From 4ca84d83c714ea87925ba7ade01fe28234a82edf Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 25 Sep 2024 03:32:08 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-6wvf-f2vw-3425.json | 6 +- .../GHSA-xjqm-c5w6-2r9x.json | 3 +- .../GHSA-45rh-q5fv-wf42.json | 6 +- .../GHSA-5568-g9wp-2cv7.json | 6 +- .../GHSA-3323-f6mh-57mx.json | 6 +- .../GHSA-5v64-89vr-vpwr.json | 6 +- .../GHSA-6c77-g3p7-g7ch.json | 6 +- .../GHSA-c2mc-q4gg-xgm7.json | 3 +- .../GHSA-m89f-h769-x259.json | 2 +- .../GHSA-q8p7-cg4r-8f76.json | 3 +- .../GHSA-28h8-8gfr-gwwm.json | 2 +- .../GHSA-3975-pf2x-843g.json | 2 +- .../GHSA-3jm2-mqgw-5jj8.json | 1 + .../GHSA-4xvr-ch6x-96mj.json | 1 + .../GHSA-5wxq-q7xr-cgpw.json | 2 +- .../GHSA-6h39-mx58-5ch2.json | 3 +- .../GHSA-6pgc-3w24-9rcw.json | 2 +- .../GHSA-6w8x-vrh5-r745.json | 3 +- .../GHSA-7w4f-p7cf-gqxq.json | 2 +- .../GHSA-8j5g-957r-vpvw.json | 1 + .../GHSA-8wm7-r267-8mqr.json | 2 +- .../GHSA-8x56-c587-3rqg.json | 3 +- .../GHSA-c2qv-7h5q-gh2f.json | 2 +- .../GHSA-cjp8-pj2w-v99h.json | 2 +- .../GHSA-f9x4-2mf9-q8x2.json | 1 + .../GHSA-fg7v-q6g2-52wh.json | 2 +- .../GHSA-g288-cc4f-69p8.json | 2 +- .../GHSA-gr6q-9m75-87c6.json | 2 +- .../GHSA-h58p-f4w7-jcpv.json | 3 +- .../GHSA-h724-w27c-6j67.json | 3 +- .../GHSA-hcvv-hp4h-gfwx.json | 2 +- .../GHSA-hmqw-w898-xwx8.json | 1 + .../GHSA-jp22-8r3p-f4wr.json | 1 + .../GHSA-m47m-h5jm-m7g4.json | 3 +- .../GHSA-pqcf-6fpm-w7j4.json | 3 +- .../GHSA-pw36-82xr-g6rw.json | 2 +- .../GHSA-q5x2-c4xq-2wmv.json | 2 +- .../GHSA-qw9q-7f95-xh3q.json | 1 + .../GHSA-rccm-547v-jf77.json | 2 +- .../GHSA-vhfm-hcpf-g55q.json | 2 +- .../GHSA-w8j8-gh53-mg37.json | 2 +- .../GHSA-wg68-3v48-jc2x.json | 2 +- .../GHSA-wjgm-r92h-xvvr.json | 2 +- .../GHSA-f2v5-p4rx-6wc2.json | 2 +- .../GHSA-qr26-2mpm-7j4x.json | 1 + .../GHSA-rgvf-j3x5-6277.json | 6 +- .../GHSA-fchp-8m28-g68f.json | 1 + .../GHSA-ffhx-2rrf-9c23.json | 6 +- .../GHSA-v9xm-vjq4-6r8q.json | 6 +- .../GHSA-74vq-jpr9-j6wj.json | 6 +- .../GHSA-7c7g-wccp-rrhj.json | 6 +- .../GHSA-rqmr-f8r9-69wq.json | 6 +- .../GHSA-2mqq-6v49-g869.json | 38 ++++++++++++ .../GHSA-3522-f7v7-pv57.json | 42 ++++++++++++++ .../GHSA-3hc5-r53w-6ph8.json | 38 ++++++++++++ .../GHSA-3hq4-wjf7-pw99.json | 46 +++++++++++++++ .../GHSA-3qcf-857g-5p4x.json | 38 ++++++++++++ .../GHSA-3qr7-fhm2-q3h8.json | 11 ++-- .../GHSA-3w2h-6gvg-jj2v.json | 9 ++- .../GHSA-3xm5-r3mx-685g.json | 42 ++++++++++++++ .../GHSA-4f4g-mjgj-wqjc.json | 42 ++++++++++++++ .../GHSA-4fw3-822r-pqw6.json | 39 +++++++++++++ .../GHSA-4x6v-7m8g-5v5x.json | 54 +++++++++++++++++ .../GHSA-52jr-7fqr-h29h.json | 38 ++++++++++++ .../GHSA-53c9-m2h7-5xhr.json | 9 ++- .../GHSA-563f-r8fh-rrgc.json | 42 ++++++++++++++ .../GHSA-564c-h2vx-x449.json | 54 +++++++++++++++++ .../GHSA-5cxp-2w3f-wh6m.json | 42 ++++++++++++++ .../GHSA-6375-pg5j-8wph.json | 39 +++++++++++++ .../GHSA-697p-23gh-47wj.json | 42 ++++++++++++++ .../GHSA-6pm7-68mw-p76q.json | 42 ++++++++++++++ .../GHSA-7fm9-f48p-wp4r.json | 46 +++++++++++++++ .../GHSA-7jvh-4mqp-gf66.json | 11 ++-- .../GHSA-7r3j-2p7m-rq9g.json | 50 ++++++++++++++++ .../GHSA-826x-99fw-6qrv.json | 42 ++++++++++++++ .../GHSA-8g8m-p65c-g42p.json | 38 ++++++++++++ .../GHSA-8m93-gvh9-j85x.json | 58 +++++++++++++++++++ .../GHSA-8mxg-6836-hfxw.json | 50 ++++++++++++++++ .../GHSA-8vp8-g29r-fxpf.json | 39 +++++++++++++ .../GHSA-8w9v-r586-45j6.json | 46 +++++++++++++++ .../GHSA-93ch-7fcj-pjpp.json | 46 +++++++++++++++ .../GHSA-98hf-m87w-cq6h.json | 42 ++++++++++++++ .../GHSA-9q33-jhxg-4ch5.json | 39 +++++++++++++ .../GHSA-c2c6-68mw-462f.json | 39 +++++++++++++ .../GHSA-c6jq-3xcg-q498.json | 42 ++++++++++++++ .../GHSA-cv79-5xmw-3x8r.json | 42 ++++++++++++++ .../GHSA-cwfh-p5vc-jcg4.json | 11 ++-- .../GHSA-cx8w-8pxg-9q94.json | 38 ++++++++++++ .../GHSA-cxp2-364h-667j.json | 42 ++++++++++++++ .../GHSA-f6r8-rvcx-qr37.json | 11 ++-- .../GHSA-f93h-pcqv-5rf7.json | 39 +++++++++++++ .../GHSA-f95m-8pg6-37q7.json | 46 +++++++++++++++ .../GHSA-fg7m-78jh-8697.json | 42 ++++++++++++++ .../GHSA-fjx8-c5r7-57qm.json | 42 ++++++++++++++ .../GHSA-g2fg-5q38-f4pv.json | 46 +++++++++++++++ .../GHSA-g68m-7q78-xjw3.json | 42 ++++++++++++++ .../GHSA-gpmc-p7f9-wcpr.json | 54 +++++++++++++++++ .../GHSA-gr7q-37gq-cg24.json | 46 +++++++++++++++ .../GHSA-gxh2-x2v6-99jr.json | 38 ++++++++++++ .../GHSA-h558-mxfr-c3px.json | 42 ++++++++++++++ .../GHSA-h55v-8rq9-7qx3.json | 42 ++++++++++++++ .../GHSA-h863-2hm3-rc4r.json | 42 ++++++++++++++ .../GHSA-h8vm-65gc-gw46.json | 38 ++++++++++++ .../GHSA-hwr4-f3g6-5mmp.json | 42 ++++++++++++++ .../GHSA-j287-529v-pjr9.json | 42 ++++++++++++++ .../GHSA-jc57-w67w-3ggw.json | 50 ++++++++++++++++ .../GHSA-m5p9-xvxj-64c8.json | 38 ++++++++++++ .../GHSA-mc8h-gfm5-j86q.json | 42 ++++++++++++++ .../GHSA-mrxm-9rwr-qw4f.json | 42 ++++++++++++++ .../GHSA-p2cr-39jq-4vw3.json | 38 ++++++++++++ .../GHSA-phjc-jpwh-fv7x.json | 42 ++++++++++++++ .../GHSA-pvc7-6xhm-95vf.json | 46 +++++++++++++++ .../GHSA-q7qr-22qw-pqgx.json | 50 ++++++++++++++++ .../GHSA-q97c-vhwv-v5w3.json | 42 ++++++++++++++ .../GHSA-qcr8-x9j3-5j62.json | 39 +++++++++++++ .../GHSA-qqwc-7hxc-6ghp.json | 42 ++++++++++++++ .../GHSA-qxr9-x265-vp39.json | 11 ++-- .../GHSA-r44h-cw52-2x2f.json | 38 ++++++++++++ .../GHSA-rm3j-jj6h-qrq4.json | 46 +++++++++++++++ .../GHSA-rxmx-cgf3-gfph.json | 11 ++-- .../GHSA-vj7c-8fv8-732h.json | 38 ++++++++++++ .../GHSA-w3jq-wqph-2fhr.json | 42 ++++++++++++++ .../GHSA-w72w-8rm9-6684.json | 42 ++++++++++++++ .../GHSA-wpw2-69v8-6f9h.json | 38 ++++++++++++ .../GHSA-wvhj-f7hf-4qv2.json | 38 ++++++++++++ .../GHSA-wx2g-pjx5-v6r9.json | 42 ++++++++++++++ .../GHSA-x4p5-53p5-3j33.json | 42 ++++++++++++++ .../GHSA-x8h2-255q-jg4x.json | 54 +++++++++++++++++ .../GHSA-xh87-v57g-jhpw.json | 39 +++++++++++++ .../GHSA-xhff-3q93-x4p6.json | 42 ++++++++++++++ .../GHSA-xpx9-f724-2jfc.json | 38 ++++++++++++ .../GHSA-xqjg-gmg7-72xr.json | 11 ++-- .../GHSA-xvwc-mxm8-8hqg.json | 38 ++++++++++++ .../GHSA-xwv3-34j2-7jgx.json | 43 ++++++++++++++ 134 files changed, 3282 insertions(+), 77 deletions(-) create mode 100644 advisories/unreviewed/2024/09/GHSA-2mqq-6v49-g869/GHSA-2mqq-6v49-g869.json create mode 100644 advisories/unreviewed/2024/09/GHSA-3522-f7v7-pv57/GHSA-3522-f7v7-pv57.json create mode 100644 advisories/unreviewed/2024/09/GHSA-3hc5-r53w-6ph8/GHSA-3hc5-r53w-6ph8.json create mode 100644 advisories/unreviewed/2024/09/GHSA-3hq4-wjf7-pw99/GHSA-3hq4-wjf7-pw99.json create mode 100644 advisories/unreviewed/2024/09/GHSA-3qcf-857g-5p4x/GHSA-3qcf-857g-5p4x.json create mode 100644 advisories/unreviewed/2024/09/GHSA-3xm5-r3mx-685g/GHSA-3xm5-r3mx-685g.json create mode 100644 advisories/unreviewed/2024/09/GHSA-4f4g-mjgj-wqjc/GHSA-4f4g-mjgj-wqjc.json create mode 100644 advisories/unreviewed/2024/09/GHSA-4fw3-822r-pqw6/GHSA-4fw3-822r-pqw6.json create mode 100644 advisories/unreviewed/2024/09/GHSA-4x6v-7m8g-5v5x/GHSA-4x6v-7m8g-5v5x.json create mode 100644 advisories/unreviewed/2024/09/GHSA-52jr-7fqr-h29h/GHSA-52jr-7fqr-h29h.json create mode 100644 advisories/unreviewed/2024/09/GHSA-563f-r8fh-rrgc/GHSA-563f-r8fh-rrgc.json create mode 100644 advisories/unreviewed/2024/09/GHSA-564c-h2vx-x449/GHSA-564c-h2vx-x449.json create mode 100644 advisories/unreviewed/2024/09/GHSA-5cxp-2w3f-wh6m/GHSA-5cxp-2w3f-wh6m.json create mode 100644 advisories/unreviewed/2024/09/GHSA-6375-pg5j-8wph/GHSA-6375-pg5j-8wph.json create mode 100644 advisories/unreviewed/2024/09/GHSA-697p-23gh-47wj/GHSA-697p-23gh-47wj.json create mode 100644 advisories/unreviewed/2024/09/GHSA-6pm7-68mw-p76q/GHSA-6pm7-68mw-p76q.json create mode 100644 advisories/unreviewed/2024/09/GHSA-7fm9-f48p-wp4r/GHSA-7fm9-f48p-wp4r.json create mode 100644 advisories/unreviewed/2024/09/GHSA-7r3j-2p7m-rq9g/GHSA-7r3j-2p7m-rq9g.json create mode 100644 advisories/unreviewed/2024/09/GHSA-826x-99fw-6qrv/GHSA-826x-99fw-6qrv.json create mode 100644 advisories/unreviewed/2024/09/GHSA-8g8m-p65c-g42p/GHSA-8g8m-p65c-g42p.json create mode 100644 advisories/unreviewed/2024/09/GHSA-8m93-gvh9-j85x/GHSA-8m93-gvh9-j85x.json create mode 100644 advisories/unreviewed/2024/09/GHSA-8mxg-6836-hfxw/GHSA-8mxg-6836-hfxw.json create mode 100644 advisories/unreviewed/2024/09/GHSA-8vp8-g29r-fxpf/GHSA-8vp8-g29r-fxpf.json create mode 100644 advisories/unreviewed/2024/09/GHSA-8w9v-r586-45j6/GHSA-8w9v-r586-45j6.json create mode 100644 advisories/unreviewed/2024/09/GHSA-93ch-7fcj-pjpp/GHSA-93ch-7fcj-pjpp.json create mode 100644 advisories/unreviewed/2024/09/GHSA-98hf-m87w-cq6h/GHSA-98hf-m87w-cq6h.json create mode 100644 advisories/unreviewed/2024/09/GHSA-9q33-jhxg-4ch5/GHSA-9q33-jhxg-4ch5.json create mode 100644 advisories/unreviewed/2024/09/GHSA-c2c6-68mw-462f/GHSA-c2c6-68mw-462f.json create mode 100644 advisories/unreviewed/2024/09/GHSA-c6jq-3xcg-q498/GHSA-c6jq-3xcg-q498.json create mode 100644 advisories/unreviewed/2024/09/GHSA-cv79-5xmw-3x8r/GHSA-cv79-5xmw-3x8r.json create mode 100644 advisories/unreviewed/2024/09/GHSA-cx8w-8pxg-9q94/GHSA-cx8w-8pxg-9q94.json create mode 100644 advisories/unreviewed/2024/09/GHSA-cxp2-364h-667j/GHSA-cxp2-364h-667j.json create mode 100644 advisories/unreviewed/2024/09/GHSA-f93h-pcqv-5rf7/GHSA-f93h-pcqv-5rf7.json create mode 100644 advisories/unreviewed/2024/09/GHSA-f95m-8pg6-37q7/GHSA-f95m-8pg6-37q7.json create mode 100644 advisories/unreviewed/2024/09/GHSA-fg7m-78jh-8697/GHSA-fg7m-78jh-8697.json create mode 100644 advisories/unreviewed/2024/09/GHSA-fjx8-c5r7-57qm/GHSA-fjx8-c5r7-57qm.json create mode 100644 advisories/unreviewed/2024/09/GHSA-g2fg-5q38-f4pv/GHSA-g2fg-5q38-f4pv.json create mode 100644 advisories/unreviewed/2024/09/GHSA-g68m-7q78-xjw3/GHSA-g68m-7q78-xjw3.json create mode 100644 advisories/unreviewed/2024/09/GHSA-gpmc-p7f9-wcpr/GHSA-gpmc-p7f9-wcpr.json create mode 100644 advisories/unreviewed/2024/09/GHSA-gr7q-37gq-cg24/GHSA-gr7q-37gq-cg24.json create mode 100644 advisories/unreviewed/2024/09/GHSA-gxh2-x2v6-99jr/GHSA-gxh2-x2v6-99jr.json create mode 100644 advisories/unreviewed/2024/09/GHSA-h558-mxfr-c3px/GHSA-h558-mxfr-c3px.json create mode 100644 advisories/unreviewed/2024/09/GHSA-h55v-8rq9-7qx3/GHSA-h55v-8rq9-7qx3.json create mode 100644 advisories/unreviewed/2024/09/GHSA-h863-2hm3-rc4r/GHSA-h863-2hm3-rc4r.json create mode 100644 advisories/unreviewed/2024/09/GHSA-h8vm-65gc-gw46/GHSA-h8vm-65gc-gw46.json create mode 100644 advisories/unreviewed/2024/09/GHSA-hwr4-f3g6-5mmp/GHSA-hwr4-f3g6-5mmp.json create mode 100644 advisories/unreviewed/2024/09/GHSA-j287-529v-pjr9/GHSA-j287-529v-pjr9.json create mode 100644 advisories/unreviewed/2024/09/GHSA-jc57-w67w-3ggw/GHSA-jc57-w67w-3ggw.json create mode 100644 advisories/unreviewed/2024/09/GHSA-m5p9-xvxj-64c8/GHSA-m5p9-xvxj-64c8.json create mode 100644 advisories/unreviewed/2024/09/GHSA-mc8h-gfm5-j86q/GHSA-mc8h-gfm5-j86q.json create mode 100644 advisories/unreviewed/2024/09/GHSA-mrxm-9rwr-qw4f/GHSA-mrxm-9rwr-qw4f.json create mode 100644 advisories/unreviewed/2024/09/GHSA-p2cr-39jq-4vw3/GHSA-p2cr-39jq-4vw3.json create mode 100644 advisories/unreviewed/2024/09/GHSA-phjc-jpwh-fv7x/GHSA-phjc-jpwh-fv7x.json create mode 100644 advisories/unreviewed/2024/09/GHSA-pvc7-6xhm-95vf/GHSA-pvc7-6xhm-95vf.json create mode 100644 advisories/unreviewed/2024/09/GHSA-q7qr-22qw-pqgx/GHSA-q7qr-22qw-pqgx.json create mode 100644 advisories/unreviewed/2024/09/GHSA-q97c-vhwv-v5w3/GHSA-q97c-vhwv-v5w3.json create mode 100644 advisories/unreviewed/2024/09/GHSA-qcr8-x9j3-5j62/GHSA-qcr8-x9j3-5j62.json create mode 100644 advisories/unreviewed/2024/09/GHSA-qqwc-7hxc-6ghp/GHSA-qqwc-7hxc-6ghp.json create mode 100644 advisories/unreviewed/2024/09/GHSA-r44h-cw52-2x2f/GHSA-r44h-cw52-2x2f.json create mode 100644 advisories/unreviewed/2024/09/GHSA-rm3j-jj6h-qrq4/GHSA-rm3j-jj6h-qrq4.json create mode 100644 advisories/unreviewed/2024/09/GHSA-vj7c-8fv8-732h/GHSA-vj7c-8fv8-732h.json create mode 100644 advisories/unreviewed/2024/09/GHSA-w3jq-wqph-2fhr/GHSA-w3jq-wqph-2fhr.json create mode 100644 advisories/unreviewed/2024/09/GHSA-w72w-8rm9-6684/GHSA-w72w-8rm9-6684.json create mode 100644 advisories/unreviewed/2024/09/GHSA-wpw2-69v8-6f9h/GHSA-wpw2-69v8-6f9h.json create mode 100644 advisories/unreviewed/2024/09/GHSA-wvhj-f7hf-4qv2/GHSA-wvhj-f7hf-4qv2.json create mode 100644 advisories/unreviewed/2024/09/GHSA-wx2g-pjx5-v6r9/GHSA-wx2g-pjx5-v6r9.json create mode 100644 advisories/unreviewed/2024/09/GHSA-x4p5-53p5-3j33/GHSA-x4p5-53p5-3j33.json create mode 100644 advisories/unreviewed/2024/09/GHSA-x8h2-255q-jg4x/GHSA-x8h2-255q-jg4x.json create mode 100644 advisories/unreviewed/2024/09/GHSA-xh87-v57g-jhpw/GHSA-xh87-v57g-jhpw.json create mode 100644 advisories/unreviewed/2024/09/GHSA-xhff-3q93-x4p6/GHSA-xhff-3q93-x4p6.json create mode 100644 advisories/unreviewed/2024/09/GHSA-xpx9-f724-2jfc/GHSA-xpx9-f724-2jfc.json create mode 100644 advisories/unreviewed/2024/09/GHSA-xvwc-mxm8-8hqg/GHSA-xvwc-mxm8-8hqg.json create mode 100644 advisories/unreviewed/2024/09/GHSA-xwv3-34j2-7jgx/GHSA-xwv3-34j2-7jgx.json diff --git a/advisories/github-reviewed/2024/05/GHSA-6wvf-f2vw-3425/GHSA-6wvf-f2vw-3425.json b/advisories/github-reviewed/2024/05/GHSA-6wvf-f2vw-3425/GHSA-6wvf-f2vw-3425.json index 70d80d397c7..dbca0e9b6d1 100644 --- a/advisories/github-reviewed/2024/05/GHSA-6wvf-f2vw-3425/GHSA-6wvf-f2vw-3425.json +++ b/advisories/github-reviewed/2024/05/GHSA-6wvf-f2vw-3425/GHSA-6wvf-f2vw-3425.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6wvf-f2vw-3425", - "modified": "2024-09-17T00:31:03Z", + "modified": "2024-09-25T03:30:35Z", "published": "2024-05-14T18:30:52Z", "aliases": [ "CVE-2024-3727" @@ -154,6 +154,10 @@ "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-3727" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6824" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:6708" diff --git a/advisories/unreviewed/2023/06/GHSA-xjqm-c5w6-2r9x/GHSA-xjqm-c5w6-2r9x.json b/advisories/unreviewed/2023/06/GHSA-xjqm-c5w6-2r9x/GHSA-xjqm-c5w6-2r9x.json index 71a87a80ab6..68aa0c946bd 100644 --- a/advisories/unreviewed/2023/06/GHSA-xjqm-c5w6-2r9x/GHSA-xjqm-c5w6-2r9x.json +++ b/advisories/unreviewed/2023/06/GHSA-xjqm-c5w6-2r9x/GHSA-xjqm-c5w6-2r9x.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-131" + "CWE-131", + "CWE-787" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-45rh-q5fv-wf42/GHSA-45rh-q5fv-wf42.json b/advisories/unreviewed/2023/07/GHSA-45rh-q5fv-wf42/GHSA-45rh-q5fv-wf42.json index 47475c696c5..c8ac24e4933 100644 --- a/advisories/unreviewed/2023/07/GHSA-45rh-q5fv-wf42/GHSA-45rh-q5fv-wf42.json +++ b/advisories/unreviewed/2023/07/GHSA-45rh-q5fv-wf42/GHSA-45rh-q5fv-wf42.