From 5781cd00cbd3f4249eee9351b86e22d26574213b Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 20 Nov 2024 15:32:03 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-6887-rccf-7c23.json | 9 ++-- .../GHSA-6qrc-68pp-rj6x.json | 7 ++- .../GHSA-fgvj-4m6x-j67f.json | 6 ++- .../GHSA-p8xr-vj9g-9j25.json | 2 +- .../GHSA-w2gv-7447-6h8c.json | 7 ++- .../GHSA-3h2r-mh7w-gr5w.json | 2 +- .../GHSA-662h-7f84-69rv.json | 2 +- .../GHSA-hm28-rwr4-j8f5.json | 9 ++-- .../GHSA-3gr8-4rjx-crp8.json | 39 +++++++++++++++ .../GHSA-42jm-px5r-4qxq.json | 1 + .../GHSA-47rc-w5x7-93j8.json | 3 +- .../GHSA-48rr-fh2m-hhjh.json | 1 + .../GHSA-4pm3-3999-hj74.json | 38 ++++++++++++++ .../GHSA-535g-mv5c-jrh8.json | 50 +++++++++++++++++++ .../GHSA-5436-rp7w-v3hq.json | 38 ++++++++++++++ .../GHSA-8ff3-4xrr-3mhr.json | 38 ++++++++++++++ .../GHSA-94rm-rq6h-h95x.json | 38 ++++++++++++++ .../GHSA-9rq6-3xh4-jjch.json | 3 +- .../GHSA-cgr4-9xhv-p6x6.json | 3 +- .../GHSA-crmh-vcgf-prwv.json | 2 +- .../GHSA-cwrq-8w42-mhc5.json | 38 ++++++++++++++ .../GHSA-f75h-cwp9-8h5x.json | 3 +- .../GHSA-gwhh-pw54-jgx4.json | 1 + .../GHSA-gwm3-gp4w-96g7.json | 1 + .../GHSA-gx4q-m69p-mf52.json | 1 + .../GHSA-h53w-2cq3-cj2p.json | 3 +- .../GHSA-hjr8-c78p-hrvc.json | 1 + .../GHSA-hwv8-q8m9-3f2j.json | 38 ++++++++++++++ .../GHSA-j4v3-wwwx-5gqv.json | 6 ++- .../GHSA-mqxv-7638-9mpv.json | 38 ++++++++++++++ .../GHSA-p284-cx3v-33vg.json | 38 ++++++++++++++ .../GHSA-pr37-gvg2-qr9v.json | 1 + .../GHSA-qj3w-6895-r5mf.json | 1 + .../GHSA-qwhj-q28h-8hg6.json | 39 +++++++++++++++ .../GHSA-wpfc-gx92-f98v.json | 11 ++-- .../GHSA-wrr5-xwcp-mrf2.json | 9 ++-- .../GHSA-xc59-47r9-5932.json | 46 +++++++++++++++++ 37 files changed, 545 insertions(+), 28 deletions(-) create mode 100644 advisories/unreviewed/2024/11/GHSA-3gr8-4rjx-crp8/GHSA-3gr8-4rjx-crp8.json create mode 100644 advisories/unreviewed/2024/11/GHSA-4pm3-3999-hj74/GHSA-4pm3-3999-hj74.json create mode 100644 advisories/unreviewed/2024/11/GHSA-535g-mv5c-jrh8/GHSA-535g-mv5c-jrh8.json create mode 100644 advisories/unreviewed/2024/11/GHSA-5436-rp7w-v3hq/GHSA-5436-rp7w-v3hq.json create mode 100644 advisories/unreviewed/2024/11/GHSA-8ff3-4xrr-3mhr/GHSA-8ff3-4xrr-3mhr.json create mode 100644 advisories/unreviewed/2024/11/GHSA-94rm-rq6h-h95x/GHSA-94rm-rq6h-h95x.json create mode 100644 advisories/unreviewed/2024/11/GHSA-cwrq-8w42-mhc5/GHSA-cwrq-8w42-mhc5.json create mode 100644 advisories/unreviewed/2024/11/GHSA-hwv8-q8m9-3f2j/GHSA-hwv8-q8m9-3f2j.json create mode 100644 advisories/unreviewed/2024/11/GHSA-mqxv-7638-9mpv/GHSA-mqxv-7638-9mpv.json create mode 100644 advisories/unreviewed/2024/11/GHSA-p284-cx3v-33vg/GHSA-p284-cx3v-33vg.json create mode 100644 advisories/unreviewed/2024/11/GHSA-qwhj-q28h-8hg6/GHSA-qwhj-q28h-8hg6.json create mode 100644 advisories/unreviewed/2024/11/GHSA-xc59-47r9-5932/GHSA-xc59-47r9-5932.json diff --git a/advisories/unreviewed/2022/05/GHSA-6887-rccf-7c23/GHSA-6887-rccf-7c23.json b/advisories/unreviewed/2022/05/GHSA-6887-rccf-7c23/GHSA-6887-rccf-7c23.json index 0fe30c9074e..16d088c61f9 100644 --- a/advisories/unreviewed/2022/05/GHSA-6887-rccf-7c23/GHSA-6887-rccf-7c23.json +++ b/advisories/unreviewed/2022/05/GHSA-6887-rccf-7c23/GHSA-6887-rccf-7c23.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6887-rccf-7c23", - "modified": "2022-05-24T17:17:16Z", + "modified": "2024-11-20T15:30:48Z", "published": "2022-05-24T17:17:16Z", "aliases": [ "CVE-2020-11727" ], "details": "A cross-site scripting (XSS) vulnerability in the AlgolPlus Advanced Order Export For WooCommerce plugin 3.1.