diff --git a/advisories/github-reviewed/2024/02/GHSA-c57v-4vg5-cm2x/GHSA-c57v-4vg5-cm2x.json b/advisories/github-reviewed/2024/02/GHSA-c57v-4vg5-cm2x/GHSA-c57v-4vg5-cm2x.json index 33ed401fb59..30a8c73d86f 100644 --- a/advisories/github-reviewed/2024/02/GHSA-c57v-4vg5-cm2x/GHSA-c57v-4vg5-cm2x.json +++ b/advisories/github-reviewed/2024/02/GHSA-c57v-4vg5-cm2x/GHSA-c57v-4vg5-cm2x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c57v-4vg5-cm2x", - "modified": "2024-02-07T18:23:31Z", + "modified": "2024-07-22T09:31:55Z", "published": "2024-02-07T12:30:25Z", "aliases": [ "CVE-2023-51437" @@ -106,6 +106,10 @@ "type": "WEB", "url": "https://lists.apache.org/thread/5kgmvvolf5tzp5rz9xjwfg2ncwvqqgl5" }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2024/02/07/1" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/02/07/1" diff --git a/advisories/unreviewed/2024/04/GHSA-5qc4-82jh-h385/GHSA-5qc4-82jh-h385.json b/advisories/unreviewed/2024/04/GHSA-5qc4-82jh-h385/GHSA-5qc4-82jh-h385.json index 5dba5e51d99..cf96b6ca360 100644 --- a/advisories/unreviewed/2024/04/GHSA-5qc4-82jh-h385/GHSA-5qc4-82jh-h385.json +++ b/advisories/unreviewed/2024/04/GHSA-5qc4-82jh-h385/GHSA-5qc4-82jh-h385.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5qc4-82jh-h385", - "modified": "2024-06-10T18:30:54Z", + "modified": "2024-07-22T09:31:55Z", "published": "2024-04-04T21:30:31Z", "aliases": [ "CVE-2024-27316" @@ -45,6 +45,10 @@ "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20240415-0013" }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2024/04/03/16" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/04/03/16" diff --git a/advisories/unreviewed/2024/07/GHSA-3qg2-hgm3-r76h/GHSA-3qg2-hgm3-r76h.json b/advisories/unreviewed/2024/07/GHSA-3qg2-hgm3-r76h/GHSA-3qg2-hgm3-r76h.json new file mode 100644 index 00000000000..b411037bd9f --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-3qg2-hgm3-r76h/GHSA-3qg2-hgm3-r76h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3qg2-hgm3-r76h", + "modified": "2024-07-22T09:31:56Z", + "published": "2024-07-22T09:31:56Z", + "aliases": [ + "CVE-2024-37409" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Beaver Addons PowerPack Lite for Beaver Builder allows Stored XSS.This issue affects PowerPack Lite for Beaver Builder: from n/a through 1.3.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37409" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/powerpack-addon-for-beaver-builder/wordpress-powerpack-lite-for-beaver-builder-plugin-1-3-0-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-22T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-4j3p-jf3j-fvwj/GHSA-4j3p-jf3j-fvwj.json b/advisories/unreviewed/2024/07/GHSA-4j3p-jf3j-fvwj/GHSA-4j3p-jf3j-fvwj.json new file mode 100644 index 00000000000..4b6edc453a2 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-4j3p-jf3j-fvwj/GHSA-4j3p-jf3j-fvwj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4j3p-jf3j-fvwj", + "modified": "2024-07-22T09:31:56Z", + "published": "2024-07-22T09:31:56Z", + "aliases": [ + "CVE-2024-37414" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Depicter Slider and Popup by Averta Depicter Slider allows Stored XSS.This issue affects Depicter Slider: from n/a through 3.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37414" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/depicter/wordpress-depicter-slider-plugin-3-0-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-22T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-4p4f-q3pj-23qr/GHSA-4p4f-q3pj-23qr.json b/advisories/unreviewed/2024/07/GHSA-4p4f-q3pj-23qr/GHSA-4p4f-q3pj-23qr.json new file mode 100644 index 00000000000..f23855ea04e --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-4p4f-q3pj-23qr/GHSA-4p4f-q3pj-23qr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4p4f-q3pj-23qr", + "modified": "2024-07-22T09:31:55Z", + "published": "2024-07-22T09:31:55Z", + "aliases": [ + "CVE-2024-37246" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jethin Gallery Slideshow allows Stored XSS.This issue affects Gallery Slideshow: from n/a through 1.4.