49397" + ], + "details": "The affected product is vulnerable to a cross-site scripting attack which may allow an attacker to bypass authentication and takeover admin accounts.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49397" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-291-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-64wj-w5hh-h98q/GHSA-64wj-w5hh-h98q.json b/advisories/unreviewed/2024/10/GHSA-64wj-w5hh-h98q/GHSA-64wj-w5hh-h98q.json new file mode 100644 index 00000000000..f556391d9fe --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-64wj-w5hh-h98q/GHSA-64wj-w5hh-h98q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-64wj-w5hh-h98q", + "modified": "2024-10-17T18:31:37Z", + "published": "2024-10-17T18:31:37Z", + "aliases": [ + "CVE-2024-49246" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in anand23 Ajax Rating with Custom Login allows SQL Injection.This issue affects Ajax Rating with Custom Login: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49246" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ajax-rating-with-custom-login/wordpress-ajax-rating-with-custom-login-plugin-1-1-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-6573-c535-4x9f/GHSA-6573-c535-4x9f.json b/advisories/unreviewed/2024/10/GHSA-6573-c535-4x9f/GHSA-6573-c535-4x9f.json new file mode 100644 index 00000000000..05fd75185cf --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-6573-c535-4x9f/GHSA-6573-c535-4x9f.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6573-c535-4x9f", + "modified": "2024-10-17T18:31:36Z", + "published": "2024-10-17T18:31:36Z", + "aliases": [ + "CVE-2024-48635" + ], + "details": "D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the VLANID:2/VID parameter in the SetVLANSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48635" + }, + { + "type": "WEB", + "url": "https://github.com/pjqwudi1/my_vuln/tree/main/D-link4/vuln_38" + }, + { + "type": "WEB", + "url": "https://www.dlink.com/en/security-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-65j2-63g4-wq84/GHSA-65j2-63g4-wq84.json b/advisories/unreviewed/2024/10/GHSA-65j2-63g4-wq84/GHSA-65j2-63g4-wq84.json new file mode 100644 index 00000000000..12079cd7523 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-65j2-63g4-wq84/GHSA-65j2-63g4-wq84.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-65j2-63g4-wq84", + "modified": "2024-10-17T18:31:36Z", + "published": "2024-10-17T18:31:36Z", + "aliases": [ + "CVE-2024-10072" + ], + "details": "A vulnerability, which was classified as critical, has been found in ESAFENET CDG 5. This issue affects the function actionAddEncryptPolicyGroup of the file /com/esafenet/servlet/policy/EncryptPolicyService.java. The manipulation of the argument checklist leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10072" + }, + { + "type": "WEB", + "url": "https://flowus.cn/share/dd690c21-bb5c-4db4-a737-afb2cf54c8e1?code=G8A6P3" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.280721" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.280721" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.420914" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-6j47-rxg5-g629/GHSA-6j47-rxg5-g629.json b/advisories/unreviewed/2024/10/GHSA-6j47-rxg5-g629/GHSA-6j47-rxg5-g629.json new file mode 100644 index 00000000000..ae3d64de3c5 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-6j47-rxg5-g629/GHSA-6j47-rxg5-g629.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6j47-rxg5-g629", + "modified": "2024-10-17T18:31:37Z", + "published": "2024-10-17T18:31:36Z", + "aliases": [ + "CVE-2024-49235" + ], + "details": "Insertion of Sensitive Information Into Sent Data vulnerability in VideoWhisper.Com Contact Forms, Live Support, CRM, Video Messages allows Retrieve Embedded Sensitive Data.This issue affects Contact Forms, Live Support, CRM, Video Messages: from n/a through 1.10.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49235" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/live-support-tickets/wordpress-contact-forms-live-support-crm-video-messages-plugin-1-10-2-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-201" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-6r8j-2f85-xr6c/GHSA-6r8j-2f85-xr6c.json b/advisories/unreviewed/2024/10/GHSA-6r8j-2f85-xr6c/GHSA-6r8j-2f85-xr6c.json new file mode 100644 index 00000000000..837139731a6 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-6r8j-2f85-xr6c/GHSA-6r8j-2f85-xr6c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6r8j-2f85-xr6c", + "modified": "2024-10-17T18:31:36Z", + "published": "2024-10-17T18:31:36Z", + "aliases": [ + "CVE-2024-49399" + ], + "details": "The affected product is vulnerable to an attacker being able to use commands without providing a password which may allow an attacker to leak information.