From 9844cbbd6108d0757e20f5a71f70ebba26a3e1ca Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 6 May 2024 21:32:04 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-245h-h68p-v4jq.json | 35 ++++++++++++++ .../GHSA-25gf-mm96-28wq.json | 38 +++++++++++++++ .../GHSA-29q6-h2f3-x724.json | 38 +++++++++++++++ .../GHSA-2pxq-hcw9-cvgv.json | 38 +++++++++++++++ .../GHSA-442q-pmc8-45rg.json | 35 ++++++++++++++ .../GHSA-4jjj-r6hx-hx6f.json | 35 ++++++++++++++ .../GHSA-4qhm-36g2-5mv9.json | 38 +++++++++++++++ .../GHSA-4rhr-3r55-929p.json | 38 +++++++++++++++ .../GHSA-4vmc-32f5-wrhg.json | 38 +++++++++++++++ .../GHSA-536w-qc2g-q32f.json | 38 +++++++++++++++ .../GHSA-6h69-r77q-c662.json | 35 ++++++++++++++ .../GHSA-6m8c-prp8-6wxm.json | 38 +++++++++++++++ .../GHSA-6qmw-vrwj-3jq5.json | 38 +++++++++++++++ .../GHSA-73vf-rffh-r96q.json | 38 +++++++++++++++ .../GHSA-8wf4-5jmv-gw97.json | 31 +++++++++++++ .../GHSA-95mp-mxq2-vr8j.json | 38 +++++++++++++++ .../GHSA-9gvm-vcgf-x5xw.json | 35 ++++++++++++++ .../GHSA-9hr4-r2h6-9m6f.json | 38 +++++++++++++++ .../GHSA-9qrf-qw9f-xpj5.json | 35 ++++++++++++++ .../GHSA-cfhf-6366-c7pf.json | 38 +++++++++++++++ .../GHSA-f4cf-2w52-c853.json | 35 ++++++++++++++ .../GHSA-f4pv-q5f7-2h55.json | 35 ++++++++++++++ .../GHSA-fx5j-8jwv-3gcc.json | 38 +++++++++++++++ .../GHSA-g9vc-r3ph-h584.json | 38 +++++++++++++++ .../GHSA-grp9-5xj3-5wrx.json | 38 +++++++++++++++ .../GHSA-h6fc-crpw-qg89.json | 38 +++++++++++++++ .../GHSA-h786-fjcx-j2mr.json | 38 +++++++++++++++ .../GHSA-h9f3-6hh4-649x.json | 38 +++++++++++++++ .../GHSA-hm96-7687-wcj3.json | 38 +++++++++++++++ .../GHSA-hmw2-fx34-2q97.json | 35 ++++++++++++++ .../GHSA-j4rq-4w69-pqmq.json | 39 ++++++++++++++++ .../GHSA-jc32-8xr7-m3gr.json | 38 +++++++++++++++ .../GHSA-jcv7-6v4q-4m7x.json | 46 +++++++++++++++++++ .../GHSA-jv3g-6pg3-v9j8.json | 35 ++++++++++++++ .../GHSA-jvfj-c7wv-mq45.json | 35 ++++++++++++++ .../GHSA-m6xf-rg25-42wc.json | 6 ++- .../GHSA-qfx9-qfc2-j6vj.json | 38 +++++++++++++++ .../GHSA-qqr5-9q23-995q.json | 38 +++++++++++++++ .../GHSA-r2pm-p649-q2r3.json | 38 +++++++++++++++ .../GHSA-rgrm-rq44-w47f.json | 38 +++++++++++++++ .../GHSA-v8fc-7564-v98v.json | 35 ++++++++++++++ .../GHSA-vhjm-ghx5-jwm3.json | 38 +++++++++++++++ .../GHSA-wfjf-pjxw-v8wf.json | 38 +++++++++++++++ .../GHSA-x8pq-qq4m-4ffg.json | 38 +++++++++++++++ 44 files changed, 1605 insertions(+), 1 deletion(-) create mode 100644 advisories/unreviewed/2024/05/GHSA-245h-h68p-v4jq/GHSA-245h-h68p-v4jq.json create mode 100644 advisories/unreviewed/2024/05/GHSA-25gf-mm96-28wq/GHSA-25gf-mm96-28wq.json create mode 100644 advisories/unreviewed/2024/05/GHSA-29q6-h2f3-x724/GHSA-29q6-h2f3-x724.json create mode 100644 advisories/unreviewed/2024/05/GHSA-2pxq-hcw9-cvgv/GHSA-2pxq-hcw9-cvgv.json create mode 100644 advisories/unreviewed/2024/05/GHSA-442q-pmc8-45rg/GHSA-442q-pmc8-45rg.json create mode 100644 advisories/unreviewed/2024/05/GHSA-4jjj-r6hx-hx6f/GHSA-4jjj-r6hx-hx6f.json create mode 100644 advisories/unreviewed/2024/05/GHSA-4qhm-36g2-5mv9/GHSA-4qhm-36g2-5mv9.json create mode 100644 advisories/unreviewed/2024/05/GHSA-4rhr-3r55-929p/GHSA-4rhr-3r55-929p.json create mode 100644 advisories/unreviewed/2024/05/GHSA-4vmc-32f5-wrhg/GHSA-4vmc-32f5-wrhg.json create mode 100644 advisories/unreviewed/2024/05/GHSA-536w-qc2g-q32f/GHSA-536w-qc2g-q32f.json create mode 100644 advisories/unreviewed/2024/05/GHSA-6h69-r77q-c662/GHSA-6h69-r77q-c662.json create mode 100644 advisories/unreviewed/2024/05/GHSA-6m8c-prp8-6wxm/GHSA-6m8c-prp8-6wxm.json create mode 100644 advisories/unreviewed/2024/05/GHSA-6qmw-vrwj-3jq5/GHSA-6qmw-vrwj-3jq5.json create mode 100644 advisories/unreviewed/2024/05/GHSA-73vf-rffh-r96q/GHSA-73vf-rffh-r96q.json create mode 100644 advisories/unreviewed/2024/05/GHSA-8wf4-5jmv-gw97/GHSA-8wf4-5jmv-gw97.json create mode 100644 advisories/unreviewed/2024/05/GHSA-95mp-mxq2-vr8j/GHSA-95mp-mxq2-vr8j.json create mode 100644 advisories/unreviewed/2024/05/GHSA-9gvm-vcgf-x5xw/GHSA-9gvm-vcgf-x5xw.json create mode 100644 advisories/unreviewed/2024/05/GHSA-9hr4-r2h6-9m6f/GHSA-9hr4-r2h6-9m6f.json create mode 100644 advisories/unreviewed/2024/05/GHSA-9qrf-qw9f-xpj5/GHSA-9qrf-qw9f-xpj5.json create mode 100644 advisories/unreviewed/2024/05/GHSA-cfhf-6366-c7pf/GHSA-cfhf-6366-c7pf.json create mode 100644 advisories/unreviewed/2024/05/GHSA-f4cf-2w52-c853/GHSA-f4cf-2w52-c853.json create mode 100644 advisories/unreviewed/2024/05/GHSA-f4pv-q5f7-2h55/GHSA-f4pv-q5f7-2h55.json create mode 100644 advisories/unreviewed/2024/05/GHSA-fx5j-8jwv-3gcc/GHSA-fx5j-8jwv-3gcc.json create mode 100644 advisories/unreviewed/2024/05/GHSA-g9vc-r3ph-h584/GHSA-g9vc-r3ph-h584.json create mode 100644 advisories/unreviewed/2024/05/GHSA-grp9-5xj3-5wrx/GHSA-grp9-5xj3-5wrx.json create mode 100644 advisories/unreviewed/2024/05/GHSA-h6fc-crpw-qg89/GHSA-h6fc-crpw-qg89.json create mode 100644 advisories/unreviewed/2024/05/GHSA-h786-fjcx-j2mr/GHSA-h786-fjcx-j2mr.json create mode 100644 advisories/unreviewed/2024/05/GHSA-h9f3-6hh4-649x/GHSA-h9f3-6hh4-649x.json create mode 100644 advisories/unreviewed/2024/05/GHSA-hm96-7687-wcj3/GHSA-hm96-7687-wcj3.json create mode 100644 advisories/unreviewed/2024/05/GHSA-hmw2-fx34-2q97/GHSA-hmw2-fx34-2q97.json create mode 100644 advisories/unreviewed/2024/05/GHSA-j4rq-4w69-pqmq/GHSA-j4rq-4w69-pqmq.json create mode 100644 advisories/unreviewed/2024/05/GHSA-jc32-8xr7-m3gr/GHSA-jc32-8xr7-m3gr.json create mode 100644 advisories/unreviewed/2024/05/GHSA-jcv7-6v4q-4m7x/GHSA-jcv7-6v4q-4m7x.json create mode 100644 advisories/unreviewed/2024/05/GHSA-jv3g-6pg3-v9j8/GHSA-jv3g-6pg3-v9j8.json create mode 100644 advisories/unreviewed/2024/05/GHSA-jvfj-c7wv-mq45/GHSA-jvfj-c7wv-mq45.json create mode 100644 advisories/unreviewed/2024/05/GHSA-qfx9-qfc2-j6vj/GHSA-qfx9-qfc2-j6vj.json create mode 100644 advisories/unreviewed/2024/05/GHSA-qqr5-9q23-995q/GHSA-qqr5-9q23-995q.json