diff --git a/advisories/unreviewed/2024/02/GHSA-268r-8rwm-mqq9/GHSA-268r-8rwm-mqq9.json b/advisories/unreviewed/2024/02/GHSA-268r-8rwm-mqq9/GHSA-268r-8rwm-mqq9.json index e7e43041a88..ae5306299c4 100644 --- a/advisories/unreviewed/2024/02/GHSA-268r-8rwm-mqq9/GHSA-268r-8rwm-mqq9.json +++ b/advisories/unreviewed/2024/02/GHSA-268r-8rwm-mqq9/GHSA-268r-8rwm-mqq9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-268r-8rwm-mqq9", - "modified": "2024-06-27T12:30:43Z", + "modified": "2024-11-04T15:31:51Z", "published": "2024-02-22T18:30:29Z", "aliases": [ "CVE-2023-52449" diff --git a/advisories/unreviewed/2024/03/GHSA-25m9-3j97-v6cg/GHSA-25m9-3j97-v6cg.json b/advisories/unreviewed/2024/03/GHSA-25m9-3j97-v6cg/GHSA-25m9-3j97-v6cg.json index b6a59b12902..158f1935e35 100644 --- a/advisories/unreviewed/2024/03/GHSA-25m9-3j97-v6cg/GHSA-25m9-3j97-v6cg.json +++ b/advisories/unreviewed/2024/03/GHSA-25m9-3j97-v6cg/GHSA-25m9-3j97-v6cg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-25m9-3j97-v6cg", - "modified": "2024-06-27T15:30:38Z", + "modified": "2024-11-04T15:31:53Z", "published": "2024-03-26T18:32:06Z", "aliases": [ "CVE-2023-52622" diff --git a/advisories/unreviewed/2024/03/GHSA-8jm2-4r4f-748v/GHSA-8jm2-4r4f-748v.json b/advisories/unreviewed/2024/03/GHSA-8jm2-4r4f-748v/GHSA-8jm2-4r4f-748v.json index 7346e4c7235..bb27039048b 100644 --- a/advisories/unreviewed/2024/03/GHSA-8jm2-4r4f-748v/GHSA-8jm2-4r4f-748v.json +++ b/advisories/unreviewed/2024/03/GHSA-8jm2-4r4f-748v/GHSA-8jm2-4r4f-748v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8jm2-4r4f-748v", - "modified": "2024-03-25T06:30:23Z", + "modified": "2024-11-04T15:31:53Z", "published": "2024-03-25T06:30:23Z", "aliases": [ "CVE-2024-29071" ], "details": "HGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue. A network-adjacent unauthenticated attacker may change the system settings.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-522" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-25T04:15:09Z" diff --git a/advisories/unreviewed/2024/10/GHSA-43hm-c86x-ppxj/GHSA-43hm-c86x-ppxj.json b/advisories/unreviewed/2024/10/GHSA-43hm-c86x-ppxj/GHSA-43hm-c86x-ppxj.json index 29d9731c891..07598928218 100644 --- a/advisories/unreviewed/2024/10/GHSA-43hm-c86x-ppxj/GHSA-43hm-c86x-ppxj.json +++ b/advisories/unreviewed/2024/10/GHSA-43hm-c86x-ppxj/GHSA-43hm-c86x-ppxj.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-639" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-4vhv-rmg8-wc9v/GHSA-4vhv-rmg8-wc9v.json b/advisories/unreviewed/2024/10/GHSA-4vhv-rmg8-wc9v/GHSA-4vhv-rmg8-wc9v.json index fb99bf3cba6..1f801faefa8 100644 --- a/advisories/unreviewed/2024/10/GHSA-4vhv-rmg8-wc9v/GHSA-4vhv-rmg8-wc9v.json +++ b/advisories/unreviewed/2024/10/GHSA-4vhv-rmg8-wc9v/GHSA-4vhv-rmg8-wc9v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4vhv-rmg8-wc9v", - "modified": "2024-10-30T15:30:44Z", + "modified": "2024-11-04T15:31:54Z", "published": "2024-10-11T15:30:33Z", "aliases": [ "CVE-2024-6657" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://community.silabs.com/068Vm00000FPVg0" }, + { + "type": "WEB", + "url": "https://community.silabs.com/068Vm00000FfVNN" + }, { "type": "WEB", "url": "https://siliconlabs.lightning.force.com/sfc/servlet.shepherd/document/download/069Vm00000E9IIbIAN?operationContext=S1" diff --git a/advisories/unreviewed/2024/10/GHSA-9v98-vwhg-6x24/GHSA-9v98-vwhg-6x24.json b/advisories/unreviewed/2024/10/GHSA-9v98-vwhg-6x24/GHSA-9v98-vwhg-6x24.json index e9b343d6ef5..0078e070261 100644 --- a/advisories/unreviewed/2024/10/GHSA-9v98-vwhg-6x24/GHSA-9v98-vwhg-6x24.json +++ b/advisories/unreviewed/2024/10/GHSA-9v98-vwhg-6x24/GHSA-9v98-vwhg-6x24.json @@ -44,7 +44,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-120" + "CWE-120", + "CWE-787" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-xhw3-h8gq-2w23/GHSA-xhw3-h8gq-2w23.json b/advisories/unreviewed/2024/10/GHSA-xhw3-h8gq-2w23/GHSA-xhw3-h8gq-2w23.json index ca646777cd5..48a364f5611 100644 --- a/advisories/unreviewed/2024/10/GHSA-xhw3-h8gq-2w23/GHSA-xhw3-h8gq-2w23.json +++ b/advisories/unreviewed/2024/10/GHSA-xhw3-h8gq-2w23/GHSA-xhw3-h8gq-2w23.json @@ -36,6 +36,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-362", "CWE-770" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2024/11/GHSA-287m-m4rw-v572/GHSA-287m-m4rw-v572.json b/advisories/unreviewed/2024/11/GHSA-287m-m4rw-v572/GHSA-287m-m4rw-v572.json new file mode 100644 index 00000000000..f1c88c5ab9c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-287m-m4rw-v572/GHSA-287m-m4rw-v572.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-287m-m4rw-v572", + "modified": "2024-11-04T15:31:58Z", + "published": "2024-11-04T15:31:58Z", + "aliases": [ + "CVE-2024-51246" + ], + "details": "In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPTP function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51246" + }, + { + "type": "WEB", + "url": "https://github.com/fu37kola/cve/blob/main/DrayTek/Vigor3900/1.5.1.3/DrayTek_Vigor_3900_1.5.1.3.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T14:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-2h8f-5758-wfx8/GHSA-2h8f-5758-wfx8.json b/advisories/unreviewed/2024/11/GHSA-2h8f-5758-wfx8/GHSA-2h8f-5758-wfx8.json new file mode 100644 index 00000000000..e0aa8ff503a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-2h8f-5758-wfx8/GHSA-2h8f-5758-wfx8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2h8f-5758-wfx8", + "modified": "2024-11-04T15:31:59Z", + "published": "2024-11-04T15:31:59Z", + "aliases": [ + "CVE-2024-51681" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CodeRevolution WP Pocket URLs allows Stored XSS.This issue affects WP Pocket URLs: from n/a through 1.