From a4957fb5b8e239cf8d2e1f8df0397431ae358ebf Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 19 Nov 2024 18:32:42 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-9j55-g998-6v4p.json | 3 +- .../GHSA-225p-gh6f-c6xc.json | 9 ++- .../GHSA-236f-m6gm-vp93.json | 2 +- .../GHSA-247x-jv5h-grf9.json | 38 +++++++++++ .../GHSA-24vh-3994-4wxm.json | 38 +++++++++++ .../GHSA-259q-92w6-wrgj.json | 39 ++++++++++++ .../GHSA-263m-wcmp-r5j6.json | 6 +- .../GHSA-276p-5gr8-q5fq.json | 43 +++++++++++++ .../GHSA-278c-qcm2-c4mv.json | 38 +++++++++++ .../GHSA-28mj-q95m-9rc8.json | 38 +++++++++++ .../GHSA-2ccf-wxp6-xgr9.json | 38 +++++++++++ .../GHSA-2ch6-g4cg-g5ph.json | 38 +++++++++++ .../GHSA-2jpp-f2p3-hhw9.json | 38 +++++++++++ .../GHSA-2pgq-v89h-j58m.json | 38 +++++++++++ .../GHSA-2qmr-p234-34wm.json | 38 +++++++++++ .../GHSA-2v77-g93r-76vh.json | 3 +- .../GHSA-2vrj-cvff-5p56.json | 39 ++++++++++++ .../GHSA-33c8-2qq8-ffcg.json | 38 +++++++++++ .../GHSA-363w-4gjr-hxxf.json | 51 +++++++++++++++ .../GHSA-373q-7p85-gr9f.json | 38 +++++++++++ .../GHSA-38wf-gvg7-rrvw.json | 38 +++++++++++ .../GHSA-3gf8-c827-8cjg.json | 38 +++++++++++ .../GHSA-3jp2-56w2-f943.json | 38 +++++++++++ .../GHSA-3mjq-gr7r-h6x3.json | 11 ++-- .../GHSA-3mvg-wf73-6mx2.json | 38 +++++++++++ .../GHSA-3vhp-r544-3wrg.json | 11 ++-- .../GHSA-3w4r-prc4-q67c.json | 38 +++++++++++ .../GHSA-3w88-854j-p487.json | 38 +++++++++++ .../GHSA-3wcp-g7h4-2r32.json | 38 +++++++++++ .../GHSA-42c7-w7r7-3v3m.json | 39 ++++++++++++ .../GHSA-42qw-9g84-jp2h.json | 38 +++++++++++ .../GHSA-432j-87hp-h33w.json | 38 +++++++++++ .../GHSA-43h5-8p3v-hfvv.json | 38 +++++++++++ .../GHSA-4437-j8j7-wqjr.json | 38 +++++++++++ .../GHSA-45w9-22fh-qrx4.json | 2 +- .../GHSA-4696-66c4-2gvx.json | 46 ++++++++++++++ .../GHSA-49fm-c6jx-pv73.json | 38 +++++++++++ .../GHSA-4cx4-xm36-7hp9.json | 38 +++++++++++ .../GHSA-4f2j-5xcx-5g9w.json | 43 +++++++++++++ .../GHSA-4f73-836m-4mcr.json | 39 ++++++++++++ .../GHSA-4gjx-j363-q574.json | 38 +++++++++++ .../GHSA-4pmx-qx84-x3f4.json | 38 +++++++++++ .../GHSA-4rq4-85gc-8wf8.json | 38 +++++++++++ .../GHSA-4wrj-7475-35c2.json | 38 +++++++++++ .../GHSA-4xwh-jfmg-xmv5.json | 38 +++++++++++ .../GHSA-533v-gm9h-955p.json | 38 +++++++++++ .../GHSA-548p-gmg2-4cqq.json | 38 +++++++++++ .../GHSA-54hc-gq3w-c935.json | 39 ++++++++++++ .../GHSA-553q-p66q-xfmv.json | 38 +++++++++++ .../GHSA-56f7-h7m2-r62r.json | 38 +++++++++++ .../GHSA-56wh-6gx4-4442.json | 39 ++++++++++++ .../GHSA-57xx-4r4j-43p7.json | 11 ++-- .../GHSA-594x-49wf-v3rp.json | 38 +++++++++++ .../GHSA-59r4-qr9h-8crh.json | 38 +++++++++++ .../GHSA-5ggj-xwvc-9x57.json | 39 ++++++++++++ .../GHSA-5gw7-xq3v-7q6c.json | 11 ++-- .../GHSA-5m89-67rv-p8wm.json | 38 +++++++++++ .../GHSA-5qr2-q8cp-vq2r.json | 38 +++++++++++ .../GHSA-5qw6-857j-hf24.json | 11 ++-- .../GHSA-5xgh-3xqg-v5p2.json | 38 +++++++++++ .../GHSA-65pc-phr9-277f.json | 38 +++++++++++ .../GHSA-66w7-vgc6-vh9v.json | 38 +++++++++++ .../GHSA-67c4-pjh7-g54h.json | 38 +++++++++++ .../GHSA-6999-6m26-m9xx.json | 39 ++++++++++++ .../GHSA-69h8-v2gw-h8q9.json | 39 ++++++++++++ .../GHSA-6gpv-2g95-83h9.json | 35 +++++++++++ .../GHSA-6h6f-84wv-5rqq.json | 11 ++-- .../GHSA-6jjx-758m-9gc4.json | 38 +++++++++++ .../GHSA-6jv4-h5x3-vxf3.json | 38 +++++++++++ .../GHSA-6pj7-c745-c2mx.json | 38 +++++++++++ .../GHSA-6pq4-p6m9-6r69.json | 11 ++-- .../GHSA-6qgf-95ch-q924.json | 38 +++++++++++ .../GHSA-6rh5-p63w-qc58.json | 38 +++++++++++ .../GHSA-6v28-4x74-3hpj.json | 38 +++++++++++ .../GHSA-6vqc-w6hm-2r5w.json | 38 +++++++++++ .../GHSA-6w26-4vm6-c7f2.json | 39 ++++++++++++ .../GHSA-7259-cwhj-xf2j.json | 38 +++++++++++ .../GHSA-73c2-2543-rv69.json | 38 +++++++++++ .../GHSA-73h5-69j6-pq7f.json | 38 +++++++++++ .../GHSA-74rr-c455-62vq.json | 35 +++++++++++ .../GHSA-75f9-w444-4xg7.json | 38 +++++++++++ .../GHSA-7866-w9g3-g699.json | 39 ++++++++++++ .../GHSA-78xf-x743-mmc6.json | 63 +++++++++++++++++++ .../GHSA-79f9-q2cg-p5x7.json | 38 +++++++++++ .../GHSA-7c65-3hqv-hvmm.json | 46 ++++++++++++++ .../GHSA-7ghh-hpqx-6wf8.json | 39 ++++++++++++ .../GHSA-7h32-65hg-rrp7.json | 38 +++++++++++ .../GHSA-7hr9-vfjf-38m4.json | 38 +++++++++++ .../GHSA-7hwj-x2vh-jqv9.json | 63 +++++++++++++++++++ .../GHSA-7mjf-5rrm-399r.json | 39 ++++++++++++ .../GHSA-7q26-9p5f-2xq5.json | 38 +++++++++++ .../GHSA-8348-jmhf-5pcj.json | 38 +++++++++++ .../GHSA-84vq-r732-qrg9.json | 38 +++++++++++ .../GHSA-874j-2w8f-c73r.json | 38 +++++++++++ .../GHSA-87q3-4f3j-74q7.json | 11 ++-- .../GHSA-87vp-wcxm-f9g2.json | 39 ++++++++++++ .../GHSA-88vw-5p88-2p6c.json | 38 +++++++++++ .../GHSA-8cp8-922f-xc53.json | 38 +++++++++++ .../GHSA-8cq9-rv8g-3wpg.json | 38 +++++++++++ .../GHSA-8frm-8r9v-j76p.json | 38 +++++++++++ .../GHSA-8gqp-w9h7-vrxp.json | 39 ++++++++++++ .../GHSA-8hgx-89h7-3vhm.json | 43 +++++++++++++ .../GHSA-8hj6-f2qf-5rxh.json | 38 +++++++++++ .../GHSA-8j46-pm7j-wh94.json | 35 +++++++++++ .../GHSA-8qpp-hcww-69wh.json | 38 +++++++++++ .../GHSA-8vf7-6fh2-6qw4.json | 11 ++-- .../GHSA-8vpp-w76f-8mx8.json | 11 ++-- .../GHSA-8vv8-fmp2-x4c4.json | 39 ++++++++++++ .../GHSA-8wxp-xf8h-h599.json | 38 +++++++++++ .../GHSA-8xg6-r8pq-vfwc.json | 38 +++++++++++ .../GHSA-8xx7-6q95-5vcp.json | 38 +++++++++++ .../GHSA-975c-w82q-mxhv.json | 11 ++-- .../GHSA-97h5-gfw2-p92x.json | 35 +++++++++++ .../GHSA-98fw-263x-275m.json | 38 +++++++++++ .../GHSA-9964-jv72-p792.json | 38 +++++++++++ .../GHSA-996p-gjg5-jmfx.json | 38 +++++++++++ .../GHSA-99qq-7hp5-9h5x.json | 38 +++++++++++ .../GHSA-9f4h-r2c7-m6w4.json | 50 +++++++++++++++ .../GHSA-9g3h-hh7f-7m88.json | 38 +++++++++++ .../GHSA-9h24-8pw7-c9p6.json | 38 +++++++++++ .../GHSA-9h8f-hjmp-pwxx.json | 2 +- .../GHSA-9r3x-3x49-29r7.json | 43 +++++++++++++ .../GHSA-9rhr-hcff-89rc.json | 38 +++++++++++ .../GHSA-9w8f-6h5p-xj5x.json | 51 +++++++++++++++ .../GHSA-9wcj-qpv5-8x56.json | 38 +++++++++++ .../GHSA-9x98-cfgr-9v24.json | 38 +++++++++++ .../GHSA-9xfw-pcxh-9682.json | 38 +++++++++++ .../GHSA-c2hm-g5g7-h823.json | 38 +++++++++++ .../GHSA-c3cr-hpjv-gv7r.json | 38 +++++++++++ .../GHSA-c3rv-gq44-hm8f.json | 38 +++++++++++ .../GHSA-c64j-4r5h-4rmp.json | 38 +++++++++++ .../GHSA-c6vv-jw3g-77q9.json | 38 +++++++++++ .../GHSA-c95v-4jjw-2rfc.json | 39 ++++++++++++ .../GHSA-c9q8-68wq-p8wf.json | 38 +++++++++++ .../GHSA-cgh6-mrm3-hqpj.json | 47 ++++++++++++++ .../GHSA-cgvw-jh5j-mgq3.json | 6 +- .../GHSA-chwg-hrp2-25gc.json | 38 +++++++++++ .../GHSA-cp57-7c6j-pxfg.json | 35 +++++++++++ .../GHSA-cv4q-xjgm-hcp3.json | 38 +++++++++++ .../GHSA-cvf9-v6p6-9c32.json | 38 +++++++++++ .../GHSA-cw9g-65q4-rpvj.json | 38 +++++++++++ .../GHSA-cwqh-jjqr-q2hf.json | 38 +++++++++++ .../GHSA-f2hp-wgc9-mcvf.json | 38 +++++++++++ .../GHSA-f6c2-ph4p-hmh6.json | 38 +++++++++++ .../GHSA-f76r-8x77-pwm4.json | 38 +++++++++++ .../GHSA-fc6c-wh46-2q9r.json | 63 +++++++++++++++++++ .../GHSA-ffrw-8p66-394j.json | 6 +- .../GHSA-fhmx-7jhg-8h34.json | 55 ++++++++++++++++ .../GHSA-fmfg-pggg-vmwc.json | 38 +++++++++++ .../GHSA-fp2v-7r4c-j6p5.json | 38 +++++++++++ .../GHSA-fw3x-9gjw-x3mg.json | 38 +++++++++++ .../GHSA-fw47-6v57-fjcf.json | 43 +++++++++++++ .../GHSA-fx99-8m8g-rfwx.json | 39 ++++++++++++ .../GHSA-g4gg-7gqp-cf6m.json | 39 ++++++++++++ .../GHSA-g63v-c4x5-2g6v.json | 51 +++++++++++++++ .../GHSA-g76f-r4m8-gr75.json | 38 +++++++++++ .../GHSA-g77r-mcw3-wcx8.json | 38 +++++++++++ .../GHSA-ggmg-vvg8-55m2.json | 38 +++++++++++ .../GHSA-gh8c-2875-38xv.json | 43 +++++++++++++ .../GHSA-gm4p-xxcw-q3xf.json | 38 +++++++++++ .../GHSA-gpf9-2frf-hch3.json | 38 +++++++++++ .../GHSA-gpvr-4p58-r896.json | 38 +++++++++++ .../GHSA-gr9q-mvmm-jr7v.json | 38 +++++++++++ .../GHSA-gv5x-w6m9-qv2v.json | 38 +++++++++++ .../GHSA-h29g-hxg6-g48j.json | 38 +++++++++++ .../GHSA-h2fw-j3h2-4fh6.json | 38 +++++++++++ .../GHSA-h7jr-f9m2-rr37.json | 39 ++++++++++++ .../GHSA-h9q9-3g7p-gq9x.json | 11 ++-- .../GHSA-h9vw-x7c8-cqgm.json | 38 +++++++++++ .../GHSA-hcpj-7xxx-7pm4.json | 2 +- .../GHSA-hf57-pc64-3428.json | 39 ++++++++++++ .../GHSA-hfwx-j6h2-rmf7.json | 38 +++++++++++ .../GHSA-hh3g-4c3h-9xq5.json | 38 +++++++++++ .../GHSA-hjf4-jrvv-979w.json | 38 +++++++++++ .../GHSA-hp9m-99c7-gwmq.json | 38 +++++++++++ .../GHSA-hvf6-4mg8-8mgf.json | 38 +++++++++++ .../GHSA-j2fh-p4jc-3h97.json | 59 +++++++++++++++++ .../GHSA-j5vh-vfg7-3v94.json | 63 +++++++++++++++++++ .../GHSA-j5w7-63fj-6h4c.json | 2 +- .../GHSA-j68m-vr9h-7553.json | 38 +++++++++++ .../GHSA-j6m7-43jh-w34q.json | 38 +++++++++++ .../GHSA-j6x9-wwrp-prcf.json | 38 +++++++++++ .../GHSA-j7jv-w7wp-p2c3.json | 11 ++-- .../GHSA-jfgv-5f9v-whcx.json | 38 +++++++++++ .../GHSA-jfhm-j25g-cc8g.json | 11 ++-- .../GHSA-jhv7-p7w6-pw88.json | 38 +++++++++++ .../GHSA-jmjg-j2x5-82q8.json | 38 +++++++++++ .../GHSA-jvf8-6jxw-rf4x.json | 38 +++++++++++ .../GHSA-jvv6-rqgj-96j7.json | 38 +++++++++++ .../GHSA-jwcx-68j5-jrh6.json | 38 +++++++++++ .../GHSA-jxg2-g8jw-r8cj.json | 11 ++-- .../GHSA-jxgm-wv4j-x2w3.json | 38 +++++++++++ .../GHSA-m2w9-hmqh-m77h.json | 47 ++++++++++++++ .../GHSA-m3h2-jj4m-f3r9.json | 38 +++++++++++ .../GHSA-m3m4-wgh9-w3h5.json | 11 ++-- .../GHSA-m55g-97f8-c8vx.json | 38 +++++++++++ .../GHSA-m5vv-7jxc-8p6x.json | 43 +++++++++++++ .../GHSA-m79j-g4w8-7827.json | 38 +++++++++++ .../GHSA-m8hc-32hf-2jqr.json | 38 +++++++++++ .../GHSA-mcr8-cmcm-2p3c.json | 11 ++-- .../GHSA-mh8w-gxgh-8grm.json | 39 ++++++++++++ .../GHSA-mm63-c923-gw6c.json | 47 ++++++++++++++ .../GHSA-mqv3-f225-3xw2.json | 6 +- .../GHSA-mw9x-2qwv-599p.json | 6 +- .../GHSA-mxpx-p28m-mmww.json | 38 +++++++++++ .../GHSA-p3w4-3pq3-x7jm.json | 38 +++++++++++ .../GHSA-p3xg-2r2p-7rm4.json | 47 ++++++++++++++ .../GHSA-p4hm-8mwq-2h86.json | 38 +++++++++++ .../GHSA-p4mv-gm84-6fw2.json | 38 +++++++++++ .../GHSA-p5f5-7hv4-9wpx.json | 38 +++++++++++ .../GHSA-p6r6-34c3-vr68.json | 38 +++++++++++ .../GHSA-p747-x98p-7r7q.json | 39 ++++++++++++ .../GHSA-p87g-j8m4-pq52.json | 11 ++-- .../GHSA-pf3m-7gr7-926f.json | 38 +++++++++++ .../GHSA-pfvf-x267-f8rm.json | 38 +++++++++++ .../GHSA-pjh6-pqrj-qmjf.json | 39 ++++++++++++ .../GHSA-pmrc-966v-gr3q.json | 38 +++++++++++ .../GHSA-pp55-x3vr-94gx.json | 55 ++++++++++++++++ .../GHSA-pp64-vq4m-47h3.json | 9 ++- .../GHSA-ppj4-7gjh-f85r.json | 38 +++++++++++ .../GHSA-prvm-q4qw-w4gx.json | 38 +++++++++++ .../GHSA-pvpr-32hp-969g.json | 38 +++++++++++ .../GHSA-q3q5-2v5f-27x5.json | 38 +++++++++++ .../GHSA-q4cm-g2jm-8qx9.json | 38 +++++++++++ .../GHSA-q5mh-gwp9-x87m.json | 38 +++++++++++ .../GHSA-qf34-69mr-2hfx.json | 38 +++++++++++ .../GHSA-qf6g-hc26-w8mg.json | 38 +++++++++++ .../GHSA-qfrw-x46f-qv6r.json | 38 +++++++++++ .../GHSA-qgc5-rj8x-fc6x.json | 38 +++++++++++ .../GHSA-qh3x-8m6r-29r6.json | 38 +++++++++++ .../GHSA-qh6g-wvgm-fwfg.json | 38 +++++++++++ .../GHSA-qjx8-h9wc-h7j9.json | 38 +++++++++++ .../GHSA-qm83-29c6-cf2c.json | 47 ++++++++++++++ .../GHSA-qmxp-r8m7-qpxp.json | 38 +++++++++++ .../GHSA-qq67-p454-7jfc.json | 39 ++++++++++++ .../GHSA-qqh6-573q-j4w7.json | 38 +++++++++++ .../GHSA-qr8x-vx57-f875.json | 38 +++++++++++ .../GHSA-qrvg-j482-9r53.json | 38 +++++++++++ .../GHSA-qvfj-fv3r-6gxc.json | 38 +++++++++++ .../GHSA-qxp5-vjrm-298x.json | 9 ++- .../GHSA-r2hm-v6g9-pjcm.json | 38 +++++++++++ .../GHSA-r3wj-h9cw-w763.json | 38 +++++++++++ .../GHSA-r59c-8gpj-2fqr.json | 11 ++-- .../GHSA-r6fq-j5gx-rmcc.json | 39 ++++++++++++ .../GHSA-r88f-6cwp-mh6c.json | 38 +++++++++++ .../GHSA-r9m7-7gg7-9ppr.json | 63 +++++++++++++++++++ .../GHSA-rf58-r74g-wxch.json | 38 +++++++++++ .../GHSA-rf66-cpg6-q99p.json | 39 ++++++++++++ .../GHSA-rfxg-68vv-hjqg.json | 38 +++++++++++ .../GHSA-rg5j-wjh5-jjvq.json | 38 +++++++++++ .../GHSA-rgj2-69w4-v6x7.json | 2 +- .../GHSA-rmcg-5mh4-47x7.json | 11 ++-- .../GHSA-rmvp-hjvh-xmv3.json | 38 +++++++++++ .../GHSA-rr7g-vx4c-mvhf.json | 38 +++++++++++ .../GHSA-rx3v-xhcx-x379.json | 38 +++++++++++ .../GHSA-rx57-hfr8-vvw9.json | 38 +++++++++++ .../GHSA-v24h-h5qr-mqm8.json | 11 ++-- .../GHSA-v57f-wfrq-gh7p.json | 38 +++++++++++ .../GHSA-v5fr-mh59-qcqr.json | 38 +++++++++++ .../GHSA-v6rr-j96c-5w92.json | 38 +++++++++++ .../GHSA-v74c-f2q4-m3f5.json | 38 +++++++++++ .../GHSA-v87w-5qjf-xwc5.json | 11 ++-- .../GHSA-v8mh-p5f4-xfcq.json | 38 +++++++++++ .../GHSA-v8x5-jx2w-cph3.json | 38 +++++++++++ .../GHSA-vfhj-c5g9-3c9h.json | 9 ++- .../GHSA-vfpr-487g-rfrf.json | 38 +++++++++++ .../GHSA-vggf-6chm-6r3x.json | 38 +++++++++++ .../GHSA-vgvr-f26x-4vmv.json | 38 +++++++++++ .../GHSA-vj8f-r84j-pcvr.json | 11 ++-- .../GHSA-vmhp-qx23-hrx5.json | 38 +++++++++++ .../GHSA-vqv9-vmmf-2xqf.json | 38 +++++++++++ .../GHSA-vqx8-5r3c-qh77.json | 38 +++++++++++ .../GHSA-vr6r-x4g3-mjh6.json | 38 +++++++++++ .../GHSA-vrqp-jr32-665v.json | 38 +++++++++++ .../GHSA-vwqj-2j54-46q6.json | 11 ++-- .../GHSA-vwxq-h662-6mgh.json | 38 +++++++++++ .../GHSA-w2qx-q8vr-wvvh.json | 38 +++++++++++ .../GHSA-w3xc-4v65-w7fm.json | 38 +++++++++++ .../GHSA-w3xr-946r-w34h.json | 11 ++-- .../GHSA-w4ph-h9qj-wr34.json | 38 +++++++++++ .../GHSA-w6rx-9ffq-gq99.json | 38 +++++++++++ .../GHSA-w73m-7g8j-rpvx.json | 3 +- .../GHSA-w83r-gj25-6vrc.json | 11 ++-- .../GHSA-w95f-w4vg-jw2g.json | 38 +++++++++++ .../GHSA-wch2-95xq-3vrc.json | 38 +++++++++++ .../GHSA-wcmp-8223-fqxm.json | 38 +++++++++++ .../GHSA-wfh7-4g7r-cxxq.json | 6 +- .../GHSA-wg74-2782-fg3q.json | 38 +++++++++++ .../GHSA-whhx-pr5h-v8mc.json | 38 +++++++++++ .../GHSA-wj78-hqg6-26m2.json | 38 +++++++++++ .../GHSA-wj8m-wqv6-9w99.json | 38 +++++++++++ .../GHSA-wm4w-qc6f-f7h3.json | 38 +++++++++++ .../GHSA-wm6c-245h-h448.json | 11 ++-- .../GHSA-wp26-g22c-7r5j.json | 51 +++++++++++++++ .../GHSA-wqrp-f4rh-26fr.json | 38 +++++++++++ .../GHSA-wqw7-mcpw-gfgp.json | 38 +++++++++++ .../GHSA-wr8m-prmg-jgh7.json | 38 +++++++++++ .../GHSA-wrm6-cj5m-64m9.json | 38 +++++++++++ .../GHSA-wrr4-ffgm-8pqx.json | 38 +++++++++++ .../GHSA-wrrw-gvg8-cw7v.json | 38 +++++++++++ .../GHSA-ww39-c4gp-m7pr.json | 38 +++++++++++ .../GHSA-wx56-ff7p-8j6f.json | 3 +- .../GHSA-wx59-9gp6-398v.json | 11 ++-- .../GHSA-wxxr-rfhp-3pg5.json | 38 +++++++++++ .../GHSA-x2f7-hh2h-82c7.json | 38 +++++++++++ .../GHSA-x3ch-xq4h-88x8.json | 38 +++++++++++ .../GHSA-x3h6-m99c-xwp8.json | 38 +++++++++++ .../GHSA-xfrj-fcpr-f4m8.json | 38 +++++++++++ .../GHSA-xgfv-v34v-46vm.json | 38 +++++++++++ .../GHSA-xmg5-qqq4-wfw3.json | 38 +++++++++++ .../GHSA-xmgx-2283-p55h.json | 46 ++++++++++++++ .../GHSA-xmvp-3p7r-g4vm.json | 38 +++++++++++ .../GHSA-xq44-wcjx-g3w9.json | 2 +- .../GHSA-xqj5-wxw2-5ww9.json | 38 +++++++++++ .../GHSA-xrg9-2q4w-gf5c.json | 39 ++++++++++++ .../GHSA-xvcg-crx7-qcjv.json | 39 ++++++++++++ .../GHSA-xxcq-q4px-9ggw.json | 39 ++++++++++++ 317 files changed, 10812 insertions(+), 141 deletions(-) create mode 100644 advisories/unreviewed/2024/11/GHSA-247x-jv5h-grf9/GHSA-247x-jv5h-grf9.json create mode 100644 advisories/unreviewed/2024/11/GHSA-24vh-3994-4wxm/GHSA-24vh-3994-4wxm.json create mode 100644 advisories/unreviewed/2024/11/GHSA-259q-92w6-wrgj/GHSA-259q-92w6-wrgj.json create mode 100644 advisories/unreviewed/2024/11/GHSA-276p-5gr8-q5fq/GHSA-276p-5gr8-q5fq.json create mode 100644 advisories/unreviewed/2024/11/GHSA-278c-qcm2-c4mv/GHSA-278c-qcm2-c4mv.json create mode 100644 advisories/unreviewed/2024/11/GHSA-28mj-q95m-9rc8/GHSA-28mj-q95m-9rc8.json create mode 100644 advisories/unreviewed/2024/11/GHSA-2ccf-wxp6-xgr9/GHSA-2ccf-wxp6-xgr9.json create mode 100644 advisories/unreviewed/2024/11/GHSA-2ch6-g4cg-g5ph/GHSA-2ch6-g4cg-g5ph.json create mode 100644 advisories/unreviewed/2024/11/GHSA-2jpp-f2p3-hhw9/GHSA-2jpp-f2p3-hhw9.json create mode 100644 advisories/unreviewed/2024/11/GHSA-2pgq-v89h-j58m/GHSA-2pgq-v89h-j58m.json create mode 100644 advisories/unreviewed/2024/11/GHSA-2qmr-p234-34wm/GHSA-2qmr-p234-34wm.json create mode 100644 advisories/unreviewed/2024/11/GHSA-2vrj-cvff-5p56/GHSA-2vrj-cvff-5p56.json create mode 100644 advisories/unreviewed/2024/11/GHSA-33c8-2qq8-ffcg/GHSA-33c8-2qq8-ffcg.json create mode 100644 advisories/unreviewed/2024/11/GHSA-363w-4gjr-hxxf/GHSA-363w-4gjr-hxxf.json create mode 100644 advisories/unreviewed/2024/11/GHSA-373q-7p85-gr9f/GHSA-373q-7p85-gr9f.json create mode 100644 advisories/unreviewed/2024/11/GHSA-38wf-gvg7-rrvw/GHSA-38wf-gvg7-rrvw.json create mode 100644 advisories/unreviewed/2024/11/GHSA-3gf8-c827-8cjg/GHSA-3gf8-c827-8cjg.json create mode 100644 advisories/unreviewed/2024/11/GHSA-3jp2-56w2-f943/GHSA-3jp2-56w2-f943.json create mode 100644 advisories/unreviewed/2024/11/GHSA-3mvg-wf73-6mx2/GHSA-3mvg-wf73-6mx2.json create mode 100644 advisories/unreviewed/2024/11/GHSA-3w4r-prc4-q67c/GHSA-3w4r-prc4-q67c.json create mode 100644 advisories/unreviewed/2024/11/GHSA-3w88-854j-p487/GHSA-3w88-854j-p487.json create mode 100644 advisories/unreviewed/2024/11/GHSA-3wcp-g7h4-2r32/GHSA-3wcp-g7h4-2r32.json create mode 100644 advisories/unreviewed/2024/11/GHSA-42c7-w7r7-3v3m/GHSA-42c7-w7r7-3v3m.json create mode 100644 advisories/unreviewed/2024/11/GHSA-42qw-9g84-jp2h/GHSA-42qw-9g84-jp2h.json create mode 100644 advisories/unreviewed/2024/11/GHSA-432j-87hp-h33w/GHSA-432j-87hp-h33w.json create mode 100644 advisories/unreviewed/2024/11/GHSA-43h5-8p3v-hfvv/GHSA-43h5-8p3v-hfvv.json create mode 100644 advisories/unreviewed/2024/11/GHSA-4437-j8j7-wqjr/GHSA-4437-j8j7-wqjr.json create mode 100644 advisories/unreviewed/2024/11/GHSA-4696-66c4-2gvx/GHSA-4696-66c4-2gvx.json create mode 100644 advisories/unreviewed/2024/11/GHSA-49fm-c6jx-pv73/GHSA-49fm-c6jx-pv73.json create mode 100644 advisories/unreviewed/2024/11/GHSA-4cx4-xm36-7hp9/GHSA-4cx4-xm36-7hp9.json create mode 100644 advisories/unreviewed/2024/11/GHSA-4f2j-5xcx-5g9w/GHSA-4f2j-5xcx-5g9w.json create mode 100644 advisories/unreviewed/2024/11/GHSA-4f73-836m-4mcr/GHSA-4f73-836m-4mcr.json create mode 100644 advisories/unreviewed/2024/11/GHSA-4gjx-j363-q574/GHSA-4gjx-j363-q574.json create mode 100644 advisories/unreviewed/2024/11/GHSA-4pmx-qx84-x3f4/GHSA-4pmx-qx84-x3f4.json create mode 100644 advisories/unreviewed/2024/11/GHSA-4rq4-85gc-8wf8/GHSA-4rq4-85gc-8wf8.json create mode 100644 advisories/unreviewed/2024/11/GHSA-4wrj-7475-35c2/GHSA-4wrj-7475-35c2.json create mode 100644 advisories/unreviewed/2024/11/GHSA-4xwh-jfmg-xmv5/GHSA-4xwh-jfmg-xmv5.json create mode 100644 advisories/unreviewed/2024/11/GHSA-533v-gm9h-955p/GHSA-533v-gm9h-955p.json create mode 100644 advisories/unreviewed/2024/11/GHSA-548p-gmg2-4cqq/GHSA-548p-gmg2-4cqq.json create mode 100644 advisories/unreviewed/2024/11/GHSA-54hc-gq3w-c935/GHSA-54hc-gq3w-c935.json create mode 100644 advisories/unreviewed/2024/11/GHSA-553q-p66q-xfmv/GHSA-553q-p66q-xfmv.json create mode 100644 advisories/unreviewed/2024/11/GHSA-56f7-h7m2-r62r/GHSA-56f7-h7m2-r62r.json create mode 100644 advisories/unreviewed/2024/11/GHSA-56wh-6gx4-4442/GHSA-56wh-6gx4-4442.json create mode 100644 advisories/unreviewed/2024/11/GHSA-594x-49wf-v3rp/GHSA-594x-49wf-v3rp.json create mode 100644 advisories/unreviewed/2024/11/GHSA-59r4-qr9h-8crh/GHSA-59r4-qr9h-8crh.json create mode 100644 advisories/unreviewed/2024/11/GHSA-5ggj-xwvc-9x57/GHSA-5ggj-xwvc-9x57.json create mode 100644 advisories/unreviewed/2024/11/GHSA-5m89-67rv-p8wm/GHSA-5m89-67rv-p8wm.json create mode 100644 advisories/unreviewed/2024/11/GHSA-5qr2-q8cp-vq2r/GHSA-5qr2-q8cp-vq2r.json create mode 100644 advisories/unreviewed/2024/11/GHSA-5xgh-3xqg-v5p2/GHSA-5xgh-3xqg-v5p2.json create mode 100644 advisories/unreviewed/2024/11/GHSA-65pc-phr9-277f/GHSA-65pc-phr9-277f.json create mode 100644 advisories/unreviewed/2024/11/GHSA-66w7-vgc6-vh9v/GHSA-66w7-vgc6-vh9v.json create mode 100644 advisories/unreviewed/2024/11/GHSA-67c4-pjh7-g54h/GHSA-67c4-pjh7-g54h.json create mode 100644 advisories/unreviewed/2024/11/GHSA-6999-6m26-m9xx/GHSA-6999-6m26-m9xx.json create mode 100644 advisories/unreviewed/2024/11/GHSA-69h8-v2gw-h8q9/GHSA-69h8-v2gw-h8q9.json create mode 100644 advisories/unreviewed/2024/11/GHSA-6gpv-2g95-83h9/GHSA-6gpv-2g95-83h9.json create mode 100644 advisories/unreviewed/2024/11/GHSA-6jjx-758m-9gc4/GHSA-6jjx-758m-9gc4.json create mode 100644 advisories/unreviewed/2024/11/GHSA-6jv4-h5x3-vxf3/GHSA-6jv4-h5x3-vxf3.json create mode 100644 advisories/unreviewed/2024/11/GHSA-6pj7-c745-c2mx/GHSA-6pj7-c745-c2mx.json create mode 100644 advisories/unreviewed/2024/11/GHSA-6qgf-95ch-q924/GHSA-6qgf-95ch-q924.json create mode 100644 advisories/unreviewed/2024/11/GHSA-6rh5-p63w-qc58/GHSA-6rh5-p63w-qc58.json create mode 100644 advisories/unreviewed/2024/11/GHSA-6v28-4x74-3hpj/GHSA-6v28-4x74-3hpj.json create mode 100644 advisories/unreviewed/2024/11/GHSA-6vqc-w6hm-2r5w/GHSA-6vqc-w6hm-2r5w.json create mode 100644 advisories/unreviewed/2024/11/GHSA-6w26-4vm6-c7f2/GHSA-6w26-4vm6-c7f2.json create mode 100644 advisories/unreviewed/2024/11/GHSA-7259-cwhj-xf2j/GHSA-7259-cwhj-xf2j.json create mode 100644 advisories/unreviewed/2024/11/GHSA-73c2-2543-rv69/GHSA-73c2-2543-rv69.json create mode 100644 advisories/unreviewed/2024/11/GHSA-73h5-69j6-pq7f/GHSA-73h5-69j6-pq7f.json create mode 100644 advisories/unreviewed/2024/11/GHSA-74rr-c455-62vq/GHSA-74rr-c455-62vq.json create mode 100644 advisories/unreviewed/2024/11/GHSA-75f9-w444-4xg7/GHSA-75f9-w444-4xg7.json create mode 100644 advisories/unreviewed/2024/11/GHSA-7866-w9g3-g699/GHSA-7866-w9g3-g699.json create mode 100644 advisories/unreviewed/2024/11/GHSA-78xf-x743-mmc6/GHSA-78xf-x743-mmc6.json create mode 100644 advisories/unreviewed/2024/11/GHSA-79f9-q2cg-p5x7/GHSA-79f9-q2cg-p5x7.json create mode 100644 advisories/unreviewed/2024/11/GHSA-7c65-3hqv-hvmm/GHSA-7c65-3hqv-hvmm.json create mode 100644 advisories/unreviewed/2024/11/GHSA-7ghh-hpqx-6wf8/GHSA-7ghh-hpqx-6wf8.json create mode 100644 advisories/unreviewed/2024/11/GHSA-7h32-65hg-rrp7/GHSA-7h32-65hg-rrp7.json create mode 100644 advisories/unreviewed/2024/11/GHSA-7hr9-vfjf-38m4/GHSA-7hr9-vfjf-38m4.json create mode 100644 advisories/unreviewed/2024/11/GHSA-7hwj-x2vh-jqv9/GHSA-7hwj-x2vh-jqv9.json create mode 100644 advisories/unreviewed/2024/11/GHSA-7mjf-5rrm-399r/GHSA-7mjf-5rrm-399r.json create mode 100644 advisories/unreviewed/2024/11/GHSA-7q26-9p5f-2xq5/GHSA-7q26-9p5f-2xq5.json create mode 100644 advisories/unreviewed/2024/11/GHSA-8348-jmhf-5pcj/GHSA-8348-jmhf-5pcj.json create mode 100644 advisories/unreviewed/2024/11/GHSA-84vq-r732-qrg9/GHSA-84vq-r732-qrg9.json create mode 100644 advisories/unreviewed/2024/11/GHSA-874j-2w8f-c73r/GHSA-874j-2w8f-c73r.json create mode 100644 advisories/unreviewed/2024/11/GHSA-87vp-wcxm-f9g2/GHSA-87vp-wcxm-f9g2.json create mode 100644 advisories/unreviewed/2024/11/GHSA-88vw-5p88-2p6c/GHSA-88vw-5p88-2p6c.json create mode 100644 advisories/unreviewed/2024/11/GHSA-8cp8-922f-xc53/GHSA-8cp8-922f-xc53.json create mode 100644 advisories/unreviewed/2024/11/GHSA-8cq9-rv8g-3wpg/GHSA-8cq9-rv8g-3wpg.json create mode 100644 advisories/unreviewed/2024/11/GHSA-8frm-8r9v-j76p/GHSA-8frm-8r9v-j76p.json create mode 100644 advisories/unreviewed/2024/11/GHSA-8gqp-w9h7-vrxp/GHSA-8gqp-w9h7-vrxp.json create mode 100644 advisories/unreviewed/2024/11/GHSA-8hgx-89h7-3vhm/GHSA-8hgx-89h7-3vhm.json create mode 100644 advisories/unreviewed/2024/11/GHSA-8hj6-f2qf-5rxh/GHSA-8hj6-f2qf-5rxh.json create mode 100644 advisories/unreviewed/2024/11/GHSA-8j46-pm7j-wh94/GHSA-8j46-pm7j-wh94.json create mode 100644 advisories/unreviewed/2024/11/GHSA-8qpp-hcww-69wh/GHSA-8qpp-hcww-69wh.json create mode 100644 advisories/unreviewed/2024/11/GHSA-8vv8-fmp2-x4c4/GHSA-8vv8-fmp2-x4c4.json create mode 100644 advisories/unreviewed/2024/11/GHSA-8wxp-xf8h-h599/GHSA-8wxp-xf8h-h599.json create mode 100644 advisories/unreviewed/2024/11/GHSA-8xg6-r8pq-vfwc/GHSA-8xg6-r8pq-vfwc.json create mode 100644 advisories/unreviewed/2024/11/GHSA-8xx7-6q95-5vcp/GHSA-8xx7-6q95-5vcp.json create mode 100644 advisories/unreviewed/2024/11/GHSA-97h5-gfw2-p92x/GHSA-97h5-gfw2-p92x.json create mode 100644 advisories/unreviewed/2024/11/GHSA-98fw-263x-275m/GHSA-98fw-263x-275m.json create mode 100644 advisories/unreviewed/2024/11/GHSA-9964-jv72-p792/GHSA-9964-jv72-p792.json create mode 100644 advisories/unreviewed/2024/11/GHSA-996p-gjg5-jmfx/GHSA-996p-gjg5-jmfx.json create mode 100644 advisories/unreviewed/2024/11/GHSA-99qq-7hp5-9h5x/GHSA-99qq-7hp5-9h5x.json create mode 100644 advisories/unreviewed/2024/11/GHSA-9f4h-r2c7-m6w4/GHSA-9f4h-r2c7-m6w4.json create mode 100644 advisories/unreviewed/2024/11/GHSA-9g3h-hh7f-7m88/GHSA-9g3h-hh7f-7m88.json create mode 100644 advisories/unreviewed/2024/11/GHSA-9h24-8pw7-c9p6/GHSA-9h24-8pw7-c9p6.json create mode 100644 advisories/unreviewed/2024/11/GHSA-9r3x-3x49-29r7/GHSA-9r3x-3x49-29r7.json create mode 100644 advisories/unreviewed/2024/11/GHSA-9rhr-hcff-89rc/GHSA-9rhr-hcff-89rc.json create mode 100644 advisories/unreviewed/2024/11/GHSA-9w8f-6h5p-xj5x/GHSA-9w8f-6h5p-xj5x.json create mode 100644 advisories/unreviewed/2024/11/GHSA-9wcj-qpv5-8x56/GHSA-9wcj-qpv5-8x56.json create mode 100644 advisories/unreviewed/2024/11/GHSA-9x98-cfgr-9v24/GHSA-9x98-cfgr-9v24.json create mode 100644 advisories/unreviewed/2024/11/GHSA-9xfw-pcxh-9682/GHSA-9xfw-pcxh-9682.json create mode 100644 advisories/unreviewed/2024/11/GHSA-c2hm-g5g7-h823/GHSA-c2hm-g5g7-h823.json create mode 100644 advisories/unreviewed/2024/11/GHSA-c3cr-hpjv-gv7r/GHSA-c3cr-hpjv-gv7r.json create mode 100644 advisories/unreviewed/2024/11/GHSA-c3rv-gq44-hm8f/GHSA-c3rv-gq44-hm8f.json create mode 100644 advisories/unreviewed/2024/11/GHSA-c64j-4r5h-4rmp/GHSA-c64j-4r5h-4rmp.json create mode 100644 advisories/unreviewed/2024/11/GHSA-c6vv-jw3g-77q9/GHSA-c6vv-jw3g-77q9.json create mode 100644 advisories/unreviewed/2024/11/GHSA-c95v-4jjw-2rfc/GHSA-c95v-4jjw-2rfc.json create mode 100644 advisories/unreviewed/2024/11/GHSA-c9q8-68wq-p8wf/GHSA-c9q8-68wq-p8wf.json create mode 100644 advisories/unreviewed/2024/11/GHSA-cgh6-mrm3-hqpj/GHSA-cgh6-mrm3-hqpj.json create mode 100644 advisories/unreviewed/2024/11/GHSA-chwg-hrp2-25gc/GHSA-chwg-hrp2-25gc.json create mode 100644 advisories/unreviewed/2024/11/GHSA-cp57-7c6j-pxfg/GHSA-cp57-7c6j-pxfg.json create mode 100644 advisories/unreviewed/2024/11/GHSA-cv4q-xjgm-hcp3/GHSA-cv4q-xjgm-hcp3.json create mode 100644 advisories/unreviewed/2024/11/GHSA-cvf9-v6p6-9c32/GHSA-cvf9-v6p6-9c32.json create mode 100644 advisories/unreviewed/2024/11/GHSA-cw9g-65q4-rpvj/GHSA-cw9g-65q4-rpvj.json create mode 100644 advisories/unreviewed/2024/11/GHSA-cwqh-jjqr-q2hf/GHSA-cwqh-jjqr-q2hf.json create mode 100644 advisories/unreviewed/2024/11/GHSA-f2hp-wgc9-mcvf/GHSA-f2hp-wgc9-mcvf.json create mode 100644 advisories/unreviewed/2024/11/GHSA-f6c2-ph4p-hmh6/GHSA-f6c2-ph4p-hmh6.json create mode 100644 advisories/unreviewed/2024/11/GHSA-f76r-8x77-pwm4/GHSA-f76r-8x77-pwm4.json create mode 100644 advisories/unreviewed/2024/11/GHSA-fc6c-wh46-2q9r/GHSA-fc6c-wh46-2q9r.json create mode 100644 advisories/unreviewed/2024/11/GHSA-fhmx-7jhg-8h34/GHSA-fhmx-7jhg-8h34.json create mode 100644 advisories/unreviewed/2024/11/GHSA-fmfg-pggg-vmwc/GHSA-fmfg-pggg-vmwc.json create mode 100644 advisories/unreviewed/2024/11/GHSA-fp2v-7r4c-j6p5/GHSA-fp2v-7r4c-j6p5.json create mode 100644 advisories/unreviewed/2024/11/GHSA-fw3x-9gjw-x3mg/GHSA-fw3x-9gjw-x3mg.json create mode 100644 advisories/unreviewed/2024/11/GHSA-fw47-6v57-fjcf/GHSA-fw47-6v57-fjcf.json create mode 100644 advisories/unreviewed/2024/11/GHSA-fx99-8m8g-rfwx/GHSA-fx99-8m8g-rfwx.json create mode 100644 advisories/unreviewed/2024/11/GHSA-g4gg-7gqp-cf6m/GHSA-g4gg-7gqp-cf6m.json create mode 100644 advisories/unreviewed/2024/11/GHSA-g63v-c4x5-2g6v/GHSA-g63v-c4x5-2g6v.json create mode 100644 advisories/unreviewed/2024/11/GHSA-g76f-r4m8-gr75/GHSA-g76f-r4m8-gr75.json create mode 100644 advisories/unreviewed/2024/11/GHSA-g77r-mcw3-wcx8/GHSA-g77r-mcw3-wcx8.json create mode 100644 advisories/unreviewed/2024/11/GHSA-ggmg-vvg8-55m2/GHSA-ggmg-vvg8-55m2.json create mode 100644 advisories/unreviewed/2024/11/GHSA-gh8c-2875-38xv/GHSA-gh8c-2875-38xv.json create mode 100644 advisories/unreviewed/2024/11/GHSA-gm4p-xxcw-q3xf/GHSA-gm4p-xxcw-q3xf.json create mode 100644 advisories/unreviewed/2024/11/GHSA-gpf9-2frf-hch3/GHSA-gpf9-2frf-hch3.json create mode 100644 advisories/unreviewed/2024/11/GHSA-gpvr-4p58-r896/GHSA-gpvr-4p58-r896.json create mode 100644 advisories/unreviewed/2024/11/GHSA-gr9q-mvmm-jr7v/GHSA-gr9q-mvmm-jr7v.json create mode 100644 advisories/unreviewed/2024/11/GHSA-gv5x-w6m9-qv2v/GHSA-gv5x-w6m9-qv2v.json create mode 100644 advisories/unreviewed/2024/11/GHSA-h29g-hxg6-g48j/GHSA-h29g-hxg6-g48j.json create mode 100644 advisories/unreviewed/2024/11/GHSA-h2fw-j3h2-4fh6/GHSA-h2fw-j3h2-4fh6.json create mode 100644 advisories/unreviewed/2024/11/GHSA-h7jr-f9m2-rr37/GHSA-h7jr-f9m2-rr37.json create mode 100644 advisories/unreviewed/2024/11/GHSA-h9vw-x7c8-cqgm/GHSA-h9vw-x7c8-cqgm.json create mode 100644 advisories/unreviewed/2024/11/GHSA-hf57-pc64-3428/GHSA-hf57-pc64-3428.json create mode 100644 advisories/unreviewed/2024/11/GHSA-hfwx-j6h2-rmf7/GHSA-hfwx-j6h2-rmf7.json create mode 100644 advisories/unreviewed/2024/11/GHSA-hh3g-4c3h-9xq5/GHSA-hh3g-4c3h-9xq5.json create mode 100644 advisories/unreviewed/2024/11/GHSA-hjf4-jrvv-979w/GHSA-hjf4-jrvv-979w.json create mode 100644 advisories/unreviewed/2024/11/GHSA-hp9m-99c7-gwmq/GHSA-hp9m-99c7-gwmq.json create mode 100644 advisories/unreviewed/2024/11/GHSA-hvf6-4mg8-8mgf/GHSA-hvf6-4mg8-8mgf.json create mode 100644 advisories/unreviewed/2024/11/GHSA-j2fh-p4jc-3h97/GHSA-j2fh-p4jc-3h97.json create mode 100644 advisories/unreviewed/2024/11/GHSA-j5vh-vfg7-3v94/GHSA-j5vh-vfg7-3v94.json create mode 100644 advisories/unreviewed/2024/11/GHSA-j68m-vr9h-7553/GHSA-j68m-vr9h-7553.json create mode 100644 advisories/unreviewed/2024/11/GHSA-j6m7-43jh-w34q/GHSA-j6m7-43jh-w34q.json create mode 100644 advisories/unreviewed/2024/11/GHSA-j6x9-wwrp-prcf/GHSA-j6x9-wwrp-prcf.json create mode 100644 advisories/unreviewed/2024/11/GHSA-jfgv-5f9v-whcx/GHSA-jfgv-5f9v-whcx.json create mode 100644 advisories/unreviewed/2024/11/GHSA-jhv7-p7w6-pw88/GHSA-jhv7-p7w6-pw88.json create mode 100644 advisories/unreviewed/2024/11/GHSA-jmjg-j2x5-82q8/GHSA-jmjg-j2x5-82q8.json create mode 100644 advisories/unreviewed/2024/11/GHSA-jvf8-6jxw-rf4x/GHSA-jvf8-6jxw-rf4x.json create mode 100644 advisories/unreviewed/2024/11/GHSA-jvv6-rqgj-96j7/GHSA-jvv6-rqgj-96j7.json create mode 100644 advisories/unreviewed/2024/11/GHSA-jwcx-68j5-jrh6/GHSA-jwcx-68j5-jrh6.json create mode 100644 advisories/unreviewed/2024/11/GHSA-jxgm-wv4j-x2w3/GHSA-jxgm-wv4j-x2w3.json create mode 100644 advisories/unreviewed/2024/11/GHSA-m2w9-hmqh-m77h/GHSA-m2w9-hmqh-m77h.json create mode 100644 advisories/unreviewed/2024/11/GHSA-m3h2-jj4m-f3r9/GHSA-m3h2-jj4m-f3r9.json create mode 100644 advisories/unreviewed/2024/11/GHSA-m55g-97f8-c8vx/GHSA-m55g-97f8-c8vx.json create mode 100644 advisories/unreviewed/2024/11/GHSA-m5vv-7jxc-8p6x/GHSA-m5vv-7jxc-8p6x.json create mode 100644 advisories/unreviewed/2024/11/GHSA-m79j-g4w8-7827/GHSA-m79j-g4w8-7827.json create mode 100644 advisories/unreviewed/2024/11/GHSA-m8hc-32hf-2jqr/GHSA-m8hc-32hf-2jqr.json create mode 100644 advisories/unreviewed/2024/11/GHSA-mh8w-gxgh-8grm/GHSA-mh8w-gxgh-8grm.json create mode 100644 advisories/unreviewed/2024/11/GHSA-mm63-c923-gw6c/GHSA-mm63-c923-gw6c.json create mode 100644 advisories/unreviewed/2024/11/GHSA-mxpx-p28m-mmww/GHSA-mxpx-p28m-mmww.json create mode 100644 advisories/unreviewed/2024/11/GHSA-p3w4-3pq3-x7jm/GHSA-p3w4-3pq3-x7jm.json create mode 100644 advisories/unreviewed/2024/11/GHSA-p3xg-2r2p-7rm4/GHSA-p3xg-2r2p-7rm4.json create mode 100644 advisories/unreviewed/2024/11/GHSA-p4hm-8mwq-2h86/GHSA-p4hm-8mwq-2h86.json create mode 100644 advisories/unreviewed/2024/11/GHSA-p4mv-gm84-6fw2/GHSA-p4mv-gm84-6fw2.json create mode 100644 advisories/unreviewed/2024/11/GHSA-p5f5-7hv4-9wpx/GHSA-p5f5-7hv4-9wpx.json create mode 100644 advisories/unreviewed/2024/11/GHSA-p6r6-34c3-vr68/GHSA-p6r6-34c3-vr68.json create mode 100644 advisories/unreviewed/2024/11/GHSA-p747-x98p-7r7q/GHSA-p747-x98p-7r7q.json create mode 100644 advisories/unreviewed/2024/11/GHSA-pf3m-7gr7-926f/GHSA-pf3m-7gr7-926f.json create mode 100644 advisories/unreviewed/2024/11/GHSA-pfvf-x267-f8rm/GHSA-pfvf-x267-f8rm.json create mode 100644 advisories/unreviewed/2024/11/GHSA-pjh6-pqrj-qmjf/GHSA-pjh6-pqrj-qmjf.json create mode 100644 advisories/unreviewed/2024/11/GHSA-pmrc-966v-gr3q/GHSA-pmrc-966v-gr3q.json create mode 100644 advisories/unreviewed/2024/11/GHSA-pp55-x3vr-94gx/GHSA-pp55-x3vr-94gx.json create mode 100644 advisories/unreviewed/2024/11/GHSA-ppj4-7gjh-f85r/GHSA-ppj4-7gjh-f85r.json create mode 100644 advisories/unreviewed/2024/11/GHSA-prvm-q4qw-w4gx/GHSA-prvm-q4qw-w4gx.json create mode 100644 advisories/unreviewed/2024/11/GHSA-pvpr-32hp-969g/GHSA-pvpr-32hp-969g.json create mode 100644 advisories/unreviewed/2024/11/GHSA-q3q5-2v5f-27x5/GHSA-q3q5-2v5f-27x5.json create mode 100644 advisories/unreviewed/2024/11/GHSA-q4cm-g2jm-8qx9/GHSA-q4cm-g2jm-8qx9.json create mode 100644 advisories/unreviewed/2024/11/GHSA-q5mh-gwp9-x87m/GHSA-q5mh-gwp9-x87m.json create mode 100644 advisories/unreviewed/2024/11/GHSA-qf34-69mr-2hfx/GHSA-qf34-69mr-2hfx.json create mode 100644 advisories/unreviewed/2024/11/GHSA-qf6g-hc26-w8mg/GHSA-qf6g-hc26-w8mg.json create mode 100644 advisories/unreviewed/2024/11/GHSA-qfrw-x46f-qv6r/GHSA-qfrw-x46f-qv6r.json create mode 100644 advisories/unreviewed/2024/11/GHSA-qgc5-rj8x-fc6x/GHSA-qgc5-rj8x-fc6x.json create mode 100644 advisories/unreviewed/2024/11/GHSA-qh3x-8m6r-29r6/GHSA-qh3x-8m6r-29r6.json create mode 100644 advisories/unreviewed/2024/11/GHSA-qh6g-wvgm-fwfg/GHSA-qh6g-wvgm-fwfg.json create mode 100644 advisories/unreviewed/2024/11/GHSA-qjx8-h9wc-h7j9/GHSA-qjx8-h9wc-h7j9.json create mode 100644 advisories/unreviewed/2024/11/GHSA-qm83-29c6-cf2c/GHSA-qm83-29c6-cf2c.json create mode 100644 advisories/unreviewed/2024/11/GHSA-qmxp-r8m7-qpxp/GHSA-qmxp-r8m7-qpxp.json create mode 100644 advisories/unreviewed/2024/11/GHSA-qq67-p454-7jfc/GHSA-qq67-p454-7jfc.json create mode 100644 advisories/unreviewed/2024/11/GHSA-qqh6-573q-j4w7/GHSA-qqh6-573q-j4w7.json create mode 100644 advisories/unreviewed/2024/11/GHSA-qr8x-vx57-f875/GHSA-qr8x-vx57-f875.json create mode 100644 advisories/unreviewed/2024/11/GHSA-qrvg-j482-9r53/GHSA-qrvg-j482-9r53.json create mode 100644 advisories/unreviewed/2024/11/GHSA-qvfj-fv3r-6gxc/GHSA-qvfj-fv3r-6gxc.json create mode 100644 advisories/unreviewed/2024/11/GHSA-r2hm-v6g9-pjcm/GHSA-r2hm-v6g9-pjcm.json create mode 100644 advisories/unreviewed/2024/11/GHSA-r3wj-h9cw-w763/GHSA-r3wj-h9cw-w763.json create mode 100644 advisories/unreviewed/2024/11/GHSA-r6fq-j5gx-rmcc/GHSA-r6fq-j5gx-rmcc.json create mode 100644 advisories/unreviewed/2024/11/GHSA-r88f-6cwp-mh6c/GHSA-r88f-6cwp-mh6c.json create mode 100644 advisories/unreviewed/2024/11/GHSA-r9m7-7gg7-9ppr/GHSA-r9m7-7gg7-9ppr.json create mode 100644 advisories/unreviewed/2024/11/GHSA-rf58-r74g-wxch/GHSA-rf58-r74g-wxch.json create mode 100644 advisories/unreviewed/2024/11/GHSA-rf66-cpg6-q99p/GHSA-rf66-cpg6-q99p.json create mode 100644 advisories/unreviewed/2024/11/GHSA-rfxg-68vv-hjqg/GHSA-rfxg-68vv-hjqg.json create mode 100644 advisories/unreviewed/2024/11/GHSA-rg5j-wjh5-jjvq/GHSA-rg5j-wjh5-jjvq.json create mode 100644 advisories/unreviewed/2024/11/GHSA-rmvp-hjvh-xmv3/GHSA-rmvp-hjvh-xmv3.json create mode 100644 advisories/unreviewed/2024/11/GHSA-rr7g-vx4c-mvhf/GHSA-rr7g-vx4c-mvhf.json create mode 100644 advisories/unreviewed/2024/11/GHSA-rx3v-xhcx-x379/GHSA-rx3v-xhcx-x379.json create mode 100644 advisories/unreviewed/2024/11/GHSA-rx57-hfr8-vvw9/GHSA-rx57-hfr8-vvw9.json create mode 100644 advisories/unreviewed/2024/11/GHSA-v57f-wfrq-gh7p/GHSA-v57f-wfrq-gh7p.json create mode 100644 advisories/unreviewed/2024/11/GHSA-v5fr-mh59-qcqr/GHSA-v5fr-mh59-qcqr.json create mode 100644 advisories/unreviewed/2024/11/GHSA-v6rr-j96c-5w92/GHSA-v6rr-j96c-5w92.json create mode 100644 advisories/unreviewed/2024/11/GHSA-v74c-f2q4-m3f5/GHSA-v74c-f2q4-m3f5.json create mode 100644 advisories/unreviewed/2024/11/GHSA-v8mh-p5f4-xfcq/GHSA-v8mh-p5f4-xfcq.json create mode 100644 advisories/unreviewed/2024/11/GHSA-v8x5-jx2w-cph3/GHSA-v8x5-jx2w-cph3.json create mode 100644 advisories/unreviewed/2024/11/GHSA-vfpr-487g-rfrf/GHSA-vfpr-487g-rfrf.json create mode 100644 advisories/unreviewed/2024/11/GHSA-vggf-6chm-6r3x/GHSA-vggf-6chm-6r3x.json create mode 100644 advisories/unreviewed/2024/11/GHSA-vgvr-f26x-4vmv/GHSA-vgvr-f26x-4vmv.json create mode 100644 advisories/unreviewed/2024/11/GHSA-vmhp-qx23-hrx5/GHSA-vmhp-qx23-hrx5.json create mode 100644 advisories/unreviewed/2024/11/GHSA-vqv9-vmmf-2xqf/GHSA-vqv9-vmmf-2xqf.json create mode 100644 advisories/unreviewed/2024/11/GHSA-vqx8-5r3c-qh77/GHSA-vqx8-5r3c-qh77.json create mode 100644 advisories/unreviewed/2024/11/GHSA-vr6r-x4g3-mjh6/GHSA-vr6r-x4g3-mjh6.json create mode 100644 advisories/unreviewed/2024/11/GHSA-vrqp-jr32-665v/GHSA-vrqp-jr32-665v.json create mode 100644 advisories/unreviewed/2024/11/GHSA-vwxq-h662-6mgh/GHSA-vwxq-h662-6mgh.json create mode 100644 advisories/unreviewed/2024/11/GHSA-w2qx-q8vr-wvvh/GHSA-w2qx-q8vr-wvvh.json create mode 100644 advisories/unreviewed/2024/11/GHSA-w3xc-4v65-w7fm/GHSA-w3xc-4v65-w7fm.json create mode 100644 advisories/unreviewed/2024/11/GHSA-w4ph-h9qj-wr34/GHSA-w4ph-h9qj-wr34.json create mode 100644 advisories/unreviewed/2024/11/GHSA-w6rx-9ffq-gq99/GHSA-w6rx-9ffq-gq99.json create mode 100644 advisories/unreviewed/2024/11/GHSA-w95f-w4vg-jw2g/GHSA-w95f-w4vg-jw2g.json create mode 100644 advisories/unreviewed/2024/11/GHSA-wch2-95xq-3vrc/GHSA-wch2-95xq-3vrc.json create mode 100644 advisories/unreviewed/2024/11/GHSA-wcmp-8223-fqxm/GHSA-wcmp-8223-fqxm.json create mode 100644 advisories/unreviewed/2024/11/GHSA-wg74-2782-fg3q/GHSA-wg74-2782-fg3q.json create mode 100644 advisories/unreviewed/2024/11/GHSA-whhx-pr5h-v8mc/GHSA-whhx-pr5h-v8mc.json create mode 100644 advisories/unreviewed/2024/11/GHSA-wj78-hqg6-26m2/GHSA-wj78-hqg6-26m2.json create mode 100644 advisories/unreviewed/2024/11/GHSA-wj8m-wqv6-9w99/GHSA-wj8m-wqv6-9w99.json create mode 100644 advisories/unreviewed/2024/11/GHSA-wm4w-qc6f-f7h3/GHSA-wm4w-qc6f-f7h3.json create mode 100644 advisories/unreviewed/2024/11/GHSA-wp26-g22c-7r5j/GHSA-wp26-g22c-7r5j.json create mode 100644 advisories/unreviewed/2024/11/GHSA-wqrp-f4rh-26fr/GHSA-wqrp-f4rh-26fr.json create mode 100644 advisories/unreviewed/2024/11/GHSA-wqw7-mcpw-gfgp/GHSA-wqw7-mcpw-gfgp.json create mode 100644 advisories/unreviewed/2024/11/GHSA-wr8m-prmg-jgh7/GHSA-wr8m-prmg-jgh7.json create mode 100644 advisories/unreviewed/2024/11/GHSA-wrm6-cj5m-64m9/GHSA-wrm6-cj5m-64m9.json create mode 100644 advisories/unreviewed/2024/11/GHSA-wrr4-ffgm-8pqx/GHSA-wrr4-ffgm-8pqx.json create mode 100644 advisories/unreviewed/2024/11/GHSA-wrrw-gvg8-cw7v/GHSA-wrrw-gvg8-cw7v.json create mode 100644 advisories/unreviewed/2024/11/GHSA-ww39-c4gp-m7pr/GHSA-ww39-c4gp-m7pr.json create mode 100644 advisories/unreviewed/2024/11/GHSA-wxxr-rfhp-3pg5/GHSA-wxxr-rfhp-3pg5.json create mode 100644 advisories/unreviewed/2024/11/GHSA-x2f7-hh2h-82c7/GHSA-x2f7-hh2h-82c7.json create mode 100644 advisories/unreviewed/2024/11/GHSA-x3ch-xq4h-88x8/GHSA-x3ch-xq4h-88x8.json create mode 100644 advisories/unreviewed/2024/11/GHSA-x3h6-m99c-xwp8/GHSA-x3h6-m99c-xwp8.json create mode 100644 advisories/unreviewed/2024/11/GHSA-xfrj-fcpr-f4m8/GHSA-xfrj-fcpr-f4m8.json create mode 100644 advisories/unreviewed/2024/11/GHSA-xgfv-v34v-46vm/GHSA-xgfv-v34v-46vm.json create mode 100644 advisories/unreviewed/2024/11/GHSA-xmg5-qqq4-wfw3/GHSA-xmg5-qqq4-wfw3.json create mode 100644 advisories/unreviewed/2024/11/GHSA-xmgx-2283-p55h/GHSA-xmgx-2283-p55h.json create mode 100644 advisories/unreviewed/2024/11/GHSA-xmvp-3p7r-g4vm/GHSA-xmvp-3p7r-g4vm.json create mode 100644 advisories/unreviewed/2024/11/GHSA-xqj5-wxw2-5ww9/GHSA-xqj5-wxw2-5ww9.json create mode 100644 advisories/unreviewed/2024/11/GHSA-xrg9-2q4w-gf5c/GHSA-xrg9-2q4w-gf5c.json create mode 100644 advisories/unreviewed/2024/11/GHSA-xvcg-crx7-qcjv/GHSA-xvcg-crx7-qcjv.json create mode 100644 advisories/unreviewed/2024/11/GHSA-xxcq-q4px-9ggw/GHSA-xxcq-q4px-9ggw.json diff --git a/advisories/unreviewed/2024/02/GHSA-9j55-g998-6v4p/GHSA-9j55-g998-6v4p.json b/advisories/unreviewed/2024/02/GHSA-9j55-g998-6v4p/GHSA-9j55-g998-6v4p.json index 41cee70b328..c604fe29af5 100644 --- a/advisories/unreviewed/2024/02/GHSA-9j55-g998-6v4p/GHSA-9j55-g998-6v4p.json +++ b/advisories/unreviewed/2024/02/GHSA-9j55-g998-6v4p/GHSA-9j55-g998-6v4p.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-225p-gh6f-c6xc/GHSA-225p-gh6f-c6xc.json b/advisories/unreviewed/2024/11/GHSA-225p-gh6f-c6xc/GHSA-225p-gh6f-c6xc.json index 371983a8c05..76931d5fe8b 100644 --- a/advisories/unreviewed/2024/11/GHSA-225p-gh6f-c6xc/GHSA-225p-gh6f-c6xc.json +++ b/advisories/unreviewed/2024/11/GHSA-225p-gh6f-c6xc/GHSA-225p-gh6f-c6xc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-225p-gh6f-c6xc", - "modified": "2024-11-13T18:32:04Z", + "modified": "2024-11-19T18:30:55Z", "published": "2024-11-13T18:32:04Z", "aliases": [ "CVE-2023-35686" ], "details": "In PVRSRVRGXKickTA3DKM of rgxta3d.c, there is a possible arbitrary code execution due to improper input validation. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-13T18:15:19Z" diff --git a/advisories/unreviewed/2024/11/GHSA-236f-m6gm-vp93/GHSA-236f-m6gm-vp93.json b/advisories/unreviewed/2024/11/GHSA-236f-m6gm-vp93/GHSA-236f-m6gm-vp93.json index 18ce3b9a21a..25f432f6e64 100644 --- a/advisories/unreviewed/2024/11/GHSA-236f-m6gm-vp93/GHSA-236f-m6gm-vp93.json +++ b/advisories/unreviewed/2024/11/GHSA-236f-m6gm-vp93/GHSA-236f-m6gm-vp93.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-247x-jv5h-grf9/GHSA-247x-jv5h-grf9.json b/advisories/unreviewed/2024/11/GHSA-247x-jv5h-grf9/GHSA-247x-jv5h-grf9.json new file mode 100644 index 00000000000..57b40e1b024 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-247x-jv5h-grf9/GHSA-247x-jv5h-grf9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-247x-jv5h-grf9", + "modified": "2024-11-19T18:31:04Z", + "published": "2024-11-19T18:31:04Z", + "aliases": [ + "CVE-2024-51872" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Luzuk Luzuk Testimonials allows Stored XSS.This issue affects Luzuk Testimonials: from n/a through 0.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51872" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/luzuk-testimonials/wordpress-luzuk-testimonials-plugin-0-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-24vh-3994-4wxm/GHSA-24vh-3994-4wxm.json b/advisories/unreviewed/2024/11/GHSA-24vh-3994-4wxm/GHSA-24vh-3994-4wxm.json new file mode 100644 index 00000000000..fee63e899cb --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-24vh-3994-4wxm/GHSA-24vh-3994-4wxm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-24vh-3994-4wxm", + "modified": "2024-11-19T18:31:02Z", + "published": "2024-11-19T18:31:02Z", + "aliases": [ + "CVE-2024-51653" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Mario Spinaci UPDATE NOTIFICATIONS allows Stored XSS.This issue affects UPDATE NOTIFICATIONS: from n/a through 0.3.