create mode 100644 advisories/unreviewed/2024/05/GHSA-r2pm-p649-q2r3/GHSA-r2pm-p649-q2r3.json create mode 100644 advisories/unreviewed/2024/05/GHSA-rgrm-rq44-w47f/GHSA-rgrm-rq44-w47f.json create mode 100644 advisories/unreviewed/2024/05/GHSA-v8fc-7564-v98v/GHSA-v8fc-7564-v98v.json create mode 100644 advisories/unreviewed/2024/05/GHSA-vhjm-ghx5-jwm3/GHSA-vhjm-ghx5-jwm3.json create mode 100644 advisories/unreviewed/2024/05/GHSA-wfjf-pjxw-v8wf/GHSA-wfjf-pjxw-v8wf.json create mode 100644 advisories/unreviewed/2024/05/GHSA-x8pq-qq4m-4ffg/GHSA-x8pq-qq4m-4ffg.json diff --git a/advisories/unreviewed/2024/05/GHSA-245h-h68p-v4jq/GHSA-245h-h68p-v4jq.json b/advisories/unreviewed/2024/05/GHSA-245h-h68p-v4jq/GHSA-245h-h68p-v4jq.json new file mode 100644 index 00000000000..0bbe602f6f9 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-245h-h68p-v4jq/GHSA-245h-h68p-v4jq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-245h-h68p-v4jq", + "modified": "2024-05-06T21:30:38Z", + "published": "2024-05-06T21:30:38Z", + "aliases": [ + "CVE-2024-33117" + ], + "details": "crmeb_java v1.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the mergeList method in class com.zbkj.front.pub.ImageMergeController.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33117" + }, + { + "type": "WEB", + "url": "https://github.com/cxcxcxcxcxcxcxc/cxcxcxcxcxcxcxc/blob/main/cxcxcxcxcxc/about-2024/33117.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-06T20:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-25gf-mm96-28wq/GHSA-25gf-mm96-28wq.json b/advisories/unreviewed/2024/05/GHSA-25gf-mm96-28wq/GHSA-25gf-mm96-28wq.json new file mode 100644 index 00000000000..038e14b5a55 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-25gf-mm96-28wq/GHSA-25gf-mm96-28wq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-25gf-mm96-28wq", + "modified": "2024-05-06T21:30:38Z", + "published": "2024-05-06T21:30:38Z", + "aliases": [ + "CVE-2024-34387" + ], + "details": "Missing Authorization vulnerability in AF themes WP Post Author.This issue affects WP Post Author: from n/a through 3.6.4.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34387" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-post-author/wordpress-wp-post-author-plugin-3-6-4-rating-value-manipulation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-06T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-29q6-h2f3-x724/GHSA-29q6-h2f3-x724.json b/advisories/unreviewed/2024/05/GHSA-29q6-h2f3-x724/GHSA-29q6-h2f3-x724.json new file mode 100644 index 00000000000..ef58e5e026f --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-29q6-h2f3-x724/GHSA-29q6-h2f3-x724.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-29q6-h2f3-x724", + "modified": "2024-05-06T21:30:38Z", + "published": "2024-05-06T21:30:38Z", + "aliases": [ + "CVE-2024-34372" + ], + "details": "Missing Authorization vulnerability in AddonMaster Post Grid Master.This issue affects Post Grid Master: from n/a through 3.4.7.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34372" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ajax-filter-posts/wordpress-post-grid-master-plugin-3-4-7-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-06T19:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-2pxq-hcw9-cvgv/GHSA-2pxq-hcw9-cvgv.json b/advisories/unreviewed/2024/05/GHSA-2pxq-hcw9-cvgv/GHSA-2pxq-hcw9-cvgv.json new file mode 100644 index 00000000000..8084c35efed --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-2pxq-hcw9-cvgv/GHSA-2pxq-hcw9-cvgv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2pxq-hcw9-cvgv", + "modified": "2024-05-06T21:30:38Z", + "published": "2024-05-06T21:30:38Z", + "aliases": [ + "CVE-2024-4568" + ], + "details": "In Xpdf 4.05 (and earlier), a PDF object loop in the PDF resources leads to infinite recursion and a stack overflow.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4568" + }, + { + "type": "WEB", + "url": "https://www.xpdfreader.com/security-bug/object-loops.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-674" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-06T20:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-442q-pmc8-45rg/GHSA-442q-pmc8-45rg.json b/advisories/unreviewed/2024/05/GHSA-442q-pmc8-45rg/GHSA-442q-pmc8-45rg.json new file mode 100644 index 00000000000..ead6ffe5796 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-442q-pmc8-45rg/GHSA-442q-pmc8-45rg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-442q-pmc8-45rg", + "modified": "2024-05-06T21:30:38Z", + "published": "2024-05-06T21:30:38Z", + "aliases": [ + "CVE-2023-33548" + ], + "details": "Cross Site Scripting (XSS) vulnerability in ASUS RT-AC51U with firmware versions up to and including 3.0.0.4.380.8591 allows attackers to run arbitrary code via the WPA Pre-Shared Key field.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33548" + }, + { + "type": "WEB", + "url": "https://github.com/Idaht/ASUS_RT-AC51U_CVE/blob/main/XSS%20-%20WPA%20Pre-Shared%20Key" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-06T21:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-4jjj-r6hx-hx6f/GHSA-4jjj-r6hx-hx6f.json b/advisories/unreviewed/2024/05/GHSA-4jjj-r6hx-hx6f/GHSA-4jjj-r6hx-hx6f.json new file mode 100644 index 00000000000..01d09dfa694 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-4jjj-r6hx-hx6f/GHSA-4jjj-r6hx-hx6f.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4jjj-r6hx-hx6f", + "modified": "2024-05-06T21:30:38Z", + "published": "2024-05-06T21:30:38Z", + "aliases": [ + "CVE-2024-34534" + ], + "details": "A SQL injection vulnerability in Cybrosys Techno Solutions Text Commander module (aka text_commander) 16.0 through 16.0.1 allows a remote attacker to gain privileges via the data parameter to models/ir_model.py:IrModel::chech_model.