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the view/settings-form.php woe_post_type parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -37,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-6qrc-68pp-rj6x/GHSA-6qrc-68pp-rj6x.json b/advisories/unreviewed/2022/05/GHSA-6qrc-68pp-rj6x/GHSA-6qrc-68pp-rj6x.json index d0c5af2d846..080fc43852d 100644 --- a/advisories/unreviewed/2022/05/GHSA-6qrc-68pp-rj6x/GHSA-6qrc-68pp-rj6x.json +++ b/advisories/unreviewed/2022/05/GHSA-6qrc-68pp-rj6x/GHSA-6qrc-68pp-rj6x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6qrc-68pp-rj6x", - "modified": "2022-05-24T17:46:05Z", + "modified": "2024-11-20T15:30:48Z", "published": "2022-05-24T17:46:05Z", "aliases": [ "CVE-2021-27349" ], "details": "Advanced Order Export before 3.1.8 for WooCommerce allows XSS, a different vulnerability than CVE-2020-11727.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-fgvj-4m6x-j67f/GHSA-fgvj-4m6x-j67f.json b/advisories/unreviewed/2022/05/GHSA-fgvj-4m6x-j67f/GHSA-fgvj-4m6x-j67f.json index 17cbda28c37..f0593bb763e 100644 --- a/advisories/unreviewed/2022/05/GHSA-fgvj-4m6x-j67f/GHSA-fgvj-4m6x-j67f.json +++ b/advisories/unreviewed/2022/05/GHSA-fgvj-4m6x-j67f/GHSA-fgvj-4m6x-j67f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fgvj-4m6x-j67f", - "modified": "2022-05-25T00:00:24Z", + "modified": "2024-11-20T15:30:48Z", "published": "2022-05-24T17:17:44Z", "aliases": [ "CVE-2020-8156" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-8156" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KC6HLX5SG4PZO6Y54D2LFJ4ATG76BKOP" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KC6HLX5SG4PZO6Y54D2LFJ4ATG76BKOP" diff --git a/advisories/unreviewed/2022/05/GHSA-p8xr-vj9g-9j25/GHSA-p8xr-vj9g-9j25.json b/advisories/unreviewed/2022/05/GHSA-p8xr-vj9g-9j25/GHSA-p8xr-vj9g-9j25.json index d65de254806..d53e9d6336c 100644 --- a/advisories/unreviewed/2022/05/GHSA-p8xr-vj9g-9j25/GHSA-p8xr-vj9g-9j25.json +++ b/advisories/unreviewed/2022/05/GHSA-p8xr-vj9g-9j25/GHSA-p8xr-vj9g-9j25.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p8xr-vj9g-9j25", - "modified": "2022-05-13T01:18:56Z", + "modified": "2024-11-20T15:30:48Z", "published": "2022-05-13T01:18:56Z", "aliases": [ "CVE-2018-11525" diff --git a/advisories/unreviewed/2022/05/GHSA-w2gv-7447-6h8c/GHSA-w2gv-7447-6h8c.json b/advisories/unreviewed/2022/05/GHSA-w2gv-7447-6h8c/GHSA-w2gv-7447-6h8c.json index 26664144b93..8c4e82bfb09 100644 --- a/advisories/unreviewed/2022/05/GHSA-w2gv-7447-6h8c/GHSA-w2gv-7447-6h8c.json +++ b/advisories/unreviewed/2022/05/GHSA-w2gv-7447-6h8c/GHSA-w2gv-7447-6h8c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w2gv-7447-6h8c", - "modified": "2022-05-24T17:46:31Z", + "modified": "2024-11-20T15:30:48Z", "published": "2022-05-24T17:46:31Z", "aliases": [ "CVE-2021-24169" ], "details": "This Advanced Order Export For WooCommerce WordPress plugin before 3.1.8 helps you to easily export WooCommerce order data. The tab parameter in the Admin Panel is vulnerable to reflected XSS.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/09/GHSA-3h2r-mh7w-gr5w/GHSA-3h2r-mh7w-gr5w.json b/advisories/unreviewed/2022/09/GHSA-3h2r-mh7w-gr5w/GHSA-3h2r-mh7w-gr5w.json index 22787be388d..98b351ebabe 100644 --- a/advisories/unreviewed/2022/09/GHSA-3h2r-mh7w-gr5w/GHSA-3h2r-mh7w-gr5w.json +++ b/advisories/unreviewed/2022/09/GHSA-3h2r-mh7w-gr5w/GHSA-3h2r-mh7w-gr5w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3h2r-mh7w-gr5w", - "modified": "2022-09-11T00:00:29Z", + "modified": "2024-11-20T15:30:48Z", "published": "2022-09-10T00:00:27Z", "aliases": [ "CVE-2022-35275" diff --git a/advisories/unreviewed/2022/11/GHSA-662h-7f84-69rv/GHSA-662h-7f84-69rv.json b/advisories/unreviewed/2022/11/GHSA-662h-7f84-69rv/GHSA-662h-7f84-69rv.json index e2f9690a962..e52b1145b15 