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51653" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/update-notifications/wordpress-update-notifications-plugin-0-3-4-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-259q-92w6-wrgj/GHSA-259q-92w6-wrgj.json b/advisories/unreviewed/2024/11/GHSA-259q-92w6-wrgj/GHSA-259q-92w6-wrgj.json new file mode 100644 index 00000000000..d425e32f444 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-259q-92w6-wrgj/GHSA-259q-92w6-wrgj.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-259q-92w6-wrgj", + "modified": "2024-11-19T18:31:06Z", + "published": "2024-11-19T18:31:06Z", + "aliases": [ + "CVE-2024-50304" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: ip_tunnel: Fix suspicious RCU usage warning in ip_tunnel_find()\n\nThe per-netns IP tunnel hash table is protected by the RTNL mutex and\nip_tunnel_find() is only called from the control path where the mutex is\ntaken.\n\nAdd a lockdep expression to hlist_for_each_entry_rcu() in\nip_tunnel_find() in order to validate that the mutex is held and to\nsilence the suspicious RCU usage warning [1].\n\n[1]\nWARNING: suspicious RCU usage\n6.12.0-rc3-custom-gd95d9a31aceb #139 Not tainted\n-----------------------------\nnet/ipv4/ip_tunnel.c:221 RCU-list traversed in non-reader section!!\n\nother info that might help us debug this:\n\nrcu_scheduler_active = 2, debug_locks = 1\n1 lock held by ip/362:\n #0: ffffffff86fc7cb0 (rtnl_mutex){+.+.}-{3:3}, at: rtnetlink_rcv_msg+0x377/0xf60\n\nstack backtrace:\nCPU: 12 UID: 0 PID: 362 Comm: ip Not tainted 6.12.0-rc3-custom-gd95d9a31aceb #139\nHardware name: Bochs Bochs, BIOS Bochs 01/01/2011\nCall Trace:\n \n dump_stack_lvl+0xba/0x110\n lockdep_rcu_suspicious.cold+0x4f/0xd6\n ip_tunnel_find+0x435/0x4d0\n ip_tunnel_newlink+0x517/0x7a0\n ipgre_newlink+0x14c/0x170\n __rtnl_newlink+0x1173/0x19c0\n rtnl_newlink+0x6c/0xa0\n rtnetlink_rcv_msg+0x3cc/0xf60\n netlink_rcv_skb+0x171/0x450\n netlink_unicast+0x539/0x7f0\n netlink_sendmsg+0x8c1/0xd80\n ____sys_sendmsg+0x8f9/0xc20\n ___sys_sendmsg+0x197/0x1e0\n __sys_sendmsg+0x122/0x1f0\n do_syscall_64+0xbb/0x1d0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50304" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/90e0569dd3d32f4f4d2ca691d3fa5a8a14a13c12" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f20fe2cfe06ca1b008b09da4f2b4e0c5547ccef6" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-263m-wcmp-r5j6/GHSA-263m-wcmp-r5j6.json b/advisories/unreviewed/2024/11/GHSA-263m-wcmp-r5j6/GHSA-263m-wcmp-r5j6.json index 55145cfac79..840a6fcb8a1 100644 --- a/advisories/unreviewed/2024/11/GHSA-263m-wcmp-r5j6/GHSA-263m-wcmp-r5j6.json +++ b/advisories/unreviewed/2024/11/GHSA-263m-wcmp-r5j6/GHSA-263m-wcmp-r5j6.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-263m-wcmp-r5j6", - "modified": "2024-11-14T21:32:03Z", + "modified": "2024-11-19T18:30:55Z", "published": "2024-11-14T21:32:03Z", "aliases": [ "CVE-2024-10394" ], "details": "A local user can bypass the OpenAFS PAG (Process Authentication Group)\nthrottling mechanism in Unix clients, allowing the user to create a PAG using\nan existing id number, effectively joining the PAG and letting the user steal\nthe credentials in that PAG.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/11/GHSA-276p-5gr8-q5fq/GHSA-276p-5gr8-q5fq.json b/advisories/unreviewed/2024/11/GHSA-276p-5gr8-q5fq/GHSA-276p-5gr8-q5fq.json new file mode 100644 index 00000000000..dfb60bd7a7d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-276p-5gr8-q5fq/GHSA-276p-5gr8-q5fq.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-276p-5gr8-q5fq", + "modified": "2024-11-19T18:31:06Z", + "published": "2024-11-19T18:31:06Z", + "aliases": [ + "CVE-2024-53047" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: init: protect sched with rcu_read_lock\n\nEnabling CONFIG_PROVE_RCU_LIST with its dependence CONFIG_RCU_EXPERT\ncreates this splat when an MPTCP socket is created:\n\n =============================\n WARNING: suspicious RCU usage\n 6.12.0-rc2+ #11 Not tainted\n -----------------------------\n net/mptcp/sched.c:44 RCU-list traversed in non-reader section!!\n\n other info that might help us debug this:\n\n rcu_scheduler_active = 2, debug_locks = 1\n no locks held by mptcp_connect/176.\n\n stack backtrace:\n CPU: 0 UID: 0 PID: 176 Comm: mptcp_connect Not tainted 6.12.0-rc2+ #11\n Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011\n Call Trace:\n \n dump_stack_lvl (lib/dump_stack.c:123)\n lockdep_rcu_suspicious (kernel/locking/lockdep.c:6822)\n mptcp_sched_find (net/mptcp/sched.c:44 (discriminator 7))\n mptcp_init_sock (net/mptcp/protocol.c:2867 (discriminator 1))\n ? sock_init_data_uid (arch/x86/include/asm/atomic.h:28)\n inet_create.part.0.constprop.0 (net/ipv4/af_inet.c:386)\n ? __sock_create (include/linux/rcupdate.h:347 (discriminator 1))\n __sock_create (net/socket.c:1576)\n __sys_socket (net/socket.c:1671)\n ? __pfx___sys_socket (net/socket.c:1712)\n ? do_user_addr_fault (arch/x86/mm/fault.c:1419 (discriminator 1))\n __x64_sys_socket (net/socket.c:1728)\n do_syscall_64 (arch/x86/entry/common.c:52 (discriminator 1))\n entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130)\n\nThat's because when the socket is initialised, rcu_read_lock() is not\nused despite the explicit comment written above the declaration of\nmptcp_sched_find() in sched.c. Adding the missing lock/unlock avoids the\nwarning.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53047" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3deb12c788c385e17142ce6ec50f769852fcec65" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/494eb22f9a7bd03783e60595a57611c209175f1a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cb8b81ad3e893a6d18dcdd3754cc2ea2a42c0136" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-278c-qcm2-c4mv/GHSA-278c-qcm2-c4mv.json b/advisories/unreviewed/2024/11/GHSA-278c-qcm2-c4mv/GHSA-278c-qcm2-c4mv.json new file mode 100644 index 00000000000..10cbb35ccd0 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-278c-qcm2-c4mv/GHSA-278c-qcm2-c4mv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-278c-qcm2-c4mv", + "modified": "2024-11-19T18:31:04Z", + "published": "2024-11-19T18:31:04Z", + "aliases": [ + "CVE-2024-51886" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Takashi Matsuyama Posts Filter allows Stored XSS.This issue affects Posts Filter: from n/a through 1.3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51886" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/posts-filter/wordpress-posts-filter-plugin-1-3-1-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-28mj-q95m-9rc8/GHSA-28mj-q95m-9rc8.json b/advisories/unreviewed/2024/11/GHSA-28mj-q95m-9rc8/GHSA-28mj-q95m-9rc8.json new file mode 100644 index 00000000000..5e3656ea887 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-28mj-q95m-9rc8/GHSA-28mj-q95m-9rc8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-28mj-q95m-9rc8", + "modified": "2024-11-19T18:31:05Z", + "published": "2024-11-19T18:31:05Z", + "aliases": [ + "CVE-2024-51928" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jakir Hasan Blocks Post Grid allows DOM-Based XSS.This issue affects Blocks Post Grid: from n/a through 1.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51928" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/blocks-post-grid/wordpress-blocks-post-grid-plugin-1-0-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-2ccf-wxp6-xgr9/GHSA-2ccf-wxp6-xgr9.json b/advisories/unreviewed/2024/11/GHSA-2ccf-wxp6-xgr9/GHSA-2ccf-wxp6-xgr9.json new file mode 100644 index 00000000000..51f28404624 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-2ccf-wxp6-xgr9/GHSA-2ccf-wxp6-xgr9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2ccf-wxp6-xgr9", + "modified": "2024-11-19T18:31:01Z", + "published": "2024-11-19T18:31:01Z", + "aliases": [ + "CVE-2024-50556" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MD. Mamunur Roshid WM Zoom allows DOM-Based XSS.This issue affects WM Zoom: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50556" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wm-zoom/wordpress-wm-zoom-plugin-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-2ch6-g4cg-g5ph/GHSA-2ch6-g4cg-g5ph.json b/advisories/unreviewed/2024/11/GHSA-2ch6-g4cg-g5ph/GHSA-2ch6-g4cg-g5ph.json new file mode 100644 index 00000000000..cdb0d5f7d85 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-2ch6-g4cg-g5ph/GHSA-2ch6-g4cg-g5ph.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2ch6-g4cg-g5ph", + "modified": "2024-11-19T18:31:02Z", + "published": "2024-11-19T18:31:02Z", + "aliases": [ + "CVE-2024-51795" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ByteLabX Pdf Embedder Fay allows DOM-Based XSS.This issue affects Pdf Embedder Fay: from n/a through 1.10.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51795" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/pdf-embedder-fay/wordpress-pdf-embedder-fay-plugin-1-10-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-2jpp-f2p3-hhw9/GHSA-2jpp-f2p3-hhw9.json b/advisories/unreviewed/2024/11/GHSA-2jpp-f2p3-hhw9/GHSA-2jpp-f2p3-hhw9.json new file mode 100644 index 00000000000..668f4176c49 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-2jpp-f2p3-hhw9/GHSA-2jpp-f2p3-hhw9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2jpp-f2p3-hhw9", + "modified": "2024-11-19T18:31:03Z", + "published": "2024-11-19T18:31:03Z", + "aliases": [ + "CVE-2024-51850" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bchristopeit WoW Guild Armory Roster allows Stored XSS.This issue affects WoW Guild Armory Roster: from n/a through 0.5.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51850" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/guild-armory-roster/wordpress-wow-guild-armory-roster-plugin-0-5-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-2pgq-v89h-j58m/GHSA-2pgq-v89h-j58m.json b/advisories/unreviewed/2024/11/GHSA-2pgq-v89h-j58m/GHSA-2pgq-v89h-j58m.json new file mode 100644 index 00000000000..543c2b4e25e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-2pgq-v89h-j58m/GHSA-2pgq-v89h-j58m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2pgq-v89h-j58m", + "modified": "2024-11-19T18:31:01Z", + "published": "2024-11-19T18:31:01Z", + "aliases": [ + "CVE-2024-51632" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Sam Hoe SH Slideshow allows Stored XSS.This issue affects SH Slideshow: from n/a through 4.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51632" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/sh-slideshow/wordpress-sh-slideshow-plugin-4-3-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-2qmr-p234-34wm/GHSA-2qmr-p234-34wm.json b/advisories/unreviewed/2024/11/GHSA-2qmr-p234-34wm/GHSA-2qmr-p234-34wm.json new file mode 100644 index 00000000000..0d04f053d5e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-2qmr-p234-34wm/GHSA-2qmr-p234-34wm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2qmr-p234-34wm", + "modified": "2024-11-19T18:31:03Z", + "published": "2024-11-19T18:31:03Z", + "aliases": [ + "CVE-2024-51826" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in James Turner Bitcoin Payments allows DOM-Based XSS.This issue affects Bitcoin Payments: from n/a through 1.4.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51826" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/bitcoin-payments/wordpress-bitcoin-payments-plugin-1-4-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-2v77-g93r-76vh/GHSA-2v77-g93r-76vh.json b/advisories/unreviewed/2024/11/GHSA-2v77-g93r-76vh/GHSA-2v77-g93r-76vh.json index f20a64066dc..ae566c80b22 100644 --- a/advisories/unreviewed/2024/11/GHSA-2v77-g93r-76vh/GHSA-2v77-g93r-76vh.json +++ b/advisories/unreviewed/2024/11/GHSA-2v77-g93r-76vh/GHSA-2v77-g93r-76vh.json @@ -48,7 +48,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-2vrj-cvff-5p56/GHSA-2vrj-cvff-5p56.json b/advisories/unreviewed/2024/11/GHSA-2vrj-cvff-5p56/GHSA-2vrj-cvff-5p56.json new file mode 100644 index 00000000000..5206cf7ebb3 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-2vrj-cvff-5p56/GHSA-2vrj-cvff-5p56.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2vrj-cvff-5p56", + "modified": "2024-11-19T18:31:07Z", + "published": "2024-11-19T18:31:07Z", + "aliases": [ + "CVE-2024-53069" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: qcom: scm: fix a NULL-pointer dereference\n\nSome SCM calls can be invoked with __scm being NULL (the driver may not\nhave been and will not be probed as there's no SCM entry in device-tree).\nMake sure we don't dereference a NULL pointer.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53069" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3d36e2b1d803f0d1cc674115d295a8f20ddb9268" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ca61d6836e6f4442a77762e1074d2706a2a6e578" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-33c8-2qq8-ffcg/GHSA-33c8-2qq8-ffcg.json b/advisories/unreviewed/2024/11/GHSA-33c8-2qq8-ffcg/GHSA-33c8-2qq8-ffcg.json new file mode 100644 index 00000000000..b7ad2f9c3fd --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-33c8-2qq8-ffcg/GHSA-33c8-2qq8-ffcg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-33c8-2qq8-ffcg", + "modified": "2024-11-19T18:31:03Z", + "published": "2024-11-19T18:31:03Z", + "aliases": [ + "CVE-2024-51852" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DynamicWebLab Dynamic Post Grid Elementor Addon allows DOM-Based XSS.This issue affects Dynamic Post Grid Elementor Addon: from n/a through 1.0.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51852" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/dynamic-post-grid-elementor-addon/wordpress-dynamic-post-grid-elementor-addon-plugin-1-0-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-363w-4gjr-hxxf/GHSA-363w-4gjr-hxxf.json b/advisories/unreviewed/2024/11/GHSA-363w-4gjr-hxxf/GHSA-363w-4gjr-hxxf.json new file mode 100644 index 00000000000..93c7a99d89c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-363w-4gjr-hxxf/GHSA-363w-4gjr-hxxf.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-363w-4gjr-hxxf", + "modified": "2024-11-19T18:31:07Z", + "published": "2024-11-19T18:31:07Z", + "aliases": [ + "CVE-2024-53070" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: dwc3: fix fault at system suspend if device was already runtime suspended\n\nIf the device was already runtime suspended then during system suspend\nwe cannot access the device registers else it will crash.\n\nAlso we cannot access any registers after dwc3_core_exit() on some\nplatforms so move the dwc3_enable_susphy() call to the top.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53070" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/06b98197b69e2f2af9cb1991ee0b1c876edf7b86" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4abc5ee334fe4aba50461c45fdaaa4c5e5c57789" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/562804b1561cc248cc37746a1c96c83cab1d7209" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9cfb31e4c89d200d8ab7cb1e0bb9e6e8d621ca0b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d9e65d461a9de037e7c9d584776d025cfce6d86d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-373q-7p85-gr9f/GHSA-373q-7p85-gr9f.json b/advisories/unreviewed/2024/11/GHSA-373q-7p85-gr9f/GHSA-373q-7p85-gr9f.json new file mode 100644 index 00000000000..8cefea0a12e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-373q-7p85-gr9f/GHSA-373q-7p85-gr9f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-373q-7p85-gr9f", + "modified": "2024-11-19T18:31:05Z", + "published": "2024-11-19T18:31:05Z", + "aliases": [ + "CVE-2024-51932" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saif Bin-Alam Kings Tab Slider allows DOM-Based XSS.This issue affects Kings Tab Slider: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51932" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/kings-tab-slider/wordpress-kings-tab-slider-plugin-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-38wf-gvg7-rrvw/GHSA-38wf-gvg7-rrvw.json b/advisories/unreviewed/2024/11/GHSA-38wf-gvg7-rrvw/GHSA-38wf-gvg7-rrvw.json new file mode 100644 index 00000000000..a6ab85f1096 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-38wf-gvg7-rrvw/GHSA-38wf-gvg7-rrvw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-38wf-gvg7-rrvw", + "modified": "2024-11-19T18:31:00Z", + "published": "2024-11-19T18:31:00Z", + "aliases": [ + "CVE-2024-49689" + ], + "details": "Missing Authorization vulnerability in Harmonic Design HD Quiz – Save Results Light allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HD Quiz – Save Results Light: from n/a through 0.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49689" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/hd-quiz-save-results-light/wordpress-hd-quiz-save-results-light-plugin-0-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-3gf8-c827-8cjg/GHSA-3gf8-c827-8cjg.json b/advisories/unreviewed/2024/11/GHSA-3gf8-c827-8cjg/GHSA-3gf8-c827-8cjg.json new file mode 100644 index 00000000000..83777abaf45 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3gf8-c827-8cjg/GHSA-3gf8-c827-8cjg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3gf8-c827-8cjg", + "modified": "2024-11-19T18:31:01Z", + "published": "2024-11-19T18:31:01Z", + "aliases": [ + "CVE-2024-50541" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Enea Overclokk Advanced Control Manager for WordPress by ItalyStrap allows Stored XSS.This issue affects Advanced Control Manager for WordPress by ItalyStrap: from n/a through 2.16.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50541" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/advanced-control-manager/wordpress-advanced-control-manager-plugin-2-16-0-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-3jp2-56w2-f943/GHSA-3jp2-56w2-f943.json b/advisories/unreviewed/2024/11/GHSA-3jp2-56w2-f943/GHSA-3jp2-56w2-f943.json new file mode 100644 index 00000000000..256fb8d2019 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3jp2-56w2-f943/GHSA-3jp2-56w2-f943.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3jp2-56w2-f943", + "modified": "2024-11-19T18:31:03Z", + "published": "2024-11-19T18:31:03Z", + "aliases": [ + "CVE-2024-51848" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Digital Zoom Studio Parallaxer allows Stored XSS.This issue affects Parallaxer: from n/a through 1.00.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51848" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/parallaxer-lite-parallax-effects-on-images/wordpress-parallaxer-plugin-1-00-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-3mjq-gr7r-h6x3/GHSA-3mjq-gr7r-h6x3.json b/advisories/unreviewed/2024/11/GHSA-3mjq-gr7r-h6x3/GHSA-3mjq-gr7r-h6x3.json index 36fab43c482..4945d6250da 100644 --- a/advisories/unreviewed/2024/11/GHSA-3mjq-gr7r-h6x3/GHSA-3mjq-gr7r-h6x3.json +++ b/advisories/unreviewed/2024/11/GHSA-3mjq-gr7r-h6x3/GHSA-3mjq-gr7r-h6x3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3mjq-gr7r-h6x3", - "modified": "2024-11-18T21:30:47Z", + "modified": "2024-11-19T18:30:59Z", "published": "2024-11-18T21:30:47Z", "aliases": [ "CVE-2024-50848" ], "details": "An XML External Entity (XXE) vulnerability in the Import object and Translation Memory import functionalities of WorldServer v11.8.2 to access sensitive information and execute arbitrary commands via supplying a crafted .tmx file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-611" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-18T21:15:06Z" diff --git a/advisories/unreviewed/2024/11/GHSA-3mvg-wf73-6mx2/GHSA-3mvg-wf73-6mx2.json b/advisories/unreviewed/2024/11/GHSA-3mvg-wf73-6mx2/GHSA-3mvg-wf73-6mx2.json new file mode 100644 index 00000000000..177fdddd720 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3mvg-wf73-6mx2/GHSA-3mvg-wf73-6mx2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3mvg-wf73-6mx2", + "modified": "2024-11-19T18:31:04Z", + "published": "2024-11-19T18:31:04Z", + "aliases": [ + "CVE-2024-51876" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Codstack Team wp_automatic_widget allows DOM-Based XSS.This issue affects wp_automatic_widget: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51876" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-automatic-widget/wordpress-wp-automatic-widget-plugin-1-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-3vhp-r544-3wrg/GHSA-3vhp-r544-3wrg.json b/advisories/unreviewed/2024/11/GHSA-3vhp-r544-3wrg/GHSA-3vhp-r544-3wrg.json index b5f7ca1afbb..36cd43e1754 100644 --- a/advisories/unreviewed/2024/11/GHSA-3vhp-r544-3wrg/GHSA-3vhp-r544-3wrg.json +++ b/advisories/unreviewed/2024/11/GHSA-3vhp-r544-3wrg/GHSA-3vhp-r544-3wrg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3vhp-r544-3wrg", - "modified": "2024-11-16T00:31:51Z", + "modified": "2024-11-19T18:30:57Z", "published": "2024-11-16T00:31:50Z", "aliases": [ "CVE-2017-13310" ], "details": "In createFromParcel of ViewPager.java, there is a possible read/write serialization issue leading to a permissions bypass. This could lead to local escalation of privilege where an app can start an activity with system privileges with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-15T22:15:14Z" diff --git a/advisories/unreviewed/2024/11/GHSA-3w4r-prc4-q67c/GHSA-3w4r-prc4-q67c.json b/advisories/unreviewed/2024/11/GHSA-3w4r-prc4-q67c/GHSA-3w4r-prc4-q67c.json new file mode 100644 index 00000000000..f8cd6555545 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3w4r-prc4-q67c/GHSA-3w4r-prc4-q67c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3w4r-prc4-q67c", + "modified": "2024-11-19T18:31:04Z", + "published": "2024-11-19T18:31:04Z", + "aliases": [ + "CVE-2024-51864" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Agnel Waghela Shortcode Collection allows Stored XSS.This issue affects Shortcode Collection: from n/a through 1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51864" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/shortcode-collection/wordpress-shortcode-collection-plugin-1-4-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-3w88-854j-p487/GHSA-3w88-854j-p487.json b/advisories/unreviewed/2024/11/GHSA-3w88-854j-p487/GHSA-3w88-854j-p487.json new file mode 100644 index 00000000000..fe1dcb16cfe --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3w88-854j-p487/GHSA-3w88-854j-p487.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3w88-854j-p487", + "modified": "2024-11-19T18:31:02Z", + "published": "2024-11-19T18:31:02Z", + "aliases": [ + "CVE-2024-51811" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hussam Hussien Popup Image allows Stored XSS.This issue affects Popup Image: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51811" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/popup-image/wordpress-popup-image-plugin-1-0-1-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-3wcp-g7h4-2r32/GHSA-3wcp-g7h4-2r32.json b/advisories/unreviewed/2024/11/GHSA-3wcp-g7h4-2r32/GHSA-3wcp-g7h4-2r32.json new file mode 100644 index 00000000000..7c4122bf1ca --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3wcp-g7h4-2r32/GHSA-3wcp-g7h4-2r32.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3wcp-g7h4-2r32", + "modified": "2024-11-19T18:31:04Z", + "published": "2024-11-19T18:31:04Z", + "aliases": [ + "CVE-2024-51856" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Moose Moose Elementor Kit allows DOM-Based XSS.This issue affects Moose Elementor Kit: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51856" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/moose-elementor-kit/wordpress-moose-elementor-kit-plugin-1-0-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-42c7-w7r7-3v3m/GHSA-42c7-w7r7-3v3m.json b/advisories/unreviewed/2024/11/GHSA-42c7-w7r7-3v3m/GHSA-42c7-w7r7-3v3m.json new file mode 100644 index 00000000000..175c70a4f59 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-42c7-w7r7-3v3m/GHSA-42c7-w7r7-3v3m.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-42c7-w7r7-3v3m", + "modified": "2024-11-19T18:31:07Z", + "published": "2024-11-19T18:31:07Z", + "aliases": [ + "CVE-2024-53071" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/panthor: Be stricter about IO mapping flags\n\nThe current panthor_device_mmap_io() implementation has two issues:\n\n1. For mapping DRM_PANTHOR_USER_FLUSH_ID_MMIO_OFFSET,\n panthor_device_mmap_io() bails if VM_WRITE is set, but does not clear\n VM_MAYWRITE. That means userspace can use mprotect() to make the mapping\n writable later on. This is a classic Linux driver gotcha.\n I don't think this actually has any impact in practice:\n When the GPU is powered, writes to the FLUSH_ID seem to be ignored; and\n when the GPU is not powered, the dummy_latest_flush page provided by the\n driver is deliberately designed to not do any flushes, so the only thing\n writing to the dummy_latest_flush could achieve would be to make *more*\n flushes happen.\n\n2. panthor_device_mmap_io() does not block MAP_PRIVATE mappings (which are\n mappings without the VM_SHARED flag).\n MAP_PRIVATE in combination with VM_MAYWRITE indicates that the VMA has\n copy-on-write semantics, which for VM_PFNMAP are semi-supported but\n fairly cursed.\n In particular, in such a mapping, the driver can only install PTEs\n during mmap() by calling remap_pfn_range() (because remap_pfn_range()\n wants to **store the physical address of the mapped physical memory into\n the vm_pgoff of the VMA**); installing PTEs later on with a fault\n handler (as panthor does) is not supported in private mappings, and so\n if you try to fault in such a mapping, vmf_insert_pfn_prot() splats when\n it hits a BUG() check.\n\nFix it by clearing the VM_MAYWRITE flag (userspace writing to the FLUSH_ID\ndoesn't make sense) and requiring VM_SHARED (copy-on-write semantics for\nthe FLUSH_ID don't make sense).\n\nReproducers for both scenarios are in the notes of my patch on the mailing\nlist; I tested that these bugs exist on a Rock 5B machine.\n\nNote that I only compile-tested the patch, I haven't tested it; I don't\nhave a working kernel build setup for the test machine yet. Please test it\nbefore applying it.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53071" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2604afd65043e8f9d4be036cb1242adf6b5723cf" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f432a1621f049bb207e78363d9d0e3c6fa2da5db" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-42qw-9g84-jp2h/GHSA-42qw-9g84-jp2h.json b/advisories/unreviewed/2024/11/GHSA-42qw-9g84-jp2h/GHSA-42qw-9g84-jp2h.json new file mode 100644 index 00000000000..199277686f1 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-42qw-9g84-jp2h/GHSA-42qw-9g84-jp2h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-42qw-9g84-jp2h", + "modified": "2024-11-19T18:31:04Z", + "published": "2024-11-19T18:31:04Z", + "aliases": [ + "CVE-2024-51887" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryan Sutana NV Slider allows Stored XSS.This issue affects NV Slider: from n/a through 1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51887" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/nv-slider/wordpress-nv-slider-plugin-1-6-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-432j-87hp-h33w/GHSA-432j-87hp-h33w.json b/advisories/unreviewed/2024/11/GHSA-432j-87hp-h33w/GHSA-432j-87hp-h33w.json new file mode 100644 index 00000000000..d42a76bbd7f --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-432j-87hp-h33w/GHSA-432j-87hp-h33w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-432j-87hp-h33w", + "modified": "2024-11-19T18:31:02Z", + "published": "2024-11-19T18:31:02Z", + "aliases": [ + "CVE-2024-51657" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Woopy Plugins SmartLink Dynamic URLs allows Stored XSS.This issue affects SmartLink Dynamic URLs: from n/a through 1.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51657" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/smartlink-dinamic-urls/wordpress-smartlink-dynamic-urls-plugin-1-1-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-43h5-8p3v-hfvv/GHSA-43h5-8p3v-hfvv.json b/advisories/unreviewed/2024/11/GHSA-43h5-8p3v-hfvv/GHSA-43h5-8p3v-hfvv.json new file mode 100644 index 00000000000..279ea4c7311 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-43h5-8p3v-hfvv/GHSA-43h5-8p3v-hfvv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-43h5-8p3v-hfvv", + "modified": "2024-11-19T18:31:04Z", + "published": "2024-11-19T18:31:04Z", + "aliases": [ + "CVE-2024-51870" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aniketji007 Ultimate Flipbox Addon for Elementor allows Stored XSS.This issue affects Ultimate Flipbox Addon for Elementor: from n/a through .4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51870" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ultimate-flipbox-addon-for-elementor/wordpress-ultimate-flipbox-addon-for-elementor-plugin-1-0-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4437-j8j7-wqjr/GHSA-4437-j8j7-wqjr.json b/advisories/unreviewed/2024/11/GHSA-4437-j8j7-wqjr/GHSA-4437-j8j7-wqjr.json new file mode 100644 index 00000000000..97789ae0f9e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4437-j8j7-wqjr/GHSA-4437-j8j7-wqjr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4437-j8j7-wqjr", + "modified": "2024-11-19T18:31:05Z", + "published": "2024-11-19T18:31:05Z", + "aliases": [ + "CVE-2024-51911" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ketan Patel Featured product by category name allows DOM-Based XSS.This issue affects Featured product by category name: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51911" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/featured-product-by-category-name/wordpress-featured-product-by-category-name-plugin-1-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-45w9-22fh-qrx4/GHSA-45w9-22fh-qrx4.json b/advisories/unreviewed/2024/11/GHSA-45w9-22fh-qrx4/GHSA-45w9-22fh-qrx4.json index 54813055dd4..d8ef8dc98ee 100644 --- a/advisories/unreviewed/2024/11/GHSA-45w9-22fh-qrx4/GHSA-45w9-22fh-qrx4.json +++ b/advisories/unreviewed/2024/11/GHSA-45w9-22fh-qrx4/GHSA-45w9-22fh-qrx4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-45w9-22fh-qrx4", - "modified": "2024-11-15T12:31:44Z", + "modified": "2024-11-19T18:30:56Z", "published": "2024-11-15T12:31:44Z", "aliases": [ "CVE-2024-8979" diff --git a/advisories/unreviewed/2024/11/GHSA-4696-66c4-2gvx/GHSA-4696-66c4-2gvx.json b/advisories/unreviewed/2024/11/GHSA-4696-66c4-2gvx/GHSA-4696-66c4-2gvx.json new file mode 100644 index 00000000000..0e3942115c9 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4696-66c4-2gvx/GHSA-4696-66c4-2gvx.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4696-66c4-2gvx", + "modified": "2024-11-19T18:31:06Z", + "published": "2024-11-19T18:31:06Z", + "aliases": [ + "CVE-2024-48991" + ], + "details": "Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by winning a race condition and tricking needrestart into running their own, fake Python interpreter (instead of the system's real Python interpreter).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48991" + }, + { + "type": "WEB", + "url": "https://github.com/liske/needrestart/commit/6ce6136cccc307c6b8a0f8cae12f9a22ac2aad59" + }, + { + "type": "WEB", + "url": "https://www.cve.org/CVERecord?id=CVE-2024-48991" + }, + { + "type": "WEB", + "url": "https://www.qualys.com/2024/11/19/needrestart/needrestart.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-49fm-c6jx-pv73/GHSA-49fm-c6jx-pv73.json b/advisories/unreviewed/2024/11/GHSA-49fm-c6jx-pv73/GHSA-49fm-c6jx-pv73.json new file mode 100644 index 00000000000..1e481911272 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-49fm-c6jx-pv73/GHSA-49fm-c6jx-pv73.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-49fm-c6jx-pv73", + "modified": "2024-11-19T18:31:02Z", + "published": "2024-11-19T18:31:02Z", + "aliases": [ + "CVE-2024-51824" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sony7596, mrseankumar25, miraclewebssoft Advanced Video Player with Analytics allows DOM-Based XSS.This issue affects Advanced Video Player with Analytics: from n/a through 1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51824" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/advanced-video-player-with-analytics/wordpress-advanced-video-player-with-analytics-plugin-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4cx4-xm36-7hp9/GHSA-4cx4-xm36-7hp9.json b/advisories/unreviewed/2024/11/GHSA-4cx4-xm36-7hp9/GHSA-4cx4-xm36-7hp9.json new file mode 100644 index 00000000000..aa02a60feab --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4cx4-xm36-7hp9/GHSA-4cx4-xm36-7hp9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4cx4-xm36-7hp9", + "modified": "2024-11-19T18:31:01Z", + "published": "2024-11-19T18:31:01Z", + "aliases": [ + "CVE-2024-50537" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stefano Marra Smart Mockups allows Stored XSS.This issue affects Smart Mockups: from n/a through 1.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50537" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/smart-mockups/wordpress-smart-mockups-plugin-1-2-0-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4f2j-5xcx-5g9w/GHSA-4f2j-5xcx-5g9w.json b/advisories/unreviewed/2024/11/GHSA-4f2j-5xcx-5g9w/GHSA-4f2j-5xcx-5g9w.json new file mode 100644 index 00000000000..fc1939b2d7b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4f2j-5xcx-5g9w/GHSA-4f2j-5xcx-5g9w.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4f2j-5xcx-5g9w", + "modified": "2024-11-19T18:31:07Z", + "published": "2024-11-19T18:31:07Z", + "aliases": [ + "CVE-2024-53079" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/thp: fix deferred split unqueue naming and locking\n\nRecent changes are putting more pressure on THP deferred split queues:\nunder load revealing long-standing races, causing list_del corruptions,\n\"Bad page state\"s and worse (I keep BUGs in both of those, so usually\ndon't get to see how badly they end up without). The relevant recent\nchanges being 6.8's mTHP, 6.10's mTHP swapout, and 6.12's mTHP swapin,\nimproved swap allocation, and underused THP splitting.\n\nBefore fixing locking: rename misleading folio_undo_large_rmappable(),\nwhich does not undo large_rmappable, to folio_unqueue_deferred_split(),\nwhich is what it does. But that and its out-of-line __callee are mm\ninternals of very limited usability: add comment and WARN_ON_ONCEs to\ncheck usage; and return a bool to say if a deferred split was unqueued,\nwhich can then be used in WARN_ON_ONCEs around safety checks (sparing\ncallers the arcane conditionals in __folio_unqueue_deferred_split()).\n\nJust omit the folio_unqueue_deferred_split() from free_unref_folios(), all\nof whose callers now call it beforehand (and if any forget then bad_page()\nwill tell) - except for its caller put_pages_list(), which itself no\nlonger has any callers (and will be deleted separately).\n\nSwapout: mem_cgroup_swapout() has been resetting folio->memcg_data 0\nwithout checking and unqueueing a THP folio from deferred split list;\nwhich is unfortunate, since the split_queue_lock depends on the memcg\n(when memcg is enabled); so swapout has been unqueueing such THPs later,\nwhen freeing the folio, using the pgdat's lock instead: potentially\ncorrupting the memcg's list. __remove_mapping() has frozen refcount to 0\nhere, so no problem with calling folio_unqueue_deferred_split() before\nresetting memcg_data.\n\nThat goes back to 5.4 commit 87eaceb3faa5 (\"mm: thp: make deferred split\nshrinker memcg aware\"): which included a check on swapcache before adding\nto deferred queue, but no check on deferred queue before adding THP to\nswapcache. That worked fine with the usual sequence of events in reclaim\n(though there were a couple of rare ways in which a THP on deferred queue\ncould have been swapped out), but 6.12 commit dafff3f4c850 (\"mm: split\nunderused THPs\") avoids splitting underused THPs in reclaim, which makes\nswapcache THPs on deferred queue commonplace.\n\nKeep the check on swapcache before adding to deferred queue? Yes: it is\nno longer essential, but preserves the existing behaviour, and is likely\nto be a worthwhile optimization (vmstat showed much more traffic on the\nqueue under swapping load if the check was removed); update its comment.\n\nMemcg-v1 move (deprecated): mem_cgroup_move_account() has been changing\nfolio->memcg_data without checking and unqueueing a THP folio from the\ndeferred list, sometimes corrupting \"from\" memcg's list, like swapout. \nRefcount is non-zero here, so folio_unqueue_deferred_split() can only be\nused in a WARN_ON_ONCE to validate the fix, which must be done earlier:\nmem_cgroup_move_charge_pte_range() first try to split the THP (splitting\nof course unqueues), or skip it if that fails. Not ideal, but moving\ncharge has been requested, and khugepaged should repair the THP later:\nnobody wants new custom unqueueing code just for this deprecated case.\n\nThe 87eaceb3faa5 commit did have the code to move from one deferred list\nto another (but was not conscious of its unsafety while refcount non-0);\nbut that was removed by 5.6 commit fac0516b5534 (\"mm: thp: don't need care\ndeferred split queue in memcg charge move path\"), which argued that the\nexistence of a PMD mapping guarantees that the THP cannot be on a deferred\nlist. As above, false in rare cases, and now commonly false.\n\nBackport to 6.11 should be straightforward. Earlier backports must take\ncare that other _deferred_list fixes and dependencies are included. There\nis not a strong case for backports, but they can fix cornercases.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53079" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/afb1352d06b1b6b2cfd1f901c766a430c87078b3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f8f931bba0f92052cf842b7e30917b1afcc77d5a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fc4951c3e3358dd82ea508e893695b916c813f17" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4f73-836m-4mcr/GHSA-4f73-836m-4mcr.json b/advisories/unreviewed/2024/11/GHSA-4f73-836m-4mcr/GHSA-4f73-836m-4mcr.json new file mode 100644 index 00000000000..6f4fb9f5c4c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4f73-836m-4mcr/GHSA-4f73-836m-4mcr.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4f73-836m-4mcr", + "modified": "2024-11-19T18:31:07Z", + "published": "2024-11-19T18:31:07Z", + "aliases": [ + "CVE-2024-53073" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nNFSD: Never decrement pending_async_copies on error\n\nThe error flow in nfsd4_copy() calls cleanup_async_copy(), which\nalready decrements nn->pending_async_copies.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53073" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1421883aa30c5d26bc3370e2d19cb350f0d5ca28" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8286f8b622990194207df9ab852e0f87c60d35e9" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4gjx-j363-q574/GHSA-4gjx-j363-q574.json b/advisories/unreviewed/2024/11/GHSA-4gjx-j363-q574/GHSA-4gjx-j363-q574.json new file mode 100644 index 00000000000..e4447d5a655 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4gjx-j363-q574/GHSA-4gjx-j363-q574.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4gjx-j363-q574", + "modified": "2024-11-19T18:31:01Z", + "published": "2024-11-19T18:31:01Z", + "aliases": [ + "CVE-2024-51638" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Sanjeev Mohindra Awesome Shortcodes For Genesis allows Stored XSS.This issue affects Awesome Shortcodes For Genesis: from n/a through .8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51638" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/awesome-shortcodes-for-genesis/wordpress-awesome-shortcodes-for-genesis-plugin-1-1-8-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4pmx-qx84-x3f4/GHSA-4pmx-qx84-x3f4.json b/advisories/unreviewed/2024/11/GHSA-4pmx-qx84-x3f4/GHSA-4pmx-qx84-x3f4.json new file mode 100644 index 00000000000..99add9fe52f --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4pmx-qx84-x3f4/GHSA-4pmx-qx84-x3f4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4pmx-qx84-x3f4", + "modified": "2024-11-19T18:31:03Z", + "published": "2024-11-19T18:31:03Z", + "aliases": [ + "CVE-2024-51846" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Simpson Community Yard Sale allows Stored XSS.This issue affects Community Yard Sale: from n/a through 1.1.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51846" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/community-yard-sale/wordpress-community-yard-sale-plugin-1-1-11-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4rq4-85gc-8wf8/GHSA-4rq4-85gc-8wf8.json b/advisories/unreviewed/2024/11/GHSA-4rq4-85gc-8wf8/GHSA-4rq4-85gc-8wf8.json new file mode 100644 index 00000000000..32e5cd52cd8 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4rq4-85gc-8wf8/GHSA-4rq4-85gc-8wf8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4rq4-85gc-8wf8", + "modified": "2024-11-19T18:31:00Z", + "published": "2024-11-19T18:31:00Z", + "aliases": [ + "CVE-2024-50514" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saturday Drive Ninja Forms allows Stored XSS.This issue affects Ninja Forms: from n/a through 3.8.16.