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34534" + }, + { + "type": "WEB", + "url": "https://github.com/luvsn/OdZoo/tree/main/exploits/text_commander" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-06T21:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-4qhm-36g2-5mv9/GHSA-4qhm-36g2-5mv9.json b/advisories/unreviewed/2024/05/GHSA-4qhm-36g2-5mv9/GHSA-4qhm-36g2-5mv9.json new file mode 100644 index 00000000000..866f74d40ce --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-4qhm-36g2-5mv9/GHSA-4qhm-36g2-5mv9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4qhm-36g2-5mv9", + "modified": "2024-05-06T21:30:38Z", + "published": "2024-05-06T21:30:38Z", + "aliases": [ + "CVE-2024-34381" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PropertyHive allows Stored XSS.This issue affects PropertyHive: from n/a through 2.0.10.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34381" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/propertyhive/wordpress-propertyhive-plugin-2-0-10-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-06T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-4rhr-3r55-929p/GHSA-4rhr-3r55-929p.json b/advisories/unreviewed/2024/05/GHSA-4rhr-3r55-929p/GHSA-4rhr-3r55-929p.json new file mode 100644 index 00000000000..e25399be955 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-4rhr-3r55-929p/GHSA-4rhr-3r55-929p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4rhr-3r55-929p", + "modified": "2024-05-06T21:30:38Z", + "published": "2024-05-06T21:30:38Z", + "aliases": [ + "CVE-2024-33570" + ], + "details": "Missing Authorization vulnerability in Wpmet Metform Elementor Contact Form Builder.This issue affects Metform Elementor Contact Form Builder: from n/a through 3.8.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33570" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/metform/wordpress-metform-plugin-3-8-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-06T20:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-4vmc-32f5-wrhg/GHSA-4vmc-32f5-wrhg.json b/advisories/unreviewed/2024/05/GHSA-4vmc-32f5-wrhg/GHSA-4vmc-32f5-wrhg.json new file mode 100644 index 00000000000..7cac2cb4255 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-4vmc-32f5-wrhg/GHSA-4vmc-32f5-wrhg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4vmc-32f5-wrhg", + "modified": "2024-05-06T21:30:38Z", + "published": "2024-05-06T21:30:38Z", + "aliases": [ + "CVE-2024-34386" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Lucian Apostol Auto Affiliate Links.This issue affects Auto Affiliate Links: from n/a through 6.4.3.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34386" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-auto-affiliate-links/wordpress-auto-affiliate-links-plugin-6-4-3-1-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-06T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-536w-qc2g-q32f/GHSA-536w-qc2g-q32f.json b/advisories/unreviewed/2024/05/GHSA-536w-qc2g-q32f/GHSA-536w-qc2g-q32f.json new file mode 100644 index 00000000000..b81fd334ce9 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-536w-qc2g-q32f/GHSA-536w-qc2g-q32f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-536w-qc2g-q32f", + "modified": "2024-05-06T21:30:38Z", + "published": "2024-05-06T21:30:38Z", + "aliases": [ + "CVE-2024-34375" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPPOOL Sheets To WP Table Live Sync allows Stored XSS.This issue affects Sheets To WP Table Live Sync: from n/a through 3.7.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34375" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/sheets-to-wp-table-live-sync/wordpress-sheets-to-wp-table-live-sync-plugin-3-7-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-06T19:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-6h69-r77q-c662/GHSA-6h69-r77q-c662.json b/advisories/unreviewed/2024/05/GHSA-6h69-r77q-c662/GHSA-6h69-r77q-c662.json new file mode 100644 index 00000000000..216c8722056 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-6h69-r77q-c662/GHSA-6h69-r77q-c662.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6h69-r77q-c662", + "modified": "2024-05-06T21:30:38Z", + "published": "2024-05-06T21:30:38Z", + "aliases": [ + "CVE-2024-34532" + ], + "details": "A SQL injection vulnerability in Yvan Dotet PostgreSQL Query Deluxe module (aka query_deluxe) 17.x before 17.0.0.4 allows a remote attacker to gain privileges via the query parameter to models/querydeluxe.py:QueryDeluxe::get_result_from_query.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34532" + }, + { + "type": "WEB", + "url": "https://github.com/luvsn/OdZoo/tree/main/exploits/query_deluxe" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-06T21:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-6m8c-prp8-6wxm/GHSA-6m8c-prp8-6wxm.json b/advisories/unreviewed/2024/05/GHSA-6m8c-prp8-6wxm/GHSA-6m8c-prp8-6wxm.json new file mode 100644 index 00000000000..3f127f512d2 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-6m8c-prp8-6wxm/GHSA-6m8c-prp8-6wxm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6m8c-prp8-6wxm", + "modified": "2024-05-06T21:30:38Z", + "published": "2024-05-06T21:30:38Z", + "aliases": [ + "CVE-2024-34379" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme Restaurant and Cafe.This issue affects Restaurant and Cafe: from n/a through 1.2.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34379" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/restaurant-and-cafe/wordpress-restaurant-and-cafe-theme-1-2-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-06T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-6qmw-vrwj-3jq5/GHSA-6qmw-vrwj-3jq5.json b/advisories/unreviewed/2024/05/GHSA-6qmw-vrwj-3jq5/GHSA-6qmw-vrwj-3jq5.json new file mode 100644 index 00000000000..5a555d99be5 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-6qmw-vrwj-3jq5/GHSA-6qmw-vrwj-3jq5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6qmw-vrwj-3jq5", + "modified": "2024-05-06T21:30:37Z", + "published": "2024-05-06T21:30:37Z", + "aliases": [ + "CVE-2024-33910" + ], + "details": "Missing Authorization vulnerability in Supsystic Digital Publications by Supsystic.This issue affects Digital Publications by Supsystic: from n/a through 1.7.7.