diff --git a/advisories/unreviewed/2024/02/GHSA-7268-248f-7vgg/GHSA-7268-248f-7vgg.json b/advisories/unreviewed/2024/02/GHSA-7268-248f-7vgg/GHSA-7268-248f-7vgg.json index 14cd4173e9f..d16754bd607 100644 --- a/advisories/unreviewed/2024/02/GHSA-7268-248f-7vgg/GHSA-7268-248f-7vgg.json +++ b/advisories/unreviewed/2024/02/GHSA-7268-248f-7vgg/GHSA-7268-248f-7vgg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7268-248f-7vgg", - "modified": "2024-02-14T18:30:26Z", + "modified": "2024-12-09T15:31:31Z", "published": "2024-02-14T18:30:26Z", "aliases": [ "CVE-2024-0010" diff --git a/advisories/unreviewed/2024/02/GHSA-9ppw-9f8w-5r25/GHSA-9ppw-9f8w-5r25.json b/advisories/unreviewed/2024/02/GHSA-9ppw-9f8w-5r25/GHSA-9ppw-9f8w-5r25.json index dd352808339..e02ad437b89 100644 --- a/advisories/unreviewed/2024/02/GHSA-9ppw-9f8w-5r25/GHSA-9ppw-9f8w-5r25.json +++ b/advisories/unreviewed/2024/02/GHSA-9ppw-9f8w-5r25/GHSA-9ppw-9f8w-5r25.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-346", "CWE-940" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/02/GHSA-ghwc-v2xp-4mwg/GHSA-ghwc-v2xp-4mwg.json b/advisories/unreviewed/2024/02/GHSA-ghwc-v2xp-4mwg/GHSA-ghwc-v2xp-4mwg.json index 012daec0e50..8891cdb6c26 100644 --- a/advisories/unreviewed/2024/02/GHSA-ghwc-v2xp-4mwg/GHSA-ghwc-v2xp-4mwg.json +++ b/advisories/unreviewed/2024/02/GHSA-ghwc-v2xp-4mwg/GHSA-ghwc-v2xp-4mwg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ghwc-v2xp-4mwg", - "modified": "2024-02-14T18:30:26Z", + "modified": "2024-12-09T15:31:31Z", "published": "2024-02-14T18:30:26Z", "aliases": [ "CVE-2024-0011" diff --git a/advisories/unreviewed/2024/03/GHSA-4466-5jhm-q8x8/GHSA-4466-5jhm-q8x8.json b/advisories/unreviewed/2024/03/GHSA-4466-5jhm-q8x8/GHSA-4466-5jhm-q8x8.json index 45e30467d32..1e2ad56a99e 100644 --- a/advisories/unreviewed/2024/03/GHSA-4466-5jhm-q8x8/GHSA-4466-5jhm-q8x8.json +++ b/advisories/unreviewed/2024/03/GHSA-4466-5jhm-q8x8/GHSA-4466-5jhm-q8x8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4466-5jhm-q8x8", - "modified": "2024-03-13T21:31:02Z", + "modified": "2024-12-09T15:31:32Z", "published": "2024-03-08T03:31:25Z", "aliases": [ "CVE-2024-23292" ], "details": "This issue was addressed with improved data protection. This issue is fixed in macOS Sonoma 14.4, iOS 17.4 and iPadOS 17.4. An app may be able to access information about a user's contacts.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -29,7 +34,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-08T02:15:50Z" diff --git a/advisories/unreviewed/2024/03/GHSA-8857-m4qp-w9m7/GHSA-8857-m4qp-w9m7.json b/advisories/unreviewed/2024/03/GHSA-8857-m4qp-w9m7/GHSA-8857-m4qp-w9m7.json index a5b0e357d8b..6b91f2bc41c 100644 --- a/advisories/unreviewed/2024/03/GHSA-8857-m4qp-w9m7/GHSA-8857-m4qp-w9m7.json +++ b/advisories/unreviewed/2024/03/GHSA-8857-m4qp-w9m7/GHSA-8857-m4qp-w9m7.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-f86g-qrx4-c3h8/GHSA-f86g-qrx4-c3h8.json b/advisories/unreviewed/2024/03/GHSA-f86g-qrx4-c3h8/GHSA-f86g-qrx4-c3h8.json index 21f5f137ce2..044b3cd6091 100644 --- a/advisories/unreviewed/2024/03/GHSA-f86g-qrx4-c3h8/GHSA-f86g-qrx4-c3h8.json +++ b/advisories/unreviewed/2024/03/GHSA-f86g-qrx4-c3h8/GHSA-f86g-qrx4-c3h8.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-g4m8-6xwj-mc45/GHSA-g4m8-6xwj-mc45.json b/advisories/unreviewed/2024/03/GHSA-g4m8-6xwj-mc45/GHSA-g4m8-6xwj-mc45.json index d07872858bb..eeca077f5d7 100644 --- a/advisories/unreviewed/2024/03/GHSA-g4m8-6xwj-mc45/GHSA-g4m8-6xwj-mc45.json +++ b/advisories/unreviewed/2024/03/GHSA-g4m8-6xwj-mc45/GHSA-g4m8-6xwj-mc45.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g4m8-6xwj-mc45", - "modified": "2024-03-14T00:31:05Z", + "modified": "2024-12-09T15:31:31Z", "published": "2024-03-08T03:31:25Z", "aliases": [ "CVE-2024-23262" ], "details": "This issue was addressed with additional entitlement checks. This issue is fixed in visionOS 1.1, iOS 17.4 and iPadOS 17.4, iOS 16.7.6 and iPadOS 16.7.6. An app may be able to spoof system notifications and UI.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-863" + ], + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-08T02:15:48Z" diff --git a/advisories/unreviewed/2024/03/GHSA-mq4f-242h-v9hj/GHSA-mq4f-242h-v9hj.json b/advisories/unreviewed/2024/03/GHSA-mq4f-242h-v9hj/GHSA-mq4f-242h-v9hj.json index 9042b34795f..0c95991a289 100644 --- a/advisories/unreviewed/2024/03/GHSA-mq4f-242h-v9hj/GHSA-mq4f-242h-v9hj.json +++ b/advisories/unreviewed/2024/03/GHSA-mq4f-242h-v9hj/GHSA-mq4f-242h-v9hj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mq4f-242h-v9hj", - "modified": "2024-03-14T00:31:05Z", + "modified": "2024-12-09T15:31:32Z", "published": "2024-03-08T03:31:25Z", "aliases": [ "CVE-2024-23287" ], "details": "A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sonoma 14.4, iOS 17.4 and iPadOS 17.4, watchOS 10.4. An app may be able to access user-sensitive data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -37,7 +42,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-08T02:15:50Z" diff --git a/advisories/unreviewed/2024/03/GHSA-ppgm-9w39-cx97/GHSA-ppgm-9w39-cx97.json b/advisories/unreviewed/2024/03/GHSA-ppgm-9w39-cx97/GHSA-ppgm-9w39-cx97.json index 82436573f28..864778f8202 100644 --- a/advisories/unreviewed/2024/03/GHSA-ppgm-9w39-cx97/GHSA-ppgm-9w39-cx97.json +++ b/advisories/unreviewed/2024/03/GHSA-ppgm-9w39-cx97/GHSA-ppgm-9w39-cx97.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-ppgm-9w39-cx97", - "modified": "2024-05-07T06:30:35Z", + "modified": "2024-12-09T15:31:32Z", "published": "2024-03-08T03:31:25Z", "aliases": [ "CVE-2024-23284" ], "details": "A logic issue was addressed with improved state management. This issue is fixed in tvOS 17.4, macOS Sonoma 14.4, visionOS 1.1, iOS 17.4 and iPadOS 17.4, watchOS 10.4, iOS 16.7.6 and iPadOS 16.7.6, Safari 17.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -85,7 +90,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-08T02:15:49Z" diff --git a/advisories/unreviewed/2024/03/GHSA-pw65-258f-v77h/GHSA-pw65-258f-v77h.json b/advisories/unreviewed/2024/03/GHSA-pw65-258f-v77h/GHSA-pw65-258f-v77h.json index cb94c1621fb..9671fd0fdd1 100644 --- a/advisories/unreviewed/2024/03/GHSA-pw65-258f-v77h/GHSA-pw65-258f-v77h.json +++ b/advisories/unreviewed/2024/03/GHSA-pw65-258f-v77h/GHSA-pw65-258f-v77h.json @@ -78,7 +78,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-787" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-5c83-88f2-q34h/GHSA-5c83-88f2-q34h.json b/advisories/unreviewed/2024/04/GHSA-5c83-88f2-q34h/GHSA-5c83-88f2-q34h.json index e9e13c5a517..a7b3def5b3a 100644 --- a/advisories/unreviewed/2024/04/GHSA-5c83-88f2-q34h/GHSA-5c83-88f2-q34h.json +++ b/advisories/unreviewed/2024/04/GHSA-5c83-88f2-q34h/GHSA-5c83-88f2-q34h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5c83-88f2-q34h", - "modified": "2024-04-08T09:31:13Z", + "modified": "2024-12-09T15:31:32Z", "published": "2024-04-08T09:31:13Z", "aliases": [ "CVE-2023-52540" ], "details": "Vulnerability of improper authentication in the Iaware module.\nImpact: Successful exploitation of this vulnerability will affect availability.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-08T09:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-6hjj-7r3r-92p5/GHSA-6hjj-7r3r-92p5.json b/advisories/unreviewed/2024/04/GHSA-6hjj-7r3r-92p5/GHSA-6hjj-7r3r-92p5.json index 77d051c0ea5..8c9bee1ba2c 100644 --- a/advisories/unreviewed/2024/04/GHSA-6hjj-7r3r-92p5/GHSA-6hjj-7r3r-92p5.json +++ b/advisories/unreviewed/2024/04/GHSA-6hjj-7r3r-92p5/GHSA-6hjj-7r3r-92p5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6hjj-7r3r-92p5", - "modified": "2024-04-08T09:31:13Z", + "modified": "2024-12-09T15:31:32Z", "published": "2024-04-08T09:31:13Z", "aliases": [ "CVE-2023-52546" ], "details": "Vulnerability of package name verification being bypassed in the Calendar app.\nImpact: Successful exploitation of this vulnerability may affect service confidentiality.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-08T09:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-mgx5-jrhq-g7rg/GHSA-mgx5-jrhq-g7rg.json b/advisories/unreviewed/2024/04/GHSA-mgx5-jrhq-g7rg/GHSA-mgx5-jrhq-g7rg.json index 6ad895bafdb..f00ed96d83e 100644 --- a/advisories/unreviewed/2024/04/GHSA-mgx5-jrhq-g7rg/GHSA-mgx5-jrhq-g7rg.json +++ b/advisories/unreviewed/2024/04/GHSA-mgx5-jrhq-g7rg/GHSA-mgx5-jrhq-g7rg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mgx5-jrhq-g7rg", - "modified": "2024-04-03T15:30:42Z", + "modified": "2024-12-09T15:31:32Z", "published": "2024-04-03T15:30:42Z", "aliases": [ "CVE-2024-26686" @@ -18,6 +18,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/27978243f165b44e342f28f449b91327944ea071" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3820b0fac7732a653bcc6f6ac20c1d72e697f8f6" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/7601df8031fd67310af891897ef6cc0df4209305" diff --git a/advisories/unreviewed/2024/05/GHSA-q8gh-g2x4-x4cm/GHSA-q8gh-g2x4-x4cm.json b/advisories/unreviewed/2024/05/GHSA-q8gh-g2x4-x4cm/GHSA-q8gh-g2x4-x4cm.json index 902f9fb1c3a..859e5998575 100644 --- a/advisories/unreviewed/2024/05/GHSA-q8gh-g2x4-x4cm/GHSA-q8gh-g2x4-x4cm.json +++ b/advisories/unreviewed/2024/05/GHSA-q8gh-g2x4-x4cm/GHSA-q8gh-g2x4-x4cm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q8gh-g2x4-x4cm", - "modified": "2024-05-14T21:34:45Z", + "modified": "2024-12-09T15:31:32Z", "published": "2024-05-14T21:34:44Z", "aliases": [ "CVE-2024-4562" diff --git a/advisories/unreviewed/2024/07/GHSA-g8xj-4vj8-qmx3/GHSA-g8xj-4vj8-qmx3.json b/advisories/unreviewed/2024/07/GHSA-g8xj-4vj8-qmx3/GHSA-g8xj-4vj8-qmx3.json index e6a8afed4db..fe7bf197c03 100644 --- a/advisories/unreviewed/2024/07/GHSA-g8xj-4vj8-qmx3/GHSA-g8xj-4vj8-qmx3.json +++ b/advisories/unreviewed/2024/07/GHSA-g8xj-4vj8-qmx3/GHSA-g8xj-4vj8-qmx3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g8xj-4vj8-qmx3", - "modified": "2024-07-12T15:31:29Z", + "modified": "2024-12-09T15:31:32Z", "published": "2024-07-12T15:31:29Z", "aliases": [ "CVE-2024-40975" @@ -14,6 +14,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40975" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/36ff963c133a25ed1166a25c3ba8b357ea010fda" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/3de0f2627ef849735f155c1818247f58404dddfe" diff --git a/advisories/unreviewed/2024/07/GHSA-hq79-5p4q-xv2w/GHSA-hq79-5p4q-xv2w.json b/advisories/unreviewed/2024/07/GHSA-hq79-5p4q-xv2w/GHSA-hq79-5p4q-xv2w.json index 90aa0101b74..f79cd9ac1d9 100644 --- a/advisories/unreviewed/2024/07/GHSA-hq79-5p4q-xv2w/GHSA-hq79-5p4q-xv2w.json +++ b/advisories/unreviewed/2024/07/GHSA-hq79-5p4q-xv2w/GHSA-hq79-5p4q-xv2w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hq79-5p4q-xv2w", - "modified": "2024-09-16T14:37:24Z", + "modified": "2024-12-09T15:31:32Z", "published": "2024-07-30T09:31:52Z", "aliases": [ "CVE-2024-42122" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/8e65a1b7118acf6af96449e1e66b7adbc9396912" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cd1e565a5b7fa60c349ca8a16db1e61715fe8230" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-jfpf-jvq3-6jwv/GHSA-jfpf-jvq3-6jwv.json b/advisories/unreviewed/2024/07/GHSA-jfpf-jvq3-6jwv/GHSA-jfpf-jvq3-6jwv.json index ca080aa13eb..d40e4de646d 100644 --- a/advisories/unreviewed/2024/07/GHSA-jfpf-jvq3-6jwv/GHSA-jfpf-jvq3-6jwv.json +++ b/advisories/unreviewed/2024/07/GHSA-jfpf-jvq3-6jwv/GHSA-jfpf-jvq3-6jwv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jfpf-jvq3-6jwv", - "modified": "2024-07-29T09:36:13Z", + "modified": "2024-12-09T15:31:32Z", "published": "2024-07-29T09:36:13Z", "aliases": [ "CVE-2024-41014" @@ -14,6 +14,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41014" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7cd9f0a33e738cd58876f1bc8d6c1aa5bc4fc8c1" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/fb63435b7c7dc112b1ae1baea5486e0a6e27b196" diff --git a/advisories/unreviewed/2024/07/GHSA-r49f-c964-6w6w/GHSA-r49f-c964-6w6w.json b/advisories/unreviewed/2024/07/GHSA-r49f-c964-6w6w/GHSA-r49f-c964-6w6w.json index 5e995afd8de..3f4f294b19c 100644 --- a/advisories/unreviewed/2024/07/GHSA-r49f-c964-6w6w/GHSA-r49f-c964-6w6w.json +++ b/advisories/unreviewed/2024/07/GHSA-r49f-c964-6w6w/GHSA-r49f-c964-6w6w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r49f-c964-6w6w", - "modified": "2024-09-09T18:30:29Z", + "modified": "2024-12-09T15:31:32Z", "published": "2024-07-12T15:31:28Z", "aliases": [ "CVE-2024-40965" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/4268254a39484fc11ba991ae148bacbe75d9cc0a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d038693e08adf9c162c6377800495e4f5a2df045" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-vqfv-6vgr-3j88/GHSA-vqfv-6vgr-3j88.json b/advisories/unreviewed/2024/07/GHSA-vqfv-6vgr-3j88/GHSA-vqfv-6vgr-3j88.json index d78fba7819a..1fca1b6cb27 100644 --- a/advisories/unreviewed/2024/07/GHSA-vqfv-6vgr-3j88/GHSA-vqfv-6vgr-3j88.json +++ b/advisories/unreviewed/2024/07/GHSA-vqfv-6vgr-3j88/GHSA-vqfv-6vgr-3j88.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vqfv-6vgr-3j88", - "modified": "2024-08-02T15:31:17Z", + "modified": "2024-12-09T15:31:32Z", "published": "2024-07-30T09:32:03Z", "aliases": [ "CVE-2024-42156" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/7f6243edd901b75aaece326c90a1cc0dcb60cc3d" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a891938947f4427f98cb1ce54f27223501efe750" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/d65d76a44ffe74c73298ada25b0f578680576073" diff --git a/advisories/unreviewed/2024/08/GHSA-4765-gch7-m8cw/GHSA-4765-gch7-m8cw.json b/advisories/unreviewed/2024/08/GHSA-4765-gch7-m8cw/GHSA-4765-gch7-m8cw.json index 9bcb2492437..72c24df738c 100644 --- a/advisories/unreviewed/2024/08/GHSA-4765-gch7-m8cw/GHSA-4765-gch7-m8cw.json +++ b/advisories/unreviewed/2024/08/GHSA-4765-gch7-m8cw/GHSA-4765-gch7-m8cw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4765-gch7-m8cw", - "modified": "2024-09-06T15:32:55Z", + "modified": "2024-12-09T15:31:32Z", "published": "2024-08-08T09:30:37Z", "aliases": [ "CVE-2024-42252" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/5d85f2ab79d5918a66539ebf046c099f7448db8d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ecb4aaa658da760fb83afd79cc5fd4360aa60635" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/08/GHSA-58m4-2cjm-4j54/GHSA-58m4-2cjm-4j54.json b/advisories/unreviewed/2024/08/GHSA-58m4-2cjm-4j54/GHSA-58m4-2cjm-4j54.json index 661e646c4f8..c9ff492bbe1 100644 --- a/advisories/unreviewed/2024/08/GHSA-58m4-2cjm-4j54/GHSA-58m4-2cjm-4j54.json +++ b/advisories/unreviewed/2024/08/GHSA-58m4-2cjm-4j54/GHSA-58m4-2cjm-4j54.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-58m4-2cjm-4j54", - "modified": "2024-08-17T09:30:25Z", + "modified": "2024-12-09T15:31:32Z", "published": "2024-08-17T09:30:25Z", "aliases": [ "CVE-2024-42319" @@ -21,6 +21,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/a8bd68e4329f9a0ad1b878733e0f80be6a971649" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d00df6700ad10974a7e20646956f4ff22cdbe0ec" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/08/GHSA-v5c2-f543-4vhm/GHSA-v5c2-f543-4vhm.json b/advisories/unreviewed/2024/08/GHSA-v5c2-f543-4vhm/GHSA-v5c2-f543-4vhm.json index 6b9b0c29ec3..f5a49344d0e 100644 --- a/advisories/unreviewed/2024/08/GHSA-v5c2-f543-4vhm/GHSA-v5c2-f543-4vhm.json +++ b/advisories/unreviewed/2024/08/GHSA-v5c2-f543-4vhm/GHSA-v5c2-f543-4vhm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v5c2-f543-4vhm", - "modified": "2024-08-22T18:31:20Z", + "modified": "2024-12-09T15:31:33Z", "published": "2024-08-17T12:30:33Z", "aliases": [ "CVE-2024-43857" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/381cbe85592c78fbaeb3e770e3e9f3bfa3e67efb" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b98777309756ebe15cc9ad4e8ab64bbfaf878a3f" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/c82bc1ab2a8a5e73d9728e80c4c2ed87e8921a38" diff --git a/advisories/unreviewed/2024/08/GHSA-w46w-6cr6-6pvh/GHSA-w46w-6cr6-6pvh.json b/advisories/unreviewed/2024/08/GHSA-w46w-6cr6-6pvh/GHSA-w46w-6cr6-6pvh.json index 4a4ea1b4569..e510a19fcff 100644 --- a/advisories/unreviewed/2024/08/GHSA-w46w-6cr6-6pvh/GHSA-w46w-6cr6-6pvh.json +++ b/advisories/unreviewed/2024/08/GHSA-w46w-6cr6-6pvh/GHSA-w46w-6cr6-6pvh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w46w-6cr6-6pvh", - "modified": "2024-09-05T18:30:51Z", + "modified": "2024-12-09T15:31:33Z", "published": "2024-08-26T12:31:20Z", "aliases": [ "CVE-2024-43913" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/d59c4d0eb6adc24c2201f153ccb7fd0a335b0d3d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f7d9a18572fcd7130459b7691bd19ee2a2e951ad" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/09/GHSA-3hjf-m6vc-vh7h/GHSA-3hjf-m6vc-vh7h.json b/advisories/unreviewed/2024/09/GHSA-3hjf-m6vc-vh7h/GHSA-3hjf-m6vc-vh7h.json index c278aa8f585..ffb9760c8c6 100644 --- a/advisories/unreviewed/2024/09/GHSA-3hjf-m6vc-vh7h/GHSA-3hjf-m6vc-vh7h.json +++ b/advisories/unreviewed/2024/09/GHSA-3hjf-m6vc-vh7h/GHSA-3hjf-m6vc-vh7h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3hjf-m6vc-vh7h", - "modified": "2024-10-08T18:33:07Z", + "modified": "2024-12-09T15:31:33Z", "published": "2024-09-27T15:30:34Z", "aliases": [ "CVE-2024-46841" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46841" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/135b4819f6fba87fd5a2693023133e78ac73f1d3" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/704c359b4093a2af650a20eaa030c435d7c30f91" diff --git a/advisories/unreviewed/2024/09/GHSA-9388-m6c7-2394/GHSA-9388-m6c7-2394.json b/advisories/unreviewed/2024/09/GHSA-9388-m6c7-2394/GHSA-9388-m6c7-2394.json index 29ce209ca99..6dab7d40b5c 100644 --- a/advisories/unreviewed/2024/09/GHSA-9388-m6c7-2394/GHSA-9388-m6c7-2394.json +++ b/advisories/unreviewed/2024/09/GHSA-9388-m6c7-2394/GHSA-9388-m6c7-2394.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9388-m6c7-2394", - "modified": "2024-10-04T18:31:09Z", + "modified": "2024-12-09T15:31:33Z", "published": "2024-09-04T21:30:31Z", "aliases": [ "CVE-2024-44963" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44963" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/22d907bcd283d69d5e60497fc0d51969545c583b" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/98251cd60b4d702a8a81de442ab621e83a3fb24f" diff --git a/advisories/unreviewed/2024/09/GHSA-hw6f-2v4x-m477/GHSA-hw6f-2v4x-m477.json b/advisories/unreviewed/2024/09/GHSA-hw6f-2v4x-m477/GHSA-hw6f-2v4x-m477.json index f73cc6cfe6c..5215e40034d 100644 --- a/advisories/unreviewed/2024/09/GHSA-hw6f-2v4x-m477/GHSA-hw6f-2v4x-m477.json +++ b/advisories/unreviewed/2024/09/GHSA-hw6f-2v4x-m477/GHSA-hw6f-2v4x-m477.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hw6f-2v4x-m477", - "modified": "2024-10-09T15:32:18Z", + "modified": "2024-12-09T15:31:33Z", "published": "2024-09-04T21:30:31Z", "aliases": [ "CVE-2024-44950" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/7d3b793faaab1305994ce568b59d61927235f57b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dc5ead0e8fc5ef53b8553394d4aab60c277976b3" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/09/GHSA-qcm7-vmfg-h8xw/GHSA-qcm7-vmfg-h8xw.json b/advisories/unreviewed/2024/09/GHSA-qcm7-vmfg-h8xw/GHSA-qcm7-vmfg-h8xw.json index 699833f70d7..52753b1f237 100644 --- a/advisories/unreviewed/2024/09/GHSA-qcm7-vmfg-h8xw/GHSA-qcm7-vmfg-h8xw.json +++ b/advisories/unreviewed/2024/09/GHSA-qcm7-vmfg-h8xw/GHSA-qcm7-vmfg-h8xw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qcm7-vmfg-h8xw", - "modified": "2024-10-10T18:31:08Z", + "modified": "2024-12-09T15:31:33Z", "published": "2024-09-04T21:30:31Z", "aliases": [ "CVE-2024-44955" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/39b217193729aa45eded8de24d9245468a0c0263" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c7e65cab54a89f4df54110f0b44c4ade93d1a911" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/fcf6a49d79923a234844b8efe830a61f3f0584e4" diff --git a/advisories/unreviewed/2024/10/GHSA-22wr-xr3p-42c4/GHSA-22wr-xr3p-42c4.json b/advisories/unreviewed/2024/10/GHSA-22wr-xr3p-42c4/GHSA-22wr-xr3p-42c4.json index efe55660fbe..9ba8cb91b63 100644 --- a/advisories/unreviewed/2024/10/GHSA-22wr-xr3p-42c4/GHSA-22wr-xr3p-42c4.json +++ b/advisories/unreviewed/2024/10/GHSA-22wr-xr3p-42c4/GHSA-22wr-xr3p-42c4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-22wr-xr3p-42c4", - "modified": "2024-11-01T15:31:45Z", + "modified": "2024-12-09T15:31:33Z", "published": "2024-10-21T18:30:57Z", "aliases": [ "CVE-2024-49897" @@ -30,6 +30,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/3ba1219e299ab5462b5cb374c2fa2a67af0ea190" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d247af7c5dbf143ad6be8179bb1550e76d6af57e" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/10/GHSA-2h84-jhpc-6px2/GHSA-2h84-jhpc-6px2.json b/advisories/unreviewed/2024/10/GHSA-2h84-jhpc-6px2/GHSA-2h84-jhpc-6px2.json index 66e5698726b..b42b49f91be 100644 --- a/advisories/unreviewed/2024/10/GHSA-2h84-jhpc-6px2/GHSA-2h84-jhpc-6px2.json +++ b/advisories/unreviewed/2024/10/GHSA-2h84-jhpc-6px2/GHSA-2h84-jhpc-6px2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2h84-jhpc-6px2", - "modified": "2024-10-24T18:30:41Z", + "modified": "2024-12-09T15:31:33Z", "published": "2024-10-21T18:30:57Z", "aliases": [ "CVE-2024-49915" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/c395fd47d1565bd67671f45cca281b3acc2c31ef" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ec1be3c527b4a5fc85bcc1b0be7cec08bf60c796" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/f0454b3cb0584a6bf275aeb49be61a760fd546a2" diff --git a/advisories/unreviewed/2024/10/GHSA-2m92-hrph-h3f7/GHSA-2m92-hrph-h3f7.json b/advisories/unreviewed/2024/10/GHSA-2m92-hrph-h3f7/GHSA-2m92-hrph-h3f7.json index 9bfa6736c7e..6752f5abfbe 100644 --- a/advisories/unreviewed/2024/10/GHSA-2m92-hrph-h3f7/GHSA-2m92-hrph-h3f7.json +++ b/advisories/unreviewed/2024/10/GHSA-2m92-hrph-h3f7/GHSA-2m92-hrph-h3f7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2m92-hrph-h3f7", - "modified": "2024-10-24T03:30:50Z", + "modified": "2024-12-09T15:31:33Z", "published": "2024-10-21T18:30:57Z", "aliases": [ "CVE-2024-49909" @@ -30,6 +30,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/5298270bdabe97be5b8236e544c9e936415fe1f2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f38b09ba6a335c511eb27920bb9bb4a1b2c20084" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/10/GHSA-7797-cc95-p257/GHSA-7797-cc95-p257.json b/advisories/unreviewed/2024/10/GHSA-7797-cc95-p257/GHSA-7797-cc95-p257.json index e594f92f675..bd6a5502dc0 100644 --- a/advisories/unreviewed/2024/10/GHSA-7797-cc95-p257/GHSA-7797-cc95-p257.json +++ b/advisories/unreviewed/2024/10/GHSA-7797-cc95-p257/GHSA-7797-cc95-p257.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7797-cc95-p257", - "modified": "2024-10-24T18:30:41Z", + "modified": "2024-12-09T15:31:33Z", "published": "2024-10-21T18:30:57Z", "aliases": [ "CVE-2024-49917" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49917" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/205e3b96cc9aa9211fd2c849a16245cf236b2d36" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/5443c83eb8fd2f88c71ced38848fbf744d6206a2" diff --git a/advisories/unreviewed/2024/10/GHSA-7f96-m827-q2r2/GHSA-7f96-m827-q2r2.json b/advisories/unreviewed/2024/10/GHSA-7f96-m827-q2r2/GHSA-7f96-m827-q2r2.json index 4407cba5a30..55edaf65e10 100644 --- a/advisories/unreviewed/2024/10/GHSA-7f96-m827-q2r2/GHSA-7f96-m827-q2r2.json +++ b/advisories/unreviewed/2024/10/GHSA-7f96-m827-q2r2/GHSA-7f96-m827-q2r2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7f96-m827-q2r2", - "modified": "2024-10-24T03:30:50Z", + "modified": "2024-12-09T15:31:33Z", "published": "2024-10-21T18:30:57Z", "aliases": [ "CVE-2024-49911" @@ -30,6 +30,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/827380b114f83c30b3e56d1a675980b6d65f7c88" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8c854138b593efbbd8fa46a25f3288c121c1d1a1" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/10/GHSA-ffxc-rwg8-qgjw/GHSA-ffxc-rwg8-qgjw.json b/advisories/unreviewed/2024/10/GHSA-ffxc-rwg8-qgjw/GHSA-ffxc-rwg8-qgjw.json index dd215928b24..f6dcf062db3 100644 --- a/advisories/unreviewed/2024/10/GHSA-ffxc-rwg8-qgjw/GHSA-ffxc-rwg8-qgjw.json +++ b/advisories/unreviewed/2024/10/GHSA-ffxc-rwg8-qgjw/GHSA-ffxc-rwg8-qgjw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ffxc-rwg8-qgjw", - "modified": "2024-10-24T06:30:29Z", + "modified": "2024-12-09T15:31:33Z", "published": "2024-10-21T18:30:57Z", "aliases": [ "CVE-2024-49906" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/2002ccb93004e76a471b180560accb2c1f850f35" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ebef6616219ff04abdeb39450625f85419787ee3" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/10/GHSA-g9mh-3crx-2qvf/GHSA-g9mh-3crx-2qvf.json b/advisories/unreviewed/2024/10/GHSA-g9mh-3crx-2qvf/GHSA-g9mh-3crx-2qvf.json index 6f80e7f68ae..c8976794305 100644 --- a/advisories/unreviewed/2024/10/GHSA-g9mh-3crx-2qvf/GHSA-g9mh-3crx-2qvf.json +++ b/advisories/unreviewed/2024/10/GHSA-g9mh-3crx-2qvf/GHSA-g9mh-3crx-2qvf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g9mh-3crx-2qvf", - "modified": "2024-10-24T18:30:41Z", + "modified": "2024-12-09T15:31:33Z", "published": "2024-10-21T18:30:57Z", "aliases": [ "CVE-2024-49914" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/65a6fee22d5cfa645cb05489892dc9cd3d142fc2" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/68f75e6f08aad66069a629db8d7840919156c761" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/8e4ed3cf1642df0c4456443d865cff61a9598aa8" diff --git a/advisories/unreviewed/2024/10/GHSA-mf62-gm5r-38wj/GHSA-mf62-gm5r-38wj.json b/advisories/unreviewed/2024/10/GHSA-mf62-gm5r-38wj/GHSA-mf62-gm5r-38wj.json index 670f99d07a0..b36b38586f0 100644 --- a/advisories/unreviewed/2024/10/GHSA-mf62-gm5r-38wj/GHSA-mf62-gm5r-38wj.json +++ b/advisories/unreviewed/2024/10/GHSA-mf62-gm5r-38wj/GHSA-mf62-gm5r-38wj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mf62-gm5r-38wj", - "modified": "2024-10-25T15:31:25Z", + "modified": "2024-12-09T15:31:33Z", "published": "2024-10-21T18:30:57Z", "aliases": [ "CVE-2024-49899" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/7f8e93b862aba08d540f1e9e03e0ceb4d0cfd5fb" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9f35cec5e4b9759b38c663d18eae4eaf30f36527" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/b995c0a6de6c74656a0c39cd57a0626351b13e3c" diff --git a/advisories/unreviewed/2024/10/GHSA-q8m3-vwhc-qqmc/GHSA-q8m3-vwhc-qqmc.json b/advisories/unreviewed/2024/10/GHSA-q8m3-vwhc-qqmc/GHSA-q8m3-vwhc-qqmc.json index cbf730cccd1..67d6fff5f3b 100644 --- a/advisories/unreviewed/2024/10/GHSA-q8m3-vwhc-qqmc/GHSA-q8m3-vwhc-qqmc.json +++ b/advisories/unreviewed/2024/10/GHSA-q8m3-vwhc-qqmc/GHSA-q8m3-vwhc-qqmc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q8m3-vwhc-qqmc", - "modified": "2024-10-25T15:31:25Z", + "modified": "2024-12-09T15:31:33Z", "published": "2024-10-21T18:30:57Z", "aliases": [ "CVE-2024-49891" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49891" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/232a138bd843d48cb2368f604646d990db7640f3" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/2be1d4f11944cd6283cb97268b3e17c4424945ca" diff --git a/advisories/unreviewed/2024/10/GHSA-v3jw-p9pj-m453/GHSA-v3jw-p9pj-m453.json b/advisories/unreviewed/2024/10/GHSA-v3jw-p9pj-m453/GHSA-v3jw-p9pj-m453.json index 8c03724420f..636feb8baa1 100644 --- a/advisories/unreviewed/2024/10/GHSA-v3jw-p9pj-m453/GHSA-v3jw-p9pj-m453.json +++ b/advisories/unreviewed/2024/10/GHSA-v3jw-p9pj-m453/GHSA-v3jw-p9pj-m453.