diff --git a/advisories/unreviewed/2024/03/GHSA-2mfm-m7q3-xch8/GHSA-2mfm-m7q3-xch8.json b/advisories/unreviewed/2024/03/GHSA-2mfm-m7q3-xch8/GHSA-2mfm-m7q3-xch8.json index 08d78820c3a..739e7acafd2 100644 --- a/advisories/unreviewed/2024/03/GHSA-2mfm-m7q3-xch8/GHSA-2mfm-m7q3-xch8.json +++ b/advisories/unreviewed/2024/03/GHSA-2mfm-m7q3-xch8/GHSA-2mfm-m7q3-xch8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2mfm-m7q3-xch8", - "modified": "2024-03-04T21:31:11Z", + "modified": "2024-06-21T15:31:05Z", "published": "2024-03-04T21:31:11Z", "aliases": [ "CVE-2021-47107" @@ -22,6 +22,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/53b1119a6e5028b125f431a0116ba73510d82a72" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9e291a6a28d32545ed2fd959a8165144d1724df1" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/eabc0aab98e5218ceecd82069b0d6fdfff5ee885" diff --git a/advisories/unreviewed/2024/03/GHSA-x66g-5578-7px9/GHSA-x66g-5578-7px9.json b/advisories/unreviewed/2024/03/GHSA-x66g-5578-7px9/GHSA-x66g-5578-7px9.json index 9c01dc2cbaa..f59f70b37a9 100644 --- a/advisories/unreviewed/2024/03/GHSA-x66g-5578-7px9/GHSA-x66g-5578-7px9.json +++ b/advisories/unreviewed/2024/03/GHSA-x66g-5578-7px9/GHSA-x66g-5578-7px9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x66g-5578-7px9", - "modified": "2024-06-10T18:30:52Z", + "modified": "2024-06-21T15:31:05Z", "published": "2024-03-13T15:31:05Z", "aliases": [ "CVE-2024-26629" @@ -22,6 +22,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/8f5b860de87039b007e84a28a5eefc888154e098" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/99fb654d01dc3f08b5905c663ad6c89a9d83302f" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/b7d2eee1f53899b53f069bba3a59a419fc3d331b" diff --git a/advisories/unreviewed/2024/05/GHSA-rvcc-g859-q9qh/GHSA-rvcc-g859-q9qh.json b/advisories/unreviewed/2024/05/GHSA-rvcc-g859-q9qh/GHSA-rvcc-g859-q9qh.json index 0ca499db894..3b478d7f138 100644 --- a/advisories/unreviewed/2024/05/GHSA-rvcc-g859-q9qh/GHSA-rvcc-g859-q9qh.json +++ b/advisories/unreviewed/2024/05/GHSA-rvcc-g859-q9qh/GHSA-rvcc-g859-q9qh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rvcc-g859-q9qh", - "modified": "2024-06-03T18:55:53Z", + "modified": "2024-06-21T15:31:05Z", "published": "2024-05-01T06:31:43Z", "aliases": [ "CVE-2024-27022" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27022" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/04b0c41912349aff11a1bbaef6a722bd7fbb90ac" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/0c42f7e039aba3de6d7dbf92da708e2b2ecba557" @@ -37,6 +41,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/cec11fa2eb512ebe3a459c185f4aca1d44059bbf" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dd782da470761077f4d1120e191f1a35787cda6e" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4EZ6PJW7VOZ224TD7N4JZNU6KV32ZJ53" diff --git a/advisories/unreviewed/2024/05/GHSA-x95x-w6hq-mwxc/GHSA-x95x-w6hq-mwxc.json b/advisories/unreviewed/2024/05/GHSA-x95x-w6hq-mwxc/GHSA-x95x-w6hq-mwxc.json index 36edf2a8763..b68dc243791 100644 --- a/advisories/unreviewed/2024/05/GHSA-x95x-w6hq-mwxc/GHSA-x95x-w6hq-mwxc.json +++ b/advisories/unreviewed/2024/05/GHSA-x95x-w6hq-mwxc/GHSA-x95x-w6hq-mwxc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x95x-w6hq-mwxc", - "modified": "2024-05-21T15:31:42Z", + "modified": "2024-06-21T15:31:05Z", "published": "2024-05-21T15:31:42Z", "aliases": [ "CVE-2021-47316" @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/ab1016d39cc052064e32f25ad18ef8767a0ee3b8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e79057d15d96ef19de4de6d7e479bae3d58a2a8d" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/06/GHSA-293h-f2f3-6fqq/GHSA-293h-f2f3-6fqq.json b/advisories/unreviewed/2024/06/GHSA-293h-f2f3-6fqq/GHSA-293h-f2f3-6fqq.json new file mode 100644 index 00000000000..b078498a8c0 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-293h-f2f3-6fqq/GHSA-293h-f2f3-6fqq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-293h-f2f3-6fqq", + "modified": "2024-06-21T15:31:06Z", + "published": "2024-06-21T15:31:06Z", + "aliases": [ + "CVE-2024-35776" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Exeebit phpinfo() WP.This issue affects phpinfo() WP: from n/a through 5.