diff --git a/advisories/unreviewed/2024/07/GHSA-2g58-2r94-f674/GHSA-2g58-2r94-f674.json b/advisories/unreviewed/2024/07/GHSA-2g58-2r94-f674/GHSA-2g58-2r94-f674.json new file mode 100644 index 00000000000..51baed14fc3 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-2g58-2r94-f674/GHSA-2g58-2r94-f674.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2g58-2r94-f674", + "modified": "2024-07-31T12:31:48Z", + "published": "2024-07-31T12:31:48Z", + "aliases": [ + "CVE-2024-7321" + ], + "details": "A vulnerability classified as problematic was found in itsourcecode Online Blood Bank Management System 1.0. This vulnerability affects unknown code of the file signup.php of the component User Registration Handler. The manipulation of the argument user leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273232.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7321" + }, + { + "type": "WEB", + "url": "https://github.com/cl4irv0yance/CVEs/issues/4" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.273232" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.273232" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.383437" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-31T12:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-8235-8498-xmmj/GHSA-8235-8498-xmmj.json b/advisories/unreviewed/2024/07/GHSA-8235-8498-xmmj/GHSA-8235-8498-xmmj.json new file mode 100644 index 00000000000..f11ff7bd09e --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-8235-8498-xmmj/GHSA-8235-8498-xmmj.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8235-8498-xmmj", + "modified": "2024-07-31T12:31:47Z", + "published": "2024-07-31T12:31:47Z", + "aliases": [ + "CVE-2024-7310" + ], + "details": "A vulnerability was found in SourceCodester Record Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file sort_user.php. The manipulation of the argument sort leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-273202 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7310" + }, + { + "type": "WEB", + "url": "https://github.com/zw-a11y/VUL/blob/main/Record-Management-System-2.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.273202" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.273202" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.382507" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-31T10:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-8v62-x5cp-8hx4/GHSA-8v62-x5cp-8hx4.json b/advisories/unreviewed/2024/07/GHSA-8v62-x5cp-8hx4/GHSA-8v62-x5cp-8hx4.json new file mode 100644 index 00000000000..532b2e7f586 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-8v62-x5cp-8hx4/GHSA-8v62-x5cp-8hx4.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8v62-x5cp-8hx4", + "modified": "2024-07-31T12:31:48Z", + "published": "2024-07-31T12:31:48Z", + "aliases": [ + "CVE-2024-7135" + ], + "details": "The Tainacan plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_file' function in all versions up to, and including, 0.21.7. The function is also vulnerable to directory traversal. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7135" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/tainacan/trunk/classes/api/endpoints/class-tainacan-rest-background-processes-controller.php#L370" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/tainacan/trunk/classes/api/endpoints/class-tainacan-rest-background-processes-controller.php#L378" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3127693" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e4dd0c6a-75af-4b53-ac13-fc4ef0e9001d?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-31T11:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-97c4-2w4v-c7r8/GHSA-97c4-2w4v-c7r8.json b/advisories/unreviewed/2024/07/GHSA-97c4-2w4v-c7r8/GHSA-97c4-2w4v-c7r8.json index aedfc9541f7..7da6aca3297 100644 --- a/advisories/unreviewed/2024/07/GHSA-97c4-2w4v-c7r8/GHSA-97c4-2w4v-c7r8.json +++ b/advisories/unreviewed/2024/07/GHSA-97c4-2w4v-c7r8/GHSA-97c4-2w4v-c7r8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-97c4-2w4v-c7r8", - "modified": "2024-07-31T09:30:49Z", + "modified": "2024-07-31T12:31:47Z", "published": "2024-07-31T09:30:49Z", "aliases": [ "CVE-2024-7264" @@ -29,6 +29,10 @@ { "type": "WEB", "url": "https://curl.se/docs/CVE-2024-7264.json" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/07/31/1" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-9xxq-vvgh-v3r9/GHSA-9xxq-vvgh-v3r9.json b/advisories/unreviewed/2024/07/GHSA-9xxq-vvgh-v3r9/GHSA-9xxq-vvgh-v3r9.json index b7ef24b1921..1305f9031f3 100644 --- a/advisories/unreviewed/2024/07/GHSA-9xxq-vvgh-v3r9/GHSA-9xxq-vvgh-v3r9.json +++ b/advisories/unreviewed/2024/07/GHSA-9xxq-vvgh-v3r9/GHSA-9xxq-vvgh-v3r9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9xxq-vvgh-v3r9", - "modified": "2024-07-23T18:31:07Z", + "modified": "2024-07-31T12:31:47Z", "published": "2024-07-23T15:31:09Z", "aliases": [ "CVE-2024-1737" @@ -32,6 +32,10 @@ { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/07/23/1" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/07/31/2" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-gfw8-mh94-9w58/GHSA-gfw8-mh94-9w58.json b/advisories/unreviewed/2024/07/GHSA-gfw8-mh94-9w58/GHSA-gfw8-mh94-9w58.json index 6a56eb8192d..2fd6fc2103a 100644 --- a/advisories/unreviewed/2024/07/GHSA-gfw8-mh94-9w58/GHSA-gfw8-mh94-9w58.json +++ b/advisories/unreviewed/2024/07/GHSA-gfw8-mh94-9w58/GHSA-gfw8-mh94-9w58.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gfw8-mh94-9w58", - "modified": "2024-07-23T18:31:07Z", + "modified": "2024-07-31T12:31:47Z", "published": "2024-07-23T15:31:09Z", "aliases": [ "CVE-2024-4076" @@ -28,6 +28,10 @@ { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/07/23/1" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/07/31/2" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-hmw7-rcmw-2wqj/GHSA-hmw7-rcmw-2wqj.json b/advisories/unreviewed/2024/07/GHSA-hmw7-rcmw-2wqj/GHSA-hmw7-rcmw-2wqj.json new file mode 100644 index 00000000000..86017345a6a --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-hmw7-rcmw-2wqj/GHSA-hmw7-rcmw-2wqj.