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-45rh-q5fv-wf42", - "modified": "2024-04-04T06:21:35Z", + "modified": "2024-09-25T03:30:33Z", "published": "2023-07-26T06:30:16Z", "aliases": [ "CVE-2022-2502" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-2502" }, + { + "type": "WEB", + "url": "https://publisher.hitachienergy.com/preview?DocumentID=8DBD000121&LanguageCode=en&DocumentPartId=&Action=Launch" + }, { "type": "WEB", "url": "https://search.abb.com/library/Download.aspx?DocumentID=8DBD000121&LanguageCode=en&DocumentPartId=&Action=Launch" diff --git a/advisories/unreviewed/2023/07/GHSA-5568-g9wp-2cv7/GHSA-5568-g9wp-2cv7.json b/advisories/unreviewed/2023/07/GHSA-5568-g9wp-2cv7/GHSA-5568-g9wp-2cv7.json index 7a9b16a9822..8d255bba5b9 100644 --- a/advisories/unreviewed/2023/07/GHSA-5568-g9wp-2cv7/GHSA-5568-g9wp-2cv7.json +++ b/advisories/unreviewed/2023/07/GHSA-5568-g9wp-2cv7/GHSA-5568-g9wp-2cv7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5568-g9wp-2cv7", - "modified": "2024-04-04T06:21:38Z", + "modified": "2024-09-25T03:30:33Z", "published": "2023-07-26T06:30:16Z", "aliases": [ "CVE-2022-4608" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-4608" }, + { + "type": "WEB", + "url": "https://publisher.hitachienergy.com/preview?DocumentID=8DBD000121&LanguageCode=en&DocumentPartId=&Action=Launch" + }, { "type": "WEB", "url": "https://search.abb.com/library/Download.aspx?DocumentID=8DBD000121&LanguageCode=en&DocumentPartId=&Action=Launch" diff --git a/advisories/unreviewed/2023/08/GHSA-3323-f6mh-57mx/GHSA-3323-f6mh-57mx.json b/advisories/unreviewed/2023/08/GHSA-3323-f6mh-57mx/GHSA-3323-f6mh-57mx.json index 53d7275b306..382bc58c609 100644 --- a/advisories/unreviewed/2023/08/GHSA-3323-f6mh-57mx/GHSA-3323-f6mh-57mx.json +++ b/advisories/unreviewed/2023/08/GHSA-3323-f6mh-57mx/GHSA-3323-f6mh-57mx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3323-f6mh-57mx", - "modified": "2024-04-04T06:54:50Z", + "modified": "2024-09-25T03:30:34Z", "published": "2023-08-14T15:33:41Z", "aliases": [ "CVE-2023-37070" @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://github.com/Mr-Secure-Code/My-CVE/blob/main/CVE-2023-37070-Exploit.md" + }, + { + "type": "WEB", + "url": "https://github.com/riteshs4hu/My-CVE/blob/main/CVE-2023-37070-Exploit.md" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/08/GHSA-5v64-89vr-vpwr/GHSA-5v64-89vr-vpwr.json b/advisories/unreviewed/2023/08/GHSA-5v64-89vr-vpwr/GHSA-5v64-89vr-vpwr.json index 1b1811b8fd0..194ad9c5fa1 100644 --- a/advisories/unreviewed/2023/08/GHSA-5v64-89vr-vpwr/GHSA-5v64-89vr-vpwr.json +++ b/advisories/unreviewed/2023/08/GHSA-5v64-89vr-vpwr/GHSA-5v64-89vr-vpwr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5v64-89vr-vpwr", - "modified": "2024-04-04T06:45:53Z", + "modified": "2024-09-25T03:30:33Z", "published": "2023-08-09T21:30:44Z", "aliases": [ "CVE-2023-37068" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://github.com/Mr-Secure-Code/My-CVE/blob/main/CVE-2023-37068-Exploit.md" + }, + { + "type": "WEB", + "url": "https://github.com/riteshs4hu/My-CVE/blob/main/CVE-2023-37068-Exploit.md" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/08/GHSA-6c77-g3p7-g7ch/GHSA-6c77-g3p7-g7ch.json b/advisories/unreviewed/2023/08/GHSA-6c77-g3p7-g7ch/GHSA-6c77-g3p7-g7ch.json index e2fa5f0f13c..3415dcfbdeb 100644 --- a/advisories/unreviewed/2023/08/GHSA-6c77-g3p7-g7ch/GHSA-6c77-g3p7-g7ch.json +++ b/advisories/unreviewed/2023/08/GHSA-6c77-g3p7-g7ch/GHSA-6c77-g3p7-g7ch.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6c77-g3p7-g7ch", - "modified": "2024-04-04T06:47:15Z", + "modified": "2024-09-25T03:30:34Z", "published": "2023-08-10T15:30:22Z", "aliases": [ "CVE-2023-37069" @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://github.com/Mr-Secure-Code/My-CVE/blob/main/CVE-2023-37069-Exploit.md" + }, + { + "type": "WEB", + "url": "https://github.com/riteshs4hu/My-CVE/blob/main/CVE-2023-37069-Exploit.md" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/08/GHSA-c2mc-q4gg-xgm7/GHSA-c2mc-q4gg-xgm7.json b/advisories/unreviewed/2023/08/GHSA-c2mc-q4gg-xgm7/GHSA-c2mc-q4gg-xgm7.json index b97ba383830..87f0e9856b4 100644 --- a/advisories/unreviewed/2023/08/GHSA-c2mc-q4gg-xgm7/GHSA-c2mc-q4gg-xgm7.json +++ b/advisories/unreviewed/2023/08/GHSA-c2mc-q4gg-xgm7/GHSA-c2mc-q4gg-xgm7.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-321" + "CWE-321", + "CWE-522" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/08/GHSA-m89f-h769-x259/GHSA-m89f-h769-x259.json b/advisories/unreviewed/2023/08/GHSA-m89f-h769-x259/GHSA-m89f-h769-x259.json index 7c7487bba44..883e39f2c89 100644 --- a/advisories/unreviewed/2023/08/GHSA-m89f-h769-x259/GHSA-m89f-h769-x259.json +++ b/advisories/unreviewed/2023/08/GHSA-m89f-h769-x259/GHSA-m89f-h769-x259.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-326" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/08/GHSA-q8p7-cg4r-8f76/GHSA-q8p7-cg4r-8f76.json b/advisories/unreviewed/2023/08/GHSA-q8p7-cg4r-8f76/GHSA-q8p7-cg4r-8f76.json index b3834e95a09..1d70f90a06a 100644 --- a/advisories/unreviewed/2023/08/GHSA-q8p7-cg4r-8f76/GHSA-q8p7-cg4r-8f76.json +++ b/advisories/unreviewed/2023/08/GHSA-q8p7-cg4r-8f76/GHSA-q8p7-cg4r-8f76.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-327" + "CWE-327", + "CWE-522" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-28h8-8gfr-gwwm/GHSA-28h8-8gfr-gwwm.json b/advisories/unreviewed/2023/09/GHSA-28h8-8gfr-gwwm/GHSA-28h8-8gfr-gwwm.json index 4ea5adc3084..133899ff858 100644 --- a/advisories/unreviewed/2023/09/GHSA-28h8-8gfr-gwwm/GHSA-28h8-8gfr-gwwm.json +++ b/advisories/unreviewed/2023/09/GHSA-28h8-8gfr-gwwm/GHSA-28h8-8gfr-gwwm.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-532" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-3975-pf2x-843g/GHSA-3975-pf2x-843g.json b/advisories/unreviewed/2023/09/GHSA-3975-pf2x-843g/GHSA-3975-pf2x-843g.json index f393718395c..d2cb0ab3e0a 100644 --- a/advisories/unreviewed/2023/09/GHSA-3975-pf2x-843g/GHSA-3975-pf2x-843g.json +++ b/advisories/unreviewed/2023/09/GHSA-3975-pf2x-843g/GHSA-3975-pf2x-843g.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-3jm2-mqgw-5jj8/GHSA-3jm2-mqgw-5jj8.json b/advisories/unreviewed/2023/09/GHSA-3jm2-mqgw-5jj8/GHSA-3jm2-mqgw-5jj8.json index eeadac27414..9f1ae87c11a 100644 --- a/advisories/unreviewed/2023/09/GHSA-3jm2-mqgw-5jj8/GHSA-3jm2-mqgw-5jj8.json +++ b/advisories/unreviewed/2023/09/GHSA-3jm2-mqgw-5jj8/GHSA-3jm2-mqgw-5jj8.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-121", "CWE-787" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2023/09/GHSA-4xvr-ch6x-96mj/GHSA-4xvr-ch6x-96mj.json b/advisories/unreviewed/2023/09/GHSA-4xvr-ch6x-96mj/GHSA-4xvr-ch6x-96mj.json index 63b62d66867..c302ffa02d6 100644 --- a/advisories/unreviewed/2023/09/GHSA-4xvr-ch6x-96mj/GHSA-4xvr-ch6x-96mj.json +++ b/advisories/unreviewed/2023/09/GHSA-4xvr-ch6x-96mj/GHSA-4xvr-ch6x-96mj.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-121", "CWE-787" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2023/09/GHSA-5wxq-q7xr-cgpw/GHSA-5wxq-q7xr-cgpw.json b/advisories/unreviewed/2023/09/GHSA-5wxq-q7xr-cgpw/GHSA-5wxq-q7xr-cgpw.json index f1ade6583f8..8acf642c372 100644 --- a/advisories/unreviewed/2023/09/GHSA-5wxq-q7xr-cgpw/GHSA-5wxq-q7xr-cgpw.json +++ b/advisories/unreviewed/2023/09/GHSA-5wxq-q7xr-cgpw/GHSA-5wxq-q7xr-cgpw.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-6h39-mx58-5ch2/GHSA-6h39-mx58-5ch2.json b/advisories/unreviewed/2023/09/GHSA-6h39-mx58-5ch2/GHSA-6h39-mx58-5ch2.json index f6a48090e15..ea611551d73 100644 --- a/advisories/unreviewed/2023/09/GHSA-6h39-mx58-5ch2/GHSA-6h39-mx58-5ch2.json +++ b/advisories/unreviewed/2023/09/GHSA-6h39-mx58-5ch2/GHSA-6h39-mx58-5ch2.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-121" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-6pgc-3w24-9rcw/GHSA-6pgc-3w24-9rcw.json b/advisories/unreviewed/2023/09/GHSA-6pgc-3w24-9rcw/GHSA-6pgc-3w24-9rcw.json index 11c4fd99b29..b0b8e15e8d4 100644 --- a/advisories/unreviewed/2023/09/GHSA-6pgc-3w24-9rcw/GHSA-6pgc-3w24-9rcw.json +++ b/advisories/unreviewed/2023/09/GHSA-6pgc-3w24-9rcw/GHSA-6pgc-3w24-9rcw.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-15" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-6w8x-vrh5-r745/GHSA-6w8x-vrh5-r745.json b/advisories/unreviewed/2023/09/GHSA-6w8x-vrh5-r745/GHSA-6w8x-vrh5-r745.json index d09fd79e801..29d876c177d 100644 --- a/advisories/unreviewed/2023/09/GHSA-6w8x-vrh5-r745/GHSA-6w8x-vrh5-r745.json +++ b/advisories/unreviewed/2023/09/GHSA-6w8x-vrh5-r745/GHSA-6w8x-vrh5-r745.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-121" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-7w4f-p7cf-gqxq/GHSA-7w4f-p7cf-gqxq.json b/advisories/unreviewed/2023/09/GHSA-7w4f-p7cf-gqxq/GHSA-7w4f-p7cf-gqxq.json index ddfb70beb61..3cd4bac011f 100644 --- a/advisories/unreviewed/2023/09/GHSA-7w4f-p7cf-gqxq/GHSA-7w4f-p7cf-gqxq.json +++ b/advisories/unreviewed/2023/09/GHSA-7w4f-p7cf-gqxq/GHSA-7w4f-p7cf-gqxq.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-8j5g-957r-vpvw/GHSA-8j5g-957r-vpvw.json b/advisories/unreviewed/2023/09/GHSA-8j5g-957r-vpvw/GHSA-8j5g-957r-vpvw.json index 53070ee9582..4ec7966c90a 100644 --- a/advisories/unreviewed/2023/09/GHSA-8j5g-957r-vpvw/GHSA-8j5g-957r-vpvw.json +++ b/advisories/unreviewed/2023/09/GHSA-8j5g-957r-vpvw/GHSA-8j5g-957r-vpvw.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-121", "CWE-787" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2023/09/GHSA-8wm7-r267-8mqr/GHSA-8wm7-r267-8mqr.json b/advisories/unreviewed/2023/09/GHSA-8wm7-r267-8mqr/GHSA-8wm7-r267-8mqr.json index 2960d7184bd..80d524ac0c3 100644 --- a/advisories/unreviewed/2023/09/GHSA-8wm7-r267-8mqr/GHSA-8wm7-r267-8mqr.json +++ b/advisories/unreviewed/2023/09/GHSA-8wm7-r267-8mqr/GHSA-8wm7-r267-8mqr.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-8x56-c587-3rqg/GHSA-8x56-c587-3rqg.json b/advisories/unreviewed/2023/09/GHSA-8x56-c587-3rqg/GHSA-8x56-c587-3rqg.json index aaa0c7a6c7a..cb4c9b4e8df 100644 --- a/advisories/unreviewed/2023/09/GHSA-8x56-c587-3rqg/GHSA-8x56-c587-3rqg.json +++ b/advisories/unreviewed/2023/09/GHSA-8x56-c587-3rqg/GHSA-8x56-c587-3rqg.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-121" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-c2qv-7h5q-gh2f/GHSA-c2qv-7h5q-gh2f.json b/advisories/unreviewed/2023/09/GHSA-c2qv-7h5q-gh2f/GHSA-c2qv-7h5q-gh2f.json index 85b6c833785..b36c2d8adb0 100644 --- a/advisories/unreviewed/2023/09/GHSA-c2qv-7h5q-gh2f/GHSA-c2qv-7h5q-gh2f.json +++ b/advisories/unreviewed/2023/09/GHSA-c2qv-7h5q-gh2f/GHSA-c2qv-7h5q-gh2f.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-cjp8-pj2w-v99h/GHSA-cjp8-pj2w-v99h.json b/advisories/unreviewed/2023/09/GHSA-cjp8-pj2w-v99h/GHSA-cjp8-pj2w-v99h.json index e4ce00368fc..e8bb6e545e3 100644 --- a/advisories/unreviewed/2023/09/GHSA-cjp8-pj2w-v99h/GHSA-cjp8-pj2w-v99h.json +++ b/advisories/unreviewed/2023/09/GHSA-cjp8-pj2w-v99h/GHSA-cjp8-pj2w-v99h.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-f9x4-2mf9-q8x2/GHSA-f9x4-2mf9-q8x2.json b/advisories/unreviewed/2023/09/GHSA-f9x4-2mf9-q8x2/GHSA-f9x4-2mf9-q8x2.json index 53001af4ac2..355af341d6a 100644 --- a/advisories/unreviewed/2023/09/GHSA-f9x4-2mf9-q8x2/GHSA-f9x4-2mf9-q8x2.json +++ b/advisories/unreviewed/2023/09/GHSA-f9x4-2mf9-q8x2/GHSA-f9x4-2mf9-q8x2.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-121", "CWE-787" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2023/09/GHSA-fg7v-q6g2-52wh/GHSA-fg7v-q6g2-52wh.json b/advisories/unreviewed/2023/09/GHSA-fg7v-q6g2-52wh/GHSA-fg7v-q6g2-52wh.json index 37375faefa8..1052fd0eb50 100644 --- a/advisories/unreviewed/2023/09/GHSA-fg7v-q6g2-52wh/GHSA-fg7v-q6g2-52wh.json +++ b/advisories/unreviewed/2023/09/GHSA-fg7v-q6g2-52wh/GHSA-fg7v-q6g2-52wh.json @@ -40,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-g288-cc4f-69p8/GHSA-g288-cc4f-69p8.json b/advisories/unreviewed/2023/09/GHSA-g288-cc4f-69p8/GHSA-g288-cc4f-69p8.json index 26f1b3d8e6f..19e1b4a495e 100644 --- a/advisories/unreviewed/2023/09/GHSA-g288-cc4f-69p8/GHSA-g288-cc4f-69p8.json +++ b/advisories/unreviewed/2023/09/GHSA-g288-cc4f-69p8/GHSA-g288-cc4f-69p8.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-gr6q-9m75-87c6/GHSA-gr6q-9m75-87c6.json b/advisories/unreviewed/2023/09/GHSA-gr6q-9m75-87c6/GHSA-gr6q-9m75-87c6.json index 022ad06a16d..9b44a5f6f52 100644 --- a/advisories/unreviewed/2023/09/GHSA-gr6q-9m75-87c6/GHSA-gr6q-9m75-87c6.json +++ b/advisories/unreviewed/2023/09/GHSA-gr6q-9m75-87c6/GHSA-gr6q-9m75-87c6.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-h58p-f4w7-jcpv/GHSA-h58p-f4w7-jcpv.json b/advisories/unreviewed/2023/09/GHSA-h58p-f4w7-jcpv/GHSA-h58p-f4w7-jcpv.json index a8faf40e580..2a84d162ff4 100644 --- a/advisories/unreviewed/2023/09/GHSA-h58p-f4w7-jcpv/GHSA-h58p-f4w7-jcpv.json +++ b/advisories/unreviewed/2023/09/GHSA-h58p-f4w7-jcpv/GHSA-h58p-f4w7-jcpv.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-121" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-h724-w27c-6j67/GHSA-h724-w27c-6j67.json b/advisories/unreviewed/2023/09/GHSA-h724-w27c-6j67/GHSA-h724-w27c-6j67.json index 29b200c7a84..9e3d483f3bb 100644 --- a/advisories/unreviewed/2023/09/GHSA-h724-w27c-6j67/GHSA-h724-w27c-6j67.json +++ b/advisories/unreviewed/2023/09/GHSA-h724-w27c-6j67/GHSA-h724-w27c-6j67.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-121" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-hcvv-hp4h-gfwx/GHSA-hcvv-hp4h-gfwx.json b/advisories/unreviewed/2023/09/GHSA-hcvv-hp4h-gfwx/GHSA-hcvv-hp4h-gfwx.json index 30f85eb2ebb..3c68fc19494 100644 --- a/advisories/unreviewed/2023/09/GHSA-hcvv-hp4h-gfwx/GHSA-hcvv-hp4h-gfwx.json +++ b/advisories/unreviewed/2023/09/GHSA-hcvv-hp4h-gfwx/GHSA-hcvv-hp4h-gfwx.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-hmqw-w898-xwx8/GHSA-hmqw-w898-xwx8.json b/advisories/unreviewed/2023/09/GHSA-hmqw-w898-xwx8/GHSA-hmqw-w898-xwx8.json index abe6b6faf33..84ccb7725b8 100644 --- a/advisories/unreviewed/2023/09/GHSA-hmqw-w898-xwx8/GHSA-hmqw-w898-xwx8.json +++ b/advisories/unreviewed/2023/09/GHSA-hmqw-w898-xwx8/GHSA-hmqw-w898-xwx8.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-121", "CWE-787" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2023/09/GHSA-jp22-8r3p-f4wr/GHSA-jp22-8r3p-f4wr.json b/advisories/unreviewed/2023/09/GHSA-jp22-8r3p-f4wr/GHSA-jp22-8r3p-f4wr.json index 2d45b02375b..18f8ddb7fcb 100644 --- a/advisories/unreviewed/2023/09/GHSA-jp22-8r3p-f4wr/GHSA-jp22-8r3p-f4wr.json +++ b/advisories/unreviewed/2023/09/GHSA-jp22-8r3p-f4wr/GHSA-jp22-8r3p-f4wr.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-79", "CWE-89" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/09/GHSA-m47m-h5jm-m7g4/GHSA-m47m-h5jm-m7g4.json b/advisories/unreviewed/2023/09/GHSA-m47m-h5jm-m7g4/GHSA-m47m-h5jm-m7g4.json index 010861979e5..a9e4c7a1dbc 100644 --- a/advisories/unreviewed/2023/09/GHSA-m47m-h5jm-m7g4/GHSA-m47m-h5jm-m7g4.json +++ b/advisories/unreviewed/2023/09/GHSA-m47m-h5jm-m7g4/GHSA-m47m-h5jm-m7g4.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-121" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-pqcf-6fpm-w7j4/GHSA-pqcf-6fpm-w7j4.json b/advisories/unreviewed/2023/09/GHSA-pqcf-6fpm-w7j4/GHSA-pqcf-6fpm-w7j4.json index 745319f9caf..2eafba2ac90 100644 --- a/advisories/unreviewed/2023/09/GHSA-pqcf-6fpm-w7j4/GHSA-pqcf-6fpm-w7j4.json +++ b/advisories/unreviewed/2023/09/GHSA-pqcf-6fpm-w7j4/GHSA-pqcf-6fpm-w7j4.