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v3jw-p9pj-m453", - "modified": "2024-11-13T15:31:37Z", + "modified": "2024-12-09T15:31:33Z", "published": "2024-10-21T18:30:58Z", "aliases": [ "CVE-2024-49934" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/7f7b850689ac06a62befe26e1fd1806799e7f152" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e0f6ee75f50476607ca82fc7c3711c795ce09b52" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/ef921bc72328b577cb45772ff7921cba4773b74a" diff --git a/advisories/unreviewed/2024/10/GHSA-x3rh-vhj8-7wq6/GHSA-x3rh-vhj8-7wq6.json b/advisories/unreviewed/2024/10/GHSA-x3rh-vhj8-7wq6/GHSA-x3rh-vhj8-7wq6.json index 5680e0aaca3..a23f8d2bb56 100644 --- a/advisories/unreviewed/2024/10/GHSA-x3rh-vhj8-7wq6/GHSA-x3rh-vhj8-7wq6.json +++ b/advisories/unreviewed/2024/10/GHSA-x3rh-vhj8-7wq6/GHSA-x3rh-vhj8-7wq6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x3rh-vhj8-7wq6", - "modified": "2024-10-24T06:30:29Z", + "modified": "2024-12-09T15:31:33Z", "published": "2024-10-21T18:30:57Z", "aliases": [ "CVE-2024-49898" @@ -30,6 +30,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/3fc70ae048fe0936761b73b50700a810ff61e853" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c3a3b6d9a9383e3c1a4a08878ba5046e68647595" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/11/GHSA-8vv8-fmp2-x4c4/GHSA-8vv8-fmp2-x4c4.json b/advisories/unreviewed/2024/11/GHSA-8vv8-fmp2-x4c4/GHSA-8vv8-fmp2-x4c4.json index 4c471da78c5..df8fb728487 100644 --- a/advisories/unreviewed/2024/11/GHSA-8vv8-fmp2-x4c4/GHSA-8vv8-fmp2-x4c4.json +++ b/advisories/unreviewed/2024/11/GHSA-8vv8-fmp2-x4c4/GHSA-8vv8-fmp2-x4c4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8vv8-fmp2-x4c4", - "modified": "2024-11-27T21:32:44Z", + "modified": "2024-12-09T15:31:33Z", "published": "2024-11-19T18:31:07Z", "aliases": [ "CVE-2024-53085" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/bc203fe416abdd1c29da594565a7c3c4e979488e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cfaf83501a0cbb104499c5b0892ee5ebde4e967f" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/12/GHSA-26cq-p273-7g8h/GHSA-26cq-p273-7g8h.json b/advisories/unreviewed/2024/12/GHSA-26cq-p273-7g8h/GHSA-26cq-p273-7g8h.json new file mode 100644 index 00000000000..c4b0298e1f5 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-26cq-p273-7g8h/GHSA-26cq-p273-7g8h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-26cq-p273-7g8h", + "modified": "2024-12-09T15:31:35Z", + "published": "2024-12-09T15:31:35Z", + "aliases": [ + "CVE-2023-49755" + ], + "details": "Missing Authorization vulnerability in B.M. Rafiul Alam Elementor Timeline Widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elementor Timeline Widget: from n/a through 2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49755" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/3r-elementor-timeline-widget/vulnerability/wordpress-elementor-timeline-widget-plugin-2-0-notice-dismissal-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-2cgr-rv3r-g9vw/GHSA-2cgr-rv3r-g9vw.json b/advisories/unreviewed/2024/12/GHSA-2cgr-rv3r-g9vw/GHSA-2cgr-rv3r-g9vw.json new file mode 100644 index 00000000000..81f78547181 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-2cgr-rv3r-g9vw/GHSA-2cgr-rv3r-g9vw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2cgr-rv3r-g9vw", + "modified": "2024-12-09T15:31:37Z", + "published": "2024-12-09T15:31:37Z", + "aliases": [ + "CVE-2024-52391" + ], + "details": "Missing Authorization vulnerability in Genetech Pie Register Premium.This issue affects Pie Register Premium: from n/a before 3.8.3.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52391" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/pie-register-premium/vulnerability/wordpress-pie-register-premium-plugin-3-8-3-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-2cx9-54hp-r698/GHSA-2cx9-54hp-r698.json b/advisories/unreviewed/2024/12/GHSA-2cx9-54hp-r698/GHSA-2cx9-54hp-r698.json new file mode 100644 index 00000000000..52224111bbe --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-2cx9-54hp-r698/GHSA-2cx9-54hp-r698.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2cx9-54hp-r698", + "modified": "2024-12-09T15:31:37Z", + "published": "2024-12-09T15:31:37Z", + "aliases": [ + "CVE-2024-53948" + ], + "details": "Generation of Error Message Containing analytics metadata Information in Apache Superset.\n\nThis issue affects Apache Superset: before 4.1.0.\n\nUsers are recommended to upgrade to version 4.1.0, which fixes the issue.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53948" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/8howpf3png0wrgpls46ggk441oczlfvf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-209" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-2fq3-7c2h-3gr7/GHSA-2fq3-7c2h-3gr7.json b/advisories/unreviewed/2024/12/GHSA-2fq3-7c2h-3gr7/GHSA-2fq3-7c2h-3gr7.json new file mode 100644 index 00000000000..e795f157c9e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-2fq3-7c2h-3gr7/GHSA-2fq3-7c2h-3gr7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2fq3-7c2h-3gr7", + "modified": "2024-12-09T15:31:37Z", + "published": "2024-12-09T15:31:37Z", + "aliases": [ + "CVE-2024-49602" + ], + "details": "Dell PowerScale OneFS Versions 8.2.2.x through 9.8.0.x contain an improper resource unlocking vulnerability. A remote low privileged attacker could potentially exploit this vulnerability, leading to denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49602" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-in/000256645/dsa-2024-453-security-update-for-dell-powerscale-onefs-multiple-security-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-765" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-2r24-7795-jp6m/GHSA-2r24-7795-jp6m.json b/advisories/unreviewed/2024/12/GHSA-2r24-7795-jp6m/GHSA-2r24-7795-jp6m.json new file mode 100644 index 00000000000..7480a13cda4 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-2r24-7795-jp6m/GHSA-2r24-7795-jp6m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2r24-7795-jp6m", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-30873" + ], + "details": "Missing Authorization vulnerability in Fahad Mahmood WP Docs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Docs: from n/a through 1.9.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30873" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-docs/vulnerability/wordpress-wp-docs-plugin-1-9-8-broken-access-control?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-329j-3w84-m2g4/GHSA-329j-3w84-m2g4.json b/advisories/unreviewed/2024/12/GHSA-329j-3w84-m2g4/GHSA-329j-3w84-m2g4.json new file mode 100644 index 00000000000..58ff08ff41a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-329j-3w84-m2g4/GHSA-329j-3w84-m2g4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-329j-3w84-m2g4", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2023-49856" + ], + "details": "Missing Authorization vulnerability in RedNao Smart Forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Smart Forms: from n/a through 2.6.84.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49856" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/smart-forms/vulnerability/wordpress-smart-forms-plugin-2-6-84-authenticated-arbitrary-options-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-3388-qvp6-f76j/GHSA-3388-qvp6-f76j.json b/advisories/unreviewed/2024/12/GHSA-3388-qvp6-f76j/GHSA-3388-qvp6-f76j.json new file mode 100644 index 00000000000..dd3367b6aeb --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-3388-qvp6-f76j/GHSA-3388-qvp6-f76j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3388-qvp6-f76j", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2024-54228" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebOccult Technologies Pvt Ltd Wot Elementor Widgets allows DOM-Based XSS.This issue affects Wot Elementor Widgets: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54228" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wot-elementor-widgets/vulnerability/wordpress-wot-elementor-widgets-plugin-1-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-33rg-rm58-mc58/GHSA-33rg-rm58-mc58.json b/advisories/unreviewed/2024/12/GHSA-33rg-rm58-mc58/GHSA-33rg-rm58-mc58.json new file mode 100644 index 00000000000..d0d4997ec97 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-33rg-rm58-mc58/GHSA-33rg-rm58-mc58.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-33rg-rm58-mc58", + "modified": "2024-12-09T15:31:35Z", + "published": "2024-12-09T15:31:35Z", + "aliases": [ + "CVE-2023-49167" + ], + "details": "Missing Authorization vulnerability in Code4Life Database for CF7 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Database for CF7: from n/a through 1.2.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49167" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/database-for-cf7/vulnerability/wordpress-database-for-cf7-plugin-1-2-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-35fc-9hrj-3585/GHSA-35fc-9hrj-3585.json b/advisories/unreviewed/2024/12/GHSA-35fc-9hrj-3585/GHSA-35fc-9hrj-3585.json new file mode 100644 index 00000000000..cf2b820113f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-35fc-9hrj-3585/GHSA-35fc-9hrj-3585.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-35fc-9hrj-3585", + "modified": "2024-12-09T15:31:37Z", + "published": "2024-12-09T15:31:37Z", + "aliases": [ + "CVE-2024-53949" + ], + "details": "Improper Authorization vulnerability in Apache Superset when FAB_ADD_SECURITY_API is enabled (disabled by default). Allows for lower privilege users to use this API.\n\n issue affects Apache Superset: from 2.0.0 before 4.1.0.\n\nUsers are recommended to upgrade to version 4.1.0, which fixes the issue.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53949" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/d3scbwmfpzbpm6npnzdw5y4owtqqyq8d" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-35qp-cqfp-xw3g/GHSA-35qp-cqfp-xw3g.json b/advisories/unreviewed/2024/12/GHSA-35qp-cqfp-xw3g/GHSA-35qp-cqfp-xw3g.json new file mode 100644 index 00000000000..7bf23a8b4d4 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-35qp-cqfp-xw3g/GHSA-35qp-cqfp-xw3g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-35qp-cqfp-xw3g", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2023-50899" + ], + "details": "Missing Authorization vulnerability in MultiVendorX Product Catalog Enquiry for WooCommerce by MultiVendorX allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Catalog Enquiry for WooCommerce by MultiVendorX: from n/a through 5.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50899" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woocommerce-catalog-enquiry/vulnerability/wordpress-product-catalog-enquiry-for-woocommerce-by-multivendorx-plugin-5-0-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-37wh-hqrh-8rw4/GHSA-37wh-hqrh-8rw4.json b/advisories/unreviewed/2024/12/GHSA-37wh-hqrh-8rw4/GHSA-37wh-hqrh-8rw4.json new file mode 100644 index 00000000000..98c71c3fde1 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-37wh-hqrh-8rw4/GHSA-37wh-hqrh-8rw4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-37wh-hqrh-8rw4", + "modified": "2024-12-09T15:31:35Z", + "published": "2024-12-09T15:31:35Z", + "aliases": [ + "CVE-2023-48776" + ], + "details": "Missing Authorization vulnerability in Thomas Scholl canvasio3D Light allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects canvasio3D Light: from n/a through 2.5.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48776" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/canvasio3d-light/vulnerability/wordpress-canvasio3d-light-plugin-2-4-6-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-385w-3r67-h9rr/GHSA-385w-3r67-h9rr.json b/advisories/unreviewed/2024/12/GHSA-385w-3r67-h9rr/GHSA-385w-3r67-h9rr.json new file mode 100644 index 00000000000..53a25d3a2ce --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-385w-3r67-h9rr/GHSA-385w-3r67-h9rr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-385w-3r67-h9rr", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-47694" + ], + "details": "Missing Authorization vulnerability in appsbd Mini Cart Drawer For WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mini Cart Drawer For WooCommerce: from n/a through 4.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47694" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woo-mini-cart-drawer/vulnerability/wordpress-mini-cart-drawer-for-woocommerce-plugin-3-3-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-3862-f8g9-4ffc/GHSA-3862-f8g9-4ffc.json b/advisories/unreviewed/2024/12/GHSA-3862-f8g9-4ffc/GHSA-3862-f8g9-4ffc.json new file mode 100644 index 00000000000..930c8dbbe55 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-3862-f8g9-4ffc/GHSA-3862-f8g9-4ffc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3862-f8g9-4ffc", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-30488" + ], + "details": "Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Featured Post Creative allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Featured Post Creative: from n/a through 1.2.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30488" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/featured-post-creative/vulnerability/wordpress-featured-post-creative-plugin-1-2-7-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-38hv-w5wp-prfp/GHSA-38hv-w5wp-prfp.json b/advisories/unreviewed/2024/12/GHSA-38hv-w5wp-prfp/GHSA-38hv-w5wp-prfp.json new file mode 100644 index 00000000000..254a2c69cf7 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-38hv-w5wp-prfp/GHSA-38hv-w5wp-prfp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-38hv-w5wp-prfp", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2023-50884" + ], + "details": "Missing Authorization vulnerability in LA-Studio LA-Studio Element Kit for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50884" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/lastudio-element-kit/vulnerability/wordpress-la-studio-element-kit-for-elementor-plugin-1-1-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-3jgf-q42j-3657/GHSA-3jgf-q42j-3657.json b/advisories/unreviewed/2024/12/GHSA-3jgf-q42j-3657/GHSA-3jgf-q42j-3657.json new file mode 100644 index 00000000000..0a704e6e136 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-3jgf-q42j-3657/GHSA-3jgf-q42j-3657.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3jgf-q42j-3657", + "modified": "2024-12-09T15:31:35Z", + "published": "2024-12-09T15:31:35Z", + "aliases": [ + "CVE-2023-47830" + ], + "details": "Missing Authorization vulnerability in Addons for Contact Form 7 Live Preview for Contact Form 7 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Live Preview for Contact Form 7: from n/a through 1.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47830" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cf7-live-preview/vulnerability/wordpress-live-preview-for-contact-form-7-plugin-1-2-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-3vmr-3jv9-76jr/GHSA-3vmr-3jv9-76jr.json b/advisories/unreviewed/2024/12/GHSA-3vmr-3jv9-76jr/GHSA-3vmr-3jv9-76jr.json new file mode 100644 index 00000000000..0563490f680 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-3vmr-3jv9-76jr/GHSA-3vmr-3jv9-76jr.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3vmr-3jv9-76jr", + "modified": "2024-12-09T15:31:37Z", + "published": "2024-12-09T15:31:37Z", + "aliases": [ + "CVE-2024-54919" + ], + "details": "A Stored Cross Site Scripting (XSS ) was found in /teacher_avatar.php of kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to execute arbitrary java script via the filename parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54919" + }, + { + "type": "WEB", + "url": "https://github.com/m14r41/Writeups/blob/main/CVE/Kashipara/E-learning%20Management%20System%20project/XSS%20by%20File%20Upload%20-%20Update%20Avatar.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T15:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-43f2-7v5v-7h6m/GHSA-43f2-7v5v-7h6m.json b/advisories/unreviewed/2024/12/GHSA-43f2-7v5v-7h6m/GHSA-43f2-7v5v-7h6m.json new file mode 100644 index 00000000000..bdb61382b74 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-43f2-7v5v-7h6m/GHSA-43f2-7v5v-7h6m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-43f2-7v5v-7h6m", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-27626" + ], + "details": "Missing Authorization vulnerability in Aleksandar Urošević Stock Ticker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Stock Ticker: from n/a through 3.23.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27626" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/stock-ticker/vulnerability/wordpress-stock-ticker-plugin-3-23-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-43x3-r3pp-x53v/GHSA-43x3-r3pp-x53v.json b/advisories/unreviewed/2024/12/GHSA-43x3-r3pp-x53v/GHSA-43x3-r3pp-x53v.json new file mode 100644 index 00000000000..86d6448a7ca --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-43x3-r3pp-x53v/GHSA-43x3-r3pp-x53v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-43x3-r3pp-x53v", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-28168" + ], + "details": "Missing Authorization vulnerability in Jerod Santo WordPress Console allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Console: from n/a through 0.3.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28168" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wordpress-console/vulnerability/wordpress-wordpress-console-plugin-0-3-9-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-4fgf-49jq-4vc7/GHSA-4fgf-49jq-4vc7.json b/advisories/unreviewed/2024/12/GHSA-4fgf-49jq-4vc7/GHSA-4fgf-49jq-4vc7.json new file mode 100644 index 00000000000..849fd103753 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-4fgf-49jq-4vc7/GHSA-4fgf-49jq-4vc7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4fgf-49jq-4vc7", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2024-53791" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ogun Labs Lenxel Core for Lenxel(LNX) LMS allows Stored XSS.This issue affects Lenxel Core for Lenxel(LNX) LMS: from n/a through 1.2.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53791" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/lenxel-core/vulnerability/wordpress-lenxel-core-plugin-1-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-4gm3-rmrg-4778/GHSA-4gm3-rmrg-4778.json b/advisories/unreviewed/2024/12/GHSA-4gm3-rmrg-4778/GHSA-4gm3-rmrg-4778.json new file mode 100644 index 00000000000..71b9231cada --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-4gm3-rmrg-4778/GHSA-4gm3-rmrg-4778.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4gm3-rmrg-4778", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2024-53816" + ], + "details": "Missing Authorization vulnerability in Themeum Tutor LMS Elementor Addons.This issue affects Tutor LMS Elementor Addons: from n/a through 2.1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53816" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/tutor-lms-elementor-addons/vulnerability/wordpress-tutor-lms-elementor-addons-plugin-2-1-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-4hpq-5jrv-896m/GHSA-4hpq-5jrv-896m.json b/advisories/unreviewed/2024/12/GHSA-4hpq-5jrv-896m/GHSA-4hpq-5jrv-896m.json new file mode 100644 index 00000000000..3111e2c1830 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-4hpq-5jrv-896m/GHSA-4hpq-5jrv-896m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4hpq-5jrv-896m", + "modified": "2024-12-09T15:31:37Z", + "published": "2024-12-09T15:31:37Z", + "aliases": [ + "CVE-2024-53814" + ], + "details": "Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Analytify.This issue affects Analytify: from n/a through 5.4.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53814" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-analytify/vulnerability/wordpress-analytify-plugin-5-4-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-4pmr-4q2r-c836/GHSA-4pmr-4q2r-c836.json b/advisories/unreviewed/2024/12/GHSA-4pmr-4q2r-c836/GHSA-4pmr-4q2r-c836.json new file mode 100644 index 00000000000..5f4b8bc1046 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-4pmr-4q2r-c836/GHSA-4pmr-4q2r-c836.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4pmr-4q2r-c836", + "modified": "2024-12-09T15:31:33Z", + "published": "2024-12-09T15:31:33Z", + "aliases": [ + "CVE-2023-23886" + ], + "details": "Missing Authorization vulnerability in mg12 WP-RecentComments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP-RecentComments: from n/a through 2.2.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23886" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-recentcomments/vulnerability/wordpress-wp-recentcomments-plugin-2-2-7-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-4pvx-85q5-6cwq/GHSA-4pvx-85q5-6cwq.json b/advisories/unreviewed/2024/12/GHSA-4pvx-85q5-6cwq/GHSA-4pvx-85q5-6cwq.json new file mode 100644 index 00000000000..c32d4fb7eff --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-4pvx-85q5-6cwq/GHSA-4pvx-85q5-6cwq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4pvx-85q5-6cwq", + "modified": "2024-12-09T15:31:37Z", + "published": "2024-12-09T15:31:37Z", + "aliases": [ + "CVE-2024-54232" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rrdevs RRAddons for Elementor allows Stored XSS.This issue affects RRAddons for Elementor: from n/a through 1.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54232" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/rrdevs-for-elementor/vulnerability/wordpress-rraddons-for-elementor-plugin-1-1-0-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-4qgc-h55q-cm8r/GHSA-4qgc-h55q-cm8r.json b/advisories/unreviewed/2024/12/GHSA-4qgc-h55q-cm8r/GHSA-4qgc-h55q-cm8r.json new file mode 100644 index 00000000000..b14df5746bb --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-4qgc-h55q-cm8r/GHSA-4qgc-h55q-cm8r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4qgc-h55q-cm8r", + "modified": "2024-12-09T15:31:35Z", + "published": "2024-12-09T15:31:35Z", + "aliases": [ + "CVE-2023-47869" + ], + "details": "Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in gVectors Team wpForo Forum allows Code Injection.This issue affects wpForo Forum: from n/a through 2.2.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47869" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpforo/vulnerability/wordpress-wpforo-plugin-2-2-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-80" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-4vqg-hq2v-8672/GHSA-4vqg-hq2v-8672.json b/advisories/unreviewed/2024/12/GHSA-4vqg-hq2v-8672/GHSA-4vqg-hq2v-8672.json new file mode 100644 index 00000000000..512e8558a29 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-4vqg-hq2v-8672/GHSA-4vqg-hq2v-8672.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4vqg-hq2v-8672", + "modified": "2024-12-09T15:31:33Z", + "published": "2024-12-09T15:31:33Z", + "aliases": [ + "CVE-2023-23868" + ], + "details": "Missing Authorization vulnerability in WPFactory Cost of Goods for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cost of Goods for WooCommerce: from n/a through 2.8.