diff --git a/advisories/github-reviewed/2023/10/GHSA-m6vm-37g8-gqvh/GHSA-m6vm-37g8-gqvh.json b/advisories/github-reviewed/2023/10/GHSA-m6vm-37g8-gqvh/GHSA-m6vm-37g8-gqvh.json new file mode 100644 index 00000000000..7c314ad0138 --- /dev/null +++ b/advisories/github-reviewed/2023/10/GHSA-m6vm-37g8-gqvh/GHSA-m6vm-37g8-gqvh.json @@ -0,0 +1,92 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m6vm-37g8-gqvh", + "modified": "2024-08-29T18:32:05Z", + "published": "2023-10-18T00:31:42Z", + "aliases": [ + "CVE-2023-22102" + ], + "summary": "MySQL Connectors takeover vulnerability", + "details": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in MySQL Connectors, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of MySQL Connectors.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "com.mysql:mysql-connector-j" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "8.2.0" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "com.mysql:mysql-connector-java" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "8.2.0" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22102" + }, + { + "type": "PACKAGE", + "url": "https://github.com/mysql/mysql-connector-j" + }, + { + "type": "WEB", + "url": "https://github.com/mysql/mysql-connector-j/compare/8.1.0...8.2.0" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20231027-0007" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2023.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2024-08-29T18:32:05Z", + "nvd_published_at": "2023-10-17T22:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-m6vm-37g8-gqvh/GHSA-m6vm-37g8-gqvh.json b/advisories/unreviewed/2023/10/GHSA-m6vm-37g8-gqvh/GHSA-m6vm-37g8-gqvh.json deleted file mode 100644 index 04486113494..00000000000 --- a/advisories/unreviewed/2023/10/GHSA-m6vm-37g8-gqvh/GHSA-m6vm-37g8-gqvh.json +++ /dev/null @@ -1,42 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-m6vm-37g8-gqvh", - "modified": "2024-04-04T08:44:38Z", - "published": "2023-10-18T00:31:42Z", - "aliases": [ - "CVE-2023-22102" - ], - "details": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in MySQL Connectors, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" - } - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22102" - }, - { - "type": "WEB", - "url": "https://security.netapp.com/advisory/ntap-20231027-0007" - }, - { - "type": "WEB", - "url": "https://www.oracle.com/security-alerts/cpuoct2023.html" - } - ], - "database_specific": { - "cwe_ids": [ - - ], - "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2023-10-17T22:15:15Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-37c3-qm4g-jf9g/GHSA-37c3-qm4g-jf9g.json b/advisories/unreviewed/2024/05/GHSA-37c3-qm4g-jf9g/GHSA-37c3-qm4g-jf9g.json index d9e15242aaa..6c13d73aed5 100644 --- a/advisories/unreviewed/2024/05/GHSA-37c3-qm4g-jf9g/GHSA-37c3-qm4g-jf9g.json +++ b/advisories/unreviewed/2024/05/GHSA-37c3-qm4g-jf9g/GHSA-37c3-qm4g-jf9g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-37c3-qm4g-jf9g", - "modified": "2024-06-26T00:31:43Z", + "modified": "2024-08-29T18:31:32Z", "published": "2024-05-19T09:34:47Z", "aliases": [ "CVE-2024-35895" @@ -26,6 +26,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/6af057ccdd8e7619960aca1f0428339f213b31cd" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/913c30f827e17d8cda1da6eeb990f350d36cb69b" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/a44770fed86515eedb5a7c00b787f847ebb134a5" diff --git a/advisories/unreviewed/2024/05/GHSA-45rj-9f26-3gf5/GHSA-45rj-9f26-3gf5.json b/advisories/unreviewed/2024/05/GHSA-45rj-9f26-3gf5/GHSA-45rj-9f26-3gf5.json index 632fb19f950..b9dae8c566d 100644 --- a/advisories/unreviewed/2024/05/GHSA-45rj-9f26-3gf5/GHSA-45rj-9f26-3gf5.json +++ b/advisories/unreviewed/2024/05/GHSA-45rj-9f26-3gf5/GHSA-45rj-9f26-3gf5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-45rj-9f26-3gf5", - "modified": "2024-05-19T12:30:39Z", + "modified": "2024-08-29T18:31:34Z", "published": "2024-05-19T12:30:39Z", "aliases": [ "CVE-2024-35937" @@ -29,6 +29,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/9ad7974856926129f190ffbe3beea78460b3b7cc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9eb3bc0973d084423a6df21cf2c74692ff05647e" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/05/GHSA-wvq2-rqp6-pwmj/GHSA-wvq2-rqp6-pwmj.json b/advisories/unreviewed/2024/05/GHSA-wvq2-rqp6-pwmj/GHSA-wvq2-rqp6-pwmj.json index 4fdf8f0c20d..da59f18cf87 100644 --- a/advisories/unreviewed/2024/05/GHSA-wvq2-rqp6-pwmj/GHSA-wvq2-rqp6-pwmj.json +++ b/advisories/unreviewed/2024/05/GHSA-wvq2-rqp6-pwmj/GHSA-wvq2-rqp6-pwmj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wvq2-rqp6-pwmj", - "modified": "2024-08-19T06:30:52Z", + "modified": "2024-08-29T18:31:34Z", "published": "2024-05-20T12:30:28Z", "aliases": [ "CVE-2024-35966" @@ -29,6 +29,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/c3f787a3eafe519c93df9abbb0ca5145861c8d0f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/eea40d33bf936a5c7fb03c190e61e0cfee00e872" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-47ph-rf63-2m8f/GHSA-47ph-rf63-2m8f.json b/advisories/unreviewed/2024/07/GHSA-47ph-rf63-2m8f/GHSA-47ph-rf63-2m8f.json index cf8de81eb54..6b857d45ade 100644 --- a/advisories/unreviewed/2024/07/GHSA-47ph-rf63-2m8f/GHSA-47ph-rf63-2m8f.json +++ b/advisories/unreviewed/2024/07/GHSA-47ph-rf63-2m8f/GHSA-47ph-rf63-2m8f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-47ph-rf63-2m8f", - "modified": "2024-07-28T06:30:45Z", + "modified": "2024-08-29T18:31:34Z", "published": "2024-07-28T06:30:45Z", "aliases": [ "CVE-2024-42055" ], "details": "Cervantes through 0.5-alpha allows stored XSS.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-28T04:15:01Z" diff --git a/advisories/unreviewed/2024/07/GHSA-5r86-7p4c-pw27/GHSA-5r86-7p4c-pw27.json b/advisories/unreviewed/2024/07/GHSA-5r86-7p4c-pw27/GHSA-5r86-7p4c-pw27.json index 00099844711..7483147daea 100644 --- a/advisories/unreviewed/2024/07/GHSA-5r86-7p4c-pw27/GHSA-5r86-7p4c-pw27.json +++ b/advisories/unreviewed/2024/07/GHSA-5r86-7p4c-pw27/GHSA-5r86-7p4c-pw27.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5r86-7p4c-pw27", - "modified": "2024-07-29T15:30:39Z", + "modified": "2024-08-29T18:31:34Z", "published": "2024-07-29T15:30:39Z", "aliases": [ "CVE-2024-41024" @@ -18,6 +18,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41024" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2eb973ee4770a26d9b5e292b58ad29822d321c7f" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/5e305b5986dc52122a9368a1461f0c13e1de3fd6" @@ -29,6 +33,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/c69fd8afacebfdf2f8a1ee1ea7e0723786529874" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ea13bd807f1cef1af375d999980a9b9794c789b6" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-6pc8-wjpf-r5vj/GHSA-6pc8-wjpf-r5vj.json b/advisories/unreviewed/2024/07/GHSA-6pc8-wjpf-r5vj/GHSA-6pc8-wjpf-r5vj.json index e92d96caae1..099a376caf1 100644 --- a/advisories/unreviewed/2024/07/GHSA-6pc8-wjpf-r5vj/GHSA-6pc8-wjpf-r5vj.json +++ b/advisories/unreviewed/2024/07/GHSA-6pc8-wjpf-r5vj/GHSA-6pc8-wjpf-r5vj.