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50514" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ninja-forms/wordpress-ninja-forms-the-contact-form-builder-that-grows-with-you-plugin-3-8-16-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4wrj-7475-35c2/GHSA-4wrj-7475-35c2.json b/advisories/unreviewed/2024/11/GHSA-4wrj-7475-35c2/GHSA-4wrj-7475-35c2.json new file mode 100644 index 00000000000..d1c23244600 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4wrj-7475-35c2/GHSA-4wrj-7475-35c2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4wrj-7475-35c2", + "modified": "2024-11-19T18:31:03Z", + "published": "2024-11-19T18:31:03Z", + "aliases": [ + "CVE-2024-51853" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alberuni Azad Faltu Testimonial Rotator allows DOM-Based XSS.This issue affects Faltu Testimonial Rotator: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51853" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/faltu-testimonial-rotator/wordpress-faltu-testimonial-rotator-plugin-1-0-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4xwh-jfmg-xmv5/GHSA-4xwh-jfmg-xmv5.json b/advisories/unreviewed/2024/11/GHSA-4xwh-jfmg-xmv5/GHSA-4xwh-jfmg-xmv5.json new file mode 100644 index 00000000000..129d60fbfa8 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4xwh-jfmg-xmv5/GHSA-4xwh-jfmg-xmv5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4xwh-jfmg-xmv5", + "modified": "2024-11-19T18:31:02Z", + "published": "2024-11-19T18:31:02Z", + "aliases": [ + "CVE-2024-51652" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Prem Nawaz Khan, Victor Tsaran, Ron Feathers, and Marc Kocher Skip To allows Stored XSS.This issue affects Skip To: from n/a through 2.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51652" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/skip-to/wordpress-skip-to-plugin-2-0-0-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-533v-gm9h-955p/GHSA-533v-gm9h-955p.json b/advisories/unreviewed/2024/11/GHSA-533v-gm9h-955p/GHSA-533v-gm9h-955p.json new file mode 100644 index 00000000000..bcb239e4018 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-533v-gm9h-955p/GHSA-533v-gm9h-955p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-533v-gm9h-955p", + "modified": "2024-11-19T18:31:03Z", + "published": "2024-11-19T18:31:03Z", + "aliases": [ + "CVE-2024-51867" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alexander Conroy Simpul Events by Esotech allows Stored XSS.This issue affects Simpul Events by Esotech: from n/a through 1.8.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51867" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/simpul-events-by-esotech/wordpress-simpul-events-by-esotech-plugin-1-8-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-548p-gmg2-4cqq/GHSA-548p-gmg2-4cqq.json b/advisories/unreviewed/2024/11/GHSA-548p-gmg2-4cqq/GHSA-548p-gmg2-4cqq.json new file mode 100644 index 00000000000..af36d077add --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-548p-gmg2-4cqq/GHSA-548p-gmg2-4cqq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-548p-gmg2-4cqq", + "modified": "2024-11-19T18:31:04Z", + "published": "2024-11-19T18:31:04Z", + "aliases": [ + "CVE-2024-51877" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in straightvisions GmbH SV Forms allows DOM-Based XSS.This issue affects SV Forms: from n/a through 2.0.05.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51877" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/sv-forms/wordpress-sv-forms-plugin-2-0-05-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-54hc-gq3w-c935/GHSA-54hc-gq3w-c935.json b/advisories/unreviewed/2024/11/GHSA-54hc-gq3w-c935/GHSA-54hc-gq3w-c935.json new file mode 100644 index 00000000000..901b0e3a9b8 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-54hc-gq3w-c935/GHSA-54hc-gq3w-c935.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-54hc-gq3w-c935", + "modified": "2024-11-19T18:31:06Z", + "published": "2024-11-19T18:31:06Z", + "aliases": [ + "CVE-2024-53050" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915/hdcp: Add encoder check in hdcp2_get_capability\n\nAdd encoder check in intel_hdcp2_get_capability to avoid\nnull pointer error.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53050" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5b89dcf23575eb5bb95ce8d672cbc2232c2eb096" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d34f4f058edf1235c103ca9c921dc54820d14d40" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-553q-p66q-xfmv/GHSA-553q-p66q-xfmv.json b/advisories/unreviewed/2024/11/GHSA-553q-p66q-xfmv/GHSA-553q-p66q-xfmv.json new file mode 100644 index 00000000000..83d88c0a254 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-553q-p66q-xfmv/GHSA-553q-p66q-xfmv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-553q-p66q-xfmv", + "modified": "2024-11-19T18:31:01Z", + "published": "2024-11-19T18:31:01Z", + "aliases": [ + "CVE-2024-51641" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in jcmlmorav Advanced PDF Generator allows Stored XSS.This issue affects Advanced PDF Generator: from n/a through 0.4.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51641" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/advanced-pdf-generator/wordpress-advanced-pdf-generator-plugin-0-4-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-56f7-h7m2-r62r/GHSA-56f7-h7m2-r62r.json b/advisories/unreviewed/2024/11/GHSA-56f7-h7m2-r62r/GHSA-56f7-h7m2-r62r.json new file mode 100644 index 00000000000..8e7ad1b86e2 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-56f7-h7m2-r62r/GHSA-56f7-h7m2-r62r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-56f7-h7m2-r62r", + "modified": "2024-11-19T18:31:01Z", + "published": "2024-11-19T18:31:01Z", + "aliases": [ + "CVE-2024-51631" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Eftakhairul Islam Sticky Social Bar allows Cross Site Request Forgery.This issue affects Sticky Social Bar: from n/a through 2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51631" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/sticky-social-bar/wordpress-sticky-social-bar-plugin-2-0-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-56wh-6gx4-4442/GHSA-56wh-6gx4-4442.json b/advisories/unreviewed/2024/11/GHSA-56wh-6gx4-4442/GHSA-56wh-6gx4-4442.json new file mode 100644 index 00000000000..a2973e81c54 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-56wh-6gx4-4442/GHSA-56wh-6gx4-4442.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-56wh-6gx4-4442", + "modified": "2024-11-19T18:31:07Z", + "published": "2024-11-19T18:31:07Z", + "aliases": [ + "CVE-2024-53065" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/slab: fix warning caused by duplicate kmem_cache creation in kmem_buckets_create\n\nCommit b035f5a6d852 (\"mm: slab: reduce the kmalloc() minimum alignment\nif DMA bouncing possible\") reduced ARCH_KMALLOC_MINALIGN to 8 on arm64.\nHowever, with KASAN_HW_TAGS enabled, arch_slab_minalign() becomes 16.\nThis causes kmalloc_caches[*][8] to be aliased to kmalloc_caches[*][16],\nresulting in kmem_buckets_create() attempting to create a kmem_cache for\nsize 16 twice. This duplication triggers warnings on boot:\n\n[ 2.325108] ------------[ cut here ]------------\n[ 2.325135] kmem_cache of name 'memdup_user-16' already exists\n[ 2.325783] WARNING: CPU: 0 PID: 1 at mm/slab_common.c:107 __kmem_cache_create_args+0xb8/0x3b0\n[ 2.327957] Modules linked in:\n[ 2.328550] CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Not tainted 6.12.0-rc5mm-unstable-arm64+ #12\n[ 2.328683] Hardware name: QEMU QEMU Virtual Machine, BIOS 2024.02-2 03/11/2024\n[ 2.328790] pstate: 61000009 (nZCv daif -PAN -UAO -TCO +DIT -SSBS BTYPE=--)\n[ 2.328911] pc : __kmem_cache_create_args+0xb8/0x3b0\n[ 2.328930] lr : __kmem_cache_create_args+0xb8/0x3b0\n[ 2.328942] sp : ffff800083d6fc50\n[ 2.328961] x29: ffff800083d6fc50 x28: f2ff0000c1674410 x27: ffff8000820b0598\n[ 2.329061] x26: 000000007fffffff x25: 0000000000000010 x24: 0000000000002000\n[ 2.329101] x23: ffff800083d6fce8 x22: ffff8000832222e8 x21: ffff800083222388\n[ 2.329118] x20: f2ff0000c1674410 x19: f5ff0000c16364c0 x18: ffff800083d80030\n[ 2.329135] x17: 0000000000000000 x16: 0000000000000000 x15: 0000000000000000\n[ 2.329152] x14: 0000000000000000 x13: 0a73747369786520 x12: 79646165726c6120\n[ 2.329169] x11: 656820747563205b x10: 2d2d2d2d2d2d2d2d x9 : 0000000000000000\n[ 2.329194] x8 : 0000000000000000 x7 : 0000000000000000 x6 : 0000000000000000\n[ 2.329210] x5 : 0000000000000000 x4 : 0000000000000000 x3 : 0000000000000000\n[ 2.329226] x2 : 0000000000000000 x1 : 0000000000000000 x0 : 0000000000000000\n[ 2.329291] Call trace:\n[ 2.329407] __kmem_cache_create_args+0xb8/0x3b0\n[ 2.329499] kmem_buckets_create+0xfc/0x320\n[ 2.329526] init_user_buckets+0x34/0x78\n[ 2.329540] do_one_initcall+0x64/0x3c8\n[ 2.329550] kernel_init_freeable+0x26c/0x578\n[ 2.329562] kernel_init+0x3c/0x258\n[ 2.329574] ret_from_fork+0x10/0x20\n[ 2.329698] ---[ end trace 0000000000000000 ]---\n\n[ 2.403704] ------------[ cut here ]------------\n[ 2.404716] kmem_cache of name 'msg_msg-16' already exists\n[ 2.404801] WARNING: CPU: 2 PID: 1 at mm/slab_common.c:107 __kmem_cache_create_args+0xb8/0x3b0\n[ 2.404842] Modules linked in:\n[ 2.404971] CPU: 2 UID: 0 PID: 1 Comm: swapper/0 Tainted: G W 6.12.0-rc5mm-unstable-arm64+ #12\n[ 2.405026] Tainted: [W]=WARN\n[ 2.405043] Hardware name: QEMU QEMU Virtual Machine, BIOS 2024.02-2 03/11/2024\n[ 2.405057] pstate: 60400009 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n[ 2.405079] pc : __kmem_cache_create_args+0xb8/0x3b0\n[ 2.405100] lr : __kmem_cache_create_args+0xb8/0x3b0\n[ 2.405111] sp : ffff800083d6fc50\n[ 2.405115] x29: ffff800083d6fc50 x28: fbff0000c1674410 x27: ffff8000820b0598\n[ 2.405135] x26: 000000000000ffd0 x25: 0000000000000010 x24: 0000000000006000\n[ 2.405153] x23: ffff800083d6fce8 x22: ffff8000832222e8 x21: ffff800083222388\n[ 2.405169] x20: fbff0000c1674410 x19: fdff0000c163d6c0 x18: ffff800083d80030\n[ 2.405185] x17: 0000000000000000 x16: 0000000000000000 x15: 0000000000000000\n[ 2.405201] x14: 0000000000000000 x13: 0a73747369786520 x12: 79646165726c6120\n[ 2.405217] x11: 656820747563205b x10: 2d2d2d2d2d2d2d2d x9 : 0000000000000000\n[ 2.405233] x8 : 0000000000000000 x7 : 0000000000000000 x6 : 0000000000000000\n[ 2.405248] x5 : 0000000000000000 x4 : 0000000000000000 x3 : 0000000000000000\n[ 2.405271] x2 : 0000000000000000 x1 : 0000000000000000 x0 : 0000000000000000\n[ 2.405287] Call trace:\n[ 2\n---truncated---", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53065" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1b47f9febf48641d3530ec877f4d0995c58e6b73" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9c9201afebea1efc7ea4b8f721ee18a05bb8aca1" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-57xx-4r4j-43p7/GHSA-57xx-4r4j-43p7.json b/advisories/unreviewed/2024/11/GHSA-57xx-4r4j-43p7/GHSA-57xx-4r4j-43p7.json index 56cd3824c86..bf4989ff372 100644 --- a/advisories/unreviewed/2024/11/GHSA-57xx-4r4j-43p7/GHSA-57xx-4r4j-43p7.json +++ b/advisories/unreviewed/2024/11/GHSA-57xx-4r4j-43p7/GHSA-57xx-4r4j-43p7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-57xx-4r4j-43p7", - "modified": "2024-11-08T18:30:50Z", + "modified": "2024-11-19T18:30:54Z", "published": "2024-11-08T06:30:49Z", "aliases": [ "CVE-2024-50208" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/bnxt_re: Fix a bug while setting up Level-2 PBL pages\n\nAvoid memory corruption while setting up Level-2 PBL pages for the non MR\nresources when num_pages > 256K.\n\nThere will be a single PDE page address (contiguous pages in the case of >\nPAGE_SIZE), but, current logic assumes multiple pages, leading to invalid\nmemory access after 256K PBL entries in the PDE.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-08T06:15:17Z" diff --git a/advisories/unreviewed/2024/11/GHSA-594x-49wf-v3rp/GHSA-594x-49wf-v3rp.json b/advisories/unreviewed/2024/11/GHSA-594x-49wf-v3rp/GHSA-594x-49wf-v3rp.json new file mode 100644 index 00000000000..77bca7f494e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-594x-49wf-v3rp/GHSA-594x-49wf-v3rp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-594x-49wf-v3rp", + "modified": "2024-11-19T18:31:04Z", + "published": "2024-11-19T18:31:04Z", + "aliases": [ + "CVE-2024-51871" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Luzuk Luzuk Team allows Stored XSS.This issue affects Luzuk Team: from n/a through 0.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51871" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/luzuk-team/wordpress-luzuk-team-plugin-0-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-59r4-qr9h-8crh/GHSA-59r4-qr9h-8crh.json b/advisories/unreviewed/2024/11/GHSA-59r4-qr9h-8crh/GHSA-59r4-qr9h-8crh.json new file mode 100644 index 00000000000..5bfa4848cbd --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-59r4-qr9h-8crh/GHSA-59r4-qr9h-8crh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-59r4-qr9h-8crh", + "modified": "2024-11-19T18:31:01Z", + "published": "2024-11-19T18:31:01Z", + "aliases": [ + "CVE-2024-50543" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Amazing Team amazing neo icon font for elementor allows DOM-Based XSS.This issue affects amazing neo icon font for elementor: from n/a through 2.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50543" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/amazing-neo-icon-font-for-elementor/wordpress-amazing-neo-icon-font-for-elementor-plugin-2-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-5ggj-xwvc-9x57/GHSA-5ggj-xwvc-9x57.json b/advisories/unreviewed/2024/11/GHSA-5ggj-xwvc-9x57/GHSA-5ggj-xwvc-9x57.json new file mode 100644 index 00000000000..023d4119243 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-5ggj-xwvc-9x57/GHSA-5ggj-xwvc-9x57.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5ggj-xwvc-9x57", + "modified": "2024-11-19T18:31:06Z", + "published": "2024-11-19T18:31:06Z", + "aliases": [ + "CVE-2024-53056" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/mediatek: Fix potential NULL dereference in mtk_crtc_destroy()\n\nIn mtk_crtc_create(), if the call to mbox_request_channel() fails then we\nset the \"mtk_crtc->cmdq_client.chan\" pointer to NULL. In that situation,\nwe do not call cmdq_pkt_create().\n\nDuring the cleanup, we need to check if the \"mtk_crtc->cmdq_client.chan\"\nis NULL first before calling cmdq_pkt_destroy(). Calling\ncmdq_pkt_destroy() is unnecessary if we didn't call cmdq_pkt_create() and\nit will result in a NULL pointer dereference.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53056" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4018651ba5c409034149f297d3dd3328b91561fd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c60583a87cb4a85b69d1f448f0be5eb6ec62cbb2" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-5gw7-xq3v-7q6c/GHSA-5gw7-xq3v-7q6c.json b/advisories/unreviewed/2024/11/GHSA-5gw7-xq3v-7q6c/GHSA-5gw7-xq3v-7q6c.json index 50eca7e1e3e..84f4bbc6c3a 100644 --- a/advisories/unreviewed/2024/11/GHSA-5gw7-xq3v-7q6c/GHSA-5gw7-xq3v-7q6c.json +++ b/advisories/unreviewed/2024/11/GHSA-5gw7-xq3v-7q6c/GHSA-5gw7-xq3v-7q6c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5gw7-xq3v-7q6c", - "modified": "2024-11-16T00:31:51Z", + "modified": "2024-11-19T18:30:57Z", "published": "2024-11-16T00:31:51Z", "aliases": [ "CVE-2017-13314" ], "details": "In setAllowOnlyVpnForUids of NetworkManagementService.java, there is a possible security settings bypass due to a missing permission check. This could lead to local escalation of privilege allowing users to access non-VPN networks, when they are supposed to be restricted to the VPN networks, with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-15T22:15:14Z" diff --git a/advisories/unreviewed/2024/11/GHSA-5m89-67rv-p8wm/GHSA-5m89-67rv-p8wm.json b/advisories/unreviewed/2024/11/GHSA-5m89-67rv-p8wm/GHSA-5m89-67rv-p8wm.json new file mode 100644 index 00000000000..55b2837f62e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-5m89-67rv-p8wm/GHSA-5m89-67rv-p8wm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5m89-67rv-p8wm", + "modified": "2024-11-19T18:31:04Z", + "published": "2024-11-19T18:31:04Z", + "aliases": [ + "CVE-2024-51904" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joan Boluda Embed documents shortcode allows Stored XSS.This issue affects Embed documents shortcode: from n/a through 1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51904" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/embed-documents-shortcode/wordpress-embed-documents-shortcode-plugin-1-5-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-5qr2-q8cp-vq2r/GHSA-5qr2-q8cp-vq2r.json b/advisories/unreviewed/2024/11/GHSA-5qr2-q8cp-vq2r/GHSA-5qr2-q8cp-vq2r.json new file mode 100644 index 00000000000..8dc5736168d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-5qr2-q8cp-vq2r/GHSA-5qr2-q8cp-vq2r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5qr2-q8cp-vq2r", + "modified": "2024-11-19T18:31:01Z", + "published": "2024-11-19T18:31:01Z", + "aliases": [ + "CVE-2024-51617" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rami Yushuvaev Clyp allows Stored XSS.This issue affects Clyp: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51617" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/clyp/wordpress-clyp-plugin-1-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-5qw6-857j-hf24/GHSA-5qw6-857j-hf24.json b/advisories/unreviewed/2024/11/GHSA-5qw6-857j-hf24/GHSA-5qw6-857j-hf24.json index 4da7e2f38ac..770cfab1fdc 100644 --- a/advisories/unreviewed/2024/11/GHSA-5qw6-857j-hf24/GHSA-5qw6-857j-hf24.json +++ b/advisories/unreviewed/2024/11/GHSA-5qw6-857j-hf24/GHSA-5qw6-857j-hf24.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5qw6-857j-hf24", - "modified": "2024-11-16T00:31:51Z", + "modified": "2024-11-19T18:30:57Z", "published": "2024-11-16T00:31:51Z", "aliases": [ "CVE-2024-51765" ], "details": "A security vulnerability has been identified in HPE Cray Data Virtualization Service (DVS). Depending on configuration, this vulnerability may lead to local/cluster unauthorized access.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-15T22:15:16Z" diff --git a/advisories/unreviewed/2024/11/GHSA-5xgh-3xqg-v5p2/GHSA-5xgh-3xqg-v5p2.json b/advisories/unreviewed/2024/11/GHSA-5xgh-3xqg-v5p2/GHSA-5xgh-3xqg-v5p2.json new file mode 100644 index 00000000000..610346a8e51 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-5xgh-3xqg-v5p2/GHSA-5xgh-3xqg-v5p2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5xgh-3xqg-v5p2", + "modified": "2024-11-19T18:31:05Z", + "published": "2024-11-19T18:31:05Z", + "aliases": [ + "CVE-2024-51913" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mapme Mapme allows Stored XSS.This issue affects Mapme: from n/a through 1.3.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51913" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/mapme/wordpress-mapme-plugin-1-3-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-65pc-phr9-277f/GHSA-65pc-phr9-277f.json b/advisories/unreviewed/2024/11/GHSA-65pc-phr9-277f/GHSA-65pc-phr9-277f.json new file mode 100644 index 00000000000..6119512f350 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-65pc-phr9-277f/GHSA-65pc-phr9-277f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-65pc-phr9-277f", + "modified": "2024-11-19T18:31:04Z", + "published": "2024-11-19T18:31:04Z", + "aliases": [ + "CVE-2024-51905" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ravi & Suma RSV PDF Preview allows Stored XSS.This issue affects RSV PDF Preview: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51905" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/rsv-pdf-preview/wordpress-rsv-pdf-preview-plugin-1-0-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-66w7-vgc6-vh9v/GHSA-66w7-vgc6-vh9v.json b/advisories/unreviewed/2024/11/GHSA-66w7-vgc6-vh9v/GHSA-66w7-vgc6-vh9v.json new file mode 100644 index 00000000000..5bf11e44615 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-66w7-vgc6-vh9v/GHSA-66w7-vgc6-vh9v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-66w7-vgc6-vh9v", + "modified": "2024-11-19T18:31:05Z", + "published": "2024-11-19T18:31:05Z", + "aliases": [ + "CVE-2024-51937" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Information Analytics IA Map Analytics Basic allows DOM-Based XSS.This issue affects IA Map Analytics Basic: from n/a through 20170413.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51937" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ia-map-analytics-basic/wordpress-ia-map-analytics-basic-plugin-20170413-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-67c4-pjh7-g54h/GHSA-67c4-pjh7-g54h.json b/advisories/unreviewed/2024/11/GHSA-67c4-pjh7-g54h/GHSA-67c4-pjh7-g54h.json new file mode 100644 index 00000000000..17df7a8337d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-67c4-pjh7-g54h/GHSA-67c4-pjh7-g54h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-67c4-pjh7-g54h", + "modified": "2024-11-19T18:31:05Z", + "published": "2024-11-19T18:31:05Z", + "aliases": [ + "CVE-2024-51935" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sam Perrow Fast Video and Image Display allows DOM-Based XSS.This issue affects Fast Video and Image Display: from n/a through 2.5.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51935" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/fast-video-and-image-display/wordpress-fast-video-and-image-display-plugin-2-5-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-6999-6m26-m9xx/GHSA-6999-6m26-m9xx.json b/advisories/unreviewed/2024/11/GHSA-6999-6m26-m9xx/GHSA-6999-6m26-m9xx.json new file mode 100644 index 00000000000..02ed102bd39 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6999-6m26-m9xx/GHSA-6999-6m26-m9xx.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6999-6m26-m9xx", + "modified": "2024-11-19T18:31:06Z", + "published": "2024-11-19T18:31:06Z", + "aliases": [ + "CVE-2024-48069" + ], + "details": "A remote code execution (RCE) vulnerability in the component /inventory/doCptimpoptInventory of Weaver Ecology v9.* allows attackers to execute arbitrary code via injecting a crafted payload into the name of an uploaded file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48069" + }, + { + "type": "WEB", + "url": "https://gist.github.com/CoinIsMoney/5dd555805e8f974630ced8a1df8182f1" + }, + { + "type": "WEB", + "url": "https://github.com/stuven1989/TemporaryGuild/blob/main/guild2.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-69h8-v2gw-h8q9/GHSA-69h8-v2gw-h8q9.json b/advisories/unreviewed/2024/11/GHSA-69h8-v2gw-h8q9/GHSA-69h8-v2gw-h8q9.json new file mode 100644 index 00000000000..8472e60211e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-69h8-v2gw-h8q9/GHSA-69h8-v2gw-h8q9.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-69h8-v2gw-h8q9", + "modified": "2024-11-19T18:31:06Z", + "published": "2024-11-19T18:31:06Z", + "aliases": [ + "CVE-2024-53062" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: mgb4: protect driver against spectre\n\nFrequency range is set from sysfs via frequency_range_store(),\nbeing vulnerable to spectre, as reported by smatch:\n\n\tdrivers/media/pci/mgb4/mgb4_cmt.c:231 mgb4_cmt_set_vin_freq_range() warn: potential spectre issue 'cmt_vals_in' [r]\n\tdrivers/media/pci/mgb4/mgb4_cmt.c:238 mgb4_cmt_set_vin_freq_range() warn: possible spectre second half. 'reg_set'\n\nFix it.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53062" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2aee207e5b3c94ef859316008119ea06d6798d49" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e0bc90742bbd6eb9c63e6c22f8f6e10be7b1e225" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-6gpv-2g95-83h9/GHSA-6gpv-2g95-83h9.json b/advisories/unreviewed/2024/11/GHSA-6gpv-2g95-83h9/GHSA-6gpv-2g95-83h9.json new file mode 100644 index 00000000000..225c0deaf1b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6gpv-2g95-83h9/GHSA-6gpv-2g95-83h9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6gpv-2g95-83h9", + "modified": "2024-11-19T18:31:05Z", + "published": "2024-11-19T18:31:05Z", + "aliases": [ + "CVE-2024-52788" + ], + "details": "Tenda W9 v1.0.0.7(4456) was discovered to contain a hardcoded password vulnerability in /etc_ro/shadow, which allows attackers to log in as root.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52788" + }, + { + "type": "WEB", + "url": "https://colorful-meadow-5b9.notion.site/W9_HardCode_vuln-13dc216a1c30800fb31bdcdca7345ec3" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-6h6f-84wv-5rqq/GHSA-6h6f-84wv-5rqq.json b/advisories/unreviewed/2024/11/GHSA-6h6f-84wv-5rqq/GHSA-6h6f-84wv-5rqq.json index eadf9bf2cdf..544a236a16a 100644 --- a/advisories/unreviewed/2024/11/GHSA-6h6f-84wv-5rqq/GHSA-6h6f-84wv-5rqq.json +++ b/advisories/unreviewed/2024/11/GHSA-6h6f-84wv-5rqq/GHSA-6h6f-84wv-5rqq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6h6f-84wv-5rqq", - "modified": "2024-11-08T06:30:49Z", + "modified": "2024-11-19T18:30:54Z", "published": "2024-11-08T06:30:49Z", "aliases": [ "CVE-2024-50207" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nring-buffer: Fix reader locking when changing the sub buffer order\n\nThe function ring_buffer_subbuf_order_set() updates each\nring_buffer_per_cpu and installs new sub buffers that match the requested\npage order. This operation may be invoked concurrently with readers that\nrely on some of the modified data, such as the head bit (RB_PAGE_HEAD), or\nthe ring_buffer_per_cpu.pages and reader_page pointers. However, no\nexclusive access is acquired by ring_buffer_subbuf_order_set(). Modifying\nthe mentioned data while a reader also operates on them can then result in\nincorrect memory access and various crashes.\n\nFix the problem by taking the reader_lock when updating a specific\nring_buffer_per_cpu in ring_buffer_subbuf_order_set().", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-667" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-08T06:15:17Z" diff --git a/advisories/unreviewed/2024/11/GHSA-6jjx-758m-9gc4/GHSA-6jjx-758m-9gc4.json b/advisories/unreviewed/2024/11/GHSA-6jjx-758m-9gc4/GHSA-6jjx-758m-9gc4.json new file mode 100644 index 00000000000..8872903717f --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6jjx-758m-9gc4/GHSA-6jjx-758m-9gc4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6jjx-758m-9gc4", + "modified": "2024-11-19T18:31:01Z", + "published": "2024-11-19T18:31:01Z", + "aliases": [ + "CVE-2024-50532" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jerin K Alexander Events Manager Pro – extended allows Reflected XSS.This issue affects Events Manager Pro – extended: from n/a through 0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50532" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/events-manager-pro-extended/wordpress-events-manager-pro-extended-plugin-0-1-csrf-to-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-6jv4-h5x3-vxf3/GHSA-6jv4-h5x3-vxf3.json b/advisories/unreviewed/2024/11/GHSA-6jv4-h5x3-vxf3/GHSA-6jv4-h5x3-vxf3.json new file mode 100644 index 00000000000..a254cbed9c9 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6jv4-h5x3-vxf3/GHSA-6jv4-h5x3-vxf3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6jv4-h5x3-vxf3", + "modified": "2024-11-19T18:31:02Z", + "published": "2024-11-19T18:31:02Z", + "aliases": [ + "CVE-2024-51660" + ], + "details": "Missing Authorization vulnerability in Zakaria Binsaifullah Easy Accordion Gutenberg Block allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Accordion Gutenberg Block: from n/a through 1.2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51660" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/easy-accordion-block/wordpress-easy-accordion-gutenberg-block-plugin-1-2-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-6pj7-c745-c2mx/GHSA-6pj7-c745-c2mx.json b/advisories/unreviewed/2024/11/GHSA-6pj7-c745-c2mx/GHSA-6pj7-c745-c2mx.json new file mode 100644 index 00000000000..94dc7923a83 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6pj7-c745-c2mx/GHSA-6pj7-c745-c2mx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6pj7-c745-c2mx", + "modified": "2024-11-19T18:31:03Z", + "published": "2024-11-19T18:31:03Z", + "aliases": [ + "CVE-2024-51827" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Boombox Boombox Shortcode allows DOM-Based XSS.This issue affects Boombox Shortcode: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51827" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/boombox-shortcode/wordpress-boombox-shortcode-plugin-1-0-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-6pq4-p6m9-6r69/GHSA-6pq4-p6m9-6r69.json b/advisories/unreviewed/2024/11/GHSA-6pq4-p6m9-6r69/GHSA-6pq4-p6m9-6r69.json index a300ef605d7..f56ff45c439 100644 --- a/advisories/unreviewed/2024/11/GHSA-6pq4-p6m9-6r69/GHSA-6pq4-p6m9-6r69.json +++ b/advisories/unreviewed/2024/11/GHSA-6pq4-p6m9-6r69/GHSA-6pq4-p6m9-6r69.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6pq4-p6m9-6r69", - "modified": "2024-11-18T21:30:47Z", + "modified": "2024-11-19T18:30:59Z", "published": "2024-11-18T21:30:47Z", "aliases": [ "CVE-2024-50849" ], "details": "Cross-Site Scripting (XSS) in the \"Rules\" functionality in WordServer 11.8.2 allows a remote authenticated attacker to execute arbitrary code.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-18T21:15:06Z" diff --git a/advisories/unreviewed/2024/11/GHSA-6qgf-95ch-q924/GHSA-6qgf-95ch-q924.json b/advisories/unreviewed/2024/11/GHSA-6qgf-95ch-q924/GHSA-6qgf-95ch-q924.json new file mode 100644 index 00000000000..1b56b16de47 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6qgf-95ch-q924/GHSA-6qgf-95ch-q924.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6qgf-95ch-q924", + "modified": "2024-11-19T18:31:00Z", + "published": "2024-11-19T18:31:00Z", + "aliases": [ + "CVE-2024-50516" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Adam Skaat Countdown & Clock allows Stored XSS.This issue affects Countdown & Clock: from n/a through 2.8.0.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50516" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/countdown-builder/wordpress-countdown-clock-plugin-2-8-0-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-6rh5-p63w-qc58/GHSA-6rh5-p63w-qc58.json b/advisories/unreviewed/2024/11/GHSA-6rh5-p63w-qc58/GHSA-6rh5-p63w-qc58.json new file mode 100644 index 00000000000..4619eb2beb0 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6rh5-p63w-qc58/GHSA-6rh5-p63w-qc58.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6rh5-p63w-qc58", + "modified": "2024-11-19T18:31:01Z", + "published": "2024-11-19T18:31:01Z", + "aliases": [ + "CVE-2024-51640" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Matt Rude MDR Webmaster Tools allows Stored XSS.This issue affects MDR Webmaster Tools: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51640" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/mdr-webmaster-tools/wordpress-mdr-webmaster-tools-plugin-1-1-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-6v28-4x74-3hpj/GHSA-6v28-4x74-3hpj.json b/advisories/unreviewed/2024/11/GHSA-6v28-4x74-3hpj/GHSA-6v28-4x74-3hpj.json new file mode 100644 index 00000000000..13a003e82b2 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6v28-4x74-3hpj/GHSA-6v28-4x74-3hpj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6v28-4x74-3hpj", + "modified": "2024-11-19T18:31:04Z", + "published": "2024-11-19T18:31:04Z", + "aliases": [ + "CVE-2024-51862" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Baptiste Wicht Google Visualization Charts allows Stored XSS.This issue affects Google Visualization Charts: from n/a through 0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51862" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/google-visualization-charts/wordpress-google-visualization-charts-plugin-0-1-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-6vqc-w6hm-2r5w/GHSA-6vqc-w6hm-2r5w.json b/advisories/unreviewed/2024/11/GHSA-6vqc-w6hm-2r5w/GHSA-6vqc-w6hm-2r5w.json new file mode 100644 index 00000000000..0816089792b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6vqc-w6hm-2r5w/GHSA-6vqc-w6hm-2r5w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6vqc-w6hm-2r5w", + "modified": "2024-11-19T18:31:03Z", + "published": "2024-11-19T18:31:03Z", + "aliases": [ + "CVE-2024-51828" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Daniel J Griffiths Beacon For Help Scout allows DOM-Based XSS.This issue affects Beacon For Help Scout: from n/a through 1.3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51828" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/beacon-for-helpscout/wordpress-beacon-for-help-scout-plugin-1-3-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-6w26-4vm6-c7f2/GHSA-6w26-4vm6-c7f2.json b/advisories/unreviewed/2024/11/GHSA-6w26-4vm6-c7f2/GHSA-6w26-4vm6-c7f2.json new file mode 100644 index 00000000000..fe7bb27a577 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6w26-4vm6-c7f2/GHSA-6w26-4vm6-c7f2.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6w26-4vm6-c7f2", + "modified": "2024-11-19T18:31:07Z", + "published": "2024-11-19T18:31:07Z", + "aliases": [ + "CVE-2024-53086" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe: Drop VM dma-resv lock on xe_sync_in_fence_get failure in exec IOCTL\n\nUpon failure all locks need to be dropped before returning to the user.\n\n(cherry picked from commit 7d1a4258e602ffdce529f56686925034c1b3b095)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53086" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/64a2b6ed4bfd890a0e91955dd8ef8422a3944ed9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/96397b1e25dda8389dea63ec914038a170bf953d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-7259-cwhj-xf2j/GHSA-7259-cwhj-xf2j.json b/advisories/unreviewed/2024/11/GHSA-7259-cwhj-xf2j/GHSA-7259-cwhj-xf2j.json new file mode 100644 index 00000000000..9a5f22fe303 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-7259-cwhj-xf2j/GHSA-7259-cwhj-xf2j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7259-cwhj-xf2j", + "modified": "2024-11-19T18:31:01Z", + "published": "2024-11-19T18:31:01Z", + "aliases": [ + "CVE-2024-51644" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Sam Wilson Addressbook allows Stored XSS.This issue affects Addressbook: from n/a through 1.1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51644" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/addressbook/wordpress-addressbook-plugin-1-1-3-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-73c2-2543-rv69/GHSA-73c2-2543-rv69.json b/advisories/unreviewed/2024/11/GHSA-73c2-2543-rv69/GHSA-73c2-2543-rv69.json new file mode 100644 index 00000000000..f84578a0ce7 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-73c2-2543-rv69/GHSA-73c2-2543-rv69.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-73c2-2543-rv69", + "modified": "2024-11-19T18:31:03Z", + "published": "2024-11-19T18:31:03Z", + "aliases": [ + "CVE-2024-51832" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Plenigo Plenigo allows Stored XSS.This issue affects Plenigo: from n/a through 1.12.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51832" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/plenigo/wordpress-plenigo-plugin-1-12-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-73h5-69j6-pq7f/GHSA-73h5-69j6-pq7f.json b/advisories/unreviewed/2024/11/GHSA-73h5-69j6-pq7f/GHSA-73h5-69j6-pq7f.json new file mode 100644 index 00000000000..2f9e0486db8 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-73h5-69j6-pq7f/GHSA-73h5-69j6-pq7f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-73h5-69j6-pq7f", + "modified": "2024-11-19T18:31:01Z", + "published": "2024-11-19T18:31:01Z", + "aliases": [ + "CVE-2024-50551" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alessandro Staniscia EndomondoWP allows Stored XSS.This issue affects EndomondoWP: from n/a through 0.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50551" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/endomondowp/wordpress-endomondowp-plugin-0-1-1-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-74rr-c455-62vq/GHSA-74rr-c455-62vq.json b/advisories/unreviewed/2024/11/GHSA-74rr-c455-62vq/GHSA-74rr-c455-62vq.json new file mode 100644 index 00000000000..2ba2e86c11b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-74rr-c455-62vq/GHSA-74rr-c455-62vq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-74rr-c455-62vq", + "modified": "2024-11-19T18:31:06Z", + "published": "2024-11-19T18:31:06Z", + "aliases": [ + "CVE-2018-9338" + ], + "details": "In ResStringPool::setTo of ResourceTypes.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9338" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-06-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-75f9-w444-4xg7/GHSA-75f9-w444-4xg7.json b/advisories/unreviewed/2024/11/GHSA-75f9-w444-4xg7/GHSA-75f9-w444-4xg7.json new file mode 100644 index 00000000000..cb6a1d50d8c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-75f9-w444-4xg7/GHSA-75f9-w444-4xg7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-75f9-w444-4xg7", + "modified": "2024-11-19T18:31:03Z", + "published": "2024-11-19T18:31:03Z", + "aliases": [ + "CVE-2024-51854" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hola Networks Hola Free Video Player allows DOM-Based XSS.This issue affects Hola Free Video Player: from n/a through 1.3.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51854" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/hola-free-video-player/wordpress-hola-free-video-player-plugin-1-3-9-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-7866-w9g3-g699/GHSA-7866-w9g3-g699.json b/advisories/unreviewed/2024/11/GHSA-7866-w9g3-g699/GHSA-7866-w9g3-g699.json new file mode 100644 index 00000000000..d4c66f6ceba --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-7866-w9g3-g699/GHSA-7866-w9g3-g699.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7866-w9g3-g699", + "modified": "2024-11-19T18:31:07Z", + "published": "2024-11-19T18:31:07Z", + "aliases": [ + "CVE-2024-53075" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nriscv: Prevent a bad reference count on CPU nodes\n\nWhen populating cache leaves we previously fetched the CPU device node\nat the very beginning. But when ACPI is enabled we go through a\nspecific branch which returns early and does not call 'of_node_put' for\nthe node that was acquired.\n\nSince we are not using a CPU device node for the ACPI code anyways, we\ncan simply move the initialization of it just passed the ACPI block, and\nwe are guaranteed to have an 'of_node_put' call for the acquired node.\nThis prevents a bad reference count of the CPU device node.\n\nMoreover, the previous function did not check for errors when acquiring\nthe device node, so a return -ENOENT has been added for that case.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53075" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/303846a3dc275e35fbb556d72f1e356ba669e4f8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/37233169a6ea912020c572f870075a63293b786a" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-78xf-x743-mmc6/GHSA-78xf-x743-mmc6.json b/advisories/unreviewed/2024/11/GHSA-78xf-x743-mmc6/GHSA-78xf-x743-mmc6.json new file mode 100644 index 00000000000..9afa804d3be --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-78xf-x743-mmc6/GHSA-78xf-x743-mmc6.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-78xf-x743-mmc6", + "modified": "2024-11-19T18:31:07Z", + "published": "2024-11-19T18:31:07Z", + "aliases": [ + "CVE-2024-53061" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: s5p-jpeg: prevent buffer overflows\n\nThe current logic allows word to be less than 2. If this happens,\nthere will be buffer overflows, as reported by smatch. Add extra\nchecks to prevent it.\n\nWhile here, remove an unused word = 0 assignment.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53061" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/14a22762c3daeac59a5a534e124acbb4d7a79b3a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/784bc785a453eb2f8433dd62075befdfa1b2d6fd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a930cddfd153b5d4401df0c01effa14c831ff21e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c5f6fefcda8fac8f082b6c5bf416567f4e100c51" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c85db2d4432de4ff9d97006691ce2dcb5bda660e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c951a0859fdacf49a2298b5551a7e52b95ff6f51" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e5117f6e7adcf9fd7546cdd0edc9abe4474bc98b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f54e8e1e39dacccebcfb9a9a36f0552a0a97e2ef" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-79f9-q2cg-p5x7/GHSA-79f9-q2cg-p5x7.json b/advisories/unreviewed/2024/11/GHSA-79f9-q2cg-p5x7/GHSA-79f9-q2cg-p5x7.json new file mode 100644 index 00000000000..828700f3f65 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-79f9-q2cg-p5x7/GHSA-79f9-q2cg-p5x7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-79f9-q2cg-p5x7", + "modified": "2024-11-19T18:31:03Z", + "published": "2024-11-19T18:31:03Z", + "aliases": [ + "CVE-2024-51858" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Umar Social Locker allows Stored XSS.This issue affects Social Locker: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51858" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/social-locker-content/wordpress-social-locker-plugin-1-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-7c65-3hqv-hvmm/GHSA-7c65-3hqv-hvmm.json b/advisories/unreviewed/2024/11/GHSA-7c65-3hqv-hvmm/GHSA-7c65-3hqv-hvmm.json new file mode 100644 index 00000000000..e4ed92052e0 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-7c65-3hqv-hvmm/GHSA-7c65-3hqv-hvmm.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7c65-3hqv-hvmm", + "modified": "2024-11-19T18:31:06Z", + "published": "2024-11-19T18:31:06Z", + "aliases": [ + "CVE-2024-48990" + ], + "details": "Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Python interpreter with an attacker-controlled PYTHONPATH environment variable.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48990" + }, + { + "type": "WEB", + "url": "https://github.com/liske/needrestart/commit/fcc9a4401392231bef4ef5ed026a0d7a275149ab" + }, + { + "type": "WEB", + "url": "https://www.cve.org/CVERecord?id=CVE-2024-48990" + }, + { + "type": "WEB", + "url": "https://www.qualys.com/2024/11/19/needrestart/needrestart.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-7ghh-hpqx-6wf8/GHSA-7ghh-hpqx-6wf8.json b/advisories/unreviewed/2024/11/GHSA-7ghh-hpqx-6wf8/GHSA-7ghh-hpqx-6wf8.json new file mode 100644 index 00000000000..2967f9449a6 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-7ghh-hpqx-6wf8/GHSA-7ghh-hpqx-6wf8.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7ghh-hpqx-6wf8", + "modified": "2024-11-19T18:31:07Z", + "published": "2024-11-19T18:31:07Z", + "aliases": [ + "CVE-2024-53074" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: mvm: don't leak a link on AP removal\n\nRelease the link mapping resource in AP removal. This impacted devices\nthat do not support the MLD API (9260 and down).\nOn those devices, we couldn't start the AP again after the AP has been\nalready started and stopped.