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23868" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cost-of-goods-for-woocommerce/vulnerability/wordpress-cost-of-goods-for-woocommerce-plugin-2-8-6-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-5525-5wvp-f98h/GHSA-5525-5wvp-f98h.json b/advisories/unreviewed/2024/12/GHSA-5525-5wvp-f98h/GHSA-5525-5wvp-f98h.json new file mode 100644 index 00000000000..4a7e680849b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-5525-5wvp-f98h/GHSA-5525-5wvp-f98h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5525-5wvp-f98h", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-25469" + ], + "details": "Missing Authorization vulnerability in Magazine3 Easy Table of Contents allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Table of Contents: from n/a through 2.0.45.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25469" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/easy-table-of-contents/vulnerability/wordpress-easy-table-of-contents-plugin-2-0-45-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-563r-99qp-c364/GHSA-563r-99qp-c364.json b/advisories/unreviewed/2024/12/GHSA-563r-99qp-c364/GHSA-563r-99qp-c364.json new file mode 100644 index 00000000000..9a51c28105c --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-563r-99qp-c364/GHSA-563r-99qp-c364.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-563r-99qp-c364", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-27625" + ], + "details": "Missing Authorization vulnerability in Paul Ryley Site Reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Site Reviews: from n/a through 6.5.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27625" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/site-reviews/vulnerability/wordpress-site-reviews-plugin-6-5-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-576h-rq5m-cx74/GHSA-576h-rq5m-cx74.json b/advisories/unreviewed/2024/12/GHSA-576h-rq5m-cx74/GHSA-576h-rq5m-cx74.json new file mode 100644 index 00000000000..023f6d1bb4d --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-576h-rq5m-cx74/GHSA-576h-rq5m-cx74.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-576h-rq5m-cx74", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2024-53790" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ogun Labs Lenxel Core for Lenxel(LNX) LMS.This issue affects Lenxel Core for Lenxel(LNX) LMS: from n/a through 1.2.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53790" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/lenxel-core/vulnerability/wordpress-lenxel-core-plugin-1-1-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-58v3-m92j-9vc2/GHSA-58v3-m92j-9vc2.json b/advisories/unreviewed/2024/12/GHSA-58v3-m92j-9vc2/GHSA-58v3-m92j-9vc2.json new file mode 100644 index 00000000000..d52e4b4c2a5 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-58v3-m92j-9vc2/GHSA-58v3-m92j-9vc2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-58v3-m92j-9vc2", + "modified": "2024-12-09T15:31:33Z", + "published": "2024-12-09T15:31:33Z", + "aliases": [ + "CVE-2023-23716" + ], + "details": "Missing Authorization vulnerability in Zendesk Zendesk Support for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zendesk Support for WordPress: from n/a through 1.8.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23716" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/zendesk/vulnerability/wordpress-zendesk-support-for-wordpress-plugin-1-8-4-cross-site-request-forgery-csrf?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-59mm-3634-jcpw/GHSA-59mm-3634-jcpw.json b/advisories/unreviewed/2024/12/GHSA-59mm-3634-jcpw/GHSA-59mm-3634-jcpw.json new file mode 100644 index 00000000000..1a00ca2572f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-59mm-3634-jcpw/GHSA-59mm-3634-jcpw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-59mm-3634-jcpw", + "modified": "2024-12-09T15:31:33Z", + "published": "2024-12-09T15:31:33Z", + "aliases": [ + "CVE-2023-25026" + ], + "details": "Missing Authorization vulnerability in PayPal PayPal Brasil para WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PayPal Brasil para WooCommerce: from n/a through 1.4.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25026" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/paypal-brasil-para-woocommerce/vulnerability/wordpress-paypal-brasil-para-woocommerce-plugin-1-4-2-broken-access-control?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-5cm9-mm2r-2m65/GHSA-5cm9-mm2r-2m65.json b/advisories/unreviewed/2024/12/GHSA-5cm9-mm2r-2m65/GHSA-5cm9-mm2r-2m65.json new file mode 100644 index 00000000000..9821364ff10 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-5cm9-mm2r-2m65/GHSA-5cm9-mm2r-2m65.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5cm9-mm2r-2m65", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-28532" + ], + "details": "Missing Authorization vulnerability in wpdirectorykit.com Real Estate Directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Real Estate Directory: from n/a through 1.0.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28532" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/real-estate-directory/vulnerability/wordpress-real-estate-directory-theme-1-0-5-authenticated-arbitrary-plugin-activation?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-5crx-h3h6-hrh8/GHSA-5crx-h3h6-hrh8.json b/advisories/unreviewed/2024/12/GHSA-5crx-h3h6-hrh8/GHSA-5crx-h3h6-hrh8.json new file mode 100644 index 00000000000..e79860ab8ac --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-5crx-h3h6-hrh8/GHSA-5crx-h3h6-hrh8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5crx-h3h6-hrh8", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-28689" + ], + "details": "Missing Authorization vulnerability in JoomSky JS Job Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Job Manager: from n/a through 2.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28689" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/js-jobs/vulnerability/wordpress-js-job-manager-plugin-2-0-0-broken-access-control?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-5p2q-r363-h3r3/GHSA-5p2q-r363-h3r3.json b/advisories/unreviewed/2024/12/GHSA-5p2q-r363-h3r3/GHSA-5p2q-r363-h3r3.json new file mode 100644 index 00000000000..47316216fde --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-5p2q-r363-h3r3/GHSA-5p2q-r363-h3r3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5p2q-r363-h3r3", + "modified": "2024-12-09T15:31:35Z", + "published": "2024-12-09T15:31:35Z", + "aliases": [ + "CVE-2023-49192" + ], + "details": "Missing Authorization vulnerability in Clever Widgets Enhanced Text Widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Enhanced Text Widget: from n/a through 1.6.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49192" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/enhanced-text-widget/vulnerability/wordpress-enhanced-text-widget-plugin-1-6-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-5vg4-fmh3-6xh3/GHSA-5vg4-fmh3-6xh3.json b/advisories/unreviewed/2024/12/GHSA-5vg4-fmh3-6xh3/GHSA-5vg4-fmh3-6xh3.json new file mode 100644 index 00000000000..5d361a7c139 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-5vg4-fmh3-6xh3/GHSA-5vg4-fmh3-6xh3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5vg4-fmh3-6xh3", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2024-54224" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuomodoSoft ElementsReady Addons for Elementor allows DOM-Based XSS.This issue affects ElementsReady Addons for Elementor: from n/a through 6.4.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54224" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/element-ready-lite/vulnerability/wordpress-elementsready-addons-for-elementor-plugin-6-4-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-63v2-5jqx-j9v7/GHSA-63v2-5jqx-j9v7.json b/advisories/unreviewed/2024/12/GHSA-63v2-5jqx-j9v7/GHSA-63v2-5jqx-j9v7.json new file mode 100644 index 00000000000..451594ce6d1 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-63v2-5jqx-j9v7/GHSA-63v2-5jqx-j9v7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-63v2-5jqx-j9v7", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2023-51360" + ], + "details": "Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential Blocks for Gutenberg: from n/a through 4.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51360" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/essential-blocks/vulnerability/wordpress-essential-blocks-plugin-4-2-0-multiple-subscriber-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-63v3-mvp3-3r8v/GHSA-63v3-mvp3-3r8v.json b/advisories/unreviewed/2024/12/GHSA-63v3-mvp3-3r8v/GHSA-63v3-mvp3-3r8v.json new file mode 100644 index 00000000000..f6107ea8b78 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-63v3-mvp3-3r8v/GHSA-63v3-mvp3-3r8v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-63v3-mvp3-3r8v", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-31214" + ], + "details": "Missing Authorization vulnerability in Arul Prasad J WP Quick Post Duplicator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Quick Post Duplicator: from n/a through 2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31214" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-quick-post-duplicator/vulnerability/wordpress-wp-quick-post-duplicator-plugin-1-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-6f3q-67gr-5v5r/GHSA-6f3q-67gr-5v5r.json b/advisories/unreviewed/2024/12/GHSA-6f3q-67gr-5v5r/GHSA-6f3q-67gr-5v5r.json new file mode 100644 index 00000000000..a57955589ac --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-6f3q-67gr-5v5r/GHSA-6f3q-67gr-5v5r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6f3q-67gr-5v5r", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-31073" + ], + "details": "Missing Authorization vulnerability in Jose Vega Display custom fields in the frontend – Post and User Profile Fields allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Display custom fields in the frontend – Post and User Profile Fields: from n/a through 1.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31073" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/shortcode-to-display-post-and-user-data/vulnerability/wordpress-shortcode-to-display-post-and-user-data-plugin-1-2-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-6gx2-v462-gr3m/GHSA-6gx2-v462-gr3m.json b/advisories/unreviewed/2024/12/GHSA-6gx2-v462-gr3m/GHSA-6gx2-v462-gr3m.json new file mode 100644 index 00000000000..e2f7e027812 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-6gx2-v462-gr3m/GHSA-6gx2-v462-gr3m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6gx2-v462-gr3m", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2023-49848" + ], + "details": "Missing Authorization vulnerability in wooproductimporter Sharkdropship dropshipping for Aliexpress, eBay, Amazon, etsy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sharkdropship dropshipping for Aliexpress, eBay, Amazon, etsy: from n/a through 2.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49848" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woo-aliexpress-dropshipping/vulnerability/wordpress-sharkdropship-dropshipping-for-aliexpress-ebay-amazon-etsy-plugin-2-1-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-6mcv-9288-fjqm/GHSA-6mcv-9288-fjqm.json b/advisories/unreviewed/2024/12/GHSA-6mcv-9288-fjqm/GHSA-6mcv-9288-fjqm.json new file mode 100644 index 00000000000..6f480b20389 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-6mcv-9288-fjqm/GHSA-6mcv-9288-fjqm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6mcv-9288-fjqm", + "modified": "2024-12-09T15:31:35Z", + "published": "2024-12-09T15:31:35Z", + "aliases": [ + "CVE-2023-47761" + ], + "details": "Missing Authorization vulnerability in WPDeveloper Simple 301 Redirects by BetterLinks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple 301 Redirects by BetterLinks: from n/a through 2.0.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47761" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/simple-301-redirects/vulnerability/wordpress-simple-301-redirects-by-betterlinks-plugin-2-0-7-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-6x3h-jq42-qq24/GHSA-6x3h-jq42-qq24.json b/advisories/unreviewed/2024/12/GHSA-6x3h-jq42-qq24/GHSA-6x3h-jq42-qq24.json new file mode 100644 index 00000000000..e24d12f8206 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-6x3h-jq42-qq24/GHSA-6x3h-jq42-qq24.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6x3h-jq42-qq24", + "modified": "2024-12-09T15:31:37Z", + "published": "2024-12-09T15:31:37Z", + "aliases": [ + "CVE-2024-52480" + ], + "details": "Missing Authorization vulnerability in Astoundify Jobify - Job Board WordPress Theme.This issue affects Jobify - Job Board WordPress Theme: from n/a through 4.2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52480" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/jobify/vulnerability/wordpress-jobify-plugin-4-2-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-72cj-44mg-7gv5/GHSA-72cj-44mg-7gv5.json b/advisories/unreviewed/2024/12/GHSA-72cj-44mg-7gv5/GHSA-72cj-44mg-7gv5.json new file mode 100644 index 00000000000..74fea0e3382 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-72cj-44mg-7gv5/GHSA-72cj-44mg-7gv5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-72cj-44mg-7gv5", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-25714" + ], + "details": "Missing Authorization vulnerability in Fullworks Quick Paypal Payments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quick Paypal Payments: from n/a through 5.7.25.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25714" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/quick-paypal-payments/vulnerability/wordpress-quick-paypal-payments-plugin-5-7-25-broken-access-control?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-72qv-3p6q-gfc7/GHSA-72qv-3p6q-gfc7.json b/advisories/unreviewed/2024/12/GHSA-72qv-3p6q-gfc7/GHSA-72qv-3p6q-gfc7.json new file mode 100644 index 00000000000..47cbf7ed7e3 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-72qv-3p6q-gfc7/GHSA-72qv-3p6q-gfc7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-72qv-3p6q-gfc7", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-29239" + ], + "details": "Missing Authorization vulnerability in LuckyWP LuckyWP Scripts Control allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LuckyWP Scripts Control: from n/a through 1.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29239" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/luckywp-scripts-control/vulnerability/wordpress-luckywp-scripts-control-plugin-1-2-1-broken-access-control-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-73xg-5c69-2755/GHSA-73xg-5c69-2755.json b/advisories/unreviewed/2024/12/GHSA-73xg-5c69-2755/GHSA-73xg-5c69-2755.json index d1addaeaa12..e26de868cf5 100644 --- a/advisories/unreviewed/2024/12/GHSA-73xg-5c69-2755/GHSA-73xg-5c69-2755.json +++ b/advisories/unreviewed/2024/12/GHSA-73xg-5c69-2755/GHSA-73xg-5c69-2755.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-73xg-5c69-2755", - "modified": "2024-12-06T12:30:47Z", + "modified": "2024-12-09T15:31:33Z", "published": "2024-12-06T12:30:47Z", "aliases": [ "CVE-2024-53142" @@ -14,6 +14,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53142" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1a423bbbeaf9e3e20c4686501efd9b661fe834db" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/49d01e736c3045319e030d1e75fb983011abaca7" diff --git a/advisories/unreviewed/2024/12/GHSA-75hg-8v8m-22xg/GHSA-75hg-8v8m-22xg.json b/advisories/unreviewed/2024/12/GHSA-75hg-8v8m-22xg/GHSA-75hg-8v8m-22xg.json new file mode 100644 index 00000000000..1975c055076 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-75hg-8v8m-22xg/GHSA-75hg-8v8m-22xg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-75hg-8v8m-22xg", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-30783" + ], + "details": "Missing Authorization vulnerability in YummyWP Smart WooCommerce Search allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Smart WooCommerce Search: from n/a through 2.5.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30783" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/smart-woocommerce-search/vulnerability/wordpress-smart-woocommerce-search-plugin-2-5-0-broken-access-control?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-7635-6274-7qjr/GHSA-7635-6274-7qjr.json b/advisories/unreviewed/2024/12/GHSA-7635-6274-7qjr/GHSA-7635-6274-7qjr.json new file mode 100644 index 00000000000..a717f62c872 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-7635-6274-7qjr/GHSA-7635-6274-7qjr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7635-6274-7qjr", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2023-50373" + ], + "details": "Missing Authorization vulnerability in WPSAAD Alt Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Alt Manager: from n/a through 1.6.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50373" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/alt-manager/vulnerability/wordpress-alt-manager-plugin-1-5-9-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-7cw8-5w9g-qq8w/GHSA-7cw8-5w9g-qq8w.json b/advisories/unreviewed/2024/12/GHSA-7cw8-5w9g-qq8w/GHSA-7cw8-5w9g-qq8w.json new file mode 100644 index 00000000000..485a6b936a8 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-7cw8-5w9g-qq8w/GHSA-7cw8-5w9g-qq8w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7cw8-5w9g-qq8w", + "modified": "2024-12-09T15:31:37Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2024-54215" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Envato Security Team Revy.This issue affects Revy: from n/a through 1.18.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54215" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/revy/vulnerability/wordpress-revy-plugin-1-18-unauthenticated-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-7p4r-h9v5-5p45/GHSA-7p4r-h9v5-5p45.json b/advisories/unreviewed/2024/12/GHSA-7p4r-h9v5-5p45/GHSA-7p4r-h9v5-5p45.json new file mode 100644 index 00000000000..26c3ca3cee3 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-7p4r-h9v5-5p45/GHSA-7p4r-h9v5-5p45.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7p4r-h9v5-5p45", + "modified": "2024-12-09T15:31:35Z", + "published": "2024-12-09T15:31:35Z", + "aliases": [ + "CVE-2023-47838" + ], + "details": "Missing Authorization vulnerability in Jules Colle Conditional Fields for Contact Form 7 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Conditional Fields for Contact Form 7: from n/a through 2.4.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47838" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cf7-conditional-fields/vulnerability/wordpress-conditional-fields-for-contact-form-7-plugin-2-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-7r2c-x2h3-wr96/GHSA-7r2c-x2h3-wr96.json b/advisories/unreviewed/2024/12/GHSA-7r2c-x2h3-wr96/GHSA-7r2c-x2h3-wr96.json new file mode 100644 index 00000000000..3c5a65091d2 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-7r2c-x2h3-wr96/GHSA-7r2c-x2h3-wr96.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7r2c-x2h3-wr96", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-28536" + ], + "details": "Missing Authorization vulnerability in Acato Branded Social Images allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Branded Social Images: from n/a through 1.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28536" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/branded-social-images/vulnerability/wordpress-branded-social-images-plugin-1-1-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-7v28-88f9-8882/GHSA-7v28-88f9-8882.json b/advisories/unreviewed/2024/12/GHSA-7v28-88f9-8882/GHSA-7v28-88f9-8882.json new file mode 100644 index 00000000000..a59ee9b8828 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-7v28-88f9-8882/GHSA-7v28-88f9-8882.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7v28-88f9-8882", + "modified": "2024-12-09T15:31:35Z", + "published": "2024-12-09T15:31:35Z", + "aliases": [ + "CVE-2023-49194" + ], + "details": "Insertion of Sensitive Information Into Debugging Code vulnerability in Importify Importify (Dropshipping WooCommerce) allows Retrieve Embedded Sensitive Data.This issue affects Importify (Dropshipping WooCommerce): from n/a through 1.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49194" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/importify/vulnerability/wordpress-importify-dropshipping-woocommerce-plugin-1-0-4-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-215" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-84h3-h84r-7g7v/GHSA-84h3-h84r-7g7v.json b/advisories/unreviewed/2024/12/GHSA-84h3-h84r-7g7v/GHSA-84h3-h84r-7g7v.json new file mode 100644 index 00000000000..37a8933722b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-84h3-h84r-7g7v/GHSA-84h3-h84r-7g7v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-84h3-h84r-7g7v", + "modified": "2024-12-09T15:31:35Z", + "published": "2024-12-09T15:31:35Z", + "aliases": [ + "CVE-2023-47756" + ], + "details": "Missing Authorization vulnerability in David Vongries Welcome Email Editor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Welcome Email Editor: from n/a through 5.0.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47756" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/welcome-email-editor/vulnerability/wordpress-welcome-email-editor-plugin-5-0-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-85rv-m554-fjhh/GHSA-85rv-m554-fjhh.json b/advisories/unreviewed/2024/12/GHSA-85rv-m554-fjhh/GHSA-85rv-m554-fjhh.json new file mode 100644 index 00000000000..29ee503ce80 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-85rv-m554-fjhh/GHSA-85rv-m554-fjhh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-85rv-m554-fjhh", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-29237" + ], + "details": "Missing Authorization vulnerability in Muhammad Rehman Remove Duplicate Posts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Remove Duplicate Posts: from n/a through 1.3.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29237" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/remove-duplicate-posts/vulnerability/wordpress-remove-duplicate-posts-plugin-1-3-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8jc6-xgrg-9fp3/GHSA-8jc6-xgrg-9fp3.json b/advisories/unreviewed/2024/12/GHSA-8jc6-xgrg-9fp3/GHSA-8jc6-xgrg-9fp3.json new file mode 100644 index 00000000000..e4af1b03387 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8jc6-xgrg-9fp3/GHSA-8jc6-xgrg-9fp3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8jc6-xgrg-9fp3", + "modified": "2024-12-09T15:31:33Z", + "published": "2024-12-09T15:31:33Z", + "aliases": [ + "CVE-2023-23986" + ], + "details": "Missing Authorization vulnerability in Noah Hearle, Design Extreme Reviews and Rating – Google My Business allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Reviews and Rating – Google My Business: from n/a through 4.14.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23986" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/g-business-reviews-rating/vulnerability/wordpress-reviews-and-rating-google-my-business-plugin-4-14-broken-access-control?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8jfh-2hq3-wq5v/GHSA-8jfh-2hq3-wq5v.json b/advisories/unreviewed/2024/12/GHSA-8jfh-2hq3-wq5v/GHSA-8jfh-2hq3-wq5v.json new file mode 100644 index 00000000000..9b2895ec438 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8jfh-2hq3-wq5v/GHSA-8jfh-2hq3-wq5v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8jfh-2hq3-wq5v", + "modified": "2024-12-09T15:31:37Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2024-54225" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodegearThemes Designer allows PHP Local File Inclusion.This issue affects Designer: from n/a through 1.3.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54225" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/designer/vulnerability/wordpress-designer-plugin-1-3-3-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8qq7-8jcq-724w/GHSA-8qq7-8jcq-724w.json b/advisories/unreviewed/2024/12/GHSA-8qq7-8jcq-724w/GHSA-8qq7-8jcq-724w.json new file mode 100644 index 00000000000..019df75d228 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8qq7-8jcq-724w/GHSA-8qq7-8jcq-724w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8qq7-8jcq-724w", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-27454" + ], + "details": "Missing Authorization vulnerability in Apollo13Themes Rife Elementor Extensions & Templates allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rife Elementor Extensions & Templates: from n/a through 1.1.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27454" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/rife-elementor-extensions/vulnerability/wordpress-rife-elementor-extensions-templates-plugin-1-1-10-broken-access-control?