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-934p-m4fh-22q3/GHSA-934p-m4fh-22q3.json b/advisories/unreviewed/2024/07/GHSA-934p-m4fh-22q3/GHSA-934p-m4fh-22q3.json index 71d3eb64d10..8debfdaae29 100644 --- a/advisories/unreviewed/2024/07/GHSA-934p-m4fh-22q3/GHSA-934p-m4fh-22q3.json +++ b/advisories/unreviewed/2024/07/GHSA-934p-m4fh-22q3/GHSA-934p-m4fh-22q3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-934p-m4fh-22q3", - "modified": "2024-08-19T06:30:52Z", + "modified": "2024-08-29T18:31:34Z", "published": "2024-07-12T15:31:29Z", "aliases": [ "CVE-2024-40972" @@ -18,6 +18,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40972" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0752e7fb549d90c33b4d4186f11cfd25a556d1dd" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/0a46ef234756dca04623b7591e8ebb3440622f0b" diff --git a/advisories/unreviewed/2024/07/GHSA-gjhv-rjxp-wwwg/GHSA-gjhv-rjxp-wwwg.json b/advisories/unreviewed/2024/07/GHSA-gjhv-rjxp-wwwg/GHSA-gjhv-rjxp-wwwg.json index 59f4c3b066e..aa82c30b7ee 100644 --- a/advisories/unreviewed/2024/07/GHSA-gjhv-rjxp-wwwg/GHSA-gjhv-rjxp-wwwg.json +++ b/advisories/unreviewed/2024/07/GHSA-gjhv-rjxp-wwwg/GHSA-gjhv-rjxp-wwwg.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gjhv-rjxp-wwwg", - "modified": "2024-07-10T00:30:42Z", + "modified": "2024-08-29T18:31:34Z", "published": "2024-07-10T00:30:42Z", "aliases": [ "CVE-2024-39881" ], "details": "Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a memory corruption condition. If a target visits a malicious page or opens a malicious file an attacker can leverage this vulnerability to execute code in the context of the current process.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/07/GHSA-r3jw-6ppm-jp54/GHSA-r3jw-6ppm-jp54.json b/advisories/unreviewed/2024/07/GHSA-r3jw-6ppm-jp54/GHSA-r3jw-6ppm-jp54.json index 2431e55cd3b..32460d05376 100644 --- a/advisories/unreviewed/2024/07/GHSA-r3jw-6ppm-jp54/GHSA-r3jw-6ppm-jp54.json +++ b/advisories/unreviewed/2024/07/GHSA-r3jw-6ppm-jp54/GHSA-r3jw-6ppm-jp54.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r3jw-6ppm-jp54", - "modified": "2024-07-10T00:30:42Z", + "modified": "2024-08-29T18:31:34Z", "published": "2024-07-10T00:30:42Z", "aliases": [ "CVE-2024-39883" ], "details": "Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. If a target visits a malicious page or opens a malicious file an attacker can leverage this vulnerability to execute code in the context of the current process.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" @@ -28,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-r595-x79c-68p4/GHSA-r595-x79c-68p4.json b/advisories/unreviewed/2024/07/GHSA-r595-x79c-68p4/GHSA-r595-x79c-68p4.json index dccdb2e1fde..16afdeb15a1 100644 --- a/advisories/unreviewed/2024/07/GHSA-r595-x79c-68p4/GHSA-r595-x79c-68p4.json +++ b/advisories/unreviewed/2024/07/GHSA-r595-x79c-68p4/GHSA-r595-x79c-68p4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r595-x79c-68p4", - "modified": "2024-07-16T18:31:42Z", + "modified": "2024-08-29T18:31:34Z", "published": "2024-07-09T15:30:54Z", "aliases": [ "CVE-2024-6610" ], "details": "Form validation popups could capture escape key presses. Therefore, spamming form validation messages could be used to prevent users from exiting full-screen mode. This vulnerability affects Firefox < 128.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-09T15:15:12Z" diff --git a/advisories/unreviewed/2024/07/GHSA-r8m6-4m9c-fg6x/GHSA-r8m6-4m9c-fg6x.json b/advisories/unreviewed/2024/07/GHSA-r8m6-4m9c-fg6x/GHSA-r8m6-4m9c-fg6x.json index 914d449e360..8c689e2dd2c 100644 --- a/advisories/unreviewed/2024/07/GHSA-r8m6-4m9c-fg6x/GHSA-r8m6-4m9c-fg6x.json +++ b/advisories/unreviewed/2024/07/GHSA-r8m6-4m9c-fg6x/GHSA-r8m6-4m9c-fg6x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r8m6-4m9c-fg6x", - "modified": "2024-07-28T06:30:45Z", + "modified": "2024-08-29T18:31:34Z", "published": "2024-07-28T06:30:45Z", "aliases": [ "CVE-2024-42054" ], "details": "Cervantes through 0.5-alpha accepts insecure file uploads.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-28T04:15:01Z" diff --git a/advisories/unreviewed/2024/07/GHSA-wmrf-m77q-pc98/GHSA-wmrf-m77q-pc98.json b/advisories/unreviewed/2024/07/GHSA-wmrf-m77q-pc98/GHSA-wmrf-m77q-pc98.json index 619a0fb138b..a57cc958174 100644 --- a/advisories/unreviewed/2024/07/GHSA-wmrf-m77q-pc98/GHSA-wmrf-m77q-pc98.json +++ b/advisories/unreviewed/2024/07/GHSA-wmrf-m77q-pc98/GHSA-wmrf-m77q-pc98.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wmrf-m77q-pc98", - "modified": "2024-07-10T00:30:42Z", + "modified": "2024-08-29T18:31:34Z", "published": "2024-07-10T00:30:42Z", "aliases": [ "CVE-2024-39882" ], "details": "Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. If a target visits a malicious page or opens a malicious file an attacker can leverage this vulnerability to execute code in the context of the current process.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/08/GHSA-27qw-rmpj-379q/GHSA-27qw-rmpj-379q.json b/advisories/unreviewed/2024/08/GHSA-27qw-rmpj-379q/GHSA-27qw-rmpj-379q.json index f27b08c2578..f24e471b436 100644 --- a/advisories/unreviewed/2024/08/GHSA-27qw-rmpj-379q/GHSA-27qw-rmpj-379q.json +++ b/advisories/unreviewed/2024/08/GHSA-27qw-rmpj-379q/GHSA-27qw-rmpj-379q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-27qw-rmpj-379q", - "modified": "2024-08-26T12:31:20Z", + "modified": "2024-08-29T18:31:35Z", "published": "2024-08-26T12:31:20Z", "aliases": [ "CVE-2024-44939" @@ -18,6 +18,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44939" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/53023ab11836ac56fd75f7a71ec1356e50920fa9" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/6ea10dbb1e6c58384136e9adfd75f81951e423f6" diff --git a/advisories/unreviewed/2024/08/GHSA-2c63-x392-hx7w/GHSA-2c63-x392-hx7w.json b/advisories/unreviewed/2024/08/GHSA-2c63-x392-hx7w/GHSA-2c63-x392-hx7w.json new file mode 100644 index 00000000000..593d5ffe03e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-2c63-x392-hx7w/GHSA-2c63-x392-hx7w.