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35776" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/phpinfo-wp/wordpress-phpinfo-wp-plugin-5-0-unauthenticated-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-21T13:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-2g5v-h9c6-j9cv/GHSA-2g5v-h9c6-j9cv.json b/advisories/unreviewed/2024/06/GHSA-2g5v-h9c6-j9cv/GHSA-2g5v-h9c6-j9cv.json index f3ed9773a89..032127c8ac4 100644 --- a/advisories/unreviewed/2024/06/GHSA-2g5v-h9c6-j9cv/GHSA-2g5v-h9c6-j9cv.json +++ b/advisories/unreviewed/2024/06/GHSA-2g5v-h9c6-j9cv/GHSA-2g5v-h9c6-j9cv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2g5v-h9c6-j9cv", - "modified": "2024-06-20T09:30:59Z", + "modified": "2024-06-21T15:31:06Z", "published": "2024-06-20T09:30:59Z", "aliases": [ "CVE-2024-38619" @@ -21,6 +21,18 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/16637fea001ab3c8df528a8995b3211906165a30" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/24bff7f714bdff97c2a75a0ff6a368cdf8ad5af4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2cc32639ec347e3365075b130f9953ef16cb13f1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e0e2eec76920a133dd49a4fbe4656d83596a1361" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/06/GHSA-2gf4-m97g-cvpw/GHSA-2gf4-m97g-cvpw.json b/advisories/unreviewed/2024/06/GHSA-2gf4-m97g-cvpw/GHSA-2gf4-m97g-cvpw.json index 1f8781a754a..dc594beda26 100644 --- a/advisories/unreviewed/2024/06/GHSA-2gf4-m97g-cvpw/GHSA-2gf4-m97g-cvpw.json +++ b/advisories/unreviewed/2024/06/GHSA-2gf4-m97g-cvpw/GHSA-2gf4-m97g-cvpw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2gf4-m97g-cvpw", - "modified": "2024-06-21T03:30:33Z", + "modified": "2024-06-21T15:31:05Z", "published": "2024-06-20T00:30:46Z", "aliases": [ "CVE-2024-6102" @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6HYUEHZ35ZPY2EONVZCGO6LPT3AMLZCP" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U5NRNCEYS246CYGOR32MF7OGKWOWER22" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/06/GHSA-328q-x484-qwc2/GHSA-328q-x484-qwc2.json b/advisories/unreviewed/2024/06/GHSA-328q-x484-qwc2/GHSA-328q-x484-qwc2.json new file mode 100644 index 00000000000..a8bdc8493f5 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-328q-x484-qwc2/GHSA-328q-x484-qwc2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-328q-x484-qwc2", + "modified": "2024-06-21T15:31:06Z", + "published": "2024-06-21T15:31:06Z", + "aliases": [ + "CVE-2024-35758" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Theme Horse Interface allows Stored XSS.This issue affects Interface: from n/a through 3.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35758" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/interface/wordpress-interface-theme-3-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-21T13:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-3qmp-76v8-cgx2/GHSA-3qmp-76v8-cgx2.json b/advisories/unreviewed/2024/06/GHSA-3qmp-76v8-cgx2/GHSA-3qmp-76v8-cgx2.json new file mode 100644 index 00000000000..ad9b048fe7c --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-3qmp-76v8-cgx2/GHSA-3qmp-76v8-cgx2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3qmp-76v8-cgx2", + "modified": "2024-06-21T15:31:06Z", + "published": "2024-06-21T15:31:06Z", + "aliases": [ + "CVE-2024-35771" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in presscustomizr Customizr.This issue affects Customizr: from n/a through 4.4.21.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35771" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/customizr/wordpress-customizr-theme-4-4-21-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-21T13:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-473j-qqgp-gcmm/GHSA-473j-qqgp-gcmm.json b/advisories/unreviewed/2024/06/GHSA-473j-qqgp-gcmm/GHSA-473j-qqgp-gcmm.json new file mode 100644 index 00000000000..5b3ebc9ef18 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-473j-qqgp-gcmm/GHSA-473j-qqgp-gcmm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-473j-qqgp-gcmm", + "modified": "2024-06-21T15:31:06Z", + "published": "2024-06-21T15:31:06Z", + "aliases": [ + "CVE-2023-45197" + ], + "details": "The file upload plugin in Adminer and AdminerEvo allows an attacker to upload a file with a table name of “..” to the root of the Adminer directory. The attacker can effectively guess the name of the uploaded file and execute it. Adminer is no longer supported, but this issue was fixed in AdminerEvo version 4.8.3.