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8rr9-98f9-jfm4/GHSA-8rr9-98f9-jfm4.json b/advisories/unreviewed/2024/12/GHSA-8rr9-98f9-jfm4/GHSA-8rr9-98f9-jfm4.json new file mode 100644 index 00000000000..5afd377f832 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8rr9-98f9-jfm4/GHSA-8rr9-98f9-jfm4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8rr9-98f9-jfm4", + "modified": "2024-12-09T15:31:33Z", + "published": "2024-12-09T15:31:33Z", + "aliases": [ + "CVE-2023-24375" + ], + "details": "Missing Authorization vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn): from n/a through 7.5.14.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24375" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/miniorange-login-openid/vulnerability/wordpress-wordpress-social-login-and-register-discord-google-twitter-linkedin-plugin-7-5-14-broken-access-control?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8wv9-79mg-hgfg/GHSA-8wv9-79mg-hgfg.json b/advisories/unreviewed/2024/12/GHSA-8wv9-79mg-hgfg/GHSA-8wv9-79mg-hgfg.json new file mode 100644 index 00000000000..4f89f066b1b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8wv9-79mg-hgfg/GHSA-8wv9-79mg-hgfg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8wv9-79mg-hgfg", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-25966" + ], + "details": "Missing Authorization vulnerability in Ninja Team Filebird allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Filebird: from n/a through 5.1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25966" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/filebird/vulnerability/wordpress-filebird-plugin-5-1-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-92cp-8wwq-gm56/GHSA-92cp-8wwq-gm56.json b/advisories/unreviewed/2024/12/GHSA-92cp-8wwq-gm56/GHSA-92cp-8wwq-gm56.json new file mode 100644 index 00000000000..537010e28cd --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-92cp-8wwq-gm56/GHSA-92cp-8wwq-gm56.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-92cp-8wwq-gm56", + "modified": "2024-12-09T15:31:37Z", + "published": "2024-12-09T15:31:37Z", + "aliases": [ + "CVE-2024-54255" + ], + "details": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in aviplugins.com Login Widget With Shortcode allows Phishing.This issue affects Login Widget With Shortcode: from n/a through 6.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54255" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/login-sidebar-widget/vulnerability/wordpress-login-widget-with-shortcode-plugin-6-1-2-open-redirection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-92gq-43f3-q488/GHSA-92gq-43f3-q488.json b/advisories/unreviewed/2024/12/GHSA-92gq-43f3-q488/GHSA-92gq-43f3-q488.json new file mode 100644 index 00000000000..daa9eb7dae8 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-92gq-43f3-q488/GHSA-92gq-43f3-q488.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-92gq-43f3-q488", + "modified": "2024-12-09T15:31:37Z", + "published": "2024-12-09T15:31:37Z", + "aliases": [ + "CVE-2024-49600" + ], + "details": "Dell Power Manager (DPM), versions prior to 3.17, contain an improper access control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution and Elevation of Privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49600" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000244438/dsa-2024-439" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-92qf-8gh3-gwcm/GHSA-92qf-8gh3-gwcm.json b/advisories/unreviewed/2024/12/GHSA-92qf-8gh3-gwcm/GHSA-92qf-8gh3-gwcm.json new file mode 100644 index 00000000000..9972735352c --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-92qf-8gh3-gwcm/GHSA-92qf-8gh3-gwcm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-92qf-8gh3-gwcm", + "modified": "2024-12-09T15:31:37Z", + "published": "2024-12-09T15:31:37Z", + "aliases": [ + "CVE-2024-53947" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Superset. Specifically, certain engine-specific functions are not checked, which allows attackers to bypass Apache Superset's SQL authorization. This issue is a follow-up to CVE-2024-39887 with additional disallowed PostgreSQL functions now included: query_to_xml_and_xmlschema, table_to_xml, table_to_xml_and_xmlschema.\n\nThis issue affects Apache Superset: <4.1.0.\n\nUsers are recommended to upgrade to version 4.1.0, which fixes the issue or add these Postgres functions to the config set DISALLOWED_SQL_FUNCTIONS.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53947" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/hj3gfsjh67vqw12nlrshlsym4bkopjmn" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-945m-723r-jmgg/GHSA-945m-723r-jmgg.json b/advisories/unreviewed/2024/12/GHSA-945m-723r-jmgg/GHSA-945m-723r-jmgg.json new file mode 100644 index 00000000000..9ab6ad7e704 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-945m-723r-jmgg/GHSA-945m-723r-jmgg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-945m-723r-jmgg", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-25060" + ], + "details": "Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Album and Image Gallery plus Lightbox allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Album and Image Gallery plus Lightbox: from n/a through 1.6.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25060" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/album-and-image-gallery-plus-lightbox/vulnerability/wordpress-album-and-image-gallery-plus-lightbox-plugin-1-6-2-broken-access-control?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-9567-2gw8-p4p5/GHSA-9567-2gw8-p4p5.json b/advisories/unreviewed/2024/12/GHSA-9567-2gw8-p4p5/GHSA-9567-2gw8-p4p5.json index e8a529196fc..bc450bc7326 100644 --- a/advisories/unreviewed/2024/12/GHSA-9567-2gw8-p4p5/GHSA-9567-2gw8-p4p5.json +++ b/advisories/unreviewed/2024/12/GHSA-9567-2gw8-p4p5/GHSA-9567-2gw8-p4p5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9567-2gw8-p4p5", - "modified": "2024-12-06T12:30:47Z", + "modified": "2024-12-09T15:31:33Z", "published": "2024-12-06T12:30:47Z", "aliases": [ "CVE-2024-53141" @@ -29,6 +29,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/591efa494a1cf649f50a35def649c43ae984cd03" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/856023ef032d824309abd5c747241dffa33aae8c" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/12/GHSA-9hfr-xch8-m267/GHSA-9hfr-xch8-m267.json b/advisories/unreviewed/2024/12/GHSA-9hfr-xch8-m267/GHSA-9hfr-xch8-m267.json new file mode 100644 index 00000000000..5db43f3cb7b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-9hfr-xch8-m267/GHSA-9hfr-xch8-m267.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9hfr-xch8-m267", + "modified": "2024-12-09T15:31:35Z", + "published": "2024-12-09T15:31:35Z", + "aliases": [ + "CVE-2023-47849" + ], + "details": "Missing Authorization vulnerability in blossomthemes BlossomThemes Email Newsletter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BlossomThemes Email Newsletter: from n/a through 2.2.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47849" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/blossomthemes-email-newsletter/vulnerability/wordpress-blossomthemes-email-newsletter-plugin-2-2-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-9j38-gh4r-29cw/GHSA-9j38-gh4r-29cw.json b/advisories/unreviewed/2024/12/GHSA-9j38-gh4r-29cw/GHSA-9j38-gh4r-29cw.json new file mode 100644 index 00000000000..c5e0c591479 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-9j38-gh4r-29cw/GHSA-9j38-gh4r-29cw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9j38-gh4r-29cw", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2023-51353" + ], + "details": "Missing Authorization vulnerability in supsystic.com Popup by Supsystic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup by Supsystic: from n/a through 1.10.19.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51353" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/popup-by-supsystic/vulnerability/wordpress-popup-by-supsystic-plugin-1-10-19-broken-access-control-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-9vq9-cp9w-6mxv/GHSA-9vq9-cp9w-6mxv.json b/advisories/unreviewed/2024/12/GHSA-9vq9-cp9w-6mxv/GHSA-9vq9-cp9w-6mxv.json new file mode 100644 index 00000000000..b367d30ac7f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-9vq9-cp9w-6mxv/GHSA-9vq9-cp9w-6mxv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9vq9-cp9w-6mxv", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-27428" + ], + "details": "Missing Authorization vulnerability in Damir Calusic WP users media allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP users media: from n/a through 4.2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27428" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-users-media/vulnerability/wordpress-wp-users-media-plugin-4-2-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-9w22-fmp9-f4j7/GHSA-9w22-fmp9-f4j7.json b/advisories/unreviewed/2024/12/GHSA-9w22-fmp9-f4j7/GHSA-9w22-fmp9-f4j7.json new file mode 100644 index 00000000000..53ac41b47d4 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-9w22-fmp9-f4j7/GHSA-9w22-fmp9-f4j7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9w22-fmp9-f4j7", + "modified": "2024-12-09T15:31:35Z", + "published": "2024-12-09T15:31:35Z", + "aliases": [ + "CVE-2023-49156" + ], + "details": "Missing Authorization vulnerability in GoDaddy GoDaddy Email Marketing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GoDaddy Email Marketing: from n/a through 1.4.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49156" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/godaddy-email-marketing-sign-up-forms/vulnerability/wordpress-godaddy-email-marketing-plugin-1-4-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-9wjp-m7pw-vf4c/GHSA-9wjp-m7pw-vf4c.json b/advisories/unreviewed/2024/12/GHSA-9wjp-m7pw-vf4c/GHSA-9wjp-m7pw-vf4c.json new file mode 100644 index 00000000000..ba35cfdec1d --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-9wjp-m7pw-vf4c/GHSA-9wjp-m7pw-vf4c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9wjp-m7pw-vf4c", + "modified": "2024-12-09T15:31:37Z", + "published": "2024-12-09T15:31:37Z", + "aliases": [ + "CVE-2024-54251" + ], + "details": "Missing Authorization vulnerability in Prodigy Commerce Prodigy Commerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Prodigy Commerce: from n/a through 3.0.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54251" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/prodigy-commerce/vulnerability/wordpress-prodigy-commerce-plugin-3-0-7-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-9x39-vc5c-rcvv/GHSA-9x39-vc5c-rcvv.json b/advisories/unreviewed/2024/12/GHSA-9x39-vc5c-rcvv/GHSA-9x39-vc5c-rcvv.json new file mode 100644 index 00000000000..6c15d18490c --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-9x39-vc5c-rcvv/GHSA-9x39-vc5c-rcvv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9x39-vc5c-rcvv", + "modified": "2024-12-09T15:31:35Z", + "published": "2024-12-09T15:31:35Z", + "aliases": [ + "CVE-2023-48277" + ], + "details": "Missing Authorization vulnerability in SuperPWA Super Progressive Web Apps allows Exploiting Incorrectly Configured Access Control Security Levels.\n\nThis issue affects Super Progressive Web Apps: from n/a through 2.2.21.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48277" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/super-progressive-web-apps/vulnerability/wordpress-super-progressive-web-apps-plugin-2-2-21-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-9xp6-xqfq-5258/GHSA-9xp6-xqfq-5258.json b/advisories/unreviewed/2024/12/GHSA-9xp6-xqfq-5258/GHSA-9xp6-xqfq-5258.json new file mode 100644 index 00000000000..a32c8605708 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-9xp6-xqfq-5258/GHSA-9xp6-xqfq-5258.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9xp6-xqfq-5258", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2023-51357" + ], + "details": "Missing Authorization vulnerability in Conversios Conversios.io allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Conversios.io: from n/a through 6.5.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51357" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/enhanced-e-commerce-for-woocommerce-store/vulnerability/wordpress-track-google-analytics-4-facebook-pixel-conversions-api-via-google-tag-manager-for-woocommerce-plugin-6-5-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-c6mp-vwvj-g8hr/GHSA-c6mp-vwvj-g8hr.json b/advisories/unreviewed/2024/12/GHSA-c6mp-vwvj-g8hr/GHSA-c6mp-vwvj-g8hr.json new file mode 100644 index 00000000000..580c327553e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-c6mp-vwvj-g8hr/GHSA-c6mp-vwvj-g8hr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c6mp-vwvj-g8hr", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2023-50876" + ], + "details": "Missing Authorization vulnerability in Molongui Molongui allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Molongui: from n/a through 4.7.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50876" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/molongui-authorship/vulnerability/wordpress-molongui-plugin-4-7-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-c876-w45q-72x4/GHSA-c876-w45q-72x4.json b/advisories/unreviewed/2024/12/GHSA-c876-w45q-72x4/GHSA-c876-w45q-72x4.json new file mode 100644 index 00000000000..e755c489056 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-c876-w45q-72x4/GHSA-c876-w45q-72x4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c876-w45q-72x4", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2024-53798" + ], + "details": "Missing Authorization vulnerability in BAKKBONE Australia FloristPress.This issue affects FloristPress: from n/a through 7.3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53798" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bakkbone-florist-companion/vulnerability/wordpress-floristpress-plugin-7-3-0-nonce-leakage-to-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-cfp8-crh7-p68w/GHSA-cfp8-crh7-p68w.json b/advisories/unreviewed/2024/12/GHSA-cfp8-crh7-p68w/GHSA-cfp8-crh7-p68w.json new file mode 100644 index 00000000000..e8d5cfe159b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-cfp8-crh7-p68w/GHSA-cfp8-crh7-p68w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cfp8-crh7-p68w", + "modified": "2024-12-09T15:31:35Z", + "published": "2024-12-09T15:31:35Z", + "aliases": [ + "CVE-2023-47793" + ], + "details": "Missing Authorization vulnerability in acmethemes Acme Fix Images allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Acme Fix Images: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47793" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/acme-fix-images/vulnerability/wordpress-acme-fix-images-plugin-1-0-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-cg38-qgv8-xggm/GHSA-cg38-qgv8-xggm.json b/advisories/unreviewed/2024/12/GHSA-cg38-qgv8-xggm/GHSA-cg38-qgv8-xggm.json new file mode 100644 index 00000000000..b4e2cb5a103 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-cg38-qgv8-xggm/GHSA-cg38-qgv8-xggm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cg38-qgv8-xggm", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2023-49849" + ], + "details": "Missing Authorization vulnerability in Aakash Chakravarthy Shortcoder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Shortcoder: from n/a through 6.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49849" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/shortcoder/vulnerability/wordpress-shortcoder-plugin-6-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-cg7m-6ffc-q2vq/GHSA-cg7m-6ffc-q2vq.json b/advisories/unreviewed/2024/12/GHSA-cg7m-6ffc-q2vq/GHSA-cg7m-6ffc-q2vq.json new file mode 100644 index 00000000000..459df9b7470 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-cg7m-6ffc-q2vq/GHSA-cg7m-6ffc-q2vq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cg7m-6ffc-q2vq", + "modified": "2024-12-09T15:31:35Z", + "published": "2024-12-09T15:31:35Z", + "aliases": [ + "CVE-2023-48750" + ], + "details": "Missing Authorization vulnerability in VOID CODERS Void Elementor Post Grid Addon for Elementor Page builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Void Elementor Post Grid Addon for Elementor Page builder: from n/a through 2.1.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48750" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/void-elementor-post-grid-addon-for-elementor-page-builder/vulnerability/wordpress-void-elementor-post-grid-addon-for-elementor-page-builder-plugin-2-1-10-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-cgwx-876g-49h6/GHSA-cgwx-876g-49h6.json b/advisories/unreviewed/2024/12/GHSA-cgwx-876g-49h6/GHSA-cgwx-876g-49h6.json new file mode 100644 index 00000000000..a890fccd995 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-cgwx-876g-49h6/GHSA-cgwx-876g-49h6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cgwx-876g-49h6", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-32126" + ], + "details": "Missing Authorization vulnerability in WPoperation SALERT allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SALERT: from n/a through 1.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32126" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/salert/vulnerability/wordpress-salert-plugin-1-2-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-chqw-mw32-x7wh/GHSA-chqw-mw32-x7wh.json b/advisories/unreviewed/2024/12/GHSA-chqw-mw32-x7wh/GHSA-chqw-mw32-x7wh.json new file mode 100644 index 00000000000..56fe3f036b5 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-chqw-mw32-x7wh/GHSA-chqw-mw32-x7wh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-chqw-mw32-x7wh", + "modified": "2024-12-09T15:31:37Z", + "published": "2024-12-09T15:31:37Z", + "aliases": [ + "CVE-2024-54218" + ], + "details": "Missing Authorization vulnerability in Thehp AIO Contact.This issue affects AIO Contact: from n/a through 2.8.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54218" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/aio-contact/vulnerability/wordpress-aio-contact-plugin-2-8-1-unauthenticated-plugin-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-cmc6-jgxj-h4r2/GHSA-cmc6-jgxj-h4r2.json b/advisories/unreviewed/2024/12/GHSA-cmc6-jgxj-h4r2/GHSA-cmc6-jgxj-h4r2.json new file mode 100644 index 00000000000..239d5e34026 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-cmc6-jgxj-h4r2/GHSA-cmc6-jgxj-h4r2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cmc6-jgxj-h4r2", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2023-49832" + ], + "details": "Missing Authorization vulnerability in Paul Ryley Site Reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Site Reviews: from n/a through 6.10.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49832" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/site-reviews/vulnerability/wordpress-site-reviews-plugin-6-10-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-cq2v-v3g2-pcmr/GHSA-cq2v-v3g2-pcmr.json b/advisories/unreviewed/2024/12/GHSA-cq2v-v3g2-pcmr/GHSA-cq2v-v3g2-pcmr.json new file mode 100644 index 00000000000..9ec99899f35 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-cq2v-v3g2-pcmr/GHSA-cq2v-v3g2-pcmr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cq2v-v3g2-pcmr", + "modified": "2024-12-09T15:31:35Z", + "published": "2024-12-09T15:31:35Z", + "aliases": [ + "CVE-2023-47847" + ], + "details": "Missing Authorization vulnerability in PayTR Ödeme ve Elektronik Para Kuruluşu A.Ş. PayTR Taksit Tablosu allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PayTR Taksit Tablosu: from n/a through 1.3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47847" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/paytr-taksit-tablosu-woocommerce/vulnerability/wordpress-paytr-taksit-tablosu-plugin-1-3-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-cr97-j27x-353p/GHSA-cr97-j27x-353p.json b/advisories/unreviewed/2024/12/GHSA-cr97-j27x-353p/GHSA-cr97-j27x-353p.json new file mode 100644 index 00000000000..1739997b155 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-cr97-j27x-353p/GHSA-cr97-j27x-353p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cr97-j27x-353p", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2024-53785" + ], + "details": "Missing Authorization vulnerability in Alexander Volkov Chatter.This issue affects Chatter: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53785" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/chatter/vulnerability/wordpress-chatter-plugin-1-0-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-crfq-94qw-vfrw/GHSA-crfq-94qw-vfrw.json b/advisories/unreviewed/2024/12/GHSA-crfq-94qw-vfrw/GHSA-crfq-94qw-vfrw.json new file mode 100644 index 00000000000..05f604ab5fc --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-crfq-94qw-vfrw/GHSA-crfq-94qw-vfrw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-crfq-94qw-vfrw", + "modified": "2024-12-09T15:31:33Z", + "published": "2024-12-09T15:31:33Z", + "aliases": [ + "CVE-2023-23715" + ], + "details": "Missing Authorization vulnerability in JobBoardWP JobBoardWP – Job Board Listings and Submissions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JobBoardWP – Job Board Listings and Submissions: from n/a through 1.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23715" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/jobboardwp/vulnerability/wordpress-jobboardwp-job-board-listings-and-submissions-plugin-1-2-2-idor-leading-to-job-removal-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-cx6f-c84v-72h8/GHSA-cx6f-c84v-72h8.json b/advisories/unreviewed/2024/12/GHSA-cx6f-c84v-72h8/GHSA-cx6f-c84v-72h8.json new file mode 100644 index 00000000000..afc64addcd5 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-cx6f-c84v-72h8/GHSA-cx6f-c84v-72h8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cx6f-c84v-72h8", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2024-43222" + ], + "details": "Missing Authorization vulnerability in Envato Security Team Sweet Date.This issue affects Sweet Date: from n/a through 3.7.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43222" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/sweetdate/vulnerability/wordpress-sweet-date-more-than-a-wordpress-dating-theme-theme-3-7-3-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-f42h-pj3v-gmw8/GHSA-f42h-pj3v-gmw8.json b/advisories/unreviewed/2024/12/GHSA-f42h-pj3v-gmw8/GHSA-f42h-pj3v-gmw8.json new file mode 100644 index 00000000000..bfdc7fd9fb4 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-f42h-pj3v-gmw8/GHSA-f42h-pj3v-gmw8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f42h-pj3v-gmw8", + "modified": "2024-12-09T15:31:37Z", + "published": "2024-12-09T15:31:37Z", + "aliases": [ + "CVE-2024-42426" + ], + "details": "Dell PowerScale OneFS Versions 9.5.0.x through 9.8.0.x contain an uncontrolled resource consumption vulnerability. A low privilege remote attacker could potentially exploit this vulnerability, leading to denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42426" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-in/000256645/dsa-2024-453-security-update-for-dell-powerscale-onefs-multiple-security-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T15:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-f47g-ccch-6353/GHSA-f47g-ccch-6353.json b/advisories/unreviewed/2024/12/GHSA-f47g-ccch-6353/GHSA-f47g-ccch-6353.json new file mode 100644 index 00000000000..22f2c22c427 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-f47g-ccch-6353/GHSA-f47g-ccch-6353.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f47g-ccch-6353", + "modified": "2024-12-09T15:31:35Z", + "published": "2024-12-09T15:31:35Z", + "aliases": [ + "CVE-2023-48774" + ], + "details": "Missing Authorization vulnerability in Martin Gibson IdeaPush allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects IdeaPush: from n/a through n/a.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48774" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ideapush/vulnerability/wordpress-ideapush-plugin-8-53-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-f596-88pf-rrm5/GHSA-f596-88pf-rrm5.json b/advisories/unreviewed/2024/12/GHSA-f596-88pf-rrm5/GHSA-f596-88pf-rrm5.json new file mode 100644 index 00000000000..1d46bde5b33 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-f596-88pf-rrm5/GHSA-f596-88pf-rrm5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f596-88pf-rrm5", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2023-50882" + ], + "details": "Missing Authorization vulnerability in ProfilePress Membership Team ProfilePress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ProfilePress: from n/a through 4.13.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50882" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-user-avatar/vulnerability/wordpress-profilepress-plugin-4-13-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-f82h-rc53-967h/GHSA-f82h-rc53-967h.json b/advisories/unreviewed/2024/12/GHSA-f82h-rc53-967h/GHSA-f82h-rc53-967h.json new file mode 100644 index 00000000000..bb21ee9ccef --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-f82h-rc53-967h/GHSA-f82h-rc53-967h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f82h-rc53-967h", + "modified": "2024-12-09T15:31:37Z", + "published": "2024-12-09T15:31:37Z", + "aliases": [ + "CVE-2024-49603" + ], + "details": "Dell PowerScale OneFS Versions 8.2.2.x through 9.9.0.x contain an incorrect specified argument vulnerability. A remote low privileged legitimate user could potentially exploit this vulnerability, leading to information disclosure.