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2c63-x392-hx7w", + "modified": "2024-08-29T18:31:35Z", + "published": "2024-08-29T18:31:35Z", + "aliases": [ + "CVE-2024-35118" + ], + "details": "IBM MaaS360 for Android 6.31 through 8.60 is using hard coded credentials that can be obtained by a user with physical access to the device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35118" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/290341" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7166750" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-798" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-2p5q-hvc3-c85p/GHSA-2p5q-hvc3-c85p.json b/advisories/unreviewed/2024/08/GHSA-2p5q-hvc3-c85p/GHSA-2p5q-hvc3-c85p.json index 90287fc47af..b966707ad09 100644 --- a/advisories/unreviewed/2024/08/GHSA-2p5q-hvc3-c85p/GHSA-2p5q-hvc3-c85p.json +++ b/advisories/unreviewed/2024/08/GHSA-2p5q-hvc3-c85p/GHSA-2p5q-hvc3-c85p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2p5q-hvc3-c85p", - "modified": "2024-08-07T09:31:08Z", + "modified": "2024-08-29T18:31:34Z", "published": "2024-08-07T09:31:08Z", "aliases": [ "CVE-2024-42222" ], "details": "In Apache CloudStack 4.19.1.0, a regression in the network listing API allows unauthorised list access of network details for domain admin and normal user accounts. This vulnerability compromises tenant isolation, potentially leading to unauthorised access to network details, configurations and data.\n\nAffected users are advised to upgrade to version 4.19.1.1 to address this issue. Users on older versions of CloudStack considering to upgrade, can skip 4.19.1.0 and upgrade directly to 4.19.1.1.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ "CWE-200" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-07T08:16:12Z" diff --git a/advisories/unreviewed/2024/08/GHSA-328c-8rw4-p536/GHSA-328c-8rw4-p536.json b/advisories/unreviewed/2024/08/GHSA-328c-8rw4-p536/GHSA-328c-8rw4-p536.json new file mode 100644 index 00000000000..37a2f1e3dc9 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-328c-8rw4-p536/GHSA-328c-8rw4-p536.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-328c-8rw4-p536", + "modified": "2024-08-29T18:31:35Z", + "published": "2024-08-29T18:31:35Z", + "aliases": [ + "CVE-2024-43952" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreations Esotera allows Stored XSS.This issue affects Esotera: from n/a through 1.2.5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43952" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/esotera/wordpress-esotera-theme-1-2-5-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-32r9-2j7h-3vqq/GHSA-32r9-2j7h-3vqq.json b/advisories/unreviewed/2024/08/GHSA-32r9-2j7h-3vqq/GHSA-32r9-2j7h-3vqq.json new file mode 100644 index 00000000000..d4906d0807f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-32r9-2j7h-3vqq/GHSA-32r9-2j7h-3vqq.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-32r9-2j7h-3vqq", + "modified": "2024-08-29T18:31:36Z", + "published": "2024-08-29T18:31:36Z", + "aliases": [ + "CVE-2024-44778" + ], + "details": "A reflected cross-site scripting (XSS) vulnerability in the parent parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44778" + }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com/files/180462/vTiger-CRM-7.4.0-Cross-Site-Scripting.html" + }, + { + "type": "WEB", + "url": "http://vtiger.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-38g8-fv8m-xfpr/GHSA-38g8-fv8m-xfpr.json b/advisories/unreviewed/2024/08/GHSA-38g8-fv8m-xfpr/GHSA-38g8-fv8m-xfpr.json new file mode 100644 index 00000000000..a7a9be3d451 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-38g8-fv8m-xfpr/GHSA-38g8-fv8m-xfpr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-38g8-fv8m-xfpr", + "modified": "2024-08-29T18:31:35Z", + "published": "2024-08-29T18:31:35Z", + "aliases": [ + "CVE-2024-43926" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Beaver Builder Team Beaver Builder allows Reflected XSS.This issue affects Beaver Builder: from n/a through 2.8.3.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43926" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/beaver-builder-lite-version/wordpress-beaver-builder-plugin-2-8-3-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-3mqr-vvf3-23jj/GHSA-3mqr-vvf3-23jj.json b/advisories/unreviewed/2024/08/GHSA-3mqr-vvf3-23jj/GHSA-3mqr-vvf3-23jj.json index afb60e25c3e..6afb9129346 100644 --- a/advisories/unreviewed/2024/08/GHSA-3mqr-vvf3-23jj/GHSA-3mqr-vvf3-23jj.json +++ b/advisories/unreviewed/2024/08/GHSA-3mqr-vvf3-23jj/GHSA-3mqr-vvf3-23jj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3mqr-vvf3-23jj", - "modified": "2024-08-26T12:31:20Z", + "modified": "2024-08-29T18:31:35Z", "published": "2024-08-26T12:31:20Z", "aliases": [ "CVE-2024-44940" @@ -26,6 +26,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/440ab7f97261bc28501636a13998e1b1946d2e79" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5a2e37bc648a2503bf6d687aed27b9f4455d82eb" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/dd89a81d850fa9a65f67b4527c0e420d15bf836c" diff --git a/advisories/unreviewed/2024/08/GHSA-3pcg-3m3w-7636/GHSA-3pcg-3m3w-7636.json b/advisories/unreviewed/2024/08/GHSA-3pcg-3m3w-7636/GHSA-3pcg-3m3w-7636.json new file mode 100644 index 00000000000..14479f904a5 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-3pcg-3m3w-7636/GHSA-3pcg-3m3w-7636.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3pcg-3m3w-7636", + "modified": "2024-08-29T18:31:35Z", + "published": "2024-08-29T18:31:35Z", + "aliases": [ + "CVE-2024-43948" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dinesh Karki WP Armour Extended.This issue affects WP Armour Extended: from n/a through 1.26.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43948" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-armour-extended/wordpress-wp-armour-extended-plugin-1-26-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-44m4-gm9r-m853/GHSA-44m4-gm9r-m853.json b/advisories/unreviewed/2024/08/GHSA-44m4-gm9r-m853/GHSA-44m4-gm9r-m853.json index 2c26830efa3..aeaf8ce7336 100644 --- a/advisories/unreviewed/2024/08/GHSA-44m4-gm9r-m853/GHSA-44m4-gm9r-m853.json +++ b/advisories/unreviewed/2024/08/GHSA-44m4-gm9r-m853/GHSA-44m4-gm9r-m853.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-44m4-gm9r-m853", - "modified": "2024-08-26T12:31:19Z", + "modified": "2024-08-29T18:31:35Z", "published": "2024-08-26T12:31:19Z", "aliases": [ "CVE-2024-43897" @@ -29,6 +29,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/89add40066f9ed9abe5f7f886fe5789ff7e0c50e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f01c5e335fbb7fb612d40f14a3c02e2612a43d3b" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/08/GHSA-47jp-rpvr-wqf3/GHSA-47jp-rpvr-wqf3.json b/advisories/unreviewed/2024/08/GHSA-47jp-rpvr-wqf3/GHSA-47jp-rpvr-wqf3.json new file mode 100644 index 00000000000..d99eddd8844 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-47jp-rpvr-wqf3/GHSA-47jp-rpvr-wqf3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-47jp-rpvr-wqf3", + "modified": "2024-08-29T18:31:35Z", + "published": "2024-08-29T18:31:35Z", + "aliases": [ + "CVE-2024-43964" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Michael Leithold DSGVO All in one for WP allows Stored XSS.This issue affects DSGVO All in one for WP: from n/a through 4.