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51681" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-pocket-urls/wordpress-wp-pocket-urls-plugin-1-0-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T15:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-2hx5-4rrf-crcp/GHSA-2hx5-4rrf-crcp.json b/advisories/unreviewed/2024/11/GHSA-2hx5-4rrf-crcp/GHSA-2hx5-4rrf-crcp.json index ee585e3659f..0bdad0c191f 100644 --- a/advisories/unreviewed/2024/11/GHSA-2hx5-4rrf-crcp/GHSA-2hx5-4rrf-crcp.json +++ b/advisories/unreviewed/2024/11/GHSA-2hx5-4rrf-crcp/GHSA-2hx5-4rrf-crcp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2hx5-4rrf-crcp", - "modified": "2024-11-01T21:31:51Z", + "modified": "2024-11-04T15:31:56Z", "published": "2024-11-01T21:31:51Z", "aliases": [ "CVE-2024-44234" ], "details": "The issue was addressed with improved bounds checks. This issue is fixed in macOS Sonoma 14.7.1, macOS Ventura 13.7.1, visionOS 2.1, watchOS 11.1, tvOS 18.1, iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1. Parsing a maliciously crafted video file may lead to unexpected system termination.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -51,7 +54,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-01T21:15:14Z" diff --git a/advisories/unreviewed/2024/11/GHSA-2php-rv2v-c3w8/GHSA-2php-rv2v-c3w8.json b/advisories/unreviewed/2024/11/GHSA-2php-rv2v-c3w8/GHSA-2php-rv2v-c3w8.json new file mode 100644 index 00000000000..ab2cf64b416 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-2php-rv2v-c3w8/GHSA-2php-rv2v-c3w8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2php-rv2v-c3w8", + "modified": "2024-11-04T15:31:59Z", + "published": "2024-11-04T15:31:59Z", + "aliases": [ + "CVE-2024-51683" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Michael Gangolf Custom post type templates for Elementor allows Stored XSS.This issue affects Custom post type templates for Elementor: from n/a through 1.10.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51683" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/custom-post-type-templates-for-elementor/wordpress-custom-post-type-templates-for-elementor-plugin-1-10-1-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T15:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-2qxr-7mvv-54x4/GHSA-2qxr-7mvv-54x4.json b/advisories/unreviewed/2024/11/GHSA-2qxr-7mvv-54x4/GHSA-2qxr-7mvv-54x4.json new file mode 100644 index 00000000000..aaa99a4ff17 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-2qxr-7mvv-54x4/GHSA-2qxr-7mvv-54x4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2qxr-7mvv-54x4", + "modified": "2024-11-04T15:31:58Z", + "published": "2024-11-04T15:31:58Z", + "aliases": [ + "CVE-2024-51251" + ], + "details": "In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the backup function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51251" + }, + { + "type": "WEB", + "url": "https://github.com/fu37kola/cve/blob/main/DrayTek/Vigor3900/1.5.1.3/DrayTek_Vigor_3900_1.5.1.3.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T14:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-2r6v-v2j7-w3xh/GHSA-2r6v-v2j7-w3xh.json b/advisories/unreviewed/2024/11/GHSA-2r6v-v2j7-w3xh/GHSA-2r6v-v2j7-w3xh.json new file mode 100644 index 00000000000..212de0dea3c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-2r6v-v2j7-w3xh/GHSA-2r6v-v2j7-w3xh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2r6v-v2j7-w3xh", + "modified": "2024-11-04T15:31:58Z", + "published": "2024-11-04T15:31:58Z", + "aliases": [ + "CVE-2024-51672" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPDeveloper BetterLinks allows SQL Injection.This issue affects BetterLinks: from n/a through 2.1.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51672" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/betterlinks/wordpress-betterlinks-plugin-2-1-7-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T14:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-32h9-hqhx-9j29/GHSA-32h9-hqhx-9j29.json b/advisories/unreviewed/2024/11/GHSA-32h9-hqhx-9j29/GHSA-32h9-hqhx-9j29.json new file mode 100644 index 00000000000..e2ce7afe0e7 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-32h9-hqhx-9j29/GHSA-32h9-hqhx-9j29.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-32h9-hqhx-9j29", + "modified": "2024-11-04T15:31:57Z", + "published": "2024-11-04T15:31:57Z", + "aliases": [ + "CVE-2024-51560" + ], + "details": "This vulnerability exists in the Wave 2.0 due to improper exception handling for invalid inputs at certain API endpoint. An authenticated remote attacker could exploit this vulnerability by providing invalid inputs for “userId” parameter in the API request leading to generation of error message containing sensitive information on the targeted system.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51560" + }, + { + "type": "WEB", + "url": "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0332" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-209" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T13:17:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-45f9-c4pq-qxgq/GHSA-45f9-c4pq-qxgq.json b/advisories/unreviewed/2024/11/GHSA-45f9-c4pq-qxgq/GHSA-45f9-c4pq-qxgq.json new file mode 100644 index 00000000000..0c6e3ddf9dc --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-45f9-c4pq-qxgq/GHSA-45f9-c4pq-qxgq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-45f9-c4pq-qxgq", + "modified": "2024-11-04T15:31:58Z", + "published": "2024-11-04T15:31:58Z", + "aliases": [ + "CVE-2024-50530" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Myriad Solutionz Stars SMTP Mailer allows Upload a Web Shell to a Web Server.This issue affects Stars SMTP Mailer: from n/a through 1.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50530" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/stars-smtp-mailer/wordpress-stars-smtp-mailer-plugin-1-7-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T14:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4964-vg4p-rr2m/GHSA-4964-vg4p-rr2m.json b/advisories/unreviewed/2024/11/GHSA-4964-vg4p-rr2m/GHSA-4964-vg4p-rr2m.json index ef5c8078af8..560e05930b1 100644 --- a/advisories/unreviewed/2024/11/GHSA-4964-vg4p-rr2m/GHSA-4964-vg4p-rr2m.json +++ b/advisories/unreviewed/2024/11/GHSA-4964-vg4p-rr2m/GHSA-4964-vg4p-rr2m.json @@ -48,7 +48,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-4j38-c7m4-7f9g/GHSA-4j38-c7m4-7f9g.json b/advisories/unreviewed/2024/11/GHSA-4j38-c7m4-7f9g/GHSA-4j38-c7m4-7f9g.json new file mode 100644 index 00000000000..d5fb8d1f760 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4j38-c7m4-7f9g/GHSA-4j38-c7m4-7f9g.