diff --git a/advisories/unreviewed/2024/03/GHSA-8497-6qx5-88vv/GHSA-8497-6qx5-88vv.json b/advisories/unreviewed/2024/03/GHSA-8497-6qx5-88vv/GHSA-8497-6qx5-88vv.json index 6ea6289046f..7c3fd900f35 100644 --- a/advisories/unreviewed/2024/03/GHSA-8497-6qx5-88vv/GHSA-8497-6qx5-88vv.json +++ b/advisories/unreviewed/2024/03/GHSA-8497-6qx5-88vv/GHSA-8497-6qx5-88vv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8497-6qx5-88vv", - "modified": "2024-03-07T21:30:22Z", + "modified": "2024-11-19T00:32:42Z", "published": "2024-03-07T21:30:22Z", "aliases": [ "CVE-2024-26492" ], "details": "An issue in Online Diagnostic Lab Management System 1.0 allows a remote attacker to gain control of a 'Staff' user account via a crafted POST request using the id, email, password, and cpass parameters.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-07T21:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-r944-7xp4-cg8q/GHSA-r944-7xp4-cg8q.json b/advisories/unreviewed/2024/03/GHSA-r944-7xp4-cg8q/GHSA-r944-7xp4-cg8q.json index 10478f5168a..69a755f143d 100644 --- a/advisories/unreviewed/2024/03/GHSA-r944-7xp4-cg8q/GHSA-r944-7xp4-cg8q.json +++ b/advisories/unreviewed/2024/03/GHSA-r944-7xp4-cg8q/GHSA-r944-7xp4-cg8q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r944-7xp4-cg8q", - "modified": "2024-03-14T00:31:05Z", + "modified": "2024-11-19T00:32:42Z", "published": "2024-03-08T03:31:24Z", "aliases": [ "CVE-2024-23241" ], "details": "This issue was addressed through improved state management. This issue is fixed in tvOS 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. An app may be able to leak sensitive user information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-922" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-08T02:15:48Z" diff --git a/advisories/unreviewed/2024/03/GHSA-xqpf-pfm9-3p52/GHSA-xqpf-pfm9-3p52.json b/advisories/unreviewed/2024/03/GHSA-xqpf-pfm9-3p52/GHSA-xqpf-pfm9-3p52.json index e2c9f8f92b8..f4667aa4d67 100644 --- a/advisories/unreviewed/2024/03/GHSA-xqpf-pfm9-3p52/GHSA-xqpf-pfm9-3p52.json +++ b/advisories/unreviewed/2024/03/GHSA-xqpf-pfm9-3p52/GHSA-xqpf-pfm9-3p52.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xqpf-pfm9-3p52", - "modified": "2024-03-14T00:31:04Z", + "modified": "2024-11-19T00:32:42Z", "published": "2024-03-08T03:31:24Z", "aliases": [ "CVE-2024-23220" ], "details": "The issue was addressed with improved handling of caches. This issue is fixed in visionOS 1.1, iOS 17.4 and iPadOS 17.4. An app may be able to fingerprint the user.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-08T02:15:47Z" diff --git a/advisories/unreviewed/2024/04/GHSA-39fv-p94v-rg6c/GHSA-39fv-p94v-rg6c.json b/advisories/unreviewed/2024/04/GHSA-39fv-p94v-rg6c/GHSA-39fv-p94v-rg6c.json index 48e31173936..c221dca8a42 100644 --- a/advisories/unreviewed/2024/04/GHSA-39fv-p94v-rg6c/GHSA-39fv-p94v-rg6c.json +++ b/advisories/unreviewed/2024/04/GHSA-39fv-p94v-rg6c/GHSA-39fv-p94v-rg6c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-39fv-p94v-rg6c", - "modified": "2024-04-03T03:30:30Z", + "modified": "2024-11-19T00:32:42Z", "published": "2024-04-03T03:30:30Z", "aliases": [ "CVE-2024-28836" ], "details": "An issue was discovered in Mbed TLS 3.5.x before 3.6.0. When negotiating the TLS version on the server side, it can fall back to the TLS 1.2 implementation of the protocol if it is disabled. If the TLS 1.2 implementation was disabled at build time, a TLS 1.2 client could put a TLS 1.3-only server into an infinite loop processing a TLS 1.2 ClientHello, resulting in a denial of service. If the TLS 1.2 implementation was disabled at runtime, a TLS 1.2 client can successfully establish a TLS 1.2 connection with the server.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T03:15:10Z" diff --git a/advisories/unreviewed/2024/04/GHSA-5q9m-f76w-7rm3/GHSA-5q9m-f76w-7rm3.json b/advisories/unreviewed/2024/04/GHSA-5q9m-f76w-7rm3/GHSA-5q9m-f76w-7rm3.json index ea2b7a73a8b..dc851b26918 100644 --- a/advisories/unreviewed/2024/04/GHSA-5q9m-f76w-7rm3/GHSA-5q9m-f76w-7rm3.json +++ b/advisories/unreviewed/2024/04/GHSA-5q9m-f76w-7rm3/GHSA-5q9m-f76w-7rm3.