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43964" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/dsgvo-all-in-one-for-wp/wordpress-dsgvo-all-in-one-for-wp-plugin-4-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-5cmh-fwww-gj5w/GHSA-5cmh-fwww-gj5w.json b/advisories/unreviewed/2024/08/GHSA-5cmh-fwww-gj5w/GHSA-5cmh-fwww-gj5w.json new file mode 100644 index 00000000000..04f31384078 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-5cmh-fwww-gj5w/GHSA-5cmh-fwww-gj5w.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5cmh-fwww-gj5w", + "modified": "2024-08-29T18:31:36Z", + "published": "2024-08-29T18:31:36Z", + "aliases": [ + "CVE-2024-44777" + ], + "details": "A reflected cross-site scripting (XSS) vulnerability in the tag parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44777" + }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com/files/180462/vTiger-CRM-7.4.0-Cross-Site-Scripting.html" + }, + { + "type": "WEB", + "url": "http://vtiger.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-5jvj-q6wc-xghj/GHSA-5jvj-q6wc-xghj.json b/advisories/unreviewed/2024/08/GHSA-5jvj-q6wc-xghj/GHSA-5jvj-q6wc-xghj.json index be0c45549ef..ab76c87e64b 100644 --- a/advisories/unreviewed/2024/08/GHSA-5jvj-q6wc-xghj/GHSA-5jvj-q6wc-xghj.json +++ b/advisories/unreviewed/2024/08/GHSA-5jvj-q6wc-xghj/GHSA-5jvj-q6wc-xghj.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-5v2c-phpf-wrv5/GHSA-5v2c-phpf-wrv5.json b/advisories/unreviewed/2024/08/GHSA-5v2c-phpf-wrv5/GHSA-5v2c-phpf-wrv5.json index 338ba4609c0..8ee0842254c 100644 --- a/advisories/unreviewed/2024/08/GHSA-5v2c-phpf-wrv5/GHSA-5v2c-phpf-wrv5.json +++ b/advisories/unreviewed/2024/08/GHSA-5v2c-phpf-wrv5/GHSA-5v2c-phpf-wrv5.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-457" + "CWE-457", + "CWE-908" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-5x3f-3wg2-mc2h/GHSA-5x3f-3wg2-mc2h.json b/advisories/unreviewed/2024/08/GHSA-5x3f-3wg2-mc2h/GHSA-5x3f-3wg2-mc2h.json index 028f3e79302..ea77f18bd56 100644 --- a/advisories/unreviewed/2024/08/GHSA-5x3f-3wg2-mc2h/GHSA-5x3f-3wg2-mc2h.json +++ b/advisories/unreviewed/2024/08/GHSA-5x3f-3wg2-mc2h/GHSA-5x3f-3wg2-mc2h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5x3f-3wg2-mc2h", - "modified": "2024-08-06T18:30:57Z", + "modified": "2024-08-29T18:31:34Z", "published": "2024-08-06T18:30:57Z", "aliases": [ "CVE-2024-43113" ], "details": "The contextual menu for links could provide an opportunity for cross-site scripting attacks This vulnerability affects Firefox for iOS < 129.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-06T16:15:49Z" diff --git a/advisories/unreviewed/2024/08/GHSA-5x5q-cqf6-gj8r/GHSA-5x5q-cqf6-gj8r.json b/advisories/unreviewed/2024/08/GHSA-5x5q-cqf6-gj8r/GHSA-5x5q-cqf6-gj8r.json new file mode 100644 index 00000000000..74964b822c5 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-5x5q-cqf6-gj8r/GHSA-5x5q-cqf6-gj8r.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5x5q-cqf6-gj8r", + "modified": "2024-08-29T18:31:36Z", + "published": "2024-08-29T18:31:36Z", + "aliases": [ + "CVE-2024-44930" + ], + "details": "Serilog before v2.1.0 was discovered to contain a Client IP Spoofing vulnerability, which allows attackers to falsify their IP addresses by specifying an arbitrary IP as a value of X-Forwarded-For or Client-Ip headers while performing HTTP requests.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44930" + }, + { + "type": "WEB", + "url": "https://github.com/serilog-contrib/serilog-enrichers-clientinfo/issues/29" + }, + { + "type": "WEB", + "url": "https://github.com/serilog-contrib/serilog-enrichers-clientinfo/releases/tag/v2.1.0" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-62gg-j5pm-8r49/GHSA-62gg-j5pm-8r49.json b/advisories/unreviewed/2024/08/GHSA-62gg-j5pm-8r49/GHSA-62gg-j5pm-8r49.json new file mode 100644 index 00000000000..5e590326811 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-62gg-j5pm-8r49/GHSA-62gg-j5pm-8r49.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62gg-j5pm-8r49", + "modified": "2024-08-29T18:31:35Z", + "published": "2024-08-29T18:31:35Z", + "aliases": [ + "CVE-2024-43934" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Robert Felty Collapsing Archives allows Stored XSS.This issue affects Collapsing Archives: from n/a through 3.0.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43934" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/collapsing-archives/wordpress-collapsing-archives-plugin-3-0-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-6g28-ppr3-c5v8/GHSA-6g28-ppr3-c5v8.json b/advisories/unreviewed/2024/08/GHSA-6g28-ppr3-c5v8/GHSA-6g28-ppr3-c5v8.json new file mode 100644 index 00000000000..c48985b11e6 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6g28-ppr3-c5v8/GHSA-6g28-ppr3-c5v8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6g28-ppr3-c5v8", + "modified": "2024-08-29T18:31:35Z", + "published": "2024-08-29T18:31:35Z", + "aliases": [ + "CVE-2024-43944" + ], + "details": "Incorrect Authorization vulnerability in Yassine Idrissi Maintenance & Coming Soon Redirect Animation allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Maintenance & Coming Soon Redirect Animation: from n/a through 2.1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43944" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/maintenance-coming-soon-redirect-animation/wordpress-maintenance-coming-soon-redirect-animation-plugin-2-1-3-ip-bypass-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-6mc3-f5wc-vw2x/GHSA-6mc3-f5wc-vw2x.json b/advisories/unreviewed/2024/08/GHSA-6mc3-f5wc-vw2x/GHSA-6mc3-f5wc-vw2x.json new file mode 100644 index 00000000000..3c13759f564 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6mc3-f5wc-vw2x/GHSA-6mc3-f5wc-vw2x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6mc3-f5wc-vw2x", + "modified": "2024-08-29T18:31:35Z", + "published": "2024-08-29T18:31:35Z", + "aliases": [ + "CVE-2024-43963" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WaspThemes YellowPencil Visual CSS Style Editor allows Reflected XSS.This issue affects YellowPencil Visual CSS Style Editor: from n/a through 7.6.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43963" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/yellow-pencil-visual-theme-customizer/wordpress-visual-css-style-editor-plugin-7-6-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-6mjw-w6cc-3r69/GHSA-6mjw-w6cc-3r69.json b/advisories/unreviewed/2024/08/GHSA-6mjw-w6cc-3r69/GHSA-6mjw-w6cc-3r69.json new file mode 100644 index 00000000000..13c078946b4 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6mjw-w6cc-3r69/GHSA-6mjw-w6cc-3r69.