diff --git a/advisories/unreviewed/2022/03/GHSA-38pg-fhjw-6gv5/GHSA-38pg-fhjw-6gv5.json b/advisories/unreviewed/2022/03/GHSA-38pg-fhjw-6gv5/GHSA-38pg-fhjw-6gv5.json index 10db6876a09..1a0a5fd0cf8 100644 --- a/advisories/unreviewed/2022/03/GHSA-38pg-fhjw-6gv5/GHSA-38pg-fhjw-6gv5.json +++ b/advisories/unreviewed/2022/03/GHSA-38pg-fhjw-6gv5/GHSA-38pg-fhjw-6gv5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-38pg-fhjw-6gv5", - "modified": "2022-03-20T00:00:33Z", + "modified": "2024-10-16T12:30:46Z", "published": "2022-03-15T00:01:01Z", "aliases": [ "CVE-2022-24387" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-24387" }, + { + "type": "WEB", + "url": "https://csirt.divd.nl/CVE-2022-24387" + }, { "type": "WEB", "url": "https://csirt.divd.nl/DIVD-2021-00029" diff --git a/advisories/unreviewed/2023/01/GHSA-67q5-5xj6-vp4m/GHSA-67q5-5xj6-vp4m.json b/advisories/unreviewed/2023/01/GHSA-67q5-5xj6-vp4m/GHSA-67q5-5xj6-vp4m.json index 2c1df763122..66d154b38f4 100644 --- a/advisories/unreviewed/2023/01/GHSA-67q5-5xj6-vp4m/GHSA-67q5-5xj6-vp4m.json +++ b/advisories/unreviewed/2023/01/GHSA-67q5-5xj6-vp4m/GHSA-67q5-5xj6-vp4m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-67q5-5xj6-vp4m", - "modified": "2023-01-11T03:30:18Z", + "modified": "2024-10-16T12:30:47Z", "published": "2023-01-04T21:30:19Z", "aliases": [ "CVE-2022-45052" diff --git a/advisories/unreviewed/2023/06/GHSA-6xpq-789w-crhj/GHSA-6xpq-789w-crhj.json b/advisories/unreviewed/2023/06/GHSA-6xpq-789w-crhj/GHSA-6xpq-789w-crhj.json index ccbde5c95cf..99bb990b30e 100644 --- a/advisories/unreviewed/2023/06/GHSA-6xpq-789w-crhj/GHSA-6xpq-789w-crhj.json +++ b/advisories/unreviewed/2023/06/GHSA-6xpq-789w-crhj/GHSA-6xpq-789w-crhj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6xpq-789w-crhj", - "modified": "2024-04-04T04:43:03Z", + "modified": "2024-10-16T12:30:47Z", "published": "2023-06-11T15:30:30Z", "aliases": [ "CVE-2023-22584" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22584" }, + { + "type": "WEB", + "url": "https://csirt.divd.nl/CVE-2023-22584" + }, { "type": "WEB", "url": "https://csirt.divd.nl/DIVD-2023-00021" diff --git a/advisories/unreviewed/2023/06/GHSA-9926-q94j-c3rc/GHSA-9926-q94j-c3rc.json b/advisories/unreviewed/2023/06/GHSA-9926-q94j-c3rc/GHSA-9926-q94j-c3rc.json index a0670246e66..8ca6e3e66c5 100644 --- a/advisories/unreviewed/2023/06/GHSA-9926-q94j-c3rc/GHSA-9926-q94j-c3rc.json +++ b/advisories/unreviewed/2023/06/GHSA-9926-q94j-c3rc/GHSA-9926-q94j-c3rc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9926-q94j-c3rc", - "modified": "2024-04-04T04:43:01Z", + "modified": "2024-10-16T12:30:47Z", "published": "2023-06-11T15:30:30Z", "aliases": [ "CVE-2023-22582" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22582" }, + { + "type": "WEB", + "url": "https://csirt.divd.nl/CVE-2023-22582" + }, { "type": "WEB", "url": "https://csirt.divd.nl/DIVD-2023-00021" diff --git a/advisories/unreviewed/2023/06/GHSA-f3qm-vwjc-2pfv/GHSA-f3qm-vwjc-2pfv.json b/advisories/unreviewed/2023/06/GHSA-f3qm-vwjc-2pfv/GHSA-f3qm-vwjc-2pfv.json index c15b4721216..5b2c8747045 100644 --- a/advisories/unreviewed/2023/06/GHSA-f3qm-vwjc-2pfv/GHSA-f3qm-vwjc-2pfv.json +++ b/advisories/unreviewed/2023/06/GHSA-f3qm-vwjc-2pfv/GHSA-f3qm-vwjc-2pfv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f3qm-vwjc-2pfv", - "modified": "2024-04-04T04:43:07Z", + "modified": "2024-10-16T12:30:47Z", "published": "2023-06-11T15:30:30Z", "aliases": [ "CVE-2023-22586" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22586" }, + { + "type": "WEB", + "url": "https://csirt.divd.nl/CVE-2023-22586" + }, { "type": "WEB", "url": "https://csirt.divd.nl/DIVD-2023-00021" diff --git a/advisories/unreviewed/2023/06/GHSA-m336-3p9f-8r49/GHSA-m336-3p9f-8r49.json b/advisories/unreviewed/2023/06/GHSA-m336-3p9f-8r49/GHSA-m336-3p9f-8r49.json index 84c79ce8b26..77d064f8f12 100644 --- a/advisories/unreviewed/2023/06/GHSA-m336-3p9f-8r49/GHSA-m336-3p9f-8r49.json +++ b/advisories/unreviewed/2023/06/GHSA-m336-3p9f-8r49/GHSA-m336-3p9f-8r49.