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45197" + }, + { + "type": "WEB", + "url": "https://github.com/adminerevo/adminerevo/commit/1cc06d6a1005fd833fa009701badd5641627a1d4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-21T15:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-48m9-fmq5-xm4p/GHSA-48m9-fmq5-xm4p.json b/advisories/unreviewed/2024/06/GHSA-48m9-fmq5-xm4p/GHSA-48m9-fmq5-xm4p.json new file mode 100644 index 00000000000..d4136c8b699 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-48m9-fmq5-xm4p/GHSA-48m9-fmq5-xm4p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-48m9-fmq5-xm4p", + "modified": "2024-06-21T15:31:06Z", + "published": "2024-06-21T15:31:06Z", + "aliases": [ + "CVE-2024-37230" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme Book Landing Page.This issue affects Book Landing Page: from n/a through 1.2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37230" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/book-landing-page/wordpress-book-landing-page-theme-1-2-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-21T14:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-58rc-whxg-m7ch/GHSA-58rc-whxg-m7ch.json b/advisories/unreviewed/2024/06/GHSA-58rc-whxg-m7ch/GHSA-58rc-whxg-m7ch.json new file mode 100644 index 00000000000..7c56a8242ce --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-58rc-whxg-m7ch/GHSA-58rc-whxg-m7ch.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-58rc-whxg-m7ch", + "modified": "2024-06-21T15:31:06Z", + "published": "2024-06-21T15:31:06Z", + "aliases": [ + "CVE-2024-35766" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ollybach WPPizza allows Reflected XSS.This issue affects WPPizza: from n/a through 3.18.13.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35766" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wppizza/wordpress-wppizza-a-restaurant-plugin-plugin-3-18-13-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-21T13:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-592c-fmq9-g63c/GHSA-592c-fmq9-g63c.json b/advisories/unreviewed/2024/06/GHSA-592c-fmq9-g63c/GHSA-592c-fmq9-g63c.json index 971c16147eb..8e6d15406b4 100644 --- a/advisories/unreviewed/2024/06/GHSA-592c-fmq9-g63c/GHSA-592c-fmq9-g63c.json +++ b/advisories/unreviewed/2024/06/GHSA-592c-fmq9-g63c/GHSA-592c-fmq9-g63c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-592c-fmq9-g63c", - "modified": "2024-06-21T03:30:33Z", + "modified": "2024-06-21T15:31:05Z", "published": "2024-06-05T21:31:29Z", "aliases": [ "CVE-2024-5171" @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6HYUEHZ35ZPY2EONVZCGO6LPT3AMLZCP" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U5NRNCEYS246CYGOR32MF7OGKWOWER22" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/06/GHSA-6g2q-m7q5-4w3c/GHSA-6g2q-m7q5-4w3c.json b/advisories/unreviewed/2024/06/GHSA-6g2q-m7q5-4w3c/GHSA-6g2q-m7q5-4w3c.json new file mode 100644 index 00000000000..e6eba1910ad --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-6g2q-m7q5-4w3c/GHSA-6g2q-m7q5-4w3c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6g2q-m7q5-4w3c", + "modified": "2024-06-21T15:31:06Z", + "published": "2024-06-21T15:31:06Z", + "aliases": [ + "CVE-2024-37118" + ], + "details": "Cross Site Request Forgery (CSRF) vulnerability in Uncanny Owl Uncanny Automator Pro.This issue affects Uncanny Automator Pro: from n/a through 5.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37118" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/uncanny-automator-pro/wordpress-uncanny-automator-pro-plugin-5-3-cross-site-request-forgery-csrf-leading-to-license-settings-reset-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-21T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-7cww-wfxx-j2m2/GHSA-7cww-wfxx-j2m2.json b/advisories/unreviewed/2024/06/GHSA-7cww-wfxx-j2m2/GHSA-7cww-wfxx-j2m2.json new file mode 100644 index 00000000000..cd609a83042 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-7cww-wfxx-j2m2/GHSA-7cww-wfxx-j2m2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7cww-wfxx-j2m2", + "modified": "2024-06-21T15:31:06Z", + "published": "2024-06-21T15:31:06Z", + "aliases": [ + "CVE-2024-5059" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in A WP Life Event Management Tickets Booking.This issue affects Event Management Tickets Booking: from n/a through 1.4.