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49399" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-291-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-6v6v-w6v8-phhr/GHSA-6v6v-w6v8-phhr.json b/advisories/unreviewed/2024/10/GHSA-6v6v-w6v8-phhr/GHSA-6v6v-w6v8-phhr.json new file mode 100644 index 00000000000..7b958449e2e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-6v6v-w6v8-phhr/GHSA-6v6v-w6v8-phhr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6v6v-w6v8-phhr", + "modified": "2024-10-17T18:31:36Z", + "published": "2024-10-17T18:31:36Z", + "aliases": [ + "CVE-2024-49217" + ], + "details": "Incorrect Privilege Assignment vulnerability in Madiri Salman Aashish Adding drop down roles in registration allows Privilege Escalation.This issue affects Adding drop down roles in registration: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49217" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/user-drop-down-roles-in-registration/wordpress-adding-drop-down-roles-in-registration-plugin-1-1-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-6xfc-pfpw-jjvg/GHSA-6xfc-pfpw-jjvg.json b/advisories/unreviewed/2024/10/GHSA-6xfc-pfpw-jjvg/GHSA-6xfc-pfpw-jjvg.json new file mode 100644 index 00000000000..d8328c94ae5 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-6xfc-pfpw-jjvg/GHSA-6xfc-pfpw-jjvg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6xfc-pfpw-jjvg", + "modified": "2024-10-17T18:31:37Z", + "published": "2024-10-17T18:31:37Z", + "aliases": [ + "CVE-2024-49291" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Gora Tech LLC Cooked Pro.This issue affects Cooked Pro: from n/a before 1.8.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49291" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/cooked-pro/wordpress-cooked-pro-plugin-1-8-0-unauthenticated-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-7646-3v28-562q/GHSA-7646-3v28-562q.json b/advisories/unreviewed/2024/10/GHSA-7646-3v28-562q/GHSA-7646-3v28-562q.json index 93f8218449b..71a5b249053 100644 --- a/advisories/unreviewed/2024/10/GHSA-7646-3v28-562q/GHSA-7646-3v28-562q.json +++ b/advisories/unreviewed/2024/10/GHSA-7646-3v28-562q/GHSA-7646-3v28-562q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7646-3v28-562q", - "modified": "2024-10-09T06:30:22Z", + "modified": "2024-10-17T18:31:33Z", "published": "2024-10-09T06:30:22Z", "aliases": [ "CVE-2024-32608" ], "details": "HDF5 library through 1.14.3 has memory corruption in H5A__close resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-09T05:15:13Z" diff --git a/advisories/unreviewed/2024/10/GHSA-79v4-xhfm-cr97/GHSA-79v4-xhfm-cr97.json b/advisories/unreviewed/2024/10/GHSA-79v4-xhfm-cr97/GHSA-79v4-xhfm-cr97.json index 8157e4b450b..a41b5be1abf 100644 --- a/advisories/unreviewed/2024/10/GHSA-79v4-xhfm-cr97/GHSA-79v4-xhfm-cr97.json +++ b/advisories/unreviewed/2024/10/GHSA-79v4-xhfm-cr97/GHSA-79v4-xhfm-cr97.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-79v4-xhfm-cr97", - "modified": "2024-10-15T15:30:49Z", + "modified": "2024-10-17T18:31:34Z", "published": "2024-10-11T18:32:49Z", "aliases": [ "CVE-2024-47491" diff --git a/advisories/unreviewed/2024/10/GHSA-7w9c-mwvx-vwrc/GHSA-7w9c-mwvx-vwrc.json b/advisories/unreviewed/2024/10/GHSA-7w9c-mwvx-vwrc/GHSA-7w9c-mwvx-vwrc.json new file mode 100644 index 00000000000..05e48d33c73 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-7w9c-mwvx-vwrc/GHSA-7w9c-mwvx-vwrc.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7w9c-mwvx-vwrc", + "modified": "2024-10-17T18:31:36Z", + "published": "2024-10-17T18:31:36Z", + "aliases": [ + "CVE-2024-48631" + ], + "details": "D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the SSID parameter in the SetWLanRadioSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48631" + }, + { + "type": "WEB", + "url": "https://github.com/pjqwudi1/my_vuln/blob/main/D-link4/vuln_32/32.md" + }, + { + "type": "WEB", + "url": "https://www.dlink.com/en/security-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-7xw5-vv24-6xg9/GHSA-7xw5-vv24-6xg9.json b/advisories/unreviewed/2024/10/GHSA-7xw5-vv24-6xg9/GHSA-7xw5-vv24-6xg9.json new file mode 100644 index 00000000000..455a1afe6c9 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-7xw5-vv24-6xg9/GHSA-7xw5-vv24-6xg9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7xw5-vv24-6xg9", + "modified": "2024-10-17T18:31:37Z", + "published": "2024-10-17T18:31:37Z", + "aliases": [ + "CVE-2024-49285" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Moridrin SSV MailChimp allows PHP Local File Inclusion.This issue affects SSV MailChimp: from n/a through 3.1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49285" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ssv-mailchimp/wordpress-ssv-mailchimp-plugin-3-1-5-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-83rg-r6p3-c2jp/GHSA-83rg-r6p3-c2jp.json b/advisories/unreviewed/2024/10/GHSA-83rg-r6p3-c2jp/GHSA-83rg-r6p3-c2jp.json new file mode 100644 index 00000000000..8ac229cad31 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-83rg-r6p3-c2jp/GHSA-83rg-r6p3-c2jp.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-83rg-r6p3-c2jp", + "modified": "2024-10-17T18:31:36Z", + "published": "2024-10-17T18:31:36Z", + "aliases": [ + "CVE-2024-48632" + ], + "details": "D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain multiple command injection vulnerabilities via the LocalIPAddress, TCPPorts, and UDPPorts parameters in the SetPortForwardingSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48632" + }, + { + "type": "WEB", + "url": "https://github.com/pjqwudi1/my_vuln/blob/main/D-link4/vuln_39/39.md" + }, + { + "type": "WEB", + "url": "https://www.dlink.com/en/security-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-8mj6-v7f2-fc7m/GHSA-8mj6-v7f2-fc7m.json b/advisories/unreviewed/2024/10/GHSA-8mj6-v7f2-fc7m/GHSA-8mj6-v7f2-fc7m.json index 560c7780eb4..95f13a84148 100644 --- a/advisories/unreviewed/2024/10/GHSA-8mj6-v7f2-fc7m/GHSA-8mj6-v7f2-fc7m.json +++ b/advisories/unreviewed/2024/10/GHSA-8mj6-v7f2-fc7m/GHSA-8mj6-v7f2-fc7m.