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49603" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-in/000256645/dsa-2024-453-security-update-for-dell-powerscale-onefs-multiple-security-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-687" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-fc7x-ffxp-c9q2/GHSA-fc7x-ffxp-c9q2.json b/advisories/unreviewed/2024/12/GHSA-fc7x-ffxp-c9q2/GHSA-fc7x-ffxp-c9q2.json new file mode 100644 index 00000000000..6875788acb5 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-fc7x-ffxp-c9q2/GHSA-fc7x-ffxp-c9q2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fc7x-ffxp-c9q2", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-32117" + ], + "details": "Missing Authorization vulnerability in SoftLab Integrate Google Drive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Integrate Google Drive: from n/a through 1.1.99.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32117" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/integrate-google-drive/vulnerability/wordpress-integrate-google-drive-plugin-1-1-99-unauthenticated-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-fj4j-xqfc-mrx8/GHSA-fj4j-xqfc-mrx8.json b/advisories/unreviewed/2024/12/GHSA-fj4j-xqfc-mrx8/GHSA-fj4j-xqfc-mrx8.json new file mode 100644 index 00000000000..614e2746816 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-fj4j-xqfc-mrx8/GHSA-fj4j-xqfc-mrx8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fj4j-xqfc-mrx8", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-27449" + ], + "details": "Missing Authorization vulnerability in TotalSuite Total Poll Lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Total Poll Lite: from n/a through 4.8.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27449" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/totalpoll-lite/vulnerability/wordpress-total-poll-lite-plugin-4-8-6-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-fjcp-5fg9-5x25/GHSA-fjcp-5fg9-5x25.json b/advisories/unreviewed/2024/12/GHSA-fjcp-5fg9-5x25/GHSA-fjcp-5fg9-5x25.json new file mode 100644 index 00000000000..fcb78566dcd --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-fjcp-5fg9-5x25/GHSA-fjcp-5fg9-5x25.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fjcp-5fg9-5x25", + "modified": "2024-12-09T15:31:33Z", + "published": "2024-12-09T15:31:33Z", + "aliases": [ + "CVE-2023-22708" + ], + "details": "Missing Authorization vulnerability in Karim Salman Kraken.io Image Optimizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kraken.io Image Optimizer: from n/a through 2.6.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22708" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/kraken-image-optimizer/vulnerability/wordpress-kraken-io-image-optimizer-plugin-2-6-7-broken-access-control?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-fjxc-63wq-qpxv/GHSA-fjxc-63wq-qpxv.json b/advisories/unreviewed/2024/12/GHSA-fjxc-63wq-qpxv/GHSA-fjxc-63wq-qpxv.json new file mode 100644 index 00000000000..28460aa9d3d --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-fjxc-63wq-qpxv/GHSA-fjxc-63wq-qpxv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fjxc-63wq-qpxv", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2023-49858" + ], + "details": "Missing Authorization vulnerability in Austin Passy Custom Login allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Custom Login: from n/a through 4.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49858" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/custom-login/vulnerability/wordpress-custom-login-plugin-4-1-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-fppg-2vjw-7hf6/GHSA-fppg-2vjw-7hf6.json b/advisories/unreviewed/2024/12/GHSA-fppg-2vjw-7hf6/GHSA-fppg-2vjw-7hf6.json new file mode 100644 index 00000000000..ca61245c1ad --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-fppg-2vjw-7hf6/GHSA-fppg-2vjw-7hf6.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fppg-2vjw-7hf6", + "modified": "2024-12-09T15:31:37Z", + "published": "2024-12-09T15:31:37Z", + "aliases": [ + "CVE-2024-54929" + ], + "details": "KASHIPARA E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_subject.php.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54929" + }, + { + "type": "WEB", + "url": "https://github.com/m14r41/Writeups/blob/main/CVE/Kashipara/E-learning%20Management%20System%20project/SQL%20Injection%20-%20delete%20subject.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-fqm4-vq4f-gjfc/GHSA-fqm4-vq4f-gjfc.json b/advisories/unreviewed/2024/12/GHSA-fqm4-vq4f-gjfc/GHSA-fqm4-vq4f-gjfc.json new file mode 100644 index 00000000000..13bc61db434 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-fqm4-vq4f-gjfc/GHSA-fqm4-vq4f-gjfc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fqm4-vq4f-gjfc", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-32094" + ], + "details": "Missing Authorization vulnerability in Felix Welberg Extended Post Status allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Extended Post Status: from n/a through 1.0.19.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32094" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/extended-post-status/vulnerability/wordpress-extended-post-status-plugin-1-0-19-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-fqp5-36cq-qjxw/GHSA-fqp5-36cq-qjxw.json b/advisories/unreviewed/2024/12/GHSA-fqp5-36cq-qjxw/GHSA-fqp5-36cq-qjxw.json new file mode 100644 index 00000000000..d8f76a641cc --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-fqp5-36cq-qjxw/GHSA-fqp5-36cq-qjxw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fqp5-36cq-qjxw", + "modified": "2024-12-09T15:31:37Z", + "published": "2024-12-09T15:31:37Z", + "aliases": [ + "CVE-2023-7298" + ], + "details": "A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-7298" + }, + { + "type": "WEB", + "url": "https://autodesk.com/trust/security-advisories/adsk-sa-2023-0025" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-fr4r-345h-fgrq/GHSA-fr4r-345h-fgrq.json b/advisories/unreviewed/2024/12/GHSA-fr4r-345h-fgrq/GHSA-fr4r-345h-fgrq.json new file mode 100644 index 00000000000..a7f4ccc5832 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-fr4r-345h-fgrq/GHSA-fr4r-345h-fgrq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fr4r-345h-fgrq", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2023-49818" + ], + "details": "Missing Authorization vulnerability in Webflow Webflow Pages allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Webflow Pages: from n/a through 1.0.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49818" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/webflow-pages/vulnerability/wordpress-webflow-pages-plugin-1-0-8-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-fr5v-gxxp-r8wr/GHSA-fr5v-gxxp-r8wr.json b/advisories/unreviewed/2024/12/GHSA-fr5v-gxxp-r8wr/GHSA-fr5v-gxxp-r8wr.json new file mode 100644 index 00000000000..71a82b84ab6 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-fr5v-gxxp-r8wr/GHSA-fr5v-gxxp-r8wr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fr5v-gxxp-r8wr", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-29429" + ], + "details": "Missing Authorization vulnerability in WPEverest User Registration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Registration: from n/a through 2.3.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29429" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/user-registration/vulnerability/wordpress-user-registration-plugin-2-3-2-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-g2cc-qr3j-8v4w/GHSA-g2cc-qr3j-8v4w.json b/advisories/unreviewed/2024/12/GHSA-g2cc-qr3j-8v4w/GHSA-g2cc-qr3j-8v4w.json new file mode 100644 index 00000000000..5b7ece408ba --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-g2cc-qr3j-8v4w/GHSA-g2cc-qr3j-8v4w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g2cc-qr3j-8v4w", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-25703" + ], + "details": "Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Meta slider and carousel with lightbox allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Meta slider and carousel with lightbox: from n/a through 1.6.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25703" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/meta-slider-and-carousel-with-lightbox/vulnerability/wordpress-meta-slider-and-carousel-with-lightbox-plugin-1-6-2-broken-access-control?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-g4mp-v546-gp2c/GHSA-g4mp-v546-gp2c.json b/advisories/unreviewed/2024/12/GHSA-g4mp-v546-gp2c/GHSA-g4mp-v546-gp2c.json new file mode 100644 index 00000000000..90a4c2010b5 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-g4mp-v546-gp2c/GHSA-g4mp-v546-gp2c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g4mp-v546-gp2c", + "modified": "2024-12-09T15:31:35Z", + "published": "2024-12-09T15:31:35Z", + "aliases": [ + "CVE-2023-47832" + ], + "details": "Missing Authorization vulnerability in searchiq SearchIQ allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SearchIQ: from n/a through 4.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47832" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/searchiq/vulnerability/wordpress-searchiq-plugin-4-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-g524-pw9w-43g3/GHSA-g524-pw9w-43g3.json b/advisories/unreviewed/2024/12/GHSA-g524-pw9w-43g3/GHSA-g524-pw9w-43g3.json new file mode 100644 index 00000000000..1786416001c --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-g524-pw9w-43g3/GHSA-g524-pw9w-43g3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g524-pw9w-43g3", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2023-50375" + ], + "details": "Missing Authorization vulnerability in Translate AI Multilingual Solutions Google Language Translator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Google Language Translator: from n/a through 6.0.19.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50375" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/google-language-translator/vulnerability/wordpress-translate-wordpress-google-language-translator-plugin-6-0-19-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-g5x4-6wrj-6j37/GHSA-g5x4-6wrj-6j37.json b/advisories/unreviewed/2024/12/GHSA-g5x4-6wrj-6j37/GHSA-g5x4-6wrj-6j37.json new file mode 100644 index 00000000000..bc70711d226 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-g5x4-6wrj-6j37/GHSA-g5x4-6wrj-6j37.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g5x4-6wrj-6j37", + "modified": "2024-12-09T15:31:35Z", + "published": "2024-12-09T15:31:35Z", + "aliases": [ + "CVE-2023-48286" + ], + "details": "Missing Authorization vulnerability in Tips and Tricks HQ, wptipsntricks Stripe Payments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Stripe Payments: from n/a through 2.0.79.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48286" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/stripe-payments/vulnerability/wordpress-accept-stripe-payments-plugin-2-0-79-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-g82v-73f7-4w62/GHSA-g82v-73f7-4w62.json b/advisories/unreviewed/2024/12/GHSA-g82v-73f7-4w62/GHSA-g82v-73f7-4w62.json new file mode 100644 index 00000000000..dc0b78800ce --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-g82v-73f7-4w62/GHSA-g82v-73f7-4w62.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g82v-73f7-4w62", + "modified": "2024-12-09T15:31:37Z", + "published": "2024-12-09T15:31:37Z", + "aliases": [ + "CVE-2023-41953" + ], + "details": "Missing Authorization vulnerability in ProfilePress Membership Team ProfilePress.This issue affects ProfilePress: from n/a through 4.13.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41953" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-user-avatar/vulnerability/wordpress-profilepress-plugin-4-13-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-g8qh-57gx-75gj/GHSA-g8qh-57gx-75gj.json b/advisories/unreviewed/2024/12/GHSA-g8qh-57gx-75gj/GHSA-g8qh-57gx-75gj.json new file mode 100644 index 00000000000..9a6f978a11d --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-g8qh-57gx-75gj/GHSA-g8qh-57gx-75gj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g8qh-57gx-75gj", + "modified": "2024-12-09T15:31:33Z", + "published": "2024-12-09T15:31:33Z", + "aliases": [ + "CVE-2023-23814" + ], + "details": "Missing Authorization vulnerability in CodePeople CP Multi View Event Calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CP Multi View Event Calendar : from n/a through 1.4.13.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23814" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cp-multi-view-calendar/vulnerability/wordpress-calendar-event-multi-view-plugin-1-4-13-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-g8xw-cr5r-q559/GHSA-g8xw-cr5r-q559.json b/advisories/unreviewed/2024/12/GHSA-g8xw-cr5r-q559/GHSA-g8xw-cr5r-q559.json new file mode 100644 index 00000000000..11c343dc491 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-g8xw-cr5r-q559/GHSA-g8xw-cr5r-q559.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g8xw-cr5r-q559", + "modified": "2024-12-09T15:31:37Z", + "published": "2024-12-09T15:31:37Z", + "aliases": [ + "CVE-2024-54254" + ], + "details": "Missing Authorization vulnerability in Kofi Mokome Message Filter for Contact Form 7.This issue affects Message Filter for Contact Form 7: from n/a through 1.6.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54254" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cf7-message-filter/vulnerability/wordpress-message-filter-for-contact-form-7-plugin-1-6-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-g95m-f3r3-pv8g/GHSA-g95m-f3r3-pv8g.json b/advisories/unreviewed/2024/12/GHSA-g95m-f3r3-pv8g/GHSA-g95m-f3r3-pv8g.json new file mode 100644 index 00000000000..929f4a3e903 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-g95m-f3r3-pv8g/GHSA-g95m-f3r3-pv8g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g95m-f3r3-pv8g", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2023-49851" + ], + "details": "Missing Authorization vulnerability in ILMDESIGNS Square Thumbnails allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Square Thumbnails: from n/a through 1.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49851" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/square-thumbnails/vulnerability/wordpress-square-thumbnails-plugin-1-1-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-gcmf-c5mg-j2x8/GHSA-gcmf-c5mg-j2x8.json b/advisories/unreviewed/2024/12/GHSA-gcmf-c5mg-j2x8/GHSA-gcmf-c5mg-j2x8.json new file mode 100644 index 00000000000..ee191d9a05c --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-gcmf-c5mg-j2x8/GHSA-gcmf-c5mg-j2x8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gcmf-c5mg-j2x8", + "modified": "2024-12-09T15:31:35Z", + "published": "2024-12-09T15:31:35Z", + "aliases": [ + "CVE-2023-49754" + ], + "details": "Missing Authorization vulnerability in Yogesh Pawar, Clarion Technologies Bulk Edit Post Titles allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bulk Edit Post Titles: from n/a through 5.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49754" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bulk-edit-post-titles/vulnerability/wordpress-bulk-edit-post-titles-plugin-5-0-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-gf8c-4235-7g24/GHSA-gf8c-4235-7g24.json b/advisories/unreviewed/2024/12/GHSA-gf8c-4235-7g24/GHSA-gf8c-4235-7g24.json new file mode 100644 index 00000000000..b38e1f5ff69 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-gf8c-4235-7g24/GHSA-gf8c-4235-7g24.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gf8c-4235-7g24", + "modified": "2024-12-09T15:31:35Z", + "published": "2024-12-09T15:31:35Z", + "aliases": [ + "CVE-2023-47871" + ], + "details": "Missing Authorization vulnerability in IT Path Solutions Contact Form to Any API allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form to Any API: from n/a through 1.1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47871" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/contact-form-to-any-api/vulnerability/wordpress-contact-form-to-any-api-plugin-1-1-6-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-gfw9-xq8v-9qf2/GHSA-gfw9-xq8v-9qf2.json b/advisories/unreviewed/2024/12/GHSA-gfw9-xq8v-9qf2/GHSA-gfw9-xq8v-9qf2.json new file mode 100644 index 00000000000..fd7037bc29d --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-gfw9-xq8v-9qf2/GHSA-gfw9-xq8v-9qf2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gfw9-xq8v-9qf2", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2024-54230" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPRealizer Unlock Addons for Elementor allows DOM-Based XSS.This issue affects Unlock Addons for Elementor: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54230" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/unlock-addons-for-elementor/vulnerability/wordpress-unlock-addons-for-elementor-plugin-1-0-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-gqj9-g6j7-jf68/GHSA-gqj9-g6j7-jf68.json b/advisories/unreviewed/2024/12/GHSA-gqj9-g6j7-jf68/GHSA-gqj9-g6j7-jf68.json new file mode 100644 index 00000000000..e9c954635e4 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-gqj9-g6j7-jf68/GHSA-gqj9-g6j7-jf68.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gqj9-g6j7-jf68", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-29173" + ], + "details": "Missing Authorization vulnerability in AWESOME TOGI Product Category Tree allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Category Tree: from n/a through 2.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29173" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/product-category-tree/vulnerability/wordpress-product-category-tree-plugin-2-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-gqxc-c4x9-wc48/GHSA-gqxc-c4x9-wc48.json b/advisories/unreviewed/2024/12/GHSA-gqxc-c4x9-wc48/GHSA-gqxc-c4x9-wc48.json new file mode 100644 index 00000000000..0eda0c23cbc --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-gqxc-c4x9-wc48/GHSA-gqxc-c4x9-wc48.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gqxc-c4x9-wc48", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2023-49857" + ], + "details": "Missing Authorization vulnerability in Awesome Support Team Awesome Support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Awesome Support: from n/a through 6.1.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49857" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/awesome-support/vulnerability/wordpress-awesome-support-plugin-6-1-6-broken-access-control-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-gwrx-cjv8-qj99/GHSA-gwrx-cjv8-qj99.json b/advisories/unreviewed/2024/12/GHSA-gwrx-cjv8-qj99/GHSA-gwrx-cjv8-qj99.json new file mode 100644 index 00000000000..b1a07874bee --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-gwrx-cjv8-qj99/GHSA-gwrx-cjv8-qj99.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gwrx-cjv8-qj99", + "modified": "2024-12-09T15:31:35Z", + "published": "2024-12-09T15:31:35Z", + "aliases": [ + "CVE-2023-47826" + ], + "details": "Missing Authorization vulnerability in NicheAddons Restaurant & Cafe Addon for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Restaurant & Cafe Addon for Elementor: from n/a through 1.5.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47826" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/restaurant-cafe-addon-for-elementor/vulnerability/wordpress-restaurant-cafe-addon-for-elementor-plugin-1-5-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-gwxf-w6rq-6q8h/GHSA-gwxf-w6rq-6q8h.json b/advisories/unreviewed/2024/12/GHSA-gwxf-w6rq-6q8h/GHSA-gwxf-w6rq-6q8h.json new file mode 100644 index 00000000000..45f541dbd93 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-gwxf-w6rq-6q8h/GHSA-gwxf-w6rq-6q8h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gwxf-w6rq-6q8h", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2023-49859" + ], + "details": "Missing Authorization vulnerability in Pixelite Login With Ajax allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Login With Ajax: from n/a through 4.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49859" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/login-with-ajax/vulnerability/wordpress-login-with-ajax-plugin-4-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-h3c8-cf53-m8j7/GHSA-h3c8-cf53-m8j7.json b/advisories/unreviewed/2024/12/GHSA-h3c8-cf53-m8j7/GHSA-h3c8-cf53-m8j7.json new file mode 100644 index 00000000000..2d6206d04c4 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-h3c8-cf53-m8j7/GHSA-h3c8-cf53-m8j7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h3c8-cf53-m8j7", + "modified": "2024-12-09T15:31:37Z", + "published": "2024-12-09T15:31:37Z", + "aliases": [ + "CVE-2024-8259" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eryaz Information Technologies NatraCar B2B Dealer Management Program allows SQL Injection.This issue affects NatraCar B2B Dealer Management Program: through 09.12.2024.\n\n\n\nNOTE: The vendor was contacted and it was learned that the product is not supported.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8259" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-24-1881" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T14:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-h49h-j7pc-4p78/GHSA-h49h-j7pc-4p78.json b/advisories/unreviewed/2024/12/GHSA-h49h-j7pc-4p78/GHSA-h49h-j7pc-4p78.json new file mode 100644 index 00000000000..5908ea94e5f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-h49h-j7pc-4p78/GHSA-h49h-j7pc-4p78.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h49h-j7pc-4p78", + "modified": "2024-12-09T15:31:35Z", + "published": "2024-12-09T15:31:35Z", + "aliases": [ + "CVE-2023-49193" + ], + "details": "Missing Authorization vulnerability in NerdPress Social Pug allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social Pug: from n/a through 1.30.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49193" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/social-pug/vulnerability/wordpress-grow-social-plugin-1-20-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-h79h-xmwc-8687/GHSA-h79h-xmwc-8687.json b/advisories/unreviewed/2024/12/GHSA-h79h-xmwc-8687/GHSA-h79h-xmwc-8687.json new file mode 100644 index 00000000000..2a8c150e1d0 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-h79h-xmwc-8687/GHSA-h79h-xmwc-8687.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h79h-xmwc-8687", + "modified": "2024-12-09T15:31:35Z", + "published": "2024-12-09T15:31:35Z", + "aliases": [ + "CVE-2023-47776" + ], + "details": "Missing Authorization vulnerability in miniOrange miniorange otp verification allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects miniorange otp verification: from n/a through 4.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47776" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/miniorange-otp-verification/vulnerability/wordpress-miniorange-otp-verification-plugin-4-2-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-hfh8-5fj3-qqrh/GHSA-hfh8-5fj3-qqrh.json b/advisories/unreviewed/2024/12/GHSA-hfh8-5fj3-qqrh/GHSA-hfh8-5fj3-qqrh.json new file mode 100644 index 00000000000..72bb2c830f2 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-hfh8-5fj3-qqrh/GHSA-hfh8-5fj3-qqrh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hfh8-5fj3-qqrh", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-25454" + ], + "details": "Missing Authorization vulnerability in Nate Reist Protected Posts Logout Button allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Protected Posts Logout Button: from n/a through 1.4.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25454" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/protected-posts-logout-button/vulnerability/wordpress-protected-posts-logout-button-plugin-1-4-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-hgjv-8v3q-g4h2/GHSA-hgjv-8v3q-g4h2.json b/advisories/unreviewed/2024/12/GHSA-hgjv-8v3q-g4h2/GHSA-hgjv-8v3q-g4h2.json new file mode 100644 index 00000000000..8e68e2f0240 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-hgjv-8v3q-g4h2/GHSA-hgjv-8v3q-g4h2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hgjv-8v3q-g4h2", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-26520" + ], + "details": "Missing Authorization vulnerability in Max Chirkov Advanced Text Widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Text Widget : from n/a through 2.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26520" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/advanced-text-widget/vulnerability/wordpress-advanced-text-widget-plugin-2-1-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-hh53-wjg9-hph8/GHSA-hh53-wjg9-hph8.json b/advisories/unreviewed/2024/12/GHSA-hh53-wjg9-hph8/GHSA-hh53-wjg9-hph8.json new file mode 100644 index 00000000000..61770954451 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-hh53-wjg9-hph8/GHSA-hh53-wjg9-hph8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hh53-wjg9-hph8", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:35Z", + "aliases": [ + "CVE-2023-49757" + ], + "details": "Missing Authorization vulnerability in Awesome Support Team Awesome Support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Awesome Support: from n/a through 6.1.