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37246" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/gallery-slideshow/wordpress-gallery-slideshow-plugin-1-4-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-22T09:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-5ccp-rwvw-22f2/GHSA-5ccp-rwvw-22f2.json b/advisories/unreviewed/2024/07/GHSA-5ccp-rwvw-22f2/GHSA-5ccp-rwvw-22f2.json new file mode 100644 index 00000000000..268b992ba6b --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-5ccp-rwvw-22f2/GHSA-5ccp-rwvw-22f2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5ccp-rwvw-22f2", + "modified": "2024-07-22T09:31:56Z", + "published": "2024-07-22T09:31:56Z", + "aliases": [ + "CVE-2024-37432" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemeGrill Esteem allows Stored XSS.This issue affects Esteem: from n/a through 1.5.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37432" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/esteem/wordpress-esteem-theme-1-5-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-22T09:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-5m9h-8xjw-3jm3/GHSA-5m9h-8xjw-3jm3.json b/advisories/unreviewed/2024/07/GHSA-5m9h-8xjw-3jm3/GHSA-5m9h-8xjw-3jm3.json new file mode 100644 index 00000000000..0ff59b14f85 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-5m9h-8xjw-3jm3/GHSA-5m9h-8xjw-3jm3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5m9h-8xjw-3jm3", + "modified": "2024-07-22T09:31:55Z", + "published": "2024-07-22T09:31:55Z", + "aliases": [ + "CVE-2024-37263" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemeLooks Enter Addons enteraddons allows Stored XSS.This issue affects Enter Addons: from n/a through 2.1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37263" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/enteraddons/wordpress-enter-addons-ultimate-template-builder-for-elementor-plugin-2-1-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-22T09:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-63w7-g889-pgj2/GHSA-63w7-g889-pgj2.json b/advisories/unreviewed/2024/07/GHSA-63w7-g889-pgj2/GHSA-63w7-g889-pgj2.json new file mode 100644 index 00000000000..4733d056d64 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-63w7-g889-pgj2/GHSA-63w7-g889-pgj2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-63w7-g889-pgj2", + "modified": "2024-07-22T09:31:55Z", + "published": "2024-07-22T09:31:55Z", + "aliases": [ + "CVE-2024-37245" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Vsourz Digital All In One Redirection allows Reflected XSS.This issue affects All In One Redirection: from n/a through 2.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37245" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/all-in-one-redirection/wordpress-all-in-one-redirection-plugin-2-2-0-cross-site-scripting-xss-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-22T09:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-88xp-q26w-2359/GHSA-88xp-q26w-2359.json b/advisories/unreviewed/2024/07/GHSA-88xp-q26w-2359/GHSA-88xp-q26w-2359.json new file mode 100644 index 00000000000..f591cde0e26 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-88xp-q26w-2359/GHSA-88xp-q26w-2359.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-88xp-q26w-2359", + "modified": "2024-07-22T09:31:56Z", + "published": "2024-07-22T09:31:55Z", + "aliases": [ + "CVE-2024-37275" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in NextScripts allows Reflected XSS.This issue affects NextScripts: from n/a through 4.4.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37275" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/social-networks-auto-poster-facebook-twitter-g/wordpress-nextscripts-plugin-4-4-6-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-22T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-8fff-pwm7-53j5/GHSA-8fff-pwm7-53j5.json b/advisories/unreviewed/2024/07/GHSA-8fff-pwm7-53j5/GHSA-8fff-pwm7-53j5.json new file mode 100644 index 00000000000..7e526274919 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-8fff-pwm7-53j5/GHSA-8fff-pwm7-53j5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8fff-pwm7-53j5", + "modified": "2024-07-22T09:31:55Z", + "published": "2024-07-22T09:31:55Z", + "aliases": [ + "CVE-2024-37261" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Lab WP-Lister Lite for Amazon allows Reflected XSS.This issue affects WP-Lister Lite for Amazon: from n/a through 2.6.16.