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53074" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3ed092997a004d68a3a5b0eeb94e71b69839d0f7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/70ddf9ce1894c48dbbf10b0de51a95e4fb3dd376" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-7h32-65hg-rrp7/GHSA-7h32-65hg-rrp7.json b/advisories/unreviewed/2024/11/GHSA-7h32-65hg-rrp7/GHSA-7h32-65hg-rrp7.json new file mode 100644 index 00000000000..78ee5dd9e6f --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-7h32-65hg-rrp7/GHSA-7h32-65hg-rrp7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7h32-65hg-rrp7", + "modified": "2024-11-19T18:31:02Z", + "published": "2024-11-19T18:31:02Z", + "aliases": [ + "CVE-2024-51686" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Deepak Khokhar, Surender Khokhar Manage User Columns allows Cross Site Request Forgery.This issue affects Manage User Columns: from n/a through 1.0.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51686" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/manage-user-columns/wordpress-manage-user-columns-plugin-1-0-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-7hr9-vfjf-38m4/GHSA-7hr9-vfjf-38m4.json b/advisories/unreviewed/2024/11/GHSA-7hr9-vfjf-38m4/GHSA-7hr9-vfjf-38m4.json new file mode 100644 index 00000000000..6a1510c7970 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-7hr9-vfjf-38m4/GHSA-7hr9-vfjf-38m4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7hr9-vfjf-38m4", + "modified": "2024-11-19T18:31:04Z", + "published": "2024-11-19T18:31:04Z", + "aliases": [ + "CVE-2024-51869" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Best WP Developer Gutenium Blocks allows Stored XSS.This issue affects Gutenium Blocks: from n/a through 1.1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51869" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/gutenium/wordpress-gutenium-blocks-plugin-1-1-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-7hwj-x2vh-jqv9/GHSA-7hwj-x2vh-jqv9.json b/advisories/unreviewed/2024/11/GHSA-7hwj-x2vh-jqv9/GHSA-7hwj-x2vh-jqv9.json new file mode 100644 index 00000000000..d9c1f8472a7 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-7hwj-x2vh-jqv9/GHSA-7hwj-x2vh-jqv9.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7hwj-x2vh-jqv9", + "modified": "2024-11-19T18:31:07Z", + "published": "2024-11-19T18:31:07Z", + "aliases": [ + "CVE-2024-53063" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: dvbdev: prevent the risk of out of memory access\n\nThe dvbdev contains a static variable used to store dvb minors.\n\nThe behavior of it depends if CONFIG_DVB_DYNAMIC_MINORS is set\nor not. When not set, dvb_register_device() won't check for\nboundaries, as it will rely that a previous call to\ndvb_register_adapter() would already be enforcing it.\n\nOn a similar way, dvb_device_open() uses the assumption\nthat the register functions already did the needed checks.\n\nThis can be fragile if some device ends using different\ncalls. This also generate warnings on static check analysers\nlike Coverity.\n\nSo, add explicit guards to prevent potential risk of OOM issues.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53063" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1e461672616b726f29261ee81bb991528818537c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3b88675e18b6517043a6f734eaa8ea6eb3bfa140" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5f76f7df14861e3a560898fa41979ec92424b58f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/972e63e895abbe8aa1ccbdbb4e6362abda7cd457" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9c17085fabbde2041c893d29599800f2d4992b23" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a4a17210c03ade1c8d9a9f193a105654b7a05c11" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b751a96025275c17f04083cbfe856822f1658946" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fedfde9deb83ac8d2f3d5f36f111023df34b1684" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-7mjf-5rrm-399r/GHSA-7mjf-5rrm-399r.json b/advisories/unreviewed/2024/11/GHSA-7mjf-5rrm-399r/GHSA-7mjf-5rrm-399r.json new file mode 100644 index 00000000000..f0f82f9f06b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-7mjf-5rrm-399r/GHSA-7mjf-5rrm-399r.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7mjf-5rrm-399r", + "modified": "2024-11-19T18:31:07Z", + "published": "2024-11-19T18:31:07Z", + "aliases": [ + "CVE-2024-53084" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/imagination: Break an object reference loop\n\nWhen remaining resources are being cleaned up on driver close,\noutstanding VM mappings may result in resources being leaked, due\nto an object reference loop, as shown below, with each object (or\nset of objects) referencing the object below it:\n\n PVR GEM Object\n GPU scheduler \"finished\" fence\n GPU scheduler “scheduled” fence\n PVR driver “done” fence\n PVR Context\n PVR VM Context\n PVR VM Mappings\n PVR GEM Object\n\nThe reference that the PVR VM Context has on the VM mappings is a\nsoft one, in the sense that the freeing of outstanding VM mappings\nis done as part of VM context destruction; no reference counts are\ninvolved, as is the case for all the other references in the loop.\n\nTo break the reference loop during cleanup, free the outstanding\nVM mappings before destroying the PVR Context associated with the\nVM context.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53084" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b04ce1e718bd55302b52d05d6873e233cb3ec7a1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cb86db12b290ed07d05df00d99fa150bb123e80e" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-7q26-9p5f-2xq5/GHSA-7q26-9p5f-2xq5.json b/advisories/unreviewed/2024/11/GHSA-7q26-9p5f-2xq5/GHSA-7q26-9p5f-2xq5.json new file mode 100644 index 00000000000..e4f146e9c0d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-7q26-9p5f-2xq5/GHSA-7q26-9p5f-2xq5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7q26-9p5f-2xq5", + "modified": "2024-11-19T18:31:05Z", + "published": "2024-11-19T18:31:05Z", + "aliases": [ + "CVE-2024-51930" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jie Wang Custom URL Shortener allows Stored XSS.This issue affects Custom URL Shortener: from n/a through 0.3.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51930" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/custom-url-shorter/wordpress-custom-url-shortener-plugin-0-3-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-8348-jmhf-5pcj/GHSA-8348-jmhf-5pcj.json b/advisories/unreviewed/2024/11/GHSA-8348-jmhf-5pcj/GHSA-8348-jmhf-5pcj.json new file mode 100644 index 00000000000..f803cc6a3de --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-8348-jmhf-5pcj/GHSA-8348-jmhf-5pcj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8348-jmhf-5pcj", + "modified": "2024-11-19T18:31:05Z", + "published": "2024-11-19T18:31:05Z", + "aliases": [ + "CVE-2024-51933" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Christian Ladewig Cookie Nonsense for YT allows DOM-Based XSS.This issue affects Cookie Nonsense for YT: from n/a through 1.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51933" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/yt-cookie-nonsense/wordpress-cookie-nonsense-for-yt-plugin-1-2-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-84vq-r732-qrg9/GHSA-84vq-r732-qrg9.json b/advisories/unreviewed/2024/11/GHSA-84vq-r732-qrg9/GHSA-84vq-r732-qrg9.json new file mode 100644 index 00000000000..124c9a7055b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-84vq-r732-qrg9/GHSA-84vq-r732-qrg9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-84vq-r732-qrg9", + "modified": "2024-11-19T18:31:04Z", + "published": "2024-11-19T18:31:04Z", + "aliases": [ + "CVE-2024-51878" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joey Straile AchillesTheme-shortcodes allows DOM-Based XSS.This issue affects AchillesTheme-shortcodes: from n/a through 0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51878" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/achilles-shortcodes/wordpress-achillestheme-shortcodes-plugin-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-874j-2w8f-c73r/GHSA-874j-2w8f-c73r.json b/advisories/unreviewed/2024/11/GHSA-874j-2w8f-c73r/GHSA-874j-2w8f-c73r.json new file mode 100644 index 00000000000..778755896a5 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-874j-2w8f-c73r/GHSA-874j-2w8f-c73r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-874j-2w8f-c73r", + "modified": "2024-11-19T18:31:05Z", + "published": "2024-11-19T18:31:05Z", + "aliases": [ + "CVE-2024-51910" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mauro Cordioli Assist24 Help Desk allows DOM-Based XSS.This issue affects Assist24 Help Desk: from n/a through 20150401.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51910" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/assist24it/wordpress-assist24-help-desk-plugin-20150401-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-87q3-4f3j-74q7/GHSA-87q3-4f3j-74q7.json b/advisories/unreviewed/2024/11/GHSA-87q3-4f3j-74q7/GHSA-87q3-4f3j-74q7.json index 4c54d3043a6..5d9b14be276 100644 --- a/advisories/unreviewed/2024/11/GHSA-87q3-4f3j-74q7/GHSA-87q3-4f3j-74q7.json +++ b/advisories/unreviewed/2024/11/GHSA-87q3-4f3j-74q7/GHSA-87q3-4f3j-74q7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-87q3-4f3j-74q7", - "modified": "2024-11-18T21:30:46Z", + "modified": "2024-11-19T18:30:58Z", "published": "2024-11-18T21:30:46Z", "aliases": [ "CVE-2024-48294" ], "details": "A NULL pointer dereference in the component libPdfCore.dll of Wondershare PDF Reader v1.0.9.2544 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-18T19:15:05Z" diff --git a/advisories/unreviewed/2024/11/GHSA-87vp-wcxm-f9g2/GHSA-87vp-wcxm-f9g2.json b/advisories/unreviewed/2024/11/GHSA-87vp-wcxm-f9g2/GHSA-87vp-wcxm-f9g2.json new file mode 100644 index 00000000000..72033213f9d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-87vp-wcxm-f9g2/GHSA-87vp-wcxm-f9g2.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-87vp-wcxm-f9g2", + "modified": "2024-11-19T18:31:07Z", + "published": "2024-11-19T18:31:06Z", + "aliases": [ + "CVE-2024-53064" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nidpf: fix idpf_vc_core_init error path\n\nIn an event where the platform running the device control plane\nis rebooted, reset is detected on the driver. It releases\nall the resources and waits for the reset to complete. Once the\nreset is done, it tries to build the resources back. At this\ntime if the device control plane is not yet started, then\nthe driver timeouts on the virtchnl message and retries to\nestablish the mailbox again.\n\nIn the retry flow, mailbox is deinitialized but the mailbox\nworkqueue is still alive and polling for the mailbox message.\nThis results in accessing the released control queue leading to\nnull-ptr-deref. Fix it by unrolling the work queue cancellation\nand mailbox deinitialization in the reverse order which they got\ninitialized.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53064" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/683fcd90ba22507ebeb1921a26dfe77efff8c266" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9b58031ff96b84a38d7b73b23c7ecfb2e0557f43" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-88vw-5p88-2p6c/GHSA-88vw-5p88-2p6c.json b/advisories/unreviewed/2024/11/GHSA-88vw-5p88-2p6c/GHSA-88vw-5p88-2p6c.json new file mode 100644 index 00000000000..b53af694139 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-88vw-5p88-2p6c/GHSA-88vw-5p88-2p6c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-88vw-5p88-2p6c", + "modified": "2024-11-19T18:31:03Z", + "published": "2024-11-19T18:31:03Z", + "aliases": [ + "CVE-2024-51833" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noman Akhtar Easy Social Sharebar allows Stored XSS.This issue affects Easy Social Sharebar: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51833" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/easy-social-sharebar/wordpress-easy-social-sharebar-plugin-1-0-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-8cp8-922f-xc53/GHSA-8cp8-922f-xc53.json b/advisories/unreviewed/2024/11/GHSA-8cp8-922f-xc53/GHSA-8cp8-922f-xc53.json new file mode 100644 index 00000000000..3670fe6cc12 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-8cp8-922f-xc53/GHSA-8cp8-922f-xc53.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8cp8-922f-xc53", + "modified": "2024-11-19T18:31:05Z", + "published": "2024-11-19T18:31:05Z", + "aliases": [ + "CVE-2024-52395" + ], + "details": "Missing Authorization vulnerability in QunatumCloud Floating Buttons for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Floating Buttons for WooCommerce: from n/a through 2.8.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52395" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/shop-assistant-for-woocommerce-jarvis/wordpress-floating-buttons-for-woocommerce-plugin-2-8-8-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-8cq9-rv8g-3wpg/GHSA-8cq9-rv8g-3wpg.json b/advisories/unreviewed/2024/11/GHSA-8cq9-rv8g-3wpg/GHSA-8cq9-rv8g-3wpg.json new file mode 100644 index 00000000000..e60fbed5420 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-8cq9-rv8g-3wpg/GHSA-8cq9-rv8g-3wpg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8cq9-rv8g-3wpg", + "modified": "2024-11-19T18:31:01Z", + "published": "2024-11-19T18:31:01Z", + "aliases": [ + "CVE-2024-50540" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DemixPress (dp) AddThis allows Stored XSS.This issue affects (dp) AddThis: from n/a through 1.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50540" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/dp-addthis/wordpress-dp-addthis-plugin-1-0-2-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-8frm-8r9v-j76p/GHSA-8frm-8r9v-j76p.json b/advisories/unreviewed/2024/11/GHSA-8frm-8r9v-j76p/GHSA-8frm-8r9v-j76p.json new file mode 100644 index 00000000000..c310d2c8d73 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-8frm-8r9v-j76p/GHSA-8frm-8r9v-j76p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8frm-8r9v-j76p", + "modified": "2024-11-19T18:31:04Z", + "published": "2024-11-19T18:31:04Z", + "aliases": [ + "CVE-2024-51892" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in naa986 Sell Media File with Stripe allows Stored XSS.This issue affects Sell Media File with Stripe: from n/a through 1.0.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51892" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/sell-media-file/wordpress-sell-media-file-with-stripe-plugin-1-0-6-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-8gqp-w9h7-vrxp/GHSA-8gqp-w9h7-vrxp.json b/advisories/unreviewed/2024/11/GHSA-8gqp-w9h7-vrxp/GHSA-8gqp-w9h7-vrxp.json new file mode 100644 index 00000000000..e5684e57d85 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-8gqp-w9h7-vrxp/GHSA-8gqp-w9h7-vrxp.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8gqp-w9h7-vrxp", + "modified": "2024-11-19T18:31:07Z", + "published": "2024-11-19T18:31:07Z", + "aliases": [ + "CVE-2024-53087" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe: Fix possible exec queue leak in exec IOCTL\n\nIn a couple of places after an exec queue is looked up the exec IOCTL\nreturns on input errors without dropping the exec queue ref. Fix this\nensuring the exec queue ref is dropped on input error.\n\n(cherry picked from commit 07064a200b40ac2195cb6b7b779897d9377e5e6f)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53087" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2f92b77a8ce043fbda2664d9be4b66bdc57f67b7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/af797b831d8975cb4610f396dcb7f03f4b9908e7" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-8hgx-89h7-3vhm/GHSA-8hgx-89h7-3vhm.json b/advisories/unreviewed/2024/11/GHSA-8hgx-89h7-3vhm/GHSA-8hgx-89h7-3vhm.json new file mode 100644 index 00000000000..106dab43aa5 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-8hgx-89h7-3vhm/GHSA-8hgx-89h7-3vhm.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8hgx-89h7-3vhm", + "modified": "2024-11-19T18:31:06Z", + "published": "2024-11-19T18:31:06Z", + "aliases": [ + "CVE-2024-53046" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\narm64: dts: imx8ulp: correct the flexspi compatible string\n\nThe flexspi on imx8ulp only has 16 LUTs, and imx8mm flexspi has\n32 LUTs, so correct the compatible string here, otherwise will\nmeet below error:\n\n[ 1.119072] ------------[ cut here ]------------\n[ 1.123926] WARNING: CPU: 0 PID: 1 at drivers/spi/spi-nxp-fspi.c:855 nxp_fspi_exec_op+0xb04/0xb64\n[ 1.133239] Modules linked in:\n[ 1.136448] CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Not tainted 6.11.0-rc6-next-20240902-00001-g131bf9439dd9 #69\n[ 1.146821] Hardware name: NXP i.MX8ULP EVK (DT)\n[ 1.151647] pstate: 40000005 (nZcv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n[ 1.158931] pc : nxp_fspi_exec_op+0xb04/0xb64\n[ 1.163496] lr : nxp_fspi_exec_op+0xa34/0xb64\n[ 1.168060] sp : ffff80008002b2a0\n[ 1.171526] x29: ffff80008002b2d0 x28: 0000000000000000 x27: 0000000000000000\n[ 1.179002] x26: ffff2eb645542580 x25: ffff800080610014 x24: ffff800080610000\n[ 1.186480] x23: ffff2eb645548080 x22: 0000000000000006 x21: ffff2eb6455425e0\n[ 1.193956] x20: 0000000000000000 x19: ffff80008002b5e0 x18: ffffffffffffffff\n[ 1.201432] x17: ffff2eb644467508 x16: 0000000000000138 x15: 0000000000000002\n[ 1.208907] x14: 0000000000000000 x13: ffff2eb6400d8080 x12: 00000000ffffff00\n[ 1.216378] x11: 0000000000000000 x10: ffff2eb6400d8080 x9 : ffff2eb697adca80\n[ 1.223850] x8 : ffff2eb697ad3cc0 x7 : 0000000100000000 x6 : 0000000000000001\n[ 1.231324] x5 : 0000000000000000 x4 : 0000000000000000 x3 : 00000000000007a6\n[ 1.238795] x2 : 0000000000000000 x1 : 00000000000001ce x0 : 00000000ffffff92\n[ 1.246267] Call trace:\n[ 1.248824] nxp_fspi_exec_op+0xb04/0xb64\n[ 1.253031] spi_mem_exec_op+0x3a0/0x430\n[ 1.257139] spi_nor_read_id+0x80/0xcc\n[ 1.261065] spi_nor_scan+0x1ec/0xf10\n[ 1.264901] spi_nor_probe+0x108/0x2fc\n[ 1.268828] spi_mem_probe+0x6c/0xbc\n[ 1.272574] spi_probe+0x84/0xe4\n[ 1.275958] really_probe+0xbc/0x29c\n[ 1.279713] __driver_probe_device+0x78/0x12c\n[ 1.284277] driver_probe_device+0xd8/0x15c\n[ 1.288660] __device_attach_driver+0xb8/0x134\n[ 1.293316] bus_for_each_drv+0x88/0xe8\n[ 1.297337] __device_attach+0xa0/0x190\n[ 1.301353] device_initial_probe+0x14/0x20\n[ 1.305734] bus_probe_device+0xac/0xb0\n[ 1.309752] device_add+0x5d0/0x790\n[ 1.313408] __spi_add_device+0x134/0x204\n[ 1.317606] of_register_spi_device+0x3b4/0x590\n[ 1.322348] spi_register_controller+0x47c/0x754\n[ 1.327181] devm_spi_register_controller+0x4c/0xa4\n[ 1.332289] nxp_fspi_probe+0x1cc/0x2b0\n[ 1.336307] platform_probe+0x68/0xc4\n[ 1.340145] really_probe+0xbc/0x29c\n[ 1.343893] __driver_probe_device+0x78/0x12c\n[ 1.348457] driver_probe_device+0xd8/0x15c\n[ 1.352838] __driver_attach+0x90/0x19c\n[ 1.356857] bus_for_each_dev+0x7c/0xdc\n[ 1.360877] driver_attach+0x24/0x30\n[ 1.364624] bus_add_driver+0xe4/0x208\n[ 1.368552] driver_register+0x5c/0x124\n[ 1.372573] __platform_driver_register+0x28/0x34\n[ 1.377497] nxp_fspi_driver_init+0x1c/0x28\n[ 1.381888] do_one_initcall+0x80/0x1c8\n[ 1.385908] kernel_init_freeable+0x1c4/0x28c\n[ 1.390472] kernel_init+0x20/0x1d8\n[ 1.394138] ret_from_fork+0x10/0x20\n[ 1.397885] ---[ end trace 0000000000000000 ]---\n[ 1.407908] ------------[ cut here ]------------", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53046" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/409dc5196d5b6eb67468a06bf4d2d07d7225a67b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c3c02fa6a560b3af7999a067cd387970f4b3f1fa" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e3fb0e6afcc399660770428a35162b4880e2e14e" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-8hj6-f2qf-5rxh/GHSA-8hj6-f2qf-5rxh.json b/advisories/unreviewed/2024/11/GHSA-8hj6-f2qf-5rxh/GHSA-8hj6-f2qf-5rxh.json new file mode 100644 index 00000000000..c5bae12911d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-8hj6-f2qf-5rxh/GHSA-8hj6-f2qf-5rxh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8hj6-f2qf-5rxh", + "modified": "2024-11-19T18:31:02Z", + "published": "2024-11-19T18:31:02Z", + "aliases": [ + "CVE-2024-51796" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPManageNinja Trendy Restaurant Menu allows DOM-Based XSS.This issue affects Trendy Restaurant Menu: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51796" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/trendy-restaurant-menu/wordpress-trendy-restaurant-menu-plugin-1-0-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-8j46-pm7j-wh94/GHSA-8j46-pm7j-wh94.json b/advisories/unreviewed/2024/11/GHSA-8j46-pm7j-wh94/GHSA-8j46-pm7j-wh94.json new file mode 100644 index 00000000000..e7409917931 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-8j46-pm7j-wh94/GHSA-8j46-pm7j-wh94.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8j46-pm7j-wh94", + "modified": "2024-11-19T18:31:05Z", + "published": "2024-11-19T18:31:05Z", + "aliases": [ + "CVE-2024-52789" + ], + "details": "Tenda W30E v2.0 V16.01.0.8 was discovered to contain a hardcoded password vulnerability in /etc_ro/shadow, which allows attackers to log in as root.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52789" + }, + { + "type": "WEB", + "url": "https://colorful-meadow-5b9.notion.site/W30E_HardCode_vuln-13dc216a1c30805998f8d994f966760a" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-8qpp-hcww-69wh/GHSA-8qpp-hcww-69wh.json b/advisories/unreviewed/2024/11/GHSA-8qpp-hcww-69wh/GHSA-8qpp-hcww-69wh.json new file mode 100644 index 00000000000..5bf722f676f --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-8qpp-hcww-69wh/GHSA-8qpp-hcww-69wh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8qpp-hcww-69wh", + "modified": "2024-11-19T18:31:00Z", + "published": "2024-11-19T18:31:00Z", + "aliases": [ + "CVE-2024-50517" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SlovenskoIT a.s. ID-SK Toolkit allows Stored XSS.This issue affects ID-SK Toolkit: from n/a through 1.7.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50517" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/idsk-toolkit/wordpress-id-sk-toolkit-plugin-1-7-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-8vf7-6fh2-6qw4/GHSA-8vf7-6fh2-6qw4.json b/advisories/unreviewed/2024/11/GHSA-8vf7-6fh2-6qw4/GHSA-8vf7-6fh2-6qw4.json index b1c0c393c8a..9bcb86677e0 100644 --- a/advisories/unreviewed/2024/11/GHSA-8vf7-6fh2-6qw4/GHSA-8vf7-6fh2-6qw4.json +++ b/advisories/unreviewed/2024/11/GHSA-8vf7-6fh2-6qw4/GHSA-8vf7-6fh2-6qw4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8vf7-6fh2-6qw4", - "modified": "2024-11-18T21:30:46Z", + "modified": "2024-11-19T18:30:59Z", "published": "2024-11-18T21:30:46Z", "aliases": [ "CVE-2024-50919" ], "details": "Jpress until v5.1.1 has arbitrary file uploads on the windows platform, and the construction of non-standard file formats such as .jsp. can lead to arbitrary command execution", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-18T20:15:05Z" diff --git a/advisories/unreviewed/2024/11/GHSA-8vpp-w76f-8mx8/GHSA-8vpp-w76f-8mx8.json b/advisories/unreviewed/2024/11/GHSA-8vpp-w76f-8mx8/GHSA-8vpp-w76f-8mx8.json index 314c415c281..48ae095f2ab 100644 --- a/advisories/unreviewed/2024/11/GHSA-8vpp-w76f-8mx8/GHSA-8vpp-w76f-8mx8.json +++ b/advisories/unreviewed/2024/11/GHSA-8vpp-w76f-8mx8/GHSA-8vpp-w76f-8mx8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8vpp-w76f-8mx8", - "modified": "2024-11-15T21:30:46Z", + "modified": "2024-11-19T18:30:57Z", "published": "2024-11-15T21:30:46Z", "aliases": [ "CVE-2024-24446" ], "details": "An uninitialized pointer dereference in OpenAirInterface CN5G AMF up to v2.0.0 allows attackers to cause a Denial of Service (DoS) via a crafted InitialContextSetupResponse message sent to the AMF.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-15T19:15:06Z" diff --git a/advisories/unreviewed/2024/11/GHSA-8vv8-fmp2-x4c4/GHSA-8vv8-fmp2-x4c4.json b/advisories/unreviewed/2024/11/GHSA-8vv8-fmp2-x4c4/GHSA-8vv8-fmp2-x4c4.json new file mode 100644 index 00000000000..d8e568542f6 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-8vv8-fmp2-x4c4/GHSA-8vv8-fmp2-x4c4.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8vv8-fmp2-x4c4", + "modified": "2024-11-19T18:31:07Z", + "published": "2024-11-19T18:31:07Z", + "aliases": [ + "CVE-2024-53085" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntpm: Lock TPM chip in tpm_pm_suspend() first\n\nSetting TPM_CHIP_FLAG_SUSPENDED in the end of tpm_pm_suspend() can be racy\naccording, as this leaves window for tpm_hwrng_read() to be called while\nthe operation is in progress. The recent bug report gives also evidence of\nthis behaviour.\n\nAadress this by locking the TPM chip before checking any chip->flags both\nin tpm_pm_suspend() and tpm_hwrng_read(). Move TPM_CHIP_FLAG_SUSPENDED\ncheck inside tpm_get_random() so that it will be always checked only when\nthe lock is reserved.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53085" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9265fed6db601ee2ec47577815387458ef4f047a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bc203fe416abdd1c29da594565a7c3c4e979488e" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-8wxp-xf8h-h599/GHSA-8wxp-xf8h-h599.json b/advisories/unreviewed/2024/11/GHSA-8wxp-xf8h-h599/GHSA-8wxp-xf8h-h599.json new file mode 100644 index 00000000000..32dfd723d4a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-8wxp-xf8h-h599/GHSA-8wxp-xf8h-h599.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8wxp-xf8h-h599", + "modified": "2024-11-19T18:31:05Z", + "published": "2024-11-19T18:31:05Z", + "aliases": [ + "CVE-2024-51917" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Huy Le Multiple Votes in one page allows Stored XSS.This issue affects Multiple Votes in one page: from n/a through 1.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51917" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/multiple-votes-in-one-page/wordpress-multiple-votes-in-one-page-plugin-1-0-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-8xg6-r8pq-vfwc/GHSA-8xg6-r8pq-vfwc.json b/advisories/unreviewed/2024/11/GHSA-8xg6-r8pq-vfwc/GHSA-8xg6-r8pq-vfwc.json new file mode 100644 index 00000000000..ce1d200d033 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-8xg6-r8pq-vfwc/GHSA-8xg6-r8pq-vfwc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8xg6-r8pq-vfwc", + "modified": "2024-11-19T18:31:04Z", + "published": "2024-11-19T18:31:04Z", + "aliases": [ + "CVE-2024-51906" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rapid Sort RSV 360 View allows DOM-Based XSS.This issue affects RSV 360 View: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51906" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/rsv-360-view/wordpress-rsv-360-view-plugin-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-8xx7-6q95-5vcp/GHSA-8xx7-6q95-5vcp.json b/advisories/unreviewed/2024/11/GHSA-8xx7-6q95-5vcp/GHSA-8xx7-6q95-5vcp.json new file mode 100644 index 00000000000..5cbaa847536 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-8xx7-6q95-5vcp/GHSA-8xx7-6q95-5vcp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8xx7-6q95-5vcp", + "modified": "2024-11-19T18:31:04Z", + "published": "2024-11-19T18:31:04Z", + "aliases": [ + "CVE-2024-51889" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GeroNikolov Fancy User List allows Stored XSS.This issue affects Fancy User List: from n/a through 3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51889" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/fancy-user-listing/wordpress-fancy-user-list-plugin-3-1-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-975c-w82q-mxhv/GHSA-975c-w82q-mxhv.json b/advisories/unreviewed/2024/11/GHSA-975c-w82q-mxhv/GHSA-975c-w82q-mxhv.json index 90dfe491cfc..5b4d896edd7 100644 --- a/advisories/unreviewed/2024/11/GHSA-975c-w82q-mxhv/GHSA-975c-w82q-mxhv.json +++ b/advisories/unreviewed/2024/11/GHSA-975c-w82q-mxhv/GHSA-975c-w82q-mxhv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-975c-w82q-mxhv", - "modified": "2024-11-08T18:30:50Z", + "modified": "2024-11-19T18:30:54Z", "published": "2024-11-08T06:30:49Z", "aliases": [ "CVE-2024-50210" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nposix-clock: posix-clock: Fix unbalanced locking in pc_clock_settime()\n\nIf get_clock_desc() succeeds, it calls fget() for the clockid's fd,\nand get the clk->rwsem read lock, so the error path should release\nthe lock to make the lock balance and fput the clockid's fd to make\nthe refcount balance and release the fd related resource.\n\nHowever the below commit left the error path locked behind resulting in\nunbalanced locking. Check timespec64_valid_strict() before\nget_clock_desc() to fix it, because the \"ts\" is not changed\nafter that.\n\n[pabeni@redhat.com: fixed commit message typo]", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-667" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-08T06:15:17Z" diff --git a/advisories/unreviewed/2024/11/GHSA-97h5-gfw2-p92x/GHSA-97h5-gfw2-p92x.json b/advisories/unreviewed/2024/11/GHSA-97h5-gfw2-p92x/GHSA-97h5-gfw2-p92x.json new file mode 100644 index 00000000000..97899d08e76 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-97h5-gfw2-p92x/GHSA-97h5-gfw2-p92x.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-97h5-gfw2-p92x", + "modified": "2024-11-19T18:31:06Z", + "published": "2024-11-19T18:31:06Z", + "aliases": [ + "CVE-2017-13315" + ], + "details": "In writeToParcel and createFromParcel of DcParamObject.java, there is a permission bypass due to a write size mismatch. This could lead to an elevation of privileges where the user can start an activity with system privileges, with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2017-13315" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-05-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-98fw-263x-275m/GHSA-98fw-263x-275m.json b/advisories/unreviewed/2024/11/GHSA-98fw-263x-275m/GHSA-98fw-263x-275m.json new file mode 100644 index 00000000000..4d87f7f23b6 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-98fw-263x-275m/GHSA-98fw-263x-275m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-98fw-263x-275m", + "modified": "2024-11-19T18:31:06Z", + "published": "2024-11-19T18:31:05Z", + "aliases": [ + "CVE-2024-52421" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in wp-buy WP Popup Window Maker allows Stored XSS.This issue affects WP Popup Window Maker: from n/a through 2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52421" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/easy-popup-lightbox-maker/wordpress-wp-popup-window-maker-plugin-2-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9964-jv72-p792/GHSA-9964-jv72-p792.json b/advisories/unreviewed/2024/11/GHSA-9964-jv72-p792/GHSA-9964-jv72-p792.json new file mode 100644 index 00000000000..eafd70d2b02 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9964-jv72-p792/GHSA-9964-jv72-p792.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9964-jv72-p792", + "modified": "2024-11-19T18:31:04Z", + "published": "2024-11-19T18:31:03Z", + "aliases": [ + "CVE-2024-51868" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DuoGeek DuoGeek Blocks allows Stored XSS.This issue affects DuoGeek Blocks: from n/a through .1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51868" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/duogeek-blocks/wordpress-duogeek-blocks-plugin-0-1-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-996p-gjg5-jmfx/GHSA-996p-gjg5-jmfx.json b/advisories/unreviewed/2024/11/GHSA-996p-gjg5-jmfx/GHSA-996p-gjg5-jmfx.json new file mode 100644 index 00000000000..259c8b6ff3a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-996p-gjg5-jmfx/GHSA-996p-gjg5-jmfx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-996p-gjg5-jmfx", + "modified": "2024-11-19T18:31:02Z", + "published": "2024-11-19T18:31:02Z", + "aliases": [ + "CVE-2024-51817" + ], + "details": "Missing Authorization vulnerability in CodeZel Combo WP Rewrite Slugs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Combo WP Rewrite Slugs: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51817" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/combo-wp-rewrite-slugs/wordpress-combo-wp-rewrite-slugs-plugin-1-0-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-99qq-7hp5-9h5x/GHSA-99qq-7hp5-9h5x.json b/advisories/unreviewed/2024/11/GHSA-99qq-7hp5-9h5x/GHSA-99qq-7hp5-9h5x.json new file mode 100644 index 00000000000..318a1742295 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-99qq-7hp5-9h5x/GHSA-99qq-7hp5-9h5x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-99qq-7hp5-9h5x", + "modified": "2024-11-19T18:31:02Z", + "published": "2024-11-19T18:31:02Z", + "aliases": [ + "CVE-2024-51821" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wordpresteem WE – Client Logo Carousel allows Stored XSS.This issue affects WE – Client Logo Carousel: from n/a through 1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51821" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/we-client-logo-carousel/wordpress-we-client-logo-carousel-plugin-1-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9f4h-r2c7-m6w4/GHSA-9f4h-r2c7-m6w4.json b/advisories/unreviewed/2024/11/GHSA-9f4h-r2c7-m6w4/GHSA-9f4h-r2c7-m6w4.json new file mode 100644 index 00000000000..4336f9d80b8 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9f4h-r2c7-m6w4/GHSA-9f4h-r2c7-m6w4.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9f4h-r2c7-m6w4", + "modified": "2024-11-19T18:31:06Z", + "published": "2024-11-19T18:31:06Z", + "aliases": [ + "CVE-2024-11003" + ], + "details": "Qualys discovered that needrestart, before version 3.8, passes unsanitized data to a library (Modules::ScanDeps) which expects safe input. This could allow a local attacker to execute arbitrary shell commands. Please see the related CVE-2024-10224 in Modules::ScanDeps.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11003" + }, + { + "type": "WEB", + "url": "https://github.com/liske/needrestart/commit/0f80a348883f72279a859ee655f58da34babefb0" + }, + { + "type": "WEB", + "url": "https://www.cve.org/CVERecord?id=CVE-2024-10224" + }, + { + "type": "WEB", + "url": "https://www.cve.org/CVERecord?id=CVE-2024-11003" + }, + { + "type": "WEB", + "url": "https://www.qualys.com/2024/11/19/needrestart/needrestart.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9g3h-hh7f-7m88/GHSA-9g3h-hh7f-7m88.json b/advisories/unreviewed/2024/11/GHSA-9g3h-hh7f-7m88/GHSA-9g3h-hh7f-7m88.json new file mode 100644 index 00000000000..9250d8cce6b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9g3h-hh7f-7m88/GHSA-9g3h-hh7f-7m88.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9g3h-hh7f-7m88", + "modified": "2024-11-19T18:31:02Z", + "published": "2024-11-19T18:31:02Z", + "aliases": [ + "CVE-2024-51797" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Md. Shiddikur Rahman Ultimate Accordion allows DOM-Based XSS.This issue affects Ultimate Accordion: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51797" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ultimate-accordion/wordpress-ultimate-accordion-plugin-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9h24-8pw7-c9p6/GHSA-9h24-8pw7-c9p6.json b/advisories/unreviewed/2024/11/GHSA-9h24-8pw7-c9p6/GHSA-9h24-8pw7-c9p6.json new file mode 100644 index 00000000000..9b4ad528928 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9h24-8pw7-c9p6/GHSA-9h24-8pw7-c9p6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9h24-8pw7-c9p6", + "modified": "2024-11-19T18:31:02Z", + "published": "2024-11-19T18:31:02Z", + "aliases": [ + "CVE-2024-51807" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Black and White Digital Ltd AgendaPress – Easily Publish Meeting Agendas and Programs on WordPress allows Stored XSS.This issue affects AgendaPress – Easily Publish Meeting Agendas and Programs on WordPress: from n/a through 1.0.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51807" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/agendapress/wordpress-agendapress-plugin-1-0-8-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9h8f-hjmp-pwxx/GHSA-9h8f-hjmp-pwxx.json b/advisories/unreviewed/2024/11/GHSA-9h8f-hjmp-pwxx/GHSA-9h8f-hjmp-pwxx.json index 12b8c5d74c9..86fdd9e1b5b 100644 --- a/advisories/unreviewed/2024/11/GHSA-9h8f-hjmp-pwxx/GHSA-9h8f-hjmp-pwxx.json +++ b/advisories/unreviewed/2024/11/GHSA-9h8f-hjmp-pwxx/GHSA-9h8f-hjmp-pwxx.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-9r3x-3x49-29r7/GHSA-9r3x-3x49-29r7.json b/advisories/unreviewed/2024/11/GHSA-9r3x-3x49-29r7/GHSA-9r3x-3x49-29r7.json new file mode 100644 index 00000000000..3ce75a3d98e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9r3x-3x49-29r7/GHSA-9r3x-3x49-29r7.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9r3x-3x49-29r7", + "modified": "2024-11-19T18:31:07Z", + "published": "2024-11-19T18:31:07Z", + "aliases": [ + "CVE-2024-53068" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: arm_scmi: Fix slab-use-after-free in scmi_bus_notifier()\n\nThe scmi_dev->name is released prematurely in __scmi_device_destroy(),\nwhich causes slab-use-after-free when accessing scmi_dev->name in\nscmi_bus_notifier(). So move the release of scmi_dev->name to\nscmi_device_release() to avoid slab-use-after-free.\n\n | BUG: KASAN: slab-use-after-free in strncmp+0xe4/0xec\n | Read of size 1 at addr ffffff80a482bcc0 by task swapper/0/1\n |\n | CPU: 1 PID: 1 Comm: swapper/0 Not tainted 6.6.38-debug #1\n | Hardware name: Qualcomm Technologies, Inc. SA8775P Ride (DT)\n | Call trace:\n | dump_backtrace+0x94/0x114\n | show_stack+0x18/0x24\n | dump_stack_lvl+0x48/0x60\n | print_report+0xf4/0x5b0\n | kasan_report+0xa4/0xec\n | __asan_report_load1_noabort+0x20/0x2c\n | strncmp+0xe4/0xec\n | scmi_bus_notifier+0x5c/0x54c\n | notifier_call_chain+0xb4/0x31c\n | blocking_notifier_call_chain+0x68/0x9c\n | bus_notify+0x54/0x78\n | device_del+0x1bc/0x840\n | device_unregister+0x20/0xb4\n | __scmi_device_destroy+0xac/0x280\n | scmi_device_destroy+0x94/0xd0\n | scmi_chan_setup+0x524/0x750\n | scmi_probe+0x7fc/0x1508\n | platform_probe+0xc4/0x19c\n | really_probe+0x32c/0x99c\n | __driver_probe_device+0x15c/0x3c4\n | driver_probe_device+0x5c/0x170\n | __driver_attach+0x1c8/0x440\n | bus_for_each_dev+0xf4/0x178\n | driver_attach+0x3c/0x58\n | bus_add_driver+0x234/0x4d4\n | driver_register+0xf4/0x3c0\n | __platform_driver_register+0x60/0x88\n | scmi_driver_init+0xb0/0x104\n | do_one_initcall+0xb4/0x664\n | kernel_init_freeable+0x3c8/0x894\n | kernel_init+0x24/0x1e8\n | ret_from_fork+0x10/0x20\n |\n | Allocated by task 1:\n | kasan_save_stack+0x2c/0x54\n | kasan_set_track+0x2c/0x40\n | kasan_save_alloc_info+0x24/0x34\n | __kasan_kmalloc+0xa0/0xb8\n | __kmalloc_node_track_caller+0x6c/0x104\n | kstrdup+0x48/0x84\n | kstrdup_const+0x34/0x40\n | __scmi_device_create.part.0+0x8c/0x408\n | scmi_device_create+0x104/0x370\n | scmi_chan_setup+0x2a0/0x750\n | scmi_probe+0x7fc/0x1508\n | platform_probe+0xc4/0x19c\n | really_probe+0x32c/0x99c\n | __driver_probe_device+0x15c/0x3c4\n | driver_probe_device+0x5c/0x170\n | __driver_attach+0x1c8/0x440\n | bus_for_each_dev+0xf4/0x178\n | driver_attach+0x3c/0x58\n | bus_add_driver+0x234/0x4d4\n | driver_register+0xf4/0x3c0\n | __platform_driver_register+0x60/0x88\n | scmi_driver_init+0xb0/0x104\n | do_one_initcall+0xb4/0x664\n | kernel_init_freeable+0x3c8/0x894\n | kernel_init+0x24/0x1e8\n | ret_from_fork+0x10/0x20\n |\n | Freed by task 1:\n | kasan_save_stack+0x2c/0x54\n | kasan_set_track+0x2c/0x40\n | kasan_save_free_info+0x38/0x5c\n | __kasan_slab_free+0xe8/0x164\n | __kmem_cache_free+0x11c/0x230\n | kfree+0x70/0x130\n | kfree_const+0x20/0x40\n | __scmi_device_destroy+0x70/0x280\n | scmi_device_destroy+0x94/0xd0\n | scmi_chan_setup+0x524/0x750\n | scmi_probe+0x7fc/0x1508\n | platform_probe+0xc4/0x19c\n | really_probe+0x32c/0x99c\n | __driver_probe_device+0x15c/0x3c4\n | driver_probe_device+0x5c/0x170\n | __driver_attach+0x1c8/0x440\n | bus_for_each_dev+0xf4/0x178\n | driver_attach+0x3c/0x58\n | bus_add_driver+0x234/0x4d4\n | driver_register+0xf4/0x3c0\n | __platform_driver_register+0x60/0x88\n | scmi_driver_init+0xb0/0x104\n | do_one_initcall+0xb4/0x664\n | kernel_init_freeable+0x3c8/0x894\n | kernel_init+0x24/0x1e8\n | ret_from_fork+0x10/0x20", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53068" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/15b17bbcea07d49c43d21aa700485cbd9f9d00d8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1e1f523b185a8ccdcba625b31ff0312d052900e2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/295416091e44806760ccf753aeafdafc0ae268f3" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9rhr-hcff-89rc/GHSA-9rhr-hcff-89rc.json b/advisories/unreviewed/2024/11/GHSA-9rhr-hcff-89rc/GHSA-9rhr-hcff-89rc.json new file mode 100644 index 00000000000..e1b54509a79 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9rhr-hcff-89rc/GHSA-9rhr-hcff-89rc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9rhr-hcff-89rc", + "modified": "2024-11-19T18:31:04Z", + "published": "2024-11-19T18:31:04Z", + "aliases": [ + "CVE-2024-51896" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webvitaly Magic Slider allows Stored XSS.This issue affects Magic Slider: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51896" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/magic-slider/wordpress-magic-slider-plugin-1-3-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9w8f-6h5p-xj5x/GHSA-9w8f-6h5p-xj5x.json b/advisories/unreviewed/2024/11/GHSA-9w8f-6h5p-xj5x/GHSA-9w8f-6h5p-xj5x.json new file mode 100644 index 00000000000..b2998fdec4d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9w8f-6h5p-xj5x/GHSA-9w8f-6h5p-xj5x.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9w8f-6h5p-xj5x", + "modified": "2024-11-19T18:31:07Z", + "published": "2024-11-19T18:31:07Z", + "aliases": [ + "CVE-2024-53088" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ni40e: fix race condition by adding filter's intermediate sync state\n\nFix a race condition in the i40e driver that leads to MAC/VLAN filters\nbecoming corrupted and leaking. Address the issue that occurs under\nheavy load when multiple threads are concurrently modifying MAC/VLAN\nfilters by setting mac and port VLAN.