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-6hf2-chq7-2mhh/GHSA-6hf2-chq7-2mhh.json b/advisories/unreviewed/2024/06/GHSA-6hf2-chq7-2mhh/GHSA-6hf2-chq7-2mhh.json index 6a36c27e55e..9ede0626e91 100644 --- a/advisories/unreviewed/2024/06/GHSA-6hf2-chq7-2mhh/GHSA-6hf2-chq7-2mhh.json +++ b/advisories/unreviewed/2024/06/GHSA-6hf2-chq7-2mhh/GHSA-6hf2-chq7-2mhh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6hf2-chq7-2mhh", - "modified": "2024-06-27T21:32:08Z", + "modified": "2024-11-19T00:32:42Z", "published": "2024-06-27T21:32:08Z", "aliases": [ "CVE-2024-31802" ], "details": "DESIGNA ABACUS v.18 and before allows an attacker to bypass the payment process via a crafted QR code.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-290" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-27T20:15:21Z" diff --git a/advisories/unreviewed/2024/06/GHSA-h3p7-vxpm-g349/GHSA-h3p7-vxpm-g349.json b/advisories/unreviewed/2024/06/GHSA-h3p7-vxpm-g349/GHSA-h3p7-vxpm-g349.json index 44b6a6e5e7a..90199e68308 100644 --- a/advisories/unreviewed/2024/06/GHSA-h3p7-vxpm-g349/GHSA-h3p7-vxpm-g349.json +++ b/advisories/unreviewed/2024/06/GHSA-h3p7-vxpm-g349/GHSA-h3p7-vxpm-g349.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h3p7-vxpm-g349", - "modified": "2024-06-17T18:31:33Z", + "modified": "2024-11-19T00:32:42Z", "published": "2024-06-14T18:31:43Z", "aliases": [ "CVE-2024-33373" ], "details": "An issue in the LB-LINK BL-W1210M v2.0 router allows attackers to bypass password complexity requirements and set single digit passwords for authentication. This vulnerability can allow attackers to access the router via a brute-force attack.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-639" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-14T16:15:11Z" diff --git a/advisories/unreviewed/2024/11/GHSA-2gfc-3f49-cfq7/GHSA-2gfc-3f49-cfq7.json b/advisories/unreviewed/2024/11/GHSA-2gfc-3f49-cfq7/GHSA-2gfc-3f49-cfq7.json new file mode 100644 index 00000000000..ce0e655f66b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-2gfc-3f49-cfq7/GHSA-2gfc-3f49-cfq7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2gfc-3f49-cfq7", + "modified": "2024-11-19T00:32:45Z", + "published": "2024-11-19T00:32:44Z", + "aliases": [ + "CVE-2024-51940" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in sohelwpexpert WP Responsive Video allows DOM-Based XSS.This issue affects WP Responsive Video: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51940" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/my-wp-responsive-video/wordpress-wp-responsive-video-plugin-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T23:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-36g3-5c2m-mrqx/GHSA-36g3-5c2m-mrqx.json b/advisories/unreviewed/2024/11/GHSA-36g3-5c2m-mrqx/GHSA-36g3-5c2m-mrqx.json index e76d368866b..ba8cd0514a8 100644 --- a/advisories/unreviewed/2024/11/GHSA-36g3-5c2m-mrqx/GHSA-36g3-5c2m-mrqx.json +++ b/advisories/unreviewed/2024/11/GHSA-36g3-5c2m-mrqx/GHSA-36g3-5c2m-mrqx.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-922" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-3qc6-x7mq-579v/GHSA-3qc6-x7mq-579v.json b/advisories/unreviewed/2024/11/GHSA-3qc6-x7mq-579v/GHSA-3qc6-x7mq-579v.json new file mode 100644 index 00000000000..7ebd31c2a93 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3qc6-x7mq-579v/GHSA-3qc6-x7mq-579v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3qc6-x7mq-579v", + "modified": "2024-11-19T00:32:44Z", + "published": "2024-11-19T00:32:44Z", + "aliases": [ + "CVE-2024-52345" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Roberto Alicata ra_qrcode allows Stored XSS.This issue affects ra_qrcode: from n/a through 2.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52345" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ra-qrcode/wordpress-ra-qrcode-plugin-2-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T22:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4ccx-55gp-x5qq/GHSA-4ccx-55gp-x5qq.json b/advisories/unreviewed/2024/11/GHSA-4ccx-55gp-x5qq/GHSA-4ccx-55gp-x5qq.json new file mode 100644 index 00000000000..5c3c42a73e8 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4ccx-55gp-x5qq/GHSA-4ccx-55gp-x5qq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4ccx-55gp-x5qq", + "modified": "2024-11-19T00:32:44Z", + "published": "2024-11-19T00:32:44Z", + "aliases": [ + "CVE-2024-52390" + ], + "details": ": Path Traversal: '.../...//' vulnerability in CYAN Backup allows Path Traversal.This issue affects CYAN Backup: from n/a through 2.5.