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33910" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/digital-publications-by-supsystic/wordpress-digital-publications-by-supsystic-plugin-1-7-7-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-06T19:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-73vf-rffh-r96q/GHSA-73vf-rffh-r96q.json b/advisories/unreviewed/2024/05/GHSA-73vf-rffh-r96q/GHSA-73vf-rffh-r96q.json new file mode 100644 index 00000000000..7c472cfd807 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-73vf-rffh-r96q/GHSA-73vf-rffh-r96q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-73vf-rffh-r96q", + "modified": "2024-05-06T21:30:38Z", + "published": "2024-05-06T21:30:38Z", + "aliases": [ + "CVE-2024-34378" + ], + "details": "Missing Authorization vulnerability in LeadConnector.This issue affects LeadConnector: from n/a through 1.7.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34378" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/leadconnector/wordpress-leadconnector-plugin-1-7-api-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-06T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-8wf4-5jmv-gw97/GHSA-8wf4-5jmv-gw97.json b/advisories/unreviewed/2024/05/GHSA-8wf4-5jmv-gw97/GHSA-8wf4-5jmv-gw97.json new file mode 100644 index 00000000000..7b45e817409 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-8wf4-5jmv-gw97/GHSA-8wf4-5jmv-gw97.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8wf4-5jmv-gw97", + "modified": "2024-05-06T21:30:38Z", + "published": "2024-05-06T21:30:38Z", + "aliases": [ + "CVE-2022-37460" + ], + "details": "Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37460" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-06T21:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-95mp-mxq2-vr8j/GHSA-95mp-mxq2-vr8j.json b/advisories/unreviewed/2024/05/GHSA-95mp-mxq2-vr8j/GHSA-95mp-mxq2-vr8j.json new file mode 100644 index 00000000000..0859fc89dbc --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-95mp-mxq2-vr8j/GHSA-95mp-mxq2-vr8j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-95mp-mxq2-vr8j", + "modified": "2024-05-06T21:30:38Z", + "published": "2024-05-06T21:30:38Z", + "aliases": [ + "CVE-2024-34377" + ], + "details": "Missing Authorization vulnerability in A WP Life Video Gallery – Api Gallery, YouTube and Vimeo, Link Gallery.This issue affects Video Gallery – Api Gallery, YouTube and Vimeo, Link Gallery: from n/a through 1.5.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34377" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/new-video-gallery/wordpress-video-gallery-api-gallery-youtube-and-vimeo-link-gallery-plugin-1-5-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-06T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-9gvm-vcgf-x5xw/GHSA-9gvm-vcgf-x5xw.json b/advisories/unreviewed/2024/05/GHSA-9gvm-vcgf-x5xw/GHSA-9gvm-vcgf-x5xw.json new file mode 100644 index 00000000000..df17ab4f5dc --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-9gvm-vcgf-x5xw/GHSA-9gvm-vcgf-x5xw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9gvm-vcgf-x5xw", + "modified": "2024-05-06T21:30:38Z", + "published": "2024-05-06T21:30:38Z", + "aliases": [ + "CVE-2024-33599" + ], + "details": "nscd: Stack-based buffer overflow in netgroup cache\n\nIf the Name Service Cache Daemon's (nscd) fixed size cache is exhausted\nby client requests then a subsequent client request for netgroup data\nmay result in a stack-based buffer overflow. This flaw was introduced\nin glibc 2.15 when the cache was added to nscd.\n\nThis vulnerability is only present in the nscd binary.\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33599" + }, + { + "type": "WEB", + "url": "https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0005" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-06T20:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-9hr4-r2h6-9m6f/GHSA-9hr4-r2h6-9m6f.json b/advisories/unreviewed/2024/05/GHSA-9hr4-r2h6-9m6f/GHSA-9hr4-r2h6-9m6f.json new file mode 100644 index 00000000000..750ab6805fb --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-9hr4-r2h6-9m6f/GHSA-9hr4-r2h6-9m6f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9hr4-r2h6-9m6f", + "modified": "2024-05-06T21:30:38Z", + "published": "2024-05-06T21:30:38Z", + "aliases": [ + "CVE-2024-34389" + ], + "details": "Missing Authorization vulnerability in AF themes WP Post Author.This issue affects WP Post Author: from n/a through 3.6.4.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34389" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-post-author/wordpress-wp-post-author-plugin-3-6-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-06T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-9qrf-qw9f-xpj5/GHSA-9qrf-qw9f-xpj5.json b/advisories/unreviewed/2024/05/GHSA-9qrf-qw9f-xpj5/GHSA-9qrf-qw9f-xpj5.json new file mode 100644 index 00000000000..e3e274efd88 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-9qrf-qw9f-xpj5/GHSA-9qrf-qw9f-xpj5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qrf-qw9f-xpj5", + "modified": "2024-05-06T21:30:38Z", + "published": "2024-05-06T21:30:38Z", + "aliases": [ + "CVE-2024-33118" + ], + "details": "LuckyFrameWeb v3.5.2 was discovered to contain an arbitrary read vulnerability via the fileDownload method in class com.luckyframe.project.common.CommonController.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33118" + }, + { + "type": "WEB", + "url": "https://github.com/cxcxcxcxcxcxcxc/cxcxcxcxcxcxcxc/blob/main/cxcxcxcxcxc/about-2024/33118.