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-8pmc-cjqv-8vg9/GHSA-8pmc-cjqv-8vg9.json b/advisories/unreviewed/2024/10/GHSA-8pmc-cjqv-8vg9/GHSA-8pmc-cjqv-8vg9.json new file mode 100644 index 00000000000..d4cdae84001 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-8pmc-cjqv-8vg9/GHSA-8pmc-cjqv-8vg9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8pmc-cjqv-8vg9", + "modified": "2024-10-17T18:31:37Z", + "published": "2024-10-17T18:31:37Z", + "aliases": [ + "CVE-2024-49299" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Surfer allows SQL Injection.This issue affects Surfer: from n/a through 1.5.0.502.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49299" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/surferseo/wordpress-surfer-plugin-1-5-0-502-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-8r4p-vrx2-6q8p/GHSA-8r4p-vrx2-6q8p.json b/advisories/unreviewed/2024/10/GHSA-8r4p-vrx2-6q8p/GHSA-8r4p-vrx2-6q8p.json index 13aaaf9b6dc..84b19e075e7 100644 --- a/advisories/unreviewed/2024/10/GHSA-8r4p-vrx2-6q8p/GHSA-8r4p-vrx2-6q8p.json +++ b/advisories/unreviewed/2024/10/GHSA-8r4p-vrx2-6q8p/GHSA-8r4p-vrx2-6q8p.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-964m-2x9c-4cwp/GHSA-964m-2x9c-4cwp.json b/advisories/unreviewed/2024/10/GHSA-964m-2x9c-4cwp/GHSA-964m-2x9c-4cwp.json new file mode 100644 index 00000000000..78710cc8ba0 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-964m-2x9c-4cwp/GHSA-964m-2x9c-4cwp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-964m-2x9c-4cwp", + "modified": "2024-10-17T18:31:37Z", + "published": "2024-10-17T18:31:37Z", + "aliases": [ + "CVE-2024-49284" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in BogdanFix WP SendFox allows Retrieve Embedded Sensitive Data.This issue affects WP SendFox: from n/a through 1.3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49284" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-sendfox/wordpress-wp-sendfox-plugin-1-3-1-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-9jg2-v5f3-rqf2/GHSA-9jg2-v5f3-rqf2.json b/advisories/unreviewed/2024/10/GHSA-9jg2-v5f3-rqf2/GHSA-9jg2-v5f3-rqf2.json index e09dbd021b2..fb8925d38a1 100644 --- a/advisories/unreviewed/2024/10/GHSA-9jg2-v5f3-rqf2/GHSA-9jg2-v5f3-rqf2.json +++ b/advisories/unreviewed/2024/10/GHSA-9jg2-v5f3-rqf2/GHSA-9jg2-v5f3-rqf2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9jg2-v5f3-rqf2", - "modified": "2024-10-16T21:31:09Z", + "modified": "2024-10-17T18:31:35Z", "published": "2024-10-16T21:31:09Z", "aliases": [ "CVE-2024-44762" ], "details": "A discrepancy in error messages for invalid login attempts in Webmin Usermin v2.100 allows attackers to enumerate valid user accounts.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-209" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-16T21:15:12Z" diff --git a/advisories/unreviewed/2024/10/GHSA-9rw2-jf8x-cgwm/GHSA-9rw2-jf8x-cgwm.json b/advisories/unreviewed/2024/10/GHSA-9rw2-jf8x-cgwm/GHSA-9rw2-jf8x-cgwm.json new file mode 100644 index 00000000000..720261beb4d --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-9rw2-jf8x-cgwm/GHSA-9rw2-jf8x-cgwm.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9rw2-jf8x-cgwm", + "modified": "2024-10-17T18:31:36Z", + "published": "2024-10-17T18:31:36Z", + "aliases": [ + "CVE-2024-10073" + ], + "details": "A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0. Affected is the function ClusteringModel of the file flair\\models\\clustering.py of the component Mode File Loader. The manipulation leads to code injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10073" + }, + { + "type": "WEB", + "url": "https://github.com/bayuncao/vul-cve-20" + }, + { + "type": "WEB", + "url": "https://github.com/bayuncao/vul-cve-20/blob/main/PoC.py" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.280722" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.280722" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.420055" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-c53c-jr4g-q5rc/GHSA-c53c-jr4g-q5rc.json b/advisories/unreviewed/2024/10/GHSA-c53c-jr4g-q5rc/GHSA-c53c-jr4g-q5rc.json new file mode 100644 index 00000000000..0e7e0e9f8c3 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-c53c-jr4g-q5rc/GHSA-c53c-jr4g-q5rc.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c53c-jr4g-q5rc", + "modified": "2024-10-17T18:31:36Z", + "published": "2024-10-17T18:31:36Z", + "aliases": [ + "CVE-2024-48629" + ], + "details": "D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the IPAddress parameter in the SetGuestZoneRouterSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48629" + }, + { + "type": "WEB", + "url": "https://github.com/pjqwudi1/my_vuln/blob/main/D-link4/vuln_34/34.md" + }, + { + "type": "WEB", + "url": "https://www.dlink.com/en/security-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-c7pp-hwqg-2h32/GHSA-c7pp-hwqg-2h32.json b/advisories/unreviewed/2024/10/GHSA-c7pp-hwqg-2h32/GHSA-c7pp-hwqg-2h32.json new file mode 100644 index 00000000000..d1444e345d1 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-c7pp-hwqg-2h32/GHSA-c7pp-hwqg-2h32.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c7pp-hwqg-2h32", + "modified": "2024-10-17T18:31:37Z", + "published": "2024-10-17T18:31:37Z", + "aliases": [ + "CVE-2024-49229" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Arif Nezami Better Author Bio allows Cross-Site Scripting (XSS).This issue affects Better Author Bio: from n/a through 2.7.10.