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4j38-c7m4-7f9g", + "modified": "2024-11-04T15:31:58Z", + "published": "2024-11-04T15:31:58Z", + "aliases": [ + "CVE-2024-45882" + ], + "details": "DrayTek Vigor3900 1.5.1.3 contains a command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `delete_map_profile.`", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45882" + }, + { + "type": "WEB", + "url": "https://github.com/N1nEmAn/wp/blob/main/test_v.zip" + }, + { + "type": "WEB", + "url": "https://github.com/fu37kola/cve/blob/main/DrayTek/Vigor3900/1.5.1.3/DrayTek_Vigor_3900_1.5.1.3.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T15:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-5g37-4gxg-27m8/GHSA-5g37-4gxg-27m8.json b/advisories/unreviewed/2024/11/GHSA-5g37-4gxg-27m8/GHSA-5g37-4gxg-27m8.json new file mode 100644 index 00000000000..dd32c8e7a46 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-5g37-4gxg-27m8/GHSA-5g37-4gxg-27m8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5g37-4gxg-27m8", + "modified": "2024-11-04T15:31:56Z", + "published": "2024-11-04T15:31:56Z", + "aliases": [ + "CVE-2024-51557" + ], + "details": "This vulnerability exists in the Wave 2.0 due to missing rate limiting on OTP requests in an API endpoint. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoint which could lead to the OTP bombing/flooding on the targeted system.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51557" + }, + { + "type": "WEB", + "url": "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0332" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-799" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T13:17:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-5ghj-4886-p5v8/GHSA-5ghj-4886-p5v8.json b/advisories/unreviewed/2024/11/GHSA-5ghj-4886-p5v8/GHSA-5ghj-4886-p5v8.json index 501ca4c9001..5cd914d6897 100644 --- a/advisories/unreviewed/2024/11/GHSA-5ghj-4886-p5v8/GHSA-5ghj-4886-p5v8.json +++ b/advisories/unreviewed/2024/11/GHSA-5ghj-4886-p5v8/GHSA-5ghj-4886-p5v8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5ghj-4886-p5v8", - "modified": "2024-11-02T09:32:25Z", + "modified": "2024-11-04T15:31:56Z", "published": "2024-11-02T09:32:25Z", "aliases": [ "CVE-2024-9896" diff --git a/advisories/unreviewed/2024/11/GHSA-5h53-fxq2-2832/GHSA-5h53-fxq2-2832.json b/advisories/unreviewed/2024/11/GHSA-5h53-fxq2-2832/GHSA-5h53-fxq2-2832.json new file mode 100644 index 00000000000..bc51f85d2cd --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-5h53-fxq2-2832/GHSA-5h53-fxq2-2832.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5h53-fxq2-2832", + "modified": "2024-11-04T15:31:59Z", + "published": "2024-11-04T15:31:59Z", + "aliases": [ + "CVE-2024-51685" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Michael Gangolf Accordion title for Elementor allows Stored XSS.This issue affects Accordion title for Elementor: from n/a through 1.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51685" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/accordion-title-for-elementor/wordpress-accordion-title-for-elementor-plugin-1-2-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T15:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-5m99-8v6r-q8c5/GHSA-5m99-8v6r-q8c5.json b/advisories/unreviewed/2024/11/GHSA-5m99-8v6r-q8c5/GHSA-5m99-8v6r-q8c5.json new file mode 100644 index 00000000000..287cefe9ba5 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-5m99-8v6r-q8c5/GHSA-5m99-8v6r-q8c5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5m99-8v6r-q8c5", + "modified": "2024-11-04T15:31:58Z", + "published": "2024-11-04T15:31:58Z", + "aliases": [ + "CVE-2024-51249" + ], + "details": "In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the reboot function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51249" + }, + { + "type": "WEB", + "url": "https://github.com/fu37kola/cve/blob/main/DrayTek/Vigor3900/1.5.1.3/DrayTek_Vigor_3900_1.5.1.3.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T14:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-6f3j-5p9m-h744/GHSA-6f3j-5p9m-h744.json b/advisories/unreviewed/2024/11/GHSA-6f3j-5p9m-h744/GHSA-6f3j-5p9m-h744.json new file mode 100644 index 00000000000..1e11b9e186f --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6f3j-5p9m-h744/GHSA-6f3j-5p9m-h744.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6f3j-5p9m-h744", + "modified": "2024-11-04T15:31:59Z", + "published": "2024-11-04T15:31:59Z", + "aliases": [ + "CVE-2024-51677" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WebberZone Knowledge Base allows Stored XSS.This issue affects Knowledge Base: from n/a through 2.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51677" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/knowledgebase/wordpress-knowledge-base-plugin-2-2-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-6pw7-57q6-83j4/GHSA-6pw7-57q6-83j4.json b/advisories/unreviewed/2024/11/GHSA-6pw7-57q6-83j4/GHSA-6pw7-57q6-83j4.json new file mode 100644 index 00000000000..5b603f1c274 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6pw7-57q6-83j4/GHSA-6pw7-57q6-83j4.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6pw7-57q6-83j4", + "modified": "2024-11-04T15:31:58Z", + "published": "2024-11-04T15:31:58Z", + "aliases": [ + "CVE-2024-45889" + ], + "details": "DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `commandTable.`", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45889" + }, + { + "type": "WEB", + "url": "https://github.com/N1nEmAn/wp/blob/main/test_v.zip" + }, + { + "type": "WEB", + "url": "https://github.com/fu37kola/cve/blob/main/DrayTek/Vigor3900/1.5.1.3/DrayTek_Vigor_3900_1.5.1.3.