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5059" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/event-monster/wordpress-event-monster-plugin-1-4-0-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-21T13:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-8969-qjjh-m9jj/GHSA-8969-qjjh-m9jj.json b/advisories/unreviewed/2024/06/GHSA-8969-qjjh-m9jj/GHSA-8969-qjjh-m9jj.json new file mode 100644 index 00000000000..d3a2cbd9775 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-8969-qjjh-m9jj/GHSA-8969-qjjh-m9jj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8969-qjjh-m9jj", + "modified": "2024-06-21T15:31:06Z", + "published": "2024-06-21T15:31:06Z", + "aliases": [ + "CVE-2022-43453" + ], + "details": "Missing Authorization vulnerability in Bill Minozzi WP Tools.This issue affects WP Tools: from n/a through 3.41.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43453" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wptools/wordpress-wp-tools-plugin-2-51-3-41-auth-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-21T14:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-8rgp-h8v7-xr48/GHSA-8rgp-h8v7-xr48.json b/advisories/unreviewed/2024/06/GHSA-8rgp-h8v7-xr48/GHSA-8rgp-h8v7-xr48.json new file mode 100644 index 00000000000..a3dba291d27 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-8rgp-h8v7-xr48/GHSA-8rgp-h8v7-xr48.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8rgp-h8v7-xr48", + "modified": "2024-06-21T15:31:06Z", + "published": "2024-06-21T15:31:06Z", + "aliases": [ + "CVE-2024-35770" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Dave Kiss Vimeography: Vimeo Video Gallery WordPress Plugin.This issue affects Vimeography: Vimeo Video Gallery WordPress Plugin: from n/a through 2.4.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35770" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/vimeography/wordpress-vimeography-plugin-2-4-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-21T13:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-9fm6-mqj4-6fg4/GHSA-9fm6-mqj4-6fg4.json b/advisories/unreviewed/2024/06/GHSA-9fm6-mqj4-6fg4/GHSA-9fm6-mqj4-6fg4.json new file mode 100644 index 00000000000..e2c6553363d --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-9fm6-mqj4-6fg4/GHSA-9fm6-mqj4-6fg4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9fm6-mqj4-6fg4", + "modified": "2024-06-21T15:31:06Z", + "published": "2024-06-21T15:31:06Z", + "aliases": [ + "CVE-2024-35768" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Live Composer Team Page Builder: Live Composer allows Stored XSS.This issue affects Page Builder: Live Composer: from n/a through 1.5.42.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35768" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/live-composer-page-builder/wordpress-page-builder-live-composer-plugin-1-5-42-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-21T13:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-cc4h-7j78-49pj/GHSA-cc4h-7j78-49pj.json b/advisories/unreviewed/2024/06/GHSA-cc4h-7j78-49pj/GHSA-cc4h-7j78-49pj.json new file mode 100644 index 00000000000..de288901552 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-cc4h-7j78-49pj/GHSA-cc4h-7j78-49pj.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cc4h-7j78-49pj", + "modified": "2024-06-21T15:31:06Z", + "published": "2024-06-21T15:31:06Z", + "aliases": [ + "CVE-2024-6239" + ], + "details": "A flaw was found in the Poppler's Pdfinfo utility. This issue occurs when using -dests parameter with pdfinfo utility. By using certain malformed input files, an attacker could cause the utility to crash, leading to a denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6239" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-6239" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2293594" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-21T14:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-cf5m-6cw2-jwwh/GHSA-cf5m-6cw2-jwwh.json b/advisories/unreviewed/2024/06/GHSA-cf5m-6cw2-jwwh/GHSA-cf5m-6cw2-jwwh.json new file mode 100644 index 00000000000..bf5b8ac2e41 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-cf5m-6cw2-jwwh/GHSA-cf5m-6cw2-jwwh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cf5m-6cw2-jwwh", + "modified": "2024-06-21T15:31:06Z", + "published": "2024-06-21T15:31:06Z", + "aliases": [ + "CVE-2024-35764" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Andy Moyle Church Admin allows Stored XSS.This issue affects Church Admin: from n/a through 4.4.