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37261" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-lister-for-amazon/wordpress-wp-lister-lite-for-amazon-plugin-2-6-16-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-22T09:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-8p76-rqv3-cvwq/GHSA-8p76-rqv3-cvwq.json b/advisories/unreviewed/2024/07/GHSA-8p76-rqv3-cvwq/GHSA-8p76-rqv3-cvwq.json new file mode 100644 index 00000000000..a6375d34867 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-8p76-rqv3-cvwq/GHSA-8p76-rqv3-cvwq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8p76-rqv3-cvwq", + "modified": "2024-07-22T09:31:56Z", + "published": "2024-07-22T09:31:56Z", + "aliases": [ + "CVE-2024-37278" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Pratik Chaskar Cards for Beaver Builder.This issue affects Cards for Beaver Builder: from n/a through 1.1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37278" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/bb-bootstrap-cards/wordpress-cards-for-beaver-builder-plugin-1-1-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-22T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-967w-jpq9-79vj/GHSA-967w-jpq9-79vj.json b/advisories/unreviewed/2024/07/GHSA-967w-jpq9-79vj/GHSA-967w-jpq9-79vj.json new file mode 100644 index 00000000000..14bb939fa98 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-967w-jpq9-79vj/GHSA-967w-jpq9-79vj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-967w-jpq9-79vj", + "modified": "2024-07-22T09:31:56Z", + "published": "2024-07-22T09:31:56Z", + "aliases": [ + "CVE-2024-37428" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themesgrove WidgetKit allows Stored XSS.This issue affects WidgetKit: from n/a through 2.5.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37428" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/widgetkit-for-elementor/wordpress-all-in-one-addons-for-elementor-widgetkit-plugin-2-5-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-22T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-99g9-vr9j-hgpq/GHSA-99g9-vr9j-hgpq.json b/advisories/unreviewed/2024/07/GHSA-99g9-vr9j-hgpq/GHSA-99g9-vr9j-hgpq.json new file mode 100644 index 00000000000..75cd64866bf --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-99g9-vr9j-hgpq/GHSA-99g9-vr9j-hgpq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-99g9-vr9j-hgpq", + "modified": "2024-07-22T09:31:55Z", + "published": "2024-07-22T09:31:55Z", + "aliases": [ + "CVE-2024-37265" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Martin Gibson IdeaPush allows Stored XSS.This issue affects IdeaPush: from n/a through 8.60.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37265" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ideapush/wordpress-ideapush-plugin-8-60-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-22T09:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-9q6h-c75x-2rqw/GHSA-9q6h-c75x-2rqw.json b/advisories/unreviewed/2024/07/GHSA-9q6h-c75x-2rqw/GHSA-9q6h-c75x-2rqw.json new file mode 100644 index 00000000000..c743279c9e8 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-9q6h-c75x-2rqw/GHSA-9q6h-c75x-2rqw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9q6h-c75x-2rqw", + "modified": "2024-07-22T09:31:55Z", + "published": "2024-07-22T09:31:55Z", + "aliases": [ + "CVE-2024-37258" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Social Rocket allows Reflected XSS.This issue affects Social Rocket: from n/a through 1.3.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37258" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/social-rocket/wordpress-social-rocket-plugin-1-3-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-22T09:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-c4x4-cgpc-c2rw/GHSA-c4x4-cgpc-c2rw.json b/advisories/unreviewed/2024/07/GHSA-c4x4-cgpc-c2rw/GHSA-c4x4-cgpc-c2rw.json new file mode 100644 index 00000000000..2a3427d07eb --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-c4x4-cgpc-c2rw/GHSA-c4x4-cgpc-c2rw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c4x4-cgpc-c2rw", + "modified": "2024-07-22T09:31:55Z", + "published": "2024-07-22T09:31:55Z", + "aliases": [ + "CVE-2024-37259" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Extended The Ultimate WordPress Toolkit – WP Extended allows Reflected XSS.This issue affects The Ultimate WordPress Toolkit – WP Extended: from n/a through 2.4.