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49757" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/awesome-support/vulnerability/wordpress-awesome-support-plugin-6-1-6-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-hj97-mcr5-vcph/GHSA-hj97-mcr5-vcph.json b/advisories/unreviewed/2024/12/GHSA-hj97-mcr5-vcph/GHSA-hj97-mcr5-vcph.json new file mode 100644 index 00000000000..c99e2219902 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-hj97-mcr5-vcph/GHSA-hj97-mcr5-vcph.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hj97-mcr5-vcph", + "modified": "2024-12-09T15:31:37Z", + "published": "2024-12-09T15:31:37Z", + "aliases": [ + "CVE-2024-52385" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Sk. Abul Hasan Team Member.This issue affects Team Member: from n/a through 7.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52385" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/team-showcase-supreme/vulnerability/wordpress-team-member-multi-language-supported-team-plugin-7-1-limited-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-hjr6-44rc-43vh/GHSA-hjr6-44rc-43vh.json b/advisories/unreviewed/2024/12/GHSA-hjr6-44rc-43vh/GHSA-hjr6-44rc-43vh.json new file mode 100644 index 00000000000..c3b4f386de1 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-hjr6-44rc-43vh/GHSA-hjr6-44rc-43vh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hjr6-44rc-43vh", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-30486" + ], + "details": "Missing Authorization vulnerability in HashThemes Square allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Square: from n/a through 2.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30486" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/square/vulnerability/wordpress-square-theme-2-0-0-broken-access-control?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-hp59-f5w9-w867/GHSA-hp59-f5w9-w867.json b/advisories/unreviewed/2024/12/GHSA-hp59-f5w9-w867/GHSA-hp59-f5w9-w867.json new file mode 100644 index 00000000000..ef81269da51 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-hp59-f5w9-w867/GHSA-hp59-f5w9-w867.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hp59-f5w9-w867", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2024-54217" + ], + "details": "Missing Authorization vulnerability in Repute info systems ARForms.This issue affects ARForms: from n/a through 6.4.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54217" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/arforms/vulnerability/wordpress-arforms-plugin-6-4-1-subscriber-plugin-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-hpqg-c42f-fxqx/GHSA-hpqg-c42f-fxqx.json b/advisories/unreviewed/2024/12/GHSA-hpqg-c42f-fxqx/GHSA-hpqg-c42f-fxqx.json new file mode 100644 index 00000000000..068d707c227 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-hpqg-c42f-fxqx/GHSA-hpqg-c42f-fxqx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hpqg-c42f-fxqx", + "modified": "2024-12-09T15:31:33Z", + "published": "2024-12-09T15:31:33Z", + "aliases": [ + "CVE-2023-23834" + ], + "details": "Missing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through 2.3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23834" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ultimate-addons-for-gutenberg/vulnerability/wordpress-spectra-wordpress-gutenberg-blocks-plugin-2-3-0-broken-access-control-csrf-on-activate-plugin-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-j444-7j4h-86hv/GHSA-j444-7j4h-86hv.json b/advisories/unreviewed/2024/12/GHSA-j444-7j4h-86hv/GHSA-j444-7j4h-86hv.json new file mode 100644 index 00000000000..b370d1f7b14 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-j444-7j4h-86hv/GHSA-j444-7j4h-86hv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j444-7j4h-86hv", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-30479" + ], + "details": "Missing Authorization vulnerability in Stamped.io Stamped.io Product Reviews & UGC for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Stamped.io Product Reviews & UGC for WooCommerce: from n/a through 2.3.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30479" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/stampedio-product-reviews/vulnerability/wordpress-stamped-io-product-reviews-ugc-for-woocommerce-plugin-2-3-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-j94f-4hmh-hx5v/GHSA-j94f-4hmh-hx5v.json b/advisories/unreviewed/2024/12/GHSA-j94f-4hmh-hx5v/GHSA-j94f-4hmh-hx5v.json new file mode 100644 index 00000000000..cae8108e8c6 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-j94f-4hmh-hx5v/GHSA-j94f-4hmh-hx5v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j94f-4hmh-hx5v", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2024-54220" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Roninwp FAT Services Booking allows Stored XSS.This issue affects FAT Services Booking: from n/a through 5.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54220" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/fat-services-booking/vulnerability/wordpress-fat-services-booking-plugin-5-6-subscriber-site-wide-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-jcwf-p9v3-fvg5/GHSA-jcwf-p9v3-fvg5.json b/advisories/unreviewed/2024/12/GHSA-jcwf-p9v3-fvg5/GHSA-jcwf-p9v3-fvg5.json new file mode 100644 index 00000000000..f85d55adee9 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-jcwf-p9v3-fvg5/GHSA-jcwf-p9v3-fvg5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jcwf-p9v3-fvg5", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2023-49835" + ], + "details": "Missing Authorization vulnerability in Metaphor Creations Post Duplicator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Duplicator: from n/a through 2.31.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49835" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/post-duplicator/vulnerability/wordpress-post-duplicator-plugin-2-31-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-jgwp-vc7j-pqj9/GHSA-jgwp-vc7j-pqj9.json b/advisories/unreviewed/2024/12/GHSA-jgwp-vc7j-pqj9/GHSA-jgwp-vc7j-pqj9.json new file mode 100644 index 00000000000..3593eb02eeb --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-jgwp-vc7j-pqj9/GHSA-jgwp-vc7j-pqj9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jgwp-vc7j-pqj9", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2023-50877" + ], + "details": "Missing Authorization vulnerability in woobewoo Product Filter by WBW allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Filter by WBW: from n/a through 2.5.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50877" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woo-product-filter/vulnerability/wordpress-product-filter-by-wbw-plugin-2-5-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-jm4g-v647-7753/GHSA-jm4g-v647-7753.json b/advisories/unreviewed/2024/12/GHSA-jm4g-v647-7753/GHSA-jm4g-v647-7753.json new file mode 100644 index 00000000000..b0c18fec23a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-jm4g-v647-7753/GHSA-jm4g-v647-7753.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jm4g-v647-7753", + "modified": "2024-12-09T15:31:35Z", + "published": "2024-12-09T15:31:35Z", + "aliases": [ + "CVE-2023-48779" + ], + "details": "Missing Authorization vulnerability in 360 Javascript Viewer 360 Javascript Viewer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 360 Javascript Viewer: from n/a through 1.7.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48779" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/360deg-javascript-viewer/vulnerability/wordpress-360-javascript-viewer-plugin-1-7-11-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-jqm9-j7qh-gxhh/GHSA-jqm9-j7qh-gxhh.json b/advisories/unreviewed/2024/12/GHSA-jqm9-j7qh-gxhh/GHSA-jqm9-j7qh-gxhh.json new file mode 100644 index 00000000000..eb4fb44cff1 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-jqm9-j7qh-gxhh/GHSA-jqm9-j7qh-gxhh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jqm9-j7qh-gxhh", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:33Z", + "aliases": [ + "CVE-2023-25067" + ], + "details": "Missing Authorization vulnerability in Noah Hearle, Design Extreme We’re Open! allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects We’re Open!: from n/a through 1.45.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25067" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/opening-hours/vulnerability/wordpress-we-re-open-plugin-1-45-broken-access-control?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-m4hr-3x7p-crp4/GHSA-m4hr-3x7p-crp4.json b/advisories/unreviewed/2024/12/GHSA-m4hr-3x7p-crp4/GHSA-m4hr-3x7p-crp4.json new file mode 100644 index 00000000000..d522284acb8 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-m4hr-3x7p-crp4/GHSA-m4hr-3x7p-crp4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m4hr-3x7p-crp4", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2023-50887" + ], + "details": "Missing Authorization vulnerability in UserFeedback Team User Feedback allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Feedback: from n/a through 1.0.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50887" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/userfeedback-lite/vulnerability/wordpress-user-feedback-plugin-1-0-10-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-m5mh-rmcg-x9pm/GHSA-m5mh-rmcg-x9pm.json b/advisories/unreviewed/2024/12/GHSA-m5mh-rmcg-x9pm/GHSA-m5mh-rmcg-x9pm.json new file mode 100644 index 00000000000..4169b5f3bcf --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-m5mh-rmcg-x9pm/GHSA-m5mh-rmcg-x9pm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m5mh-rmcg-x9pm", + "modified": "2024-12-09T15:31:35Z", + "published": "2024-12-09T15:31:35Z", + "aliases": [ + "CVE-2023-47836" + ], + "details": "Missing Authorization vulnerability in Prasad Kirpekar WP Meta and Date Remover allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Meta and Date Remover: from n/a through 2.3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47836" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-meta-and-date-remover/vulnerability/wordpress-wp-meta-and-date-remover-plugin-2-2-1-broken-access-control-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-m9x6-hmmv-9j9x/GHSA-m9x6-hmmv-9j9x.json b/advisories/unreviewed/2024/12/GHSA-m9x6-hmmv-9j9x/GHSA-m9x6-hmmv-9j9x.json new file mode 100644 index 00000000000..e43c873c503 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-m9x6-hmmv-9j9x/GHSA-m9x6-hmmv-9j9x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m9x6-hmmv-9j9x", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2023-51355" + ], + "details": "Missing Authorization vulnerability in MultiVendorX WC Marketplace allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WC Marketplace: from n/a through 4.0.23.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51355" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/dc-woocommerce-multi-vendor/vulnerability/wordpress-multivendorx-plugin-4-0-23-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-mc3r-mf88-6p5f/GHSA-mc3r-mf88-6p5f.json b/advisories/unreviewed/2024/12/GHSA-mc3r-mf88-6p5f/GHSA-mc3r-mf88-6p5f.json new file mode 100644 index 00000000000..fa93cc7b160 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-mc3r-mf88-6p5f/GHSA-mc3r-mf88-6p5f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mc3r-mf88-6p5f", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-30748" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nikola Loncar Easy Appointments allows Stored XSS.This issue affects Easy Appointments: from n/a through 3.10.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30748" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/easy-appointments/vulnerability/wordpress-easy-appointments-plugin-3-10-7-auth-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-mgmq-hw26-pjh3/GHSA-mgmq-hw26-pjh3.json b/advisories/unreviewed/2024/12/GHSA-mgmq-hw26-pjh3/GHSA-mgmq-hw26-pjh3.json new file mode 100644 index 00000000000..cb23ad6362e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-mgmq-hw26-pjh3/GHSA-mgmq-hw26-pjh3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mgmq-hw26-pjh3", + "modified": "2024-12-09T15:31:35Z", + "published": "2024-12-09T15:31:35Z", + "aliases": [ + "CVE-2023-48324" + ], + "details": "Missing Authorization vulnerability in Awesome Support Team Awesome Support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Awesome Support: from n/a through 6.1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48324" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/awesome-support/vulnerability/wordpress-awesome-support-helpdesk-plugin-6-1-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-mhgc-69vw-rqc7/GHSA-mhgc-69vw-rqc7.json b/advisories/unreviewed/2024/12/GHSA-mhgc-69vw-rqc7/GHSA-mhgc-69vw-rqc7.json new file mode 100644 index 00000000000..a989c382eac --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-mhgc-69vw-rqc7/GHSA-mhgc-69vw-rqc7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mhgc-69vw-rqc7", + "modified": "2024-12-09T15:31:33Z", + "published": "2024-12-09T15:31:33Z", + "aliases": [ + "CVE-2023-23975" + ], + "details": "Missing Authorization vulnerability in Fullworks Quick Event Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quick Event Manager: from n/a through 9.7.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23975" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/quick-event-manager/vulnerability/wordpress-quick-event-manager-plugin-9-7-4-broken-access-control?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-mhjx-fmp2-85mh/GHSA-mhjx-fmp2-85mh.json b/advisories/unreviewed/2024/12/GHSA-mhjx-fmp2-85mh/GHSA-mhjx-fmp2-85mh.json new file mode 100644 index 00000000000..aebcd4241f4 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-mhjx-fmp2-85mh/GHSA-mhjx-fmp2-85mh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mhjx-fmp2-85mh", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2023-49756" + ], + "details": "Missing Authorization vulnerability in Themewinter Eventin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Eventin: from n/a through 3.3.52.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49756" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-event-solution/vulnerability/wordpress-eventin-plugin-3-3-44-authenticated-notice-dismissal-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-mmrf-vhfh-pr67/GHSA-mmrf-vhfh-pr67.json b/advisories/unreviewed/2024/12/GHSA-mmrf-vhfh-pr67/GHSA-mmrf-vhfh-pr67.json new file mode 100644 index 00000000000..eefa37cc084 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-mmrf-vhfh-pr67/GHSA-mmrf-vhfh-pr67.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mmrf-vhfh-pr67", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2023-49758" + ], + "details": "Missing Authorization vulnerability in Veribo, Roland Murg WP Booking System allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Booking System: from n/a through 2.0.19.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49758" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-booking-system/vulnerability/wordpress-wp-booking-system-plugin-2-0-19-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-mmw6-xfhm-wxwx/GHSA-mmw6-xfhm-wxwx.json b/advisories/unreviewed/2024/12/GHSA-mmw6-xfhm-wxwx/GHSA-mmw6-xfhm-wxwx.json new file mode 100644 index 00000000000..8375c0a5489 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-mmw6-xfhm-wxwx/GHSA-mmw6-xfhm-wxwx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mmw6-xfhm-wxwx", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-28416" + ], + "details": "Missing Authorization vulnerability in Sparkle Themes Chankhe allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Chankhe: from n/a through 1.0.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28416" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/chankhe/vulnerability/wordpress-chankhe-theme-1-0-5-authenticated-arbitrary-plugin-activation?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-mrw9-2m5g-jjg2/GHSA-mrw9-2m5g-jjg2.json b/advisories/unreviewed/2024/12/GHSA-mrw9-2m5g-jjg2/GHSA-mrw9-2m5g-jjg2.json new file mode 100644 index 00000000000..4be96e61a46 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-mrw9-2m5g-jjg2/GHSA-mrw9-2m5g-jjg2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mrw9-2m5g-jjg2", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2023-51359" + ], + "details": "Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential Blocks for Gutenberg: from n/a through 4.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51359" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/essential-blocks/vulnerability/wordpress-essential-blocks-plugin-4-2-0-multiple-contributor-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-mw9g-9rrr-6ph5/GHSA-mw9g-9rrr-6ph5.json b/advisories/unreviewed/2024/12/GHSA-mw9g-9rrr-6ph5/GHSA-mw9g-9rrr-6ph5.json new file mode 100644 index 00000000000..db1e94842b2 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-mw9g-9rrr-6ph5/GHSA-mw9g-9rrr-6ph5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mw9g-9rrr-6ph5", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-28165" + ], + "details": "Missing Authorization vulnerability in Tech Banker Backup Bank: WordPress Backup Plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Backup Bank: WordPress Backup Plugin: from n/a through 4.0.28.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28165" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-backup-bank/vulnerability/wordpress-backup-bank-wordpress-backup-plugin-plugin-4-0-28-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-mxjg-fxmc-m49m/GHSA-mxjg-fxmc-m49m.json b/advisories/unreviewed/2024/12/GHSA-mxjg-fxmc-m49m/GHSA-mxjg-fxmc-m49m.json new file mode 100644 index 00000000000..70dbbafa68d --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-mxjg-fxmc-m49m/GHSA-mxjg-fxmc-m49m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mxjg-fxmc-m49m", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2023-49861" + ], + "details": "Missing Authorization vulnerability in socialmediafeather Social Media Feather allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social Media Feather: from n/a through 2.1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49861" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/social-media-feather/vulnerability/wordpress-social-media-feather-plugin-2-1-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-p25w-rw57-m43h/GHSA-p25w-rw57-m43h.json b/advisories/unreviewed/2024/12/GHSA-p25w-rw57-m43h/GHSA-p25w-rw57-m43h.json new file mode 100644 index 00000000000..ed2c7f14819 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-p25w-rw57-m43h/GHSA-p25w-rw57-m43h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p25w-rw57-m43h", + "modified": "2024-12-09T15:31:35Z", + "published": "2024-12-09T15:31:35Z", + "aliases": [ + "CVE-2023-47823" + ], + "details": "Missing Authorization vulnerability in nCrafts FormCraft allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FormCraft: from n/a through 1.2.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47823" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/formcraft-form-builder/vulnerability/wordpress-formcraft-contact-form-builder-for-wordpress-plugin-1-2-7-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-p34g-pvrv-g554/GHSA-p34g-pvrv-g554.json b/advisories/unreviewed/2024/12/GHSA-p34g-pvrv-g554/GHSA-p34g-pvrv-g554.json new file mode 100644 index 00000000000..d2fc7ffd4b2 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-p34g-pvrv-g554/GHSA-p34g-pvrv-g554.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p34g-pvrv-g554", + "modified": "2024-12-09T15:31:35Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-47698" + ], + "details": "Missing Authorization vulnerability in Artisan Workshop Japanized For WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Japanized For WooCommerce: from n/a through 2.6.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47698" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woocommerce-for-japan/vulnerability/wordpress-japanized-for-woocommerce-plugin-2-6-4-multiple-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-p3f6-h3j4-76hr/GHSA-p3f6-h3j4-76hr.json b/advisories/unreviewed/2024/12/GHSA-p3f6-h3j4-76hr/GHSA-p3f6-h3j4-76hr.json new file mode 100644 index 00000000000..7778270999e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-p3f6-h3j4-76hr/GHSA-p3f6-h3j4-76hr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p3f6-h3j4-76hr", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-29422" + ], + "details": "Missing Authorization vulnerability in AlexaCRM Dynamics 365 Integration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Dynamics 365 Integration: from n/a through 1.3.13.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29422" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/integration-dynamics/vulnerability/wordpress-dynamics-365-integration-plugin-1-3-13-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-p55v-8989-68v9/GHSA-p55v-8989-68v9.json b/advisories/unreviewed/2024/12/GHSA-p55v-8989-68v9/GHSA-p55v-8989-68v9.json new file mode 100644 index 00000000000..dd29f8f2642 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-p55v-8989-68v9/GHSA-p55v-8989-68v9.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p55v-8989-68v9", + "modified": "2024-12-09T15:31:37Z", + "published": "2024-12-09T15:31:37Z", + "aliases": [ + "CVE-2024-54920" + ], + "details": "A SQL Injection vulnerability was found in the /teacher_signup.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL command to get unauthorized database access via the firstname, lastname, and class_id parameters.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54920" + }, + { + "type": "WEB", + "url": "https://github.com/m14r41/Writeups/blob/main/CVE/Kashipara/E-learning%20Management%20System%20project/SQL%20Injection%20-%20Signup%20teacher.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T15:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-p622-c4f2-jx9v/GHSA-p622-c4f2-jx9v.json b/advisories/unreviewed/2024/12/GHSA-p622-c4f2-jx9v/GHSA-p622-c4f2-jx9v.json new file mode 100644 index 00000000000..7a05c3f1012 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-p622-c4f2-jx9v/GHSA-p622-c4f2-jx9v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p622-c4f2-jx9v", + "modified": "2024-12-09T15:31:35Z", + "published": "2024-12-09T15:31:35Z", + "aliases": [ + "CVE-2023-47822" + ], + "details": "Missing Authorization vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 4.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47822" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mp3-music-player-by-sonaar/vulnerability/wordpress-mp3-audio-player-for-music-radio-podcast-by-sonaar-plugin-4-10-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-p76v-p259-ph9f/GHSA-p76v-p259-ph9f.json b/advisories/unreviewed/2024/12/GHSA-p76v-p259-ph9f/GHSA-p76v-p259-ph9f.json new file mode 100644 index 00000000000..63c5d613958 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-p76v-p259-ph9f/GHSA-p76v-p259-ph9f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p76v-p259-ph9f", + "modified": "2024-12-09T15:31:35Z", + "published": "2024-12-09T15:31:35Z", + "aliases": [ + "CVE-2023-47780" + ], + "details": "Missing Authorization vulnerability in EasyAzon EasyAzon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EasyAzon: from n/a through 5.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47780" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/easyazon/vulnerability/wordpress-easyazon-amazon-associates-affiliate-plugin-plugin-5-1-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-pc2p-cpvm-qg7r/GHSA-pc2p-cpvm-qg7r.json b/advisories/unreviewed/2024/12/GHSA-pc2p-cpvm-qg7r/GHSA-pc2p-cpvm-qg7r.json new file mode 100644 index 00000000000..ba106f1da98 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-pc2p-cpvm-qg7r/GHSA-pc2p-cpvm-qg7r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pc2p-cpvm-qg7r", + "modified": "2024-12-09T15:31:33Z", + "published": "2024-12-09T15:31:33Z", + "aliases": [ + "CVE-2023-23887" + ], + "details": "Missing Authorization vulnerability in Shaon Easy Google Analytics for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Google Analytics for WordPress: from n/a through 1.6.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23887" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/easy-google-analytics-for-wordpress/vulnerability/wordpress-easy-google-analytics-for-wordpress-plugin-1-6-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-pc6h-vhph-vqmm/GHSA-pc6h-vhph-vqmm.json b/advisories/unreviewed/2024/12/GHSA-pc6h-vhph-vqmm/GHSA-pc6h-vhph-vqmm.json new file mode 100644 index 00000000000..4463bbf4097 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-pc6h-vhph-vqmm/GHSA-pc6h-vhph-vqmm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pc6h-vhph-vqmm", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2023-49845" + ], + "details": "Missing Authorization vulnerability in Loud Dog Redirects allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Redirects: from n/a through 1.