100644 --- a/advisories/unreviewed/2022/11/GHSA-662h-7f84-69rv/GHSA-662h-7f84-69rv.json +++ b/advisories/unreviewed/2022/11/GHSA-662h-7f84-69rv/GHSA-662h-7f84-69rv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-662h-7f84-69rv", - "modified": "2022-11-09T19:02:24Z", + "modified": "2024-11-20T15:30:49Z", "published": "2022-11-09T12:00:24Z", "aliases": [ "CVE-2022-40128" diff --git a/advisories/unreviewed/2024/09/GHSA-hm28-rwr4-j8f5/GHSA-hm28-rwr4-j8f5.json b/advisories/unreviewed/2024/09/GHSA-hm28-rwr4-j8f5/GHSA-hm28-rwr4-j8f5.json index 6ed849043a9..5c7c7814609 100644 --- a/advisories/unreviewed/2024/09/GHSA-hm28-rwr4-j8f5/GHSA-hm28-rwr4-j8f5.json +++ b/advisories/unreviewed/2024/09/GHSA-hm28-rwr4-j8f5/GHSA-hm28-rwr4-j8f5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hm28-rwr4-j8f5", - "modified": "2024-09-27T15:30:33Z", + "modified": "2024-11-20T15:30:49Z", "published": "2024-09-27T15:30:33Z", "aliases": [ "CVE-2024-46823" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nkunit/overflow: Fix UB in overflow_allocation_test\n\nThe 'device_name' array doesn't exist out of the\n'overflow_allocation_test' function scope. However, it is being used as\na driver name when calling 'kunit_driver_create' from\n'kunit_device_register'. It produces the kernel panic with KASAN\nenabled.\n\nSince this variable is used in one place only, remove it and pass the\ndevice name into kunit_device_register directly as an ascii string.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-27T13:15:14Z" diff --git a/advisories/unreviewed/2024/11/GHSA-3gr8-4rjx-crp8/GHSA-3gr8-4rjx-crp8.json b/advisories/unreviewed/2024/11/GHSA-3gr8-4rjx-crp8/GHSA-3gr8-4rjx-crp8.json new file mode 100644 index 00000000000..af5492adfdc --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3gr8-4rjx-crp8/GHSA-3gr8-4rjx-crp8.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3gr8-4rjx-crp8", + "modified": "2024-11-20T15:30:52Z", + "published": "2024-11-20T15:30:52Z", + "aliases": [ + "CVE-2024-51208" + ], + "details": "File Upload vulnerability in change-image.php in Anuj Kumar's Boat Booking System version 1.0 allows local attackers to upload a malicious PHP script via the Image Upload Mechanism parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51208" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Esquirez/985db6c65219a3e5a6521e291524aaa0" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com/boat-booking-system-using-php-and-mysql" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-42jm-px5r-4qxq/GHSA-42jm-px5r-4qxq.json b/advisories/unreviewed/2024/11/GHSA-42jm-px5r-4qxq/GHSA-42jm-px5r-4qxq.json index e05de5e61e4..6c6c8a24521 100644 --- a/advisories/unreviewed/2024/11/GHSA-42jm-px5r-4qxq/GHSA-42jm-px5r-4qxq.json +++ b/advisories/unreviewed/2024/11/GHSA-42jm-px5r-4qxq/GHSA-42jm-px5r-4qxq.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-32" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/11/GHSA-47rc-w5x7-93j8/GHSA-47rc-w5x7-93j8.json b/advisories/unreviewed/2024/11/GHSA-47rc-w5x7-93j8/GHSA-47rc-w5x7-93j8.json index d0bba358c35..c434cee94d1 100644 --- a/advisories/unreviewed/2024/11/GHSA-47rc-w5x7-93j8/GHSA-47rc-w5x7-93j8.json +++ b/advisories/unreviewed/2024/11/GHSA-47rc-w5x7-93j8/GHSA-47rc-w5x7-93j8.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-48rr-fh2m-hhjh/GHSA-48rr-fh2m-hhjh.json b/advisories/unreviewed/2024/11/GHSA-48rr-fh2m-hhjh/GHSA-48rr-fh2m-hhjh.json index f3405afafa8..5b0c32fdcc5 100644 --- a/advisories/unreviewed/2024/11/GHSA-48rr-fh2m-hhjh/GHSA-48rr-fh2m-hhjh.json +++ b/advisories/unreviewed/2024/11/GHSA-48rr-fh2m-hhjh/GHSA-48rr-fh2m-hhjh.