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-121" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-pw36-82xr-g6rw/GHSA-pw36-82xr-g6rw.json b/advisories/unreviewed/2023/09/GHSA-pw36-82xr-g6rw/GHSA-pw36-82xr-g6rw.json index 11fac210886..4314b0acdd9 100644 --- a/advisories/unreviewed/2023/09/GHSA-pw36-82xr-g6rw/GHSA-pw36-82xr-g6rw.json +++ b/advisories/unreviewed/2023/09/GHSA-pw36-82xr-g6rw/GHSA-pw36-82xr-g6rw.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-q5x2-c4xq-2wmv/GHSA-q5x2-c4xq-2wmv.json b/advisories/unreviewed/2023/09/GHSA-q5x2-c4xq-2wmv/GHSA-q5x2-c4xq-2wmv.json index 715d1b60753..c5c9ab2160c 100644 --- a/advisories/unreviewed/2023/09/GHSA-q5x2-c4xq-2wmv/GHSA-q5x2-c4xq-2wmv.json +++ b/advisories/unreviewed/2023/09/GHSA-q5x2-c4xq-2wmv/GHSA-q5x2-c4xq-2wmv.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-qw9q-7f95-xh3q/GHSA-qw9q-7f95-xh3q.json b/advisories/unreviewed/2023/09/GHSA-qw9q-7f95-xh3q/GHSA-qw9q-7f95-xh3q.json index 7e6a33c991b..15dc69ea4ef 100644 --- a/advisories/unreviewed/2023/09/GHSA-qw9q-7f95-xh3q/GHSA-qw9q-7f95-xh3q.json +++ b/advisories/unreviewed/2023/09/GHSA-qw9q-7f95-xh3q/GHSA-qw9q-7f95-xh3q.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-121", "CWE-787" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2023/09/GHSA-rccm-547v-jf77/GHSA-rccm-547v-jf77.json b/advisories/unreviewed/2023/09/GHSA-rccm-547v-jf77/GHSA-rccm-547v-jf77.json index 8325d989b4c..b9471b33386 100644 --- a/advisories/unreviewed/2023/09/GHSA-rccm-547v-jf77/GHSA-rccm-547v-jf77.json +++ b/advisories/unreviewed/2023/09/GHSA-rccm-547v-jf77/GHSA-rccm-547v-jf77.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-vhfm-hcpf-g55q/GHSA-vhfm-hcpf-g55q.json b/advisories/unreviewed/2023/09/GHSA-vhfm-hcpf-g55q/GHSA-vhfm-hcpf-g55q.json index eda9f5b0930..0aabb1a40a7 100644 --- a/advisories/unreviewed/2023/09/GHSA-vhfm-hcpf-g55q/GHSA-vhfm-hcpf-g55q.json +++ b/advisories/unreviewed/2023/09/GHSA-vhfm-hcpf-g55q/GHSA-vhfm-hcpf-g55q.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-w8j8-gh53-mg37/GHSA-w8j8-gh53-mg37.json b/advisories/unreviewed/2023/09/GHSA-w8j8-gh53-mg37/GHSA-w8j8-gh53-mg37.json index 111e7e90bb8..f52867f218a 100644 --- a/advisories/unreviewed/2023/09/GHSA-w8j8-gh53-mg37/GHSA-w8j8-gh53-mg37.json +++ b/advisories/unreviewed/2023/09/GHSA-w8j8-gh53-mg37/GHSA-w8j8-gh53-mg37.json @@ -76,7 +76,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-wg68-3v48-jc2x/GHSA-wg68-3v48-jc2x.json b/advisories/unreviewed/2023/09/GHSA-wg68-3v48-jc2x/GHSA-wg68-3v48-jc2x.json index e9096352a3e..7bb23e281b3 100644 --- a/advisories/unreviewed/2023/09/GHSA-wg68-3v48-jc2x/GHSA-wg68-3v48-jc2x.json +++ b/advisories/unreviewed/2023/09/GHSA-wg68-3v48-jc2x/GHSA-wg68-3v48-jc2x.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-wjgm-r92h-xvvr/GHSA-wjgm-r92h-xvvr.json b/advisories/unreviewed/2023/09/GHSA-wjgm-r92h-xvvr/GHSA-wjgm-r92h-xvvr.json index 797aacce36f..ec53c8c9aed 100644 --- a/advisories/unreviewed/2023/09/GHSA-wjgm-r92h-xvvr/GHSA-wjgm-r92h-xvvr.json +++ b/advisories/unreviewed/2023/09/GHSA-wjgm-r92h-xvvr/GHSA-wjgm-r92h-xvvr.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-f2v5-p4rx-6wc2/GHSA-f2v5-p4rx-6wc2.json b/advisories/unreviewed/2024/03/GHSA-f2v5-p4rx-6wc2/GHSA-f2v5-p4rx-6wc2.json index ca314b95619..5d6819f8d54 100644 --- a/advisories/unreviewed/2024/03/GHSA-f2v5-p4rx-6wc2/GHSA-f2v5-p4rx-6wc2.json +++ b/advisories/unreviewed/2024/03/GHSA-f2v5-p4rx-6wc2/GHSA-f2v5-p4rx-6wc2.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-323" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-qr26-2mpm-7j4x/GHSA-qr26-2mpm-7j4x.json b/advisories/unreviewed/2024/03/GHSA-qr26-2mpm-7j4x/GHSA-qr26-2mpm-7j4x.json index 8d5cf26f3d9..670cb5d3430 100644 --- a/advisories/unreviewed/2024/03/GHSA-qr26-2mpm-7j4x/GHSA-qr26-2mpm-7j4x.json +++ b/advisories/unreviewed/2024/03/GHSA-qr26-2mpm-7j4x/GHSA-qr26-2mpm-7j4x.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-20", "CWE-787" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2024/04/GHSA-rgvf-j3x5-6277/GHSA-rgvf-j3x5-6277.json b/advisories/unreviewed/2024/04/GHSA-rgvf-j3x5-6277/GHSA-rgvf-j3x5-6277.json index d8f4ac1ac9d..a9192ba37dd 100644 --- a/advisories/unreviewed/2024/04/GHSA-rgvf-j3x5-6277/GHSA-rgvf-j3x5-6277.json +++ b/advisories/unreviewed/2024/04/GHSA-rgvf-j3x5-6277/GHSA-rgvf-j3x5-6277.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rgvf-j3x5-6277", - "modified": "2024-04-09T21:32:00Z", + "modified": "2024-09-25T03:30:35Z", "published": "2024-04-09T21:32:00Z", "aliases": [ "CVE-2024-3446" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3446" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6964" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-3446" diff --git a/advisories/unreviewed/2024/06/GHSA-fchp-8m28-g68f/GHSA-fchp-8m28-g68f.json b/advisories/unreviewed/2024/06/GHSA-fchp-8m28-g68f/GHSA-fchp-8m28-g68f.json index 6af44b42cff..b61e38e63e4 100644 --- a/advisories/unreviewed/2024/06/GHSA-fchp-8m28-g68f/GHSA-fchp-8m28-g68f.json +++ b/advisories/unreviewed/2024/06/GHSA-fchp-8m28-g68f/GHSA-fchp-8m28-g68f.json @@ -40,6 +40,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-787", "CWE-843" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/06/GHSA-ffhx-2rrf-9c23/GHSA-ffhx-2rrf-9c23.json b/advisories/unreviewed/2024/06/GHSA-ffhx-2rrf-9c23/GHSA-ffhx-2rrf-9c23.json index ceac1bfd6c4..a94a266c976 100644 --- a/advisories/unreviewed/2024/06/GHSA-ffhx-2rrf-9c23/GHSA-ffhx-2rrf-9c23.json +++ b/advisories/unreviewed/2024/06/GHSA-ffhx-2rrf-9c23/GHSA-ffhx-2rrf-9c23.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ffhx-2rrf-9c23", - "modified": "2024-06-17T12:30:39Z", + "modified": "2024-09-25T03:30:35Z", "published": "2024-06-12T09:30:48Z", "aliases": [ "CVE-2024-5742" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5742" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6986" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-5742" diff --git a/advisories/unreviewed/2024/07/GHSA-v9xm-vjq4-6r8q/GHSA-v9xm-vjq4-6r8q.json b/advisories/unreviewed/2024/07/GHSA-v9xm-vjq4-6r8q/GHSA-v9xm-vjq4-6r8q.json index 65be1c7331f..89123bab703 100644 --- a/advisories/unreviewed/2024/07/GHSA-v9xm-vjq4-6r8q/GHSA-v9xm-vjq4-6r8q.json +++ b/advisories/unreviewed/2024/07/GHSA-v9xm-vjq4-6r8q/GHSA-v9xm-vjq4-6r8q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v9xm-vjq4-6r8q", - "modified": "2024-07-16T15:30:50Z", + "modified": "2024-09-25T03:30:35Z", "published": "2024-07-16T15:30:50Z", "aliases": [ "CVE-2024-6655" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6655" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6963" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-6655" diff --git a/advisories/unreviewed/2024/08/GHSA-74vq-jpr9-j6wj/GHSA-74vq-jpr9-j6wj.json b/advisories/unreviewed/2024/08/GHSA-74vq-jpr9-j6wj/GHSA-74vq-jpr9-j6wj.json index 3542ff9e903..4a1411c3ea0 100644 --- a/advisories/unreviewed/2024/08/GHSA-74vq-jpr9-j6wj/GHSA-74vq-jpr9-j6wj.json +++ b/advisories/unreviewed/2024/08/GHSA-74vq-jpr9-j6wj/GHSA-74vq-jpr9-j6wj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-74vq-jpr9-j6wj", - "modified": "2024-09-12T18:31:39Z", + "modified": "2024-09-25T03:30:35Z", "published": "2024-08-14T15:31:18Z", "aliases": [ "CVE-2024-42259" @@ -52,6 +52,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/ead9289a51ea82eb5b27029fcf4c34b2dd60cf06" + }, + { + "type": "WEB", + "url": "https://project-zero.issues.chromium.org/issues/42451707" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/08/GHSA-7c7g-wccp-rrhj/GHSA-7c7g-wccp-rrhj.json b/advisories/unreviewed/2024/08/GHSA-7c7g-wccp-rrhj/GHSA-7c7g-wccp-rrhj.json index 2db39b8ea6e..d54e0af3fb2 100644 --- a/advisories/unreviewed/2024/08/GHSA-7c7g-wccp-rrhj/GHSA-7c7g-wccp-rrhj.json +++ b/advisories/unreviewed/2024/08/GHSA-7c7g-wccp-rrhj/GHSA-7c7g-wccp-rrhj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7c7g-wccp-rrhj", - "modified": "2024-08-05T15:30:53Z", + "modified": "2024-09-25T03:30:35Z", "published": "2024-08-05T15:30:53Z", "aliases": [ "CVE-2024-7409" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7409" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6964" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-7409" diff --git a/advisories/unreviewed/2024/08/GHSA-rqmr-f8r9-69wq/GHSA-rqmr-f8r9-69wq.json b/advisories/unreviewed/2024/08/GHSA-rqmr-f8r9-69wq/GHSA-rqmr-f8r9-69wq.json index cf2ed9e0fc2..c03a98b49fe 100644 --- a/advisories/unreviewed/2024/08/GHSA-rqmr-f8r9-69wq/GHSA-rqmr-f8r9-69wq.json +++ b/advisories/unreviewed/2024/08/GHSA-rqmr-f8r9-69wq/GHSA-rqmr-f8r9-69wq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rqmr-f8r9-69wq", - "modified": "2024-09-18T21:30:44Z", + "modified": "2024-09-25T03:30:35Z", "published": "2024-08-05T15:30:52Z", "aliases": [ "CVE-2024-7383" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:6757" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6964" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-7383" diff --git a/advisories/unreviewed/2024/09/GHSA-2mqq-6v49-g869/GHSA-2mqq-6v49-g869.json b/advisories/unreviewed/2024/09/GHSA-2mqq-6v49-g869/GHSA-2mqq-6v49-g869.json new file mode 100644 index 00000000000..43e30030145 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-2mqq-6v49-g869/GHSA-2mqq-6v49-g869.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2mqq-6v49-g869", + "modified": "2024-09-25T03:30:35Z", + "published": "2024-09-25T03:30:35Z", + "aliases": [ + "CVE-2024-42506" + ], + "details": "Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities results in the ability to execute arbitrary code as a privileged user on the underlying operating system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42506" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04712en_us&docLocale=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-3522-f7v7-pv57/GHSA-3522-f7v7-pv57.json b/advisories/unreviewed/2024/09/GHSA-3522-f7v7-pv57/GHSA-3522-f7v7-pv57.json new file mode 100644 index 00000000000..a276b4c6efe --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-3522-f7v7-pv57/GHSA-3522-f7v7-pv57.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3522-f7v7-pv57", + "modified": "2024-09-25T03:30:36Z", + "published": "2024-09-25T03:30:36Z", + "aliases": [ + "CVE-2024-8350" + ], + "details": "The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to user group add due to a missing capability check on the /wp-json/ulgm_management/v1/add_user/ REST API endpoint in all versions up to, and including, 6.1.0.1. This makes it possible for authenticated attackers, with group leader-level access and above, to add users to their group which ultimately allows them to leverage CVE-2024-8349 and gain admin access to the site.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8350" + }, + { + "type": "WEB", + "url": "https://github.com/karlemilnikka/CVE-2024-8349-and-CVE-2024-8350" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a38a58de-5f7d-4033-9a65-41b590b7d510?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T03:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-3hc5-r53w-6ph8/GHSA-3hc5-r53w-6ph8.json b/advisories/unreviewed/2024/09/GHSA-3hc5-r53w-6ph8/GHSA-3hc5-r53w-6ph8.json new file mode 100644 index 00000000000..5988f6db7b5 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-3hc5-r53w-6ph8/GHSA-3hc5-r53w-6ph8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3hc5-r53w-6ph8", + "modified": "2024-09-25T03:30:36Z", + "published": "2024-09-25T03:30:36Z", + "aliases": [ + "CVE-2024-8941" + ], + "details": "Path traversal vulnerability in Scriptcase version 9.4.019, in /scriptcase/devel/compat/nm_edit_php_edit.php (in the “subpage” parameter), which allows unauthenticated remote users to bypass SecurityManager's intended restrictions and list and/or read a parent directory via a “/...” or directly into a path used in the POST parameter “field_file” by a web application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8941" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-scriptcase" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-3hq4-wjf7-pw99/GHSA-3hq4-wjf7-pw99.json b/advisories/unreviewed/2024/09/GHSA-3hq4-wjf7-pw99/GHSA-3hq4-wjf7-pw99.json new file mode 100644 index 00000000000..e005d5074ee --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-3hq4-wjf7-pw99/GHSA-3hq4-wjf7-pw99.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3hq4-wjf7-pw99", + "modified": "2024-09-25T03:30:37Z", + "published": "2024-09-25T03:30:37Z", + "aliases": [ + "CVE-2024-8549" + ], + "details": "The Simple Calendar – Google Calendar Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.4.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8549" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3156894/google-calendar-events/trunk/includes/admin/notices.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3156894%40google-calendar-events&new=3156894%40google-calendar-events&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/17ae3f22-6426-48f7-93e6-c0ad515b329a?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T03:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-3qcf-857g-5p4x/GHSA-3qcf-857g-5p4x.json b/advisories/unreviewed/2024/09/GHSA-3qcf-857g-5p4x/GHSA-3qcf-857g-5p4x.json new file mode 100644 index 00000000000..34e3ee72f04 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-3qcf-857g-5p4x/GHSA-3qcf-857g-5p4x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3qcf-857g-5p4x", + "modified": "2024-09-25T03:30:35Z", + "published": "2024-09-25T03:30:35Z", + "aliases": [ + "CVE-2021-38963" + ], + "details": "IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by a CSV injection vulnerability. By persuading a victim to open a specially crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-38963" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7169765" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1236" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-3qr7-fhm2-q3h8/GHSA-3qr7-fhm2-q3h8.json b/advisories/unreviewed/2024/09/GHSA-3qr7-fhm2-q3h8/GHSA-3qr7-fhm2-q3h8.json index 5af248d0cca..361fa6f7d42 100644 --- a/advisories/unreviewed/2024/09/GHSA-3qr7-fhm2-q3h8/GHSA-3qr7-fhm2-q3h8.json +++ b/advisories/unreviewed/2024/09/GHSA-3qr7-fhm2-q3h8/GHSA-3qr7-fhm2-q3h8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3qr7-fhm2-q3h8", - "modified": "2024-09-24T00:31:31Z", + "modified": "2024-09-25T03:30:35Z", "published": "2024-09-24T00:31:31Z", "aliases": [ "CVE-2023-7281" ], "details": "Inappropriate implementation in Compositing in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-451" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-23T22:15:03Z" diff --git a/advisories/unreviewed/2024/09/GHSA-3w2h-6gvg-jj2v/GHSA-3w2h-6gvg-jj2v.json b/advisories/unreviewed/2024/09/GHSA-3w2h-6gvg-jj2v/GHSA-3w2h-6gvg-jj2v.json index 45f85921a76..e475c1eb7f2 100644 --- a/advisories/unreviewed/2024/09/GHSA-3w2h-6gvg-jj2v/GHSA-3w2h-6gvg-jj2v.json +++ b/advisories/unreviewed/2024/09/GHSA-3w2h-6gvg-jj2v/GHSA-3w2h-6gvg-jj2v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3w2h-6gvg-jj2v", - "modified": "2024-09-24T00:31:31Z", + "modified": "2024-09-25T03:30:35Z", "published": "2024-09-24T00:31:31Z", "aliases": [ "CVE-2021-38023" ], "details": "Use after free in Extensions in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-23T22:15:02Z" diff --git a/advisories/unreviewed/2024/09/GHSA-3xm5-r3mx-685g/GHSA-3xm5-r3mx-685g.json b/advisories/unreviewed/2024/09/GHSA-3xm5-r3mx-685g/GHSA-3xm5-r3mx-685g.json new file mode 100644 index 00000000000..a15b2d57523 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-3xm5-r3mx-685g/GHSA-3xm5-r3mx-685g.