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-6w35-x982-hj9h/GHSA-6w35-x982-hj9h.json b/advisories/unreviewed/2024/11/GHSA-6w35-x982-hj9h/GHSA-6w35-x982-hj9h.json new file mode 100644 index 00000000000..bbeaa2a1386 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6w35-x982-hj9h/GHSA-6w35-x982-hj9h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6w35-x982-hj9h", + "modified": "2024-11-04T15:31:56Z", + "published": "2024-11-04T15:31:56Z", + "aliases": [ + "CVE-2024-51556" + ], + "details": "This vulnerability exists in the Wave 2.0 due to weak encryption of sensitive data received at the API response. An authenticated remote attacker could exploit this vulnerability by manipulating a parameter “user_id” through API request URLs leading to unauthorized access to sensitive information belonging to other users.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51556" + }, + { + "type": "WEB", + "url": "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0332" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-327" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T13:17:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-72rv-wmp8-fpjh/GHSA-72rv-wmp8-fpjh.json b/advisories/unreviewed/2024/11/GHSA-72rv-wmp8-fpjh/GHSA-72rv-wmp8-fpjh.json new file mode 100644 index 00000000000..9b618c98ca1 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-72rv-wmp8-fpjh/GHSA-72rv-wmp8-fpjh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-72rv-wmp8-fpjh", + "modified": "2024-11-04T15:31:58Z", + "published": "2024-11-04T15:31:58Z", + "aliases": [ + "CVE-2024-50526" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in mahlamusa Multi Purpose Mail Form allows Upload a Web Shell to a Web Server.This issue affects Multi Purpose Mail Form: from n/a through 1.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50526" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/multi-purpose-mail-form/wordpress-multi-purpose-mail-form-plugin-1-0-2-arbitrary-file-upload-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T14:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-7fwp-9vj9-hr6v/GHSA-7fwp-9vj9-hr6v.json b/advisories/unreviewed/2024/11/GHSA-7fwp-9vj9-hr6v/GHSA-7fwp-9vj9-hr6v.json index a5f5cbbc62d..89707497b13 100644 --- a/advisories/unreviewed/2024/11/GHSA-7fwp-9vj9-hr6v/GHSA-7fwp-9vj9-hr6v.json +++ b/advisories/unreviewed/2024/11/GHSA-7fwp-9vj9-hr6v/GHSA-7fwp-9vj9-hr6v.json @@ -44,6 +44,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-707", "CWE-89" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/11/GHSA-8mpm-hxpc-x9h5/GHSA-8mpm-hxpc-x9h5.json b/advisories/unreviewed/2024/11/GHSA-8mpm-hxpc-x9h5/GHSA-8mpm-hxpc-x9h5.json index 4e958557cae..d46b74fa47b 100644 --- a/advisories/unreviewed/2024/11/GHSA-8mpm-hxpc-x9h5/GHSA-8mpm-hxpc-x9h5.json +++ b/advisories/unreviewed/2024/11/GHSA-8mpm-hxpc-x9h5/GHSA-8mpm-hxpc-x9h5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8mpm-hxpc-x9h5", - "modified": "2024-11-02T03:32:30Z", + "modified": "2024-11-04T15:31:56Z", "published": "2024-11-02T03:32:30Z", "aliases": [ "CVE-2024-10540" diff --git a/advisories/unreviewed/2024/11/GHSA-8qc4-f7m5-569p/GHSA-8qc4-f7m5-569p.json b/advisories/unreviewed/2024/11/GHSA-8qc4-f7m5-569p/GHSA-8qc4-f7m5-569p.json new file mode 100644 index 00000000000..e40d023cf4e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-8qc4-f7m5-569p/GHSA-8qc4-f7m5-569p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8qc4-f7m5-569p", + "modified": "2024-11-04T15:31:58Z", + "published": "2024-11-04T15:31:58Z", + "aliases": [ + "CVE-2024-50529" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Rudra Innnovative Software Training – Courses allows Upload a Web Shell to a Web Server.This issue affects Training – Courses: from n/a through 2.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50529" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/training/wordpress-training-courses-plugin-2-0-1-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T14:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-94hw-32gv-86pf/GHSA-94hw-32gv-86pf.json b/advisories/unreviewed/2024/11/GHSA-94hw-32gv-86pf/GHSA-94hw-32gv-86pf.json new file mode 100644 index 00000000000..0dab52581c7 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-94hw-32gv-86pf/GHSA-94hw-32gv-86pf.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-94hw-32gv-86pf", + "modified": "2024-11-04T15:31:58Z", + "published": "2024-11-04T15:31:58Z", + "aliases": [ + "CVE-2024-51408" + ], + "details": "AppSmith Community 1.8.3 before 1.46 allows SSRF via New DataSource for application/json requests to 169.254.169.254 to retrieve AWS metadata credentials.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51408" + }, + { + "type": "WEB", + "url": "https://github.com/appsmithorg/appsmith/pull/29286" + }, + { + "type": "WEB", + "url": "https://github.com/appsmithorg/appsmith/releases/tag/v1.46" + }, + { + "type": "WEB", + "url": "https://github.com/jahithoque/Vulnerability-Research/tree/main/CVE-2024-51408" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T14:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-96wr-9r65-6g5q/GHSA-96wr-9r65-6g5q.json b/advisories/unreviewed/2024/11/GHSA-96wr-9r65-6g5q/GHSA-96wr-9r65-6g5q.json new file mode 100644 index 00000000000..d72ac0d6b54 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-96wr-9r65-6g5q/GHSA-96wr-9r65-6g5q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-96wr-9r65-6g5q", + "modified": "2024-11-04T15:31:58Z", + "published": "2024-11-04T15:31:58Z", + "aliases": [ + "CVE-2024-51665" + ], + "details": "Server-Side Request Forgery (SSRF) vulnerability in Noor alam Magical Addons For Elementor allows Server Side Request Forgery.This issue affects Magical Addons For Elementor: from n/a through 1.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51665" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/magical-addons-for-elementor/wordpress-magical-addons-for-elementor-plugin-1-2-1-server-side-request-forgery-ssrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T14:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9mxh-r848-c325/GHSA-9mxh-r848-c325.json b/advisories/unreviewed/2024/11/GHSA-9mxh-r848-c325/GHSA-9mxh-r848-c325.json new file mode 100644 index 00000000000..2b0a2b06ff4 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9mxh-r848-c325/GHSA-9mxh-r848-c325.