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52390" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/cyan-backup/wordpress-cyan-backup-plugin-2-5-3-arbitrary-file-download-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-35" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T22:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-5w7w-q2j5-4mr9/GHSA-5w7w-q2j5-4mr9.json b/advisories/unreviewed/2024/11/GHSA-5w7w-q2j5-4mr9/GHSA-5w7w-q2j5-4mr9.json new file mode 100644 index 00000000000..be2ff8ad0f7 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-5w7w-q2j5-4mr9/GHSA-5w7w-q2j5-4mr9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5w7w-q2j5-4mr9", + "modified": "2024-11-19T00:32:44Z", + "published": "2024-11-19T00:32:44Z", + "aliases": [ + "CVE-2024-52348" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in aaextention AA Audio Player allows DOM-Based XSS.This issue affects AA Audio Player: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52348" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/aa-audio-player/wordpress-aa-audio-player-plugin-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T22:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-5wm3-qv64-f636/GHSA-5wm3-qv64-f636.json b/advisories/unreviewed/2024/11/GHSA-5wm3-qv64-f636/GHSA-5wm3-qv64-f636.json new file mode 100644 index 00000000000..bd7e3857a3b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-5wm3-qv64-f636/GHSA-5wm3-qv64-f636.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5wm3-qv64-f636", + "modified": "2024-11-19T00:32:45Z", + "published": "2024-11-19T00:32:45Z", + "aliases": [ + "CVE-2024-51939" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Santhosh veer Stylish Internal Links allows DOM-Based XSS.This issue affects Stylish Internal Links: from n/a through 1.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51939" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/stylish-internal-links/wordpress-stylish-internal-links-plugin-1-9-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T23:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-7r98-27gr-j5p7/GHSA-7r98-27gr-j5p7.json b/advisories/unreviewed/2024/11/GHSA-7r98-27gr-j5p7/GHSA-7r98-27gr-j5p7.json new file mode 100644 index 00000000000..6caa098bbaa --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-7r98-27gr-j5p7/GHSA-7r98-27gr-j5p7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7r98-27gr-j5p7", + "modified": "2024-11-19T00:32:44Z", + "published": "2024-11-19T00:32:44Z", + "aliases": [ + "CVE-2024-52341" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Offshorent Solutions Pvt Ltd. | Jinesh.P.V OS Our Team allows Stored XSS.This issue affects OS Our Team: from n/a through 1.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52341" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/os-our-team/wordpress-os-our-team-plugin-1-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T22:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-8wx5-2cq5-85hv/GHSA-8wx5-2cq5-85hv.json b/advisories/unreviewed/2024/11/GHSA-8wx5-2cq5-85hv/GHSA-8wx5-2cq5-85hv.json new file mode 100644 index 00000000000..c28a7670e7a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-8wx5-2cq5-85hv/GHSA-8wx5-2cq5-85hv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8wx5-2cq5-85hv", + "modified": "2024-11-19T00:32:44Z", + "published": "2024-11-19T00:32:44Z", + "aliases": [ + "CVE-2024-52417" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BoldThemes ReConstruction allows Reflected XSS.This issue affects ReConstruction: from n/a through 1.4.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52417" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/reconstruction/wordpress-reconstruction-theme-1-4-7-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T22:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9hgq-6x66-3wfh/GHSA-9hgq-6x66-3wfh.json b/advisories/unreviewed/2024/11/GHSA-9hgq-6x66-3wfh/GHSA-9hgq-6x66-3wfh.json new file mode 100644 index 00000000000..93ec6303902 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9hgq-6x66-3wfh/GHSA-9hgq-6x66-3wfh.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9hgq-6x66-3wfh", + "modified": "2024-11-19T00:32:43Z", + "published": "2024-11-19T00:32:43Z", + "aliases": [ + "CVE-2024-10486" + ], + "details": "The Google for WooCommerce plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 2.8.6. This is due to publicly accessible print_php_information.php file. This makes it possible for unauthenticated attackers to retrieve information about Webserver and PHP configuration, which can be used to aid other attacks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10486" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/google-listings-and-ads/tags/2.8.6/vendor/googleads/google-ads-php/scripts/print_php_information.