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37259" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wpextended/wordpress-wp-extended-plugin-2-4-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-22T09:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-c9x8-gmc6-wjqj/GHSA-c9x8-gmc6-wjqj.json b/advisories/unreviewed/2024/07/GHSA-c9x8-gmc6-wjqj/GHSA-c9x8-gmc6-wjqj.json new file mode 100644 index 00000000000..5a7444780d5 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-c9x8-gmc6-wjqj/GHSA-c9x8-gmc6-wjqj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c9x8-gmc6-wjqj", + "modified": "2024-07-22T09:31:56Z", + "published": "2024-07-22T09:31:55Z", + "aliases": [ + "CVE-2024-37267" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in kaptinlin Striking allows Reflected XSS.This issue affects Striking: from n/a through 2.3.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37267" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/striking-r/wordpress-striking-theme-2-3-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-22T09:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-cmwr-vqmv-jhwm/GHSA-cmwr-vqmv-jhwm.json b/advisories/unreviewed/2024/07/GHSA-cmwr-vqmv-jhwm/GHSA-cmwr-vqmv-jhwm.json new file mode 100644 index 00000000000..9823f167b86 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-cmwr-vqmv-jhwm/GHSA-cmwr-vqmv-jhwm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cmwr-vqmv-jhwm", + "modified": "2024-07-22T09:31:55Z", + "published": "2024-07-22T09:31:55Z", + "aliases": [ + "CVE-2024-37262" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in vCita.Com Online Booking & Scheduling Calendar for WordPress by vcita allows Reflected XSS.This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through 4.4.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37262" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/meeting-scheduler-by-vcita/wordpress-online-booking-scheduling-calendar-plugin-4-4-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-22T09:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-gq6h-c7ph-5cgp/GHSA-gq6h-c7ph-5cgp.json b/advisories/unreviewed/2024/07/GHSA-gq6h-c7ph-5cgp/GHSA-gq6h-c7ph-5cgp.json new file mode 100644 index 00000000000..749c4750d61 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-gq6h-c7ph-5cgp/GHSA-gq6h-c7ph-5cgp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gq6h-c7ph-5cgp", + "modified": "2024-07-22T09:31:56Z", + "published": "2024-07-22T09:31:56Z", + "aliases": [ + "CVE-2024-37433" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in EverPress Mailster allows Reflected XSS.This issue affects Mailster: from n/a through 4.0.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37433" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/mailster/wordpress-mailster-plugin-4-0-9-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-22T09:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-hwr5-x65h-95g3/GHSA-hwr5-x65h-95g3.json b/advisories/unreviewed/2024/07/GHSA-hwr5-x65h-95g3/GHSA-hwr5-x65h-95g3.json new file mode 100644 index 00000000000..f7c54d6c66f --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-hwr5-x65h-95g3/GHSA-hwr5-x65h-95g3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hwr5-x65h-95g3", + "modified": "2024-07-22T09:31:56Z", + "published": "2024-07-22T09:31:56Z", + "aliases": [ + "CVE-2024-37436" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Uncanny Owl Uncanny Toolkit Pro for LearnDash allows Reflected XSS.This issue affects Uncanny Toolkit Pro for LearnDash: from n/a before 4.1.4.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37436" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/uncanny-toolkit-pro/wordpress-uncanny-toolkit-pro-for-learndash-plugin-4-1-4-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-22T09:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-j6jg-c7g8-8h89/GHSA-j6jg-c7g8-8h89.json b/advisories/unreviewed/2024/07/GHSA-j6jg-c7g8-8h89/GHSA-j6jg-c7g8-8h89.json new file mode 100644 index 00000000000..ba077cebf7d --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-j6jg-c7g8-8h89/GHSA-j6jg-c7g8-8h89.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6jg-c7g8-8h89", + "modified": "2024-07-22T09:31:56Z", + "published": "2024-07-22T09:31:56Z", + "aliases": [ + "CVE-2024-37422" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Team Emilia Projects Progress Planner allows Stored XSS.This issue affects Progress Planner: from n/a through 0.9.