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3xm5-r3mx-685g", + "modified": "2024-09-25T03:30:37Z", + "published": "2024-09-25T03:30:36Z", + "aliases": [ + "CVE-2024-8484" + ], + "details": "The REST API TO MiniProgram plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-json/watch-life-net/v1/comment/getcomments REST API endpoint in all versions up to, and including, 4.7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8484" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/rest-api-to-miniprogram/tags/4.7.0/includes/api/ram-rest-comments-controller.php#L247" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6e0945eb-ceec-4536-822a-fe864c21b580?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T03:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-4f4g-mjgj-wqjc/GHSA-4f4g-mjgj-wqjc.json b/advisories/unreviewed/2024/09/GHSA-4f4g-mjgj-wqjc/GHSA-4f4g-mjgj-wqjc.json new file mode 100644 index 00000000000..fd78be32d85 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-4f4g-mjgj-wqjc/GHSA-4f4g-mjgj-wqjc.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4f4g-mjgj-wqjc", + "modified": "2024-09-25T03:30:36Z", + "published": "2024-09-25T03:30:35Z", + "aliases": [ + "CVE-2024-43423" + ], + "details": "The web application for ProGauge MAGLINK LX4 CONSOLE contains an \nadministrative-level user account with a password that cannot be \nchanged.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43423" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-268-04" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-259" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-4fw3-822r-pqw6/GHSA-4fw3-822r-pqw6.json b/advisories/unreviewed/2024/09/GHSA-4fw3-822r-pqw6/GHSA-4fw3-822r-pqw6.json new file mode 100644 index 00000000000..fbfb76d9bd7 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-4fw3-822r-pqw6/GHSA-4fw3-822r-pqw6.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4fw3-822r-pqw6", + "modified": "2024-09-25T03:30:36Z", + "published": "2024-09-25T03:30:36Z", + "aliases": [ + "CVE-2024-9122" + ], + "details": "Type Confusion in V8 in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9122" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/09/stable-channel-update-for-desktop_24.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/365802567" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-843" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-4x6v-7m8g-5v5x/GHSA-4x6v-7m8g-5v5x.json b/advisories/unreviewed/2024/09/GHSA-4x6v-7m8g-5v5x/GHSA-4x6v-7m8g-5v5x.json new file mode 100644 index 00000000000..d5340721b21 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-4x6v-7m8g-5v5x/GHSA-4x6v-7m8g-5v5x.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4x6v-7m8g-5v5x", + "modified": "2024-09-25T03:30:36Z", + "published": "2024-09-25T03:30:36Z", + "aliases": [ + "CVE-2024-6590" + ], + "details": "The Spreadsheet Integration – Automate Google Sheets With WordPress, WooCommerce & Most Popular Form Plugins. Also, Display Google sheet as a Table. plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 3.7.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to edit post status, edit Google sheet integrations, and create Google sheet integrations.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6590" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wpgsi/trunk/admin/class-wpgsi-admin.php#L1168" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wpgsi/trunk/admin/class-wpgsi-admin.php#L812" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wpgsi/trunk/admin/class-wpgsi-admin.php#L863" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wpgsi/trunk/admin/class-wpgsi-admin.php#L935" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d35ff2cc-9af2-4b72-bc49-e205275daa4d?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T03:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-52jr-7fqr-h29h/GHSA-52jr-7fqr-h29h.json b/advisories/unreviewed/2024/09/GHSA-52jr-7fqr-h29h/GHSA-52jr-7fqr-h29h.json new file mode 100644 index 00000000000..8201901dd0c --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-52jr-7fqr-h29h/GHSA-52jr-7fqr-h29h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-52jr-7fqr-h29h", + "modified": "2024-09-25T03:30:36Z", + "published": "2024-09-25T03:30:36Z", + "aliases": [ + "CVE-2024-8878" + ], + "details": "The password recovery mechanism for the forgotten password in Riello Netman 204 allows an attacker to reset the admin password and take over control of the device.This issue affects Netman 204: through 4.05.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8878" + }, + { + "type": "WEB", + "url": "https://cyberdanube.com/en/en-multiple-vulnerabilities-in-riello-netman-204/index.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-640" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-53c9-m2h7-5xhr/GHSA-53c9-m2h7-5xhr.json b/advisories/unreviewed/2024/09/GHSA-53c9-m2h7-5xhr/GHSA-53c9-m2h7-5xhr.json index 8572520aed1..833e877a2c9 100644 --- a/advisories/unreviewed/2024/09/GHSA-53c9-m2h7-5xhr/GHSA-53c9-m2h7-5xhr.json +++ b/advisories/unreviewed/2024/09/GHSA-53c9-m2h7-5xhr/GHSA-53c9-m2h7-5xhr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-53c9-m2h7-5xhr", - "modified": "2024-09-24T00:31:32Z", + "modified": "2024-09-25T03:30:35Z", "published": "2024-09-24T00:31:32Z", "aliases": [ "CVE-2024-7018" ], "details": "Heap buffer overflow in PDF in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Medium)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-122" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-23T22:15:03Z" diff --git a/advisories/unreviewed/2024/09/GHSA-563f-r8fh-rrgc/GHSA-563f-r8fh-rrgc.json b/advisories/unreviewed/2024/09/GHSA-563f-r8fh-rrgc/GHSA-563f-r8fh-rrgc.json new file mode 100644 index 00000000000..0c0eb18692b --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-563f-r8fh-rrgc/GHSA-563f-r8fh-rrgc.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-563f-r8fh-rrgc", + "modified": "2024-09-25T03:30:37Z", + "published": "2024-09-25T03:30:36Z", + "aliases": [ + "CVE-2024-8485" + ], + "details": "The REST API TO MiniProgram plugin for WordPress is vulnerable to privilege escalation via account takeovr in all versions up to, and including, 4.7.1 via the updateUserInfo() due to missing validation on the 'openid' user controlled key that determines what user will be updated. This makes it possible for unauthenticated attackers to update arbitrary user's accounts, including their email to a @weixin.com email, which can the be leveraged to reset the password of the user's account, including administrators.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8485" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/rest-api-to-miniprogram/tags/4.7.0/includes/api/ram-rest-weixin-controller.php#L264" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/b53066d3-2ff3-4460-896a-facd77455914?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T03:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-564c-h2vx-x449/GHSA-564c-h2vx-x449.json b/advisories/unreviewed/2024/09/GHSA-564c-h2vx-x449/GHSA-564c-h2vx-x449.json new file mode 100644 index 00000000000..e4297aeb54c --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-564c-h2vx-x449/GHSA-564c-h2vx-x449.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-564c-h2vx-x449", + "modified": "2024-09-25T03:30:37Z", + "published": "2024-09-25T03:30:36Z", + "aliases": [ + "CVE-2024-8434" + ], + "details": "The Easy Mega Menu Plugin for WordPress – ThemeHunk plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions hooked via AJAX in all versions up to, and including, 1.0.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform actions like updating plugin settings.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8434" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3156084/themehunk-megamenu-plus/tags/1.1.0/inc/megamenu-base.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3156084/themehunk-megamenu-plus/tags/1.1.0/inc/megamenu-nav-menu-settings.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3156084/themehunk-megamenu-plus/tags/1.1.0/inc/megamenu-setting.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3156084/themehunk-megamenu-plus/tags/1.1.0/inc/megamenu-widgets.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/be3869a9-f72d-4bbb-ba51-d2761ca761f2?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T03:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-5cxp-2w3f-wh6m/GHSA-5cxp-2w3f-wh6m.json b/advisories/unreviewed/2024/09/GHSA-5cxp-2w3f-wh6m/GHSA-5cxp-2w3f-wh6m.json new file mode 100644 index 00000000000..aae88f2fd3b --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-5cxp-2w3f-wh6m/GHSA-5cxp-2w3f-wh6m.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5cxp-2w3f-wh6m", + "modified": "2024-09-25T03:30:36Z", + "published": "2024-09-25T03:30:36Z", + "aliases": [ + "CVE-2024-7386" + ], + "details": "The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.9.1. This is due to missing nonce validation on the wpdmpp_async_request() function. This makes it possible for unauthenticated attackers to perform actions such as initiating refunds via a forged request granted they can trick a site administrator or shop manager into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7386" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wpdm-premium-packages/trunk/wpdm-premium-packages.php?rev=3102989#L1148" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0a714536-c6fd-495b-b774-104657329a74?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T03:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-6375-pg5j-8wph/GHSA-6375-pg5j-8wph.json b/advisories/unreviewed/2024/09/GHSA-6375-pg5j-8wph/GHSA-6375-pg5j-8wph.json new file mode 100644 index 00000000000..c17ced7e5db --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-6375-pg5j-8wph/GHSA-6375-pg5j-8wph.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6375-pg5j-8wph", + "modified": "2024-09-25T03:30:36Z", + "published": "2024-09-25T03:30:36Z", + "aliases": [ + "CVE-2024-46935" + ], + "details": "Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to denial of service (DoS). Attackers who craft messages with specific characters may crash the workspace due to an issue in the message parser.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46935" + }, + { + "type": "WEB", + "url": "https://github.com/RocketChat/Rocket.Chat/pull/33227" + }, + { + "type": "WEB", + "url": "https://docs.rocket.chat/docs/rocketchat-security-fixes-updates-and-advisories" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-697p-23gh-47wj/GHSA-697p-23gh-47wj.json b/advisories/unreviewed/2024/09/GHSA-697p-23gh-47wj/GHSA-697p-23gh-47wj.json new file mode 100644 index 00000000000..c6dafaef3b2 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-697p-23gh-47wj/GHSA-697p-23gh-47wj.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-697p-23gh-47wj", + "modified": "2024-09-25T03:30:35Z", + "published": "2024-09-25T03:30:35Z", + "aliases": [ + "CVE-2024-41725" + ], + "details": "ProGauge MAGLINK LX CONSOLE does not have sufficient filtering on input \nfields that are used to render pages which may allow cross site \nscripting.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41725" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-268-04" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-6pm7-68mw-p76q/GHSA-6pm7-68mw-p76q.json b/advisories/unreviewed/2024/09/GHSA-6pm7-68mw-p76q/GHSA-6pm7-68mw-p76q.json new file mode 100644 index 00000000000..1ffa4467709 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-6pm7-68mw-p76q/GHSA-6pm7-68mw-p76q.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6pm7-68mw-p76q", + "modified": "2024-09-25T03:30:36Z", + "published": "2024-09-25T03:30:36Z", + "aliases": [ + "CVE-2024-8437" + ], + "details": "The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions hooked via AJAX like wpeg_settings and wpeg_add_gallery in all versions up to, and including, 4.8.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify galleries.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8437" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-easy-gallery/trunk/wp-easy-gallery.php#L42" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c8bd5021-4895-4b0e-b517-186959f76095?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-7fm9-f48p-wp4r/GHSA-7fm9-f48p-wp4r.json b/advisories/unreviewed/2024/09/GHSA-7fm9-f48p-wp4r/GHSA-7fm9-f48p-wp4r.json new file mode 100644 index 00000000000..6e74fd9da51 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-7fm9-f48p-wp4r/GHSA-7fm9-f48p-wp4r.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7fm9-f48p-wp4r", + "modified": "2024-09-25T03:30:37Z", + "published": "2024-09-25T03:30:36Z", + "aliases": [ + "CVE-2024-8483" + ], + "details": "The MAS Static Content plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.8 via the static_content() function. This makes it possible for authenticated attackers, with contributor-level access and above, to extract potentially sensitive information from private static content pages.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8483" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/mas-static-content/tags/1.0.8/includes/class-mas-static-content-shortcodes.php#L35" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3151679%40mas-static-content&new=3151679%40mas-static-content&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/794bc5cd-c9ac-4583-ae3d-a92361374b5f?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T03:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-7jvh-4mqp-gf66/GHSA-7jvh-4mqp-gf66.json b/advisories/unreviewed/2024/09/GHSA-7jvh-4mqp-gf66/GHSA-7jvh-4mqp-gf66.json index 907530ff326..2f4cec3a147 100644 --- a/advisories/unreviewed/2024/09/GHSA-7jvh-4mqp-gf66/GHSA-7jvh-4mqp-gf66.json +++ b/advisories/unreviewed/2024/09/GHSA-7jvh-4mqp-gf66/GHSA-7jvh-4mqp-gf66.