diff --git a/advisories/unreviewed/2024/05/GHSA-3vp4-9c6g-mcq2/GHSA-3vp4-9c6g-mcq2.json b/advisories/unreviewed/2024/05/GHSA-3vp4-9c6g-mcq2/GHSA-3vp4-9c6g-mcq2.json new file mode 100644 index 00000000000..ce5eef8b952 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-3vp4-9c6g-mcq2/GHSA-3vp4-9c6g-mcq2.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3vp4-9c6g-mcq2", + "modified": "2024-05-08T06:30:48Z", + "published": "2024-05-08T06:30:48Z", + "aliases": [ + "CVE-2024-32674" + ], + "details": "Heateor Social Login WordPress prior to 1.1.32 contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32674" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN87694318" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/heateor-social-login" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T04:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-8q5c-h63v-v869/GHSA-8q5c-h63v-v869.json b/advisories/unreviewed/2024/05/GHSA-8q5c-h63v-v869/GHSA-8q5c-h63v-v869.json new file mode 100644 index 00000000000..6fc02a3c425 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-8q5c-h63v-v869/GHSA-8q5c-h63v-v869.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8q5c-h63v-v869", + "modified": "2024-05-08T06:30:48Z", + "published": "2024-05-08T06:30:48Z", + "aliases": [ + "CVE-2024-1076" + ], + "details": "The SSL Zen WordPress plugin before 4.6.0 only relies on the use of .htaccess to prevent visitors from accessing the site's generated private keys, which allows an attacker to read them if the site runs on a server who doesn't support .htaccess files, like NGINX.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1076" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/9c3e9c72-3d6c-4e2c-bb8a-f4efce1371d5" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T06:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-gc8p-39g7-4mhp/GHSA-gc8p-39g7-4mhp.json b/advisories/unreviewed/2024/05/GHSA-gc8p-39g7-4mhp/GHSA-gc8p-39g7-4mhp.json new file mode 100644 index 00000000000..75c0e5019cf --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-gc8p-39g7-4mhp/GHSA-gc8p-39g7-4mhp.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gc8p-39g7-4mhp", + "modified": "2024-05-08T06:30:48Z", + "published": "2024-05-08T06:30:48Z", + "aliases": [ + "CVE-2024-3494" + ], + "details": "The Mesmerize Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mesmerize_contact_form' shortcode in all versions up to, and including, 1.6.148 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3494" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3078422/mesmerize-companion/trunk/theme-data/mesmerize/functions.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/521bb5a3-0a0c-4693-a87d-fabb64f1ad4f?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T06:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-p9h5-83v6-32fq/GHSA-p9h5-83v6-32fq.json b/advisories/unreviewed/2024/05/GHSA-p9h5-83v6-32fq/GHSA-p9h5-83v6-32fq.json new file mode 100644 index 00000000000..7a70feb6ad0 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-p9h5-83v6-32fq/GHSA-p9h5-83v6-32fq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p9h5-83v6-32fq", + "modified": "2024-05-08T06:30:48Z", + "published": "2024-05-08T06:30:48Z", + "aliases": [ + "CVE-2024-22266" + ], + "details": " VMware Avi Load Balancer contains an information disclosure vulnerability. A malicious actor with access to the system logs can view cloud connection credentials in plaintext.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22266" + }, + { + "type": "WEB", + "url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24219" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T04:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-pfmv-h3cf-mr72/GHSA-pfmv-h3cf-mr72.json b/advisories/unreviewed/2024/05/GHSA-pfmv-h3cf-mr72/GHSA-pfmv-h3cf-mr72.json new file mode 100644 index 00000000000..b9067ce1615 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-pfmv-h3cf-mr72/GHSA-pfmv-h3cf-mr72.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pfmv-h3cf-mr72", + "modified": "2024-05-08T06:30:48Z", + "published": "2024-05-08T06:30:48Z", + "aliases": [ + "CVE-2024-22264" + ], + "details": "VMware Avi Load Balancer contains a privilege escalation vulnerability. A malicious actor with admin privileges on VMware Avi Load Balancer can create, modify, execute and delete files as a root user on the host system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22264" + }, + { + "type": "WEB", + "url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24219" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T04:15:08Z" + } +} \ No newline at end of file