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-23" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/11/GHSA-4pm3-3999-hj74/GHSA-4pm3-3999-hj74.json b/advisories/unreviewed/2024/11/GHSA-4pm3-3999-hj74/GHSA-4pm3-3999-hj74.json new file mode 100644 index 00000000000..d077129ca12 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4pm3-3999-hj74/GHSA-4pm3-3999-hj74.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4pm3-3999-hj74", + "modified": "2024-11-20T15:30:52Z", + "published": "2024-11-20T15:30:52Z", + "aliases": [ + "CVE-2024-9478" + ], + "details": "Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Escalation.This issue affects upKeeper Instant Privilege Access: before 1.2.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9478" + }, + { + "type": "WEB", + "url": "https://support.upkeeper.se/hc/en-us/articles/17007638130716-CVE-2024-9478-Improper-Privilege-Management-Process" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T14:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-535g-mv5c-jrh8/GHSA-535g-mv5c-jrh8.json b/advisories/unreviewed/2024/11/GHSA-535g-mv5c-jrh8/GHSA-535g-mv5c-jrh8.json new file mode 100644 index 00000000000..096e49a67a1 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-535g-mv5c-jrh8/GHSA-535g-mv5c-jrh8.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-535g-mv5c-jrh8", + "modified": "2024-11-20T15:30:52Z", + "published": "2024-11-20T15:30:52Z", + "aliases": [ + "CVE-2024-11154" + ], + "details": "The PublishPress Revisions: Duplicate Posts, Submit, Approve and Schedule Content Changes plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.15 via the 'actAjaxRevisionDiffs' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive data including revisions of posts and pages.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11154" + }, + { + "type": "WEB", + "url": "https://github.com/publishpress/PublishPress-Revisions/blob/master/admin/history_rvy.php#L322" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/revisionary/trunk/admin/history_rvy.php#L322" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3192492" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c785b7a0-5091-4d89-87d3-cd7d9984553e?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T14:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-5436-rp7w-v3hq/GHSA-5436-rp7w-v3hq.json b/advisories/unreviewed/2024/11/GHSA-5436-rp7w-v3hq/GHSA-5436-rp7w-v3hq.json new file mode 100644 index 00000000000..d024a5c8c55 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-5436-rp7w-v3hq/GHSA-5436-rp7w-v3hq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5436-rp7w-v3hq", + "modified": "2024-11-20T15:30:52Z", + "published": "2024-11-20T15:30:52Z", + "aliases": [ + "CVE-2024-52470" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Brainvireinfo Dynamic URL SEO allows Reflected XSS.This issue affects Dynamic URL SEO: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52470" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/dynamic-url-seo/wordpress-dynamic-url-seo-plugin-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-8ff3-4xrr-3mhr/GHSA-8ff3-4xrr-3mhr.json b/advisories/unreviewed/2024/11/GHSA-8ff3-4xrr-3mhr/GHSA-8ff3-4xrr-3mhr.json new file mode 100644 index 00000000000..8bf3b6c9e13 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-8ff3-4xrr-3mhr/GHSA-8ff3-4xrr-3mhr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8ff3-4xrr-3mhr", + "modified": "2024-11-20T15:30:53Z", + "published": "2024-11-20T15:30:53Z", + "aliases": [ + "CVE-2024-52473" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Sandeep Verma HTML5 Lyrics Karaoke Player allows Reflected XSS.This issue affects HTML5 Lyrics Karaoke Player: from n/a through 2.