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7jvh-4mqp-gf66", - "modified": "2024-09-23T18:30:34Z", + "modified": "2024-09-25T03:30:35Z", "published": "2024-09-23T18:30:34Z", "aliases": [ "CVE-2024-40441" ], "details": "An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pipeline module to annotate a document automatically v.0.1.23 allows a remote attacker to escalate privileges via the model_attribs parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-918" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-23T17:15:13Z" diff --git a/advisories/unreviewed/2024/09/GHSA-7r3j-2p7m-rq9g/GHSA-7r3j-2p7m-rq9g.json b/advisories/unreviewed/2024/09/GHSA-7r3j-2p7m-rq9g/GHSA-7r3j-2p7m-rq9g.json new file mode 100644 index 00000000000..29f78fd5a40 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-7r3j-2p7m-rq9g/GHSA-7r3j-2p7m-rq9g.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7r3j-2p7m-rq9g", + "modified": "2024-09-25T03:30:37Z", + "published": "2024-09-25T03:30:37Z", + "aliases": [ + "CVE-2024-9024" + ], + "details": "The Material Design Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mdi-icon shortcode in all versions up to, and including, 0.0.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9024" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/material-design-icons/trunk/js/mdi-icons.js#L1311" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/material-design-icons/trunk/plugin.php#L87" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/material-design-icons/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/9979381e-711d-42c8-bfdf-4ee99e2e556f?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T03:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-826x-99fw-6qrv/GHSA-826x-99fw-6qrv.json b/advisories/unreviewed/2024/09/GHSA-826x-99fw-6qrv/GHSA-826x-99fw-6qrv.json new file mode 100644 index 00000000000..ee9975342ee --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-826x-99fw-6qrv/GHSA-826x-99fw-6qrv.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-826x-99fw-6qrv", + "modified": "2024-09-25T03:30:37Z", + "published": "2024-09-25T03:30:37Z", + "aliases": [ + "CVE-2024-8713" + ], + "details": "The Kodex Posts likes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.5.0. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8713" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/kodex-posts-likes/trunk/admin/partials/settings.php#L14" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/44780988-cadf-4ff2-9ba9-148b7b6650df?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T03:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-8g8m-p65c-g42p/GHSA-8g8m-p65c-g42p.json b/advisories/unreviewed/2024/09/GHSA-8g8m-p65c-g42p/GHSA-8g8m-p65c-g42p.json new file mode 100644 index 00000000000..73274d0de3d --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-8g8m-p65c-g42p/GHSA-8g8m-p65c-g42p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8g8m-p65c-g42p", + "modified": "2024-09-25T03:30:36Z", + "published": "2024-09-25T03:30:36Z", + "aliases": [ + "CVE-2024-8877" + ], + "details": "Improper neutralization of special elements results in a SQL Injection vulnerability in Riello Netman 204. It is only limited to the SQLite database of measurement data.This issue affects Netman 204: through 4.05.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8877" + }, + { + "type": "WEB", + "url": "https://cyberdanube.com/en/en-multiple-vulnerabilities-in-riello-netman-204/index.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-8m93-gvh9-j85x/GHSA-8m93-gvh9-j85x.json b/advisories/unreviewed/2024/09/GHSA-8m93-gvh9-j85x/GHSA-8m93-gvh9-j85x.json new file mode 100644 index 00000000000..b6f5c46cf08 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-8m93-gvh9-j85x/GHSA-8m93-gvh9-j85x.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8m93-gvh9-j85x", + "modified": "2024-09-25T03:30:36Z", + "published": "2024-09-25T03:30:36Z", + "aliases": [ + "CVE-2024-8103" + ], + "details": "The WP Category Dropdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' parameter in all versions up to, and including, 1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8103" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-category-dropdown/trunk/build/index.js#L270" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-category-dropdown/trunk/category_dropdown_block.php#L8" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-category-dropdown/trunk/src/edit.js#L258" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-category-dropdown/trunk/src/index.js#L24" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/wp-category-dropdown/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/7c959f9c-8ac4-4f59-9d93-8f96e650b02d?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-8mxg-6836-hfxw/GHSA-8mxg-6836-hfxw.json b/advisories/unreviewed/2024/09/GHSA-8mxg-6836-hfxw/GHSA-8mxg-6836-hfxw.json new file mode 100644 index 00000000000..934eda4f976 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-8mxg-6836-hfxw/GHSA-8mxg-6836-hfxw.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8mxg-6836-hfxw", + "modified": "2024-09-25T03:30:37Z", + "published": "2024-09-25T03:30:37Z", + "aliases": [ + "CVE-2024-9028" + ], + "details": "The WP GPX Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sgpx' shortcode in all versions up to, and including, 1.7.08 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9028" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-gpx-maps/trunk/wp-gpx-maps-admin-tracks.php#L249" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-gpx-maps/trunk/wp-gpx-maps.php#L238" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/wp-gpx-maps/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/872c8328-9089-4bc0-af17-f755524da610?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T03:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-8vp8-g29r-fxpf/GHSA-8vp8-g29r-fxpf.json b/advisories/unreviewed/2024/09/GHSA-8vp8-g29r-fxpf/GHSA-8vp8-g29r-fxpf.json new file mode 100644 index 00000000000..25c6587faae --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-8vp8-g29r-fxpf/GHSA-8vp8-g29r-fxpf.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8vp8-g29r-fxpf", + "modified": "2024-09-25T03:30:36Z", + "published": "2024-09-25T03:30:36Z", + "aliases": [ + "CVE-2024-47048" + ], + "details": "Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier allows stored XSS in the description and release notes of the marketplace and private apps.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47048" + }, + { + "type": "WEB", + "url": "https://github.com/RocketChat/Rocket.Chat/pull/33246" + }, + { + "type": "WEB", + "url": "https://docs.rocket.chat/docs/rocketchat-security-fixes-updates-and-advisories" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-8w9v-r586-45j6/GHSA-8w9v-r586-45j6.json b/advisories/unreviewed/2024/09/GHSA-8w9v-r586-45j6/GHSA-8w9v-r586-45j6.json new file mode 100644 index 00000000000..a3da719e38f --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-8w9v-r586-45j6/GHSA-8w9v-r586-45j6.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8w9v-r586-45j6", + "modified": "2024-09-25T03:30:35Z", + "published": "2024-09-25T03:30:35Z", + "aliases": [ + "CVE-2023-5359" + ], + "details": "The W3 Total Cache plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.5 via Google OAuth API secrets stored in plaintext in the publicly visible plugin source. This can allow unauthenticated attackers to impersonate W3 Total Cache and gain access to user account information in successful conditions. This would not impact the WordPress users site in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5359" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/w3-total-cache/trunk/PageSpeed_Api.php#L39" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3156426/w3-total-cache/tags/2.7.6/PageSpeed_Api.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2d89a534-978e-4fd8-be3a-5137bdc22dc9?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-93ch-7fcj-pjpp/GHSA-93ch-7fcj-pjpp.json b/advisories/unreviewed/2024/09/GHSA-93ch-7fcj-pjpp/GHSA-93ch-7fcj-pjpp.json new file mode 100644 index 00000000000..176ff0e6eeb --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-93ch-7fcj-pjpp/GHSA-93ch-7fcj-pjpp.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-93ch-7fcj-pjpp", + "modified": "2024-09-25T03:30:37Z", + "published": "2024-09-25T03:30:37Z", + "aliases": [ + "CVE-2024-9027" + ], + "details": "The WPZOOM Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'box' shortcode in all versions up to, and including, 1.0.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9027" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wpzoom-shortcodes/trunk/shortcodes/shortcodes.php#L38" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/wpzoom-shortcodes/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2cc03aa9-ad3d-4abb-9c22-cb40875ece47?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T03:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-98hf-m87w-cq6h/GHSA-98hf-m87w-cq6h.json b/advisories/unreviewed/2024/09/GHSA-98hf-m87w-cq6h/GHSA-98hf-m87w-cq6h.json new file mode 100644 index 00000000000..35434aff88d --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-98hf-m87w-cq6h/GHSA-98hf-m87w-cq6h.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-98hf-m87w-cq6h", + "modified": "2024-09-25T03:30:36Z", + "published": "2024-09-25T03:30:36Z", + "aliases": [ + "CVE-2024-46957" + ], + "details": "Mellium mellium.im/xmpp 0.0.1 through 0.21.4 allows response spoofing because the stanza type is not checked. This is fixed in 0.22.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46957" + }, + { + "type": "WEB", + "url": "https://codeberg.org/mellium/xmpp/releases" + }, + { + "type": "WEB", + "url": "https://mellium.im/cve/cve-2024-46957" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-290" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-9q33-jhxg-4ch5/GHSA-9q33-jhxg-4ch5.json b/advisories/unreviewed/2024/09/GHSA-9q33-jhxg-4ch5/GHSA-9q33-jhxg-4ch5.json new file mode 100644 index 00000000000..f2789fff902 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-9q33-jhxg-4ch5/GHSA-9q33-jhxg-4ch5.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9q33-jhxg-4ch5", + "modified": "2024-09-25T03:30:36Z", + "published": "2024-09-25T03:30:36Z", + "aliases": [ + "CVE-2024-46936" + ], + "details": "Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and before is vulnerable to a message forgery / impersonation issue. Attackers can abuse the UpdateOTRAck method to send ephemeral messages as if they were any other user they choose.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46936" + }, + { + "type": "WEB", + "url": "https://github.com/RocketChat/Rocket.Chat/pull/33246" + }, + { + "type": "WEB", + "url": "https://docs.rocket.chat/docs/rocketchat-security-fixes-updates-and-advisories" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-c2c6-68mw-462f/GHSA-c2c6-68mw-462f.json b/advisories/unreviewed/2024/09/GHSA-c2c6-68mw-462f/GHSA-c2c6-68mw-462f.json new file mode 100644 index 00000000000..8ced1766c6c --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-c2c6-68mw-462f/GHSA-c2c6-68mw-462f.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c2c6-68mw-462f", + "modified": "2024-09-25T03:30:36Z", + "published": "2024-09-25T03:30:36Z", + "aliases": [ + "CVE-2024-46934" + ], + "details": "Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to DOM-based Cross-site Scripting (XSS). Attackers may be able to abuse the UpdateOTRAck method to forge a message that contains an XSS payload.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46934" + }, + { + "type": "WEB", + "url": "https://github.com/RocketChat/Rocket.Chat/pull/33246" + }, + { + "type": "WEB", + "url": "https://docs.rocket.chat/docs/rocketchat-security-fixes-updates-and-advisories" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-c6jq-3xcg-q498/GHSA-c6jq-3xcg-q498.json b/advisories/unreviewed/2024/09/GHSA-c6jq-3xcg-q498/GHSA-c6jq-3xcg-q498.json new file mode 100644 index 00000000000..4e1000fe797 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-c6jq-3xcg-q498/GHSA-c6jq-3xcg-q498.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c6jq-3xcg-q498", + "modified": "2024-09-25T03:30:36Z", + "published": "2024-09-25T03:30:35Z", + "aliases": [ + "CVE-2024-45066" + ], + "details": "A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE IP \nsub-menu can allow a remote attacker to inject arbitrary commands.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45066" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-268-04" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-cv79-5xmw-3x8r/GHSA-cv79-5xmw-3x8r.json b/advisories/unreviewed/2024/09/GHSA-cv79-5xmw-3x8r/GHSA-cv79-5xmw-3x8r.json new file mode 100644 index 00000000000..dd1dec51502 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-cv79-5xmw-3x8r/GHSA-cv79-5xmw-3x8r.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cv79-5xmw-3x8r", + "modified": "2024-09-25T03:30:36Z", + "published": "2024-09-25T03:30:36Z", + "aliases": [ + "CVE-2024-7491" + ], + "details": "The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.3.6.1 via the woof_messenger_remove_subscr AJAX action due to missing validation on the 'key' user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to unsubscribe users from a product notification sign-ups, if they can successfully obtain or brute force the key value for users who signed up to receive notifications. This vulnerability requires the plugin's Products Messenger extension to be enabled.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7491" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3156511%40woocommerce-products-filter&old=3129454%40woocommerce-products-filter&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/daf6b0d5-79a6-4b8f-924e-9e78cb2b5742?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T03:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-cwfh-p5vc-jcg4/GHSA-cwfh-p5vc-jcg4.json b/advisories/unreviewed/2024/09/GHSA-cwfh-p5vc-jcg4/GHSA-cwfh-p5vc-jcg4.json index 11eee3fef32..0193d12aaeb 100644 --- a/advisories/unreviewed/2024/09/GHSA-cwfh-p5vc-jcg4/GHSA-cwfh-p5vc-jcg4.json +++ b/advisories/unreviewed/2024/09/GHSA-cwfh-p5vc-jcg4/GHSA-cwfh-p5vc-jcg4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cwfh-p5vc-jcg4", - "modified": "2024-09-24T00:31:32Z", + "modified": "2024-09-25T03:30:35Z", "published": "2024-09-24T00:31:32Z", "aliases": [ "CVE-2024-7023" ], "details": "Insufficient data validation in Updater in Google Chrome prior to 128.0.6537.0 allowed a remote attacker to perform privilege escalation via a malicious file. (Chromium security severity: Medium)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-23T23:15:10Z" diff --git a/advisories/unreviewed/2024/09/GHSA-cx8w-8pxg-9q94/GHSA-cx8w-8pxg-9q94.json b/advisories/unreviewed/2024/09/GHSA-cx8w-8pxg-9q94/GHSA-cx8w-8pxg-9q94.json new file mode 100644 index 00000000000..4a5583478a7 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-cx8w-8pxg-9q94/GHSA-cx8w-8pxg-9q94.