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m336-3p9f-8r49", - "modified": "2024-04-04T04:43:05Z", + "modified": "2024-10-16T12:30:47Z", "published": "2023-06-11T15:30:30Z", "aliases": [ "CVE-2023-22585" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22585" }, + { + "type": "WEB", + "url": "https://csirt.divd.nl/CVE-2023-22585" + }, { "type": "WEB", "url": "https://csirt.divd.nl/DIVD-2023-00021" diff --git a/advisories/unreviewed/2023/06/GHSA-p3xm-g7cx-5qfp/GHSA-p3xm-g7cx-5qfp.json b/advisories/unreviewed/2023/06/GHSA-p3xm-g7cx-5qfp/GHSA-p3xm-g7cx-5qfp.json index 8332a8b4b11..d51c9fa2411 100644 --- a/advisories/unreviewed/2023/06/GHSA-p3xm-g7cx-5qfp/GHSA-p3xm-g7cx-5qfp.json +++ b/advisories/unreviewed/2023/06/GHSA-p3xm-g7cx-5qfp/GHSA-p3xm-g7cx-5qfp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p3xm-g7cx-5qfp", - "modified": "2024-04-04T04:43:09Z", + "modified": "2024-10-16T12:30:47Z", "published": "2023-06-11T15:30:30Z", "aliases": [ "CVE-2023-25912" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25912" }, + { + "type": "WEB", + "url": "https://csirt.divd.nl/CVE-2023-25912" + }, { "type": "WEB", "url": "https://csirt.divd.nl/DIVD-2023-00021" diff --git a/advisories/unreviewed/2023/06/GHSA-r358-c7w3-46x5/GHSA-r358-c7w3-46x5.json b/advisories/unreviewed/2023/06/GHSA-r358-c7w3-46x5/GHSA-r358-c7w3-46x5.json index 7141a99c515..e725a49ec1d 100644 --- a/advisories/unreviewed/2023/06/GHSA-r358-c7w3-46x5/GHSA-r358-c7w3-46x5.json +++ b/advisories/unreviewed/2023/06/GHSA-r358-c7w3-46x5/GHSA-r358-c7w3-46x5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r358-c7w3-46x5", - "modified": "2024-04-04T04:43:06Z", + "modified": "2024-10-16T12:30:47Z", "published": "2023-06-11T15:30:30Z", "aliases": [ "CVE-2023-25911" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25911" }, + { + "type": "WEB", + "url": "https://csirt.divd.nl/CVE-2023-25911" + }, { "type": "WEB", "url": "https://csirt.divd.nl/DIVD-2023-00021" diff --git a/advisories/unreviewed/2023/06/GHSA-rw57-p6vv-42wg/GHSA-rw57-p6vv-42wg.json b/advisories/unreviewed/2023/06/GHSA-rw57-p6vv-42wg/GHSA-rw57-p6vv-42wg.json index b470704fa4f..922f0f1d7e9 100644 --- a/advisories/unreviewed/2023/06/GHSA-rw57-p6vv-42wg/GHSA-rw57-p6vv-42wg.json +++ b/advisories/unreviewed/2023/06/GHSA-rw57-p6vv-42wg/GHSA-rw57-p6vv-42wg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rw57-p6vv-42wg", - "modified": "2024-04-04T04:43:02Z", + "modified": "2024-10-16T12:30:47Z", "published": "2023-06-11T15:30:30Z", "aliases": [ "CVE-2023-22583" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22583" }, + { + "type": "WEB", + "url": "https://csirt.divd.nl/CVE-2023-22583" + }, { "type": "WEB", "url": "https://csirt.divd.nl/DIVD-2023-00021" diff --git a/advisories/unreviewed/2023/07/GHSA-2xf9-j9jw-g7f7/GHSA-2xf9-j9jw-g7f7.json b/advisories/unreviewed/2023/07/GHSA-2xf9-j9jw-g7f7/GHSA-2xf9-j9jw-g7f7.json index bec966a0fb2..2f239ab89f6 100644 --- a/advisories/unreviewed/2023/07/GHSA-2xf9-j9jw-g7f7/GHSA-2xf9-j9jw-g7f7.json +++ b/advisories/unreviewed/2023/07/GHSA-2xf9-j9jw-g7f7/GHSA-2xf9-j9jw-g7f7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2xf9-j9jw-g7f7", - "modified": "2024-04-04T05:51:16Z", + "modified": "2024-10-16T12:30:47Z", "published": "2023-07-10T18:30:47Z", "aliases": [ "CVE-2021-4406" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://csirt.divd.nl/CVE-2021-4406" }, + { + "type": "WEB", + "url": "https://csirt.divd.nl/DIVD-2021-00020" + }, { "type": "WEB", "url": "https://www.divd.nl/DIVD-2021-00020" diff --git a/advisories/unreviewed/2023/07/GHSA-3x7w-vvg2-w6r8/GHSA-3x7w-vvg2-w6r8.json b/advisories/unreviewed/2023/07/GHSA-3x7w-vvg2-w6r8/GHSA-3x7w-vvg2-w6r8.json index 936022e80e7..3780a39d14d 100644 --- a/advisories/unreviewed/2023/07/GHSA-3x7w-vvg2-w6r8/GHSA-3x7w-vvg2-w6r8.json +++ b/advisories/unreviewed/2023/07/GHSA-3x7w-vvg2-w6r8/GHSA-3x7w-vvg2-w6r8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3x7w-vvg2-w6r8", - "modified": "2024-04-04T05:51:15Z", + "modified": "2024-10-16T12:30:47Z", "published": "2023-07-10T18:30:47Z", "aliases": [ "CVE-2021-42082" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://csirt.divd.nl/CVE-2021-42082" }, + { + "type": "WEB", + "url": "https://csirt.divd.nl/DIVD-2021-00020" + }, { "type": "WEB", "url": "https://www.divd.nl/DIVD-2021-00020" diff --git a/advisories/unreviewed/2023/07/GHSA-4v64-w7v7-ch7f/GHSA-4v64-w7v7-ch7f.json b/advisories/unreviewed/2023/07/GHSA-4v64-w7v7-ch7f/GHSA-4v64-w7v7-ch7f.json index c2fcb972c27..6a4c397800b 100644 --- a/advisories/unreviewed/2023/07/GHSA-4v64-w7v7-ch7f/GHSA-4v64-w7v7-ch7f.json +++ b/advisories/unreviewed/2023/07/GHSA-4v64-w7v7-ch7f/GHSA-4v64-w7v7-ch7f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4v64-w7v7-ch7f", - "modified": "2024-04-04T05:51:11Z", + "modified": "2024-10-16T12:30:47Z", "published": "2023-07-10T18:30:47Z", "aliases": [ "CVE-2021-42079" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-42079" }, + { + "type": "WEB", + "url": "https://cisrt.divd.nl/DIVD-2021-00020" + }, { "type": "WEB", "url": "https://csirt.divd.nl/CVE-2021-42079" diff --git a/advisories/unreviewed/2023/07/GHSA-7g9g-whvg-fhcj/GHSA-7g9g-whvg-fhcj.json b/advisories/unreviewed/2023/07/GHSA-7g9g-whvg-fhcj/GHSA-7g9g-whvg-fhcj.json index 477e3e25ecf..12fbe0c4ca9 100644 --- a/advisories/unreviewed/2023/07/GHSA-7g9g-whvg-fhcj/GHSA-7g9g-whvg-fhcj.json +++ b/advisories/unreviewed/2023/07/GHSA-7g9g-whvg-fhcj/GHSA-7g9g-whvg-fhcj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7g9g-whvg-fhcj", - "modified": "2024-04-04T05:51:13Z", + "modified": "2024-10-16T12:30:47Z", "published": "2023-07-10T18:30:47Z", "aliases": [ "CVE-2021-42081" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://csirt.divd.nl/CVE-2021-42081" }, + { + "type": "WEB", + "url": "https://csirt.divd.nl/DIVD-2021-00020" + }, { "type": "WEB", "url": "https://www.divd.nl/DIVD-2021-00020" diff --git a/advisories/unreviewed/2023/07/GHSA-9c8q-55w7-h67h/GHSA-9c8q-55w7-h67h.json b/advisories/unreviewed/2023/07/GHSA-9c8q-55w7-h67h/GHSA-9c8q-55w7-h67h.json index 3c346d40dfd..9cb8eb66b26 100644 --- a/advisories/unreviewed/2023/07/GHSA-9c8q-55w7-h67h/GHSA-9c8q-55w7-h67h.json +++ b/advisories/unreviewed/2023/07/GHSA-9c8q-55w7-h67h/GHSA-9c8q-55w7-h67h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9c8q-55w7-h67h", - "modified": "2024-01-02T21:30:23Z", + "modified": "2024-10-16T12:30:47Z", "published": "2023-07-10T18:30:47Z", "aliases": [ "CVE-2021-42083" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://csirt.divd.nl/CVE-2021-42083" }, + { + "type": "WEB", + "url": "https://csirt.divd.nl/DIVD-2021-00020" + }, { "type": "WEB", "url": "https://www.divd.nl/DIVD-2021-00020" diff --git a/advisories/unreviewed/2023/07/GHSA-wf5c-q6vq-584r/GHSA-wf5c-q6vq-584r.json b/advisories/unreviewed/2023/07/GHSA-wf5c-q6vq-584r/GHSA-wf5c-q6vq-584r.json index 306a19e8834..ca9b69acf35 100644 --- a/advisories/unreviewed/2023/07/GHSA-wf5c-q6vq-584r/GHSA-wf5c-q6vq-584r.json +++ b/advisories/unreviewed/2023/07/GHSA-wf5c-q6vq-584r/GHSA-wf5c-q6vq-584r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wf5c-q6vq-584r", - "modified": "2024-04-04T05:51:12Z", + "modified": "2024-10-16T12:30:47Z", "published": "2023-07-10T18:30:47Z", "aliases": [ "CVE-2021-42080" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://csirt.divd.nl/CVE-2021-42080" }, + { + "type": "WEB", + "url": "https://csirt.divd.nl/DIVD-2021-00020" + }, { "type": "WEB", "url": "https://www.divd.nl/DIVD-2021-00020" diff --git a/advisories/unreviewed/2024/10/GHSA-74q3-7j69-pcjv/GHSA-74q3-7j69-pcjv.json b/advisories/unreviewed/2024/10/GHSA-74q3-7j69-pcjv/GHSA-74q3-7j69-pcjv.json new file mode 100644 index 00000000000..f4aaf67d51d --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-74q3-7j69-pcjv/GHSA-74q3-7j69-pcjv.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-74q3-7j69-pcjv", + "modified": "2024-10-16T12:30:48Z", + "published": "2024-10-16T12:30:47Z", + "aliases": [ + "CVE-2024-10022" + ], + "details": "A vulnerability classified as critical has been found in code-projects Pharmacy Management System 1.0. This affects an unknown part of the file /php/manage_supplier.php?action=search. The manipulation of the argument text leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10022" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://gist.github.com/higordiego/2bd0a94e480906a60ce83b8a4ec26957" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.280557" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.280557" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.424337" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T12:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-7qqw-h3cr-wwj4/GHSA-7qqw-h3cr-wwj4.json b/advisories/unreviewed/2024/10/GHSA-7qqw-h3cr-wwj4/GHSA-7qqw-h3cr-wwj4.json new file mode 100644 index 00000000000..deebe50fcd1 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-7qqw-h3cr-wwj4/GHSA-7qqw-h3cr-wwj4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7qqw-h3cr-wwj4", + "modified": "2024-10-16T12:30:47Z", + "published": "2024-10-16T12:30:47Z", + "aliases": [ + "CVE-2024-6380" + ], + "details": "A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6380" + }, + { + "type": "WEB", + "url": "https://www.3ds.com/vulnerability/advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T12:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-9v2g-7h8m-q5hc/GHSA-9v2g-7h8m-q5hc.json b/advisories/unreviewed/2024/10/GHSA-9v2g-7h8m-q5hc/GHSA-9v2g-7h8m-q5hc.json new file mode 100644 index 00000000000..b590504dbef --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-9v2g-7h8m-q5hc/GHSA-9v2g-7h8m-q5hc.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9v2g-7h8m-q5hc", + "modified": "2024-10-16T12:30:47Z", + "published": "2024-10-16T12:30:47Z", + "aliases": [ + "CVE-2024-8921" + ], + "details": "The Zita Elementor Site Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.6.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8921" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/zita-site-library/trunk/importer/wxr-importer.php#L160" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/zita-site-library/trunk/inc/importer.php#L148" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3168327" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/zita-site-library/#developers" + }, + { + "type": "WEB", + "url": "https://wpzita.com/changelog" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/cc1c76ee-078d-4c9a-a4d3-063d9147d7e8?