\n\n1. Thread T0 allocates a filter in i40e_add_filter() within\n i40e_ndo_set_vf_port_vlan().\n2. Thread T1 concurrently frees the filter in __i40e_del_filter() within\n i40e_ndo_set_vf_mac().\n3. Subsequently, i40e_service_task() calls i40e_sync_vsi_filters(), which\n refers to the already freed filter memory, causing corruption.\n\nReproduction steps:\n1. Spawn multiple VFs.\n2. Apply a concurrent heavy load by running parallel operations to change\n MAC addresses on the VFs and change port VLANs on the host.\n3. Observe errors in dmesg:\n\"Error I40E_AQ_RC_ENOSPC adding RX filters on VF XX,\n\tplease set promiscuous on manually for VF XX\".\n\nExact code for stable reproduction Intel can't open-source now.\n\nThe fix involves implementing a new intermediate filter state,\nI40E_FILTER_NEW_SYNC, for the time when a filter is on a tmp_add_list.\nThese filters cannot be deleted from the hash list directly but\nmust be removed using the full process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53088" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/262dc6ea5f1eb18c4d08ad83d51222d0dd0dd42a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6e046f4937474bc1b9fa980c1ad8f3253fc638f6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7ad3fb3bfd43feb4e15c81dffd23ac4e55742791" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bf5f837d9fd27d32fb76df0a108babcaf4446ff1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f30490e9695ef7da3d0899c6a0293cc7cd373567" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9wcj-qpv5-8x56/GHSA-9wcj-qpv5-8x56.json b/advisories/unreviewed/2024/11/GHSA-9wcj-qpv5-8x56/GHSA-9wcj-qpv5-8x56.json new file mode 100644 index 00000000000..eed10b820d3 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9wcj-qpv5-8x56/GHSA-9wcj-qpv5-8x56.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9wcj-qpv5-8x56", + "modified": "2024-11-19T18:31:02Z", + "published": "2024-11-19T18:31:02Z", + "aliases": [ + "CVE-2024-51804" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Matsuoka Moka Get Posts Shortcode allows DOM-Based XSS.This issue affects Moka Get Posts Shortcode: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51804" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/moka-get-posts/wordpress-moka-get-posts-shortcode-plugin-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9x98-cfgr-9v24/GHSA-9x98-cfgr-9v24.json b/advisories/unreviewed/2024/11/GHSA-9x98-cfgr-9v24/GHSA-9x98-cfgr-9v24.json new file mode 100644 index 00000000000..663c16a8a3d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9x98-cfgr-9v24/GHSA-9x98-cfgr-9v24.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9x98-cfgr-9v24", + "modified": "2024-11-19T18:31:03Z", + "published": "2024-11-19T18:31:03Z", + "aliases": [ + "CVE-2024-51851" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in saleh attari best bootstrap widgets for elementor allows DOM-Based XSS.This issue affects best bootstrap widgets for elementor: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51851" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/best-bootstrap-widgets-for-elementor/wordpress-best-bootstrap-widgets-for-elementor-plugin-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9xfw-pcxh-9682/GHSA-9xfw-pcxh-9682.json b/advisories/unreviewed/2024/11/GHSA-9xfw-pcxh-9682/GHSA-9xfw-pcxh-9682.json new file mode 100644 index 00000000000..54a8c62bab0 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9xfw-pcxh-9682/GHSA-9xfw-pcxh-9682.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9xfw-pcxh-9682", + "modified": "2024-11-19T18:31:04Z", + "published": "2024-11-19T18:31:04Z", + "aliases": [ + "CVE-2024-51891" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 4B Systems sp. z o.o Official SalesWizard CRM Plugin allows Stored XSS.This issue affects Official SalesWizard CRM Plugin: from n/a through 1.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51891" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/official-saleswizard-crm/wordpress-official-saleswizard-crm-plugin-plugin-1-0-2-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-c2hm-g5g7-h823/GHSA-c2hm-g5g7-h823.json b/advisories/unreviewed/2024/11/GHSA-c2hm-g5g7-h823/GHSA-c2hm-g5g7-h823.json new file mode 100644 index 00000000000..c7b43c957a2 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-c2hm-g5g7-h823/GHSA-c2hm-g5g7-h823.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c2hm-g5g7-h823", + "modified": "2024-11-19T18:31:01Z", + "published": "2024-11-19T18:31:01Z", + "aliases": [ + "CVE-2024-50547" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themedy Themedy Toolbox allows DOM-Based XSS.This issue affects Themedy Toolbox: from n/a through 1.0.16.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50547" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/themedy-toolbox/wordpress-themedy-toolbox-plugin-1-0-16-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-c3cr-hpjv-gv7r/GHSA-c3cr-hpjv-gv7r.json b/advisories/unreviewed/2024/11/GHSA-c3cr-hpjv-gv7r/GHSA-c3cr-hpjv-gv7r.json new file mode 100644 index 00000000000..b11adea3ece --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-c3cr-hpjv-gv7r/GHSA-c3cr-hpjv-gv7r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c3cr-hpjv-gv7r", + "modified": "2024-11-19T18:31:04Z", + "published": "2024-11-19T18:31:04Z", + "aliases": [ + "CVE-2024-51909" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Monarkie Digital Content Solutions audioCase allows DOM-Based XSS.This issue affects audioCase: from n/a through 1.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51909" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/audiocase/wordpress-audiocase-plugin-1-2-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-c3rv-gq44-hm8f/GHSA-c3rv-gq44-hm8f.json b/advisories/unreviewed/2024/11/GHSA-c3rv-gq44-hm8f/GHSA-c3rv-gq44-hm8f.json new file mode 100644 index 00000000000..c9f7bbd0913 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-c3rv-gq44-hm8f/GHSA-c3rv-gq44-hm8f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c3rv-gq44-hm8f", + "modified": "2024-11-19T18:31:00Z", + "published": "2024-11-19T18:31:00Z", + "aliases": [ + "CVE-2024-49680" + ], + "details": "Missing Authorization vulnerability in Rextheme WP VR allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP VR: from n/a through 8.5.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49680" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wpvr/wordpress-wpvr-plugin-8-5-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-c64j-4r5h-4rmp/GHSA-c64j-4r5h-4rmp.json b/advisories/unreviewed/2024/11/GHSA-c64j-4r5h-4rmp/GHSA-c64j-4r5h-4rmp.json new file mode 100644 index 00000000000..b1dc2e6d72c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-c64j-4r5h-4rmp/GHSA-c64j-4r5h-4rmp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c64j-4r5h-4rmp", + "modified": "2024-11-19T18:31:01Z", + "published": "2024-11-19T18:31:01Z", + "aliases": [ + "CVE-2024-51639" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Hints Naver Blog allows Stored XSS.This issue affects Naver Blog: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51639" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/naver-blog-api/wordpress-naver-blog-plugin-1-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-c6vv-jw3g-77q9/GHSA-c6vv-jw3g-77q9.json b/advisories/unreviewed/2024/11/GHSA-c6vv-jw3g-77q9/GHSA-c6vv-jw3g-77q9.json new file mode 100644 index 00000000000..0374db957c7 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-c6vv-jw3g-77q9/GHSA-c6vv-jw3g-77q9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c6vv-jw3g-77q9", + "modified": "2024-11-19T18:31:04Z", + "published": "2024-11-19T18:31:04Z", + "aliases": [ + "CVE-2024-51890" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in geoWP Geoportail Shortcode allows Stored XSS.This issue affects Geoportail Shortcode: from n/a through 2.4.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51890" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/geoportail-shortcode/wordpress-geoportail-shortcode-plugin-2-4-4-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-c95v-4jjw-2rfc/GHSA-c95v-4jjw-2rfc.json b/advisories/unreviewed/2024/11/GHSA-c95v-4jjw-2rfc/GHSA-c95v-4jjw-2rfc.json new file mode 100644 index 00000000000..43d753a83aa --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-c95v-4jjw-2rfc/GHSA-c95v-4jjw-2rfc.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c95v-4jjw-2rfc", + "modified": "2024-11-19T18:31:07Z", + "published": "2024-11-19T18:31:07Z", + "aliases": [ + "CVE-2024-53077" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nrpcrdma: Always release the rpcrdma_device's xa_array\n\nDai pointed out that the xa_init_flags() in rpcrdma_add_one() needs\nto have a matching xa_destroy() in rpcrdma_remove_one() to release\nunderlying memory that the xarray might have accrued during\noperation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53077" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/36b7f5a4f300d038270324640ff7c1399245159d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/63a81588cd2025e75fbaf30b65930b76825c456f" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-c9q8-68wq-p8wf/GHSA-c9q8-68wq-p8wf.json b/advisories/unreviewed/2024/11/GHSA-c9q8-68wq-p8wf/GHSA-c9q8-68wq-p8wf.json new file mode 100644 index 00000000000..48660d0517b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-c9q8-68wq-p8wf/GHSA-c9q8-68wq-p8wf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c9q8-68wq-p8wf", + "modified": "2024-11-19T18:31:01Z", + "published": "2024-11-19T18:31:01Z", + "aliases": [ + "CVE-2024-50521" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in alleythemes Alley Elementor Widget allows DOM-Based XSS.This issue affects Alley Elementor Widget: from n/a through 1.0.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50521" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/alley-elementor-widget/wordpress-alley-elementor-widget-plugin-1-0-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-cgh6-mrm3-hqpj/GHSA-cgh6-mrm3-hqpj.json b/advisories/unreviewed/2024/11/GHSA-cgh6-mrm3-hqpj/GHSA-cgh6-mrm3-hqpj.json new file mode 100644 index 00000000000..bbd30082b23 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-cgh6-mrm3-hqpj/GHSA-cgh6-mrm3-hqpj.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cgh6-mrm3-hqpj", + "modified": "2024-11-19T18:31:07Z", + "published": "2024-11-19T18:31:07Z", + "aliases": [ + "CVE-2024-53072" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86/amd/pmc: Detect when STB is not available\n\nLoading the amd_pmc module as:\n\n amd_pmc enable_stb=1\n\n...can result in the following messages in the kernel ring buffer:\n\n amd_pmc AMDI0009:00: SMU cmd failed. err: 0xff\n ioremap on RAM at 0x0000000000000000 - 0x0000000000ffffff\n WARNING: CPU: 10 PID: 2151 at arch/x86/mm/ioremap.c:217 __ioremap_caller+0x2cd/0x340\n\nFurther debugging reveals that this occurs when the requests for\nS2D_PHYS_ADDR_LOW and S2D_PHYS_ADDR_HIGH return a value of 0,\nindicating that the STB is inaccessible. To prevent the ioremap\nwarning and provide clarity to the user, handle the invalid address\nand display an error message.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53072" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/67ff30e24a0466bdd5be1d0b84385ec3c85fdacd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7a3ed3f125292bc3398e04d10108124250892e3f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a50863dd1f92d43c975ab2ecc3476617fe98a66e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bceec87a73804bb4c33b9a6c96e2d27cd893a801" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-cgvw-jh5j-mgq3/GHSA-cgvw-jh5j-mgq3.json b/advisories/unreviewed/2024/11/GHSA-cgvw-jh5j-mgq3/GHSA-cgvw-jh5j-mgq3.json index 815661b4e36..2a3557d66f6 100644 --- a/advisories/unreviewed/2024/11/GHSA-cgvw-jh5j-mgq3/GHSA-cgvw-jh5j-mgq3.json +++ b/advisories/unreviewed/2024/11/GHSA-cgvw-jh5j-mgq3/GHSA-cgvw-jh5j-mgq3.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cgvw-jh5j-mgq3", - "modified": "2024-11-18T18:30:58Z", + "modified": "2024-11-19T18:30:59Z", "published": "2024-11-18T18:30:58Z", "aliases": [ "CVE-2024-9474" ], "details": "A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges.\n\nCloud NGFW and Prisma Access are not impacted by this vulnerability.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:Red" diff --git a/advisories/unreviewed/2024/11/GHSA-chwg-hrp2-25gc/GHSA-chwg-hrp2-25gc.json b/advisories/unreviewed/2024/11/GHSA-chwg-hrp2-25gc/GHSA-chwg-hrp2-25gc.json new file mode 100644 index 00000000000..bd2b894962e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-chwg-hrp2-25gc/GHSA-chwg-hrp2-25gc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-chwg-hrp2-25gc", + "modified": "2024-11-19T18:31:04Z", + "published": "2024-11-19T18:31:04Z", + "aliases": [ + "CVE-2024-51881" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Beautimour Be Shortcodes allows DOM-Based XSS.This issue affects Be Shortcodes: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51881" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/be-shortcodes/wordpress-be-shortcodes-plugin-1-0-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-cp57-7c6j-pxfg/GHSA-cp57-7c6j-pxfg.json b/advisories/unreviewed/2024/11/GHSA-cp57-7c6j-pxfg/GHSA-cp57-7c6j-pxfg.json new file mode 100644 index 00000000000..7132909f6e1 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-cp57-7c6j-pxfg/GHSA-cp57-7c6j-pxfg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cp57-7c6j-pxfg", + "modified": "2024-11-19T18:31:06Z", + "published": "2024-11-19T18:31:06Z", + "aliases": [ + "CVE-2023-21270" + ], + "details": "In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way for an app to keep permissions that should be revoked due to incorrect permission flags cleared during an update. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-21270" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2023-08-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-cv4q-xjgm-hcp3/GHSA-cv4q-xjgm-hcp3.json b/advisories/unreviewed/2024/11/GHSA-cv4q-xjgm-hcp3/GHSA-cv4q-xjgm-hcp3.json new file mode 100644 index 00000000000..00841a77f5c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-cv4q-xjgm-hcp3/GHSA-cv4q-xjgm-hcp3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cv4q-xjgm-hcp3", + "modified": "2024-11-19T18:31:03Z", + "published": "2024-11-19T18:31:03Z", + "aliases": [ + "CVE-2024-51866" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mr. Riponshah Social button allows Stored XSS.This issue affects Social button: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51866" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/social-button/wordpress-social-button-plugin-1-3-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-cvf9-v6p6-9c32/GHSA-cvf9-v6p6-9c32.json b/advisories/unreviewed/2024/11/GHSA-cvf9-v6p6-9c32/GHSA-cvf9-v6p6-9c32.json new file mode 100644 index 00000000000..754a7941c8a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-cvf9-v6p6-9c32/GHSA-cvf9-v6p6-9c32.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cvf9-v6p6-9c32", + "modified": "2024-11-19T18:31:03Z", + "published": "2024-11-19T18:31:03Z", + "aliases": [ + "CVE-2024-51863" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Team Profit-Funnels PF Timer allows Stored XSS.This issue affects PF Timer: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51863" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/pf-timer/wordpress-pf-timer-plugin-1-0-0-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-cw9g-65q4-rpvj/GHSA-cw9g-65q4-rpvj.json b/advisories/unreviewed/2024/11/GHSA-cw9g-65q4-rpvj/GHSA-cw9g-65q4-rpvj.json new file mode 100644 index 00000000000..1e85db03519 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-cw9g-65q4-rpvj/GHSA-cw9g-65q4-rpvj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cw9g-65q4-rpvj", + "modified": "2024-11-19T18:31:02Z", + "published": "2024-11-19T18:31:02Z", + "aliases": [ + "CVE-2024-51814" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 野人 活动链接推广插件 allows DOM-Based XSS.This issue affects 活动链接推广插件: from n/a through 1.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51814" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/yr-activity-link/wordpress-plugin-1-2-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-cwqh-jjqr-q2hf/GHSA-cwqh-jjqr-q2hf.json b/advisories/unreviewed/2024/11/GHSA-cwqh-jjqr-q2hf/GHSA-cwqh-jjqr-q2hf.json new file mode 100644 index 00000000000..d7057684eff --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-cwqh-jjqr-q2hf/GHSA-cwqh-jjqr-q2hf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cwqh-jjqr-q2hf", + "modified": "2024-11-19T18:31:02Z", + "published": "2024-11-19T18:31:02Z", + "aliases": [ + "CVE-2024-51655" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Microkid Custom Author URL allows Stored XSS.This issue affects Custom Author URL: from n/a through 2.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51655" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/author-slug/wordpress-custom-author-url-plugin-2-0-1-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-f2hp-wgc9-mcvf/GHSA-f2hp-wgc9-mcvf.json b/advisories/unreviewed/2024/11/GHSA-f2hp-wgc9-mcvf/GHSA-f2hp-wgc9-mcvf.json new file mode 100644 index 00000000000..5396079ced0 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-f2hp-wgc9-mcvf/GHSA-f2hp-wgc9-mcvf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f2hp-wgc9-mcvf", + "modified": "2024-11-19T18:31:02Z", + "published": "2024-11-19T18:31:02Z", + "aliases": [ + "CVE-2024-51671" + ], + "details": "Missing Authorization vulnerability in ThemeIsle Otter - Gutenberg Block allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Otter - Gutenberg Block: from n/a through 3.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51671" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/otter-blocks/wordpress-otter-blocks-plugin-3-0-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-f6c2-ph4p-hmh6/GHSA-f6c2-ph4p-hmh6.json b/advisories/unreviewed/2024/11/GHSA-f6c2-ph4p-hmh6/GHSA-f6c2-ph4p-hmh6.json new file mode 100644 index 00000000000..ef90165a064 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-f6c2-ph4p-hmh6/GHSA-f6c2-ph4p-hmh6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f6c2-ph4p-hmh6", + "modified": "2024-11-19T18:31:05Z", + "published": "2024-11-19T18:31:05Z", + "aliases": [ + "CVE-2024-51931" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marketever AzonBox allows DOM-Based XSS.This issue affects AzonBox: from n/a through 1.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51931" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/azonbox/wordpress-azonbox-plugin-1-1-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-f76r-8x77-pwm4/GHSA-f76r-8x77-pwm4.json b/advisories/unreviewed/2024/11/GHSA-f76r-8x77-pwm4/GHSA-f76r-8x77-pwm4.json new file mode 100644 index 00000000000..252d82d2353 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-f76r-8x77-pwm4/GHSA-f76r-8x77-pwm4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f76r-8x77-pwm4", + "modified": "2024-11-19T18:31:02Z", + "published": "2024-11-19T18:31:02Z", + "aliases": [ + "CVE-2024-51802" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bread & Butter IO Inc. Bread & Butter allows DOM-Based XSS.This issue affects Bread & Butter: from n/a through 7.4.857.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51802" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/bread-butter/wordpress-bread-butter-plugin-7-4-857-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-fc6c-wh46-2q9r/GHSA-fc6c-wh46-2q9r.json b/advisories/unreviewed/2024/11/GHSA-fc6c-wh46-2q9r/GHSA-fc6c-wh46-2q9r.json new file mode 100644 index 00000000000..6db62b1ba60 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-fc6c-wh46-2q9r/GHSA-fc6c-wh46-2q9r.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fc6c-wh46-2q9r", + "modified": "2024-11-19T18:31:07Z", + "published": "2024-11-19T18:31:07Z", + "aliases": [ + "CVE-2024-53066" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfs: Fix KMSAN warning in decode_getfattr_attrs()\n\nFix the following KMSAN warning:\n\nCPU: 1 UID: 0 PID: 7651 Comm: cp Tainted: G B\nTainted: [B]=BAD_PAGE\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009)\n=====================================================\n=====================================================\nBUG: KMSAN: uninit-value in decode_getfattr_attrs+0x2d6d/0x2f90\n decode_getfattr_attrs+0x2d6d/0x2f90\n decode_getfattr_generic+0x806/0xb00\n nfs4_xdr_dec_getattr+0x1de/0x240\n rpcauth_unwrap_resp_decode+0xab/0x100\n rpcauth_unwrap_resp+0x95/0xc0\n call_decode+0x4ff/0xb50\n __rpc_execute+0x57b/0x19d0\n rpc_execute+0x368/0x5e0\n rpc_run_task+0xcfe/0xee0\n nfs4_proc_getattr+0x5b5/0x990\n __nfs_revalidate_inode+0x477/0xd00\n nfs_access_get_cached+0x1021/0x1cc0\n nfs_do_access+0x9f/0xae0\n nfs_permission+0x1e4/0x8c0\n inode_permission+0x356/0x6c0\n link_path_walk+0x958/0x1330\n path_lookupat+0xce/0x6b0\n filename_lookup+0x23e/0x770\n vfs_statx+0xe7/0x970\n vfs_fstatat+0x1f2/0x2c0\n __se_sys_newfstatat+0x67/0x880\n __x64_sys_newfstatat+0xbd/0x120\n x64_sys_call+0x1826/0x3cf0\n do_syscall_64+0xd0/0x1b0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nThe KMSAN warning is triggered in decode_getfattr_attrs(), when calling\ndecode_attr_mdsthreshold(). It appears that fattr->mdsthreshold is not\ninitialized.\n\nFix the issue by initializing fattr->mdsthreshold to NULL in\nnfs_fattr_init().", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53066" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/25ffd294fef81a7f3cd9528adf21560c04d98747" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8fc5ea9231af9122d227c9c13f5e578fca48d2e3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9b453e8b108a5a93a6e348cf2ba4c9c138314a00" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9be0a21ae52b3b822d0eec4d14e909ab394f8a92" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bbfcd261cc068fe1cd02a4e871275074a0daa4e2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dc270d7159699ad6d11decadfce9633f0f71c1db" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f6b2b2b981af8e7d7c62d34143acefa4e1edfe8b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f749cb60a01f8391c760a1d6ecd938cadacf9549" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-ffrw-8p66-394j/GHSA-ffrw-8p66-394j.json b/advisories/unreviewed/2024/11/GHSA-ffrw-8p66-394j/GHSA-ffrw-8p66-394j.json index 3696c37ee86..334c2fec6f5 100644 --- a/advisories/unreviewed/2024/11/GHSA-ffrw-8p66-394j/GHSA-ffrw-8p66-394j.json +++ b/advisories/unreviewed/2024/11/GHSA-ffrw-8p66-394j/GHSA-ffrw-8p66-394j.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ffrw-8p66-394j", - "modified": "2024-11-18T09:31:14Z", + "modified": "2024-11-19T18:30:58Z", "published": "2024-11-18T09:31:14Z", "aliases": [ "CVE-2024-48962" ], "details": "Improper Control of Generation of Code ('Code Injection'), Cross-Site Request Forgery (CSRF), : Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz.\n\nThis issue affects Apache OFBiz: before 18.12.17.\n\nUsers are recommended to upgrade to version 18.12.17, which fixes the issue.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:Amber" diff --git a/advisories/unreviewed/2024/11/GHSA-fhmx-7jhg-8h34/GHSA-fhmx-7jhg-8h34.json b/advisories/unreviewed/2024/11/GHSA-fhmx-7jhg-8h34/GHSA-fhmx-7jhg-8h34.json new file mode 100644 index 00000000000..f1e80263fa8 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-fhmx-7jhg-8h34/GHSA-fhmx-7jhg-8h34.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fhmx-7jhg-8h34", + "modified": "2024-11-19T18:31:06Z", + "published": "2024-11-19T18:31:06Z", + "aliases": [ + "CVE-2024-53052" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring/rw: fix missing NOWAIT check for O_DIRECT start write\n\nWhen io_uring starts a write, it'll call kiocb_start_write() to bump the\nsuper block rwsem, preventing any freezes from happening while that\nwrite is in-flight. The freeze side will grab that rwsem for writing,\nexcluding any new writers from happening and waiting for existing writes\nto finish. But io_uring unconditionally uses kiocb_start_write(), which\nwill block if someone is currently attempting to freeze the mount point.\nThis causes a deadlock where freeze is waiting for previous writes to\ncomplete, but the previous writes cannot complete, as the task that is\nsupposed to complete them is blocked waiting on starting a new write.\nThis results in the following stuck trace showing that dependency with\nthe write blocked starting a new write:\n\ntask:fio state:D stack:0 pid:886 tgid:886 ppid:876\nCall trace:\n __switch_to+0x1d8/0x348\n __schedule+0x8e8/0x2248\n schedule+0x110/0x3f0\n percpu_rwsem_wait+0x1e8/0x3f8\n __percpu_down_read+0xe8/0x500\n io_write+0xbb8/0xff8\n io_issue_sqe+0x10c/0x1020\n io_submit_sqes+0x614/0x2110\n __arm64_sys_io_uring_enter+0x524/0x1038\n invoke_syscall+0x74/0x268\n el0_svc_common.constprop.0+0x160/0x238\n do_el0_svc+0x44/0x60\n el0_svc+0x44/0xb0\n el0t_64_sync_handler+0x118/0x128\n el0t_64_sync+0x168/0x170\nINFO: task fsfreeze:7364 blocked for more than 15 seconds.\n Not tainted 6.12.0-rc5-00063-g76aaf945701c #7963\n\nwith the attempting freezer stuck trying to grab the rwsem:\n\ntask:fsfreeze state:D stack:0 pid:7364 tgid:7364 ppid:995\nCall trace:\n __switch_to+0x1d8/0x348\n __schedule+0x8e8/0x2248\n schedule+0x110/0x3f0\n percpu_down_write+0x2b0/0x680\n freeze_super+0x248/0x8a8\n do_vfs_ioctl+0x149c/0x1b18\n __arm64_sys_ioctl+0xd0/0x1a0\n invoke_syscall+0x74/0x268\n el0_svc_common.constprop.0+0x160/0x238\n do_el0_svc+0x44/0x60\n el0_svc+0x44/0xb0\n el0t_64_sync_handler+0x118/0x128\n el0t_64_sync+0x168/0x170\n\nFix this by having the io_uring side honor IOCB_NOWAIT, and only attempt a\nblocking grab of the super block rwsem if it isn't set. For normal issue\nwhere IOCB_NOWAIT would always be set, this returns -EAGAIN which will\nhave io_uring core issue a blocking attempt of the write. That will in\nturn also get completions run, ensuring forward progress.\n\nSince freezing requires CAP_SYS_ADMIN in the first place, this isn't\nsomething that can be triggered by a regular user.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53052" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/003d2996964c03dfd34860500428f4cdf1f5879e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1d60d74e852647255bd8e76f5a22dc42531e4389" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/26b8c48f369b7591f5679e0b90612f4862a32929" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/485d9232112b17f389b29497ff41b97b3189546b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4e24041ba86d50aaa4c792ae2c88ed01b3d96243" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9e8debb8e51354b201db494689198078ec2c1e75" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-fmfg-pggg-vmwc/GHSA-fmfg-pggg-vmwc.json b/advisories/unreviewed/2024/11/GHSA-fmfg-pggg-vmwc/GHSA-fmfg-pggg-vmwc.json new file mode 100644 index 00000000000..3b04b15140e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-fmfg-pggg-vmwc/GHSA-fmfg-pggg-vmwc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fmfg-pggg-vmwc", + "modified": "2024-11-19T18:31:05Z", + "published": "2024-11-19T18:31:05Z", + "aliases": [ + "CVE-2024-51926" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wpsoul GreenCon allows Stored XSS.This issue affects GreenCon: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51926" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/greencon/wordpress-greencon-plugin-1-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-fp2v-7r4c-j6p5/GHSA-fp2v-7r4c-j6p5.json b/advisories/unreviewed/2024/11/GHSA-fp2v-7r4c-j6p5/GHSA-fp2v-7r4c-j6p5.json new file mode 100644 index 00000000000..37b050ee5a9 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-fp2v-7r4c-j6p5/GHSA-fp2v-7r4c-j6p5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fp2v-7r4c-j6p5", + "modified": "2024-11-19T18:31:05Z", + "published": "2024-11-19T18:31:05Z", + "aliases": [ + "CVE-2024-51924" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alexandre Magno WP Agenda allows Stored XSS.This issue affects WP Agenda: from n/a through 2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51924" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-agenda/wordpress-wp-agenda-plugin-2-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-fw3x-9gjw-x3mg/GHSA-fw3x-9gjw-x3mg.json b/advisories/unreviewed/2024/11/GHSA-fw3x-9gjw-x3mg/GHSA-fw3x-9gjw-x3mg.json new file mode 100644 index 00000000000..6ef696e1433 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-fw3x-9gjw-x3mg/GHSA-fw3x-9gjw-x3mg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fw3x-9gjw-x3mg", + "modified": "2024-11-19T18:31:01Z", + "published": "2024-11-19T18:31:01Z", + "aliases": [ + "CVE-2024-50553" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Classy Addons Classy Addons for Elementor allows DOM-Based XSS.This issue affects Classy Addons for Elementor: from n/a through 1.2.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50553" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/classy-addons-for-elementor/wordpress-classy-addons-for-elementor-plugin-1-2-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-fw47-6v57-fjcf/GHSA-fw47-6v57-fjcf.json b/advisories/unreviewed/2024/11/GHSA-fw47-6v57-fjcf/GHSA-fw47-6v57-fjcf.json new file mode 100644 index 00000000000..26d01caf2f8 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-fw47-6v57-fjcf/GHSA-fw47-6v57-fjcf.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fw47-6v57-fjcf", + "modified": "2024-11-19T18:31:07Z", + "published": "2024-11-19T18:31:07Z", + "aliases": [ + "CVE-2024-53083" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: qcom-pmic: init value of hdr_len/txbuf_len earlier\n\nIf the read of USB_PDPHY_RX_ACKNOWLEDGE_REG failed, then hdr_len and\ntxbuf_len are uninitialized. This commit stops to print uninitialized\nvalue and misleading/false data.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53083" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/029778a4fd2c90c2e76a902b797c2348a722f1b8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/35925e2b7b404cad3db857434d3312b892b55432" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/74d8cee747b37cd9f5ca631f678e66e7f40f2b5f" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-fx99-8m8g-rfwx/GHSA-fx99-8m8g-rfwx.json b/advisories/unreviewed/2024/11/GHSA-fx99-8m8g-rfwx/GHSA-fx99-8m8g-rfwx.json new file mode 100644 index 00000000000..f51d26bb0f3 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-fx99-8m8g-rfwx/GHSA-fx99-8m8g-rfwx.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fx99-8m8g-rfwx", + "modified": "2024-11-19T18:31:07Z", + "published": "2024-11-19T18:31:07Z", + "aliases": [ + "CVE-2024-53080" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/panthor: Lock XArray when getting entries for the VM\n\nSimilar to commit cac075706f29 (\"drm/panthor: Fix race when converting\ngroup handle to group object\") we need to use the XArray's internal\nlocking when retrieving a vm pointer from there.\n\nv2: Removed part of the patch that was trying to protect fetching\nthe heap pointer from XArray, as that operation is protected by\nthe @pool->lock.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53080" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3342f066a8e1020a6f7d1fbd6b23bfdeda473eb5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/444fa5b100e5c90550d6bccfe4476efb0391b3ca" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-g4gg-7gqp-cf6m/GHSA-g4gg-7gqp-cf6m.json b/advisories/unreviewed/2024/11/GHSA-g4gg-7gqp-cf6m/GHSA-g4gg-7gqp-cf6m.json new file mode 100644 index 00000000000..244ceccb7d8 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-g4gg-7gqp-cf6m/GHSA-g4gg-7gqp-cf6m.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g4gg-7gqp-cf6m", + "modified": "2024-11-19T18:31:06Z", + "published": "2024-11-19T18:31:06Z", + "aliases": [ + "CVE-2024-53044" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: sch_api: fix xa_insert() error path in tcf_block_get_ext()\n\nThis command:\n\n$ tc qdisc replace dev eth0 ingress_block 1 egress_block 1 clsact\nError: block dev insert failed: -EBUSY.\n\nfails because user space requests the same block index to be set for\nboth ingress and egress.\n\n[ side note, I don't think it even failed prior to commit 913b47d3424e\n (\"net/sched: Introduce tc block netdev tracking infra\"), because this\n is a command from an old set of notes of mine which used to work, but\n alas, I did not scientifically bisect this ]\n\nThe problem is not that it fails, but rather, that the second time\naround, it fails differently (and irrecoverably):\n\n$ tc qdisc replace dev eth0 ingress_block 1 egress_block 1 clsact\nError: dsa_core: Flow block cb is busy.\n\n[ another note: the extack is added by me for illustration purposes.\n the context of the problem is that clsact_init() obtains the same\n &q->ingress_block pointer as &q->egress_block, and since we call\n tcf_block_get_ext() on both of them, \"dev\" will be added to the\n block->ports xarray twice, thus failing the operation: once through\n the ingress block pointer, and once again through the egress block\n pointer. the problem itself is that when xa_insert() fails, we have\n emitted a FLOW_BLOCK_BIND command through ndo_setup_tc(), but the\n offload never sees a corresponding FLOW_BLOCK_UNBIND. ]\n\nEven correcting the bad user input, we still cannot recover:\n\n$ tc qdisc replace dev swp3 ingress_block 1 egress_block 2 clsact\nError: dsa_core: Flow block cb is busy.\n\nBasically the only way to recover is to reboot the system, or unbind and\nrebind the net device driver.\n\nTo fix the bug, we need to fill the correct error teardown path which\nwas missed during code movement, and call tcf_block_offload_unbind()\nwhen xa_insert() fails.\n\n[ last note, fundamentally I blame the label naming convention in\n tcf_block_get_ext() for the bug. The labels should be named after what\n they do, not after the error path that jumps to them. This way, it is\n obviously wrong that two labels pointing to the same code mean\n something is wrong, and checking the code correctness at the goto site\n is also easier ]", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53044" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8966eb69a143b1c032365fe84f2815f3c46f2590" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a13e690191eafc154b3f60afe9ce35aa9b9128b4" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-g63v-c4x5-2g6v/GHSA-g63v-c4x5-2g6v.json b/advisories/unreviewed/2024/11/GHSA-g63v-c4x5-2g6v/GHSA-g63v-c4x5-2g6v.json new file mode 100644 index 00000000000..166ca61e72e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-g63v-c4x5-2g6v/GHSA-g63v-c4x5-2g6v.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g63v-c4x5-2g6v", + "modified": "2024-11-19T18:31:06Z", + "published": "2024-11-19T18:31:06Z", + "aliases": [ + "CVE-2024-53055" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: mvm: fix 6 GHz scan construction\n\nIf more than 255 colocated APs exist for the set of all\nAPs found during 2.4/5 GHz scanning, then the 6 GHz scan\nconstruction will loop forever since the loop variable\nhas type u8, which can never reach the number found when\nthat's bigger than 255, and is stored in a u32 variable.\nAlso move it into the loops to have a smaller scope.\n\nUsing a u32 there is fine, we limit the number of APs in\nthe scan list and each has a limit on the number of RNR\nentries due to the frame size. With a limit of 1000 scan\nresults, a frame size upper bound of 4096 (really it's\nmore like ~2300) and a TBTT entry size of at least 11,\nwe get an upper bound for the number of ~372k, well in\nthe bounds of a u32.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53055" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2ac15e5a8f42fed5d90ed9e1197600913678c50f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2ccd5badadab2d586e91546bf5af3deda07fef1f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7245012f0f496162dd95d888ed2ceb5a35170f1a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cde8a7eb5c6762264ff0f4433358e0a0d250c875" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fc621e7a043de346c33bd7ae7e2e0c651d6152ef" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-g76f-r4m8-gr75/GHSA-g76f-r4m8-gr75.json b/advisories/unreviewed/2024/11/GHSA-g76f-r4m8-gr75/GHSA-g76f-r4m8-gr75.json new file mode 100644 index 00000000000..a06da7dddbf --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-g76f-r4m8-gr75/GHSA-g76f-r4m8-gr75.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g76f-r4m8-gr75", + "modified": "2024-11-19T18:31:02Z", + "published": "2024-11-19T18:31:02Z", + "aliases": [ + "CVE-2024-51812" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wasim Pro Addons For Elementor allows Stored XSS.This issue affects Pro Addons For Elementor: from n/a through 1.5.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51812" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/pro-addons-for-elementor/wordpress-pro-addons-for-elementor-plugin-1-5-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-g77r-mcw3-wcx8/GHSA-g77r-mcw3-wcx8.json b/advisories/unreviewed/2024/11/GHSA-g77r-mcw3-wcx8/GHSA-g77r-mcw3-wcx8.json new file mode 100644 index 00000000000..1f4ae52e2b8 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-g77r-mcw3-wcx8/GHSA-g77r-mcw3-wcx8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g77r-mcw3-wcx8", + "modified": "2024-11-19T18:31:04Z", + "published": "2024-11-19T18:31:04Z", + "aliases": [ + "CVE-2024-51884" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Takashi Matsuyama Posts Search allows Stored XSS.This issue affects Posts Search: from n/a through 1.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51884" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/posts-search/wordpress-posts-search-plugin-1-2-2-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-ggmg-vvg8-55m2/GHSA-ggmg-vvg8-55m2.json b/advisories/unreviewed/2024/11/GHSA-ggmg-vvg8-55m2/GHSA-ggmg-vvg8-55m2.json new file mode 100644 index 00000000000..8a6b4c6d2c8 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-ggmg-vvg8-55m2/GHSA-ggmg-vvg8-55m2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ggmg-vvg8-55m2", + "modified": "2024-11-19T18:31:01Z", + "published": "2024-11-19T18:31:01Z", + "aliases": [ + "CVE-2024-51642" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in webhostri Seo Free allows Stored XSS.This issue affects Seo Free: from n/a through 1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51642" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/seo-free/wordpress-seo-free-plugin-1-4-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-gh8c-2875-38xv/GHSA-gh8c-2875-38xv.json b/advisories/unreviewed/2024/11/GHSA-gh8c-2875-38xv/GHSA-gh8c-2875-38xv.json new file mode 100644 index 00000000000..7cb779f50cd --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-gh8c-2875-38xv/GHSA-gh8c-2875-38xv.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gh8c-2875-38xv", + "modified": "2024-11-19T18:31:07Z", + "published": "2024-11-19T18:31:07Z", + "aliases": [ + "CVE-2024-53076" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: gts-helper: Fix memory leaks for the error path of iio_gts_build_avail_scale_table()\n\nIf per_time_scales[i] or per_time_gains[i] kcalloc fails in the for loop\nof iio_gts_build_avail_scale_table(), the err_free_out will fail to call\nkfree() each time when i is reduced to 0, so all the per_time_scales[0]\nand per_time_gains[0] will not be freed, which will cause memory leaks.\n\nFix it by checking if i >= 0.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53076" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/369f05688911b05216cfcd6ca74473bec87948d7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/62c11896683129790b8f5ab6eb7e695818b0b723" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b304362ce836968b803e5d4c5f84dcb51a7bf0f2" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-gm4p-xxcw-q3xf/GHSA-gm4p-xxcw-q3xf.json b/advisories/unreviewed/2024/11/GHSA-gm4p-xxcw-q3xf/GHSA-gm4p-xxcw-q3xf.json new file mode 100644 index 00000000000..987cd505fdb --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-gm4p-xxcw-q3xf/GHSA-gm4p-xxcw-q3xf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gm4p-xxcw-q3xf", + "modified": "2024-11-19T18:31:03Z", + "published": "2024-11-19T18:31:03Z", + "aliases": [ + "CVE-2024-51865" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in N.O.U.S. Open Useful and Simple Simple Social Share Block allows Stored XSS.This issue affects Simple Social Share Block: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51865" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/simple-social-share-block/wordpress-simple-social-share-block-plugin-1-0-0-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-gpf9-2frf-hch3/GHSA-gpf9-2frf-hch3.json b/advisories/unreviewed/2024/11/GHSA-gpf9-2frf-hch3/GHSA-gpf9-2frf-hch3.json new file mode 100644 index 00000000000..4192aae3450 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-gpf9-2frf-hch3/GHSA-gpf9-2frf-hch3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gpf9-2frf-hch3", + "modified": "2024-11-19T18:31:04Z", + "published": "2024-11-19T18:31:04Z", + "aliases": [ + "CVE-2024-51895" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Minical Minical Hotel Booking Plugin allows Stored XSS.This issue affects Minical Hotel Booking Plugin: from n/a through 1.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51895" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/minical/wordpress-minical-hotel-booking-plugin-plugin-1-0-2-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-gpvr-4p58-r896/GHSA-gpvr-4p58-r896.json b/advisories/unreviewed/2024/11/GHSA-gpvr-4p58-r896/GHSA-gpvr-4p58-r896.json new file mode 100644 index 00000000000..bb5088d84cd --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-gpvr-4p58-r896/GHSA-gpvr-4p58-r896.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gpvr-4p58-r896", + "modified": "2024-11-19T18:31:04Z", + "published": "2024-11-19T18:31:04Z", + "aliases": [ + "CVE-2024-51883" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Micha I Plant A Tree allows Stored XSS.This issue affects I Plant A Tree: from n/a through 1.7.