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cx8w-8pxg-9q94", + "modified": "2024-09-25T03:30:35Z", + "published": "2024-09-25T03:30:35Z", + "aliases": [ + "CVE-2024-42797" + ], + "details": "An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_playlist in Kashipara Music Management System v1.0. This vulnerability allows an unauthenticated attacker to delete the valid music playlist entries.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42797" + }, + { + "type": "WEB", + "url": "https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Music%20Management%20System%20v1.0/Broken%20Access%20Control%20-%20Delete%20Playlist.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-cxp2-364h-667j/GHSA-cxp2-364h-667j.json b/advisories/unreviewed/2024/09/GHSA-cxp2-364h-667j/GHSA-cxp2-364h-667j.json new file mode 100644 index 00000000000..0ee18213db9 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-cxp2-364h-667j/GHSA-cxp2-364h-667j.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cxp2-364h-667j", + "modified": "2024-09-25T03:30:36Z", + "published": "2024-09-25T03:30:36Z", + "aliases": [ + "CVE-2024-8919" + ], + "details": "The Confetti Fall Animation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'confetti-fall-animation' shortcode in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8919" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/confetti-fall-animation/trunk/confetti-fall-animation.php#L242" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5b80fc93-212e-481d-907c-275139782e77?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-f6r8-rvcx-qr37/GHSA-f6r8-rvcx-qr37.json b/advisories/unreviewed/2024/09/GHSA-f6r8-rvcx-qr37/GHSA-f6r8-rvcx-qr37.json index 3dccd9739df..341e19e35af 100644 --- a/advisories/unreviewed/2024/09/GHSA-f6r8-rvcx-qr37/GHSA-f6r8-rvcx-qr37.json +++ b/advisories/unreviewed/2024/09/GHSA-f6r8-rvcx-qr37/GHSA-f6r8-rvcx-qr37.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f6r8-rvcx-qr37", - "modified": "2024-09-24T00:31:31Z", + "modified": "2024-09-25T03:30:35Z", "published": "2024-09-24T00:31:31Z", "aliases": [ "CVE-2023-7282" ], "details": "Inappropriate implementation in Navigation in Google Chrome prior to 113.0.5672.63 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-451" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-23T22:15:03Z" diff --git a/advisories/unreviewed/2024/09/GHSA-f93h-pcqv-5rf7/GHSA-f93h-pcqv-5rf7.json b/advisories/unreviewed/2024/09/GHSA-f93h-pcqv-5rf7/GHSA-f93h-pcqv-5rf7.json new file mode 100644 index 00000000000..05e64ad853e --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-f93h-pcqv-5rf7/GHSA-f93h-pcqv-5rf7.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f93h-pcqv-5rf7", + "modified": "2024-09-25T03:30:36Z", + "published": "2024-09-25T03:30:36Z", + "aliases": [ + "CVE-2024-46610" + ], + "details": "An access control issue in IceCMS v3.4.7 and before allows attackers to arbitrarily modify users' information, including username and password, via a crafted POST request sent to the endpoint /User/ChangeUser/s in the ChangeUser function in UserController.java", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46610" + }, + { + "type": "WEB", + "url": "https://github.com/Lunax0/LogLunax/blob/main/icecms/CVE-2024-46610.md" + }, + { + "type": "WEB", + "url": "https://github.com/Thecosy/iceCMS?tab=readme-ov-file" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-f95m-8pg6-37q7/GHSA-f95m-8pg6-37q7.json b/advisories/unreviewed/2024/09/GHSA-f95m-8pg6-37q7/GHSA-f95m-8pg6-37q7.json new file mode 100644 index 00000000000..f1952532f25 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-f95m-8pg6-37q7/GHSA-f95m-8pg6-37q7.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f95m-8pg6-37q7", + "modified": "2024-09-25T03:30:36Z", + "published": "2024-09-25T03:30:36Z", + "aliases": [ + "CVE-2024-8914" + ], + "details": "The Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, VNPay và 40 ngân hàng Việt Nam plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.0.1 due to incorrect use of the wp_kses_allowed_html function, which allows the 'onclick' attribute for certain HTML elements without sufficient restriction or context validation. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8914" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/bck-tu-dong-xac-nhan-thanh-toan-chuyen-khoan-ngan-hang/trunk/inc/functions.php#L184" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/bck-tu-dong-xac-nhan-thanh-toan-chuyen-khoan-ngan-hang/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/8ef7c48b-e8f2-40bd-aa48-191059e15453?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-fg7m-78jh-8697/GHSA-fg7m-78jh-8697.json b/advisories/unreviewed/2024/09/GHSA-fg7m-78jh-8697/GHSA-fg7m-78jh-8697.json new file mode 100644 index 00000000000..147114bef12 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-fg7m-78jh-8697/GHSA-fg7m-78jh-8697.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fg7m-78jh-8697", + "modified": "2024-09-25T03:30:37Z", + "published": "2024-09-25T03:30:37Z", + "aliases": [ + "CVE-2024-9068" + ], + "details": "The OneElements – Best Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.3.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9068" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/oneelements-ultimate-addons-for-elementor/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/3f83a514-2b42-4348-9525-438205daeeab?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T03:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-fjx8-c5r7-57qm/GHSA-fjx8-c5r7-57qm.json b/advisories/unreviewed/2024/09/GHSA-fjx8-c5r7-57qm/GHSA-fjx8-c5r7-57qm.json new file mode 100644 index 00000000000..e92346fa99e --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-fjx8-c5r7-57qm/GHSA-fjx8-c5r7-57qm.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fjx8-c5r7-57qm", + "modified": "2024-09-25T03:30:35Z", + "published": "2024-09-25T03:30:35Z", + "aliases": [ + "CVE-2023-26690" + ], + "details": "File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via File Manager/Editor component in the vendor or admin menu.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26690" + }, + { + "type": "WEB", + "url": "https://github.com/cybrops-io/CVEs/tree/main/CVE-2023-26690%20-%20%20File%20Upload%20vulnerability%20in%20File%20Manager%20of%20CS-Cart%20MultiVendor%204.16.1" + }, + { + "type": "WEB", + "url": "https://www.cs-cart.com/multivendor.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-g2fg-5q38-f4pv/GHSA-g2fg-5q38-f4pv.json b/advisories/unreviewed/2024/09/GHSA-g2fg-5q38-f4pv/GHSA-g2fg-5q38-f4pv.json new file mode 100644 index 00000000000..b934c602068 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-g2fg-5q38-f4pv/GHSA-g2fg-5q38-f4pv.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g2fg-5q38-f4pv", + "modified": "2024-09-25T03:30:37Z", + "published": "2024-09-25T03:30:37Z", + "aliases": [ + "CVE-2024-8621" + ], + "details": "The Daily Prayer Time plugin for WordPress is vulnerable to SQL Injection via the 'max_word' attribute of the 'quran_verse' shortcode in all versions up to, and including, 2024.08.26 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8621" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/daily-prayer-time-for-mosques/tags/2024.08.26/Models/QuranADay/QuranDB.php#L72" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3151906" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/866e4bc3-080a-4498-b210-e692d72d3db0?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T03:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-g68m-7q78-xjw3/GHSA-g68m-7q78-xjw3.json b/advisories/unreviewed/2024/09/GHSA-g68m-7q78-xjw3/GHSA-g68m-7q78-xjw3.json new file mode 100644 index 00000000000..7b7291098dc --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-g68m-7q78-xjw3/GHSA-g68m-7q78-xjw3.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g68m-7q78-xjw3", + "modified": "2024-09-25T03:30:36Z", + "published": "2024-09-25T03:30:36Z", + "aliases": [ + "CVE-2024-8481" + ], + "details": "The The Special Text Boxes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 6.2.2. This is due to the plugin adding the filter add_filter('comment_text', 'do_shortcode'); which will run all shortcodes in comments. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8481" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-special-textboxes/trunk/stb-class.php#L36" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/15b2a08f-2122-4eaf-ab46-1945cf6a68ca?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T03:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-gpmc-p7f9-wcpr/GHSA-gpmc-p7f9-wcpr.json b/advisories/unreviewed/2024/09/GHSA-gpmc-p7f9-wcpr/GHSA-gpmc-p7f9-wcpr.json new file mode 100644 index 00000000000..9e53b783ca6 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-gpmc-p7f9-wcpr/GHSA-gpmc-p7f9-wcpr.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gpmc-p7f9-wcpr", + "modified": "2024-09-25T03:30:36Z", + "published": "2024-09-25T03:30:36Z", + "aliases": [ + "CVE-2024-8917" + ], + "details": "The AnWP Football Leagues plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 0.16.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8917" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/football-leagues-by-anwppro/trunk/class-anwp-football-leagues.php#L675" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3153845" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3153845/football-leagues-by-anwppro/trunk/class-anwp-football-leagues.php" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/football-leagues-by-anwppro/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/29a160ea-5582-4028-8621-7988e3a8cabf?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-gr7q-37gq-cg24/GHSA-gr7q-37gq-cg24.json b/advisories/unreviewed/2024/09/GHSA-gr7q-37gq-cg24/GHSA-gr7q-37gq-cg24.json new file mode 100644 index 00000000000..723e0a0078c --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-gr7q-37gq-cg24/GHSA-gr7q-37gq-cg24.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gr7q-37gq-cg24", + "modified": "2024-09-25T03:30:36Z", + "published": "2024-09-25T03:30:36Z", + "aliases": [ + "CVE-2024-8801" + ], + "details": "The Happy Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.2 via the Content Switcher widget. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including private, draft, and pending Elementor templates.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8801" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/happy-elementor-addons/trunk/widgets/content-switcher/widget.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3154460" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/9f1078b8-f458-46a6-9982-e8d2d1d1b73b?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-gxh2-x2v6-99jr/GHSA-gxh2-x2v6-99jr.json b/advisories/unreviewed/2024/09/GHSA-gxh2-x2v6-99jr/GHSA-gxh2-x2v6-99jr.json new file mode 100644 index 00000000000..5f0f1a2b675 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-gxh2-x2v6-99jr/GHSA-gxh2-x2v6-99jr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gxh2-x2v6-99jr", + "modified": "2024-09-25T03:30:35Z", + "published": "2024-09-25T03:30:35Z", + "aliases": [ + "CVE-2024-42505" + ], + "details": "Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities results in the ability to execute arbitrary code as a privileged user on the underlying operating system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42505" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04712en_us&docLocale=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-h558-mxfr-c3px/GHSA-h558-mxfr-c3px.json b/advisories/unreviewed/2024/09/GHSA-h558-mxfr-c3px/GHSA-h558-mxfr-c3px.json new file mode 100644 index 00000000000..921cd6389d8 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-h558-mxfr-c3px/GHSA-h558-mxfr-c3px.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h558-mxfr-c3px", + "modified": "2024-09-25T03:30:35Z", + "published": "2024-09-25T03:30:35Z", + "aliases": [ + "CVE-2023-26688" + ], + "details": "Cross Site Scripting (XSS) vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via the product_data parameter of add/edit product in the administration interface.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26688" + }, + { + "type": "WEB", + "url": "https://github.com/cybrops-io/CVEs/tree/main/CVE-2023-26688%20-%20Cross%20Site%20Scripting%20%28XSS%29%20vulnerability%20in%20CS-Cart%20MultiVendor%204.16.1" + }, + { + "type": "WEB", + "url": "https://www.cs-cart.com/multivendor.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-h55v-8rq9-7qx3/GHSA-h55v-8rq9-7qx3.json b/advisories/unreviewed/2024/09/GHSA-h55v-8rq9-7qx3/GHSA-h55v-8rq9-7qx3.json new file mode 100644 index 00000000000..71a62a7d55b --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-h55v-8rq9-7qx3/GHSA-h55v-8rq9-7qx3.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h55v-8rq9-7qx3", + "modified": "2024-09-25T03:30:36Z", + "published": "2024-09-25T03:30:36Z", + "aliases": [ + "CVE-2024-8497" + ], + "details": "Franklin Fueling Systems TS-550 EVO versions prior to 2.26.4.8967 possess a file that can be read arbitrarily that could allow an attacker obtain administrator credentials.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8497" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-268-03" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-36" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-h863-2hm3-rc4r/GHSA-h863-2hm3-rc4r.json b/advisories/unreviewed/2024/09/GHSA-h863-2hm3-rc4r/GHSA-h863-2hm3-rc4r.json new file mode 100644 index 00000000000..40f302624b4 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-h863-2hm3-rc4r/GHSA-h863-2hm3-rc4r.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h863-2hm3-rc4r", + "modified": "2024-09-25T03:30:35Z", + "published": "2024-09-25T03:30:35Z", + "aliases": [ + "CVE-2023-26691" + ], + "details": "Directory Traversal vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via crafted zip file when installing a new add-on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26691" + }, + { + "type": "WEB", + "url": "https://github.com/cybrops-io/CVEs/tree/main/CVE-2023-26691%20-%20Zip%20Slip%20in%20CS-Cart%20MultiVendor%204.16.1" + }, + { + "type": "WEB", + "url": "https://www.cs-cart.com/multivendor.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-h8vm-65gc-gw46/GHSA-h8vm-65gc-gw46.json b/advisories/unreviewed/2024/09/GHSA-h8vm-65gc-gw46/GHSA-h8vm-65gc-gw46.json new file mode 100644 index 00000000000..545ac7d50ec --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-h8vm-65gc-gw46/GHSA-h8vm-65gc-gw46.