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/64bc7d47-6b63-4fd9-85d4-82126f86308a?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T22:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-cgjv-g7x3-8jrm/GHSA-cgjv-g7x3-8jrm.json b/advisories/unreviewed/2024/11/GHSA-cgjv-g7x3-8jrm/GHSA-cgjv-g7x3-8jrm.json index 2a45ad50df8..7c44450b7d5 100644 --- a/advisories/unreviewed/2024/11/GHSA-cgjv-g7x3-8jrm/GHSA-cgjv-g7x3-8jrm.json +++ b/advisories/unreviewed/2024/11/GHSA-cgjv-g7x3-8jrm/GHSA-cgjv-g7x3-8jrm.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-922" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-fjgq-f28v-c8cx/GHSA-fjgq-f28v-c8cx.json b/advisories/unreviewed/2024/11/GHSA-fjgq-f28v-c8cx/GHSA-fjgq-f28v-c8cx.json new file mode 100644 index 00000000000..59375a4ff9e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-fjgq-f28v-c8cx/GHSA-fjgq-f28v-c8cx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fjgq-f28v-c8cx", + "modified": "2024-11-19T00:32:44Z", + "published": "2024-11-19T00:32:44Z", + "aliases": [ + "CVE-2024-52343" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Offshorent Softwares Pvt. Ltd. | Jinesh.P.V OS Pricing Tables allows Stored XSS.This issue affects OS Pricing Tables: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52343" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/os-pricing-tables/wordpress-os-pricing-tables-plugin-1-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T22:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-fm94-mv68-v6p6/GHSA-fm94-mv68-v6p6.json b/advisories/unreviewed/2024/11/GHSA-fm94-mv68-v6p6/GHSA-fm94-mv68-v6p6.json new file mode 100644 index 00000000000..35f3c618e7f --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-fm94-mv68-v6p6/GHSA-fm94-mv68-v6p6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fm94-mv68-v6p6", + "modified": "2024-11-19T00:32:44Z", + "published": "2024-11-19T00:32:44Z", + "aliases": [ + "CVE-2024-52394" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in nopea.Media Print PDF Generator and Publisher allows Stored XSS.This issue affects Print PDF Generator and Publisher: from n/a through 1.1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52394" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/nopeamedia/wordpress-print-pdf-generator-and-publisher-plugin-1-1-6-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T22:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-g3wh-hjx2-p9qg/GHSA-g3wh-hjx2-p9qg.json b/advisories/unreviewed/2024/11/GHSA-g3wh-hjx2-p9qg/GHSA-g3wh-hjx2-p9qg.json new file mode 100644 index 00000000000..c817381b495 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-g3wh-hjx2-p9qg/GHSA-g3wh-hjx2-p9qg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g3wh-hjx2-p9qg", + "modified": "2024-11-19T00:32:44Z", + "published": "2024-11-19T00:32:44Z", + "aliases": [ + "CVE-2024-52342" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Offshorent Solutions Pvt Ltd. | Jinesh.P.V OS BXSlider allows Stored XSS.This issue affects OS BXSlider: from n/a through 2.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52342" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/os-bxslider/wordpress-os-bxslider-plugin-2-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T22:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-hqp7-5m3w-m539/GHSA-hqp7-5m3w-m539.json b/advisories/unreviewed/2024/11/GHSA-hqp7-5m3w-m539/GHSA-hqp7-5m3w-m539.json new file mode 100644 index 00000000000..9e3fde231bc --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-hqp7-5m3w-m539/GHSA-hqp7-5m3w-m539.