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51883" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/i-plant-a-tree/wordpress-i-plant-a-tree-plugin-1-7-3-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-gr9q-mvmm-jr7v/GHSA-gr9q-mvmm-jr7v.json b/advisories/unreviewed/2024/11/GHSA-gr9q-mvmm-jr7v/GHSA-gr9q-mvmm-jr7v.json new file mode 100644 index 00000000000..43fe292620b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-gr9q-mvmm-jr7v/GHSA-gr9q-mvmm-jr7v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gr9q-mvmm-jr7v", + "modified": "2024-11-19T18:31:01Z", + "published": "2024-11-19T18:31:01Z", + "aliases": [ + "CVE-2024-50552" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jason Pancake Hover Video Preview allows Stored XSS.This issue affects Hover Video Preview: from n/a through 1.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50552" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/hover-video-preview/wordpress-hover-video-preview-plugin-1-0-2-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-gv5x-w6m9-qv2v/GHSA-gv5x-w6m9-qv2v.json b/advisories/unreviewed/2024/11/GHSA-gv5x-w6m9-qv2v/GHSA-gv5x-w6m9-qv2v.json new file mode 100644 index 00000000000..1dd8c31b363 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-gv5x-w6m9-qv2v/GHSA-gv5x-w6m9-qv2v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gv5x-w6m9-qv2v", + "modified": "2024-11-19T18:31:03Z", + "published": "2024-11-19T18:31:03Z", + "aliases": [ + "CVE-2024-51842" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sazzad Hu Image Carousel Shortcode allows DOM-Based XSS.This issue affects Image Carousel Shortcode: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51842" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/image-carousel-shortcode/wordpress-image-carousel-shortcode-plugin-1-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-h29g-hxg6-g48j/GHSA-h29g-hxg6-g48j.json b/advisories/unreviewed/2024/11/GHSA-h29g-hxg6-g48j/GHSA-h29g-hxg6-g48j.json new file mode 100644 index 00000000000..0024384ce3f --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-h29g-hxg6-g48j/GHSA-h29g-hxg6-g48j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h29g-hxg6-g48j", + "modified": "2024-11-19T18:31:04Z", + "published": "2024-11-19T18:31:04Z", + "aliases": [ + "CVE-2024-51901" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wojciech Borowicz Smooth Maps allows Stored XSS.This issue affects Smooth Maps: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51901" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/colour-smooth-maps/wordpress-smooth-maps-plugin-1-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-h2fw-j3h2-4fh6/GHSA-h2fw-j3h2-4fh6.json b/advisories/unreviewed/2024/11/GHSA-h2fw-j3h2-4fh6/GHSA-h2fw-j3h2-4fh6.json new file mode 100644 index 00000000000..36f6c63bb84 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-h2fw-j3h2-4fh6/GHSA-h2fw-j3h2-4fh6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h2fw-j3h2-4fh6", + "modified": "2024-11-19T18:31:03Z", + "published": "2024-11-19T18:31:03Z", + "aliases": [ + "CVE-2024-51830" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fazilatunnesa News Ticker allows Stored XSS.This issue affects News Ticker: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51830" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/newsticker/wordpress-news-ticker-plugin-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-h7jr-f9m2-rr37/GHSA-h7jr-f9m2-rr37.json b/advisories/unreviewed/2024/11/GHSA-h7jr-f9m2-rr37/GHSA-h7jr-f9m2-rr37.json new file mode 100644 index 00000000000..79b1ccf8c29 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-h7jr-f9m2-rr37/GHSA-h7jr-f9m2-rr37.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h7jr-f9m2-rr37", + "modified": "2024-11-19T18:31:06Z", + "published": "2024-11-19T18:31:06Z", + "aliases": [ + "CVE-2024-53051" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915/hdcp: Add encoder check in intel_hdcp_get_capability\n\nSometimes during hotplug scenario or suspend/resume scenario encoder is\nnot always initialized when intel_hdcp_get_capability add\na check to avoid kernel null pointer dereference.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53051" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/31b42af516afa1e184d1a9f9dd4096c54044269a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4912e8fb3c37fb2dedf48d9c18bbbecd70e720f8" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-h9q9-3g7p-gq9x/GHSA-h9q9-3g7p-gq9x.json b/advisories/unreviewed/2024/11/GHSA-h9q9-3g7p-gq9x/GHSA-h9q9-3g7p-gq9x.json index e041f864eb1..3e158f935de 100644 --- a/advisories/unreviewed/2024/11/GHSA-h9q9-3g7p-gq9x/GHSA-h9q9-3g7p-gq9x.json +++ b/advisories/unreviewed/2024/11/GHSA-h9q9-3g7p-gq9x/GHSA-h9q9-3g7p-gq9x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h9q9-3g7p-gq9x", - "modified": "2024-11-16T00:31:51Z", + "modified": "2024-11-19T18:30:57Z", "published": "2024-11-16T00:31:50Z", "aliases": [ "CVE-2017-13313" ], "details": "In ElementaryStreamQueue::dequeueAccessUnitMPEG4Video of ESQueue.cpp, there is a possible infinite loop leading to resource exhaustion due to an incorrect bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-15T22:15:14Z" diff --git a/advisories/unreviewed/2024/11/GHSA-h9vw-x7c8-cqgm/GHSA-h9vw-x7c8-cqgm.json b/advisories/unreviewed/2024/11/GHSA-h9vw-x7c8-cqgm/GHSA-h9vw-x7c8-cqgm.json new file mode 100644 index 00000000000..fd3b6dbfa06 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-h9vw-x7c8-cqgm/GHSA-h9vw-x7c8-cqgm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h9vw-x7c8-cqgm", + "modified": "2024-11-19T18:31:02Z", + "published": "2024-11-19T18:31:02Z", + "aliases": [ + "CVE-2024-51654" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in APK.Support APK Downloader allows Stored XSS.This issue affects APK Downloader: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51654" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/apk-downloader/wordpress-apk-downloader-plugin-1-0-0-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-hcpj-7xxx-7pm4/GHSA-hcpj-7xxx-7pm4.json b/advisories/unreviewed/2024/11/GHSA-hcpj-7xxx-7pm4/GHSA-hcpj-7xxx-7pm4.json index 7ddf4f6e6d5..4e07a3232d0 100644 --- a/advisories/unreviewed/2024/11/GHSA-hcpj-7xxx-7pm4/GHSA-hcpj-7xxx-7pm4.json +++ b/advisories/unreviewed/2024/11/GHSA-hcpj-7xxx-7pm4/GHSA-hcpj-7xxx-7pm4.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-hf57-pc64-3428/GHSA-hf57-pc64-3428.json b/advisories/unreviewed/2024/11/GHSA-hf57-pc64-3428/GHSA-hf57-pc64-3428.json new file mode 100644 index 00000000000..07af29a6eb2 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-hf57-pc64-3428/GHSA-hf57-pc64-3428.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hf57-pc64-3428", + "modified": "2024-11-19T18:31:00Z", + "published": "2024-11-19T18:31:00Z", + "aliases": [ + "CVE-2024-48071" + ], + "details": "An issue in the component /importmould/deletefolder of Weaver Ecology v9.* allows authenticated attackers to execute a directory traversal and arbitrarily delete files.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48071" + }, + { + "type": "WEB", + "url": "https://gist.github.com/CoinIsMoney/d437f267f2d65cb80dd7da97cb2068e8" + }, + { + "type": "WEB", + "url": "https://github.com/stuven1989/TemporaryGuild/blob/main/files/exp-eng-3.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-hfwx-j6h2-rmf7/GHSA-hfwx-j6h2-rmf7.json b/advisories/unreviewed/2024/11/GHSA-hfwx-j6h2-rmf7/GHSA-hfwx-j6h2-rmf7.json new file mode 100644 index 00000000000..21e6e43c739 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-hfwx-j6h2-rmf7/GHSA-hfwx-j6h2-rmf7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hfwx-j6h2-rmf7", + "modified": "2024-11-19T18:31:06Z", + "published": "2024-11-19T18:31:06Z", + "aliases": [ + "CVE-2024-42450" + ], + "details": "The Versa Director uses PostgreSQL (Postgres) to store operational and configuration data. It is also needed for High Availability function of the Versa Director. The default configuration has a common password across all instances of Versa Director. By default, Versa Director configures Postgres to listen on all network interfaces. This combination allows an unauthenticated attacker to access and administer the database or read local filesystem contents to escalate privileges on the system. \n\nExploitation Status:\nVersa Networks is not aware of this exploitation in any production systems. A proof of concept exists in the lab environment.\n\nWorkarounds or Mitigation:\nStarting with the latest 22.1.4 version of Versa Director, the software will automatically restrict access to the Postgres and HA ports to only the local and peer Versa Directors. For older releases, Versa recommends performing manual hardening of HA ports. Please refer to the following link for the steps https://docs.versa-networks.com/Solutions/System_Hardening/Perform_Manual_Hardening_for_Versa_Director#Secure_HA_Ports \n\nThis vulnerability is not exploitable on Versa Directors if published Firewall guidelines are implemented. We have validated that no Versa-hosted head ends have been affected by this vulnerability. All Versa-hosted head ends are patched and hardened. \n\nPlease contact Versa Technical Support or Versa account team for any further assistance.\n\nSoftware Download Links:\n22.1.4: https://support.versa-networks.com/support/solutions/articles/23000026708-release-22-1-4", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42450" + }, + { + "type": "WEB", + "url": "https://security-portal.versa-networks.com/emailbulletins/6735a300415abb89e9a8a9d3" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-hh3g-4c3h-9xq5/GHSA-hh3g-4c3h-9xq5.json b/advisories/unreviewed/2024/11/GHSA-hh3g-4c3h-9xq5/GHSA-hh3g-4c3h-9xq5.json new file mode 100644 index 00000000000..db2f9e65616 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-hh3g-4c3h-9xq5/GHSA-hh3g-4c3h-9xq5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hh3g-4c3h-9xq5", + "modified": "2024-11-19T18:31:01Z", + "published": "2024-11-19T18:31:01Z", + "aliases": [ + "CVE-2024-50538" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Irfan Ardiansah Show Visitor IP Address allows Stored XSS.This issue affects Show Visitor IP Address: from n/a through 0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50538" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/show-visitor-ip-address/wordpress-show-visitor-ip-address-plugin-0-2-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-hjf4-jrvv-979w/GHSA-hjf4-jrvv-979w.json b/advisories/unreviewed/2024/11/GHSA-hjf4-jrvv-979w/GHSA-hjf4-jrvv-979w.json new file mode 100644 index 00000000000..4efbf4db214 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-hjf4-jrvv-979w/GHSA-hjf4-jrvv-979w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hjf4-jrvv-979w", + "modified": "2024-11-19T18:31:01Z", + "published": "2024-11-19T18:31:01Z", + "aliases": [ + "CVE-2024-50546" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Print Reach, Inc. MyOrderDesk allows DOM-Based XSS.This issue affects MyOrderDesk: from n/a through 3.2.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50546" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/myorderdesk/wordpress-myorderdesk-plugin-3-2-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-hp9m-99c7-gwmq/GHSA-hp9m-99c7-gwmq.json b/advisories/unreviewed/2024/11/GHSA-hp9m-99c7-gwmq/GHSA-hp9m-99c7-gwmq.json new file mode 100644 index 00000000000..27d445b227e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-hp9m-99c7-gwmq/GHSA-hp9m-99c7-gwmq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hp9m-99c7-gwmq", + "modified": "2024-11-19T18:31:05Z", + "published": "2024-11-19T18:31:05Z", + "aliases": [ + "CVE-2024-51927" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Codember Rig Elements For Elementor allows DOM-Based XSS.This issue affects Rig Elements For Elementor: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51927" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/rig-elements/wordpress-rig-elements-for-elementor-plugin-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-hvf6-4mg8-8mgf/GHSA-hvf6-4mg8-8mgf.json b/advisories/unreviewed/2024/11/GHSA-hvf6-4mg8-8mgf/GHSA-hvf6-4mg8-8mgf.json new file mode 100644 index 00000000000..51b9c854010 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-hvf6-4mg8-8mgf/GHSA-hvf6-4mg8-8mgf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hvf6-4mg8-8mgf", + "modified": "2024-11-19T18:31:01Z", + "published": "2024-11-19T18:31:01Z", + "aliases": [ + "CVE-2024-51637" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Scott E. Royalty Admin SMS Alert allows Stored XSS.This issue affects Admin SMS Alert: from n/a through 1.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51637" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/admin-sms-alert/wordpress-admin-sms-alert-plugin-1-1-0-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-j2fh-p4jc-3h97/GHSA-j2fh-p4jc-3h97.json b/advisories/unreviewed/2024/11/GHSA-j2fh-p4jc-3h97/GHSA-j2fh-p4jc-3h97.json new file mode 100644 index 00000000000..439bb781d96 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-j2fh-p4jc-3h97/GHSA-j2fh-p4jc-3h97.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j2fh-p4jc-3h97", + "modified": "2024-11-19T18:31:07Z", + "published": "2024-11-19T18:31:07Z", + "aliases": [ + "CVE-2024-53059" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: mvm: Fix response handling in iwl_mvm_send_recovery_cmd()\n\n1. The size of the response packet is not validated.\n2. The response buffer is not freed.\n\nResolve these issues by switching to iwl_mvm_send_cmd_status(),\nwhich handles both size validation and frees the buffer.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53059" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/07a6e3b78a65f4b2796a8d0d4adb1a15a81edead" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3eb986c64c6bfb721950f9666a3b723cf65d043f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3f45d590ccbae6dfd6faef54efe74c30bd85d3da" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/45a628911d3c68e024eed337054a0452b064f450" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/64d63557ded6ff3ce72b18ab87a6c4b1b652161c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9480c3045f302f43f9910d2d556d6cf5a62c1822" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9c98ee7ea463a838235e7a0e35851b38476364f2" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-j5vh-vfg7-3v94/GHSA-j5vh-vfg7-3v94.json b/advisories/unreviewed/2024/11/GHSA-j5vh-vfg7-3v94/GHSA-j5vh-vfg7-3v94.json new file mode 100644 index 00000000000..9afe356168b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-j5vh-vfg7-3v94/GHSA-j5vh-vfg7-3v94.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j5vh-vfg7-3v94", + "modified": "2024-11-19T18:31:07Z", + "published": "2024-11-19T18:31:06Z", + "aliases": [ + "CVE-2024-53057" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: stop qdisc_tree_reduce_backlog on TC_H_ROOT\n\nIn qdisc_tree_reduce_backlog, Qdiscs with major handle ffff: are assumed\nto be either root or ingress. This assumption is bogus since it's valid\nto create egress qdiscs with major handle ffff:\nBudimir Markovic found that for qdiscs like DRR that maintain an active\nclass list, it will cause a UAF with a dangling class pointer.\n\nIn 066a3b5b2346, the concern was to avoid iterating over the ingress\nqdisc since its parent is itself. The proper fix is to stop when parent\nTC_H_ROOT is reached because the only way to retrieve ingress is when a\nhierarchy which does not contain a ffff: major handle call into\nqdisc_lookup with TC_H_MAJ(TC_H_ROOT).\n\nIn the scenario where major ffff: is an egress qdisc in any of the tree\nlevels, the updates will also propagate to TC_H_ROOT, which then the\niteration must stop.\n\n\n net/sched/sch_api.c | 2 +-\n 1 file changed, 1 insertion(+), 1 deletion(-)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53057" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/05df1b1dff8f197f1c275b57ccb2ca33021df552" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2e95c4384438adeaa772caa560244b1a2efef816" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/580b3189c1972aff0f993837567d36392e9d981b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/597cf9748c3477bf61bc35f0634129f56764ad24" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9995909615c3431a5304c1210face5f268d24dba" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ce691c814bc7a3c30c220ffb5b7422715458fd9b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dbe778b08b5101df9e89bc06e0a3a7ecd2f4ef20" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e7f9a6f97eb067599a74f3bcb6761976b0ed303e" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-j5w7-63fj-6h4c/GHSA-j5w7-63fj-6h4c.json b/advisories/unreviewed/2024/11/GHSA-j5w7-63fj-6h4c/GHSA-j5w7-63fj-6h4c.json index d05688d3961..849eff52b52 100644 --- a/advisories/unreviewed/2024/11/GHSA-j5w7-63fj-6h4c/GHSA-j5w7-63fj-6h4c.json +++ b/advisories/unreviewed/2024/11/GHSA-j5w7-63fj-6h4c/GHSA-j5w7-63fj-6h4c.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-j68m-vr9h-7553/GHSA-j68m-vr9h-7553.json b/advisories/unreviewed/2024/11/GHSA-j68m-vr9h-7553/GHSA-j68m-vr9h-7553.json new file mode 100644 index 00000000000..a9fde12c8fb --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-j68m-vr9h-7553/GHSA-j68m-vr9h-7553.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j68m-vr9h-7553", + "modified": "2024-11-19T18:31:00Z", + "published": "2024-11-19T18:31:00Z", + "aliases": [ + "CVE-2024-50518" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Common Ninja Pricer Ninja allows Stored XSS.This issue affects Pricer Ninja: from n/a through 2.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50518" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/pricer-ninja-pricing-tables/wordpress-pricer-ninja-plugin-2-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-j6m7-43jh-w34q/GHSA-j6m7-43jh-w34q.json b/advisories/unreviewed/2024/11/GHSA-j6m7-43jh-w34q/GHSA-j6m7-43jh-w34q.json new file mode 100644 index 00000000000..c41a9a1826b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-j6m7-43jh-w34q/GHSA-j6m7-43jh-w34q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6m7-43jh-w34q", + "modified": "2024-11-19T18:31:02Z", + "published": "2024-11-19T18:31:02Z", + "aliases": [ + "CVE-2024-51816" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saul Morales Pacheco Banner System allows Stored XSS.This issue affects Banner System: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51816" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/banner-system/wordpress-banner-system-plugin-1-0-0-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-j6x9-wwrp-prcf/GHSA-j6x9-wwrp-prcf.json b/advisories/unreviewed/2024/11/GHSA-j6x9-wwrp-prcf/GHSA-j6x9-wwrp-prcf.json new file mode 100644 index 00000000000..dcc583810e4 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-j6x9-wwrp-prcf/GHSA-j6x9-wwrp-prcf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6x9-wwrp-prcf", + "modified": "2024-11-19T18:31:01Z", + "published": "2024-11-19T18:31:01Z", + "aliases": [ + "CVE-2024-51635" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Garmur While Loading allows Stored XSS.This issue affects While Loading: from n/a through 3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51635" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/while-it-is-loading/wordpress-while-loading-plugin-3-0-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-j7jv-w7wp-p2c3/GHSA-j7jv-w7wp-p2c3.json b/advisories/unreviewed/2024/11/GHSA-j7jv-w7wp-p2c3/GHSA-j7jv-w7wp-p2c3.json index d373585d35d..38f5240d7da 100644 --- a/advisories/unreviewed/2024/11/GHSA-j7jv-w7wp-p2c3/GHSA-j7jv-w7wp-p2c3.json +++ b/advisories/unreviewed/2024/11/GHSA-j7jv-w7wp-p2c3/GHSA-j7jv-w7wp-p2c3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j7jv-w7wp-p2c3", - "modified": "2024-11-16T00:31:51Z", + "modified": "2024-11-19T18:30:57Z", "published": "2024-11-16T00:31:51Z", "aliases": [ "CVE-2024-51764" ], "details": "A security vulnerability has been identified in HPE Data Management Framework (DMF) Suite (CXFS). Depending on configuration, this vulnerability may lead to local/cluster unauthorized access.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-15T22:15:16Z" diff --git a/advisories/unreviewed/2024/11/GHSA-jfgv-5f9v-whcx/GHSA-jfgv-5f9v-whcx.json b/advisories/unreviewed/2024/11/GHSA-jfgv-5f9v-whcx/GHSA-jfgv-5f9v-whcx.json new file mode 100644 index 00000000000..c126a0e2ea1 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jfgv-5f9v-whcx/GHSA-jfgv-5f9v-whcx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jfgv-5f9v-whcx", + "modified": "2024-11-19T18:31:01Z", + "published": "2024-11-19T18:31:01Z", + "aliases": [ + "CVE-2024-50549" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bonway Services Bonway Static Block Editor allows DOM-Based XSS.This issue affects Bonway Static Block Editor: from n/a through 1.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50549" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/bonway-static-block-editor/wordpress-bonway-static-block-editor-plugin-1-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jfhm-j25g-cc8g/GHSA-jfhm-j25g-cc8g.json b/advisories/unreviewed/2024/11/GHSA-jfhm-j25g-cc8g/GHSA-jfhm-j25g-cc8g.json index a99c5783e18..95928be2adc 100644 --- a/advisories/unreviewed/2024/11/GHSA-jfhm-j25g-cc8g/GHSA-jfhm-j25g-cc8g.json +++ b/advisories/unreviewed/2024/11/GHSA-jfhm-j25g-cc8g/GHSA-jfhm-j25g-cc8g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jfhm-j25g-cc8g", - "modified": "2024-11-16T00:31:51Z", + "modified": "2024-11-19T18:30:57Z", "published": "2024-11-16T00:31:50Z", "aliases": [ "CVE-2017-13311" ], "details": "In the read() function of ProcessStats.java, there is a possible read/write serialization issue leading to a permissions bypass. This could lead to local escalation of privilege where an app can start an activity with system privileges with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-15T22:15:14Z" diff --git a/advisories/unreviewed/2024/11/GHSA-jhv7-p7w6-pw88/GHSA-jhv7-p7w6-pw88.json b/advisories/unreviewed/2024/11/GHSA-jhv7-p7w6-pw88/GHSA-jhv7-p7w6-pw88.json new file mode 100644 index 00000000000..c23dfc28764 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jhv7-p7w6-pw88/GHSA-jhv7-p7w6-pw88.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jhv7-p7w6-pw88", + "modified": "2024-11-19T18:31:03Z", + "published": "2024-11-19T18:31:03Z", + "aliases": [ + "CVE-2024-51860" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DuoGeek Custom Dashboard Widget allows Stored XSS.This issue affects Custom Dashboard Widget: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51860" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/create-custom-dashboard-widget/wordpress-custom-dashboard-widget-plugin-1-0-0-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jmjg-j2x5-82q8/GHSA-jmjg-j2x5-82q8.json b/advisories/unreviewed/2024/11/GHSA-jmjg-j2x5-82q8/GHSA-jmjg-j2x5-82q8.json new file mode 100644 index 00000000000..eefd4775218 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jmjg-j2x5-82q8/GHSA-jmjg-j2x5-82q8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jmjg-j2x5-82q8", + "modified": "2024-11-19T18:31:01Z", + "published": "2024-11-19T18:31:01Z", + "aliases": [ + "CVE-2024-50545" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Auburnforest DataMentor allows DOM-Based XSS.This issue affects DataMentor: from n/a through 1.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50545" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/datamentor/wordpress-datamentor-plugin-1-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jvf8-6jxw-rf4x/GHSA-jvf8-6jxw-rf4x.json b/advisories/unreviewed/2024/11/GHSA-jvf8-6jxw-rf4x/GHSA-jvf8-6jxw-rf4x.json new file mode 100644 index 00000000000..3159829abdc --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jvf8-6jxw-rf4x/GHSA-jvf8-6jxw-rf4x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jvf8-6jxw-rf4x", + "modified": "2024-11-19T18:31:03Z", + "published": "2024-11-19T18:31:03Z", + "aliases": [ + "CVE-2024-51819" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tigris – Flexplatform Tigris Flexplatform allows Stored XSS.This issue affects Tigris Flexplatform: from n/a through .0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51819" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/tigris-flexplatform/wordpress-tigris-flexplatform-plugin-1-0-2-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jvv6-rqgj-96j7/GHSA-jvv6-rqgj-96j7.json b/advisories/unreviewed/2024/11/GHSA-jvv6-rqgj-96j7/GHSA-jvv6-rqgj-96j7.json new file mode 100644 index 00000000000..04b6979c6d7 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jvv6-rqgj-96j7/GHSA-jvv6-rqgj-96j7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jvv6-rqgj-96j7", + "modified": "2024-11-19T18:31:03Z", + "published": "2024-11-19T18:31:03Z", + "aliases": [ + "CVE-2024-51861" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in duogeek EventPress allows Stored XSS.This issue affects EventPress: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51861" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-eventpress/wordpress-eventpress-plugin-1-0-0-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jwcx-68j5-jrh6/GHSA-jwcx-68j5-jrh6.json b/advisories/unreviewed/2024/11/GHSA-jwcx-68j5-jrh6/GHSA-jwcx-68j5-jrh6.json new file mode 100644 index 00000000000..1ae2106ad01 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jwcx-68j5-jrh6/GHSA-jwcx-68j5-jrh6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jwcx-68j5-jrh6", + "modified": "2024-11-19T18:31:03Z", + "published": "2024-11-19T18:31:03Z", + "aliases": [ + "CVE-2024-51840" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rezaul haque Wd-image-magnifier-xoss allows DOM-Based XSS.This issue affects Wd-image-magnifier-xoss: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51840" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wd-image-magnifier-xoss/wordpress-wd-image-magnifier-xoss-plugin-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jxg2-g8jw-r8cj/GHSA-jxg2-g8jw-r8cj.json b/advisories/unreviewed/2024/11/GHSA-jxg2-g8jw-r8cj/GHSA-jxg2-g8jw-r8cj.json index 8a15519c23d..07fedb78a77 100644 --- a/advisories/unreviewed/2024/11/GHSA-jxg2-g8jw-r8cj/GHSA-jxg2-g8jw-r8cj.json +++ b/advisories/unreviewed/2024/11/GHSA-jxg2-g8jw-r8cj/GHSA-jxg2-g8jw-r8cj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jxg2-g8jw-r8cj", - "modified": "2024-11-12T21:30:51Z", + "modified": "2024-11-19T18:30:54Z", "published": "2024-11-12T21:30:51Z", "aliases": [ "CVE-2023-52268" ], "details": "The End-User Portal module before 1.0.65 for FreeScout sometimes allows an attacker to authenticate as an arbitrary user because a session token can be sent to the /auth endpoint. NOTE: this module is not part of freescout-helpdesk/freescout on GitHub.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-384" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-12T19:15:07Z" diff --git a/advisories/unreviewed/2024/11/GHSA-jxgm-wv4j-x2w3/GHSA-jxgm-wv4j-x2w3.json b/advisories/unreviewed/2024/11/GHSA-jxgm-wv4j-x2w3/GHSA-jxgm-wv4j-x2w3.json new file mode 100644 index 00000000000..0d0c6050026 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jxgm-wv4j-x2w3/GHSA-jxgm-wv4j-x2w3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jxgm-wv4j-x2w3", + "modified": "2024-11-19T18:31:03Z", + "published": "2024-11-19T18:31:03Z", + "aliases": [ + "CVE-2024-51841" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeNcode File Select Control For Elementor allows DOM-Based XSS.This issue affects File Select Control For Elementor: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51841" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/file-select-control-for-elementor/wordpress-file-select-control-for-elementor-plugin-1-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-m2w9-hmqh-m77h/GHSA-m2w9-hmqh-m77h.json b/advisories/unreviewed/2024/11/GHSA-m2w9-hmqh-m77h/GHSA-m2w9-hmqh-m77h.json new file mode 100644 index 00000000000..4c8a2e0008e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-m2w9-hmqh-m77h/GHSA-m2w9-hmqh-m77h.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m2w9-hmqh-m77h", + "modified": "2024-11-19T18:31:06Z", + "published": "2024-11-19T18:31:06Z", + "aliases": [ + "CVE-2024-53043" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmctp i2c: handle NULL header address\n\ndaddr can be NULL if there is no neighbour table entry present,\nin that case the tx packet should be dropped.\n\nsaddr will usually be set by MCTP core, but check for NULL in case a\npacket is transmitted by a different protocol.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53043" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/01e215975fd80af81b5b79f009d49ddd35976c13" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4707893315802a0917231b94cb20cbe50ccbfe03" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8c222adadc1612e4f097688875962a28e3f5ab44" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8e886e44397ba89f6e8da8471386112b4f5b67b7" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-m3h2-jj4m-f3r9/GHSA-m3h2-jj4m-f3r9.json b/advisories/unreviewed/2024/11/GHSA-m3h2-jj4m-f3r9/GHSA-m3h2-jj4m-f3r9.json new file mode 100644 index 00000000000..fba876f2470 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-m3h2-jj4m-f3r9/GHSA-m3h2-jj4m-f3r9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m3h2-jj4m-f3r9", + "modified": "2024-11-19T18:31:02Z", + "published": "2024-11-19T18:31:02Z", + "aliases": [ + "CVE-2024-51810" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in George Lewe Lewe Bootstrap Visuals allows Stored XSS.This issue affects Lewe Bootstrap Visuals: from n/a through 2.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51810" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/shortcode-bootstrap-visuals/wordpress-lewe-bootstrap-visuals-plugin-2-2-2-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-m3m4-wgh9-w3h5/GHSA-m3m4-wgh9-w3h5.json b/advisories/unreviewed/2024/11/GHSA-m3m4-wgh9-w3h5/GHSA-m3m4-wgh9-w3h5.json index 03d32075368..0258621abfa 100644 --- a/advisories/unreviewed/2024/11/GHSA-m3m4-wgh9-w3h5/GHSA-m3m4-wgh9-w3h5.json +++ b/advisories/unreviewed/2024/11/GHSA-m3m4-wgh9-w3h5/GHSA-m3m4-wgh9-w3h5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m3m4-wgh9-w3h5", - "modified": "2024-11-12T00:30:36Z", + "modified": "2024-11-19T18:30:54Z", "published": "2024-11-12T00:30:36Z", "aliases": [ "CVE-2024-25255" ], "details": "Sublime Text 4 was discovered to contain a command injection vulnerability via the New Build System module.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-11T23:15:05Z" diff --git a/advisories/unreviewed/2024/11/GHSA-m55g-97f8-c8vx/GHSA-m55g-97f8-c8vx.json b/advisories/unreviewed/2024/11/GHSA-m55g-97f8-c8vx/GHSA-m55g-97f8-c8vx.json new file mode 100644 index 00000000000..3a605f65160 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-m55g-97f8-c8vx/GHSA-m55g-97f8-c8vx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m55g-97f8-c8vx", + "modified": "2024-11-19T18:31:04Z", + "published": "2024-11-19T18:31:04Z", + "aliases": [ + "CVE-2024-51874" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ParOne, Inc. ParOne Feeds allows DOM-Based XSS.This issue affects ParOne Feeds: from n/a through 1.17.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51874" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/parone/wordpress-parone-feeds-plugin-1-17-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-m5vv-7jxc-8p6x/GHSA-m5vv-7jxc-8p6x.json b/advisories/unreviewed/2024/11/GHSA-m5vv-7jxc-8p6x/GHSA-m5vv-7jxc-8p6x.json new file mode 100644 index 00000000000..f4b37264d6d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-m5vv-7jxc-8p6x/GHSA-m5vv-7jxc-8p6x.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m5vv-7jxc-8p6x", + "modified": "2024-11-19T18:31:00Z", + "published": "2024-11-19T18:31:00Z", + "aliases": [ + "CVE-2024-50803" + ], + "details": "The mediapool feature of the Redaxo Core CMS application v 5.17.1 is vulnerable to Cross Site Scripting(XSS) which allows a remote attacker to escalate privileges", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50803" + }, + { + "type": "WEB", + "url": "https://github.com/Praison001/CVE-2024-50803-Redaxo" + }, + { + "type": "WEB", + "url": "http://redaxo-core.com" + }, + { + "type": "WEB", + "url": "http://redaxo.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T16:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-m79j-g4w8-7827/GHSA-m79j-g4w8-7827.json b/advisories/unreviewed/2024/11/GHSA-m79j-g4w8-7827/GHSA-m79j-g4w8-7827.json new file mode 100644 index 00000000000..917b75c85c9 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-m79j-g4w8-7827/GHSA-m79j-g4w8-7827.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m79j-g4w8-7827", + "modified": "2024-11-19T18:31:02Z", + "published": "2024-11-19T18:31:01Z", + "aliases": [ + "CVE-2024-51649" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Patrick Lumumba Mobilize allows Stored XSS.This issue affects Mobilize: from n/a through 3.0.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51649" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/mobilize/wordpress-mobilize-plugin-3-0-7-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-m8hc-32hf-2jqr/GHSA-m8hc-32hf-2jqr.json b/advisories/unreviewed/2024/11/GHSA-m8hc-32hf-2jqr/GHSA-m8hc-32hf-2jqr.json new file mode 100644 index 00000000000..a9a42d7b844 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-m8hc-32hf-2jqr/GHSA-m8hc-32hf-2jqr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m8hc-32hf-2jqr", + "modified": "2024-11-19T18:31:02Z", + "published": "2024-11-19T18:31:02Z", + "aliases": [ + "CVE-2024-51794" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Storely allows Stored XSS.This issue affects Storely: from n/a through 14.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51794" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/storely/wordpress-storely-theme-14-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mcr8-cmcm-2p3c/GHSA-mcr8-cmcm-2p3c.json b/advisories/unreviewed/2024/11/GHSA-mcr8-cmcm-2p3c/GHSA-mcr8-cmcm-2p3c.json index eb64bd2a598..624a8f60509 100644 --- a/advisories/unreviewed/2024/11/GHSA-mcr8-cmcm-2p3c/GHSA-mcr8-cmcm-2p3c.json +++ b/advisories/unreviewed/2024/11/GHSA-mcr8-cmcm-2p3c/GHSA-mcr8-cmcm-2p3c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mcr8-cmcm-2p3c", - "modified": "2024-11-16T00:31:50Z", + "modified": "2024-11-19T18:30:57Z", "published": "2024-11-16T00:31:50Z", "aliases": [ "CVE-2017-13312" ], "details": "In createFromParcel of MediaCas.java, there is a possible parcel read/write mismatch due to improper input validation. This could lead to local escalation of privilege where an app can start an activity with system privileges with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-15T22:15:14Z" diff --git a/advisories/unreviewed/2024/11/GHSA-mh8w-gxgh-8grm/GHSA-mh8w-gxgh-8grm.json b/advisories/unreviewed/2024/11/GHSA-mh8w-gxgh-8grm/GHSA-mh8w-gxgh-8grm.json new file mode 100644 index 00000000000..cd758a0a6ef --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mh8w-gxgh-8grm/GHSA-mh8w-gxgh-8grm.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mh8w-gxgh-8grm", + "modified": "2024-11-19T18:31:07Z", + "published": "2024-11-19T18:31:07Z", + "aliases": [ + "CVE-2024-53067" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: ufs: core: Start the RTC update work later\n\nThe RTC update work involves runtime resuming the UFS controller. Hence,\nonly start the RTC update work after runtime power management in the UFS\ndriver has been fully initialized. This patch fixes the following kernel\ncrash:\n\nInternal error: Oops: 0000000096000006 [#1] PREEMPT SMP\nWorkqueue: events ufshcd_rtc_work\nCall trace:\n _raw_spin_lock_irqsave+0x34/0x8c (P)\n pm_runtime_get_if_active+0x24/0x9c (L)\n pm_runtime_get_if_active+0x24/0x9c\n ufshcd_rtc_work+0x138/0x1b4\n process_one_work+0x148/0x288\n worker_thread+0x2cc/0x3d4\n kthread+0x110/0x114\n ret_from_fork+0x10/0x20", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53067" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4c25f784fba81227e0437337f962d34380d1c250" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/54c814c8b23bc7617be3d46abdb896937695dbfa" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mm63-c923-gw6c/GHSA-mm63-c923-gw6c.json b/advisories/unreviewed/2024/11/GHSA-mm63-c923-gw6c/GHSA-mm63-c923-gw6c.json new file mode 100644 index 00000000000..425e8ae5b1f --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mm63-c923-gw6c/GHSA-mm63-c923-gw6c.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mm63-c923-gw6c", + "modified": "2024-11-19T18:31:06Z", + "published": "2024-11-19T18:31:06Z", + "aliases": [ + "CVE-2024-53054" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncgroup/bpf: use a dedicated workqueue for cgroup bpf destruction\n\nA hung_task problem shown below was found:\n\nINFO: task kworker/0:0:8 blocked for more than 327 seconds.\n\"echo 0 > /proc/sys/kernel/hung_task_timeout_secs\" disables this message.\nWorkqueue: events cgroup_bpf_release\nCall Trace:\n \n __schedule+0x5a2/0x2050\n ? find_held_lock+0x33/0x100\n ? wq_worker_sleeping+0x9e/0xe0\n schedule+0x9f/0x180\n schedule_preempt_disabled+0x25/0x50\n __mutex_lock+0x512/0x740\n ? cgroup_bpf_release+0x1e/0x4d0\n ? cgroup_bpf_release+0xcf/0x4d0\n ? process_scheduled_works+0x161/0x8a0\n ? cgroup_bpf_release+0x1e/0x4d0\n ? mutex_lock_nested+0x2b/0x40\n ? __pfx_delay_tsc+0x10/0x10\n mutex_lock_nested+0x2b/0x40\n cgroup_bpf_release+0xcf/0x4d0\n ? process_scheduled_works+0x161/0x8a0\n ? trace_event_raw_event_workqueue_execute_start+0x64/0xd0\n ? process_scheduled_works+0x161/0x8a0\n process_scheduled_works+0x23a/0x8a0\n worker_thread+0x231/0x5b0\n ? __pfx_worker_thread+0x10/0x10\n kthread+0x14d/0x1c0\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x59/0x70\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1b/0x30\n \n\nThis issue can be reproduced by the following pressuse test:\n1. A large number of cpuset cgroups are deleted.\n2. Set cpu on and off repeatly.\n3. Set watchdog_thresh repeatly.\nThe scripts can be obtained at LINK mentioned above the signature.\n\nThe reason for this issue is cgroup_mutex and cpu_hotplug_lock are\nacquired in different tasks, which may lead to deadlock.\nIt can lead to a deadlock through the following steps:\n1. A large number of cpusets are deleted asynchronously, which puts a\n large number of cgroup_bpf_release works into system_wq. The max_active\n of system_wq is WQ_DFL_ACTIVE(256). Consequently, all active works are\n cgroup_bpf_release works, and many cgroup_bpf_release works will be put\n into inactive queue. As illustrated in the diagram, there are 256 (in\n the acvtive queue) + n (in the inactive queue) works.\n2. Setting watchdog_thresh will hold cpu_hotplug_lock.read and put\n smp_call_on_cpu work into system_wq. However step 1 has already filled\n system_wq, 'sscs.work' is put into inactive queue. 'sscs.work' has\n to wait until the works that were put into the inacvtive queue earlier\n have executed (n cgroup_bpf_release), so it will be blocked for a while.\n3. Cpu offline requires cpu_hotplug_lock.write, which is blocked by step 2.\n4. Cpusets that were deleted at step 1 put cgroup_release works into\n cgroup_destroy_wq. They are competing to get cgroup_mutex all the time.\n When cgroup_metux is acqured by work at css_killed_work_fn, it will\n call cpuset_css_offline, which needs to acqure cpu_hotplug_lock.read.\n However, cpuset_css_offline will be blocked for step 3.\n5. At this moment, there are 256 works in active queue that are\n cgroup_bpf_release, they are attempting to acquire cgroup_mutex, and as\n a result, all of them are blocked. Consequently, sscs.work can not be\n executed. Ultimately, this situation leads to four processes being\n blocked, forming a deadlock.\n\nsystem_wq(step1)\t\tWatchDog(step2)\t\t\tcpu offline(step3)\tcgroup_destroy_wq(step4)\n...\n2000+ cgroups deleted asyn\n256 actives + n inactives\n\t\t\t\t__lockup_detector_reconfigure\n\t\t\t\tP(cpu_hotplug_lock.read)\n\t\t\t\tput sscs.work into system_wq\n256 + n + 1(sscs.work)\nsscs.work wait to be executed\n\t\t\t\twarting sscs.work finish\n\t\t\t\t\t\t\t\tpercpu_down_write\n\t\t\t\t\t\t\t\tP(cpu_hotplug_lock.write)\n\t\t\t\t\t\t\t\t...blocking...\n\t\t\t\t\t\t\t\t\t\t\tcss_killed_work_fn\n\t\t\t\t\t\t\t\t\t\t\tP(cgroup_mutex)\n\t\t\t\t\t\t\t\t\t\t\tcpuset_css_offline\n\t\t\t\t\t\t\t\t\t\t\tP(cpu_hotplug_lock.read)\n\t\t\t\t\t\t\t\t\t\t\t...blocking...\n256 cgroup_bpf_release\nmutex_lock(&cgroup_mutex);\n..blocking...\n\nTo fix the problem, place cgroup_bpf_release works on a dedicated\nworkqueue which can break the loop and solve the problem. System wqs are\nfor misc things which shouldn't create a large number of concurrent work\nitems. If something is going to generate >\n---truncated---", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53054" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0d86cd70fc6a7ba18becb52ad8334d5ad3eca530" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/117932eea99b729ee5d12783601a4f7f5fd58a23" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6dab3331523ba73db1345d19e6f586dcd5f6efb4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/71f14a9f5c7db72fdbc56e667d4ed42a1a760494" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mqv3-f225-3xw2/GHSA-mqv3-f225-3xw2.json b/advisories/unreviewed/2024/11/GHSA-mqv3-f225-3xw2/GHSA-mqv3-f225-3xw2.json index 3b3bdf37b08..954e202293e 100644 --- a/advisories/unreviewed/2024/11/GHSA-mqv3-f225-3xw2/GHSA-mqv3-f225-3xw2.json +++ b/advisories/unreviewed/2024/11/GHSA-mqv3-f225-3xw2/GHSA-mqv3-f225-3xw2.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mqv3-f225-3xw2", - "modified": "2024-11-14T21:32:03Z", + "modified": "2024-11-19T18:30:56Z", "published": "2024-11-14T21:32:03Z", "aliases": [ "CVE-2024-10396" ], "details": "An authenticated user can provide a malformed ACL to the fileserver's StoreACL\nRPC, causing the fileserver to crash, possibly expose uninitialized memory, and\npossibly store garbage data in the audit log.