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h8vm-65gc-gw46", + "modified": "2024-09-25T03:30:35Z", + "published": "2024-09-25T03:30:35Z", + "aliases": [ + "CVE-2024-38324" + ], + "details": "IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI does not validate server name during registration and unregistration operations which could expose sensitive information to an attacker with access to the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38324" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7168640" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-297" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-hwr4-f3g6-5mmp/GHSA-hwr4-f3g6-5mmp.json b/advisories/unreviewed/2024/09/GHSA-hwr4-f3g6-5mmp/GHSA-hwr4-f3g6-5mmp.json new file mode 100644 index 00000000000..89a10e51d6e --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-hwr4-f3g6-5mmp/GHSA-hwr4-f3g6-5mmp.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hwr4-f3g6-5mmp", + "modified": "2024-09-25T03:30:36Z", + "published": "2024-09-25T03:30:36Z", + "aliases": [ + "CVE-2024-46612" + ], + "details": "IceCMS v3.4.7 and before was discovered to contain a hardcoded JWT key, allowing an attacker to forge JWT authentication information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46612" + }, + { + "type": "WEB", + "url": "https://github.com/Lunax0/LogLunax/blob/main/icecms/CVE-2024-46612.md" + }, + { + "type": "WEB", + "url": "https://github.com/Thecosy/iceCMS?tab=readme-ov-file" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-321" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-j287-529v-pjr9/GHSA-j287-529v-pjr9.json b/advisories/unreviewed/2024/09/GHSA-j287-529v-pjr9/GHSA-j287-529v-pjr9.json new file mode 100644 index 00000000000..3ed07f8e62c --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-j287-529v-pjr9/GHSA-j287-529v-pjr9.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j287-529v-pjr9", + "modified": "2024-09-25T03:30:36Z", + "published": "2024-09-25T03:30:35Z", + "aliases": [ + "CVE-2024-45373" + ], + "details": "Once logged in to ProGauge MAGLINK LX4 CONSOLE, a valid user can change their privileges to administrator.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45373" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-268-04" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-jc57-w67w-3ggw/GHSA-jc57-w67w-3ggw.json b/advisories/unreviewed/2024/09/GHSA-jc57-w67w-3ggw/GHSA-jc57-w67w-3ggw.json new file mode 100644 index 00000000000..c6140462e2a --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-jc57-w67w-3ggw/GHSA-jc57-w67w-3ggw.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jc57-w67w-3ggw", + "modified": "2024-09-25T03:30:36Z", + "published": "2024-09-25T03:30:36Z", + "aliases": [ + "CVE-2024-8476" + ], + "details": "The Easy PayPal Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.1. This is due to missing or incorrect nonce validation on the wpeevent_plugin_buttons() function. This makes it possible for unauthenticated attackers to delete arbitrary posts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8476" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/easy-paypal-events-tickets/tags/1.2.1/includes/private_buttons.php#L273" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/easy-paypal-events-tickets/tags/1.2.1/includes/private_buttons.php#L5" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3155809/easy-paypal-events-tickets/trunk/includes/private_buttons.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/602d337e-0778-4182-8e77-0eb3b37d5a7a?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T03:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-m5p9-xvxj-64c8/GHSA-m5p9-xvxj-64c8.json b/advisories/unreviewed/2024/09/GHSA-m5p9-xvxj-64c8/GHSA-m5p9-xvxj-64c8.json new file mode 100644 index 00000000000..f95f477981c --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-m5p9-xvxj-64c8/GHSA-m5p9-xvxj-64c8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m5p9-xvxj-64c8", + "modified": "2024-09-25T03:30:36Z", + "published": "2024-09-25T03:30:36Z", + "aliases": [ + "CVE-2024-9148" + ], + "details": "Flowise < 2.1.1 suffers from a Stored Cross-Site vulnerability due to a lack of input sanitization in Flowise Chat Embed < 2.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9148" + }, + { + "type": "WEB", + "url": "https://www.tenable.com/security/research/tra-2024-40" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-mc8h-gfm5-j86q/GHSA-mc8h-gfm5-j86q.json b/advisories/unreviewed/2024/09/GHSA-mc8h-gfm5-j86q/GHSA-mc8h-gfm5-j86q.json new file mode 100644 index 00000000000..a7cb1ae844a --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-mc8h-gfm5-j86q/GHSA-mc8h-gfm5-j86q.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mc8h-gfm5-j86q", + "modified": "2024-09-25T03:30:36Z", + "published": "2024-09-25T03:30:36Z", + "aliases": [ + "CVE-2024-7617" + ], + "details": "The Contact Form to Any API plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Contact Form 7 form fields in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7617" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/contact-form-to-any-api/trunk/admin/partials/cf7-to-any-api-admin-entries.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/39487908-5cc5-42ac-8af4-65626694b1e4?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T03:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-mrxm-9rwr-qw4f/GHSA-mrxm-9rwr-qw4f.json b/advisories/unreviewed/2024/09/GHSA-mrxm-9rwr-qw4f/GHSA-mrxm-9rwr-qw4f.json new file mode 100644 index 00000000000..d68b6b79449 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-mrxm-9rwr-qw4f/GHSA-mrxm-9rwr-qw4f.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mrxm-9rwr-qw4f", + "modified": "2024-09-25T03:30:36Z", + "published": "2024-09-25T03:30:35Z", + "aliases": [ + "CVE-2024-43693" + ], + "details": "A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE \nUTILITY sub-menu can allow a remote attacker to inject arbitrary \ncommands.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43693" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-268-04" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-p2cr-39jq-4vw3/GHSA-p2cr-39jq-4vw3.json b/advisories/unreviewed/2024/09/GHSA-p2cr-39jq-4vw3/GHSA-p2cr-39jq-4vw3.json new file mode 100644 index 00000000000..8f7955265b0 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-p2cr-39jq-4vw3/GHSA-p2cr-39jq-4vw3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p2cr-39jq-4vw3", + "modified": "2024-09-25T03:30:36Z", + "published": "2024-09-25T03:30:35Z", + "aliases": [ + "CVE-2024-42507" + ], + "details": "Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities results in the ability to execute arbitrary code as a privileged user on the underlying operating system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42507" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04712en_us&docLocale=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-phjc-jpwh-fv7x/GHSA-phjc-jpwh-fv7x.json b/advisories/unreviewed/2024/09/GHSA-phjc-jpwh-fv7x/GHSA-phjc-jpwh-fv7x.json new file mode 100644 index 00000000000..c4727c98ebd --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-phjc-jpwh-fv7x/GHSA-phjc-jpwh-fv7x.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phjc-jpwh-fv7x", + "modified": "2024-09-25T03:30:37Z", + "published": "2024-09-25T03:30:37Z", + "aliases": [ + "CVE-2024-9069" + ], + "details": "The Graphicsly – The ultimate graphics plugin for WordPress website builder ( Gutenberg, Elementor, Beaver Builder, WPBakery ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9069" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/graphicsly/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/343a6dbd-baf5-4de8-ae3e-6954fd3f1556?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T03:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-pvc7-6xhm-95vf/GHSA-pvc7-6xhm-95vf.json b/advisories/unreviewed/2024/09/GHSA-pvc7-6xhm-95vf/GHSA-pvc7-6xhm-95vf.json new file mode 100644 index 00000000000..eff3e1f3df8 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-pvc7-6xhm-95vf/GHSA-pvc7-6xhm-95vf.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pvc7-6xhm-95vf", + "modified": "2024-09-25T03:30:37Z", + "published": "2024-09-25T03:30:37Z", + "aliases": [ + "CVE-2024-8741" + ], + "details": "The Beam me up Scotty – Back to Top Button plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.0.21. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8741" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/beam-me-up-scotty/tags/1.0.21/library/template-parts/tabs.php#L27" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3156146/beam-me-up-scotty/trunk/library/template-parts/tabs.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/3428bc71-64f9-4f8d-85c8-7dda81b2ac18?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T03:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-q7qr-22qw-pqgx/GHSA-q7qr-22qw-pqgx.json b/advisories/unreviewed/2024/09/GHSA-q7qr-22qw-pqgx/GHSA-q7qr-22qw-pqgx.json new file mode 100644 index 00000000000..71d50ad98db --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-q7qr-22qw-pqgx/GHSA-q7qr-22qw-pqgx.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q7qr-22qw-pqgx", + "modified": "2024-09-25T03:30:36Z", + "published": "2024-09-25T03:30:36Z", + "aliases": [ + "CVE-2024-8291" + ], + "details": "Concrete CMS versions 9.0.0 to 9.3.3 and below 8.5.19 are vulnerable to Stored XSS in Image Editor Background Color.  A rogue admin could add malicious code to the Thumbnails/Add-Type. The Concrete CMS Security Team gave this a CVSS v4 score of 2.1 with vector CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N  Thanks,  Alexey Solovyev for reporting.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8291" + }, + { + "type": "WEB", + "url": "https://github.com/concretecms/concretecms/pull/12183" + }, + { + "type": "WEB", + "url": "https://github.com/concretecms/concretecms/commit/dbce253166f6b10ff3e0c09e50fd395370b8b065" + }, + { + "type": "WEB", + "url": "https://documentation.concretecms.org/9-x/developers/introduction/version-history/934-release-notes" + }, + { + "type": "WEB", + "url": "https://documentation.concretecms.org/developers/introduction/version-history/8519-release-notes" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-q97c-vhwv-v5w3/GHSA-q97c-vhwv-v5w3.json b/advisories/unreviewed/2024/09/GHSA-q97c-vhwv-v5w3/GHSA-q97c-vhwv-v5w3.json new file mode 100644 index 00000000000..7523e605b15 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-q97c-vhwv-v5w3/GHSA-q97c-vhwv-v5w3.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q97c-vhwv-v5w3", + "modified": "2024-09-25T03:30:36Z", + "published": "2024-09-25T03:30:36Z", + "aliases": [ + "CVE-2024-7426" + ], + "details": "The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 6.4.6.0. This is due to the plugin displaying errors and allowing direct access to the sse.php file. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7426" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/peepso-core/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2e69d666-50de-4c82-9ad4-9ed40fcc7218?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T03:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-qcr8-x9j3-5j62/GHSA-qcr8-x9j3-5j62.json b/advisories/unreviewed/2024/09/GHSA-qcr8-x9j3-5j62/GHSA-qcr8-x9j3-5j62.json new file mode 100644 index 00000000000..5823ecca06c --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-qcr8-x9j3-5j62/GHSA-qcr8-x9j3-5j62.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qcr8-x9j3-5j62", + "modified": "2024-09-25T03:30:36Z", + "published": "2024-09-25T03:30:36Z", + "aliases": [ + "CVE-2024-9121" + ], + "details": "Inappropriate implementation in V8 in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9121" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/09/stable-channel-update-for-desktop_24.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/363538434" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-qqwc-7hxc-6ghp/GHSA-qqwc-7hxc-6ghp.json b/advisories/unreviewed/2024/09/GHSA-qqwc-7hxc-6ghp/GHSA-qqwc-7hxc-6ghp.json new file mode 100644 index 00000000000..cdcec63e27c --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-qqwc-7hxc-6ghp/GHSA-qqwc-7hxc-6ghp.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qqwc-7hxc-6ghp", + "modified": "2024-09-25T03:30:35Z", + "published": "2024-09-25T03:30:35Z", + "aliases": [ + "CVE-2023-26686" + ], + "details": "File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via the image upload feature when customizing a shop.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26686" + }, + { + "type": "WEB", + "url": "https://github.com/cybrops-io/CVEs/tree/main/CVE-2023-26686%20-%20File%20Upload%20vulnerability%20in%20product%20image%20of%20CS-Cart%20MultiVendor%204.16.1" + }, + { + "type": "WEB", + "url": "https://www.cs-cart.com/multivendor.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-qxr9-x265-vp39/GHSA-qxr9-x265-vp39.json b/advisories/unreviewed/2024/09/GHSA-qxr9-x265-vp39/GHSA-qxr9-x265-vp39.json index dbc32c01502..8bd78a3dbc2 100644 --- a/advisories/unreviewed/2024/09/GHSA-qxr9-x265-vp39/GHSA-qxr9-x265-vp39.json +++ b/advisories/unreviewed/2024/09/GHSA-qxr9-x265-vp39/GHSA-qxr9-x265-vp39.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qxr9-x265-vp39", - "modified": "2024-09-24T00:31:32Z", + "modified": "2024-09-25T03:30:35Z", "published": "2024-09-24T00:31:32Z", "aliases": [ "CVE-2024-7020" ], "details": "Inappropriate implementation in Autofill in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-451" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-23T22:15:03Z" diff --git a/advisories/unreviewed/2024/09/GHSA-r44h-cw52-2x2f/GHSA-r44h-cw52-2x2f.json b/advisories/unreviewed/2024/09/GHSA-r44h-cw52-2x2f/GHSA-r44h-cw52-2x2f.json new file mode 100644 index 00000000000..91341d4d42f --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-r44h-cw52-2x2f/GHSA-r44h-cw52-2x2f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r44h-cw52-2x2f", + "modified": "2024-09-25T03:30:36Z", + "published": "2024-09-25T03:30:36Z", + "aliases": [ + "CVE-2024-8940" + ], + "details": "Vulnerability in the Scriptcase application version 9.4.019, which involves the arbitrary upload of a file via /scriptcase/devel/lib/third/jquery_plugin/jQuery-File-Upload/server/php/ via a POST request. An attacker could upload malicious files to the server due to the application not properly verifying user input.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8940" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-scriptcase" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-rm3j-jj6h-qrq4/GHSA-rm3j-jj6h-qrq4.json b/advisories/unreviewed/2024/09/GHSA-rm3j-jj6h-qrq4/GHSA-rm3j-jj6h-qrq4.json new file mode 100644 index 00000000000..e71c8f94b5d --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-rm3j-jj6h-qrq4/GHSA-rm3j-jj6h-qrq4.