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49229" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/better-author-bio/wordpress-better-author-bio-plugin-2-7-10-11-csrf-to-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-cmj8-8xcw-78x8/GHSA-cmj8-8xcw-78x8.json b/advisories/unreviewed/2024/10/GHSA-cmj8-8xcw-78x8/GHSA-cmj8-8xcw-78x8.json new file mode 100644 index 00000000000..504945ee111 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-cmj8-8xcw-78x8/GHSA-cmj8-8xcw-78x8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cmj8-8xcw-78x8", + "modified": "2024-10-17T18:31:37Z", + "published": "2024-10-17T18:31:37Z", + "aliases": [ + "CVE-2024-49322" + ], + "details": "Incorrect Privilege Assignment vulnerability in CodePassenger Job Board Manager for WordPress allows Privilege Escalation.This issue affects Job Board Manager for WordPress: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49322" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/jemployee/wordpress-job-board-manager-for-wordpress-plugin-1-0-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T18:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-crff-rm75-2v37/GHSA-crff-rm75-2v37.json b/advisories/unreviewed/2024/10/GHSA-crff-rm75-2v37/GHSA-crff-rm75-2v37.json new file mode 100644 index 00000000000..c18ccdce896 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-crff-rm75-2v37/GHSA-crff-rm75-2v37.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-crff-rm75-2v37", + "modified": "2024-10-17T18:31:37Z", + "published": "2024-10-17T18:31:37Z", + "aliases": [ + "CVE-2024-49304" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in PINPOINT.WORLD Pinpoint Booking System allows Stored XSS.This issue affects Pinpoint Booking System: from n/a through 2.9.9.5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49304" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/booking-system/wordpress-pinpoint-booking-system-plugin-2-9-9-5-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-f765-974j-wr7x/GHSA-f765-974j-wr7x.json b/advisories/unreviewed/2024/10/GHSA-f765-974j-wr7x/GHSA-f765-974j-wr7x.json new file mode 100644 index 00000000000..bcd73fe4269 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-f765-974j-wr7x/GHSA-f765-974j-wr7x.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f765-974j-wr7x", + "modified": "2024-10-17T18:31:36Z", + "published": "2024-10-17T18:31:36Z", + "aliases": [ + "CVE-2024-48638" + ], + "details": "D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the SubnetMask parameter in the SetGuestZoneRouterSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48638" + }, + { + "type": "WEB", + "url": "https://github.com/pjqwudi1/my_vuln/blob/main/D-link4/vuln_35/35.md" + }, + { + "type": "WEB", + "url": "https://www.dlink.com/en/security-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-fhcj-8xxf-6hcq/GHSA-fhcj-8xxf-6hcq.json b/advisories/unreviewed/2024/10/GHSA-fhcj-8xxf-6hcq/GHSA-fhcj-8xxf-6hcq.json new file mode 100644 index 00000000000..24112a30777 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-fhcj-8xxf-6hcq/GHSA-fhcj-8xxf-6hcq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fhcj-8xxf-6hcq", + "modified": "2024-10-17T18:31:37Z", + "published": "2024-10-17T18:31:37Z", + "aliases": [ + "CVE-2024-49305" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFactory Email Verification for WooCommerce allows SQL Injection.This issue affects Email Verification for WooCommerce: from n/a through 2.8.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49305" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/emails-verification-for-woocommerce/wordpress-customer-email-verification-for-woocommerce-plugin-2-8-10-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-fp2j-g6r8-vx87/GHSA-fp2j-g6r8-vx87.json b/advisories/unreviewed/2024/10/GHSA-fp2j-g6r8-vx87/GHSA-fp2j-g6r8-vx87.json index 9f419a1d062..0da41fdcf30 100644 --- a/advisories/unreviewed/2024/10/GHSA-fp2j-g6r8-vx87/GHSA-fp2j-g6r8-vx87.json +++ b/advisories/unreviewed/2024/10/GHSA-fp2j-g6r8-vx87/GHSA-fp2j-g6r8-vx87.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-fxj9-2pvv-7wxf/GHSA-fxj9-2pvv-7wxf.json b/advisories/unreviewed/2024/10/GHSA-fxj9-2pvv-7wxf/GHSA-fxj9-2pvv-7wxf.json new file mode 100644 index 00000000000..78d3a971106 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-fxj9-2pvv-7wxf/GHSA-fxj9-2pvv-7wxf.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fxj9-2pvv-7wxf", + "modified": "2024-10-17T18:31:36Z", + "published": "2024-10-17T18:31:36Z", + "aliases": [ + "CVE-2024-48636" + ], + "details": "D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the VLANID:0/VID parameter in the SetVLANSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48636" + }, + { + "type": "WEB", + "url": "https://github.com/pjqwudi1/my_vuln/blob/main/D-link4/vuln_36/36.md" + }, + { + "type": "WEB", + "url": "https://www.dlink.com/en/security-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-h6vc-pxj4-pcch/GHSA-h6vc-pxj4-pcch.json b/advisories/unreviewed/2024/10/GHSA-h6vc-pxj4-pcch/GHSA-h6vc-pxj4-pcch.json index 2475171b52f..b38a4e736a7 100644 --- a/advisories/unreviewed/2024/10/GHSA-h6vc-pxj4-pcch/GHSA-h6vc-pxj4-pcch.json +++ b/advisories/unreviewed/2024/10/GHSA-h6vc-pxj4-pcch/GHSA-h6vc-pxj4-pcch.