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6mjw-w6cc-3r69", + "modified": "2024-08-29T18:31:35Z", + "published": "2024-08-29T18:31:35Z", + "aliases": [ + "CVE-2024-43957" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sk. Abul Hasan Animated Number Counters allows PHP Local File Inclusion.This issue affects Animated Number Counters: from n/a through 1.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43957" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/animated-number-counters/wordpress-animated-number-counters-plugin-1-9-editor-limited-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-6q66-f3v9-mwr7/GHSA-6q66-f3v9-mwr7.json b/advisories/unreviewed/2024/08/GHSA-6q66-f3v9-mwr7/GHSA-6q66-f3v9-mwr7.json new file mode 100644 index 00000000000..880feb8c497 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6q66-f3v9-mwr7/GHSA-6q66-f3v9-mwr7.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6q66-f3v9-mwr7", + "modified": "2024-08-29T18:31:36Z", + "published": "2024-08-29T18:31:35Z", + "aliases": [ + "CVE-2024-44776" + ], + "details": "An Open Redirect vulnerability in the page parameter of vTiger CRM v7.4.0 allows attackers to redirect users to a malicious site via a crafted URL.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44776" + }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com/files/180461/vTiger-CRM-7.4.0-Open-Redirection.html" + }, + { + "type": "WEB", + "url": "http://vtiger.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7f5w-jgw7-q73x/GHSA-7f5w-jgw7-q73x.json b/advisories/unreviewed/2024/08/GHSA-7f5w-jgw7-q73x/GHSA-7f5w-jgw7-q73x.json new file mode 100644 index 00000000000..64d20976794 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-7f5w-jgw7-q73x/GHSA-7f5w-jgw7-q73x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7f5w-jgw7-q73x", + "modified": "2024-08-29T18:31:35Z", + "published": "2024-08-29T18:31:35Z", + "aliases": [ + "CVE-2024-43946" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SKT Themes SKT Blocks – Gutenberg based Page Builder allows Stored XSS.This issue affects SKT Blocks – Gutenberg based Page Builder: from n/a through 1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43946" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/skt-blocks/wordpress-skt-blocks-plugin-1-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7m9h-4qg6-4hmh/GHSA-7m9h-4qg6-4hmh.json b/advisories/unreviewed/2024/08/GHSA-7m9h-4qg6-4hmh/GHSA-7m9h-4qg6-4hmh.json index 51624dcf746..555e4a64ee5 100644 --- a/advisories/unreviewed/2024/08/GHSA-7m9h-4qg6-4hmh/GHSA-7m9h-4qg6-4hmh.json +++ b/advisories/unreviewed/2024/08/GHSA-7m9h-4qg6-4hmh/GHSA-7m9h-4qg6-4hmh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7m9h-4qg6-4hmh", - "modified": "2024-08-06T15:30:53Z", + "modified": "2024-08-29T18:31:34Z", "published": "2024-08-06T15:30:53Z", "aliases": [ "CVE-2024-7524" ], "details": "Firefox adds web-compatibility shims in place of some tracking scripts blocked by Enhanced Tracking Protection. On a site protected by Content Security Policy in \"strict-dynamic\" mode, an attacker able to inject an HTML element could have used a DOM Clobbering attack on some of the shims and achieved XSS, bypassing the CSP strict-dynamic protection. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, and Firefox ESR < 128.1.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-06T13:15:57Z" diff --git a/advisories/unreviewed/2024/08/GHSA-82qj-5g3m-xgxv/GHSA-82qj-5g3m-xgxv.json b/advisories/unreviewed/2024/08/GHSA-82qj-5g3m-xgxv/GHSA-82qj-5g3m-xgxv.json new file mode 100644 index 00000000000..93498a2d80f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-82qj-5g3m-xgxv/GHSA-82qj-5g3m-xgxv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-82qj-5g3m-xgxv", + "modified": "2024-08-29T18:31:35Z", + "published": "2024-08-29T18:31:35Z", + "aliases": [ + "CVE-2024-43958" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gianni Porto IntoTheDark allows Reflected XSS.This issue affects IntoTheDark: from n/a through 1.0.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43958" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/intothedark/wordpress-into-the-dark-theme-1-0-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-87xp-v6jc-jprf/GHSA-87xp-v6jc-jprf.json b/advisories/unreviewed/2024/08/GHSA-87xp-v6jc-jprf/GHSA-87xp-v6jc-jprf.json new file mode 100644 index 00000000000..603291dafc1 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-87xp-v6jc-jprf/GHSA-87xp-v6jc-jprf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-87xp-v6jc-jprf", + "modified": "2024-08-29T18:31:35Z", + "published": "2024-08-29T18:31:35Z", + "aliases": [ + "CVE-2024-43953" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Classic Addons Classic Addons – WPBakery Page Builder allows Stored XSS.This issue affects Classic Addons – WPBakery Page Builder: from n/a through 3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43953" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/classic-addons-wpbakery-page-builder-addons/wordpress-classic-addons-wpbakery-page-builder-plugin-3-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-8f4h-jjh9-fxrx/GHSA-8f4h-jjh9-fxrx.json b/advisories/unreviewed/2024/08/GHSA-8f4h-jjh9-fxrx/GHSA-8f4h-jjh9-fxrx.json index d55e1cf7a03..3e3851c3df9 100644 --- a/advisories/unreviewed/2024/08/GHSA-8f4h-jjh9-fxrx/GHSA-8f4h-jjh9-fxrx.json +++ b/advisories/unreviewed/2024/08/GHSA-8f4h-jjh9-fxrx/GHSA-8f4h-jjh9-fxrx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8f4h-jjh9-fxrx", - "modified": "2024-08-26T12:31:20Z", + "modified": "2024-08-29T18:31:35Z", "published": "2024-08-26T12:31:20Z", "aliases": [ "CVE-2024-44938" @@ -26,6 +26,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/7063b80268e2593e58bee8a8d709c2f3ff93e2f2" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bd04a149e3a29e7f71b7956ed41dba34e42d539e" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/f650148b43949ca9e37e820804bb6026fff404f3" diff --git a/advisories/unreviewed/2024/08/GHSA-8frx-vgqj-jxgq/GHSA-8frx-vgqj-jxgq.json b/advisories/unreviewed/2024/08/GHSA-8frx-vgqj-jxgq/GHSA-8frx-vgqj-jxgq.json new file mode 100644 index 00000000000..e76134def87 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-8frx-vgqj-jxgq/GHSA-8frx-vgqj-jxgq.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8frx-vgqj-jxgq", + "modified": "2024-08-29T18:31:36Z", + "published": "2024-08-29T18:31:36Z", + "aliases": [ + "CVE-2024-44779" + ], + "details": "A reflected cross-site scripting (XSS) vulnerability in the viewname parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44779" + }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com/files/180462/vTiger-CRM-7.4.0-Cross-Site-Scripting.html" + }, + { + "type": "WEB", + "url": "http://vtiger.