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52473" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/html5-lyrics-karaoke-player/wordpress-html5-lyrics-karaoke-player-plugin-2-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-94rm-rq6h-h95x/GHSA-94rm-rq6h-h95x.json b/advisories/unreviewed/2024/11/GHSA-94rm-rq6h-h95x/GHSA-94rm-rq6h-h95x.json new file mode 100644 index 00000000000..a54d83e2be3 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-94rm-rq6h-h95x/GHSA-94rm-rq6h-h95x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-94rm-rq6h-h95x", + "modified": "2024-11-20T15:30:52Z", + "published": "2024-11-20T15:30:52Z", + "aliases": [ + "CVE-2024-9479" + ], + "details": "Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Escalation.This issue affects upKeeper Instant Privilege Access: before 1.2.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9479" + }, + { + "type": "WEB", + "url": "https://support.upkeeper.se/hc/en-us/articles/17007729905436-CVE-2024-9479-Improper-Privilege-Management-Subprocess" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T14:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9rq6-3xh4-jjch/GHSA-9rq6-3xh4-jjch.json b/advisories/unreviewed/2024/11/GHSA-9rq6-3xh4-jjch/GHSA-9rq6-3xh4-jjch.json index dc7dbc5b99b..5537f31ca61 100644 --- a/advisories/unreviewed/2024/11/GHSA-9rq6-3xh4-jjch/GHSA-9rq6-3xh4-jjch.json +++ b/advisories/unreviewed/2024/11/GHSA-9rq6-3xh4-jjch/GHSA-9rq6-3xh4-jjch.json @@ -48,7 +48,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-cgr4-9xhv-p6x6/GHSA-cgr4-9xhv-p6x6.json b/advisories/unreviewed/2024/11/GHSA-cgr4-9xhv-p6x6/GHSA-cgr4-9xhv-p6x6.json index 48a3def58b4..781fc1bd5fe 100644 --- a/advisories/unreviewed/2024/11/GHSA-cgr4-9xhv-p6x6/GHSA-cgr4-9xhv-p6x6.json +++ b/advisories/unreviewed/2024/11/GHSA-cgr4-9xhv-p6x6/GHSA-cgr4-9xhv-p6x6.json @@ -48,7 +48,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-crmh-vcgf-prwv/GHSA-crmh-vcgf-prwv.json b/advisories/unreviewed/2024/11/GHSA-crmh-vcgf-prwv/GHSA-crmh-vcgf-prwv.json index fdc4ef907c6..4911d7ceac7 100644 --- a/advisories/unreviewed/2024/11/GHSA-crmh-vcgf-prwv/GHSA-crmh-vcgf-prwv.json +++ b/advisories/unreviewed/2024/11/GHSA-crmh-vcgf-prwv/GHSA-crmh-vcgf-prwv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-crmh-vcgf-prwv", - "modified": "2024-11-18T18:30:58Z", + "modified": "2024-11-20T15:30:51Z", "published": "2024-11-18T18:30:58Z", "aliases": [ "CVE-2024-52425" diff --git a/advisories/unreviewed/2024/11/GHSA-cwrq-8w42-mhc5/GHSA-cwrq-8w42-mhc5.json b/advisories/unreviewed/2024/11/GHSA-cwrq-8w42-mhc5/GHSA-cwrq-8w42-mhc5.json new file mode 100644 index 00000000000..13163aa8b1d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-cwrq-8w42-mhc5/GHSA-cwrq-8w42-mhc5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cwrq-8w42-mhc5", + "modified": "2024-11-20T15:30:53Z", + "published": "2024-11-20T15:30:53Z", + "aliases": [ + "CVE-2024-52472" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Weather Atlas Weather Atlas Widget allows Reflected XSS.This issue affects Weather Atlas Widget: from n/a through 3.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52472" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/weather-atlas/wordpress-weather-atlas-widget-plugin-3-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-f75h-cwp9-8h5x/GHSA-f75h-cwp9-8h5x.json b/advisories/unreviewed/2024/11/GHSA-f75h-cwp9-8h5x/GHSA-f75h-cwp9-8h5x.json index e262af7f688..62b7b23a0c1 100644 --- a/advisories/unreviewed/2024/11/GHSA-f75h-cwp9-8h5x/GHSA-f75h-cwp9-8h5x.json +++ b/advisories/unreviewed/2024/11/GHSA-f75h-cwp9-8h5x/GHSA-f75h-cwp9-8h5x.json @@ -48,7 +48,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-288" + "CWE-288", + "CWE-306" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-gwhh-pw54-jgx4/GHSA-gwhh-pw54-jgx4.json b/advisories/unreviewed/2024/11/GHSA-gwhh-pw54-jgx4/GHSA-gwhh-pw54-jgx4.json index d166b209681..d195cccaf2d 100644 --- a/advisories/unreviewed/2024/11/GHSA-gwhh-pw54-jgx4/GHSA-gwhh-pw54-jgx4.json +++ b/advisories/unreviewed/2024/11/GHSA-gwhh-pw54-jgx4/GHSA-gwhh-pw54-jgx4.