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37422" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/progress-planner/wordpress-progress-planner-plugin-0-9-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-22T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-jq7x-5g7j-c2g9/GHSA-jq7x-5g7j-c2g9.json b/advisories/unreviewed/2024/07/GHSA-jq7x-5g7j-c2g9/GHSA-jq7x-5g7j-c2g9.json new file mode 100644 index 00000000000..c17e0ecaf39 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-jq7x-5g7j-c2g9/GHSA-jq7x-5g7j-c2g9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jq7x-5g7j-c2g9", + "modified": "2024-07-22T09:31:56Z", + "published": "2024-07-22T09:31:56Z", + "aliases": [ + "CVE-2024-37429" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Hamid Alinia – idehweb Login with phone number allows Stored XSS.This issue affects Login with phone number: from n/a through 1.7.35.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37429" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/login-with-phone-number/wordpress-login-with-phone-number-plugin-1-7-35-admin-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-22T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-jvrp-rv38-7jhr/GHSA-jvrp-rv38-7jhr.json b/advisories/unreviewed/2024/07/GHSA-jvrp-rv38-7jhr/GHSA-jvrp-rv38-7jhr.json index 61dbc613e4e..2d903fb291e 100644 --- a/advisories/unreviewed/2024/07/GHSA-jvrp-rv38-7jhr/GHSA-jvrp-rv38-7jhr.json +++ b/advisories/unreviewed/2024/07/GHSA-jvrp-rv38-7jhr/GHSA-jvrp-rv38-7jhr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jvrp-rv38-7jhr", - "modified": "2024-07-18T18:31:43Z", + "modified": "2024-07-22T09:31:55Z", "published": "2024-07-18T18:31:43Z", "aliases": [ "CVE-2024-0857" diff --git a/advisories/unreviewed/2024/07/GHSA-p5w9-qwrq-hrc4/GHSA-p5w9-qwrq-hrc4.json b/advisories/unreviewed/2024/07/GHSA-p5w9-qwrq-hrc4/GHSA-p5w9-qwrq-hrc4.json new file mode 100644 index 00000000000..923fcd24e27 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-p5w9-qwrq-hrc4/GHSA-p5w9-qwrq-hrc4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p5w9-qwrq-hrc4", + "modified": "2024-07-22T09:31:55Z", + "published": "2024-07-22T09:31:55Z", + "aliases": [ + "CVE-2024-37257" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Maciej Bis Permalink Manager Lite allows Reflected XSS.This issue affects Permalink Manager Lite: from n/a through 2.4.3.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37257" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/permalink-manager/wordpress-permalink-manager-lite-plugin-2-4-3-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-22T09:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-p688-8h8g-h467/GHSA-p688-8h8g-h467.json b/advisories/unreviewed/2024/07/GHSA-p688-8h8g-h467/GHSA-p688-8h8g-h467.json new file mode 100644 index 00000000000..d20897fe3a1 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-p688-8h8g-h467/GHSA-p688-8h8g-h467.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p688-8h8g-h467", + "modified": "2024-07-22T09:31:56Z", + "published": "2024-07-22T09:31:56Z", + "aliases": [ + "CVE-2024-37416" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus allows Reflected XSS.This issue affects WP Photo Album Plus: from n/a through 8.8.00.002.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37416" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-photo-album-plus/wordpress-wp-photo-album-plus-plugin-8-8-00-002-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-22T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-q2g5-5vp7-5c9h/GHSA-q2g5-5vp7-5c9h.json b/advisories/unreviewed/2024/07/GHSA-q2g5-5vp7-5c9h/GHSA-q2g5-5vp7-5c9h.json new file mode 100644 index 00000000000..0ba0176fb50 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-q2g5-5vp7-5c9h/GHSA-q2g5-5vp7-5c9h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q2g5-5vp7-5c9h", + "modified": "2024-07-22T09:31:56Z", + "published": "2024-07-22T09:31:56Z", + "aliases": [ + "CVE-2024-37271" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Michael Nelson Print My Blog allows Stored XSS.This issue affects Print My Blog: from n/a through 3.27.