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h6vc-pxj4-pcch", - "modified": "2024-10-16T21:31:09Z", + "modified": "2024-10-17T18:31:35Z", "published": "2024-10-16T21:31:09Z", "aliases": [ "CVE-2024-46213" ], "details": "REDAXO CMS v2.11.0 was discovered to contain a remote code execution (RCE) vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-16T21:15:12Z" diff --git a/advisories/unreviewed/2024/10/GHSA-h7cj-r87j-mgmf/GHSA-h7cj-r87j-mgmf.json b/advisories/unreviewed/2024/10/GHSA-h7cj-r87j-mgmf/GHSA-h7cj-r87j-mgmf.json new file mode 100644 index 00000000000..109432d05e4 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-h7cj-r87j-mgmf/GHSA-h7cj-r87j-mgmf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h7cj-r87j-mgmf", + "modified": "2024-10-17T18:31:36Z", + "published": "2024-10-17T18:31:36Z", + "aliases": [ + "CVE-2024-9414" + ], + "details": "In LAquis SCADA version 4.7.1.511, a cross-site scripting vulnerability could allow an attacker to inject arbitrary code into a web page. This could allow an attacker to steal cookies, redirect users, or perform unauthorized actions.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9414" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-291-02" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T16:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-hjh2-x5x2-gfcq/GHSA-hjh2-x5x2-gfcq.json b/advisories/unreviewed/2024/10/GHSA-hjh2-x5x2-gfcq/GHSA-hjh2-x5x2-gfcq.json new file mode 100644 index 00000000000..fe12f12ecd9 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-hjh2-x5x2-gfcq/GHSA-hjh2-x5x2-gfcq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hjh2-x5x2-gfcq", + "modified": "2024-10-17T18:31:36Z", + "published": "2024-10-17T18:31:36Z", + "aliases": [ + "CVE-2024-47304" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPManageNinja LLC Fluent Support allows SQL Injection.This issue affects Fluent Support: from n/a through 1.8.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47304" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/fluent-support/wordpress-fluent-support-plugin-1-8-0-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T18:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-hrxv-p9g2-4f7m/GHSA-hrxv-p9g2-4f7m.json b/advisories/unreviewed/2024/10/GHSA-hrxv-p9g2-4f7m/GHSA-hrxv-p9g2-4f7m.json new file mode 100644 index 00000000000..67cf0818e45 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-hrxv-p9g2-4f7m/GHSA-hrxv-p9g2-4f7m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hrxv-p9g2-4f7m", + "modified": "2024-10-17T18:31:36Z", + "published": "2024-10-17T18:31:36Z", + "aliases": [ + "CVE-2024-47312" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPGrim Classic Editor and Classic Widgets allows SQL Injection.This issue affects Classic Editor and Classic Widgets: from n/a through 1.4.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47312" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/classic-editor-and-classic-widgets/wordpress-classic-editor-and-classic-widgets-plugin-1-4-1-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T18:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-j42f-wc6v-5xpq/GHSA-j42f-wc6v-5xpq.json b/advisories/unreviewed/2024/10/GHSA-j42f-wc6v-5xpq/GHSA-j42f-wc6v-5xpq.json new file mode 100644 index 00000000000..07e61d3fb3a --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-j42f-wc6v-5xpq/GHSA-j42f-wc6v-5xpq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j42f-wc6v-5xpq", + "modified": "2024-10-17T18:31:37Z", + "published": "2024-10-17T18:31:37Z", + "aliases": [ + "CVE-2024-49400" + ], + "details": "Tacquito prior to commit 07b49d1358e6ec0b5aa482fcd284f509191119e2 was not properly performing regex matches on authorized commands and arguments. Configured allowed commands/arguments were intended to require a match on the entire string, but instead only enforced a match on a sub-string. That would have potentially allowed unauthorized commands to be executed.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49400" + }, + { + "type": "WEB", + "url": "https://www.facebook.com/security/advisories/cve-2024-49400" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T18:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-j7g7-4mrc-2vvr/GHSA-j7g7-4mrc-2vvr.json b/advisories/unreviewed/2024/10/GHSA-j7g7-4mrc-2vvr/GHSA-j7g7-4mrc-2vvr.json new file mode 100644 index 00000000000..70c90b15033 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-j7g7-4mrc-2vvr/GHSA-j7g7-4mrc-2vvr.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j7g7-4mrc-2vvr", + "modified": "2024-10-17T18:31:36Z", + "published": "2024-10-17T18:31:36Z", + "aliases": [ + "CVE-2024-10071" + ], + "details": "A vulnerability classified as critical was found in ESAFENET CDG 5. This vulnerability affects the function actionUpdateEncryptPolicyEdit of the file /com/esafenet/servlet/policy/EncryptPolicyService.java. The manipulation of the argument encryptPolicyId leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10071" + }, + { + "type": "WEB", + "url": "https://flowus.cn/share/d1a29ce2-346c-4a8e-836a-e9533c32fad1?code=G8A6P3" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.280720" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.280720" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.420913" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T16:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-mwxv-gvxj-75w4/GHSA-mwxv-gvxj-75w4.json b/advisories/unreviewed/2024/10/GHSA-mwxv-gvxj-75w4/GHSA-mwxv-gvxj-75w4.json new