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hmw7-rcmw-2wqj", + "modified": "2024-07-31T12:31:47Z", + "published": "2024-07-31T12:31:47Z", + "aliases": [ + "CVE-2024-7309" + ], + "details": "A vulnerability was found in SourceCodester Record Management System 1.0. It has been classified as problematic. This affects an unknown part of the file entry.php. The manipulation of the argument school leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273201 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7309" + }, + { + "type": "WEB", + "url": "https://github.com/zw-a11y/VUL/blob/main/Record-Management-System-1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.273201" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.273201" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.382506" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-31T10:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-m695-893g-ffg2/GHSA-m695-893g-ffg2.json b/advisories/unreviewed/2024/07/GHSA-m695-893g-ffg2/GHSA-m695-893g-ffg2.json new file mode 100644 index 00000000000..50b943c1fd4 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-m695-893g-ffg2/GHSA-m695-893g-ffg2.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m695-893g-ffg2", + "modified": "2024-07-31T12:31:47Z", + "published": "2024-07-31T12:31:47Z", + "aliases": [ + "CVE-2024-6725" + ], + "details": "The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘html’ parameter in all versions up to, and including, 6.11.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with form editing permissions and Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6725" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/formidable/trunk/classes/models/fields/FrmFieldType.php#L875" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3128202" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/848cfa72-4211-4576-91c2-4f643e3161c3?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-31T11:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-qpfv-2pqx-cqjq/GHSA-qpfv-2pqx-cqjq.json b/advisories/unreviewed/2024/07/GHSA-qpfv-2pqx-cqjq/GHSA-qpfv-2pqx-cqjq.json new file mode 100644 index 00000000000..0af99145677 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-qpfv-2pqx-cqjq/GHSA-qpfv-2pqx-cqjq.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qpfv-2pqx-cqjq", + "modified": "2024-07-31T12:31:48Z", + "published": "2024-07-31T12:31:48Z", + "aliases": [ + "CVE-2024-7311" + ], + "details": "A vulnerability was found in code-projects Online Bus Reservation Site 1.0. It has been rated as critical. This issue affects some unknown processing of the file register.php. The manipulation of the argument Email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273203.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7311" + }, + { + "type": "WEB", + "url": "https://github.com/23588hk/cve/issues/1" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.273203" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.273203" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.383201" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-31T11:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-v3r3-642v-rqj8/GHSA-v3r3-642v-rqj8.json b/advisories/unreviewed/2024/07/GHSA-v3r3-642v-rqj8/GHSA-v3r3-642v-rqj8.json index beb8550c66e..095ef1c3e4b 100644 --- a/advisories/unreviewed/2024/07/GHSA-v3r3-642v-rqj8/GHSA-v3r3-642v-rqj8.json +++ b/advisories/unreviewed/2024/07/GHSA-v3r3-642v-rqj8/GHSA-v3r3-642v-rqj8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v3r3-642v-rqj8", - "modified": "2024-07-23T18:31:07Z", + "modified": "2024-07-31T12:31:46Z", "published": "2024-07-23T15:31:09Z", "aliases": [ "CVE-2024-0760" @@ -28,6 +28,10 @@ { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/07/23/1" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/07/31/2" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-w2gr-9pwc-5pm2/GHSA-w2gr-9pwc-5pm2.json b/advisories/unreviewed/2024/07/GHSA-w2gr-9pwc-5pm2/GHSA-w2gr-9pwc-5pm2.json new file mode 100644 index 00000000000..58f2380690d --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-w2gr-9pwc-5pm2/GHSA-w2gr-9pwc-5pm2.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w2gr-9pwc-5pm2", + "modified": "2024-07-31T12:31:48Z", + "published": "2024-07-31T12:31:48Z", + "aliases": [ + "CVE-2024-7320" + ], + "details": "A vulnerability classified as critical has been found in itsourcecode Online Blood Bank Management System 1.0. This affects an unknown part of the file /admin/index.php of the component Admin Login. The manipulation of the argument user leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273231.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7320" + }, + { + "type": "WEB", + "url": "https://github.com/cl4irv0yance/CVEs/issues/3" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.273231" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.273231" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.383397" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-31T11:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-xv2w-3fww-7hvf/GHSA-xv2w-3fww-7hvf.json b/advisories/unreviewed/2024/07/GHSA-xv2w-3fww-7hvf/GHSA-xv2w-3fww-7hvf.json index db82dc5a079..b11ff250998 100644 --- a/advisories/unreviewed/2024/07/GHSA-xv2w-3fww-7hvf/GHSA-xv2w-3fww-7hvf.json +++ b/advisories/unreviewed/2024/07/GHSA-xv2w-3fww-7hvf/GHSA-xv2w-3fww-7hvf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xv2w-3fww-7hvf", - "modified": "2024-07-23T18:31:07Z", + "modified": "2024-07-31T12:31:47Z", "published": "2024-07-23T15:31:09Z", "aliases": [ "CVE-2024-1975" @@ -28,6 +28,10 @@ { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/07/23/1" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/07/31/2" } ], "database_specific": {