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-8gp9-jmc9-crp2/GHSA-8gp9-jmc9-crp2.json b/advisories/unreviewed/2024/08/GHSA-8gp9-jmc9-crp2/GHSA-8gp9-jmc9-crp2.json new file mode 100644 index 00000000000..8505f3015c5 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-8gp9-jmc9-crp2/GHSA-8gp9-jmc9-crp2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8gp9-jmc9-crp2", + "modified": "2024-08-29T18:31:35Z", + "published": "2024-08-29T18:31:35Z", + "aliases": [ + "CVE-2024-43961" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in azurecurve azurecurve Toggle Show/Hide allows Stored XSS.This issue affects azurecurve Toggle Show/Hide: from n/a through 2.1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43961" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/azurecurve-toggle-showhide/wordpress-azurecurve-toggle-show-hide-plugin-2-1-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-c382-6838-fr3r/GHSA-c382-6838-fr3r.json b/advisories/unreviewed/2024/08/GHSA-c382-6838-fr3r/GHSA-c382-6838-fr3r.json new file mode 100644 index 00000000000..b348df41e8f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-c382-6838-fr3r/GHSA-c382-6838-fr3r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c382-6838-fr3r", + "modified": "2024-08-29T18:31:35Z", + "published": "2024-08-29T18:31:35Z", + "aliases": [ + "CVE-2024-8255" + ], + "details": "Delta Electronics DTN Soft version 2.0.1 and prior are vulnerable to an attacker achieving remote code execution through a deserialization of untrusted data vulnerability.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8255" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-242-02" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-c7vp-757h-879w/GHSA-c7vp-757h-879w.json b/advisories/unreviewed/2024/08/GHSA-c7vp-757h-879w/GHSA-c7vp-757h-879w.json index 4c629487ee5..3ccdb9f5ef7 100644 --- a/advisories/unreviewed/2024/08/GHSA-c7vp-757h-879w/GHSA-c7vp-757h-879w.json +++ b/advisories/unreviewed/2024/08/GHSA-c7vp-757h-879w/GHSA-c7vp-757h-879w.json @@ -52,7 +52,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-f2jj-rmrg-9rjx/GHSA-f2jj-rmrg-9rjx.json b/advisories/unreviewed/2024/08/GHSA-f2jj-rmrg-9rjx/GHSA-f2jj-rmrg-9rjx.json index 26ec3a61dd1..37df2efa239 100644 --- a/advisories/unreviewed/2024/08/GHSA-f2jj-rmrg-9rjx/GHSA-f2jj-rmrg-9rjx.json +++ b/advisories/unreviewed/2024/08/GHSA-f2jj-rmrg-9rjx/GHSA-f2jj-rmrg-9rjx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f2jj-rmrg-9rjx", - "modified": "2024-08-27T15:32:43Z", + "modified": "2024-08-29T18:31:35Z", "published": "2024-08-26T09:30:44Z", "aliases": [ "CVE-2024-43884" @@ -21,9 +21,21 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43884" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/064dd929c76532359d2905d90a7c12348043cfd4" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/538fd3921afac97158d4177139a0ad39f056dbb2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5da2884292329bc9be32a7778e0e119f06abe503" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ee0799103b1ae4bcfd80dc11a15df085f6ee1b61" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/08/GHSA-f839-84cr-67jq/GHSA-f839-84cr-67jq.json b/advisories/unreviewed/2024/08/GHSA-f839-84cr-67jq/GHSA-f839-84cr-67jq.json new file mode 100644 index 00000000000..00e1ae9e4c8 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-f839-84cr-67jq/GHSA-f839-84cr-67jq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f839-84cr-67jq", + "modified": "2024-08-29T18:31:35Z", + "published": "2024-08-29T18:31:35Z", + "aliases": [ + "CVE-2024-43936" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPDeveloper EmbedPress allows Stored XSS.This issue affects EmbedPress: from n/a through 4.0.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43936" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/embedpress/wordpress-embedpress-plugin-4-0-8-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-g9q9-268w-xmvw/GHSA-g9q9-268w-xmvw.json b/advisories/unreviewed/2024/08/GHSA-g9q9-268w-xmvw/GHSA-g9q9-268w-xmvw.json new file mode 100644 index 00000000000..f6777acaea7 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-g9q9-268w-xmvw/GHSA-g9q9-268w-xmvw.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g9q9-268w-xmvw", + "modified": "2024-08-29T18:31:36Z", + "published": "2024-08-29T18:31:35Z", + "aliases": [ + "CVE-2024-44717" + ], + "details": "A cross-site scripting (XSS) vulnerability in DedeBIZ v6.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44717" + }, + { + "type": "WEB", + "url": "https://gitee.com/DedeBIZ/DedeV6/releases/tag/6.3.0" + }, + { + "type": "WEB", + "url": "https://github.com/Jingyi-u/DedeBIZ2" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-hchh-wrf4-gc5c/GHSA-hchh-wrf4-gc5c.json b/advisories/unreviewed/2024/08/GHSA-hchh-wrf4-gc5c/GHSA-hchh-wrf4-gc5c.json index 6a1fbd9140a..3ab4932d5e5 100644 --- a/advisories/unreviewed/2024/08/GHSA-hchh-wrf4-gc5c/GHSA-hchh-wrf4-gc5c.json +++ b/advisories/unreviewed/2024/08/GHSA-hchh-wrf4-gc5c/GHSA-hchh-wrf4-gc5c.json @@ -52,7 +52,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-hhfv-px9r-qrj6/GHSA-hhfv-px9r-qrj6.json b/advisories/unreviewed/2024/08/GHSA-hhfv-px9r-qrj6/GHSA-hhfv-px9r-qrj6.json new file mode 100644 index 00000000000..c375f48e280 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-hhfv-px9r-qrj6/GHSA-hhfv-px9r-qrj6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hhfv-px9r-qrj6", + "modified": "2024-08-29T18:31:35Z", + "published": "2024-08-29T18:31:35Z", + "aliases": [ + "CVE-2024-43949" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Automattic GHActivity allows Stored XSS.This issue affects GHActivity: from n/a through 2.0.0-alpha.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43949" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ghactivity/wordpress-ghactivity-plugin-2-0-0-alpha-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-jchw-pqx7-w4qj/GHSA-jchw-pqx7-w4qj.json b/advisories/unreviewed/2024/08/GHSA-jchw-pqx7-w4qj/GHSA-jchw-pqx7-w4qj.json index cfa4fc2f0c1..f432680ab68 100644 --- a/advisories/unreviewed/2024/08/GHSA-jchw-pqx7-w4qj/GHSA-jchw-pqx7-w4qj.json +++ b/advisories/unreviewed/2024/08/GHSA-jchw-pqx7-w4qj/GHSA-jchw-pqx7-w4qj.