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9mxh-r848-c325", + "modified": "2024-11-04T15:31:59Z", + "published": "2024-11-04T15:31:59Z", + "aliases": [ + "CVE-2024-51682" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in HasThemes HT Builder – WordPress Theme Builder for Elementor allows Stored XSS.This issue affects HT Builder – WordPress Theme Builder for Elementor: from n/a through 1.3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51682" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ht-builder/wordpress-ht-builder-wordpress-theme-builder-for-elementor-plugin-1-3-0-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T15:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9xwg-wxgq-6vph/GHSA-9xwg-wxgq-6vph.json b/advisories/unreviewed/2024/11/GHSA-9xwg-wxgq-6vph/GHSA-9xwg-wxgq-6vph.json new file mode 100644 index 00000000000..b4db30056b7 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9xwg-wxgq-6vph/GHSA-9xwg-wxgq-6vph.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9xwg-wxgq-6vph", + "modified": "2024-11-04T15:31:57Z", + "published": "2024-11-04T15:31:57Z", + "aliases": [ + "CVE-2024-51558" + ], + "details": "This vulnerability exists in the Wave 2.0 due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker could exploit this vulnerability by conducting a brute force attack against legitimate user OTP, MPIN or password, which could lead to gain unauthorized access and compromise other user accounts.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51558" + }, + { + "type": "WEB", + "url": "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0332" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-307" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T13:17:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-f9j4-243j-7p57/GHSA-f9j4-243j-7p57.json b/advisories/unreviewed/2024/11/GHSA-f9j4-243j-7p57/GHSA-f9j4-243j-7p57.json new file mode 100644 index 00000000000..0bb01cd1db6 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-f9j4-243j-7p57/GHSA-f9j4-243j-7p57.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f9j4-243j-7p57", + "modified": "2024-11-04T15:31:57Z", + "published": "2024-11-04T15:31:57Z", + "aliases": [ + "CVE-2024-50523" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in RainbowLink Inc. All Post Contact Form allows Upload a Web Shell to a Web Server.This issue affects All Post Contact Form: from n/a through 1.7.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50523" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/allpost-contactform/wordpress-all-post-contact-form-plugin-1-6-7-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T14:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-fqg9-xpjx-879w/GHSA-fqg9-xpjx-879w.json b/advisories/unreviewed/2024/11/GHSA-fqg9-xpjx-879w/GHSA-fqg9-xpjx-879w.json new file mode 100644 index 00000000000..8e9f500cdad --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-fqg9-xpjx-879w/GHSA-fqg9-xpjx-879w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fqg9-xpjx-879w", + "modified": "2024-11-04T15:31:58Z", + "published": "2024-11-04T15:31:58Z", + "aliases": [ + "CVE-2024-50531" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in David F. Carr RSVPMaker for Toastmasters allows Upload a Web Shell to a Web Server.This issue affects RSVPMaker for Toastmasters: from n/a through 6.2.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50531" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/rsvpmaker-for-toastmasters/wordpress-rsvpmaker-for-toastmasters-plugin-6-2-4-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T14:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-g6pp-x9v7-qxm2/GHSA-g6pp-x9v7-qxm2.json b/advisories/unreviewed/2024/11/GHSA-g6pp-x9v7-qxm2/GHSA-g6pp-x9v7-qxm2.json new file mode 100644 index 00000000000..a749783b274 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-g6pp-x9v7-qxm2/GHSA-g6pp-x9v7-qxm2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g6pp-x9v7-qxm2", + "modified": "2024-11-04T15:31:58Z", + "published": "2024-11-04T15:31:58Z", + "aliases": [ + "CVE-2024-51253" + ], + "details": "In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doL2TP function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51253" + }, + { + "type": "WEB", + "url": "https://github.com/fu37kola/cve/blob/main/DrayTek/Vigor3900/1.5.1.3/DrayTek_Vigor_3900_1.5.1.3.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T14:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-gpj2-23jf-pgq2/GHSA-gpj2-23jf-pgq2.json b/advisories/unreviewed/2024/11/GHSA-gpj2-23jf-pgq2/GHSA-gpj2-23jf-pgq2.json new file mode 100644 index 00000000000..6ea126da247 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-gpj2-23jf-pgq2/GHSA-gpj2-23jf-pgq2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gpj2-23jf-pgq2", + "modified": "2024-11-04T15:31:58Z", + "published": "2024-11-04T15:31:58Z", + "aliases": [ + "CVE-2024-51582" + ], + "details": "Path Traversal: '.../...//' vulnerability in ThimPress WP Hotel Booking allows PHP Local File Inclusion.This issue affects WP Hotel Booking: from n/a through 2.1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51582" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-hotel-booking/wordpress-wp-hotel-booking-plugin-2-1-4-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-35" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T14:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-hfxc-7rp9-xw9w/GHSA-hfxc-7rp9-xw9w.json b/advisories/unreviewed/2024/11/GHSA-hfxc-7rp9-xw9w/GHSA-hfxc-7rp9-xw9w.json index 654f56b0984..811e6c61650 100644 --- a/advisories/unreviewed/2024/11/GHSA-hfxc-7rp9-xw9w/GHSA-hfxc-7rp9-xw9w.json +++ b/advisories/unreviewed/2024/11/GHSA-hfxc-7rp9-xw9w/GHSA-hfxc-7rp9-xw9w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hfxc-7rp9-xw9w", - "modified": "2024-11-02T06:32:01Z", + "modified": "2024-11-04T15:31:56Z", "published": "2024-11-02T06:32:01Z", "aliases": [ "CVE-2024-51774" ], "details": "qBittorrent before 5.0.1 proceeds with use of https URLs even after certificate validation errors.