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-23" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2024/11/GHSA-gwm3-gp4w-96g7/GHSA-gwm3-gp4w-96g7.json b/advisories/unreviewed/2024/11/GHSA-gwm3-gp4w-96g7/GHSA-gwm3-gp4w-96g7.json index 91cecaa9df6..c84e2571ab2 100644 --- a/advisories/unreviewed/2024/11/GHSA-gwm3-gp4w-96g7/GHSA-gwm3-gp4w-96g7.json +++ b/advisories/unreviewed/2024/11/GHSA-gwm3-gp4w-96g7/GHSA-gwm3-gp4w-96g7.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-23" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2024/11/GHSA-gx4q-m69p-mf52/GHSA-gx4q-m69p-mf52.json b/advisories/unreviewed/2024/11/GHSA-gx4q-m69p-mf52/GHSA-gx4q-m69p-mf52.json index 51a28493651..b3f738b5d91 100644 --- a/advisories/unreviewed/2024/11/GHSA-gx4q-m69p-mf52/GHSA-gx4q-m69p-mf52.json +++ b/advisories/unreviewed/2024/11/GHSA-gx4q-m69p-mf52/GHSA-gx4q-m69p-mf52.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-23" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2024/11/GHSA-h53w-2cq3-cj2p/GHSA-h53w-2cq3-cj2p.json b/advisories/unreviewed/2024/11/GHSA-h53w-2cq3-cj2p/GHSA-h53w-2cq3-cj2p.json index 9636f06ca28..d65d17c1fcd 100644 --- a/advisories/unreviewed/2024/11/GHSA-h53w-2cq3-cj2p/GHSA-h53w-2cq3-cj2p.json +++ b/advisories/unreviewed/2024/11/GHSA-h53w-2cq3-cj2p/GHSA-h53w-2cq3-cj2p.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-1336" + "CWE-1336", + "CWE-94" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-hjr8-c78p-hrvc/GHSA-hjr8-c78p-hrvc.json b/advisories/unreviewed/2024/11/GHSA-hjr8-c78p-hrvc/GHSA-hjr8-c78p-hrvc.json index ac2654373da..c784c04fe43 100644 --- a/advisories/unreviewed/2024/11/GHSA-hjr8-c78p-hrvc/GHSA-hjr8-c78p-hrvc.json +++ b/advisories/unreviewed/2024/11/GHSA-hjr8-c78p-hrvc/GHSA-hjr8-c78p-hrvc.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-23" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/11/GHSA-hwv8-q8m9-3f2j/GHSA-hwv8-q8m9-3f2j.json b/advisories/unreviewed/2024/11/GHSA-hwv8-q8m9-3f2j/GHSA-hwv8-q8m9-3f2j.json new file mode 100644 index 00000000000..c99fcf8cdad --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-hwv8-q8m9-3f2j/GHSA-hwv8-q8m9-3f2j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hwv8-q8m9-3f2j", + "modified": "2024-11-20T15:30:52Z", + "published": "2024-11-20T15:30:52Z", + "aliases": [ + "CVE-2024-10094" + ], + "details": "Pega Platform versions 6.x to Infinity 24.1.1 are affected by an issue with Improper Control of Generation of Code", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10094" + }, + { + "type": "WEB", + "url": "https://support.pega.com/support-doc/pega-security-advisory-d24-vulnerability-remediation-note" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-j4v3-wwwx-5gqv/GHSA-j4v3-wwwx-5gqv.json b/advisories/unreviewed/2024/11/GHSA-j4v3-wwwx-5gqv/GHSA-j4v3-wwwx-5gqv.json index 2650cf7021f..7707a8de38d 100644 --- a/advisories/unreviewed/2024/11/GHSA-j4v3-wwwx-5gqv/GHSA-j4v3-wwwx-5gqv.json +++ b/advisories/unreviewed/2024/11/GHSA-j4v3-wwwx-5gqv/GHSA-j4v3-wwwx-5gqv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j4v3-wwwx-5gqv", - "modified": "2024-11-20T12:30:35Z", + "modified": "2024-11-20T15:30:52Z", "published": "2024-11-20T12:30:35Z", "aliases": [ "CVE-2024-11404" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11404" }, + { + "type": "WEB", + "url": "https://iltosec.com/blog/post/cve-2024-11404-medium-severity-file-upload-vulnerabilities-in-django-filer-323" + }, { "type": "WEB", "url": "https://iltosec.com/blog/post/djangocms-attributes-field-300-stored-xss-vulnerability" diff --git a/advisories/unreviewed/2024/11/GHSA-mqxv-7638-9mpv/GHSA-mqxv-7638-9mpv.json b/advisories/unreviewed/2024/11/GHSA-mqxv-7638-9mpv/GHSA-mqxv-7638-9mpv.json new file mode 100644 index 00000000000..51e67045337 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mqxv-7638-9mpv/GHSA-mqxv-7638-9mpv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mqxv-7638-9mpv", + "modified": "2024-11-20T15:30:53Z", + "published": "2024-11-20T15:30:53Z", + "aliases": [ + "CVE-2024-52471" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in petesheppard84 Extensions for Elementor allows Reflected XSS.This issue affects Extensions for Elementor: from n/a through 2.0.37.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52471" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/extensions-for-elementor/wordpress-extensions-for-elementor-plugin-2-0-37-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-p284-cx3v-33vg/GHSA-p284-cx3v-33vg.json b/advisories/unreviewed/2024/11/GHSA-p284-cx3v-33vg/GHSA-p284-cx3v-33vg.json new file mode 100644 index 00000000000..8955dfa12e7 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-p284-cx3v-33vg/GHSA-p284-cx3v-33vg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p284-cx3v-33vg", + "modified": "2024-11-20T15:30:52Z", + "published": "2024-11-20T15:30:52Z", + "aliases": [ + "CVE-2024-11495" + ], + "details": "Buffer overflow vulnerability in OllyDbg, version 1.10, which could allow a local attacker to execute arbitrary code due to lack of proper bounds checking.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11495" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/buffer-overflow-ollydbg" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T13:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-pr37-gvg2-qr9v/GHSA-pr37-gvg2-qr9v.json b/advisories/unreviewed/2024/11/GHSA-pr37-gvg2-qr9v/GHSA-pr37-gvg2-qr9v.json index 0f46cacefea..d8784020140 100644 --- a/advisories/unreviewed/2024/11/GHSA-pr37-gvg2-qr9v/GHSA-pr37-gvg2-qr9v.json +++ b/advisories/unreviewed/2024/11/GHSA-pr37-gvg2-qr9v/GHSA-pr37-gvg2-qr9v.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-23" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2024/11/GHSA-qj3w-6895-r5mf/GHSA-qj3w-6895-r5mf.json b/advisories/unreviewed/2024/11/GHSA-qj3w-6895-r5mf/GHSA-qj3w-6895-r5mf.json index 0f10cf49ec0..1feddc5fa2d 100644 --- a/advisories/unreviewed/2024/11/GHSA-qj3w-6895-r5mf/GHSA-qj3w-6895-r5mf.json +++ b/advisories/unreviewed/2024/11/GHSA-qj3w-6895-r5mf/GHSA-qj3w-6895-r5mf.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-23" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2024/11/GHSA-qwhj-q28h-8hg6/GHSA-qwhj-q28h-8hg6.json b/advisories/unreviewed/2024/11/GHSA-qwhj-q28h-8hg6/GHSA-qwhj-q28h-8hg6.json new file mode 100644 index 00000000000..f304d60de1b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qwhj-q28h-8hg6/GHSA-qwhj-q28h-8hg6.