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T11:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-f97f-26jc-gffx/GHSA-f97f-26jc-gffx.json b/advisories/unreviewed/2024/10/GHSA-f97f-26jc-gffx/GHSA-f97f-26jc-gffx.json new file mode 100644 index 00000000000..ce0b67cb715 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-f97f-26jc-gffx/GHSA-f97f-26jc-gffx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f97f-26jc-gffx", + "modified": "2024-10-16T12:30:47Z", + "published": "2024-10-16T12:30:47Z", + "aliases": [ + "CVE-2023-32190" + ], + "details": "mlocate's %post script allows RUN_UPDATEDB_AS user to make arbitrary files world readable by abusing insecure file operations that run with root privileges.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32190" + }, + { + "type": "WEB", + "url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2023-32190" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T12:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-mmj7-9q6x-r9fw/GHSA-mmj7-9q6x-r9fw.json b/advisories/unreviewed/2024/10/GHSA-mmj7-9q6x-r9fw/GHSA-mmj7-9q6x-r9fw.json new file mode 100644 index 00000000000..585a9917cc1 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-mmj7-9q6x-r9fw/GHSA-mmj7-9q6x-r9fw.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mmj7-9q6x-r9fw", + "modified": "2024-10-16T12:30:48Z", + "published": "2024-10-16T12:30:48Z", + "aliases": [ + "CVE-2024-10021" + ], + "details": "A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /php/manage_purchase.php?action=search&tag=VOUCHER_NUMBER. The manipulation of the argument text leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10021" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://gist.github.com/higordiego/439f2af836c2c7d6075ba9de2e1169da" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.280556" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.280556" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.424334" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T12:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-pf8q-v3qp-47xw/GHSA-pf8q-v3qp-47xw.json b/advisories/unreviewed/2024/10/GHSA-pf8q-v3qp-47xw/GHSA-pf8q-v3qp-47xw.json new file mode 100644 index 00000000000..97f8b45064d --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-pf8q-v3qp-47xw/GHSA-pf8q-v3qp-47xw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pf8q-v3qp-47xw", + "modified": "2024-10-16T12:30:48Z", + "published": "2024-10-16T12:30:48Z", + "aliases": [ + "CVE-2024-8040" + ], + "details": "An authorization bypass through user-controlled key vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2024x allows an authenticated attacker to access some unauthorized data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8040" + }, + { + "type": "WEB", + "url": "https://www.3ds.com/vulnerability/advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T12:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-qh3h-ppj3-p38m/GHSA-qh3h-ppj3-p38m.json b/advisories/unreviewed/2024/10/GHSA-qh3h-ppj3-p38m/GHSA-qh3h-ppj3-p38m.json new file mode 100644 index 00000000000..e9d21110cad --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-qh3h-ppj3-p38m/GHSA-qh3h-ppj3-p38m.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qh3h-ppj3-p38m", + "modified": "2024-10-16T12:30:47Z", + "published": "2024-10-16T12:30:47Z", + "aliases": [ + "CVE-2024-9444" + ], + "details": "The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9444" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/element-ready-lite/trunk/inc/helper_functions.php#L1559" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3167864" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/element-ready-lite/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/bea7a4d0-d589-420b-a4ff-eaccf12e623b?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T10:15:02Z" + } +} \ No newline at end of file