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rm3j-jj6h-qrq4", + "modified": "2024-09-25T03:30:36Z", + "published": "2024-09-25T03:30:36Z", + "aliases": [ + "CVE-2024-46607" + ], + "details": "Incorrect access control in IceCMS v3.4.7 and before allows attackers to authenticate by entering any arbitrary values as the username and password via the loginAdmin method in the UserController.java file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46607" + }, + { + "type": "WEB", + "url": "https://github.com/Lunax0/LogLunax/blob/main/icecms/CVE-2024-46607.md" + }, + { + "type": "WEB", + "url": "https://github.com/Thecosy/iceCMS?tab=readme-ov-file" + }, + { + "type": "WEB", + "url": "http://icecms.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-rxmx-cgf3-gfph/GHSA-rxmx-cgf3-gfph.json b/advisories/unreviewed/2024/09/GHSA-rxmx-cgf3-gfph/GHSA-rxmx-cgf3-gfph.json index e5520dbd6be..3be19951df8 100644 --- a/advisories/unreviewed/2024/09/GHSA-rxmx-cgf3-gfph/GHSA-rxmx-cgf3-gfph.json +++ b/advisories/unreviewed/2024/09/GHSA-rxmx-cgf3-gfph/GHSA-rxmx-cgf3-gfph.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rxmx-cgf3-gfph", - "modified": "2024-09-23T18:30:34Z", + "modified": "2024-09-25T03:30:35Z", "published": "2024-09-23T18:30:34Z", "aliases": [ "CVE-2024-40442" ], "details": "An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pipeline module to annotate a document automatically v.0.1.23 allows a remote attacker to escalate privileges via a crafted REST Request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-23T17:15:13Z" diff --git a/advisories/unreviewed/2024/09/GHSA-vj7c-8fv8-732h/GHSA-vj7c-8fv8-732h.json b/advisories/unreviewed/2024/09/GHSA-vj7c-8fv8-732h/GHSA-vj7c-8fv8-732h.json new file mode 100644 index 00000000000..04168f69328 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-vj7c-8fv8-732h/GHSA-vj7c-8fv8-732h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vj7c-8fv8-732h", + "modified": "2024-09-25T03:30:35Z", + "published": "2024-09-25T03:30:35Z", + "aliases": [ + "CVE-2023-26687" + ], + "details": "Directory Traversal vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to obtain sensitive information via the product_data parameter in the PDF Add-on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26687" + }, + { + "type": "WEB", + "url": "https://github.com/cybrops-io/CVEs/tree/main/CVE-2023-26687%20-%20Local%20File%20Inclusion%20vulnerability%20in%20CS-Cart%20MultiVendor" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-w3jq-wqph-2fhr/GHSA-w3jq-wqph-2fhr.json b/advisories/unreviewed/2024/09/GHSA-w3jq-wqph-2fhr/GHSA-w3jq-wqph-2fhr.json new file mode 100644 index 00000000000..ad514540b27 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-w3jq-wqph-2fhr/GHSA-w3jq-wqph-2fhr.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w3jq-wqph-2fhr", + "modified": "2024-09-25T03:30:36Z", + "published": "2024-09-25T03:30:36Z", + "aliases": [ + "CVE-2024-8349" + ], + "details": "The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.1.0.1. This is due to the plugin not properly restricting what users a group leader can edit. This makes it possible for authenticated attackers, with group leader-level access and above, to change admin account email addresses which can subsequently lead to admin account access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8349" + }, + { + "type": "WEB", + "url": "https://github.com/karlemilnikka/CVE-2024-8349-and-CVE-2024-8350" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/64cf0ae2-8d66-40d1-8bb6-0cab1dafab0d?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T03:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-w72w-8rm9-6684/GHSA-w72w-8rm9-6684.json b/advisories/unreviewed/2024/09/GHSA-w72w-8rm9-6684/GHSA-w72w-8rm9-6684.json new file mode 100644 index 00000000000..9259275d976 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-w72w-8rm9-6684/GHSA-w72w-8rm9-6684.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w72w-8rm9-6684", + "modified": "2024-09-25T03:30:36Z", + "published": "2024-09-25T03:30:36Z", + "aliases": [ + "CVE-2024-8067" + ], + "details": "In versions of Helix Core prior to 2024.1 Patch 2 (2024.1/2655224) a Windows ANSI API Unicode \"best fit\" argument injection was identified.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8067" + }, + { + "type": "WEB", + "url": "https://portal.perforce.com/s/detail/a91PA000001SXEzYAO" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-176" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-wpw2-69v8-6f9h/GHSA-wpw2-69v8-6f9h.json b/advisories/unreviewed/2024/09/GHSA-wpw2-69v8-6f9h/GHSA-wpw2-69v8-6f9h.json new file mode 100644 index 00000000000..41466708e89 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-wpw2-69v8-6f9h/GHSA-wpw2-69v8-6f9h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wpw2-69v8-6f9h", + "modified": "2024-09-25T03:30:35Z", + "published": "2024-09-25T03:30:35Z", + "aliases": [ + "CVE-2022-43845" + ], + "details": "IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43845" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7169766" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1004" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-wvhj-f7hf-4qv2/GHSA-wvhj-f7hf-4qv2.json b/advisories/unreviewed/2024/09/GHSA-wvhj-f7hf-4qv2/GHSA-wvhj-f7hf-4qv2.json new file mode 100644 index 00000000000..184472a83de --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-wvhj-f7hf-4qv2/GHSA-wvhj-f7hf-4qv2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wvhj-f7hf-4qv2", + "modified": "2024-09-25T03:30:36Z", + "published": "2024-09-25T03:30:36Z", + "aliases": [ + "CVE-2024-9141" + ], + "details": "Cross-Site Scripting (XSS) vulnerability in the Oct8ne system. This flaw could allow an attacker to embed harmful JavaScript code into the body of a chat message. This manipulation occurs when the chat content is intercepted and altered, leading to the execution of the JavaScript payload.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9141" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/cross-site-scripting-xss-vulnerability-oct8ne" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-wx2g-pjx5-v6r9/GHSA-wx2g-pjx5-v6r9.json b/advisories/unreviewed/2024/09/GHSA-wx2g-pjx5-v6r9/GHSA-wx2g-pjx5-v6r9.json new file mode 100644 index 00000000000..2c2a146488b --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-wx2g-pjx5-v6r9/GHSA-wx2g-pjx5-v6r9.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wx2g-pjx5-v6r9", + "modified": "2024-09-25T03:30:36Z", + "published": "2024-09-25T03:30:36Z", + "aliases": [ + "CVE-2024-46609" + ], + "details": "An access control issue in the CheckVip function in UserController.java of IceCMS v3.4.7 and before allows unauthenticated attackers to access and returns all user information, including passwords", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46609" + }, + { + "type": "WEB", + "url": "https://github.com/Lunax0/LogLunax/blob/main/icecms/CVE-2024-46609.md" + }, + { + "type": "WEB", + "url": "https://github.com/Thecosy/iceCMS?tab=readme-ov-file" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-x4p5-53p5-3j33/GHSA-x4p5-53p5-3j33.json b/advisories/unreviewed/2024/09/GHSA-x4p5-53p5-3j33/GHSA-x4p5-53p5-3j33.json new file mode 100644 index 00000000000..8d5b1941b5c --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-x4p5-53p5-3j33/GHSA-x4p5-53p5-3j33.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x4p5-53p5-3j33", + "modified": "2024-09-25T03:30:36Z", + "published": "2024-09-25T03:30:35Z", + "aliases": [ + "CVE-2024-43692" + ], + "details": "An attacker can directly request the ProGauge MAGLINK LX CONSOLE \nresource sub page with full privileges by requesting the URL directly.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43692" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-268-04" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-x8h2-255q-jg4x/GHSA-x8h2-255q-jg4x.json b/advisories/unreviewed/2024/09/GHSA-x8h2-255q-jg4x/GHSA-x8h2-255q-jg4x.json new file mode 100644 index 00000000000..72932401fe3 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-x8h2-255q-jg4x/GHSA-x8h2-255q-jg4x.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x8h2-255q-jg4x", + "modified": "2024-09-25T03:30:36Z", + "published": "2024-09-25T03:30:36Z", + "aliases": [ + "CVE-2024-7398" + ], + "details": "Concrete CMS versions 9 through 9.3.3 and versions below 8.5.19 are vulnerable to stored XSS in the calendar event addition feature because the calendar event name was not sanitized on output. Users or groups with permission to create event calendars can embed scripts, and users or groups with permission to modify event calendars can execute scripts. The Concrete CMS Security Team gave this vulnerability a CVSS v4 score of 1.8 with vector CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:A/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:A/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N . Thank you, Yusuke Uchida for reporting.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:A/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7398" + }, + { + "type": "WEB", + "url": "https://github.com/concretecms/concretecms/pull/12183" + }, + { + "type": "WEB", + "url": "https://github.com/concretecms/concretecms/pull/12184" + }, + { + "type": "WEB", + "url": "https://github.com/concretecms/concretecms/commit/7c8ed0d1d9db0d7f6df7fa066e0858ea618451a5" + }, + { + "type": "WEB", + "url": "https://documentation.concretecms.org/9-x/developers/introduction/version-history/934-release-notes" + }, + { + "type": "WEB", + "url": "https://documentation.concretecms.org/developers/introduction/version-history/8519-release-notes" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-xh87-v57g-jhpw/GHSA-xh87-v57g-jhpw.json b/advisories/unreviewed/2024/09/GHSA-xh87-v57g-jhpw/GHSA-xh87-v57g-jhpw.json new file mode 100644 index 00000000000..92f180bd39a --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-xh87-v57g-jhpw/GHSA-xh87-v57g-jhpw.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xh87-v57g-jhpw", + "modified": "2024-09-25T03:30:36Z", + "published": "2024-09-25T03:30:36Z", + "aliases": [ + "CVE-2024-9120" + ], + "details": "Use after free in Dawn in Google Chrome on Windows prior to 129.0.6668.70 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9120" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/09/stable-channel-update-for-desktop_24.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/365254285" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-xhff-3q93-x4p6/GHSA-xhff-3q93-x4p6.json b/advisories/unreviewed/2024/09/GHSA-xhff-3q93-x4p6/GHSA-xhff-3q93-x4p6.json new file mode 100644 index 00000000000..6c5abf2bfac --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-xhff-3q93-x4p6/GHSA-xhff-3q93-x4p6.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xhff-3q93-x4p6", + "modified": "2024-09-25T03:30:37Z", + "published": "2024-09-25T03:30:37Z", + "aliases": [ + "CVE-2024-9073" + ], + "details": "The GutenGeek Free Gutenberg Blocks for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9073" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/gtg-advanced-blocks/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f1c68f9d-a026-4cef-82e6-25949a3d59ad?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T03:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-xpx9-f724-2jfc/GHSA-xpx9-f724-2jfc.json b/advisories/unreviewed/2024/09/GHSA-xpx9-f724-2jfc/GHSA-xpx9-f724-2jfc.json new file mode 100644 index 00000000000..b67148d6ce7 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-xpx9-f724-2jfc/GHSA-xpx9-f724-2jfc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xpx9-f724-2jfc", + "modified": "2024-09-25T03:30:36Z", + "published": "2024-09-25T03:30:36Z", + "aliases": [ + "CVE-2024-8942" + ], + "details": "Vulnerability in Scriptcase version 9.4.019 that consists of a Cross-Site Scripting (XSS), due to the lack of input validation, affecting the “id_form_msg_title” parameter, among others. This vulnerability could allow a remote user to send a specially crafted URL to a victim and retrieve their credentials.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8942" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-scriptcase" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-xqjg-gmg7-72xr/GHSA-xqjg-gmg7-72xr.json b/advisories/unreviewed/2024/09/GHSA-xqjg-gmg7-72xr/GHSA-xqjg-gmg7-72xr.json index fb2cfc58b4f..6bd955f56ba 100644 --- a/advisories/unreviewed/2024/09/GHSA-xqjg-gmg7-72xr/GHSA-xqjg-gmg7-72xr.json +++ b/advisories/unreviewed/2024/09/GHSA-xqjg-gmg7-72xr/GHSA-xqjg-gmg7-72xr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xqjg-gmg7-72xr", - "modified": "2024-09-24T00:31:32Z", + "modified": "2024-09-25T03:30:35Z", "published": "2024-09-24T00:31:32Z", "aliases": [ "CVE-2024-7019" ], "details": "Inappropriate implementation in UI in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-451" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-23T22:15:03Z" diff --git a/advisories/unreviewed/2024/09/GHSA-xvwc-mxm8-8hqg/GHSA-xvwc-mxm8-8hqg.json b/advisories/unreviewed/2024/09/GHSA-xvwc-mxm8-8hqg/GHSA-xvwc-mxm8-8hqg.json new file mode 100644 index 00000000000..4c6aee4b185 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-xvwc-mxm8-8hqg/GHSA-xvwc-mxm8-8hqg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xvwc-mxm8-8hqg", + "modified": "2024-09-25T03:30:35Z", + "published": "2024-09-25T03:30:35Z", + "aliases": [ + "CVE-2023-26689" + ], + "details": "An issue discovered in CS-Cart MultiVendor 4.16.1 allows attackers to alter arbitrary user account profiles via crafted post request.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26689" + }, + { + "type": "WEB", + "url": "https://github.com/cybrops-io/CVEs/tree/main/CVE-2023-26689%20-%20Insufficient%20Authorization%20for%20API%20key%20creation%20in%20CS-Cart%20MultiVendor%204.16.1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-286" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-xwv3-34j2-7jgx/GHSA-xwv3-34j2-7jgx.json b/advisories/unreviewed/2024/09/GHSA-xwv3-34j2-7jgx/GHSA-xwv3-34j2-7jgx.json new file mode 100644 index 00000000000..e8a156263e8 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-xwv3-34j2-7jgx/GHSA-xwv3-34j2-7jgx.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xwv3-34j2-7jgx", + "modified": "2024-09-25T03:30:36Z", + "published": "2024-09-25T03:30:36Z", + "aliases": [ + "CVE-2024-9123" + ], + "details": "Integer overflow in Skia in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9123" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/09/stable-channel-update-for-desktop_24.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/365884464" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190", + "CWE-472" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T01:15:48Z" + } +} \ No newline at end of file