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-06T20:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-cfhf-6366-c7pf/GHSA-cfhf-6366-c7pf.json b/advisories/unreviewed/2024/05/GHSA-cfhf-6366-c7pf/GHSA-cfhf-6366-c7pf.json new file mode 100644 index 00000000000..64c337e57d2 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-cfhf-6366-c7pf/GHSA-cfhf-6366-c7pf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cfhf-6366-c7pf", + "modified": "2024-05-06T21:30:38Z", + "published": "2024-05-06T21:30:38Z", + "aliases": [ + "CVE-2024-34371" + ], + "details": "Missing Authorization vulnerability in Hamid Alinia – idehweb Login with phone number.This issue affects Login with phone number: from n/a through 1.7.18.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34371" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/login-with-phone-number/wordpress-login-with-phone-number-plugin-1-7-18-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-06T19:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-f4cf-2w52-c853/GHSA-f4cf-2w52-c853.json b/advisories/unreviewed/2024/05/GHSA-f4cf-2w52-c853/GHSA-f4cf-2w52-c853.json new file mode 100644 index 00000000000..fab6b84e040 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-f4cf-2w52-c853/GHSA-f4cf-2w52-c853.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f4cf-2w52-c853", + "modified": "2024-05-06T21:30:38Z", + "published": "2024-05-06T21:30:38Z", + "aliases": [ + "CVE-2024-33601" + ], + "details": "nscd: netgroup cache may terminate daemon on memory allocation failure\n\nThe Name Service Cache Daemon's (nscd) netgroup cache uses xmalloc or\nxrealloc and these functions may terminate the process due to a memory\nallocation failure resulting in a denial of service to the clients. The\nflaw was introduced in glibc 2.15 when the cache was added to nscd.\n\nThis vulnerability is only present in the nscd binary.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33601" + }, + { + "type": "WEB", + "url": "https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0007" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-617" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-06T20:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-f4pv-q5f7-2h55/GHSA-f4pv-q5f7-2h55.json b/advisories/unreviewed/2024/05/GHSA-f4pv-q5f7-2h55/GHSA-f4pv-q5f7-2h55.json new file mode 100644 index 00000000000..43083d7356b --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-f4pv-q5f7-2h55/GHSA-f4pv-q5f7-2h55.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f4pv-q5f7-2h55", + "modified": "2024-05-06T21:30:38Z", + "published": "2024-05-06T21:30:38Z", + "aliases": [ + "CVE-2024-33602" + ], + "details": "nscd: netgroup cache assumes NSS callback uses in-buffer strings\n\nThe Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory\nwhen the NSS callback does not store all strings in the provided buffer.\nThe flaw was introduced in glibc 2.15 when the cache was added to nscd.\n\nThis vulnerability is only present in the nscd binary.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33602" + }, + { + "type": "WEB", + "url": "https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0008" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-466" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-06T20:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-fx5j-8jwv-3gcc/GHSA-fx5j-8jwv-3gcc.json b/advisories/unreviewed/2024/05/GHSA-fx5j-8jwv-3gcc/GHSA-fx5j-8jwv-3gcc.json new file mode 100644 index 00000000000..67036967271 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-fx5j-8jwv-3gcc/GHSA-fx5j-8jwv-3gcc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fx5j-8jwv-3gcc", + "modified": "2024-05-06T21:30:37Z", + "published": "2024-05-06T21:30:37Z", + "aliases": [ + "CVE-2024-33912" + ], + "details": "Missing Authorization vulnerability in Academy LMS.This issue affects Academy LMS: from n/a through 1.9.16.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33912" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/academy/wordpress-academy-lms-plugin-1-9-16-broken-access-control-on-paid-courses-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-06T19:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-g9vc-r3ph-h584/GHSA-g9vc-r3ph-h584.json b/advisories/unreviewed/2024/05/GHSA-g9vc-r3ph-h584/GHSA-g9vc-r3ph-h584.json new file mode 100644 index 00000000000..3d508e87865 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-g9vc-r3ph-h584/GHSA-g9vc-r3ph-h584.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g9vc-r3ph-h584", + "modified": "2024-05-06T21:30:38Z", + "published": "2024-05-06T21:30:38Z", + "aliases": [ + "CVE-2024-34413" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SliceWP allows Stored XSS.This issue affects SliceWP: from n/a through 1.1.10.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34413" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/slicewp/wordpress-slicewp-affiliates-plugin-1-1-10-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-06T21:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-grp9-5xj3-5wrx/GHSA-grp9-5xj3-5wrx.json b/advisories/unreviewed/2024/05/GHSA-grp9-5xj3-5wrx/GHSA-grp9-5xj3-5wrx.json new file mode 100644 index 00000000000..5635a49bdb1 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-grp9-5xj3-5wrx/GHSA-grp9-5xj3-5wrx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-grp9-5xj3-5wrx", + "modified": "2024-05-06T21:30:38Z", + "published": "2024-05-06T21:30:38Z", + "aliases": [ + "CVE-2024-34380" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud Conversational Forms for ChatBot allows Stored XSS.This issue affects Conversational Forms for ChatBot: from n/a through 1.2.