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-jmpg-vwvq-wqrc/GHSA-jmpg-vwvq-wqrc.json b/advisories/unreviewed/2024/08/GHSA-jmpg-vwvq-wqrc/GHSA-jmpg-vwvq-wqrc.json new file mode 100644 index 00000000000..2be26a74462 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-jmpg-vwvq-wqrc/GHSA-jmpg-vwvq-wqrc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jmpg-vwvq-wqrc", + "modified": "2024-08-29T18:31:35Z", + "published": "2024-08-29T18:31:35Z", + "aliases": [ + "CVE-2024-43965" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smackcoders SendGrid for WordPress allows SQL Injection.This issue affects SendGrid for WordPress: from n/a through 1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43965" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-sendgrid-mailer/wordpress-sendgrid-for-wordpress-plugin-1-4-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-jpqh-p3f6-x53r/GHSA-jpqh-p3f6-x53r.json b/advisories/unreviewed/2024/08/GHSA-jpqh-p3f6-x53r/GHSA-jpqh-p3f6-x53r.json new file mode 100644 index 00000000000..f3daaae9e5d --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-jpqh-p3f6-x53r/GHSA-jpqh-p3f6-x53r.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jpqh-p3f6-x53r", + "modified": "2024-08-29T18:31:36Z", + "published": "2024-08-29T18:31:36Z", + "aliases": [ + "CVE-2024-44716" + ], + "details": "A cross-site scripting (XSS) vulnerability in DedeBIZ v6.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44716" + }, + { + "type": "WEB", + "url": "https://gitee.com/DedeBIZ/DedeV6/releases/tag/6.3.0" + }, + { + "type": "WEB", + "url": "https://github.com/Jingyi-u/DedeBIZ" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-m7jg-gw6r-5p82/GHSA-m7jg-gw6r-5p82.json b/advisories/unreviewed/2024/08/GHSA-m7jg-gw6r-5p82/GHSA-m7jg-gw6r-5p82.json new file mode 100644 index 00000000000..a0642bdd694 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-m7jg-gw6r-5p82/GHSA-m7jg-gw6r-5p82.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m7jg-gw6r-5p82", + "modified": "2024-08-29T18:31:35Z", + "published": "2024-08-29T18:31:35Z", + "aliases": [ + "CVE-2024-35133" + ], + "details": "IBM Security Verify Access 10.0.0 through 10.0.8 OIDC Provider could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35133" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/291026" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7166712" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T17:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-pqp2-hjwx-f6qp/GHSA-pqp2-hjwx-f6qp.json b/advisories/unreviewed/2024/08/GHSA-pqp2-hjwx-f6qp/GHSA-pqp2-hjwx-f6qp.json index b1875511ef2..be8f84f2ecb 100644 --- a/advisories/unreviewed/2024/08/GHSA-pqp2-hjwx-f6qp/GHSA-pqp2-hjwx-f6qp.json +++ b/advisories/unreviewed/2024/08/GHSA-pqp2-hjwx-f6qp/GHSA-pqp2-hjwx-f6qp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pqp2-hjwx-f6qp", - "modified": "2024-08-17T12:30:33Z", + "modified": "2024-08-29T18:31:35Z", "published": "2024-08-17T12:30:33Z", "aliases": [ "CVE-2024-43845" @@ -26,6 +26,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/40d7b3ed52449d36143bab8d3e70926aa61a60f4" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c996b570305e7a6910c2ce4cdcd4c22757ffe241" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/fe2ead240c31e8d158713beca9d0681a6e6a53ab" diff --git a/advisories/unreviewed/2024/08/GHSA-q4r6-47xw-44p5/GHSA-q4r6-47xw-44p5.json b/advisories/unreviewed/2024/08/GHSA-q4r6-47xw-44p5/GHSA-q4r6-47xw-44p5.json new file mode 100644 index 00000000000..025eedc0d82 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-q4r6-47xw-44p5/GHSA-q4r6-47xw-44p5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q4r6-47xw-44p5", + "modified": "2024-08-29T18:31:35Z", + "published": "2024-08-29T18:31:35Z", + "aliases": [ + "CVE-2024-43960" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Page Builder Addons Web and WooCommerce Addons for WPBakery Builder allows Stored XSS.This issue affects Web and WooCommerce Addons for WPBakery Builder: from n/a through 1.4.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43960" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/vc-addons-by-bit14/wordpress-web-and-woocommerce-addons-for-wpbakery-builder-plugin-1-4-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-q76r-q56h-f5fj/GHSA-q76r-q56h-f5fj.json b/advisories/unreviewed/2024/08/GHSA-q76r-q56h-f5fj/GHSA-q76r-q56h-f5fj.json new file mode 100644 index 00000000000..be83bb8d748 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-q76r-q56h-f5fj/GHSA-q76r-q56h-f5fj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q76r-q56h-f5fj", + "modified": "2024-08-29T18:31:35Z", + "published": "2024-08-29T18:31:35Z", + "aliases": [ + "CVE-2024-43954" + ], + "details": "Incorrect Authorization vulnerability in Themeum Droip allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Droip: from n/a through 1.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43954" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/droip/wordpress-droip-plugin-1-1-1-subscriber-settings-change-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-q777-ff33-4xgr/GHSA-q777-ff33-4xgr.json b/advisories/unreviewed/2024/08/GHSA-q777-ff33-4xgr/GHSA-q777-ff33-4xgr.json new file mode 100644 index 00000000000..51ac51ad421 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-q777-ff33-4xgr/GHSA-q777-ff33-4xgr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q777-ff33-4xgr", + "modified": "2024-08-29T18:31:35Z", + "published": "2024-08-29T18:31:35Z", + "aliases": [ + "CVE-2024-44919" + ], + "details": "A cross-site scripting (XSS) vulnerability in the component admin_ads.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the ad description parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44919" + }, + { + "type": "WEB", + "url": "https://github.com/nn0nkey/nn0nkey/blob/main/second.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-qxmr-2g5h-fq9f/GHSA-qxmr-2g5h-fq9f.json b/advisories/unreviewed/2024/08/GHSA-qxmr-2g5h-fq9f/GHSA-qxmr-2g5h-fq9f.json new file mode 100644 index 00000000000..9951b9d0b11 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-qxmr-2g5h-fq9f/GHSA-qxmr-2g5h-fq9f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qxmr-2g5h-fq9f", + "modified": "2024-08-29T18:31:35Z", + "published": "2024-08-29T18:31:35Z", + "aliases": [ + "CVE-2024-43955" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themeum Droip allows File Manipulation.This issue affects Droip: from n/a through 1.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43955" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/droip/wordpress-droip-plugin-1-1-1-unauthenticated-arbitrary-file-download-deletion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-r7j3-9q26-4mw3/GHSA-r7j3-9q26-4mw3.json b/advisories/unreviewed/2024/08/GHSA-r7j3-9q26-4mw3/GHSA-r7j3-9q26-4mw3.json new file mode 100644 index 00000000000..270f08f29ae --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-r7j3-9q26-4mw3/GHSA-r7j3-9q26-4mw3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r7j3-9q26-4mw3", + "modified": "2024-08-29T18:31:35Z", + "published": "2024-08-29T18:31:35Z", + "aliases": [ + "CVE-2024-43943" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wpsoul Greenshift Woocommerce Addon allows SQL Injection.This issue affects Greenshift Woocommerce Addon: from n/a before 1.9.