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35764" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/church-admin/wordpress-church-admin-plugin-4-4-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-21T13:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-cx4j-pr72-qf2f/GHSA-cx4j-pr72-qf2f.json b/advisories/unreviewed/2024/06/GHSA-cx4j-pr72-qf2f/GHSA-cx4j-pr72-qf2f.json new file mode 100644 index 00000000000..461a7e2e929 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-cx4j-pr72-qf2f/GHSA-cx4j-pr72-qf2f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cx4j-pr72-qf2f", + "modified": "2024-06-21T15:31:06Z", + "published": "2024-06-21T15:31:06Z", + "aliases": [ + "CVE-2022-45803" + ], + "details": "Missing Authorization vulnerability in Nikolay Strikhar WordPress Form Builder Plugin – Gutenberg Forms.This issue affects WordPress Form Builder Plugin – Gutenberg Forms: from n/a through 2.2.8.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45803" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/forms-gutenberg/wordpress-gutenberg-forms-plugin-2-2-8-3-auth-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-21T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-fr2r-x4wp-q45h/GHSA-fr2r-x4wp-q45h.json b/advisories/unreviewed/2024/06/GHSA-fr2r-x4wp-q45h/GHSA-fr2r-x4wp-q45h.json new file mode 100644 index 00000000000..248a37cd0bb --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-fr2r-x4wp-q45h/GHSA-fr2r-x4wp-q45h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fr2r-x4wp-q45h", + "modified": "2024-06-21T15:31:06Z", + "published": "2024-06-21T15:31:06Z", + "aliases": [ + "CVE-2024-37212" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Ali2Woo Ali2Woo Lite.This issue affects Ali2Woo Lite: from n/a through 3.3.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37212" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ali2woo-lite/wordpress-aliexpress-dropshipping-with-alinext-lite-plugin-3-3-5-csrf-to-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-21T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-g59j-h2pg-qp5r/GHSA-g59j-h2pg-qp5r.json b/advisories/unreviewed/2024/06/GHSA-g59j-h2pg-qp5r/GHSA-g59j-h2pg-qp5r.json index 71d2a064c90..a19ae63c1cb 100644 --- a/advisories/unreviewed/2024/06/GHSA-g59j-h2pg-qp5r/GHSA-g59j-h2pg-qp5r.json +++ b/advisories/unreviewed/2024/06/GHSA-g59j-h2pg-qp5r/GHSA-g59j-h2pg-qp5r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g59j-h2pg-qp5r", - "modified": "2024-06-19T09:31:17Z", + "modified": "2024-06-21T15:31:05Z", "published": "2024-06-19T09:31:17Z", "aliases": [ "CVE-2024-36978" @@ -18,9 +18,21 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36978" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0f208fad86631e005754606c3ec80c0d44a11882" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/54c2c171c11a798fe887b3ff72922aa9d1411c1e" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/affc18fdc694190ca7575b9a86632a73b9fe043d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d6fb5110e8722bc00748f22caeb650fe4672f129" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/06/GHSA-g779-vpj7-v6c4/GHSA-g779-vpj7-v6c4.json b/advisories/unreviewed/2024/06/GHSA-g779-vpj7-v6c4/GHSA-g779-vpj7-v6c4.json index 96ceca9077a..89d1857f0dd 100644 --- a/advisories/unreviewed/2024/06/GHSA-g779-vpj7-v6c4/GHSA-g779-vpj7-v6c4.json +++ b/advisories/unreviewed/2024/06/GHSA-g779-vpj7-v6c4/GHSA-g779-vpj7-v6c4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g779-vpj7-v6c4", - "modified": "2024-06-21T03:30:33Z", + "modified": "2024-06-21T15:31:05Z", "published": "2024-06-20T00:30:46Z", "aliases": [ "CVE-2024-6100" @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6HYUEHZ35ZPY2EONVZCGO6LPT3AMLZCP" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U5NRNCEYS246CYGOR32MF7OGKWOWER22" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/06/GHSA-grgx-v94g-52gr/GHSA-grgx-v94g-52gr.json b/advisories/unreviewed/2024/06/GHSA-grgx-v94g-52gr/GHSA-grgx-v94g-52gr.json new file mode 100644 index 00000000000..7a5edcb059f --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-grgx-v94g-52gr/GHSA-grgx-v94g-52gr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-grgx-v94g-52gr", + "modified": "2024-06-21T15:31:06Z", + "published": "2024-06-21T15:31:06Z", + "aliases": [ + "CVE-2024-35762" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Cryout Creations Serious Slider allows Stored XSS.This issue affects Serious Slider: from n/a through 1.2.