file mode 100644 index 00000000000..e7912e277eb --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-mwxv-gvxj-75w4/GHSA-mwxv-gvxj-75w4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mwxv-gvxj-75w4", + "modified": "2024-10-17T18:31:36Z", + "published": "2024-10-17T18:31:36Z", + "aliases": [ + "CVE-2024-48192" + ], + "details": "Tenda G3 v15.01.0.5(2848_755)_EN was discovered to contain a hardcoded password vulnerability in /etc_ro/shadow, which allows attackers to log in as root", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48192" + }, + { + "type": "WEB", + "url": "https://colorful-meadow-5b9.notion.site/G3_HardCode_vuln-6b5ae19473b745d7abe5e01b4529caf8?pvs=4" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-qfvx-rvq7-99qm/GHSA-qfvx-rvq7-99qm.json b/advisories/unreviewed/2024/10/GHSA-qfvx-rvq7-99qm/GHSA-qfvx-rvq7-99qm.json new file mode 100644 index 00000000000..a17c94f6516 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-qfvx-rvq7-99qm/GHSA-qfvx-rvq7-99qm.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qfvx-rvq7-99qm", + "modified": "2024-10-17T18:31:36Z", + "published": "2024-10-17T18:31:36Z", + "aliases": [ + "CVE-2024-48634" + ], + "details": "D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the key parameter in the SetWLanRadioSecurity function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48634" + }, + { + "type": "WEB", + "url": "https://github.com/pjqwudi1/my_vuln/blob/main/D-link4/vuln_33/33.md" + }, + { + "type": "WEB", + "url": "https://www.dlink.com/en/security-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-qg3g-xgh9-3rhh/GHSA-qg3g-xgh9-3rhh.json b/advisories/unreviewed/2024/10/GHSA-qg3g-xgh9-3rhh/GHSA-qg3g-xgh9-3rhh.json new file mode 100644 index 00000000000..1d4e122de8c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-qg3g-xgh9-3rhh/GHSA-qg3g-xgh9-3rhh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qg3g-xgh9-3rhh", + "modified": "2024-10-17T18:31:37Z", + "published": "2024-10-17T18:31:37Z", + "aliases": [ + "CVE-2024-49317" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ZIPANG Point Maker allows PHP Local File Inclusion.This issue affects Point Maker: from n/a through 0.1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49317" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/point-maker/wordpress-point-maker-plugin-0-1-4-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-qhrq-52qx-58fx/GHSA-qhrq-52qx-58fx.json b/advisories/unreviewed/2024/10/GHSA-qhrq-52qx-58fx/GHSA-qhrq-52qx-58fx.json new file mode 100644 index 00000000000..1fff7d4a4f0 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-qhrq-52qx-58fx/GHSA-qhrq-52qx-58fx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qhrq-52qx-58fx", + "modified": "2024-10-17T18:31:37Z", + "published": "2024-10-17T18:31:37Z", + "aliases": [ + "CVE-2024-49318" + ], + "details": "Deserialization of Untrusted Data vulnerability in Scott Olson My Reading Library allows Object Injection.This issue affects My Reading Library: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49318" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/my-reading-library/wordpress-my-reading-library-plugin-1-0-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T18:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-qppf-gxpr-gm52/GHSA-qppf-gxpr-gm52.json b/advisories/unreviewed/2024/10/GHSA-qppf-gxpr-gm52/GHSA-qppf-gxpr-gm52.json new file mode 100644 index 00000000000..c903f19e7c0 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-qppf-gxpr-gm52/GHSA-qppf-gxpr-gm52.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qppf-gxpr-gm52", + "modified": "2024-10-17T18:31:36Z", + "published": "2024-10-17T18:31:36Z", + "aliases": [ + "CVE-2024-48630" + ], + "details": "D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the MacAddress parameter in the SetMACFilters2 function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48630" + }, + { + "type": "WEB", + "url": "https://github.com/pjqwudi1/my_vuln/blob/main/D-link4/vuln_41/41.md" + }, + { + "type": "WEB", + "url": "https://www.dlink.com/en/security-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-r2xv-6xm9-x7pv/GHSA-r2xv-6xm9-x7pv.json b/advisories/unreviewed/2024/10/GHSA-r2xv-6xm9-x7pv/GHSA-r2xv-6xm9-x7pv.json new file mode 100644 index 00000000000..512efbd3825 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-r2xv-6xm9-x7pv/GHSA-r2xv-6xm9-x7pv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r2xv-6xm9-x7pv", + "modified": "2024-10-17T18:31:36Z", + "published": "2024-10-17T18:31:36Z", + "aliases": [ + "CVE-2024-43997" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in easy.Jobs EasyJobs allows Reflected XSS.This issue affects EasyJobs: from n/a through 2.4.14.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43997" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/easyjobs/wordpress-easy-jobs-best-recruitment-plugin-for-job-board-listing-manager-career-page-for-elementor-gutenberg-plugin-2-4-14-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T18:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-r35g-phmx-hq8m/GHSA-r35g-phmx-hq8m.json b/advisories/unreviewed/2024/10/GHSA-r35g-phmx-hq8m/GHSA-r35g-phmx-hq8m.json index fad26e7bfa3..3ea019f0263 100644 --- a/advisories/unreviewed/2024/10/GHSA-r35g-phmx-hq8m/GHSA-r35g-phmx-hq8m.json +++ b/advisories/unreviewed/2024/10/GHSA-r35g-phmx-hq8m/GHSA-r35g-phmx-hq8m.