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-295" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-02T06:15:03Z" diff --git a/advisories/unreviewed/2024/11/GHSA-hjhx-mr4r-6j6j/GHSA-hjhx-mr4r-6j6j.json b/advisories/unreviewed/2024/11/GHSA-hjhx-mr4r-6j6j/GHSA-hjhx-mr4r-6j6j.json new file mode 100644 index 00000000000..127e9993f3a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-hjhx-mr4r-6j6j/GHSA-hjhx-mr4r-6j6j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hjhx-mr4r-6j6j", + "modified": "2024-11-04T15:31:57Z", + "published": "2024-11-04T15:31:57Z", + "aliases": [ + "CVE-2024-51559" + ], + "details": "This vulnerability exists in the Wave 2.0 due to missing authorization check on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating a parameter “user_id” through API request URLs which could lead to unauthorized creation, modification and deletion of alerts belonging to other user accounts.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51559" + }, + { + "type": "WEB", + "url": "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0332" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T13:17:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-hmx8-gff7-qvpr/GHSA-hmx8-gff7-qvpr.json b/advisories/unreviewed/2024/11/GHSA-hmx8-gff7-qvpr/GHSA-hmx8-gff7-qvpr.json index ac037a3a07e..6a65d7253ae 100644 --- a/advisories/unreviewed/2024/11/GHSA-hmx8-gff7-qvpr/GHSA-hmx8-gff7-qvpr.json +++ b/advisories/unreviewed/2024/11/GHSA-hmx8-gff7-qvpr/GHSA-hmx8-gff7-qvpr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hmx8-gff7-qvpr", - "modified": "2024-11-01T21:31:51Z", + "modified": "2024-11-04T15:31:56Z", "published": "2024-11-01T21:31:51Z", "aliases": [ "CVE-2024-44232" ], "details": "The issue was addressed with improved bounds checks. This issue is fixed in macOS Sonoma 14.7.1, macOS Ventura 13.7.1, visionOS 2.1, watchOS 11.1, tvOS 18.1, iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1. Parsing a maliciously crafted video file may lead to unexpected system termination.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -51,7 +54,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-01T21:15:14Z" diff --git a/advisories/unreviewed/2024/11/GHSA-hvcg-cjrj-269v/GHSA-hvcg-cjrj-269v.json b/advisories/unreviewed/2024/11/GHSA-hvcg-cjrj-269v/GHSA-hvcg-cjrj-269v.json new file mode 100644 index 00000000000..2e01f0672ff --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-hvcg-cjrj-269v/GHSA-hvcg-cjrj-269v.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hvcg-cjrj-269v", + "modified": "2024-11-04T15:31:58Z", + "published": "2024-11-04T15:31:58Z", + "aliases": [ + "CVE-2024-45885" + ], + "details": "DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `autodiscovery_clear.`", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45885" + }, + { + "type": "WEB", + "url": "https://github.com/N1nEmAn/wp/blob/main/test_v.zip" + }, + { + "type": "WEB", + "url": "https://github.com/fu37kola/cve/blob/main/DrayTek/Vigor3900/1.5.1.3/DrayTek_Vigor_3900_1.5.1.3.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jfg6-5j2q-x59w/GHSA-jfg6-5j2q-x59w.json b/advisories/unreviewed/2024/11/GHSA-jfg6-5j2q-x59w/GHSA-jfg6-5j2q-x59w.json new file mode 100644 index 00000000000..ccd8dad66f0 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jfg6-5j2q-x59w/GHSA-jfg6-5j2q-x59w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jfg6-5j2q-x59w", + "modified": "2024-11-04T15:31:58Z", + "published": "2024-11-04T15:31:58Z", + "aliases": [ + "CVE-2024-50528" + ], + "details": "Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Stacks Stacks Mobile App Builder allows Retrieve Embedded Sensitive Data.This issue affects Stacks Mobile App Builder: from n/a through 5.2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50528" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/stacks-mobile-app-builder/wordpress-stacks-mobile-app-builder-plugin-5-2-3-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T14:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jghq-wq8j-hqc4/GHSA-jghq-wq8j-hqc4.json b/advisories/unreviewed/2024/11/GHSA-jghq-wq8j-hqc4/GHSA-jghq-wq8j-hqc4.json new file mode 100644 index 00000000000..c5bc82a234b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jghq-wq8j-hqc4/GHSA-jghq-wq8j-hqc4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jghq-wq8j-hqc4", + "modified": "2024-11-04T15:31:57Z", + "published": "2024-11-04T15:31:57Z", + "aliases": [ + "CVE-2024-9147" + ], + "details": "Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Bna Informatics PosPratik allows XSS Through HTTP Query Strings.This issue affects PosPratik: before v3.2.1.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9147" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-24-1815" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-80" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T13:17:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jv8v-q52f-pxq9/GHSA-jv8v-q52f-pxq9.json b/advisories/unreviewed/2024/11/GHSA-jv8v-q52f-pxq9/GHSA-jv8v-q52f-pxq9.json new file mode 100644 index 00000000000..1ddaf317471 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jv8v-q52f-pxq9/GHSA-jv8v-q52f-pxq9.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jv8v-q52f-pxq9", + "modified": "2024-11-04T15:31:58Z", + "published": "2024-11-04T15:31:58Z", + "aliases": [ + "CVE-2024-45888" + ], + "details": "DrayTek Vigor3900 1.5.1.3 contains a command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `set_ap_map_config.'", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45888" + }, + { + "type": "WEB", + "url": "https://github.com/N1nEmAn/wp/blob/main/test_v.zip" + }, + { + "type": "WEB", + "url": "https://github.com/fu37kola/cve/blob/main/DrayTek/Vigor3900/1.5.1.3/DrayTek_Vigor_3900_1.5.1.3.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jw7m-94wq-x8ch/GHSA-jw7m-94wq-x8ch.json b/advisories/unreviewed/2024/11/GHSA-jw7m-94wq-x8ch/GHSA-jw7m-94wq-x8ch.json new file mode 100644 index 00000000000..f77fa8b865c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jw7m-94wq-x8ch/GHSA-jw7m-94wq-x8ch.