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34380" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/conversational-forms/wordpress-chatbot-conversational-forms-plugin-1-2-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-06T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-h6fc-crpw-qg89/GHSA-h6fc-crpw-qg89.json b/advisories/unreviewed/2024/05/GHSA-h6fc-crpw-qg89/GHSA-h6fc-crpw-qg89.json new file mode 100644 index 00000000000..b309ed13134 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-h6fc-crpw-qg89/GHSA-h6fc-crpw-qg89.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h6fc-crpw-qg89", + "modified": "2024-05-06T21:30:38Z", + "published": "2024-05-06T21:30:38Z", + "aliases": [ + "CVE-2024-33576" + ], + "details": "Missing Authorization vulnerability in Ollybach WPPizza.This issue affects WPPizza: from n/a through 3.18.10.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33576" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wppizza/wordpress-wppizza-plugin-3-18-10-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-06T20:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-h786-fjcx-j2mr/GHSA-h786-fjcx-j2mr.json b/advisories/unreviewed/2024/05/GHSA-h786-fjcx-j2mr/GHSA-h786-fjcx-j2mr.json new file mode 100644 index 00000000000..aa5fcc27d74 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-h786-fjcx-j2mr/GHSA-h786-fjcx-j2mr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h786-fjcx-j2mr", + "modified": "2024-05-06T21:30:38Z", + "published": "2024-05-06T21:30:38Z", + "aliases": [ + "CVE-2024-34367" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Popup Box Team Popup box allows Cross-Site Scripting (XSS).This issue affects Popup box: from n/a through 4.1.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34367" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ays-popup-box/wordpress-popup-box-plugin-4-1-2-csrf-to-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-06T19:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-h9f3-6hh4-649x/GHSA-h9f3-6hh4-649x.json b/advisories/unreviewed/2024/05/GHSA-h9f3-6hh4-649x/GHSA-h9f3-6hh4-649x.json new file mode 100644 index 00000000000..a04efec9f32 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-h9f3-6hh4-649x/GHSA-h9f3-6hh4-649x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h9f3-6hh4-649x", + "modified": "2024-05-06T21:30:38Z", + "published": "2024-05-06T21:30:37Z", + "aliases": [ + "CVE-2024-34368" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Mooberry Dreams Mooberry Book Manager.This issue affects Mooberry Book Manager: from n/a through 4.15.12.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34368" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/mooberry-book-manager/wordpress-mooberry-book-manager-plugin-4-15-12-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-06T19:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-hm96-7687-wcj3/GHSA-hm96-7687-wcj3.json b/advisories/unreviewed/2024/05/GHSA-hm96-7687-wcj3/GHSA-hm96-7687-wcj3.json new file mode 100644 index 00000000000..9b382741975 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-hm96-7687-wcj3/GHSA-hm96-7687-wcj3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hm96-7687-wcj3", + "modified": "2024-05-06T21:30:38Z", + "published": "2024-05-06T21:30:38Z", + "aliases": [ + "CVE-2024-34374" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuomodoSoft ElementsReady Addons for Elementor allows Stored XSS.This issue affects ElementsReady Addons for Elementor: from n/a through 5.8.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34374" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/element-ready-lite/wordpress-elementsready-addons-for-elementor-plugin-5-8-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-06T19:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-hmw2-fx34-2q97/GHSA-hmw2-fx34-2q97.json b/advisories/unreviewed/2024/05/GHSA-hmw2-fx34-2q97/GHSA-hmw2-fx34-2q97.json new file mode 100644 index 00000000000..1deff946881 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-hmw2-fx34-2q97/GHSA-hmw2-fx34-2q97.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hmw2-fx34-2q97", + "modified": "2024-05-06T21:30:38Z", + "published": "2024-05-06T21:30:38Z", + "aliases": [ + "CVE-2024-1695" + ], + "details": "A potential security vulnerability has been identified in the HP Application Enabling Software Driver for certain HP PC products, which might allow escalation of privilege. HP is releasing software updates to mitigate this potential vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1695" + }, + { + "type": "WEB", + "url": "https://support.hp.com/us-en/document/ish_10555591-10555627-16/hpsbhf03932" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-06T21:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-j4rq-4w69-pqmq/GHSA-j4rq-4w69-pqmq.json b/advisories/unreviewed/2024/05/GHSA-j4rq-4w69-pqmq/GHSA-j4rq-4w69-pqmq.json new file mode 100644 index 00000000000..61d3cf99c74 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-j4rq-4w69-pqmq/GHSA-j4rq-4w69-pqmq.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j4rq-4w69-pqmq", + "modified": "2024-05-06T21:30:38Z", + "published": "2024-05-06T21:30:38Z", + "aliases": [ + "CVE-2024-28725" + ], + "details": "Cross Site Scripting (XSS) vulnerability in YzmCMS 7.0 allows attackers to run arbitrary code via Ads Management, Carousel Management, and System Settings.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28725" + }, + { + "type": "WEB", + "url": "https://github.com/asenzhenshuai/DongDong/issues/1" + }, + { + "type": "WEB", + "url": "https://github.com/asenzhenshuai/DongDong/blob/main/yzmcms-xss.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-06T21:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-jc32-8xr7-m3gr/GHSA-jc32-8xr7-m3gr.json b/advisories/unreviewed/2024/05/GHSA-jc32-8xr7-m3gr/GHSA-jc32-8xr7-m3gr.json new file mode 100644 index 00000000000..5383ecfa27b --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-jc32-8xr7-m3gr/GHSA-jc32-8xr7-m3gr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jc32-8xr7-m3gr", + "modified": "2024-05-06T21:30:38Z", + "published": "2024-05-06T21:30:38Z", + "aliases": [ + "CVE-2024-34369" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webpushr Web Push Notifications Webpushr allows Reflected XSS.This issue affects Webpushr: from n/a through 4.35.