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-434", "CWE-98" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/10/GHSA-r597-7j2h-6248/GHSA-r597-7j2h-6248.json b/advisories/unreviewed/2024/10/GHSA-r597-7j2h-6248/GHSA-r597-7j2h-6248.json index c360d65b4e5..dfac83c0db0 100644 --- a/advisories/unreviewed/2024/10/GHSA-r597-7j2h-6248/GHSA-r597-7j2h-6248.json +++ b/advisories/unreviewed/2024/10/GHSA-r597-7j2h-6248/GHSA-r597-7j2h-6248.json @@ -40,7 +40,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-261" + "CWE-261", + "CWE-326" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-rfj8-grfp-vjhh/GHSA-rfj8-grfp-vjhh.json b/advisories/unreviewed/2024/10/GHSA-rfj8-grfp-vjhh/GHSA-rfj8-grfp-vjhh.json new file mode 100644 index 00000000000..86aa06633b3 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-rfj8-grfp-vjhh/GHSA-rfj8-grfp-vjhh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rfj8-grfp-vjhh", + "modified": "2024-10-17T18:31:37Z", + "published": "2024-10-17T18:31:37Z", + "aliases": [ + "CVE-2024-49237" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Ahmet Imamoglu Ahmeti Wp Timeline allows Stored XSS.This issue affects Ahmeti Wp Timeline: from n/a through 5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49237" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ahmeti-wp-timeline/wordpress-ahmeti-wp-timeline-plugin-5-1-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-rvrm-xghc-86wr/GHSA-rvrm-xghc-86wr.json b/advisories/unreviewed/2024/10/GHSA-rvrm-xghc-86wr/GHSA-rvrm-xghc-86wr.json new file mode 100644 index 00000000000..9316f361116 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-rvrm-xghc-86wr/GHSA-rvrm-xghc-86wr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rvrm-xghc-86wr", + "modified": "2024-10-17T18:31:36Z", + "published": "2024-10-17T18:31:36Z", + "aliases": [ + "CVE-2024-49396" + ], + "details": "The affected product is vulnerable due to insufficiently protected credentials, which may allow an attacker to impersonate Elvaco and send false information.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49396" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-291-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-522" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-rwhp-3v8j-67m2/GHSA-rwhp-3v8j-67m2.json b/advisories/unreviewed/2024/10/GHSA-rwhp-3v8j-67m2/GHSA-rwhp-3v8j-67m2.json index 741d6dcc2b7..066954d16f5 100644 --- a/advisories/unreviewed/2024/10/GHSA-rwhp-3v8j-67m2/GHSA-rwhp-3v8j-67m2.json +++ b/advisories/unreviewed/2024/10/GHSA-rwhp-3v8j-67m2/GHSA-rwhp-3v8j-67m2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rwhp-3v8j-67m2", - "modified": "2024-10-16T21:31:10Z", + "modified": "2024-10-17T18:31:35Z", "published": "2024-10-16T21:31:10Z", "aliases": [ "CVE-2024-48758" ], "details": "dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the addPro parameter of the component doAdminAction.php which allows a remote attacker to execute arbitrary code", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-16T21:15:13Z" diff --git a/advisories/unreviewed/2024/10/GHSA-w4q7-43c3-j3qv/GHSA-w4q7-43c3-j3qv.json b/advisories/unreviewed/2024/10/GHSA-w4q7-43c3-j3qv/GHSA-w4q7-43c3-j3qv.json new file mode 100644 index 00000000000..076e33bd989 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-w4q7-43c3-j3qv/GHSA-w4q7-43c3-j3qv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w4q7-43c3-j3qv", + "modified": "2024-10-17T18:31:36Z", + "published": "2024-10-17T18:31:36Z", + "aliases": [ + "CVE-2024-48637" + ], + "details": "D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the VLANID:1/VID parameter in the SetVLANSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48637" + }, + { + "type": "WEB", + "url": "https://github.com/pjqwudi1/my_vuln/blob/main/D-link4/vuln_37/37.md" + }, + { + "type": "WEB", + "url": "https://www.dlink.com/en/security-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-wmqp-549h-p884/GHSA-wmqp-549h-p884.json b/advisories/unreviewed/2024/10/GHSA-wmqp-549h-p884/GHSA-wmqp-549h-p884.json index dee43ce6135..1c48b34c8f0 100644 --- a/advisories/unreviewed/2024/10/GHSA-wmqp-549h-p884/GHSA-wmqp-549h-p884.json +++ b/advisories/unreviewed/2024/10/GHSA-wmqp-549h-p884/GHSA-wmqp-549h-p884.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wmqp-549h-p884", - "modified": "2024-10-17T15:31:08Z", + "modified": "2024-10-17T18:31:35Z", "published": "2024-10-17T15:31:08Z", "aliases": [ "CVE-2023-6729" ], "details": "Nokia SR OS routers allow read-write access to the entire file system via SFTP or SCP for users configured with \"access console.\" Consequently, a low privilege authenticated user with \"access console\" can read or replace the router configuration file as well as other files stored in the Compact Flash or SD card without using CLI commands. This type of attack can lead to a compromise or denial of service of the router after the system is rebooted.