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43943" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/greenshiftwoo/wordpress-greenshift-woocommerce-addon-plugin-1-9-8-subscriber-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-rmc5-c4fj-6pr3/GHSA-rmc5-c4fj-6pr3.json b/advisories/unreviewed/2024/08/GHSA-rmc5-c4fj-6pr3/GHSA-rmc5-c4fj-6pr3.json new file mode 100644 index 00000000000..f9178dc82d3 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-rmc5-c4fj-6pr3/GHSA-rmc5-c4fj-6pr3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rmc5-c4fj-6pr3", + "modified": "2024-08-29T18:31:35Z", + "published": "2024-08-29T18:31:35Z", + "aliases": [ + "CVE-2024-43935" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Delicious Delicious Recipes – WordPress Recipe Plugin allows Stored XSS.This issue affects Delicious Recipes – WordPress Recipe Plugin: from n/a through 1.6.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43935" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/delicious-recipes/wordpress-wp-delicious-recipe-plugin-for-food-bloggers-formerly-delicious-recipes-plugin-1-6-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-v7vh-p9c8-f69f/GHSA-v7vh-p9c8-f69f.json b/advisories/unreviewed/2024/08/GHSA-v7vh-p9c8-f69f/GHSA-v7vh-p9c8-f69f.json new file mode 100644 index 00000000000..c05f0a4a5bc --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-v7vh-p9c8-f69f/GHSA-v7vh-p9c8-f69f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v7vh-p9c8-f69f", + "modified": "2024-08-29T18:31:35Z", + "published": "2024-08-29T18:31:35Z", + "aliases": [ + "CVE-2024-43950" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Nextbricks Brickscore allows Stored XSS.This issue affects Brickscore: from n/a through 1.4.2.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43950" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/brickscore/wordpress-brickscore-plugin-1-4-2-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-vq6x-89qw-7665/GHSA-vq6x-89qw-7665.json b/advisories/unreviewed/2024/08/GHSA-vq6x-89qw-7665/GHSA-vq6x-89qw-7665.json index 5abbe20b6b8..e65d1e9332d 100644 --- a/advisories/unreviewed/2024/08/GHSA-vq6x-89qw-7665/GHSA-vq6x-89qw-7665.json +++ b/advisories/unreviewed/2024/08/GHSA-vq6x-89qw-7665/GHSA-vq6x-89qw-7665.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-vwcr-cpgw-p977/GHSA-vwcr-cpgw-p977.json b/advisories/unreviewed/2024/08/GHSA-vwcr-cpgw-p977/GHSA-vwcr-cpgw-p977.json index 62ccca2c88e..8fc1cf61a80 100644 --- a/advisories/unreviewed/2024/08/GHSA-vwcr-cpgw-p977/GHSA-vwcr-cpgw-p977.json +++ b/advisories/unreviewed/2024/08/GHSA-vwcr-cpgw-p977/GHSA-vwcr-cpgw-p977.json @@ -52,7 +52,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-w3xp-69rr-q6gw/GHSA-w3xp-69rr-q6gw.json b/advisories/unreviewed/2024/08/GHSA-w3xp-69rr-q6gw/GHSA-w3xp-69rr-q6gw.json index 887af760868..23861c0d058 100644 --- a/advisories/unreviewed/2024/08/GHSA-w3xp-69rr-q6gw/GHSA-w3xp-69rr-q6gw.json +++ b/advisories/unreviewed/2024/08/GHSA-w3xp-69rr-q6gw/GHSA-w3xp-69rr-q6gw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w3xp-69rr-q6gw", - "modified": "2024-08-06T15:30:53Z", + "modified": "2024-08-29T18:31:34Z", "published": "2024-08-06T15:30:53Z", "aliases": [ "CVE-2024-7523" ], "details": "A select option could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. \n*This issue only affects Android versions of Firefox.* This vulnerability affects Firefox < 129.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1021" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-06T13:15:57Z" diff --git a/advisories/unreviewed/2024/08/GHSA-wg9w-jqp9-m5g6/GHSA-wg9w-jqp9-m5g6.json b/advisories/unreviewed/2024/08/GHSA-wg9w-jqp9-m5g6/GHSA-wg9w-jqp9-m5g6.json index 08c6e55babd..d350596f361 100644 --- a/advisories/unreviewed/2024/08/GHSA-wg9w-jqp9-m5g6/GHSA-wg9w-jqp9-m5g6.json +++ b/advisories/unreviewed/2024/08/GHSA-wg9w-jqp9-m5g6/GHSA-wg9w-jqp9-m5g6.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-457" + "CWE-457", + "CWE-908" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-wh5v-48m2-2wp8/GHSA-wh5v-48m2-2wp8.json b/advisories/unreviewed/2024/08/GHSA-wh5v-48m2-2wp8/GHSA-wh5v-48m2-2wp8.json new file mode 100644 index 00000000000..9c47e9949e9 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-wh5v-48m2-2wp8/GHSA-wh5v-48m2-2wp8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wh5v-48m2-2wp8", + "modified": "2024-08-29T18:31:35Z", + "published": "2024-08-29T18:31:35Z", + "aliases": [ + "CVE-2024-43951" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreations Tempera allows Stored XSS.This issue affects Tempera: from n/a through 1.8.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43951" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/tempera/wordpress-tempera-theme-1-8-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-xj99-h8qh-p35c/GHSA-xj99-h8qh-p35c.json b/advisories/unreviewed/2024/08/GHSA-xj99-h8qh-p35c/GHSA-xj99-h8qh-p35c.json index 07793559f5d..2cdb31dd94d 100644 --- a/advisories/unreviewed/2024/08/GHSA-xj99-h8qh-p35c/GHSA-xj99-h8qh-p35c.json +++ b/advisories/unreviewed/2024/08/GHSA-xj99-h8qh-p35c/GHSA-xj99-h8qh-p35c.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-457" + "CWE-457", + "CWE-908" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-xmm2-x5jc-rvmh/GHSA-xmm2-x5jc-rvmh.json b/advisories/unreviewed/2024/08/GHSA-xmm2-x5jc-rvmh/GHSA-xmm2-x5jc-rvmh.json index 666aa1de552..8e195c1dc7b 100644 --- a/advisories/unreviewed/2024/08/GHSA-xmm2-x5jc-rvmh/GHSA-xmm2-x5jc-rvmh.json +++ b/advisories/unreviewed/2024/08/GHSA-xmm2-x5jc-rvmh/GHSA-xmm2-x5jc-rvmh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xmm2-x5jc-rvmh", - "modified": "2024-08-06T18:30:56Z", + "modified": "2024-08-29T18:31:34Z", "published": "2024-08-06T18:30:56Z", "aliases": [ "CVE-2024-43112" ], "details": "Long pressing on a download link could potentially provide a means for cross-site scripting This vulnerability affects Firefox for iOS < 129.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-06T16:15:49Z" diff --git a/advisories/unreviewed/2024/08/GHSA-xv9x-vwxf-xx9x/GHSA-xv9x-vwxf-xx9x.json b/advisories/unreviewed/2024/08/GHSA-xv9x-vwxf-xx9x/GHSA-xv9x-vwxf-xx9x.json index 12b3cfc157a..5c5bd8cbd5e 100644 --- a/advisories/unreviewed/2024/08/GHSA-xv9x-vwxf-xx9x/GHSA-xv9x-vwxf-xx9x.json +++ b/advisories/unreviewed/2024/08/GHSA-xv9x-vwxf-xx9x/GHSA-xv9x-vwxf-xx9x.json @@ -52,7 +52,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "MODERATE", "github_reviewed": false,