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34369" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/webpushr-web-push-notifications/wordpress-web-push-notifications-webpushr-plugin-4-35-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-06T19:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-jcv7-6v4q-4m7x/GHSA-jcv7-6v4q-4m7x.json b/advisories/unreviewed/2024/05/GHSA-jcv7-6v4q-4m7x/GHSA-jcv7-6v4q-4m7x.json new file mode 100644 index 00000000000..7c4079ea57a --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-jcv7-6v4q-4m7x/GHSA-jcv7-6v4q-4m7x.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jcv7-6v4q-4m7x", + "modified": "2024-05-06T21:30:38Z", + "published": "2024-05-06T21:30:38Z", + "aliases": [ + "CVE-2024-3661" + ], + "details": "By design, the DHCP protocol does not authenticate messages, including for example the classless static route option (121). An attacker with the ability to send DHCP messages can manipulate routes to redirect VPN traffic, allowing the attacker to read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN. Many, if not most VPN systems based on IP routing are susceptible to such attacks.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3661" + }, + { + "type": "WEB", + "url": "https://datatracker.ietf.org/doc/html/rfc2131#section-7" + }, + { + "type": "WEB", + "url": "https://datatracker.ietf.org/doc/html/rfc3442#section-7" + }, + { + "type": "WEB", + "url": "https://www.leviathansecurity.com/blog/tunnelvision" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-06T19:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-jv3g-6pg3-v9j8/GHSA-jv3g-6pg3-v9j8.json b/advisories/unreviewed/2024/05/GHSA-jv3g-6pg3-v9j8/GHSA-jv3g-6pg3-v9j8.json new file mode 100644 index 00000000000..849a29ee9a7 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-jv3g-6pg3-v9j8/GHSA-jv3g-6pg3-v9j8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jv3g-6pg3-v9j8", + "modified": "2024-05-06T21:30:38Z", + "published": "2024-05-06T21:30:38Z", + "aliases": [ + "CVE-2024-33600" + ], + "details": "nscd: Null pointer crashes after notfound response\n\nIf the Name Service Cache Daemon's (nscd) cache fails to add a not-found\nnetgroup response to the cache, the client request can result in a null\npointer dereference. This flaw was introduced in glibc 2.15 when the\ncache was added to nscd.\n\nThis vulnerability is only present in the nscd binary.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33600" + }, + { + "type": "WEB", + "url": "https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0006" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-06T20:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-jvfj-c7wv-mq45/GHSA-jvfj-c7wv-mq45.json b/advisories/unreviewed/2024/05/GHSA-jvfj-c7wv-mq45/GHSA-jvfj-c7wv-mq45.json new file mode 100644 index 00000000000..d279379e7ee --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-jvfj-c7wv-mq45/GHSA-jvfj-c7wv-mq45.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jvfj-c7wv-mq45", + "modified": "2024-05-06T21:30:38Z", + "published": "2024-05-06T21:30:38Z", + "aliases": [ + "CVE-2024-33121" + ], + "details": "Roothub v2.6 was discovered to contain a SQL injection vulnerability via the 's' parameter in the search() function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33121" + }, + { + "type": "WEB", + "url": "https://github.com/cxcxcxcxcxcxcxc/cxcxcxcxcxcxcxc/blob/main/cxcxcxcxcxc/about-2024/33121.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-06T20:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-m6xf-rg25-42wc/GHSA-m6xf-rg25-42wc.json b/advisories/unreviewed/2024/05/GHSA-m6xf-rg25-42wc/GHSA-m6xf-rg25-42wc.json index b3fb941d19c..2646b9f3019 100644 --- a/advisories/unreviewed/2024/05/GHSA-m6xf-rg25-42wc/GHSA-m6xf-rg25-42wc.json +++ b/advisories/unreviewed/2024/05/GHSA-m6xf-rg25-42wc/GHSA-m6xf-rg25-42wc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m6xf-rg25-42wc", - "modified": "2024-05-06T12:30:25Z", + "modified": "2024-05-06T21:30:37Z", "published": "2024-05-03T21:30:30Z", "aliases": [ "CVE-2024-34455" @@ -29,6 +29,10 @@ { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/05/06/2" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/05/06/4" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/05/GHSA-qfx9-qfc2-j6vj/GHSA-qfx9-qfc2-j6vj.json b/advisories/unreviewed/2024/05/GHSA-qfx9-qfc2-j6vj/GHSA-qfx9-qfc2-j6vj.json new file mode 100644 index 00000000000..14f9d41ce86 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-qfx9-qfc2-j6vj/GHSA-qfx9-qfc2-j6vj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qfx9-qfc2-j6vj", + "modified": "2024-05-06T21:30:38Z", + "published": "2024-05-06T21:30:38Z", + "aliases": [ + "CVE-2024-34373" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH The Plus Addons for Elementor Page Builder Lite allows Stored XSS.This issue affects The Plus Addons for Elementor Page Builder Lite: from n/a through 5.4.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34373" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/the-plus-addons-for-elementor-page-builder/wordpress-the-plus-addons-for-elementor-plugin-5-4-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-06T19:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-qqr5-9q23-995q/GHSA-qqr5-9q23-995q.json b/advisories/unreviewed/2024/05/GHSA-qqr5-9q23-995q/GHSA-qqr5-9q23-995q.json new file mode 100644 index 00000000000..3fca8f20131 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-qqr5-9q23-995q/GHSA-qqr5-9q23-995q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qqr5-9q23-995q", + "modified": "2024-05-06T21:30:38Z", + "published": "2024-05-06T21:30:38Z", + "aliases": [ + "CVE-2024-34376" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Theme Freesia Edge allows Stored XSS.This issue affects Edge: from n/a through 2.0.9.