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35762" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/cryout-serious-slider/wordpress-serious-slider-plugin-1-2-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-21T13:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-mpg3-phx5-6h24/GHSA-mpg3-phx5-6h24.json b/advisories/unreviewed/2024/06/GHSA-mpg3-phx5-6h24/GHSA-mpg3-phx5-6h24.json new file mode 100644 index 00000000000..dedb24df217 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-mpg3-phx5-6h24/GHSA-mpg3-phx5-6h24.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mpg3-phx5-6h24", + "modified": "2024-06-21T15:31:06Z", + "published": "2024-06-21T15:31:06Z", + "aliases": [ + "CVE-2024-35761" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in vCita Online Booking & Scheduling Calendar for WordPress by vcita allows Stored XSS.This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through 4.4.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35761" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/meeting-scheduler-by-vcita/wordpress-online-booking-scheduling-calendar-for-wordpress-by-vcita-plugin-4-4-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-21T13:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-mprg-vch7-563j/GHSA-mprg-vch7-563j.json b/advisories/unreviewed/2024/06/GHSA-mprg-vch7-563j/GHSA-mprg-vch7-563j.json new file mode 100644 index 00000000000..53287a33c9f --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-mprg-vch7-563j/GHSA-mprg-vch7-563j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mprg-vch7-563j", + "modified": "2024-06-21T15:31:06Z", + "published": "2024-06-21T15:31:06Z", + "aliases": [ + "CVE-2024-37227" + ], + "details": "Cross Site Request Forgery (CSRF) vulnerability in Tribulant Newsletters.This issue affects Newsletters: from n/a through 4.9.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37227" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/newsletters-lite/wordpress-newsletters-plugin-4-9-7-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-21T14:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-p5pg-m342-46wc/GHSA-p5pg-m342-46wc.json b/advisories/unreviewed/2024/06/GHSA-p5pg-m342-46wc/GHSA-p5pg-m342-46wc.json new file mode 100644 index 00000000000..45f660b23e5 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-p5pg-m342-46wc/GHSA-p5pg-m342-46wc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p5pg-m342-46wc", + "modified": "2024-06-21T15:31:06Z", + "published": "2024-06-21T15:31:06Z", + "aliases": [ + "CVE-2024-35772" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in presscustomizr Hueman.This issue affects Hueman: from n/a through 3.7.24.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35772" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/hueman/wordpress-hueman-theme-3-7-24-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-21T13:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-pfw4-7vr6-83r5/GHSA-pfw4-7vr6-83r5.json b/advisories/unreviewed/2024/06/GHSA-pfw4-7vr6-83r5/GHSA-pfw4-7vr6-83r5.json new file mode 100644 index 00000000000..24223bc27c7 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-pfw4-7vr6-83r5/GHSA-pfw4-7vr6-83r5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pfw4-7vr6-83r5", + "modified": "2024-06-21T15:31:06Z", + "published": "2024-06-21T15:31:06Z", + "aliases": [ + "CVE-2024-35759" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Job Portal allows Stored XSS.This issue affects WP Job Portal: from n/a through 2.1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35759" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-job-portal/wordpress-wp-job-portal-plugin-2-1-3-admin-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-21T13:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-ph5m-227m-fc5g/GHSA-ph5m-227m-fc5g.json b/advisories/unreviewed/2024/06/GHSA-ph5m-227m-fc5g/GHSA-ph5m-227m-fc5g.json index faab95d69bd..8cf933e908f 100644 --- a/advisories/unreviewed/2024/06/GHSA-ph5m-227m-fc5g/GHSA-ph5m-227m-fc5g.json +++ b/advisories/unreviewed/2024/06/GHSA-ph5m-227m-fc5g/GHSA-ph5m-227m-fc5g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ph5m-227m-fc5g", - "modified": "2024-06-21T03:30:33Z", + "modified": "2024-06-21T15:31:05Z", "published": "2024-06-20T00:30:47Z", "aliases": [ "CVE-2024-6103" @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6HYUEHZ35ZPY2EONVZCGO6LPT3AMLZCP" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U5NRNCEYS246CYGOR32MF7OGKWOWER22" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/06/GHSA-pqqr-79q5-9qwg/GHSA-pqqr-79q5-9qwg.json b/advisories/unreviewed/2024/06/GHSA-pqqr-79q5-9qwg/GHSA-pqqr-79q5-9qwg.json index d8b0f0ca68e..178c5734cb8 100644 --- a/advisories/unreviewed/2024/06/GHSA-pqqr-79q5-9qwg/GHSA-pqqr-79q5-9qwg.json +++ b/advisories/unreviewed/2024/06/GHSA-pqqr-79q5-9qwg/GHSA-pqqr-79q5-9qwg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pqqr-79q5-9qwg", - "modified": "2024-06-17T18:31:34Z", + "modified": "2024-06-21T15:31:05Z", "published": "2024-06-17T18:31:34Z", "aliases": [ "CVE-2024-36973" @@ -21,6 +21,18 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/086c6cbcc563c81d55257f9b27e14faf1d0963d3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1efe551982297924d05a367aa2b6ec3d275d5742" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/34ae447b138680b5ed3660f7d935ff3faf88ba1a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/86c9713602f786f441630c4ee02891987f8618b9" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/06/GHSA-q2x7-xj6p-h2cc/GHSA-q2x7-xj6p-h2cc.json b/advisories/unreviewed/2024/06/GHSA-q2x7-xj6p-h2cc/GHSA-q2x7-xj6p-h2cc.json new file mode 100644 index 00000000000..c5de84bde23 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-q2x7-xj6p-h2cc/GHSA-q2x7-xj6p-h2cc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q2x7-xj6p-h2cc", + "modified": "2024-06-21T15:31:06Z", + "published": "2024-06-21T15:31:06Z", + "aliases": [ + "CVE-2023-51375" + ], + "details": "Missing Authorization vulnerability in WPDeveloper EmbedPress.This issue affects EmbedPress: from n/a through 3.8.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51375" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/embedpress/wordpress-embedpress-plugin-3-8-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-21T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-r46w-cf8c-5v8w/GHSA-r46w-cf8c-5v8w.json b/advisories/unreviewed/2024/06/GHSA-r46w-cf8c-5v8w/GHSA-r46w-cf8c-5v8w.json new file mode 100644 index 00000000000..1cdfcbee0e3 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-r46w-cf8c-5v8w/GHSA-r46w-cf8c-5v8w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r46w-cf8c-5v8w", + "modified": "2024-06-21T15:31:06Z", + "published": "2024-06-21T15:31:06Z", + "aliases": [ + "CVE-2024-35763" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Theme Freesia Excellent allows Stored XSS.This issue affects Excellent: from n/a through 1.2.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35763" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/excellent/wordpress-excellent-theme-1-2-9-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-21T13:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-rg42-f9ww-x3w7/GHSA-rg42-f9ww-x3w7.json b/advisories/unreviewed/2024/06/GHSA-rg42-f9ww-x3w7/GHSA-rg42-f9ww-x3w7.json index 32a81a77c19..ab83eab7a7d 100644 --- a/advisories/unreviewed/2024/06/GHSA-rg42-f9ww-x3w7/GHSA-rg42-f9ww-x3w7.json +++ b/advisories/unreviewed/2024/06/GHSA-rg42-f9ww-x3w7/GHSA-rg42-f9ww-x3w7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rg42-f9ww-x3w7", - "modified": "2024-06-21T03:30:33Z", + "modified": "2024-06-21T15:31:05Z", "published": "2024-06-20T00:30:46Z", "aliases": [ "CVE-2024-6101" @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6HYUEHZ35ZPY2EONVZCGO6LPT3AMLZCP" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U5NRNCEYS246CYGOR32MF7OGKWOWER22" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/06/GHSA-rw4j-f7fm-rv9q/GHSA-rw4j-f7fm-rv9q.json b/advisories/unreviewed/2024/06/GHSA-rw4j-f7fm-rv9q/GHSA-rw4j-f7fm-rv9q.json new file mode 100644 index 00000000000..e23500044b4 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-rw4j-f7fm-rv9q/GHSA-rw4j-f7fm-rv9q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rw4j-f7fm-rv9q", + "modified": "2024-06-21T15:31:06Z", + "published": "2024-06-21T15:31:06Z", + "aliases": [ + "CVE-2024-35760" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Job Portal allows Stored XSS.This issue affects WP Job Portal: from n/a through 2.1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35760" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-job-portal/wordpress-wp-job-portal-a-complete-job-board-plugin-2-1-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-21T13:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-rx99-hq7r-6g3r/GHSA-rx99-hq7r-6g3r.json b/advisories/unreviewed/2024/06/GHSA-rx99-hq7r-6g3r/GHSA-rx99-hq7r-6g3r.json index c0d6b999e26..f3a3e5659a6 100644 --- a/advisories/unreviewed/2024/06/GHSA-rx99-hq7r-6g3r/GHSA-rx99-hq7r-6g3r.json +++ b/advisories/unreviewed/2024/06/GHSA-rx99-hq7r-6g3r/GHSA-rx99-hq7r-6g3r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rx99-hq7r-6g3r", - "modified": "2024-06-18T21:30:35Z", + "modified": "2024-06-21T15:31:05Z", "published": "2024-06-18T21:30:35Z", "aliases": [ "CVE-2024-36974" @@ -18,6 +18,18 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36974" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0bf6cc96612bd396048f57d63f1ad454a846e39c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/724050ae4b76e4fae05a923cb54101d792cf4404" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c37a27a35eadb59286c9092c49c241270c802ae2" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/f921a58ae20852d188f70842431ce6519c4fdc36" diff --git a/advisories/unreviewed/2024/06/GHSA-v3jj-jrrq-9cxm/GHSA-v3jj-jrrq-9cxm.json b/advisories/unreviewed/2024/06/GHSA-v3jj-jrrq-9cxm/GHSA-v3jj-jrrq-9cxm.json new file mode 100644 index 00000000000..1f23dccb7a7 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-v3jj-jrrq-9cxm/GHSA-v3jj-jrrq-9cxm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v3jj-jrrq-9cxm", + "modified": "2024-06-21T15:31:06Z", + "published": "2024-06-21T15:31:06Z", + "aliases": [ + "CVE-2024-37198" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in blazethemes Digital Newspaper.This issue affects Digital Newspaper: from n/a through 1.1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37198" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/digital-newspaper/wordpress-digital-newspaper-theme-1-1-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-21T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-vh28-836h-rm25/GHSA-vh28-836h-rm25.json b/advisories/unreviewed/2024/06/GHSA-vh28-836h-rm25/GHSA-vh28-836h-rm25.json new file mode 100644 index 00000000000..c41449ca294 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-vh28-836h-rm25/GHSA-vh28-836h-rm25.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vh28-836h-rm25", + "modified": "2024-06-21T15:31:06Z", + "published": "2024-06-21T15:31:06Z", + "aliases": [ + "CVE-2024-35757" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in 5 Star Plugins Easy Age Verify allows Stored XSS.This issue affects Easy Age Verify: from n/a through 1.8.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35757" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/easy-age-verify/wordpress-easy-age-verify-plugin-1-8-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-21T13:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-x5f6-gmwc-2843/GHSA-x5f6-gmwc-2843.json b/advisories/unreviewed/2024/06/GHSA-x5f6-gmwc-2843/GHSA-x5f6-gmwc-2843.json new file mode 100644 index 00000000000..f0f9fef2ed9 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-x5f6-gmwc-2843/GHSA-x5f6-gmwc-2843.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x5f6-gmwc-2843", + "modified": "2024-06-21T15:31:06Z", + "published": "2024-06-21T15:31:06Z", + "aliases": [ + "CVE-2024-6240" + ], + "details": "Improper privilege management vulnerability in Parallels Desktop Software, which affects versions earlier than 19.3.0. An attacker could add malicious code in a script and populate the BASH_ENV environment variable with the path to the malicious script, executing on application startup. An attacker could exploit this vulnerability to escalate privileges on the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6240" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/improper-privilege-management-vulnerability-parallels-desktop" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-21T14:15:14Z" + } +} \ No newline at end of file