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jw7m-94wq-x8ch", + "modified": "2024-11-04T15:31:59Z", + "published": "2024-11-04T15:31:59Z", + "aliases": [ + "CVE-2024-51626" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mansur Ahamed Woocommerce Quote Calculator allows Blind SQL Injection.This issue affects Woocommerce Quote Calculator: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51626" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/woo-quote-calculator-order/wordpress-woocommerce-quote-calculator-plugin-1-1-sql-injection-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jx6x-3r9m-87fm/GHSA-jx6x-3r9m-87fm.json b/advisories/unreviewed/2024/11/GHSA-jx6x-3r9m-87fm/GHSA-jx6x-3r9m-87fm.json new file mode 100644 index 00000000000..f0f3756fabe --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jx6x-3r9m-87fm/GHSA-jx6x-3r9m-87fm.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jx6x-3r9m-87fm", + "modified": "2024-11-04T15:31:59Z", + "published": "2024-11-04T15:31:59Z", + "aliases": [ + "CVE-2024-45890" + ], + "details": "DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `download_ovpn.`", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45890" + }, + { + "type": "WEB", + "url": "https://github.com/N1nEmAn/wp/blob/main/test_v.zip" + }, + { + "type": "WEB", + "url": "https://github.com/fu37kola/cve/blob/main/DrayTek/Vigor3900/1.5.1.3/DrayTek_Vigor_3900_1.5.1.3.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mfj7-v48v-2hh9/GHSA-mfj7-v48v-2hh9.json b/advisories/unreviewed/2024/11/GHSA-mfj7-v48v-2hh9/GHSA-mfj7-v48v-2hh9.json index dfaede37e6f..bdd266ef042 100644 --- a/advisories/unreviewed/2024/11/GHSA-mfj7-v48v-2hh9/GHSA-mfj7-v48v-2hh9.json +++ b/advisories/unreviewed/2024/11/GHSA-mfj7-v48v-2hh9/GHSA-mfj7-v48v-2hh9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mfj7-v48v-2hh9", - "modified": "2024-11-01T21:31:51Z", + "modified": "2024-11-04T15:31:56Z", "published": "2024-11-01T21:31:51Z", "aliases": [ "CVE-2024-44233" ], "details": "The issue was addressed with improved bounds checks. This issue is fixed in macOS Sonoma 14.7.1, macOS Ventura 13.7.1, visionOS 2.1, watchOS 11.1, tvOS 18.1, iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1. Parsing a maliciously crafted video file may lead to unexpected system termination.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -51,7 +54,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-01T21:15:14Z" diff --git a/advisories/unreviewed/2024/11/GHSA-mhfp-3c5c-84pj/GHSA-mhfp-3c5c-84pj.json b/advisories/unreviewed/2024/11/GHSA-mhfp-3c5c-84pj/GHSA-mhfp-3c5c-84pj.json new file mode 100644 index 00000000000..406616f7a75 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mhfp-3c5c-84pj/GHSA-mhfp-3c5c-84pj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mhfp-3c5c-84pj", + "modified": "2024-11-04T15:31:59Z", + "published": "2024-11-04T15:31:59Z", + "aliases": [ + "CVE-2024-51678" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Marcel Pol Elo Rating Shortcode allows Stored XSS.This issue affects Elo Rating Shortcode: from n/a through 1.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51678" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/elo-rating-shortcode/wordpress-elo-rating-shortcode-plugin-1-0-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T15:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-q6pm-2rpj-3xp9/GHSA-q6pm-2rpj-3xp9.json b/advisories/unreviewed/2024/11/GHSA-q6pm-2rpj-3xp9/GHSA-q6pm-2rpj-3xp9.json new file mode 100644 index 00000000000..216778fc0eb --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-q6pm-2rpj-3xp9/GHSA-q6pm-2rpj-3xp9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q6pm-2rpj-3xp9", + "modified": "2024-11-04T15:31:58Z", + "published": "2024-11-04T15:31:58Z", + "aliases": [ + "CVE-2024-50525" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Helloprint Plug your WooCommerce into the largest catalog of customized print products from Helloprint allows Upload a Web Shell to a Web Server.This issue affects Plug your WooCommerce into the largest catalog of customized print products from Helloprint: from n/a through 2.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50525" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/helloprint/wordpress-helloprint-plugin-2-0-2-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T14:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qcw6-77mc-69mj/GHSA-qcw6-77mc-69mj.json b/advisories/unreviewed/2024/11/GHSA-qcw6-77mc-69mj/GHSA-qcw6-77mc-69mj.json new file mode 100644 index 00000000000..ae5ee149670 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qcw6-77mc-69mj/GHSA-qcw6-77mc-69mj.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qcw6-77mc-69mj", + "modified": "2024-11-04T15:31:58Z", + "published": "2024-11-04T15:31:58Z", + "aliases": [ + "CVE-2024-45884" + ], + "details": "DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `setSWMGroup.`", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45884" + }, + { + "type": "WEB", + "url": "https://github.com/N1nEmAn/wp/blob/main/test_v.zip" + }, + { + "type": "WEB", + "url": "https://github.com/fu37kola/cve/blob/main/DrayTek/Vigor3900/1.5.1.3/DrayTek_Vigor_3900_1.5.1.3.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T15:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rh3g-3gh2-w68q/GHSA-rh3g-3gh2-w68q.json b/advisories/unreviewed/2024/11/GHSA-rh3g-3gh2-w68q/GHSA-rh3g-3gh2-w68q.json new file mode 100644 index 00000000000..09cb323117a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-rh3g-3gh2-w68q/GHSA-rh3g-3gh2-w68q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rh3g-3gh2-w68q", + "modified": "2024-11-04T15:31:59Z", + "published": "2024-11-04T15:31:59Z", + "aliases": [ + "CVE-2024-51680" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CrestaProject – Rizzo Andrea Cresta Addons for Elementor allows Stored XSS.This issue affects Cresta Addons for Elementor: from n/a through 1.0.