\nMalformed ACLs provided in responses to client FetchACL RPCs can cause client\nprocesses to crash and possibly expose uninitialized memory into other ACLs\nstored on the server.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/11/GHSA-mw9x-2qwv-599p/GHSA-mw9x-2qwv-599p.json b/advisories/unreviewed/2024/11/GHSA-mw9x-2qwv-599p/GHSA-mw9x-2qwv-599p.json index b3ec1794aff..9ef1cf1ce2b 100644 --- a/advisories/unreviewed/2024/11/GHSA-mw9x-2qwv-599p/GHSA-mw9x-2qwv-599p.json +++ b/advisories/unreviewed/2024/11/GHSA-mw9x-2qwv-599p/GHSA-mw9x-2qwv-599p.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mw9x-2qwv-599p", - "modified": "2024-11-18T18:30:58Z", + "modified": "2024-11-19T18:30:59Z", "published": "2024-11-18T18:30:58Z", "aliases": [ "CVE-2024-0012" ], "details": "An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities like CVE-2024-9474 https://security.paloaltonetworks.com/CVE-2024-9474 .\n\nThe risk of this issue is greatly reduced if you secure access to the management web interface by restricting access to only trusted internal IP addresses according to our recommended  best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .\n\nThis issue is applicable only to PAN-OS 10.2, PAN-OS 11.0, PAN-OS 11.1, and PAN-OS 11.2 software.\n\nCloud NGFW and Prisma Access are not impacted by this vulnerability.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:Red" diff --git a/advisories/unreviewed/2024/11/GHSA-mxpx-p28m-mmww/GHSA-mxpx-p28m-mmww.json b/advisories/unreviewed/2024/11/GHSA-mxpx-p28m-mmww/GHSA-mxpx-p28m-mmww.json new file mode 100644 index 00000000000..90427237d35 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mxpx-p28m-mmww/GHSA-mxpx-p28m-mmww.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mxpx-p28m-mmww", + "modified": "2024-11-19T18:31:03Z", + "published": "2024-11-19T18:31:03Z", + "aliases": [ + "CVE-2024-51836" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Teconce Wezido allows DOM-Based XSS.This issue affects Wezido: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51836" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wezido-elementor-addon-based-on-easy-digital-downloads/wordpress-wezido-plugin-1-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-p3w4-3pq3-x7jm/GHSA-p3w4-3pq3-x7jm.json b/advisories/unreviewed/2024/11/GHSA-p3w4-3pq3-x7jm/GHSA-p3w4-3pq3-x7jm.json new file mode 100644 index 00000000000..6ca7e93d6f0 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-p3w4-3pq3-x7jm/GHSA-p3w4-3pq3-x7jm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p3w4-3pq3-x7jm", + "modified": "2024-11-19T18:31:04Z", + "published": "2024-11-19T18:31:04Z", + "aliases": [ + "CVE-2024-51897" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Erik Saulnier News Articles allows Stored XSS.This issue affects News Articles: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51897" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/news-articles/wordpress-news-articles-plugin-1-0-0-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-p3xg-2r2p-7rm4/GHSA-p3xg-2r2p-7rm4.json b/advisories/unreviewed/2024/11/GHSA-p3xg-2r2p-7rm4/GHSA-p3xg-2r2p-7rm4.json new file mode 100644 index 00000000000..dcf3e6613ab --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-p3xg-2r2p-7rm4/GHSA-p3xg-2r2p-7rm4.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p3xg-2r2p-7rm4", + "modified": "2024-11-19T18:31:07Z", + "published": "2024-11-19T18:31:07Z", + "aliases": [ + "CVE-2024-53081" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: ar0521: don't overflow when checking PLL values\n\nThe PLL checks are comparing 64 bit integers with 32 bit\nones, as reported by Coverity. Depending on the values of\nthe variables, this may underflow.\n\nFix it ensuring that both sides of the expression are u64.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53081" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/438d3085ba5b8b5bfa5290faa594e577f6ac9aa7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5e1523076acf95b4ea68d19b6f27e6891267cc24" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/97ed0c0332d5525653668b31acf62ff1e6b50784" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a244b82d0ae60326901f2b50c15e3118298b7ecd" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-p4hm-8mwq-2h86/GHSA-p4hm-8mwq-2h86.json b/advisories/unreviewed/2024/11/GHSA-p4hm-8mwq-2h86/GHSA-p4hm-8mwq-2h86.json new file mode 100644 index 00000000000..18238e0fc73 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-p4hm-8mwq-2h86/GHSA-p4hm-8mwq-2h86.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p4hm-8mwq-2h86", + "modified": "2024-11-19T18:31:05Z", + "published": "2024-11-19T18:31:05Z", + "aliases": [ + "CVE-2024-52402" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Cliconomics Exclusive Content Password Protect allows Upload a Web Shell to a Web Server.This issue affects Exclusive Content Password Protect: from n/a through 1.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52402" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/exclusive-content-password-protect/wordpress-exclusive-content-password-protect-plugin-1-1-0-csrf-to-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-p4mv-gm84-6fw2/GHSA-p4mv-gm84-6fw2.json b/advisories/unreviewed/2024/11/GHSA-p4mv-gm84-6fw2/GHSA-p4mv-gm84-6fw2.json new file mode 100644 index 00000000000..6dd2c16861d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-p4mv-gm84-6fw2/GHSA-p4mv-gm84-6fw2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p4mv-gm84-6fw2", + "modified": "2024-11-19T18:31:03Z", + "published": "2024-11-19T18:31:03Z", + "aliases": [ + "CVE-2024-51834" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Luzuk Luzuk Slider allows Stored XSS.This issue affects Luzuk Slider: from n/a through 0.1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51834" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/luzuk-slider/wordpress-luzuk-slider-plugin-0-1-5-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-p5f5-7hv4-9wpx/GHSA-p5f5-7hv4-9wpx.json b/advisories/unreviewed/2024/11/GHSA-p5f5-7hv4-9wpx/GHSA-p5f5-7hv4-9wpx.json new file mode 100644 index 00000000000..35f3aea6796 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-p5f5-7hv4-9wpx/GHSA-p5f5-7hv4-9wpx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p5f5-7hv4-9wpx", + "modified": "2024-11-19T18:31:03Z", + "published": "2024-11-19T18:31:03Z", + "aliases": [ + "CVE-2024-51855" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Productineer Redirecter allows DOM-Based XSS.This issue affects Redirecter: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51855" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/shortcode-for-redirection/wordpress-redirecter-plugin-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-p6r6-34c3-vr68/GHSA-p6r6-34c3-vr68.json b/advisories/unreviewed/2024/11/GHSA-p6r6-34c3-vr68/GHSA-p6r6-34c3-vr68.json new file mode 100644 index 00000000000..079e51f909d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-p6r6-34c3-vr68/GHSA-p6r6-34c3-vr68.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p6r6-34c3-vr68", + "modified": "2024-11-19T18:31:03Z", + "published": "2024-11-19T18:31:03Z", + "aliases": [ + "CVE-2024-51839" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Meini Utech Spinning Earth allows DOM-Based XSS.This issue affects Utech Spinning Earth: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51839" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/utech-spinning-earth/wordpress-utech-spinning-earth-plugin-1-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-p747-x98p-7r7q/GHSA-p747-x98p-7r7q.json b/advisories/unreviewed/2024/11/GHSA-p747-x98p-7r7q/GHSA-p747-x98p-7r7q.json new file mode 100644 index 00000000000..0c152c25afc --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-p747-x98p-7r7q/GHSA-p747-x98p-7r7q.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p747-x98p-7r7q", + "modified": "2024-11-19T18:31:06Z", + "published": "2024-11-19T18:31:06Z", + "aliases": [ + "CVE-2024-50303" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nresource,kexec: walk_system_ram_res_rev must retain resource flags\n\nwalk_system_ram_res_rev() erroneously discards resource flags when passing\nthe information to the callback.\n\nThis causes systems with IORESOURCE_SYSRAM_DRIVER_MANAGED memory to have\nthese resources selected during kexec to store kexec buffers if that\nmemory happens to be at placed above normal system ram.\n\nThis leads to undefined behavior after reboot. If the kexec buffer is\nnever touched, nothing happens. If the kexec buffer is touched, it could\nlead to a crash (like below) or undefined behavior.\n\nTested on a system with CXL memory expanders with driver managed memory,\nTPM enabled, and CONFIG_IMA_KEXEC=y. Adding printk's showed the flags\nwere being discarded and as a result the check for\nIORESOURCE_SYSRAM_DRIVER_MANAGED passes.\n\nfind_next_iomem_res: name(System RAM (kmem))\n\t\t start(10000000000)\n\t\t end(1034fffffff)\n\t\t flags(83000200)\n\nlocate_mem_hole_top_down: start(10000000000) end(1034fffffff) flags(0)\n\n[.] BUG: unable to handle page fault for address: ffff89834ffff000\n[.] #PF: supervisor read access in kernel mode\n[.] #PF: error_code(0x0000) - not-present page\n[.] PGD c04c8bf067 P4D c04c8bf067 PUD c04c8be067 PMD 0\n[.] Oops: 0000 [#1] SMP\n[.] RIP: 0010:ima_restore_measurement_list+0x95/0x4b0\n[.] RSP: 0018:ffffc900000d3a80 EFLAGS: 00010286\n[.] RAX: 0000000000001000 RBX: 0000000000000000 RCX: ffff89834ffff000\n[.] RDX: 0000000000000018 RSI: ffff89834ffff000 RDI: ffff89834ffff018\n[.] RBP: ffffc900000d3ba0 R08: 0000000000000020 R09: ffff888132b8a900\n[.] R10: 4000000000000000 R11: 000000003a616d69 R12: 0000000000000000\n[.] R13: ffffffff8404ac28 R14: 0000000000000000 R15: ffff89834ffff000\n[.] FS: 0000000000000000(0000) GS:ffff893d44640000(0000) knlGS:0000000000000000\n[.] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[.] ata5: SATA link down (SStatus 0 SControl 300)\n[.] CR2: ffff89834ffff000 CR3: 000001034d00f001 CR4: 0000000000770ef0\n[.] PKRU: 55555554\n[.] Call Trace:\n[.] \n[.] ? __die+0x78/0xc0\n[.] ? page_fault_oops+0x2a8/0x3a0\n[.] ? exc_page_fault+0x84/0x130\n[.] ? asm_exc_page_fault+0x22/0x30\n[.] ? ima_restore_measurement_list+0x95/0x4b0\n[.] ? template_desc_init_fields+0x317/0x410\n[.] ? crypto_alloc_tfm_node+0x9c/0xc0\n[.] ? init_ima_lsm+0x30/0x30\n[.] ima_load_kexec_buffer+0x72/0xa0\n[.] ima_init+0x44/0xa0\n[.] __initstub__kmod_ima__373_1201_init_ima7+0x1e/0xb0\n[.] ? init_ima_lsm+0x30/0x30\n[.] do_one_initcall+0xad/0x200\n[.] ? idr_alloc_cyclic+0xaa/0x110\n[.] ? new_slab+0x12c/0x420\n[.] ? new_slab+0x12c/0x420\n[.] ? number+0x12a/0x430\n[.] ? sysvec_apic_timer_interrupt+0xa/0x80\n[.] ? asm_sysvec_apic_timer_interrupt+0x16/0x20\n[.] ? parse_args+0xd4/0x380\n[.] ? parse_args+0x14b/0x380\n[.] kernel_init_freeable+0x1c1/0x2b0\n[.] ? rest_init+0xb0/0xb0\n[.] kernel_init+0x16/0x1a0\n[.] ret_from_fork+0x2f/0x40\n[.] ? rest_init+0xb0/0xb0\n[.] ret_from_fork_asm+0x11/0x20\n[.] ", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50303" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b125a0def25a082ae944c9615208bf359abdb61c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dc9031b7919bd346514ea9a720f433b8daf3970d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-p87g-j8m4-pq52/GHSA-p87g-j8m4-pq52.json b/advisories/unreviewed/2024/11/GHSA-p87g-j8m4-pq52/GHSA-p87g-j8m4-pq52.json index e9456dc6d75..5b379e6e299 100644 --- a/advisories/unreviewed/2024/11/GHSA-p87g-j8m4-pq52/GHSA-p87g-j8m4-pq52.json +++ b/advisories/unreviewed/2024/11/GHSA-p87g-j8m4-pq52/GHSA-p87g-j8m4-pq52.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p87g-j8m4-pq52", - "modified": "2024-11-08T18:30:50Z", + "modified": "2024-11-19T18:30:54Z", "published": "2024-11-08T06:30:49Z", "aliases": [ "CVE-2024-50202" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: propagate directory read errors from nilfs_find_entry()\n\nSyzbot reported that a task hang occurs in vcs_open() during a fuzzing\ntest for nilfs2.\n\nThe root cause of this problem is that in nilfs_find_entry(), which\nsearches for directory entries, ignores errors when loading a directory\npage/folio via nilfs_get_folio() fails.\n\nIf the filesystem images is corrupted, and the i_size of the directory\ninode is large, and the directory page/folio is successfully read but\nfails the sanity check, for example when it is zero-filled,\nnilfs_check_folio() may continue to spit out error messages in bursts.\n\nFix this issue by propagating the error to the callers when loading a\npage/folio fails in nilfs_find_entry().\n\nThe current interface of nilfs_find_entry() and its callers is outdated\nand cannot propagate error codes such as -EIO and -ENOMEM returned via\nnilfs_find_entry(), so fix it together.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-755" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-08T06:15:16Z" diff --git a/advisories/unreviewed/2024/11/GHSA-pf3m-7gr7-926f/GHSA-pf3m-7gr7-926f.json b/advisories/unreviewed/2024/11/GHSA-pf3m-7gr7-926f/GHSA-pf3m-7gr7-926f.json new file mode 100644 index 00000000000..0730f5fd64d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-pf3m-7gr7-926f/GHSA-pf3m-7gr7-926f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pf3m-7gr7-926f", + "modified": "2024-11-19T18:31:04Z", + "published": "2024-11-19T18:31:04Z", + "aliases": [ + "CVE-2024-51893" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeAtelier Postify: Post Layout For Elementor allows DOM-Based XSS.This issue affects Postify: Post Layout For Elementor: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51893" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/postify-for-elementor/wordpress-postify-post-layout-for-elementor-plugin-1-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-pfvf-x267-f8rm/GHSA-pfvf-x267-f8rm.json b/advisories/unreviewed/2024/11/GHSA-pfvf-x267-f8rm/GHSA-pfvf-x267-f8rm.json new file mode 100644 index 00000000000..3c3424700e6 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-pfvf-x267-f8rm/GHSA-pfvf-x267-f8rm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pfvf-x267-f8rm", + "modified": "2024-11-19T18:31:03Z", + "published": "2024-11-19T18:31:03Z", + "aliases": [ + "CVE-2024-51831" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aboutorab Pourhaghani Persian Nested Show/Hide Text allows Stored XSS.This issue affects Persian Nested Show/Hide Text: from n/a through 1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51831" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/persian-nested-showhide-text/wordpress-persian-nested-show-hide-text-plugin-1-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-pjh6-pqrj-qmjf/GHSA-pjh6-pqrj-qmjf.json b/advisories/unreviewed/2024/11/GHSA-pjh6-pqrj-qmjf/GHSA-pjh6-pqrj-qmjf.json new file mode 100644 index 00000000000..39c4772acee --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-pjh6-pqrj-qmjf/GHSA-pjh6-pqrj-qmjf.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pjh6-pqrj-qmjf", + "modified": "2024-11-19T18:31:07Z", + "published": "2024-11-19T18:31:07Z", + "aliases": [ + "CVE-2024-53078" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/tegra: Fix NULL vs IS_ERR() check in probe()\n\nThe iommu_paging_domain_alloc() function doesn't return NULL pointers,\nit returns error pointers. Update the check to match.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53078" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6d6c005855b97b8caf6039c1774745ee74c91fa6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a85df8c7b5ee2d3d4823befada42c5c41aff4cb0" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-pmrc-966v-gr3q/GHSA-pmrc-966v-gr3q.json b/advisories/unreviewed/2024/11/GHSA-pmrc-966v-gr3q/GHSA-pmrc-966v-gr3q.json new file mode 100644 index 00000000000..f4420d23d0c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-pmrc-966v-gr3q/GHSA-pmrc-966v-gr3q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pmrc-966v-gr3q", + "modified": "2024-11-19T18:31:01Z", + "published": "2024-11-19T18:31:01Z", + "aliases": [ + "CVE-2024-51636" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Z.com by GMO GMO Social Connection allows Cross-Site Scripting (XSS).This issue affects GMO Social Connection: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51636" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/gmo-social-connection/wordpress-plugin-name-gmo-social-connection-plugin-1-2-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-pp55-x3vr-94gx/GHSA-pp55-x3vr-94gx.json b/advisories/unreviewed/2024/11/GHSA-pp55-x3vr-94gx/GHSA-pp55-x3vr-94gx.json new file mode 100644 index 00000000000..d7fffeec5be --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-pp55-x3vr-94gx/GHSA-pp55-x3vr-94gx.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pp55-x3vr-94gx", + "modified": "2024-11-19T18:31:06Z", + "published": "2024-11-19T18:31:06Z", + "aliases": [ + "CVE-2024-53042" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: ip_tunnel: Fix suspicious RCU usage warning in ip_tunnel_init_flow()\n\nThere are code paths from which the function is called without holding\nthe RCU read lock, resulting in a suspicious RCU usage warning [1].\n\nFix by using l3mdev_master_upper_ifindex_by_index() which will acquire\nthe RCU read lock before calling\nl3mdev_master_upper_ifindex_by_index_rcu().\n\n[1]\nWARNING: suspicious RCU usage\n6.12.0-rc3-custom-gac8f72681cf2 #141 Not tainted\n-----------------------------\nnet/core/dev.c:876 RCU-list traversed in non-reader section!!\n\nother info that might help us debug this:\n\nrcu_scheduler_active = 2, debug_locks = 1\n1 lock held by ip/361:\n #0: ffffffff86fc7cb0 (rtnl_mutex){+.+.}-{3:3}, at: rtnetlink_rcv_msg+0x377/0xf60\n\nstack backtrace:\nCPU: 3 UID: 0 PID: 361 Comm: ip Not tainted 6.12.0-rc3-custom-gac8f72681cf2 #141\nHardware name: Bochs Bochs, BIOS Bochs 01/01/2011\nCall Trace:\n \n dump_stack_lvl+0xba/0x110\n lockdep_rcu_suspicious.cold+0x4f/0xd6\n dev_get_by_index_rcu+0x1d3/0x210\n l3mdev_master_upper_ifindex_by_index_rcu+0x2b/0xf0\n ip_tunnel_bind_dev+0x72f/0xa00\n ip_tunnel_newlink+0x368/0x7a0\n ipgre_newlink+0x14c/0x170\n __rtnl_newlink+0x1173/0x19c0\n rtnl_newlink+0x6c/0xa0\n rtnetlink_rcv_msg+0x3cc/0xf60\n netlink_rcv_skb+0x171/0x450\n netlink_unicast+0x539/0x7f0\n netlink_sendmsg+0x8c1/0xd80\n ____sys_sendmsg+0x8f9/0xc20\n ___sys_sendmsg+0x197/0x1e0\n __sys_sendmsg+0x122/0x1f0\n do_syscall_64+0xbb/0x1d0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53042" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5edcb3fdb12c3d46a6e79eeeec27d925b80fc168" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/699b48fc31727792edf2cab3829586ae6ba649e2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6dfaa458fe923211c766238a224e0a3c0522935c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/72c0f482e39c87317ebf67661e28c8d86c93e870" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ad4a3ca6a8e886f6491910a3ae5d53595e40597d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e2742758c9c85c84e077ede5f916479f724e11c2" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-pp64-vq4m-47h3/GHSA-pp64-vq4m-47h3.json b/advisories/unreviewed/2024/11/GHSA-pp64-vq4m-47h3/GHSA-pp64-vq4m-47h3.json index d4b2cde7c91..547752169bf 100644 --- a/advisories/unreviewed/2024/11/GHSA-pp64-vq4m-47h3/GHSA-pp64-vq4m-47h3.json +++ b/advisories/unreviewed/2024/11/GHSA-pp64-vq4m-47h3/GHSA-pp64-vq4m-47h3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pp64-vq4m-47h3", - "modified": "2024-11-08T06:30:49Z", + "modified": "2024-11-19T18:30:54Z", "published": "2024-11-08T06:30:49Z", "aliases": [ "CVE-2024-50204" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs: don't try and remove empty rbtree node\n\nWhen copying a namespace we won't have added the new copy into the\nnamespace rbtree until after the copy succeeded. Calling free_mnt_ns()\nwill try to remove the copy from the rbtree which is invalid. Simply\nfree the namespace skeleton directly.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-08T06:15:16Z" diff --git a/advisories/unreviewed/2024/11/GHSA-ppj4-7gjh-f85r/GHSA-ppj4-7gjh-f85r.json b/advisories/unreviewed/2024/11/GHSA-ppj4-7gjh-f85r/GHSA-ppj4-7gjh-f85r.json new file mode 100644 index 00000000000..68e7d09fc0e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-ppj4-7gjh-f85r/GHSA-ppj4-7gjh-f85r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ppj4-7gjh-f85r", + "modified": "2024-11-19T18:31:01Z", + "published": "2024-11-19T18:31:01Z", + "aliases": [ + "CVE-2024-51645" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Themefuse ThemeFuse Maintenance Mode allows Stored XSS.This issue affects ThemeFuse Maintenance Mode: from n/a through 1.1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51645" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/themefuse-maintenance-mode/wordpress-themefuse-maintenance-mode-plugin-1-1-3-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-prvm-q4qw-w4gx/GHSA-prvm-q4qw-w4gx.json b/advisories/unreviewed/2024/11/GHSA-prvm-q4qw-w4gx/GHSA-prvm-q4qw-w4gx.json new file mode 100644 index 00000000000..f5e368153dc --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-prvm-q4qw-w4gx/GHSA-prvm-q4qw-w4gx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-prvm-q4qw-w4gx", + "modified": "2024-11-19T18:31:01Z", + "published": "2024-11-19T18:31:01Z", + "aliases": [ + "CVE-2024-51633" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in IvyCat Web Services Simple Page Specific Sidebars allows Stored XSS.This issue affects Simple Page Specific Sidebars: from n/a through 2.14.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51633" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/page-specific-sidebars/wordpress-simple-page-specific-sidebars-plugin-2-14-1-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-pvpr-32hp-969g/GHSA-pvpr-32hp-969g.json b/advisories/unreviewed/2024/11/GHSA-pvpr-32hp-969g/GHSA-pvpr-32hp-969g.json new file mode 100644 index 00000000000..b210383fb73 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-pvpr-32hp-969g/GHSA-pvpr-32hp-969g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pvpr-32hp-969g", + "modified": "2024-11-19T18:31:05Z", + "published": "2024-11-19T18:31:05Z", + "aliases": [ + "CVE-2024-51912" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lilaea Media IntelliWidget Elements allows DOM-Based XSS.This issue affects IntelliWidget Elements: from n/a through 2.2.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51912" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/intelliwidget-elements/wordpress-intelliwidget-elements-plugin-2-2-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-q3q5-2v5f-27x5/GHSA-q3q5-2v5f-27x5.json b/advisories/unreviewed/2024/11/GHSA-q3q5-2v5f-27x5/GHSA-q3q5-2v5f-27x5.json new file mode 100644 index 00000000000..71a72058489 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-q3q5-2v5f-27x5/GHSA-q3q5-2v5f-27x5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q3q5-2v5f-27x5", + "modified": "2024-11-19T18:31:01Z", + "published": "2024-11-19T18:31:01Z", + "aliases": [ + "CVE-2024-50536" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Intuitive Design GDReseller allows DOM-Based XSS.This issue affects GDReseller: from n/a through 1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50536" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/gdreseller/wordpress-gdreseller-plugin-1-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-q4cm-g2jm-8qx9/GHSA-q4cm-g2jm-8qx9.json b/advisories/unreviewed/2024/11/GHSA-q4cm-g2jm-8qx9/GHSA-q4cm-g2jm-8qx9.json new file mode 100644 index 00000000000..bd0291bf730 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-q4cm-g2jm-8qx9/GHSA-q4cm-g2jm-8qx9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q4cm-g2jm-8qx9", + "modified": "2024-11-19T18:31:03Z", + "published": "2024-11-19T18:31:03Z", + "aliases": [ + "CVE-2024-51829" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Figoli Quinn & Associates Mobile Kiosk allows Stored XSS.This issue affects Mobile Kiosk: from n/a through 1.3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51829" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/mobile-kiosk/wordpress-mobile-kiosk-plugin-1-3-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-q5mh-gwp9-x87m/GHSA-q5mh-gwp9-x87m.json b/advisories/unreviewed/2024/11/GHSA-q5mh-gwp9-x87m/GHSA-q5mh-gwp9-x87m.json new file mode 100644 index 00000000000..a37b01558cb --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-q5mh-gwp9-x87m/GHSA-q5mh-gwp9-x87m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q5mh-gwp9-x87m", + "modified": "2024-11-19T18:31:04Z", + "published": "2024-11-19T18:31:04Z", + "aliases": [ + "CVE-2024-51898" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sachin Jadhav Semantic Shortcode allows Stored XSS.This issue affects Semantic Shortcode: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51898" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/semantic-shortcode/wordpress-semantic-shortcode-plugin-1-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qf34-69mr-2hfx/GHSA-qf34-69mr-2hfx.json b/advisories/unreviewed/2024/11/GHSA-qf34-69mr-2hfx/GHSA-qf34-69mr-2hfx.json new file mode 100644 index 00000000000..04ed86bbf11 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qf34-69mr-2hfx/GHSA-qf34-69mr-2hfx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qf34-69mr-2hfx", + "modified": "2024-11-19T18:31:02Z", + "published": "2024-11-19T18:31:02Z", + "aliases": [ + "CVE-2024-51648" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Hands, Inc e-shops allows Reflected XSS.This issue affects e-shops: from n/a through 1.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51648" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/e-shops-cart2/wordpress-e-shops-plugin-1-0-3-csrf-to-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qf6g-hc26-w8mg/GHSA-qf6g-hc26-w8mg.json b/advisories/unreviewed/2024/11/GHSA-qf6g-hc26-w8mg/GHSA-qf6g-hc26-w8mg.json new file mode 100644 index 00000000000..d9915683968 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qf6g-hc26-w8mg/GHSA-qf6g-hc26-w8mg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qf6g-hc26-w8mg", + "modified": "2024-11-19T18:31:03Z", + "published": "2024-11-19T18:31:03Z", + "aliases": [ + "CVE-2024-51844" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kiran Patil Location Click Map allows Stored XSS.This issue affects Location Click Map: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51844" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/location-click-map/wordpress-location-click-map-plugin-1-0-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qfrw-x46f-qv6r/GHSA-qfrw-x46f-qv6r.json b/advisories/unreviewed/2024/11/GHSA-qfrw-x46f-qv6r/GHSA-qfrw-x46f-qv6r.json new file mode 100644 index 00000000000..842489dd089 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qfrw-x46f-qv6r/GHSA-qfrw-x46f-qv6r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qfrw-x46f-qv6r", + "modified": "2024-11-19T18:31:03Z", + "published": "2024-11-19T18:31:03Z", + "aliases": [ + "CVE-2024-51859" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bamboo Mcr Bamboo Enquiries allows Stored XSS.This issue affects Bamboo Enquiries: from n/a through 1.9.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51859" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/bamboo-enquiries/wordpress-bamboo-enquiries-plugin-1-9-3-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qgc5-rj8x-fc6x/GHSA-qgc5-rj8x-fc6x.json b/advisories/unreviewed/2024/11/GHSA-qgc5-rj8x-fc6x/GHSA-qgc5-rj8x-fc6x.json new file mode 100644 index 00000000000..1dc1df19eb8 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qgc5-rj8x-fc6x/GHSA-qgc5-rj8x-fc6x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qgc5-rj8x-fc6x", + "modified": "2024-11-19T18:31:05Z", + "published": "2024-11-19T18:31:05Z", + "aliases": [ + "CVE-2024-51920" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JDev Map Store Locator allows DOM-Based XSS.This issue affects Map Store Locator: from n/a through 1.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51920" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/map-store-location/wordpress-map-store-locator-plugin-1-2-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qh3x-8m6r-29r6/GHSA-qh3x-8m6r-29r6.json b/advisories/unreviewed/2024/11/GHSA-qh3x-8m6r-29r6/GHSA-qh3x-8m6r-29r6.json new file mode 100644 index 00000000000..f87c9462951 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qh3x-8m6r-29r6/GHSA-qh3x-8m6r-29r6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qh3x-8m6r-29r6", + "modified": "2024-11-19T18:31:03Z", + "published": "2024-11-19T18:31:03Z", + "aliases": [ + "CVE-2024-51849" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marco Piarulli My Restaurant Menu allows Stored XSS.This issue affects My Restaurant Menu: from n/a through 0.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51849" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/my-restaurant-menu/wordpress-my-restaurant-menu-plugin-0-2-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qh6g-wvgm-fwfg/GHSA-qh6g-wvgm-fwfg.json b/advisories/unreviewed/2024/11/GHSA-qh6g-wvgm-fwfg/GHSA-qh6g-wvgm-fwfg.json new file mode 100644 index 00000000000..39793026469 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qh6g-wvgm-fwfg/GHSA-qh6g-wvgm-fwfg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qh6g-wvgm-fwfg", + "modified": "2024-11-19T18:31:05Z", + "published": "2024-11-19T18:31:05Z", + "aliases": [ + "CVE-2024-51921" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in midori scrollup allows DOM-Based XSS.This issue affects scrollup: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51921" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/scrollup/wordpress-scrollup-plugin-1-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qjx8-h9wc-h7j9/GHSA-qjx8-h9wc-h7j9.json b/advisories/unreviewed/2024/11/GHSA-qjx8-h9wc-h7j9/GHSA-qjx8-h9wc-h7j9.json new file mode 100644 index 00000000000..c6cb3e68b38 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qjx8-h9wc-h7j9/GHSA-qjx8-h9wc-h7j9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qjx8-h9wc-h7j9", + "modified": "2024-11-19T18:31:01Z", + "published": "2024-11-19T18:31:01Z", + "aliases": [ + "CVE-2024-50548" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Abdullah Nahian Awesome Progress Bar allows DOM-Based XSS.This issue affects Awesome Progress Bar: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50548" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/awesome-progess-bar/wordpress-awesome-progress-bar-plugin-1-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qm83-29c6-cf2c/GHSA-qm83-29c6-cf2c.json b/advisories/unreviewed/2024/11/GHSA-qm83-29c6-cf2c/GHSA-qm83-29c6-cf2c.json new file mode 100644 index 00000000000..de14e1cba34 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qm83-29c6-cf2c/GHSA-qm83-29c6-cf2c.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qm83-29c6-cf2c", + "modified": "2024-11-19T18:31:07Z", + "published": "2024-11-19T18:31:07Z", + "aliases": [ + "CVE-2024-53082" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvirtio_net: Add hash_key_length check\n\nAdd hash_key_length check in virtnet_probe() to avoid possible out of\nbound errors when setting/reading the hash key.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53082" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3f7d9c1964fcd16d02a8a9d4fd6f6cb60c4cc530" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6a18a783b1fa590ad1ed785907263e4b86adcfe2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/af0aa8aecbe8985079232902894cc4cb62795691" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f3401e3c8d339ddb6ccb2e3d11ad634b7846a806" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qmxp-r8m7-qpxp/GHSA-qmxp-r8m7-qpxp.json b/advisories/unreviewed/2024/11/GHSA-qmxp-r8m7-qpxp/GHSA-qmxp-r8m7-qpxp.json new file mode 100644 index 00000000000..b8612bdec94 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qmxp-r8m7-qpxp/GHSA-qmxp-r8m7-qpxp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qmxp-r8m7-qpxp", + "modified": "2024-11-19T18:31:00Z", + "published": "2024-11-19T18:31:00Z", + "aliases": [ + "CVE-2024-50519" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visser Labs Jigoshop – Store Exporter allows Reflected XSS.This issue affects Jigoshop – Store Exporter: from n/a through 1.5.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50519" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/jigoshop-exporter/wordpress-jigoshop-store-exporter-plugin-1-5-8-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qq67-p454-7jfc/GHSA-qq67-p454-7jfc.json b/advisories/unreviewed/2024/11/GHSA-qq67-p454-7jfc/GHSA-qq67-p454-7jfc.json new file mode 100644 index 00000000000..20efe5248eb --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qq67-p454-7jfc/GHSA-qq67-p454-7jfc.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qq67-p454-7jfc", + "modified": "2024-11-19T18:31:06Z", + "published": "2024-11-19T18:31:06Z", + "aliases": [ + "CVE-2024-53053" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: ufs: core: Fix another deadlock during RTC update\n\nIf ufshcd_rtc_work calls ufshcd_rpm_put_sync() and the pm's usage_count\nis 0, we will enter the runtime suspend callback. However, the runtime\nsuspend callback will wait to flush ufshcd_rtc_work, causing a deadlock.\n\nReplace ufshcd_rpm_put_sync() with ufshcd_rpm_put() to avoid the\ndeadlock.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53053" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a128cfec44709ab1bd1f01d158569bcb2386f54f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cb7e509c4e0197f63717fee54fb41c4990ba8d3a" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qqh6-573q-j4w7/GHSA-qqh6-573q-j4w7.json b/advisories/unreviewed/2024/11/GHSA-qqh6-573q-j4w7/GHSA-qqh6-573q-j4w7.json new file mode 100644 index 00000000000..f87cbe4bfb5 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qqh6-573q-j4w7/GHSA-qqh6-573q-j4w7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qqh6-573q-j4w7", + "modified": "2024-11-19T18:31:02Z", + "published": "2024-11-19T18:31:02Z", + "aliases": [ + "CVE-2024-51656" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in litefeel Flash Show And Hide Box allows Stored XSS.This issue affects Flash Show And Hide Box: from n/a through 1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51656" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/flash-show-and-hide-box/wordpress-flash-show-and-hide-box-plugin-1-6-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qr8x-vx57-f875/GHSA-qr8x-vx57-f875.json b/advisories/unreviewed/2024/11/GHSA-qr8x-vx57-f875/GHSA-qr8x-vx57-f875.json new file mode 100644 index 00000000000..4fafca1907c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qr8x-vx57-f875/GHSA-qr8x-vx57-f875.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qr8x-vx57-f875", + "modified": "2024-11-19T18:31:04Z", + "published": "2024-11-19T18:31:04Z", + "aliases": [ + "CVE-2024-51880" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BeBetter Hotels BeBetter Social Icons allows DOM-Based XSS.This issue affects BeBetter Social Icons: from n/a through 2.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51880" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/bebetter-social-icons/wordpress-bebetter-social-icons-plugin-2-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qrvg-j482-9r53/GHSA-qrvg-j482-9r53.json b/advisories/unreviewed/2024/11/GHSA-qrvg-j482-9r53/GHSA-qrvg-j482-9r53.json new file mode 100644 index 00000000000..920bb3d0dfa --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qrvg-j482-9r53/GHSA-qrvg-j482-9r53.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qrvg-j482-9r53", + "modified": "2024-11-19T18:31:03Z", + "published": "2024-11-19T18:31:03Z", + "aliases": [ + "CVE-2024-51823" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sherwin Calims Add Ribbon Shortcode allows DOM-Based XSS.This issue affects Add Ribbon Shortcode: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51823" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/add-ribbon/wordpress-add-ribbon-shortcode-plugin-1-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qvfj-fv3r-6gxc/GHSA-qvfj-fv3r-6gxc.json b/advisories/unreviewed/2024/11/GHSA-qvfj-fv3r-6gxc/GHSA-qvfj-fv3r-6gxc.json new file mode 100644 index 00000000000..8e479a4413c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qvfj-fv3r-6gxc/GHSA-qvfj-fv3r-6gxc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qvfj-fv3r-6gxc", + "modified": "2024-11-19T18:31:04Z", + "published": "2024-11-19T18:31:04Z", + "aliases": [ + "CVE-2024-51894" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Reyzua Topbar ID for Elementor allows DOM-Based XSS.This issue affects Topbar ID for Elementor: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51894" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/topbar-id-for-elementor/wordpress-topbar-id-for-elementor-plugin-1-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qxp5-vjrm-298x/GHSA-qxp5-vjrm-298x.json b/advisories/unreviewed/2024/11/GHSA-qxp5-vjrm-298x/GHSA-qxp5-vjrm-298x.json index b556b812ecb..c6f32560807 100644 --- a/advisories/unreviewed/2024/11/GHSA-qxp5-vjrm-298x/GHSA-qxp5-vjrm-298x.json +++ b/advisories/unreviewed/2024/11/GHSA-qxp5-vjrm-298x/GHSA-qxp5-vjrm-298x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qxp5-vjrm-298x", - "modified": "2024-11-18T09:31:14Z", + "modified": "2024-11-19T18:30:58Z", "published": "2024-11-18T09:31:14Z", "aliases": [ "CVE-2024-47208" ], "details": "Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz.\n\nThis issue affects Apache OFBiz: before 18.12.17.\n\nUsers are recommended to upgrade to version 18.12.17, which fixes the issue.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ "CWE-918" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-18T09:15:06Z" diff --git a/advisories/unreviewed/2024/11/GHSA-r2hm-v6g9-pjcm/GHSA-r2hm-v6g9-pjcm.json b/advisories/unreviewed/2024/11/GHSA-r2hm-v6g9-pjcm/GHSA-r2hm-v6g9-pjcm.json new file mode 100644 index 00000000000..7c66b1545e6 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-r2hm-v6g9-pjcm/GHSA-r2hm-v6g9-pjcm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r2hm-v6g9-pjcm", + "modified": "2024-11-19T18:31:02Z", + "published": "2024-11-19T18:31:02Z", + "aliases": [ + "CVE-2024-51799" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VBog Bg Patriarchia BU allows DOM-Based XSS.This issue affects Bg Patriarchia BU: from n/a through 2.2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51799" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/bg-patriarchia-bu/wordpress-bg-patriarchia-bu-plugin-2-2-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-r3wj-h9cw-w763/GHSA-r3wj-h9cw-w763.json b/advisories/unreviewed/2024/11/GHSA-r3wj-h9cw-w763/GHSA-r3wj-h9cw-w763.json new file mode 100644 index 00000000000..8e913073d4f --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-r3wj-h9cw-w763/GHSA-r3wj-h9cw-w763.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r3wj-h9cw-w763", + "modified": "2024-11-19T18:31:01Z", + "published": "2024-11-19T18:31:01Z", + "aliases": [ + "CVE-2024-51643" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Rajan Agaskar Amazon Associate Filter allows Stored XSS.This issue affects Amazon Associate Filter: from n/a through 0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51643" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/amazon-associate-filter/wordpress-amazon-associate-filter-plugin-0-4-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-r59c-8gpj-2fqr/GHSA-r59c-8gpj-2fqr.json b/advisories/unreviewed/2024/11/GHSA-r59c-8gpj-2fqr/GHSA-r59c-8gpj-2fqr.json index 6fc19511ea3..da4bf4ff49e 100644 --- a/advisories/unreviewed/2024/11/GHSA-r59c-8gpj-2fqr/GHSA-r59c-8gpj-2fqr.json +++ b/advisories/unreviewed/2024/11/GHSA-r59c-8gpj-2fqr/GHSA-r59c-8gpj-2fqr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r59c-8gpj-2fqr", - "modified": "2024-11-18T18:30:59Z", + "modified": "2024-11-19T18:30:58Z", "published": "2024-11-18T18:30:59Z", "aliases": [ "CVE-2024-48292" ], "details": "An issue in the wssrvc.exe service of QuickHeal Antivirus Pro Version v24.0 and Quick Heal Total Security v24.0 allows authenticated attackers to escalate privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-18T18:15:06Z" diff --git a/advisories/unreviewed/2024/11/GHSA-r6fq-j5gx-rmcc/GHSA-r6fq-j5gx-rmcc.json b/advisories/unreviewed/2024/11/GHSA-r6fq-j5gx-rmcc/GHSA-r6fq-j5gx-rmcc.json new file mode 100644 index 00000000000..7e89811942f --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-r6fq-j5gx-rmcc/GHSA-r6fq-j5gx-rmcc.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r6fq-j5gx-rmcc", + "modified": "2024-11-19T18:31:06Z", + "published": "2024-11-19T18:31:06Z", + "aliases": [ + "CVE-2024-53048" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nice: fix crash on probe for DPLL enabled E810 LOM\n\nThe E810 Lan On Motherboard (LOM) design is vendor specific. Intel\nprovides the reference design, but it is up to vendor on the final\nproduct design. For some cases, like Linux DPLL support, the static\nvalues defined in the driver does not reflect the actual LOM design.\nCurrent implementation of dpll pins is causing the crash on probe\nof the ice driver for such DPLL enabled E810 LOM designs:\n\nWARNING: (...) at drivers/dpll/dpll_core.c:495 dpll_pin_get+0x2c4/0x330\n...\nCall Trace:\n \n ? __warn+0x83/0x130\n ? dpll_pin_get+0x2c4/0x330\n ? report_bug+0x1b7/0x1d0\n ? handle_bug+0x42/0x70\n ? exc_invalid_op+0x18/0x70\n ? asm_exc_invalid_op+0x1a/0x20\n ? dpll_pin_get+0x117/0x330\n ? dpll_pin_get+0x2c4/0x330\n ? dpll_pin_get+0x117/0x330\n ice_dpll_get_pins.isra.0+0x52/0xe0 [ice]\n...\n\nThe number of dpll pins enabled by LOM vendor is greater than expected\nand defined in the driver for Intel designed NICs, which causes the crash.\n\nPrevent the crash and allow generic pin initialization within Linux DPLL\nsubsystem for DPLL enabled E810 LOM designs.\n\nNewly designed solution for described issue will be based on \"per HW\ndesign\" pin initialization. It requires pin information dynamically\nacquired from the firmware and is already in progress, planned for\nnext-tree only.