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37271" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/print-my-blog/wordpress-print-my-blog-plugin-3-27-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-22T09:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-r297-mw4c-5xp2/GHSA-r297-mw4c-5xp2.json b/advisories/unreviewed/2024/07/GHSA-r297-mw4c-5xp2/GHSA-r297-mw4c-5xp2.json new file mode 100644 index 00000000000..d12e5ea3b45 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-r297-mw4c-5xp2/GHSA-r297-mw4c-5xp2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r297-mw4c-5xp2", + "modified": "2024-07-22T09:31:56Z", + "published": "2024-07-22T09:31:56Z", + "aliases": [ + "CVE-2024-37434" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Atarim allows Stored XSS.This issue affects Atarim: from n/a through 3.31.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37434" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/atarim-visual-collaboration/wordpress-atarim-plugin-3-31-authenticated-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-22T09:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-rwm9-7mg6-8h6c/GHSA-rwm9-7mg6-8h6c.json b/advisories/unreviewed/2024/07/GHSA-rwm9-7mg6-8h6c/GHSA-rwm9-7mg6-8h6c.json new file mode 100644 index 00000000000..c47367e64e4 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-rwm9-7mg6-8h6c/GHSA-rwm9-7mg6-8h6c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rwm9-7mg6-8h6c", + "modified": "2024-07-22T09:31:56Z", + "published": "2024-07-22T09:31:56Z", + "aliases": [ + "CVE-2024-37445" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in bPlugins Html5 Audio Player allows Stored XSS.This issue affects Html5 Audio Player: from n/a through 2.2.23.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37445" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/html5-audio-player/wordpress-html5-audio-player-plugin-2-2-23-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-22T09:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-wqfv-vr37-w73v/GHSA-wqfv-vr37-w73v.json b/advisories/unreviewed/2024/07/GHSA-wqfv-vr37-w73v/GHSA-wqfv-vr37-w73v.json new file mode 100644 index 00000000000..fcc36e8b6e2 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-wqfv-vr37-w73v/GHSA-wqfv-vr37-w73v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wqfv-vr37-w73v", + "modified": "2024-07-22T09:31:55Z", + "published": "2024-07-22T09:31:55Z", + "aliases": [ + "CVE-2024-37264" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Groundhogg Inc. Groundhogg allows Reflected XSS.This issue affects Groundhogg: from n/a through 3.4.2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37264" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/groundhogg/wordpress-groundhogg-plugin-3-4-2-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-22T09:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-x72p-g37q-4xr9/GHSA-x72p-g37q-4xr9.json b/advisories/unreviewed/2024/07/GHSA-x72p-g37q-4xr9/GHSA-x72p-g37q-4xr9.json new file mode 100644 index 00000000000..58591217e52 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-x72p-g37q-4xr9/GHSA-x72p-g37q-4xr9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x72p-g37q-4xr9", + "modified": "2024-07-22T09:31:55Z", + "published": "2024-07-22T09:31:55Z", + "aliases": [ + "CVE-2024-40430" + ], + "details": "In SFTPGO 2.6.2, the JWT implementation lacks cerrtain security measures, such as using JWT ID (JTI) claims, nonces, and proper expiration and invalidation mechanisms.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40430" + }, + { + "type": "WEB", + "url": "https://alexsecurity.rocks/posts/cve-2024-40430" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-22T07:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-xp27-8r9x-g424/GHSA-xp27-8r9x-g424.json b/advisories/unreviewed/2024/07/GHSA-xp27-8r9x-g424/GHSA-xp27-8r9x-g424.json new file mode 100644 index 00000000000..a44b552986a --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-xp27-8r9x-g424/GHSA-xp27-8r9x-g424.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xp27-8r9x-g424", + "modified": "2024-07-22T09:31:55Z", + "published": "2024-07-22T09:31:55Z", + "aliases": [ + "CVE-2024-37391" + ], + "details": "ProtonVPN before 3.2.10 on Windows mishandles the drive installer path, which should use this: '\"' + ExpandConstant('{autopf}\\Proton\\Drive') + '\"' in Setup/setup.iss.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37391" + }, + { + "type": "WEB", + "url": "https://github.com/ProtonVPN/win-app/commit/2e4e25036842aaf48838c6a59f14671b86c20aa7" + }, + { + "type": "WEB", + "url": "https://github.com/ProtonVPN/win-app/compare/3.2.9...3.2.10" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-22T07:15:01Z" + } +} \ No newline at end of file