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hqp7-5m3w-m539", + "modified": "2024-11-19T00:32:45Z", + "published": "2024-11-19T00:32:45Z", + "aliases": [ + "CVE-2024-52340" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Marty Thornley Photographer Connections allows Stored XSS.This issue affects Photographer Connections: from n/a through 1.3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52340" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/photographer-connections/wordpress-photographer-connections-plugin-1-3-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T23:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-j694-p476-7fp3/GHSA-j694-p476-7fp3.json b/advisories/unreviewed/2024/11/GHSA-j694-p476-7fp3/GHSA-j694-p476-7fp3.json new file mode 100644 index 00000000000..041458741c7 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-j694-p476-7fp3/GHSA-j694-p476-7fp3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j694-p476-7fp3", + "modified": "2024-11-19T00:32:45Z", + "published": "2024-11-19T00:32:45Z", + "aliases": [ + "CVE-2024-52339" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Mage Cast Mage Front End Forms allows Stored XSS.This issue affects Mage Front End Forms: from n/a through 1.1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52339" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/mage-forms/wordpress-mage-front-end-forms-plugin-1-1-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T23:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-j6g5-g9xr-gmxw/GHSA-j6g5-g9xr-gmxw.json b/advisories/unreviewed/2024/11/GHSA-j6g5-g9xr-gmxw/GHSA-j6g5-g9xr-gmxw.json new file mode 100644 index 00000000000..818c6e4fc7b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-j6g5-g9xr-gmxw/GHSA-j6g5-g9xr-gmxw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6g5-g9xr-gmxw", + "modified": "2024-11-19T00:32:44Z", + "published": "2024-11-19T00:32:44Z", + "aliases": [ + "CVE-2024-52346" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Javier Méndez Veira SimpleGMaps allows Stored XSS.This issue affects SimpleGMaps: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52346" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/simplegmaps/wordpress-simplegmaps-plugin-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T22:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-j6jp-rq85-43h7/GHSA-j6jp-rq85-43h7.json b/advisories/unreviewed/2024/11/GHSA-j6jp-rq85-43h7/GHSA-j6jp-rq85-43h7.json new file mode 100644 index 00000000000..436da9bc82b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-j6jp-rq85-43h7/GHSA-j6jp-rq85-43h7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6jp-rq85-43h7", + "modified": "2024-11-19T00:32:44Z", + "published": "2024-11-19T00:32:44Z", + "aliases": [ + "CVE-2024-52418" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CactusThemes Gameplan allows Reflected XSS.This issue affects Gameplan: from n/a through 1.5.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52418" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/gameplan/wordpress-gameplan-theme-1-5-10-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T22:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-pgp6-3p5j-wc9h/GHSA-pgp6-3p5j-wc9h.json b/advisories/unreviewed/2024/11/GHSA-pgp6-3p5j-wc9h/GHSA-pgp6-3p5j-wc9h.json new file mode 100644 index 00000000000..99df5fa4ebb --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-pgp6-3p5j-wc9h/GHSA-pgp6-3p5j-wc9h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pgp6-3p5j-wc9h", + "modified": "2024-11-19T00:32:44Z", + "published": "2024-11-19T00:32:44Z", + "aliases": [ + "CVE-2024-52344" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Muhammad Junaid Provide Forex Signals allows Stored XSS.This issue affects Provide Forex Signals: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52344" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/provide-forex-signals/wordpress-provide-forex-signals-plugin-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T22:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-r5q8-2vww-96fq/GHSA-r5q8-2vww-96fq.json b/advisories/unreviewed/2024/11/GHSA-r5q8-2vww-96fq/GHSA-r5q8-2vww-96fq.json new file mode 100644 index 00000000000..369dac9954c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-r5q8-2vww-96fq/GHSA-r5q8-2vww-96fq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r5q8-2vww-96fq", + "modified": "2024-11-19T00:32:44Z", + "published": "2024-11-19T00:32:44Z", + "aliases": [ + "CVE-2024-52389" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Job Portal allows Stored XSS.This issue affects WP Job Portal: from n/a through 2.