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-732" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-17T13:15:12Z" diff --git a/advisories/unreviewed/2024/10/GHSA-wqpc-58rm-xq5r/GHSA-wqpc-58rm-xq5r.json b/advisories/unreviewed/2024/10/GHSA-wqpc-58rm-xq5r/GHSA-wqpc-58rm-xq5r.json new file mode 100644 index 00000000000..64e5d3160d7 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-wqpc-58rm-xq5r/GHSA-wqpc-58rm-xq5r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wqpc-58rm-xq5r", + "modified": "2024-10-17T18:31:37Z", + "published": "2024-10-17T18:31:37Z", + "aliases": [ + "CVE-2024-49244" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in cmssoft CSV Product Import Export for WooCommerce allows SQL Injection.This issue affects CSV Product Import Export for WooCommerce: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49244" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/csv-wc-product-import-export/wordpress-sv-product-import-export-for-woocommerce-plugin-1-0-0-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-wr93-5pfw-4c2v/GHSA-wr93-5pfw-4c2v.json b/advisories/unreviewed/2024/10/GHSA-wr93-5pfw-4c2v/GHSA-wr93-5pfw-4c2v.json index c886e271d25..bd4b9009be6 100644 --- a/advisories/unreviewed/2024/10/GHSA-wr93-5pfw-4c2v/GHSA-wr93-5pfw-4c2v.json +++ b/advisories/unreviewed/2024/10/GHSA-wr93-5pfw-4c2v/GHSA-wr93-5pfw-4c2v.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-306", "CWE-552" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/10/GHSA-wrfv-4288-95xq/GHSA-wrfv-4288-95xq.json b/advisories/unreviewed/2024/10/GHSA-wrfv-4288-95xq/GHSA-wrfv-4288-95xq.json new file mode 100644 index 00000000000..149f2424399 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-wrfv-4288-95xq/GHSA-wrfv-4288-95xq.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wrfv-4288-95xq", + "modified": "2024-10-17T18:31:36Z", + "published": "2024-10-17T18:31:36Z", + "aliases": [ + "CVE-2018-25104" + ], + "details": "A vulnerability was found in CoinGate Plugin up to 1.2.7 on PrestaShop. It has been rated as problematic. Affected by this issue is the function postProcess of the file modules/coingate/controllers/front/callback.php of the component Payment Handler. The manipulation leads to business logic errors. The attack may be launched remotely. Upgrading to version 1.2.8 is able to address this issue. The patch is identified as 0a3097db0aec7c5d66686c142c6abaa1e126ca16. It is recommended to upgrade the affected component.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-25104" + }, + { + "type": "WEB", + "url": "https://github.com/coingate/prestashop-plugin/commit/0a3097db0aec7c5d66686c142c6abaa1e126ca16" + }, + { + "type": "WEB", + "url": "https://github.com/coingate/prestashop-plugin/releases/tag/v1.2.8" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.280358" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.280358" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T16:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-wxpm-572g-x86c/GHSA-wxpm-572g-x86c.json b/advisories/unreviewed/2024/10/GHSA-wxpm-572g-x86c/GHSA-wxpm-572g-x86c.json new file mode 100644 index 00000000000..83db269769c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-wxpm-572g-x86c/GHSA-wxpm-572g-x86c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wxpm-572g-x86c", + "modified": "2024-10-17T18:31:37Z", + "published": "2024-10-17T18:31:37Z", + "aliases": [ + "CVE-2024-49312" + ], + "details": "Server-Side Request Forgery (SSRF) vulnerability in WisdmLabs Edwiser Bridge.This issue affects Edwiser Bridge: from n/a through 3.0.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49312" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/edwiser-bridge/wordpress-edwiser-bridge-plugin-3-0-7-server-side-request-forgery-ssrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-x772-22wg-xfm9/GHSA-x772-22wg-xfm9.json b/advisories/unreviewed/2024/10/GHSA-x772-22wg-xfm9/GHSA-x772-22wg-xfm9.json new file mode 100644 index 00000000000..eacca85f1db --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-x772-22wg-xfm9/GHSA-x772-22wg-xfm9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x772-22wg-xfm9", + "modified": "2024-10-17T18:31:37Z", + "published": "2024-10-17T18:31:37Z", + "aliases": [ + "CVE-2024-49314" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in 酱茄 JiangQie Free Mini Program allows Upload a Web Shell to a Web Server.This issue affects JiangQie Free Mini Program: from n/a through 2.5.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49314" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/jiangqie-free-mini-program/wordpress-jiangqie-free-mini-program-plugin-2-5-2-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-xr9g-f9v2-9m3h/GHSA-xr9g-f9v2-9m3h.json b/advisories/unreviewed/2024/10/GHSA-xr9g-f9v2-9m3h/GHSA-xr9g-f9v2-9m3h.json index c3d93466f5e..cd2a1049070 100644 --- a/advisories/unreviewed/2024/10/GHSA-xr9g-f9v2-9m3h/GHSA-xr9g-f9v2-9m3h.json +++ b/advisories/unreviewed/2024/10/GHSA-xr9g-f9v2-9m3h/GHSA-xr9g-f9v2-9m3h.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xr9g-f9v2-9m3h", - "modified": "2024-10-04T21:31:29Z", + "modified": "2024-10-17T18:31:33Z", "published": "2024-10-04T21:31:29Z", "aliases": [ "CVE-2024-43684" ], "details": "Cross-Site Request Forgery (CSRF) vulnerability in Microchip TimeProvider 4100 allows Cross Site Request Forgery, Cross-Site Scripting (XSS).This issue affects TimeProvider 4100: from 1.0.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:U/V:C/RE:M/U:Amber" diff --git a/advisories/unreviewed/2024/10/GHSA-xvj4-4rq6-7x2w/GHSA-xvj4-4rq6-7x2w.json b/advisories/unreviewed/2024/10/GHSA-xvj4-4rq6-7x2w/GHSA-xvj4-4rq6-7x2w.json index 5949f890242..432c80f72fa 100644 --- a/advisories/unreviewed/2024/10/GHSA-xvj4-4rq6-7x2w/GHSA-xvj4-4rq6-7x2w.json +++ b/advisories/unreviewed/2024/10/GHSA-xvj4-4rq6-7x2w/GHSA-xvj4-4rq6-7x2w.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], "severity": "MODERATE", "github_reviewed": false,