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49845" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/redirects/vulnerability/wordpress-redirects-plugin-1-2-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-pfcf-79w8-59jx/GHSA-pfcf-79w8-59jx.json b/advisories/unreviewed/2024/12/GHSA-pfcf-79w8-59jx/GHSA-pfcf-79w8-59jx.json new file mode 100644 index 00000000000..1bfce5ec8cc --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-pfcf-79w8-59jx/GHSA-pfcf-79w8-59jx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pfcf-79w8-59jx", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-28688" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in ThemeHunk TH Variation Swatches allows Cross Site Request Forgery.This issue affects TH Variation Swatches: from n/a through 1.2.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28688" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/th-variation-swatches/vulnerability/wordpress-th-variation-swatches-plugin-1-2-7-multiple-vulnerabilities?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-pg2h-hp2v-fwjh/GHSA-pg2h-hp2v-fwjh.json b/advisories/unreviewed/2024/12/GHSA-pg2h-hp2v-fwjh/GHSA-pg2h-hp2v-fwjh.json new file mode 100644 index 00000000000..c514e066171 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-pg2h-hp2v-fwjh/GHSA-pg2h-hp2v-fwjh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pg2h-hp2v-fwjh", + "modified": "2024-12-09T15:31:35Z", + "published": "2024-12-09T15:31:35Z", + "aliases": [ + "CVE-2023-49158" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LadiPage LadiApp allows Stored XSS.This issue affects LadiApp: from n/a through 4.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49158" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ladipage/vulnerability/wordpress-ladiapp-plugin-4-3-broken-access-control-lead-to-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-pgg8-7hhg-9qjh/GHSA-pgg8-7hhg-9qjh.json b/advisories/unreviewed/2024/12/GHSA-pgg8-7hhg-9qjh/GHSA-pgg8-7hhg-9qjh.json new file mode 100644 index 00000000000..a10daddcad1 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-pgg8-7hhg-9qjh/GHSA-pgg8-7hhg-9qjh.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pgg8-7hhg-9qjh", + "modified": "2024-12-09T15:31:37Z", + "published": "2024-12-09T15:31:37Z", + "aliases": [ + "CVE-2024-54936" + ], + "details": "A Stored Cross-Site Scripting (XSS) vulnerability was found in the /send_message.php of Kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the my_message parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54936" + }, + { + "type": "WEB", + "url": "https://github.com/m14r41/Writeups/blob/main/CVE/Kashipara/E-learning%20Management%20System%20project/Stored%20XSS%20-%20teacher%20message.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T14:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-phj2-cgmx-vr7v/GHSA-phj2-cgmx-vr7v.json b/advisories/unreviewed/2024/12/GHSA-phj2-cgmx-vr7v/GHSA-phj2-cgmx-vr7v.json new file mode 100644 index 00000000000..32fbffdc9e2 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-phj2-cgmx-vr7v/GHSA-phj2-cgmx-vr7v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phj2-cgmx-vr7v", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-30870" + ], + "details": "Missing Authorization vulnerability in wooproductimporter Sharkdropship for AliExpress Dropship and Affiliate allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sharkdropship for AliExpress Dropship and Affiliate: from n/a through 2.2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30870" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wooshark-aliexpress-importer/vulnerability/wordpress-sharkdropship-for-aliexpress-dropship-and-affiliate-plugin-2-2-3-multiple-broken-access-control-vulnerabilities?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-pj62-g697-6g5q/GHSA-pj62-g697-6g5q.json b/advisories/unreviewed/2024/12/GHSA-pj62-g697-6g5q/GHSA-pj62-g697-6g5q.json new file mode 100644 index 00000000000..0909ac738d1 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-pj62-g697-6g5q/GHSA-pj62-g697-6g5q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pj62-g697-6g5q", + "modified": "2024-12-09T15:31:33Z", + "published": "2024-12-09T15:31:33Z", + "aliases": [ + "CVE-2023-23895" + ], + "details": "Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Time Slots Booking Form: from n/a through 1.1.82.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23895" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-time-slots-booking-form/vulnerability/wordpress-wp-time-slots-booking-form-plugin-1-1-82-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-pm64-6hrq-vf9h/GHSA-pm64-6hrq-vf9h.json b/advisories/unreviewed/2024/12/GHSA-pm64-6hrq-vf9h/GHSA-pm64-6hrq-vf9h.json new file mode 100644 index 00000000000..d3ffe2e0984 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-pm64-6hrq-vf9h/GHSA-pm64-6hrq-vf9h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pm64-6hrq-vf9h", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2023-49831" + ], + "details": "Missing Authorization vulnerability in Metagauss User Registration Forms RegistrationMagic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RegistrationMagic: from n/a through 5.2.3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49831" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/custom-registration-form-builder-with-submission-manager/vulnerability/wordpress-registrationmagic-plugin-5-2-3-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-pmr4-rq5x-jpmj/GHSA-pmr4-rq5x-jpmj.json b/advisories/unreviewed/2024/12/GHSA-pmr4-rq5x-jpmj/GHSA-pmr4-rq5x-jpmj.json new file mode 100644 index 00000000000..ad7bb0989f7 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-pmr4-rq5x-jpmj/GHSA-pmr4-rq5x-jpmj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pmr4-rq5x-jpmj", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-25455" + ], + "details": "Missing Authorization vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn): from n/a through 7.6.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25455" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/miniorange-login-openid/vulnerability/wordpress-wordpress-social-login-and-register-discord-google-twitter-linkedin-plugin-7-6-0-arbitrary-content-deletion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-prfg-gjqw-hrfv/GHSA-prfg-gjqw-hrfv.json b/advisories/unreviewed/2024/12/GHSA-prfg-gjqw-hrfv/GHSA-prfg-gjqw-hrfv.json new file mode 100644 index 00000000000..92c8a0e7726 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-prfg-gjqw-hrfv/GHSA-prfg-gjqw-hrfv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-prfg-gjqw-hrfv", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-28417" + ], + "details": "Missing Authorization vulnerability in AlexaCRM Dynamics 365 Integration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Dynamics 365 Integration: from n/a through 1.3.12.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28417" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/integration-dynamics/vulnerability/wordpress-dynamics-365-integration-plugin-1-3-12-broken-access-control?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-prw6-8j25-rxh9/GHSA-prw6-8j25-rxh9.json b/advisories/unreviewed/2024/12/GHSA-prw6-8j25-rxh9/GHSA-prw6-8j25-rxh9.json new file mode 100644 index 00000000000..e05abad8147 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-prw6-8j25-rxh9/GHSA-prw6-8j25-rxh9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-prw6-8j25-rxh9", + "modified": "2024-12-09T15:31:35Z", + "published": "2024-12-09T15:31:35Z", + "aliases": [ + "CVE-2023-47841" + ], + "details": "Missing Authorization vulnerability in Analytify Analytify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Analytify: from n/a through 5.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47841" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-analytify/vulnerability/wordpress-analytify-plugin-5-1-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-pv94-6hw8-hh77/GHSA-pv94-6hw8-hh77.json b/advisories/unreviewed/2024/12/GHSA-pv94-6hw8-hh77/GHSA-pv94-6hw8-hh77.json new file mode 100644 index 00000000000..4b486aced90 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-pv94-6hw8-hh77/GHSA-pv94-6hw8-hh77.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pv94-6hw8-hh77", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2023-49850" + ], + "details": "Missing Authorization vulnerability in Ashish Ajani WP Simple HTML Sitemap allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Simple HTML Sitemap: from n/a through 2.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49850" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-simple-html-sitemap/vulnerability/wordpress-wp-simple-html-sitemap-plugin-2-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-pvcx-grh4-qwx5/GHSA-pvcx-grh4-qwx5.json b/advisories/unreviewed/2024/12/GHSA-pvcx-grh4-qwx5/GHSA-pvcx-grh4-qwx5.json new file mode 100644 index 00000000000..af8b6eaed32 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-pvcx-grh4-qwx5/GHSA-pvcx-grh4-qwx5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pvcx-grh4-qwx5", + "modified": "2024-12-09T15:31:37Z", + "published": "2024-12-09T15:31:37Z", + "aliases": [ + "CVE-2024-54227" + ], + "details": "Missing Authorization vulnerability in theDotstore Minimum and Maximum Quantity for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Minimum and Maximum Quantity for WooCommerce: from n/a through 2.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54227" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/min-and-max-quantity-for-woocommerce/vulnerability/wordpress-minimum-and-maximum-quantity-for-woocommerce-plugin-2-0-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-pvx9-87pp-p3xm/GHSA-pvx9-87pp-p3xm.json b/advisories/unreviewed/2024/12/GHSA-pvx9-87pp-p3xm/GHSA-pvx9-87pp-p3xm.json new file mode 100644 index 00000000000..cb94f6bebf3 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-pvx9-87pp-p3xm/GHSA-pvx9-87pp-p3xm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pvx9-87pp-p3xm", + "modified": "2024-12-09T15:31:35Z", + "published": "2024-12-09T15:31:35Z", + "aliases": [ + "CVE-2023-48740" + ], + "details": "Missing Authorization vulnerability in Easy Social Feed Easy Social Feed allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Social Feed: from n/a through 6.5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48740" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/easy-facebook-likebox/vulnerability/wordpress-easy-social-feed-plugin-6-5-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-q35j-4rcf-vmpj/GHSA-q35j-4rcf-vmpj.json b/advisories/unreviewed/2024/12/GHSA-q35j-4rcf-vmpj/GHSA-q35j-4rcf-vmpj.json new file mode 100644 index 00000000000..7d10db230b5 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-q35j-4rcf-vmpj/GHSA-q35j-4rcf-vmpj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q35j-4rcf-vmpj", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-29433" + ], + "details": "Missing Authorization vulnerability in 腾讯云 tencentcloud-cos allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects tencentcloud-cos: from n/a through 1.0.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29433" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/tencentcloud-cos/vulnerability/wordpress-tencentcloud-cos-plugin-1-0-7-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-qm37-c96x-h869/GHSA-qm37-c96x-h869.json b/advisories/unreviewed/2024/12/GHSA-qm37-c96x-h869/GHSA-qm37-c96x-h869.json new file mode 100644 index 00000000000..cd3a5e29314 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-qm37-c96x-h869/GHSA-qm37-c96x-h869.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qm37-c96x-h869", + "modified": "2024-12-09T15:31:33Z", + "published": "2024-12-09T15:31:33Z", + "aliases": [ + "CVE-2023-23823" + ], + "details": "Missing Authorization vulnerability in Clever Widgets Enhanced Text Widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Enhanced Text Widget: from n/a through 1.5.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23823" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/enhanced-text-widget/vulnerability/wordpress-enhanced-text-widget-plugin-1-5-7-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-qm6w-2f55-rh45/GHSA-qm6w-2f55-rh45.json b/advisories/unreviewed/2024/12/GHSA-qm6w-2f55-rh45/GHSA-qm6w-2f55-rh45.json new file mode 100644 index 00000000000..5c55ed562c8 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-qm6w-2f55-rh45/GHSA-qm6w-2f55-rh45.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qm6w-2f55-rh45", + "modified": "2024-12-09T15:31:35Z", + "published": "2024-12-09T15:31:35Z", + "aliases": [ + "CVE-2023-48274" + ], + "details": "Missing Authorization vulnerability in Mondial Relay WooCommerce - WCMultiShipping WCMultiShipping allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WCMultiShipping: from n/a through 2.3.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48274" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wc-multishipping/vulnerability/wordpress-wcmultishipping-plugin-2-3-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-qmxm-x2qg-2r9p/GHSA-qmxm-x2qg-2r9p.json b/advisories/unreviewed/2024/12/GHSA-qmxm-x2qg-2r9p/GHSA-qmxm-x2qg-2r9p.json new file mode 100644 index 00000000000..b7b5950e36e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-qmxm-x2qg-2r9p/GHSA-qmxm-x2qg-2r9p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qmxm-x2qg-2r9p", + "modified": "2024-12-09T15:31:33Z", + "published": "2024-12-09T15:31:33Z", + "aliases": [ + "CVE-2023-23893" + ], + "details": "Missing Authorization vulnerability in Igor Benic Simple Giveaways allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Giveaways: from n/a through 2.48.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23893" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/giveasap/vulnerability/wordpress-simple-giveaways-plugin-2-45-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-qp8h-4cp3-g746/GHSA-qp8h-4cp3-g746.json b/advisories/unreviewed/2024/12/GHSA-qp8h-4cp3-g746/GHSA-qp8h-4cp3-g746.json new file mode 100644 index 00000000000..9be17b76699 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-qp8h-4cp3-g746/GHSA-qp8h-4cp3-g746.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qp8h-4cp3-g746", + "modified": "2024-12-09T15:31:35Z", + "published": "2024-12-09T15:31:35Z", + "aliases": [ + "CVE-2023-48332" + ], + "details": "Missing Authorization vulnerability in Tech Banker Mail Bank - #1 Mail SMTP Plugin for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mail Bank - #1 Mail SMTP Plugin for WordPress: from n/a through 4.0.14.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48332" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-mail-bank/vulnerability/wordpress-mail-bank-1-mail-smtp-plugin-for-wordpress-plugin-4-0-14-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-qpgf-q5wp-qpqp/GHSA-qpgf-q5wp-qpqp.json b/advisories/unreviewed/2024/12/GHSA-qpgf-q5wp-qpqp/GHSA-qpgf-q5wp-qpqp.json new file mode 100644 index 00000000000..fc88a3f1d92 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-qpgf-q5wp-qpqp/GHSA-qpgf-q5wp-qpqp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qpgf-q5wp-qpqp", + "modified": "2024-12-09T15:31:35Z", + "published": "2024-12-09T15:31:35Z", + "aliases": [ + "CVE-2023-49154" + ], + "details": "Missing Authorization vulnerability in Wow-Company Button Generator – easily Button Builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Button Generator – easily Button Builder: from n/a through 2.3.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49154" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/button-generation/vulnerability/wordpress-button-generator-easily-button-builder-plugin-2-3-8-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-qph7-p75r-xpc6/GHSA-qph7-p75r-xpc6.json b/advisories/unreviewed/2024/12/GHSA-qph7-p75r-xpc6/GHSA-qph7-p75r-xpc6.json new file mode 100644 index 00000000000..3cb8e81f08c --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-qph7-p75r-xpc6/GHSA-qph7-p75r-xpc6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qph7-p75r-xpc6", + "modified": "2024-12-09T15:31:35Z", + "published": "2024-12-09T15:31:35Z", + "aliases": [ + "CVE-2023-48287" + ], + "details": "Missing Authorization vulnerability in Matat Technologies TextMe SMS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TextMe SMS: from n/a through 1.9.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48287" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/textme-sms-integration/vulnerability/wordpress-textme-sms-plugin-1-9-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-qqm5-7q57-5m9g/GHSA-qqm5-7q57-5m9g.json b/advisories/unreviewed/2024/12/GHSA-qqm5-7q57-5m9g/GHSA-qqm5-7q57-5m9g.json new file mode 100644 index 00000000000..23fead2ecee --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-qqm5-7q57-5m9g/GHSA-qqm5-7q57-5m9g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qqm5-7q57-5m9g", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:33Z", + "aliases": [ + "CVE-2023-25048" + ], + "details": "Missing Authorization vulnerability in Fantastic Plugins Fantastic Content Protector Free allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fantastic Content Protector Free: from n/a through 2.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25048" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/fantastic-content-protector-free/vulnerability/wordpress-fantastic-content-protector-free-plugin-2-6-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-qr3r-vcc5-4j52/GHSA-qr3r-vcc5-4j52.json b/advisories/unreviewed/2024/12/GHSA-qr3r-vcc5-4j52/GHSA-qr3r-vcc5-4j52.json new file mode 100644 index 00000000000..a6ff53ee31f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-qr3r-vcc5-4j52/GHSA-qr3r-vcc5-4j52.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qr3r-vcc5-4j52", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-26522" + ], + "details": "Missing Authorization vulnerability in OneWebsite WP Repost allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Repost: from n/a through 0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26522" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-repost/vulnerability/wordpress-wp-repost-plugin-0-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-r84c-c4fr-6449/GHSA-r84c-c4fr-6449.json b/advisories/unreviewed/2024/12/GHSA-r84c-c4fr-6449/GHSA-r84c-c4fr-6449.json new file mode 100644 index 00000000000..543650c6688 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-r84c-c4fr-6449/GHSA-r84c-c4fr-6449.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r84c-c4fr-6449", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2024-54223" + ], + "details": "Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Contact Form - Repute InfoSystems ARForms Form Builder allows Code Injection.This issue affects ARForms Form Builder: from n/a through 1.7.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54223" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/arforms-form-builder/vulnerability/wordpress-arforms-plugin-1-7-1-html-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-80" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-r88m-8h9q-9488/GHSA-r88m-8h9q-9488.json b/advisories/unreviewed/2024/12/GHSA-r88m-8h9q-9488/GHSA-r88m-8h9q-9488.json new file mode 100644 index 00000000000..ef8dd3b1bdc --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-r88m-8h9q-9488/GHSA-r88m-8h9q-9488.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r88m-8h9q-9488", + "modified": "2024-12-09T15:31:37Z", + "published": "2024-12-09T15:31:37Z", + "aliases": [ + "CVE-2024-54260" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BlazeThemes News Kit Elementor Addons allows Stored XSS.This issue affects News Kit Elementor Addons: from n/a through 1.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54260" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/news-kit-elementor-addons/vulnerability/wordpress-news-kit-elementor-addons-plugin-1-2-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-rfxf-qhcv-3p8m/GHSA-rfxf-qhcv-3p8m.json b/advisories/unreviewed/2024/12/GHSA-rfxf-qhcv-3p8m/GHSA-rfxf-qhcv-3p8m.json new file mode 100644 index 00000000000..7ff7a4cac24 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-rfxf-qhcv-3p8m/GHSA-rfxf-qhcv-3p8m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rfxf-qhcv-3p8m", + "modified": "2024-12-09T15:31:35Z", + "published": "2024-12-09T15:31:35Z", + "aliases": [ + "CVE-2023-47764" + ], + "details": "Missing Authorization vulnerability in Metaphor Creations Ditty allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ditty: from n/a through 3.1.24.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47764" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ditty-news-ticker/vulnerability/wordpress-ditty-plugin-3-1-24-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-rg87-prc5-ccmm/GHSA-rg87-prc5-ccmm.json b/advisories/unreviewed/2024/12/GHSA-rg87-prc5-ccmm/GHSA-rg87-prc5-ccmm.json new file mode 100644 index 00000000000..80bbda9cf88 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-rg87-prc5-ccmm/GHSA-rg87-prc5-ccmm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rg87-prc5-ccmm", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-25037" + ], + "details": "Missing Authorization vulnerability in CodePeople Booking Calendar Contact Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking Calendar Contact Form: from n/a through 1.2.34.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25037" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/booking-calendar-contact-form/vulnerability/wordpress-booking-calendar-contact-form-plugin-1-2-34-broken-access-control?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-rm5f-jhvh-qv4j/GHSA-rm5f-jhvh-qv4j.json b/advisories/unreviewed/2024/12/GHSA-rm5f-jhvh-qv4j/GHSA-rm5f-jhvh-qv4j.json new file mode 100644 index 00000000000..302da816197 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-rm5f-jhvh-qv4j/GHSA-rm5f-jhvh-qv4j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rm5f-jhvh-qv4j", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2023-50904" + ], + "details": "Missing Authorization vulnerability in Poll Maker Team Poll Maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Poll Maker: from n/a through 4.8.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50904" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/poll-maker/vulnerability/wordpress-poll-maker-plugin-4-8-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-rpfq-4x8m-967r/GHSA-rpfq-4x8m-967r.json b/advisories/unreviewed/2024/12/GHSA-rpfq-4x8m-967r/GHSA-rpfq-4x8m-967r.json new file mode 100644 index 00000000000..85639a6fec5 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-rpfq-4x8m-967r/GHSA-rpfq-4x8m-967r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rpfq-4x8m-967r", + "modified": "2024-12-09T15:31:33Z", + "published": "2024-12-09T15:31:33Z", + "aliases": [ + "CVE-2023-25035" + ], + "details": "Missing Authorization vulnerability in Fullworks Quick Contact Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quick Contact Form : from n/a through 8.0.3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25035" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/quick-contact-form/vulnerability/wordpress-quick-contact-form-plugin-8-0-3-1-broken-access-control?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-rqfj-2r57-4f86/GHSA-rqfj-2r57-4f86.json b/advisories/unreviewed/2024/12/GHSA-rqfj-2r57-4f86/GHSA-rqfj-2r57-4f86.json new file mode 100644 index 00000000000..a9bab8f6ca9 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-rqfj-2r57-4f86/GHSA-rqfj-2r57-4f86.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rqfj-2r57-4f86", + "modified": "2024-12-09T15:31:35Z", + "published": "2024-12-09T15:31:35Z", + "aliases": [ + "CVE-2023-47763" + ], + "details": "Missing Authorization vulnerability in Martin Gibson WP Custom Admin Interface allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Custom Admin Interface: from n/a through 7.31.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47763" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-custom-admin-interface/vulnerability/wordpress-wp-custom-admin-interface-plugin-7-31-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-rv3p-vjhh-pg58/GHSA-rv3p-vjhh-pg58.json b/advisories/unreviewed/2024/12/GHSA-rv3p-vjhh-pg58/GHSA-rv3p-vjhh-pg58.json new file mode 100644 index 00000000000..fb27373302b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-rv3p-vjhh-pg58/GHSA-rv3p-vjhh-pg58.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rv3p-vjhh-pg58", + "modified": "2024-12-09T15:31:33Z", + "published": "2024-12-09T15:31:33Z", + "aliases": [ + "CVE-2023-23726" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Tickera.com Tickera allows Cross Site Request Forgery.This issue affects Tickera: from n/a through 3.5.