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qwhj-q28h-8hg6", + "modified": "2024-11-20T15:30:52Z", + "published": "2024-11-20T15:30:52Z", + "aliases": [ + "CVE-2024-51209" + ], + "details": "Cross-Site Scripting (XSS) vulnerabilities in Anuj Kumar's Client Management System Version 1.2 allow local attackers to inject arbitrary web script or HTML via the search input field parameter to admin search invoice page and client search invoice page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51209" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Esquirez/0c41e0279ca11d9bfc52c3938041d935" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com/client-management-system-using-php-mysql" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-wpfc-gx92-f98v/GHSA-wpfc-gx92-f98v.json b/advisories/unreviewed/2024/11/GHSA-wpfc-gx92-f98v/GHSA-wpfc-gx92-f98v.json index 6b15a4f0567..a447543721f 100644 --- a/advisories/unreviewed/2024/11/GHSA-wpfc-gx92-f98v/GHSA-wpfc-gx92-f98v.json +++ b/advisories/unreviewed/2024/11/GHSA-wpfc-gx92-f98v/GHSA-wpfc-gx92-f98v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wpfc-gx92-f98v", - "modified": "2024-11-07T12:30:35Z", + "modified": "2024-11-20T15:30:49Z", "published": "2024-11-07T12:30:35Z", "aliases": [ "CVE-2024-50156" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm: Avoid NULL dereference in msm_disp_state_print_regs()\n\nIf the allocation in msm_disp_state_dump_regs() failed then\n`block->state` can be NULL. The msm_disp_state_print_regs() function\n_does_ have code to try to handle it with:\n\n if (*reg)\n dump_addr = *reg;\n\n...but since \"dump_addr\" is initialized to NULL the above is actually\na noop. The code then goes on to dereference `dump_addr`.\n\nMake the function print \"Registers not stored\" when it sees a NULL to\nsolve this. Since we're touching the code, fix\nmsm_disp_state_print_regs() not to pointlessly take a double-pointer\nand properly mark the pointer as `const`.\n\nPatchwork: https://patchwork.freedesktop.org/patch/619657/", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-07T10:15:07Z" diff --git a/advisories/unreviewed/2024/11/GHSA-wrr5-xwcp-mrf2/GHSA-wrr5-xwcp-mrf2.json b/advisories/unreviewed/2024/11/GHSA-wrr5-xwcp-mrf2/GHSA-wrr5-xwcp-mrf2.json index 0bbb0c2610c..596ae36d49b 100644 --- a/advisories/unreviewed/2024/11/GHSA-wrr5-xwcp-mrf2/GHSA-wrr5-xwcp-mrf2.json +++ b/advisories/unreviewed/2024/11/GHSA-wrr5-xwcp-mrf2/GHSA-wrr5-xwcp-mrf2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wrr5-xwcp-mrf2", - "modified": "2024-11-15T18:30:51Z", + "modified": "2024-11-20T15:30:50Z", "published": "2024-11-15T18:30:51Z", "aliases": [ "CVE-2024-50654" ], "details": "lilishop <=4.2.4 is vulnerable to Incorrect Access Control, which can allow attackers to obtain coupons beyond the quantity limit by capturing and sending the data packets for coupon collection in high concurrency.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-15T17:15:20Z" diff --git a/advisories/unreviewed/2024/11/GHSA-xc59-47r9-5932/GHSA-xc59-47r9-5932.json b/advisories/unreviewed/2024/11/GHSA-xc59-47r9-5932/GHSA-xc59-47r9-5932.json new file mode 100644 index 00000000000..aeaa229ac23 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-xc59-47r9-5932/GHSA-xc59-47r9-5932.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xc59-47r9-5932", + "modified": "2024-11-20T15:30:52Z", + "published": "2024-11-20T15:30:52Z", + "aliases": [ + "CVE-2024-10913" + ], + "details": "The Clone plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.4.6 via deserialization of untrusted input in the 'recursive_unserialized_replace' function. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10913" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-clone-by-wp-academy//tags/2.4.6/lib/icit_srdb_replacer.php#L24" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-clone-by-wp-academy/tags/2.4.7/lib/icit_srdb_replacer.php#L24" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/16569267-ab52-4b96-86f0-d37c470a3938?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T14:15:17Z" + } +} \ No newline at end of file