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34376" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/edge/wordpress-edge-theme-2-0-9-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-06T19:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-r2pm-p649-q2r3/GHSA-r2pm-p649-q2r3.json b/advisories/unreviewed/2024/05/GHSA-r2pm-p649-q2r3/GHSA-r2pm-p649-q2r3.json new file mode 100644 index 00000000000..157ea744dfc --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-r2pm-p649-q2r3/GHSA-r2pm-p649-q2r3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r2pm-p649-q2r3", + "modified": "2024-05-06T21:30:38Z", + "published": "2024-05-06T21:30:38Z", + "aliases": [ + "CVE-2024-34390" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AddonMaster Post Grid Master allows Stored XSS.This issue affects Post Grid Master: from n/a through 3.4.8.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34390" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ajax-filter-posts/wordpress-post-grid-master-plugin-3-4-8-auth-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-06T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-rgrm-rq44-w47f/GHSA-rgrm-rq44-w47f.json b/advisories/unreviewed/2024/05/GHSA-rgrm-rq44-w47f/GHSA-rgrm-rq44-w47f.json new file mode 100644 index 00000000000..4ad8057c994 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-rgrm-rq44-w47f/GHSA-rgrm-rq44-w47f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rgrm-rq44-w47f", + "modified": "2024-05-06T21:30:38Z", + "published": "2024-05-06T21:30:38Z", + "aliases": [ + "CVE-2024-34412" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Parcel Panel ParcelPanel.This issue affects ParcelPanel: from n/a through 3.8.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34412" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/parcelpanel/wordpress-parcelpanel-plugin-3-8-1-subscriber-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-06T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-v8fc-7564-v98v/GHSA-v8fc-7564-v98v.json b/advisories/unreviewed/2024/05/GHSA-v8fc-7564-v98v/GHSA-v8fc-7564-v98v.json new file mode 100644 index 00000000000..6ca80269cf1 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-v8fc-7564-v98v/GHSA-v8fc-7564-v98v.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v8fc-7564-v98v", + "modified": "2024-05-06T21:30:38Z", + "published": "2024-05-06T21:30:38Z", + "aliases": [ + "CVE-2024-34533" + ], + "details": "A SQL injection vulnerability in ZI PT Solusi Usaha Mudah Analytic Data Query module (aka izi_data) 11.0 through 17.x before 17.0.3 allows a remote attacker to gain privileges via a query to IZITools::query_check, IZITools::query_fetch, or IZITools::query_execute.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34533" + }, + { + "type": "WEB", + "url": "https://github.com/luvsn/OdZoo/tree/main/exploits/izi_data" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-06T21:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-vhjm-ghx5-jwm3/GHSA-vhjm-ghx5-jwm3.json b/advisories/unreviewed/2024/05/GHSA-vhjm-ghx5-jwm3/GHSA-vhjm-ghx5-jwm3.json new file mode 100644 index 00000000000..28ac4f69ee2 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-vhjm-ghx5-jwm3/GHSA-vhjm-ghx5-jwm3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vhjm-ghx5-jwm3", + "modified": "2024-05-06T21:30:38Z", + "published": "2024-05-06T21:30:38Z", + "aliases": [ + "CVE-2024-33908" + ], + "details": "Missing Authorization vulnerability in Themesgrove WidgetKit.This issue affects WidgetKit: from n/a through 2.5.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33908" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/widgetkit-for-elementor/wordpress-widgetkit-plugin-2-4-8-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-06T20:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-wfjf-pjxw-v8wf/GHSA-wfjf-pjxw-v8wf.json b/advisories/unreviewed/2024/05/GHSA-wfjf-pjxw-v8wf/GHSA-wfjf-pjxw-v8wf.json new file mode 100644 index 00000000000..6eb1eb6b142 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-wfjf-pjxw-v8wf/GHSA-wfjf-pjxw-v8wf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wfjf-pjxw-v8wf", + "modified": "2024-05-06T21:30:38Z", + "published": "2024-05-06T21:30:38Z", + "aliases": [ + "CVE-2024-33907" + ], + "details": "Missing Authorization vulnerability in Michael Nelson Print My Blog.This issue affects Print My Blog: from n/a through 3.26.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33907" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/print-my-blog/wordpress-print-my-blog-plugin-3-26-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-06T20:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-x8pq-qq4m-4ffg/GHSA-x8pq-qq4m-4ffg.json b/advisories/unreviewed/2024/05/GHSA-x8pq-qq4m-4ffg/GHSA-x8pq-qq4m-4ffg.json new file mode 100644 index 00000000000..d33a4b07919 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-x8pq-qq4m-4ffg/GHSA-x8pq-qq4m-4ffg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x8pq-qq4m-4ffg", + "modified": "2024-05-06T21:30:38Z", + "published": "2024-05-06T21:30:37Z", + "aliases": [ + "CVE-2024-34366" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AltText.Ai Download Alt Text AI allows Stored XSS.This issue affects Download Alt Text AI: from n/a through 1.3.4.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34366" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/alttext-ai/wordpress-alttext-ai-plugin-1-3-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-06T19:15:07Z" + } +} \ No newline at end of file