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23726" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/tickera-event-ticketing-system/vulnerability/wordpress-tickera-wordpress-event-ticketing-plugin-3-5-1-0-csrf-leading-to-post-status-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-rvpq-4xw9-453j/GHSA-rvpq-4xw9-453j.json b/advisories/unreviewed/2024/12/GHSA-rvpq-4xw9-453j/GHSA-rvpq-4xw9-453j.json new file mode 100644 index 00000000000..18697cec511 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-rvpq-4xw9-453j/GHSA-rvpq-4xw9-453j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rvpq-4xw9-453j", + "modified": "2024-12-09T15:31:37Z", + "published": "2024-12-09T15:31:37Z", + "aliases": [ + "CVE-2024-38485" + ], + "details": "Dell ECS, versions prior to 3.8.0, contain(s) a Host Header Injection Vulnerability. A remote low-privileged attacker could potentially exploit this vulnerability to trigger redirections that leads to sensitive information leakage.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38485" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000256185/dsa-2024-331-security-update-for-dell-ecs-host-header-injection-vulnerability" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-rwxq-q4cp-87g5/GHSA-rwxq-q4cp-87g5.json b/advisories/unreviewed/2024/12/GHSA-rwxq-q4cp-87g5/GHSA-rwxq-q4cp-87g5.json new file mode 100644 index 00000000000..e42b18b9cc2 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-rwxq-q4cp-87g5/GHSA-rwxq-q4cp-87g5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rwxq-q4cp-87g5", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2023-51362" + ], + "details": "Missing Authorization vulnerability in Premio All-in-one Floating Contact Form – My Sticky Elements allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects All-in-one Floating Contact Form – My Sticky Elements: from n/a through 2.1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51362" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mystickyelements/vulnerability/wordpress-mystickyelements-plugin-2-1-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-v59g-pmpc-vmvg/GHSA-v59g-pmpc-vmvg.json b/advisories/unreviewed/2024/12/GHSA-v59g-pmpc-vmvg/GHSA-v59g-pmpc-vmvg.json new file mode 100644 index 00000000000..24619191548 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-v59g-pmpc-vmvg/GHSA-v59g-pmpc-vmvg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v59g-pmpc-vmvg", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-29431" + ], + "details": "Missing Authorization vulnerability in OntheGoSystems qTranslate X Cleanup and WPML Import allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects qTranslate X Cleanup and WPML Import: from n/a through 3.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29431" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/qtranslate-to-wpml-export/vulnerability/wordpress-qtranslate-x-cleanup-and-wpml-import-plugin-3-0-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-vh4v-g9hc-rcvv/GHSA-vh4v-g9hc-rcvv.json b/advisories/unreviewed/2024/12/GHSA-vh4v-g9hc-rcvv/GHSA-vh4v-g9hc-rcvv.json new file mode 100644 index 00000000000..e978d71d10c --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-vh4v-g9hc-rcvv/GHSA-vh4v-g9hc-rcvv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vh4v-g9hc-rcvv", + "modified": "2024-12-09T15:31:35Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-32299" + ], + "details": "Missing Authorization vulnerability in anzia Ni WooCommerce Sales Report allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ni WooCommerce Sales Report: from n/a through 3.7.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32299" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ni-woocommerce-sales-report/vulnerability/wordpress-ni-woocommerce-sales-report-plugin-3-7-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-vjvv-cmmx-vj53/GHSA-vjvv-cmmx-vj53.json b/advisories/unreviewed/2024/12/GHSA-vjvv-cmmx-vj53/GHSA-vjvv-cmmx-vj53.json new file mode 100644 index 00000000000..b85ab1e7015 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-vjvv-cmmx-vj53/GHSA-vjvv-cmmx-vj53.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vjvv-cmmx-vj53", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-30476" + ], + "details": "Missing Authorization vulnerability in Sparkle Themes Blogger Buzz allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Blogger Buzz: from n/a through 1.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30476" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/blogger-buzz/vulnerability/wordpress-blogger-buzz-theme-1-2-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-vm52-xw7f-3537/GHSA-vm52-xw7f-3537.json b/advisories/unreviewed/2024/12/GHSA-vm52-xw7f-3537/GHSA-vm52-xw7f-3537.json new file mode 100644 index 00000000000..a11b4505e26 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-vm52-xw7f-3537/GHSA-vm52-xw7f-3537.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vm52-xw7f-3537", + "modified": "2024-12-09T15:31:33Z", + "published": "2024-12-09T15:31:33Z", + "aliases": [ + "CVE-2023-24407" + ], + "details": "Missing Authorization vulnerability in WpDevArt Booking calendar, Appointment Booking System allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking calendar, Appointment Booking System: from n/a through 3.2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24407" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/booking-calendar/vulnerability/wordpress-booking-calendar-appointment-booking-system-plugin-3-2-3-broken-access-control?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-vr93-pf7q-jvm8/GHSA-vr93-pf7q-jvm8.json b/advisories/unreviewed/2024/12/GHSA-vr93-pf7q-jvm8/GHSA-vr93-pf7q-jvm8.json new file mode 100644 index 00000000000..eabe776e9cf --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-vr93-pf7q-jvm8/GHSA-vr93-pf7q-jvm8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vr93-pf7q-jvm8", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2023-50903" + ], + "details": "Missing Authorization vulnerability in Wpmet Metform Elementor Contact Form Builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Metform Elementor Contact Form Builder: from n/a through 3.4.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50903" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/metform/vulnerability/wordpress-metform-elementor-contact-form-builder-plugin-3-4-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-vrx9-xvm5-2pqp/GHSA-vrx9-xvm5-2pqp.json b/advisories/unreviewed/2024/12/GHSA-vrx9-xvm5-2pqp/GHSA-vrx9-xvm5-2pqp.json new file mode 100644 index 00000000000..f2fc6b90778 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-vrx9-xvm5-2pqp/GHSA-vrx9-xvm5-2pqp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vrx9-xvm5-2pqp", + "modified": "2024-12-09T15:31:37Z", + "published": "2024-12-09T15:31:37Z", + "aliases": [ + "CVE-2024-54253" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xpro Xpro Elementor Addons allows Stored XSS.This issue affects Xpro Elementor Addons: from n/a through 1.4.6.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54253" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/xpro-elementor-addons/vulnerability/wordpress-xpro-addons-for-elementor-plugin-1-4-6-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-vwwm-hx4x-6w7w/GHSA-vwwm-hx4x-6w7w.json b/advisories/unreviewed/2024/12/GHSA-vwwm-hx4x-6w7w/GHSA-vwwm-hx4x-6w7w.json new file mode 100644 index 00000000000..3713cd06618 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-vwwm-hx4x-6w7w/GHSA-vwwm-hx4x-6w7w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vwwm-hx4x-6w7w", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-25993" + ], + "details": "Missing Authorization vulnerability in WebberZone Top 10 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Top 10: from n/a through 3.2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25993" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/top-10/vulnerability/wordpress-top-10-popular-posts-plugin-for-wordpress-plugin-3-2-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-w2gm-7jp2-rvwh/GHSA-w2gm-7jp2-rvwh.json b/advisories/unreviewed/2024/12/GHSA-w2gm-7jp2-rvwh/GHSA-w2gm-7jp2-rvwh.json new file mode 100644 index 00000000000..ae8bbf9bba7 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-w2gm-7jp2-rvwh/GHSA-w2gm-7jp2-rvwh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w2gm-7jp2-rvwh", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2024-53819" + ], + "details": "Missing Authorization vulnerability in Sprout Invoices Client Invoicing by Sprout Invoices.This issue affects Client Invoicing by Sprout Invoices: from n/a through 20.8.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53819" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/sprout-invoices/vulnerability/wordpress-client-invoicing-by-sprout-invoices-plugin-20-8-0-insecure-direct-object-references-idor-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-w528-j4p6-w8vf/GHSA-w528-j4p6-w8vf.json b/advisories/unreviewed/2024/12/GHSA-w528-j4p6-w8vf/GHSA-w528-j4p6-w8vf.json new file mode 100644 index 00000000000..866194aa412 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-w528-j4p6-w8vf/GHSA-w528-j4p6-w8vf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w528-j4p6-w8vf", + "modified": "2024-12-09T15:31:35Z", + "published": "2024-12-09T15:31:35Z", + "aliases": [ + "CVE-2023-49196" + ], + "details": "Missing Authorization vulnerability in Pagelayer Team PageLayer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PageLayer: from n/a through 1.7.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49196" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/pagelayer/vulnerability/wordpress-pagelayer-plugin-1-7-7-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-w6jh-67xj-pjf8/GHSA-w6jh-67xj-pjf8.json b/advisories/unreviewed/2024/12/GHSA-w6jh-67xj-pjf8/GHSA-w6jh-67xj-pjf8.json new file mode 100644 index 00000000000..336d5172f2e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-w6jh-67xj-pjf8/GHSA-w6jh-67xj-pjf8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w6jh-67xj-pjf8", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-25486" + ], + "details": "Missing Authorization vulnerability in Migrate Clone allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Clone: from n/a through 2.3.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25486" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-clone-by-wp-academy/vulnerability/wordpress-clone-plugin-2-3-7-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-w736-w3q9-w9gq/GHSA-w736-w3q9-w9gq.json b/advisories/unreviewed/2024/12/GHSA-w736-w3q9-w9gq/GHSA-w736-w3q9-w9gq.json new file mode 100644 index 00000000000..0316a122477 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-w736-w3q9-w9gq/GHSA-w736-w3q9-w9gq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w736-w3q9-w9gq", + "modified": "2024-12-09T15:31:33Z", + "published": "2024-12-09T15:31:33Z", + "aliases": [ + "CVE-2023-23825" + ], + "details": "Missing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through 2.3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23825" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ultimate-addons-for-gutenberg/vulnerability/wordpress-spectra-wordpress-gutenberg-blocks-plugin-2-3-0-broken-access-control-csrf-on-import-wpforms-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-w925-jm2w-6qhw/GHSA-w925-jm2w-6qhw.json b/advisories/unreviewed/2024/12/GHSA-w925-jm2w-6qhw/GHSA-w925-jm2w-6qhw.json new file mode 100644 index 00000000000..2c0d385a4a1 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-w925-jm2w-6qhw/GHSA-w925-jm2w-6qhw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w925-jm2w-6qhw", + "modified": "2024-12-09T15:31:33Z", + "published": "2024-12-09T15:31:33Z", + "aliases": [ + "CVE-2023-22701" + ], + "details": "Missing Authorization vulnerability in Shopfiles Ltd Ebook Store allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ebook Store: from n/a through 5.775.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22701" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ebook-store/vulnerability/wordpress-ebook-store-plugin-5-775-broken-authentication-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-wc2c-7p6r-2qq8/GHSA-wc2c-7p6r-2qq8.json b/advisories/unreviewed/2024/12/GHSA-wc2c-7p6r-2qq8/GHSA-wc2c-7p6r-2qq8.json index 530859e0dec..264bdd87a35 100644 --- a/advisories/unreviewed/2024/12/GHSA-wc2c-7p6r-2qq8/GHSA-wc2c-7p6r-2qq8.json +++ b/advisories/unreviewed/2024/12/GHSA-wc2c-7p6r-2qq8/GHSA-wc2c-7p6r-2qq8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wc2c-7p6r-2qq8", - "modified": "2024-12-06T18:30:45Z", + "modified": "2024-12-09T15:31:33Z", "published": "2024-12-06T18:30:45Z", "aliases": [ "CVE-2024-54747" ], "details": "WAVLINK WN531P3 202383 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-276" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-06T16:15:22Z" diff --git a/advisories/unreviewed/2024/12/GHSA-wc68-rh2f-56m4/GHSA-wc68-rh2f-56m4.json b/advisories/unreviewed/2024/12/GHSA-wc68-rh2f-56m4/GHSA-wc68-rh2f-56m4.json new file mode 100644 index 00000000000..40fd6f50d34 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-wc68-rh2f-56m4/GHSA-wc68-rh2f-56m4.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wc68-rh2f-56m4", + "modified": "2024-12-09T15:31:37Z", + "published": "2024-12-09T15:31:37Z", + "aliases": [ + "CVE-2024-54937" + ], + "details": "A Directory Listing issue was found in Kashipara E-Learning Management System v1.0, which allows remote attackers to access sensitive files and directories via /admin/assets.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54937" + }, + { + "type": "WEB", + "url": "https://github.com/m14r41/Writeups/blob/main/CVE/Kashipara/E-learning%20Management%20System%20project/Directory%20listing%20-%20admin-assets.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T14:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-wc75-5h8q-v66g/GHSA-wc75-5h8q-v66g.json b/advisories/unreviewed/2024/12/GHSA-wc75-5h8q-v66g/GHSA-wc75-5h8q-v66g.json new file mode 100644 index 00000000000..b17dda572ef --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-wc75-5h8q-v66g/GHSA-wc75-5h8q-v66g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wc75-5h8q-v66g", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2024-54226" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Karl Kiesinger Country Blocker allows Stored XSS.This issue affects Country Blocker: from n/a through 3.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54226" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/country-blocker/vulnerability/wordpress-country-blocker-plugin-3-2-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-wcrv-pqj9-gq8r/GHSA-wcrv-pqj9-gq8r.json b/advisories/unreviewed/2024/12/GHSA-wcrv-pqj9-gq8r/GHSA-wcrv-pqj9-gq8r.json new file mode 100644 index 00000000000..b7623cd63bc --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-wcrv-pqj9-gq8r/GHSA-wcrv-pqj9-gq8r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wcrv-pqj9-gq8r", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2024-54219" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Thehp AIO Contact.This issue affects AIO Contact: from n/a through 2.8.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54219" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/aio-contact/vulnerability/wordpress-aio-contact-plugin-2-8-1-unauthenticated-site-wide-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-wpx9-v79v-w994/GHSA-wpx9-v79v-w994.json b/advisories/unreviewed/2024/12/GHSA-wpx9-v79v-w994/GHSA-wpx9-v79v-w994.json new file mode 100644 index 00000000000..bd8e7704a71 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-wpx9-v79v-w994/GHSA-wpx9-v79v-w994.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wpx9-v79v-w994", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2024-53818" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Post Grid Team by WPXPO PostX allows Stored XSS.This issue affects PostX: from n/a through 4.1.15.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53818" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ultimate-post/vulnerability/wordpress-postx-plugin-4-1-15-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-wr73-3cx2-482q/GHSA-wr73-3cx2-482q.json b/advisories/unreviewed/2024/12/GHSA-wr73-3cx2-482q/GHSA-wr73-3cx2-482q.json new file mode 100644 index 00000000000..ab6eaa49a3c --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-wr73-3cx2-482q/GHSA-wr73-3cx2-482q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wr73-3cx2-482q", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-25791" + ], + "details": "Missing Authorization vulnerability in Cadus Pro Fontiran allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fontiran: from n/a through 2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25791" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/fontiran/vulnerability/wordpress-fontiran-plugin-2-1-broken-access-control?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-wvgc-vf5q-hfmp/GHSA-wvgc-vf5q-hfmp.json b/advisories/unreviewed/2024/12/GHSA-wvgc-vf5q-hfmp/GHSA-wvgc-vf5q-hfmp.json new file mode 100644 index 00000000000..f65bb618449 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-wvgc-vf5q-hfmp/GHSA-wvgc-vf5q-hfmp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wvgc-vf5q-hfmp", + "modified": "2024-12-09T15:31:37Z", + "published": "2024-12-09T15:31:37Z", + "aliases": [ + "CVE-2024-54247" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ABCBiz ABCBiz Addons and Templates for Elementor allows Stored XSS.This issue affects ABCBiz Addons and Templates for Elementor: from n/a through 2.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54247" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/abcbiz-addons/vulnerability/wordpress-abcbiz-addons-and-templates-for-elementor-plugin-2-0-2-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-wxpf-x93m-88f8/GHSA-wxpf-x93m-88f8.json b/advisories/unreviewed/2024/12/GHSA-wxpf-x93m-88f8/GHSA-wxpf-x93m-88f8.json new file mode 100644 index 00000000000..556ea0295a1 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-wxpf-x93m-88f8/GHSA-wxpf-x93m-88f8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wxpf-x93m-88f8", + "modified": "2024-12-09T15:31:35Z", + "published": "2024-12-09T15:31:35Z", + "aliases": [ + "CVE-2023-47760" + ], + "details": "Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential Blocks for Gutenberg: from n/a through 4.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47760" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/essential-blocks/vulnerability/wordpress-essential-blocks-plugin-4-2-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-x64f-vf7p-w4x8/GHSA-x64f-vf7p-w4x8.json b/advisories/unreviewed/2024/12/GHSA-x64f-vf7p-w4x8/GHSA-x64f-vf7p-w4x8.json new file mode 100644 index 00000000000..21d5f2cfc30 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-x64f-vf7p-w4x8/GHSA-x64f-vf7p-w4x8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x64f-vf7p-w4x8", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-25959" + ], + "details": "Missing Authorization vulnerability in Apollo13Themes Apollo13 Framework Extensions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Apollo13 Framework Extensions: from n/a through 1.8.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25959" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/apollo13-framework-extensions/vulnerability/wordpress-apollo13-framework-extensions-plugin-1-8-10-broken-access-control?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-x667-jr9q-j93j/GHSA-x667-jr9q-j93j.json b/advisories/unreviewed/2024/12/GHSA-x667-jr9q-j93j/GHSA-x667-jr9q-j93j.json new file mode 100644 index 00000000000..0450af03596 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-x667-jr9q-j93j/GHSA-x667-jr9q-j93j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x667-jr9q-j93j", + "modified": "2024-12-09T15:31:35Z", + "published": "2024-12-09T15:31:35Z", + "aliases": [ + "CVE-2023-47820" + ], + "details": "Missing Authorization vulnerability in CRUDLab WP Like Button allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Like Button: from n/a through 1.7.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47820" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-like-button/vulnerability/wordpress-wp-like-button-plugin-1-7-0-broken-access-control-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-x68w-43xr-5pj2/GHSA-x68w-43xr-5pj2.json b/advisories/unreviewed/2024/12/GHSA-x68w-43xr-5pj2/GHSA-x68w-43xr-5pj2.json new file mode 100644 index 00000000000..a8259566441 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-x68w-43xr-5pj2/GHSA-x68w-43xr-5pj2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x68w-43xr-5pj2", + "modified": "2024-12-09T15:31:34Z", + "published": "2024-12-09T15:31:34Z", + "aliases": [ + "CVE-2023-32293" + ], + "details": "Missing Authorization vulnerability in Realwebcare WRC Pricing Tables allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WRC Pricing Tables: from n/a through 2.3.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32293" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wrc-pricing-tables/vulnerability/wordpress-wrc-pricing-tables-plugin-2-3-7-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-xcrg-8639-cf22/GHSA-xcrg-8639-cf22.json b/advisories/unreviewed/2024/12/GHSA-xcrg-8639-cf22/GHSA-xcrg-8639-cf22.json new file mode 100644 index 00000000000..62b15864220 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-xcrg-8639-cf22/GHSA-xcrg-8639-cf22.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xcrg-8639-cf22", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2023-49817" + ], + "details": "Missing Authorization vulnerability in heoLixfy Flexible Woocommerce Checkout Field Editor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Flexible Woocommerce Checkout Field Editor: from n/a through 2.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49817" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/flexible-woocommerce-checkout-field-editor/vulnerability/wordpress-flexible-woocommerce-checkout-field-editor-plugin-2-0-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-xgjj-x9g2-jxw7/GHSA-xgjj-x9g2-jxw7.json b/advisories/unreviewed/2024/12/GHSA-xgjj-x9g2-jxw7/GHSA-xgjj-x9g2-jxw7.json new file mode 100644 index 00000000000..01bb5cf54cc --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-xgjj-x9g2-jxw7/GHSA-xgjj-x9g2-jxw7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xgjj-x9g2-jxw7", + "modified": "2024-12-09T15:31:36Z", + "published": "2024-12-09T15:31:36Z", + "aliases": [ + "CVE-2024-53822" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Genetech Pie Register Premium.This issue affects Pie Register Premium: from n/a before 3.8.3.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53822" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/pie-register-premium/vulnerability/wordpress-pie-register-premium-plugin-3-8-3-3-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-xhpp-qjw5-78w2/GHSA-xhpp-qjw5-78w2.json b/advisories/unreviewed/2024/12/GHSA-xhpp-qjw5-78w2/GHSA-xhpp-qjw5-78w2.json new file mode 100644 index 00000000000..34af0f1bee3 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-xhpp-qjw5-78w2/GHSA-xhpp-qjw5-78w2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xhpp-qjw5-78w2", + "modified": "2024-12-09T15:31:35Z", + "published": "2024-12-09T15:31:35Z", + "aliases": [ + "CVE-2023-47762" + ], + "details": "Missing Authorization vulnerability in WPDeveloper BetterDocs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BetterDocs: from n/a through 2.5.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47762" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/betterdocs/vulnerability/wordpress-betterdocs-plugin-2-5-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-xhrx-h7vh-5v4q/GHSA-xhrx-h7vh-5v4q.json b/advisories/unreviewed/2024/12/GHSA-xhrx-h7vh-5v4q/GHSA-xhrx-h7vh-5v4q.json new file mode 100644 index 00000000000..908a5145ff5 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-xhrx-h7vh-5v4q/GHSA-xhrx-h7vh-5v4q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xhrx-h7vh-5v4q", + "modified": "2024-12-09T15:31:33Z", + "published": "2024-12-09T15:31:33Z", + "aliases": [ + "CVE-2023-23725" + ], + "details": "Missing Authorization vulnerability in Chris Baldelomar Shortcodes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Shortcodes: from n/a through 3.46.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23725" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wc-shortcodes/vulnerability/wordpress-shortcodes-by-angie-makes-plugin-3-46-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-xv9g-hfxf-cg8g/GHSA-xv9g-hfxf-cg8g.json b/advisories/unreviewed/2024/12/GHSA-xv9g-hfxf-cg8g/GHSA-xv9g-hfxf-cg8g.json new file mode 100644 index 00000000000..8dba05279eb --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-xv9g-hfxf-cg8g/GHSA-xv9g-hfxf-cg8g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xv9g-hfxf-cg8g", + "modified": "2024-12-09T15:31:35Z", + "published": "2024-12-09T15:31:35Z", + "aliases": [ + "CVE-2023-47805" + ], + "details": "Missing Authorization vulnerability in Themewinter WPCafe allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPCafe: from n/a through 2.2.22.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47805" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-cafe/vulnerability/wordpress-wpcafe-plugin-2-2-19-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T13:15:30Z" + } +} \ No newline at end of file