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51680" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/cresta-addons-for-elementor/wordpress-cresta-addons-for-elementor-plugin-1-0-9-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T15:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-vj3j-52q7-fqvp/GHSA-vj3j-52q7-fqvp.json b/advisories/unreviewed/2024/11/GHSA-vj3j-52q7-fqvp/GHSA-vj3j-52q7-fqvp.json new file mode 100644 index 00000000000..dca80e0aa16 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-vj3j-52q7-fqvp/GHSA-vj3j-52q7-fqvp.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vj3j-52q7-fqvp", + "modified": "2024-11-04T15:31:59Z", + "published": "2024-11-04T15:31:59Z", + "aliases": [ + "CVE-2024-45893" + ], + "details": "DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `setSWMOption.`", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45893" + }, + { + "type": "WEB", + "url": "https://github.com/N1nEmAn/wp/blob/main/test_v.zip" + }, + { + "type": "WEB", + "url": "https://github.com/fu37kola/cve/blob/main/DrayTek/Vigor3900/1.5.1.3/DrayTek_Vigor_3900_1.5.1.3.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-vxf5-mpg2-599p/GHSA-vxf5-mpg2-599p.json b/advisories/unreviewed/2024/11/GHSA-vxf5-mpg2-599p/GHSA-vxf5-mpg2-599p.json new file mode 100644 index 00000000000..11b22d825c8 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-vxf5-mpg2-599p/GHSA-vxf5-mpg2-599p.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vxf5-mpg2-599p", + "modified": "2024-11-04T15:31:59Z", + "published": "2024-11-04T15:31:59Z", + "aliases": [ + "CVE-2024-45891" + ], + "details": "DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `delete_wlan_profile.`", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45891" + }, + { + "type": "WEB", + "url": "https://github.com/N1nEmAn/wp/blob/main/test_v.zip" + }, + { + "type": "WEB", + "url": "https://github.com/fu37kola/cve/blob/main/DrayTek/Vigor3900/1.5.1.3/DrayTek_Vigor_3900_1.5.1.3.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-w7hw-mc66-fgp3/GHSA-w7hw-mc66-fgp3.json b/advisories/unreviewed/2024/11/GHSA-w7hw-mc66-fgp3/GHSA-w7hw-mc66-fgp3.json new file mode 100644 index 00000000000..4dbacaf0d4a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-w7hw-mc66-fgp3/GHSA-w7hw-mc66-fgp3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w7hw-mc66-fgp3", + "modified": "2024-11-04T15:31:58Z", + "published": "2024-11-04T15:31:58Z", + "aliases": [ + "CVE-2024-45887" + ], + "details": "DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `doOpenVPN.`", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45887" + }, + { + "type": "WEB", + "url": "https://github.com/N1nEmAn/wp/blob/main/test_v.zip" + }, + { + "type": "WEB", + "url": "https://github.com/fu37kola/cve/blob/main/DrayTek/Vigor3900/1.5.1.3/DrayTek_Vigor_3900_1.5.1.3.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-wjjv-5wqm-9j59/GHSA-wjjv-5wqm-9j59.json b/advisories/unreviewed/2024/11/GHSA-wjjv-5wqm-9j59/GHSA-wjjv-5wqm-9j59.json new file mode 100644 index 00000000000..e928e37a385 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-wjjv-5wqm-9j59/GHSA-wjjv-5wqm-9j59.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wjjv-5wqm-9j59", + "modified": "2024-11-04T15:31:57Z", + "published": "2024-11-04T15:31:57Z", + "aliases": [ + "CVE-2024-51561" + ], + "details": "This vulnerability exists in Aero due to improper implementation of OTP validation mechanism in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by intercepting and manipulating the responses exchanged during the second factor authentication process. \n\nSuccessful exploitation of this vulnerability could allow the attacker to bypass OTP verification for accessing other user accounts.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51561" + }, + { + "type": "WEB", + "url": "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0332" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-807" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T13:17:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-wvc6-c72c-8m45/GHSA-wvc6-c72c-8m45.json b/advisories/unreviewed/2024/11/GHSA-wvc6-c72c-8m45/GHSA-wvc6-c72c-8m45.json new file mode 100644 index 00000000000..4c1558272de --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-wvc6-c72c-8m45/GHSA-wvc6-c72c-8m45.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wvc6-c72c-8m45", + "modified": "2024-11-04T15:31:58Z", + "published": "2024-11-04T15:31:58Z", + "aliases": [ + "CVE-2024-50527" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Stacks Stacks Mobile App Builder allows Upload a Web Shell to a Web Server.This issue affects Stacks Mobile App Builder: from n/a through 5.2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50527" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/stacks-mobile-app-builder/wordpress-stacks-mobile-app-builder-plugin-5-2-3-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T14:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-xqww-45ww-cw2p/GHSA-xqww-45ww-cw2p.json b/advisories/unreviewed/2024/11/GHSA-xqww-45ww-cw2p/GHSA-xqww-45ww-cw2p.json new file mode 100644 index 00000000000..f4c33903ccd --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-xqww-45ww-cw2p/GHSA-xqww-45ww-cw2p.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xqww-45ww-cw2p", + "modified": "2024-11-04T15:31:57Z", + "published": "2024-11-04T15:31:57Z", + "aliases": [ + "CVE-2024-45164" + ], + "details": "Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the latest 19.2.0 patch and Apps Portal before 19.2.0.3 or 19.2.0.20240814, has incorrect authorization controls for the Admin functionality on the ThreatAvert Policy page. An authenticated user can navigate directly to the /#app/intelligence/threatAvertPolicies URI and disable policy enforcement.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45164" + }, + { + "type": "WEB", + "url": "https://notes.netbytesec.com/2024/11/cve-2024-45164-broken-access-control.html" + }, + { + "type": "WEB", + "url": "https://www.akamai.com/global-services/support/vulnerability-reporting" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T14:15:14Z" + } +} \ No newline at end of file