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52389" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-job-portal/wordpress-wp-job-portal-plugin-2-2-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T22:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rfph-p7rj-xmr6/GHSA-rfph-p7rj-xmr6.json b/advisories/unreviewed/2024/11/GHSA-rfph-p7rj-xmr6/GHSA-rfph-p7rj-xmr6.json new file mode 100644 index 00000000000..44fb28cf405 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-rfph-p7rj-xmr6/GHSA-rfph-p7rj-xmr6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rfph-p7rj-xmr6", + "modified": "2024-11-19T00:32:44Z", + "published": "2024-11-19T00:32:44Z", + "aliases": [ + "CVE-2024-52347" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP website creator Website remote Install vor Gravity, WPForms, Formidable, Ninja, Caldera allows Stored XSS.This issue affects Website remote Install vor Gravity, WPForms, Formidable, Ninja, Caldera: from n/a through 4.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52347" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-website-creator/wordpress-website-remote-install-vor-gravity-wpforms-formidable-ninja-caldera-plugin-4-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T22:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-vjcw-8gg8-rjq7/GHSA-vjcw-8gg8-rjq7.json b/advisories/unreviewed/2024/11/GHSA-vjcw-8gg8-rjq7/GHSA-vjcw-8gg8-rjq7.json new file mode 100644 index 00000000000..0945c5aa0ed --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-vjcw-8gg8-rjq7/GHSA-vjcw-8gg8-rjq7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vjcw-8gg8-rjq7", + "modified": "2024-11-19T00:32:44Z", + "published": "2024-11-19T00:32:44Z", + "aliases": [ + "CVE-2024-52349" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Md. Shiddikur Rahman Awesome Tool Tip allows DOM-Based XSS.This issue affects Awesome Tool Tip: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52349" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/awesome-tool-tip/wordpress-awesome-tool-tip-plugin-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T22:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-w3xr-946r-w34h/GHSA-w3xr-946r-w34h.json b/advisories/unreviewed/2024/11/GHSA-w3xr-946r-w34h/GHSA-w3xr-946r-w34h.json new file mode 100644 index 00000000000..24b3041396c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-w3xr-946r-w34h/GHSA-w3xr-946r-w34h.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w3xr-946r-w34h", + "modified": "2024-11-19T00:32:44Z", + "published": "2024-11-19T00:32:44Z", + "aliases": [ + "CVE-2024-51051" + ], + "details": "AVSCMS v8.2.0 was discovered to contain weak default credentials for the Administrator account.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51051" + }, + { + "type": "WEB", + "url": "https://binqqer.com/posts/CVE-2024-51051" + }, + { + "type": "WEB", + "url": "https://github.com/avscms/avscms/blob/main/include/config.local.php" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T22:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-wx59-9gp6-398v/GHSA-wx59-9gp6-398v.json b/advisories/unreviewed/2024/11/GHSA-wx59-9gp6-398v/GHSA-wx59-9gp6-398v.json new file mode 100644 index 00000000000..20161da1a67 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-wx59-9gp6-398v/GHSA-wx59-9gp6-398v.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wx59-9gp6-398v", + "modified": "2024-11-19T00:32:44Z", + "published": "2024-11-19T00:32:44Z", + "aliases": [ + "CVE-2024-33231" + ], + "details": "Cross Site Scripting vulnerability in Ferozo Email version 1.1 allows a local attacker to execute arbitrary code via a crafted payload to the PDF preview component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33231" + }, + { + "type": "WEB", + "url": "https://github.com/fdzdev/CVE-2024-33231" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T23:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-xq44-wcjx-g3w9/GHSA-xq44-wcjx-g3w9.json b/advisories/unreviewed/2024/11/GHSA-xq44-wcjx-g3w9/GHSA-xq44-wcjx-g3w9.json new file mode 100644 index 00000000000..0160f12c33b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-xq44-wcjx-g3w9/GHSA-xq44-wcjx-g3w9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xq44-wcjx-g3w9", + "modified": "2024-11-19T00:32:43Z", + "published": "2024-11-19T00:32:43Z", + "aliases": [ + "CVE-2024-21287" + ], + "details": "Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software Development Kit, Process Extension). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM Framework. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM Framework accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21287" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/alert-cve-2024-21287.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T22:15:05Z" + } +} \ No newline at end of file