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53048" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6e58c33106220c6c0c8fbee9ab63eae76ad8f260" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/82b107a27bab29146e159b6b9f21146c97c45a53" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-r88f-6cwp-mh6c/GHSA-r88f-6cwp-mh6c.json b/advisories/unreviewed/2024/11/GHSA-r88f-6cwp-mh6c/GHSA-r88f-6cwp-mh6c.json new file mode 100644 index 00000000000..65b3b0f080c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-r88f-6cwp-mh6c/GHSA-r88f-6cwp-mh6c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r88f-6cwp-mh6c", + "modified": "2024-11-19T18:31:05Z", + "published": "2024-11-19T18:31:05Z", + "aliases": [ + "CVE-2024-51902" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Oliver Schaal TinyCode allows Stored XSS.This issue affects TinyCode: from n/a through 1.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51902" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/tinycode/wordpress-tinycode-plugin-1-2-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-r9m7-7gg7-9ppr/GHSA-r9m7-7gg7-9ppr.json b/advisories/unreviewed/2024/11/GHSA-r9m7-7gg7-9ppr/GHSA-r9m7-7gg7-9ppr.json new file mode 100644 index 00000000000..29f3d990bff --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-r9m7-7gg7-9ppr/GHSA-r9m7-7gg7-9ppr.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r9m7-7gg7-9ppr", + "modified": "2024-11-19T18:31:07Z", + "published": "2024-11-19T18:31:06Z", + "aliases": [ + "CVE-2024-53060" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: prevent NULL pointer dereference if ATIF is not supported\n\nacpi_evaluate_object() may return AE_NOT_FOUND (failure), which\nwould result in dereferencing buffer.pointer (obj) while being NULL.\n\nAlthough this case may be unrealistic for the current code, it is\nstill better to protect against possible bugs.\n\nBail out also when status is AE_NOT_FOUND.\n\nThis fixes 1 FORWARD_NULL issue reported by Coverity\nReport: CID 1600951: Null pointer dereferences (FORWARD_NULL)\n\n(cherry picked from commit 91c9e221fe2553edf2db71627d8453f083de87a1)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53060" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1a9f55ed5b512f510ccd21ad527d532e60550e80" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/27fc29b5376998c126c85cf9b15d9dfc2afc9cbe" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2ac7f253deada4d449559b65a1c1cd0a6f6f19b7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8d7a28eca7553d35d4ce192fa1f390f2357df41b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a613a392417532ca5aaf3deac6e3277aa7aaef2b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a6dd15981c03f2cdc9a351a278f09b5479d53d2e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b9d9881237afeb52eddd70077b7174bf17e2fa30" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ce8a00a00e36f61f5a1e47734332420b68784c43" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rf58-r74g-wxch/GHSA-rf58-r74g-wxch.json b/advisories/unreviewed/2024/11/GHSA-rf58-r74g-wxch/GHSA-rf58-r74g-wxch.json new file mode 100644 index 00000000000..6766d20fc07 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-rf58-r74g-wxch/GHSA-rf58-r74g-wxch.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rf58-r74g-wxch", + "modified": "2024-11-19T18:31:05Z", + "published": "2024-11-19T18:31:05Z", + "aliases": [ + "CVE-2024-51907" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codemenschen WP Virtual Room Configurator allows Stored XSS.This issue affects WP Virtual Room Configurator: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51907" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/configure-conference-room/wordpress-wp-virtual-room-configurator-plugin-1-0-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rf66-cpg6-q99p/GHSA-rf66-cpg6-q99p.json b/advisories/unreviewed/2024/11/GHSA-rf66-cpg6-q99p/GHSA-rf66-cpg6-q99p.json new file mode 100644 index 00000000000..60dc256f0f2 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-rf66-cpg6-q99p/GHSA-rf66-cpg6-q99p.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rf66-cpg6-q99p", + "modified": "2024-11-19T18:31:06Z", + "published": "2024-11-19T18:31:06Z", + "aliases": [ + "CVE-2024-48072" + ], + "details": "Weaver Ecology v9.* was discovered to contain a SQL injection vulnerability via the component /mobilemode/Action.jsp?invoker=com.weaver.formmodel.mobile.mec.servlet.MECAction&action=getFieldTriggerValue&searchField=*&fromTable=HrmResourceManager&whereClause=1%3d1&triggerCondition=1&expression=%3d&fieldValue=1.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48072" + }, + { + "type": "WEB", + "url": "https://gist.github.com/CoinIsMoney/8ca1f2bf2e0399724c698327f2da8579" + }, + { + "type": "WEB", + "url": "https://github.com/stuven1989/TemporaryGuild/blob/main/files/exp-eng4.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rfxg-68vv-hjqg/GHSA-rfxg-68vv-hjqg.json b/advisories/unreviewed/2024/11/GHSA-rfxg-68vv-hjqg/GHSA-rfxg-68vv-hjqg.json new file mode 100644 index 00000000000..b1f670f8367 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-rfxg-68vv-hjqg/GHSA-rfxg-68vv-hjqg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rfxg-68vv-hjqg", + "modified": "2024-11-19T18:31:01Z", + "published": "2024-11-19T18:31:01Z", + "aliases": [ + "CVE-2024-50534" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Syed Umair Hussain Shah World Prayer Time allows Stored XSS.This issue affects World Prayer Time: from n/a through 2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50534" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/world-prayer-time/wordpress-world-prayer-time-plugin-2-0-csrf-to-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rg5j-wjh5-jjvq/GHSA-rg5j-wjh5-jjvq.json b/advisories/unreviewed/2024/11/GHSA-rg5j-wjh5-jjvq/GHSA-rg5j-wjh5-jjvq.json new file mode 100644 index 00000000000..f6cb822ffcb --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-rg5j-wjh5-jjvq/GHSA-rg5j-wjh5-jjvq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rg5j-wjh5-jjvq", + "modified": "2024-11-19T18:31:02Z", + "published": "2024-11-19T18:31:02Z", + "aliases": [ + "CVE-2024-51801" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jake Brown Brand my Footer allows DOM-Based XSS.This issue affects Brand my Footer: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51801" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/brand-my-footer/wordpress-brand-my-footer-plugin-1-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rgj2-69w4-v6x7/GHSA-rgj2-69w4-v6x7.json b/advisories/unreviewed/2024/11/GHSA-rgj2-69w4-v6x7/GHSA-rgj2-69w4-v6x7.json index 30197a71358..2fbf5144204 100644 --- a/advisories/unreviewed/2024/11/GHSA-rgj2-69w4-v6x7/GHSA-rgj2-69w4-v6x7.json +++ b/advisories/unreviewed/2024/11/GHSA-rgj2-69w4-v6x7/GHSA-rgj2-69w4-v6x7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rgj2-69w4-v6x7", - "modified": "2024-11-15T09:32:29Z", + "modified": "2024-11-19T18:30:55Z", "published": "2024-11-15T09:32:29Z", "aliases": [ "CVE-2024-8961" diff --git a/advisories/unreviewed/2024/11/GHSA-rmcg-5mh4-47x7/GHSA-rmcg-5mh4-47x7.json b/advisories/unreviewed/2024/11/GHSA-rmcg-5mh4-47x7/GHSA-rmcg-5mh4-47x7.json index caa96bc0b36..61e342e4807 100644 --- a/advisories/unreviewed/2024/11/GHSA-rmcg-5mh4-47x7/GHSA-rmcg-5mh4-47x7.json +++ b/advisories/unreviewed/2024/11/GHSA-rmcg-5mh4-47x7/GHSA-rmcg-5mh4-47x7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rmcg-5mh4-47x7", - "modified": "2024-11-12T21:30:55Z", + "modified": "2024-11-19T18:30:54Z", "published": "2024-11-12T21:30:55Z", "aliases": [ "CVE-2024-51094" ], "details": "An issue in Snipe-IT v.7.0.13 build 15514 allows a remote attacker to escalate privileges via the file /account/profile of the component \"Name\" field value under \"Edit Your Profile\".", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1236" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-12T21:15:14Z" diff --git a/advisories/unreviewed/2024/11/GHSA-rmvp-hjvh-xmv3/GHSA-rmvp-hjvh-xmv3.json b/advisories/unreviewed/2024/11/GHSA-rmvp-hjvh-xmv3/GHSA-rmvp-hjvh-xmv3.json new file mode 100644 index 00000000000..d75150edf76 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-rmvp-hjvh-xmv3/GHSA-rmvp-hjvh-xmv3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rmvp-hjvh-xmv3", + "modified": "2024-11-19T18:31:04Z", + "published": "2024-11-19T18:31:04Z", + "aliases": [ + "CVE-2024-51899" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SEO Themes Simple Pricing Table allows Stored XSS.This issue affects Simple Pricing Table: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51899" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/simple-pricing-table/wordpress-simple-pricing-table-plugin-1-0-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rr7g-vx4c-mvhf/GHSA-rr7g-vx4c-mvhf.json b/advisories/unreviewed/2024/11/GHSA-rr7g-vx4c-mvhf/GHSA-rr7g-vx4c-mvhf.json new file mode 100644 index 00000000000..9593f580cc5 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-rr7g-vx4c-mvhf/GHSA-rr7g-vx4c-mvhf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rr7g-vx4c-mvhf", + "modified": "2024-11-19T18:31:02Z", + "published": "2024-11-19T18:31:02Z", + "aliases": [ + "CVE-2024-51798" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Surbma Surbma | Font Awesome allows DOM-Based XSS.This issue affects Surbma | Font Awesome: from n/a through 3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51798" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/surbma-font-awesome/wordpress-surbma-font-awesome-plugin-3-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rx3v-xhcx-x379/GHSA-rx3v-xhcx-x379.json b/advisories/unreviewed/2024/11/GHSA-rx3v-xhcx-x379/GHSA-rx3v-xhcx-x379.json new file mode 100644 index 00000000000..5b3b4074d88 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-rx3v-xhcx-x379/GHSA-rx3v-xhcx-x379.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rx3v-xhcx-x379", + "modified": "2024-11-19T18:31:04Z", + "published": "2024-11-19T18:31:04Z", + "aliases": [ + "CVE-2024-51857" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Olympus Themes Olympus Shortcodes allows DOM-Based XSS.This issue affects Olympus Shortcodes: from n/a through 1.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51857" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/olympus-shortcodes/wordpress-olympus-shortcodes-plugin-1-0-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rx57-hfr8-vvw9/GHSA-rx57-hfr8-vvw9.json b/advisories/unreviewed/2024/11/GHSA-rx57-hfr8-vvw9/GHSA-rx57-hfr8-vvw9.json new file mode 100644 index 00000000000..17b81ebf5d3 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-rx57-hfr8-vvw9/GHSA-rx57-hfr8-vvw9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rx57-hfr8-vvw9", + "modified": "2024-11-19T18:31:02Z", + "published": "2024-11-19T18:31:02Z", + "aliases": [ + "CVE-2024-51822" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Keon Themes Creative Blocks allows Stored XSS.This issue affects Creative Blocks: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51822" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/creative-blocks/wordpress-creative-blocks-plugin-1-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-v24h-h5qr-mqm8/GHSA-v24h-h5qr-mqm8.json b/advisories/unreviewed/2024/11/GHSA-v24h-h5qr-mqm8/GHSA-v24h-h5qr-mqm8.json index c0491b9bea0..753d172f1ff 100644 --- a/advisories/unreviewed/2024/11/GHSA-v24h-h5qr-mqm8/GHSA-v24h-h5qr-mqm8.json +++ b/advisories/unreviewed/2024/11/GHSA-v24h-h5qr-mqm8/GHSA-v24h-h5qr-mqm8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v24h-h5qr-mqm8", - "modified": "2024-11-12T00:30:36Z", + "modified": "2024-11-19T18:30:54Z", "published": "2024-11-12T00:30:36Z", "aliases": [ "CVE-2024-25253" ], "details": "Driver Booster v10.6 was discovered to contain a buffer overflow via the Host parameter under the Customize proxy module.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-11T23:15:05Z" diff --git a/advisories/unreviewed/2024/11/GHSA-v57f-wfrq-gh7p/GHSA-v57f-wfrq-gh7p.json b/advisories/unreviewed/2024/11/GHSA-v57f-wfrq-gh7p/GHSA-v57f-wfrq-gh7p.json new file mode 100644 index 00000000000..26ca60c578a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-v57f-wfrq-gh7p/GHSA-v57f-wfrq-gh7p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v57f-wfrq-gh7p", + "modified": "2024-11-19T18:31:02Z", + "published": "2024-11-19T18:31:02Z", + "aliases": [ + "CVE-2024-51805" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yonatan Reinberg yPHPlista allows Stored XSS.This issue affects yPHPlista: from n/a through 1.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51805" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/yphplista/wordpress-yphplista-plugin-1-1-1-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-v5fr-mh59-qcqr/GHSA-v5fr-mh59-qcqr.json b/advisories/unreviewed/2024/11/GHSA-v5fr-mh59-qcqr/GHSA-v5fr-mh59-qcqr.json new file mode 100644 index 00000000000..18eb38792a8 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-v5fr-mh59-qcqr/GHSA-v5fr-mh59-qcqr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v5fr-mh59-qcqr", + "modified": "2024-11-19T18:31:06Z", + "published": "2024-11-19T18:31:06Z", + "aliases": [ + "CVE-2022-47424" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Repute InfoSystems ARMember, Repute InfoSystems ARMember Premium allows Cross-Site Request Forgery.This issue affects ARMember: from n/a through 4.0.5; ARMember Premium: from n/a before 6.7.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47424" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/armember-membership/wordpress-armember-plugin-4-0-5-cross-site-request-forgery-csrf?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-v6rr-j96c-5w92/GHSA-v6rr-j96c-5w92.json b/advisories/unreviewed/2024/11/GHSA-v6rr-j96c-5w92/GHSA-v6rr-j96c-5w92.json new file mode 100644 index 00000000000..670a67c3daa --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-v6rr-j96c-5w92/GHSA-v6rr-j96c-5w92.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v6rr-j96c-5w92", + "modified": "2024-11-19T18:31:00Z", + "published": "2024-11-19T18:31:00Z", + "aliases": [ + "CVE-2024-49697" + ], + "details": "Missing Authorization vulnerability in WP Sunshine Sunshine Photo Cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through 3.2.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49697" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/sunshine-photo-cart/wordpress-sunshine-photo-cart-plugin-3-2-9-broken-access-control-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-v74c-f2q4-m3f5/GHSA-v74c-f2q4-m3f5.json b/advisories/unreviewed/2024/11/GHSA-v74c-f2q4-m3f5/GHSA-v74c-f2q4-m3f5.json new file mode 100644 index 00000000000..850c8e78146 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-v74c-f2q4-m3f5/GHSA-v74c-f2q4-m3f5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v74c-f2q4-m3f5", + "modified": "2024-11-19T18:31:03Z", + "published": "2024-11-19T18:31:03Z", + "aliases": [ + "CVE-2024-51835" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ajinkya N OpenCart Product Display allows Stored XSS.This issue affects OpenCart Product Display: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51835" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/opencart-product-display/wordpress-opencart-product-display-plugin-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-v87w-5qjf-xwc5/GHSA-v87w-5qjf-xwc5.json b/advisories/unreviewed/2024/11/GHSA-v87w-5qjf-xwc5/GHSA-v87w-5qjf-xwc5.json index 2ff8963c85f..31744b403f9 100644 --- a/advisories/unreviewed/2024/11/GHSA-v87w-5qjf-xwc5/GHSA-v87w-5qjf-xwc5.json +++ b/advisories/unreviewed/2024/11/GHSA-v87w-5qjf-xwc5/GHSA-v87w-5qjf-xwc5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v87w-5qjf-xwc5", - "modified": "2024-11-19T06:30:40Z", + "modified": "2024-11-19T18:31:00Z", "published": "2024-11-19T06:30:40Z", "aliases": [ "CVE-2024-10103" ], "details": "In the process of testing the MailPoet WordPress plugin before 5.3.2, a vulnerability was found that allows you to implement Stored XSS on behalf of the editor by embedding malicious script, which entails account takeover backdoor", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T06:15:17Z" diff --git a/advisories/unreviewed/2024/11/GHSA-v8mh-p5f4-xfcq/GHSA-v8mh-p5f4-xfcq.json b/advisories/unreviewed/2024/11/GHSA-v8mh-p5f4-xfcq/GHSA-v8mh-p5f4-xfcq.json new file mode 100644 index 00000000000..35f20b36ba8 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-v8mh-p5f4-xfcq/GHSA-v8mh-p5f4-xfcq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v8mh-p5f4-xfcq", + "modified": "2024-11-19T18:31:05Z", + "published": "2024-11-19T18:31:05Z", + "aliases": [ + "CVE-2024-51918" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Freshlight Lab Pay With Stripe allows DOM-Based XSS.This issue affects Pay With Stripe: from n/a through 1.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51918" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/payments-stripe-gateway/wordpress-pay-with-stripe-plugin-1-2-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-v8x5-jx2w-cph3/GHSA-v8x5-jx2w-cph3.json b/advisories/unreviewed/2024/11/GHSA-v8x5-jx2w-cph3/GHSA-v8x5-jx2w-cph3.json new file mode 100644 index 00000000000..5d0dfba8326 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-v8x5-jx2w-cph3/GHSA-v8x5-jx2w-cph3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v8x5-jx2w-cph3", + "modified": "2024-11-19T18:31:05Z", + "published": "2024-11-19T18:31:05Z", + "aliases": [ + "CVE-2024-51936" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Henry ESB Testimonials allows Stored XSS.This issue affects ESB Testimonials: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51936" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/esb-testimonials/wordpress-esb-testimonials-plugin-1-0-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-vfhj-c5g9-3c9h/GHSA-vfhj-c5g9-3c9h.json b/advisories/unreviewed/2024/11/GHSA-vfhj-c5g9-3c9h/GHSA-vfhj-c5g9-3c9h.json index 5d67bb0a4cc..db59c278421 100644 --- a/advisories/unreviewed/2024/11/GHSA-vfhj-c5g9-3c9h/GHSA-vfhj-c5g9-3c9h.json +++ b/advisories/unreviewed/2024/11/GHSA-vfhj-c5g9-3c9h/GHSA-vfhj-c5g9-3c9h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vfhj-c5g9-3c9h", - "modified": "2024-11-08T06:30:49Z", + "modified": "2024-11-19T18:30:54Z", "published": "2024-11-08T06:30:49Z", "aliases": [ "CVE-2024-50201" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/radeon: Fix encoder->possible_clones\n\nInclude the encoder itself in its possible_clones bitmask.\nIn the past nothing validated that drivers were populating\npossible_clones correctly, but that changed in commit\n74d2aacbe840 (\"drm: Validate encoder->possible_clones\").\nLooks like radeon never got the memo and is still not\nfollowing the rules 100% correctly.\n\nThis results in some warnings during driver initialization:\nBogus possible_clones: [ENCODER:46:TV-46] possible_clones=0x4 (full encoder mask=0x7)\nWARNING: CPU: 0 PID: 170 at drivers/gpu/drm/drm_mode_config.c:615 drm_mode_config_validate+0x113/0x39c\n...\n\n(cherry picked from commit 3b6e7d40649c0d75572039aff9d0911864c689db)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-08T06:15:16Z" diff --git a/advisories/unreviewed/2024/11/GHSA-vfpr-487g-rfrf/GHSA-vfpr-487g-rfrf.json b/advisories/unreviewed/2024/11/GHSA-vfpr-487g-rfrf/GHSA-vfpr-487g-rfrf.json new file mode 100644 index 00000000000..130e2469e30 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-vfpr-487g-rfrf/GHSA-vfpr-487g-rfrf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vfpr-487g-rfrf", + "modified": "2024-11-19T18:31:03Z", + "published": "2024-11-19T18:31:03Z", + "aliases": [ + "CVE-2024-51847" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in giovanebribeiro WP PagSeguro Payments allows Stored XSS.This issue affects WP PagSeguro Payments: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51847" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-pagseguro-payments/wordpress-wp-pagseguro-payments-plugin-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-vggf-6chm-6r3x/GHSA-vggf-6chm-6r3x.json b/advisories/unreviewed/2024/11/GHSA-vggf-6chm-6r3x/GHSA-vggf-6chm-6r3x.json new file mode 100644 index 00000000000..07648733fa5 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-vggf-6chm-6r3x/GHSA-vggf-6chm-6r3x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vggf-6chm-6r3x", + "modified": "2024-11-19T18:31:05Z", + "published": "2024-11-19T18:31:05Z", + "aliases": [ + "CVE-2024-51922" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maruf Arafat VP Sitemap allows Stored XSS.This issue affects VP Sitemap: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51922" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/vp-sitemap/wordpress-vp-sitemap-plugin-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-vgvr-f26x-4vmv/GHSA-vgvr-f26x-4vmv.json b/advisories/unreviewed/2024/11/GHSA-vgvr-f26x-4vmv/GHSA-vgvr-f26x-4vmv.json new file mode 100644 index 00000000000..0aa7133ace5 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-vgvr-f26x-4vmv/GHSA-vgvr-f26x-4vmv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vgvr-f26x-4vmv", + "modified": "2024-11-19T18:31:05Z", + "published": "2024-11-19T18:31:05Z", + "aliases": [ + "CVE-2024-52388" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Mike “Mikeage” Miller Hebrew Date allows Stored XSS.This issue affects Hebrew Date: from n/a through 2.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52388" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/hebrewdates/wordpress-hebrew-date-plugin-2-1-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-vj8f-r84j-pcvr/GHSA-vj8f-r84j-pcvr.json b/advisories/unreviewed/2024/11/GHSA-vj8f-r84j-pcvr/GHSA-vj8f-r84j-pcvr.json index 08ee53795d6..5a9d406d215 100644 --- a/advisories/unreviewed/2024/11/GHSA-vj8f-r84j-pcvr/GHSA-vj8f-r84j-pcvr.json +++ b/advisories/unreviewed/2024/11/GHSA-vj8f-r84j-pcvr/GHSA-vj8f-r84j-pcvr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vj8f-r84j-pcvr", - "modified": "2024-11-18T21:30:47Z", + "modified": "2024-11-19T18:30:59Z", "published": "2024-11-18T21:30:47Z", "aliases": [ "CVE-2024-50804" ], "details": "Insecure Permissions vulnerability in Micro-star International MSI Center Pro 2.1.37.0 allows a local attacker to execute arbitrary code via the Device_DeviceID.dat.bak file within the C:\\ProgramData\\MSI\\One Dragon Center\\Data folder", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-18T21:15:06Z" diff --git a/advisories/unreviewed/2024/11/GHSA-vmhp-qx23-hrx5/GHSA-vmhp-qx23-hrx5.json b/advisories/unreviewed/2024/11/GHSA-vmhp-qx23-hrx5/GHSA-vmhp-qx23-hrx5.json new file mode 100644 index 00000000000..685b15693b4 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-vmhp-qx23-hrx5/GHSA-vmhp-qx23-hrx5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vmhp-qx23-hrx5", + "modified": "2024-11-19T18:31:05Z", + "published": "2024-11-19T18:31:05Z", + "aliases": [ + "CVE-2024-51934" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Uri Lazcano (Urielink) Ekiline Block Collection allows DOM-Based XSS.This issue affects Ekiline Block Collection: from n/a through 1.0.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51934" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ekiline-block-collection/wordpress-ekiline-block-collection-plugin-1-0-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-vqv9-vmmf-2xqf/GHSA-vqv9-vmmf-2xqf.json b/advisories/unreviewed/2024/11/GHSA-vqv9-vmmf-2xqf/GHSA-vqv9-vmmf-2xqf.json new file mode 100644 index 00000000000..4249ebf5aa2 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-vqv9-vmmf-2xqf/GHSA-vqv9-vmmf-2xqf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vqv9-vmmf-2xqf", + "modified": "2024-11-19T18:31:02Z", + "published": "2024-11-19T18:31:02Z", + "aliases": [ + "CVE-2024-51808" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pat O’Brien codeSnips allows Stored XSS.This issue affects codeSnips: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51808" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/codesnips/wordpress-codesnips-plugin-1-2-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-vqx8-5r3c-qh77/GHSA-vqx8-5r3c-qh77.json b/advisories/unreviewed/2024/11/GHSA-vqx8-5r3c-qh77/GHSA-vqx8-5r3c-qh77.json new file mode 100644 index 00000000000..ecd109159bc --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-vqx8-5r3c-qh77/GHSA-vqx8-5r3c-qh77.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vqx8-5r3c-qh77", + "modified": "2024-11-19T18:31:05Z", + "published": "2024-11-19T18:31:05Z", + "aliases": [ + "CVE-2024-51929" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Phil Spectrum Icon Widget allows DOM-Based XSS.This issue affects Icon Widget: from n/a through 1.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51929" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/icon-widget-with-links/wordpress-icon-widget-plugin-1-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-vr6r-x4g3-mjh6/GHSA-vr6r-x4g3-mjh6.json b/advisories/unreviewed/2024/11/GHSA-vr6r-x4g3-mjh6/GHSA-vr6r-x4g3-mjh6.json new file mode 100644 index 00000000000..943e69023a9 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-vr6r-x4g3-mjh6/GHSA-vr6r-x4g3-mjh6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vr6r-x4g3-mjh6", + "modified": "2024-11-19T18:31:02Z", + "published": "2024-11-19T18:31:02Z", + "aliases": [ + "CVE-2024-51806" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shingo Suzumura at Fitness Website Formula Awesome Fitness Testimonials allows Stored XSS.This issue affects Awesome Fitness Testimonials: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51806" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/awesome-fitness-testimonials/wordpress-awesome-fitness-testimonials-plugin-1-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-vrqp-jr32-665v/GHSA-vrqp-jr32-665v.json b/advisories/unreviewed/2024/11/GHSA-vrqp-jr32-665v/GHSA-vrqp-jr32-665v.json new file mode 100644 index 00000000000..c5ed35f0241 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-vrqp-jr32-665v/GHSA-vrqp-jr32-665v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vrqp-jr32-665v", + "modified": "2024-11-19T18:31:05Z", + "published": "2024-11-19T18:31:05Z", + "aliases": [ + "CVE-2024-51938" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NicheAddons Charity Addon for Elementor allows DOM-Based XSS.This issue affects Charity Addon for Elementor: from n/a through 1.3.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51938" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/charity-addon-for-elementor/wordpress-charity-addon-for-elementor-plugin-1-3-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-vwqj-2j54-46q6/GHSA-vwqj-2j54-46q6.json b/advisories/unreviewed/2024/11/GHSA-vwqj-2j54-46q6/GHSA-vwqj-2j54-46q6.json index f4aca32837f..c40d7655f79 100644 --- a/advisories/unreviewed/2024/11/GHSA-vwqj-2j54-46q6/GHSA-vwqj-2j54-46q6.json +++ b/advisories/unreviewed/2024/11/GHSA-vwqj-2j54-46q6/GHSA-vwqj-2j54-46q6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vwqj-2j54-46q6", - "modified": "2024-11-18T21:30:46Z", + "modified": "2024-11-19T18:30:58Z", "published": "2024-11-18T21:30:46Z", "aliases": [ "CVE-2024-48293" ], "details": "Incorrect access control in QuickHeal Antivirus Pro 24.1.0.182 and earlier allows authenticated attackers with low-level privileges to arbitrarily modify antivirus settings.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-18T19:15:05Z" diff --git a/advisories/unreviewed/2024/11/GHSA-vwxq-h662-6mgh/GHSA-vwxq-h662-6mgh.json b/advisories/unreviewed/2024/11/GHSA-vwxq-h662-6mgh/GHSA-vwxq-h662-6mgh.json new file mode 100644 index 00000000000..5ddb9cb0911 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-vwxq-h662-6mgh/GHSA-vwxq-h662-6mgh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vwxq-h662-6mgh", + "modified": "2024-11-19T18:31:05Z", + "published": "2024-11-19T18:31:05Z", + "aliases": [ + "CVE-2024-52401" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in 荒野无灯 Hacklog DownloadManager allows Upload a Web Shell to a Web Server.This issue affects Hacklog DownloadManager: from n/a through 2.1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52401" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/hacklog-downloadmanager/wordpress-hacklog-downloadmanager-plugin-2-1-4-csrf-to-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-w2qx-q8vr-wvvh/GHSA-w2qx-q8vr-wvvh.json b/advisories/unreviewed/2024/11/GHSA-w2qx-q8vr-wvvh/GHSA-w2qx-q8vr-wvvh.json new file mode 100644 index 00000000000..b967c43e7ce --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-w2qx-q8vr-wvvh/GHSA-w2qx-q8vr-wvvh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w2qx-q8vr-wvvh", + "modified": "2024-11-19T18:31:00Z", + "published": "2024-11-19T18:31:00Z", + "aliases": [ + "CVE-2024-50417" + ], + "details": "Missing Authorization vulnerability in BoldThemes Bold Page Builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bold Page Builder: from n/a through 5.1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50417" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/bold-page-builder/wordpress-bold-page-builder-plugin-5-1-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-w3xc-4v65-w7fm/GHSA-w3xc-4v65-w7fm.json b/advisories/unreviewed/2024/11/GHSA-w3xc-4v65-w7fm/GHSA-w3xc-4v65-w7fm.json new file mode 100644 index 00000000000..f441c7760df --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-w3xc-4v65-w7fm/GHSA-w3xc-4v65-w7fm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w3xc-4v65-w7fm", + "modified": "2024-11-19T18:31:00Z", + "published": "2024-11-19T18:31:00Z", + "aliases": [ + "CVE-2024-50513" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Post Grid Team by WPXPO PostX allows Stored XSS.This issue affects PostX: from n/a through 4.1.15.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50513" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ultimate-post/wordpress-post-grid-gutenberg-blocks-and-wordpress-blog-plugin-postx-plugin-4-1-15-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-w3xr-946r-w34h/GHSA-w3xr-946r-w34h.json b/advisories/unreviewed/2024/11/GHSA-w3xr-946r-w34h/GHSA-w3xr-946r-w34h.json index 24b3041396c..76019c253e7 100644 --- a/advisories/unreviewed/2024/11/GHSA-w3xr-946r-w34h/GHSA-w3xr-946r-w34h.json +++ b/advisories/unreviewed/2024/11/GHSA-w3xr-946r-w34h/GHSA-w3xr-946r-w34h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w3xr-946r-w34h", - "modified": "2024-11-19T00:32:44Z", + "modified": "2024-11-19T18:31:00Z", "published": "2024-11-19T00:32:44Z", "aliases": [ "CVE-2024-51051" ], "details": "AVSCMS v8.2.0 was discovered to contain weak default credentials for the Administrator account.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-18T22:15:06Z" diff --git a/advisories/unreviewed/2024/11/GHSA-w4ph-h9qj-wr34/GHSA-w4ph-h9qj-wr34.json b/advisories/unreviewed/2024/11/GHSA-w4ph-h9qj-wr34/GHSA-w4ph-h9qj-wr34.json new file mode 100644 index 00000000000..aec6209d682 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-w4ph-h9qj-wr34/GHSA-w4ph-h9qj-wr34.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w4ph-h9qj-wr34", + "modified": "2024-11-19T18:31:01Z", + "published": "2024-11-19T18:31:01Z", + "aliases": [ + "CVE-2024-50554" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sided Sided allows DOM-Based XSS.This issue affects Sided: from n/a through 1.4.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50554" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/sided/wordpress-sided-plugin-1-4-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-w6rx-9ffq-gq99/GHSA-w6rx-9ffq-gq99.json b/advisories/unreviewed/2024/11/GHSA-w6rx-9ffq-gq99/GHSA-w6rx-9ffq-gq99.json new file mode 100644 index 00000000000..350e98f9246 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-w6rx-9ffq-gq99/GHSA-w6rx-9ffq-gq99.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w6rx-9ffq-gq99", + "modified": "2024-11-19T18:31:02Z", + "published": "2024-11-19T18:31:02Z", + "aliases": [ + "CVE-2024-51809" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in George Rood Keymaster Chord Notation Free allows Stored XSS.This issue affects Keymaster Chord Notation Free: from n/a through 1.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51809" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/keymaster-chord-notation-free/wordpress-keymaster-chord-notation-free-plugin-1-0-2-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-w73m-7g8j-rpvx/GHSA-w73m-7g8j-rpvx.json b/advisories/unreviewed/2024/11/GHSA-w73m-7g8j-rpvx/GHSA-w73m-7g8j-rpvx.json index 664e2f00fe2..efe3c46b6f1 100644 --- a/advisories/unreviewed/2024/11/GHSA-w73m-7g8j-rpvx/GHSA-w73m-7g8j-rpvx.json +++ b/advisories/unreviewed/2024/11/GHSA-w73m-7g8j-rpvx/GHSA-w73m-7g8j-rpvx.json @@ -48,7 +48,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-434" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-w83r-gj25-6vrc/GHSA-w83r-gj25-6vrc.json b/advisories/unreviewed/2024/11/GHSA-w83r-gj25-6vrc/GHSA-w83r-gj25-6vrc.json index 193103a3fe3..e47014a433d 100644 --- a/advisories/unreviewed/2024/11/GHSA-w83r-gj25-6vrc/GHSA-w83r-gj25-6vrc.json +++ b/advisories/unreviewed/2024/11/GHSA-w83r-gj25-6vrc/GHSA-w83r-gj25-6vrc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w83r-gj25-6vrc", - "modified": "2024-11-08T06:30:49Z", + "modified": "2024-11-19T18:30:54Z", "published": "2024-11-08T06:30:49Z", "aliases": [ "CVE-2024-50203" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, arm64: Fix address emission with tag-based KASAN enabled\n\nWhen BPF_TRAMP_F_CALL_ORIG is enabled, the address of a bpf_tramp_image\nstruct on the stack is passed during the size calculation pass and\nan address on the heap is passed during code generation. This may\ncause a heap buffer overflow if the heap address is tagged because\nemit_a64_mov_i64() will emit longer code than it did during the size\ncalculation pass. The same problem could occur without tag-based\nKASAN if one of the 16-bit words of the stack address happened to\nbe all-ones during the size calculation pass. Fix the problem by\nassuming the worst case (4 instructions) when calculating the size\nof the bpf_tramp_image address emission.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-08T06:15:16Z" diff --git a/advisories/unreviewed/2024/11/GHSA-w95f-w4vg-jw2g/GHSA-w95f-w4vg-jw2g.json b/advisories/unreviewed/2024/11/GHSA-w95f-w4vg-jw2g/GHSA-w95f-w4vg-jw2g.json new file mode 100644 index 00000000000..ef3c62cc4d4 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-w95f-w4vg-jw2g/GHSA-w95f-w4vg-jw2g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w95f-w4vg-jw2g", + "modified": "2024-11-19T18:31:02Z", + "published": "2024-11-19T18:31:02Z", + "aliases": [ + "CVE-2024-51825" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cristopher Ocaña Alert Me! allows DOM-Based XSS.This issue affects Alert Me!: from n/a through 0.4.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51825" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/alert-me/wordpress-alert-me-plugin-0-4-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-wch2-95xq-3vrc/GHSA-wch2-95xq-3vrc.json b/advisories/unreviewed/2024/11/GHSA-wch2-95xq-3vrc/GHSA-wch2-95xq-3vrc.json new file mode 100644 index 00000000000..260ae92dbec --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-wch2-95xq-3vrc/GHSA-wch2-95xq-3vrc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wch2-95xq-3vrc", + "modified": "2024-11-19T18:31:00Z", + "published": "2024-11-19T18:31:00Z", + "aliases": [ + "CVE-2024-50520" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Peter J. Herrel Ancient World Linked Data allows DOM-Based XSS.This issue affects Ancient World Linked Data: from n/a through 0.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50520" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ancient-world-linked-data-for-wordpress/wordpress-ancient-world-linked-data-plugin-0-2-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-wcmp-8223-fqxm/GHSA-wcmp-8223-fqxm.json b/advisories/unreviewed/2024/11/GHSA-wcmp-8223-fqxm/GHSA-wcmp-8223-fqxm.json new file mode 100644 index 00000000000..b90d5dbd01e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-wcmp-8223-fqxm/GHSA-wcmp-8223-fqxm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wcmp-8223-fqxm", + "modified": "2024-11-19T18:31:04Z", + "published": "2024-11-19T18:31:04Z", + "aliases": [ + "CVE-2024-51879" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arash Heidari Text Advertisements allows Stored XSS.This issue affects Text Advertisements: from n/a through 2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51879" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/text-advertisements/wordpress-text-advertisements-plugin-2-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-wfh7-4g7r-cxxq/GHSA-wfh7-4g7r-cxxq.json b/advisories/unreviewed/2024/11/GHSA-wfh7-4g7r-cxxq/GHSA-wfh7-4g7r-cxxq.json index 65e03c786c3..222845c0dfd 100644 --- a/advisories/unreviewed/2024/11/GHSA-wfh7-4g7r-cxxq/GHSA-wfh7-4g7r-cxxq.json +++ b/advisories/unreviewed/2024/11/GHSA-wfh7-4g7r-cxxq/GHSA-wfh7-4g7r-cxxq.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wfh7-4g7r-cxxq", - "modified": "2024-11-14T21:32:03Z", + "modified": "2024-11-19T18:30:55Z", "published": "2024-11-14T21:32:03Z", "aliases": [ "CVE-2024-10397" ], "details": "A malicious server can crash the OpenAFS cache manager and other client\nutilities, and possibly execute arbitrary code.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/11/GHSA-wg74-2782-fg3q/GHSA-wg74-2782-fg3q.json b/advisories/unreviewed/2024/11/GHSA-wg74-2782-fg3q/GHSA-wg74-2782-fg3q.json new file mode 100644 index 00000000000..c9a3c7d5364 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-wg74-2782-fg3q/GHSA-wg74-2782-fg3q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wg74-2782-fg3q", + "modified": "2024-11-19T18:31:04Z", + "published": "2024-11-19T18:31:04Z", + "aliases": [ + "CVE-2024-51908" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gonzalo Geraldo Adventure Bucket List allows DOM-Based XSS.This issue affects Adventure Bucket List: from n/a through 1.0.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51908" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/adventure-bucket-list/wordpress-adventure-bucket-list-plugin-1-0-9-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-whhx-pr5h-v8mc/GHSA-whhx-pr5h-v8mc.json b/advisories/unreviewed/2024/11/GHSA-whhx-pr5h-v8mc/GHSA-whhx-pr5h-v8mc.json new file mode 100644 index 00000000000..4c42c4bd602 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-whhx-pr5h-v8mc/GHSA-whhx-pr5h-v8mc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-whhx-pr5h-v8mc", + "modified": "2024-11-19T18:31:01Z", + "published": "2024-11-19T18:31:01Z", + "aliases": [ + "CVE-2024-50533" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in David Garcia Domain Sharding allows Stored XSS.This issue affects Domain Sharding: from n/a through 1.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50533" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/domain-sharding/wordpress-domain-sharding-plugin-1-2-1-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-wj78-hqg6-26m2/GHSA-wj78-hqg6-26m2.json b/advisories/unreviewed/2024/11/GHSA-wj78-hqg6-26m2/GHSA-wj78-hqg6-26m2.json new file mode 100644 index 00000000000..5452e5bb3f9 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-wj78-hqg6-26m2/GHSA-wj78-hqg6-26m2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wj78-hqg6-26m2", + "modified": "2024-11-19T18:31:05Z", + "published": "2024-11-19T18:31:05Z", + "aliases": [ + "CVE-2024-51923" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Websand Websand Subscription Form allows Stored XSS.This issue affects Websand Subscription Form: from n/a through 1.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51923" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/websand-subscription-form/wordpress-websand-subscription-form-plugin-1-0-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-wj8m-wqv6-9w99/GHSA-wj8m-wqv6-9w99.json b/advisories/unreviewed/2024/11/GHSA-wj8m-wqv6-9w99/GHSA-wj8m-wqv6-9w99.json new file mode 100644 index 00000000000..529d70c41b5 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-wj8m-wqv6-9w99/GHSA-wj8m-wqv6-9w99.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wj8m-wqv6-9w99", + "modified": "2024-11-19T18:31:02Z", + "published": "2024-11-19T18:31:02Z", + "aliases": [ + "CVE-2024-51813" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Anantaddons, Anantsites Anant Addons for Elementor allows DOM-Based XSS.This issue affects Anant Addons for Elementor: from n/a through 1.0.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51813" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/anant-addons-for-elementor/wordpress-anant-addons-for-elementor-plugin-1-0-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-wm4w-qc6f-f7h3/GHSA-wm4w-qc6f-f7h3.json b/advisories/unreviewed/2024/11/GHSA-wm4w-qc6f-f7h3/GHSA-wm4w-qc6f-f7h3.json new file mode 100644 index 00000000000..d1d4b6be95d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-wm4w-qc6f-f7h3/GHSA-wm4w-qc6f-f7h3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wm4w-qc6f-f7h3", + "modified": "2024-11-19T18:31:05Z", + "published": "2024-11-19T18:31:05Z", + "aliases": [ + "CVE-2024-51916" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Creative Brahma Multifox Plus allows DOM-Based XSS.This issue affects Multifox Plus: from n/a through 1.1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51916" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/multifox-plus/wordpress-multifox-plus-plugin-1-1-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-wm6c-245h-h448/GHSA-wm6c-245h-h448.json b/advisories/unreviewed/2024/11/GHSA-wm6c-245h-h448/GHSA-wm6c-245h-h448.json index 45f87511315..b873c61e759 100644 --- a/advisories/unreviewed/2024/11/GHSA-wm6c-245h-h448/GHSA-wm6c-245h-h448.json +++ b/advisories/unreviewed/2024/11/GHSA-wm6c-245h-h448/GHSA-wm6c-245h-h448.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wm6c-245h-h448", - "modified": "2024-11-18T21:30:47Z", + "modified": "2024-11-19T18:30:59Z", "published": "2024-11-18T21:30:47Z", "aliases": [ "CVE-2024-51053" ], "details": "An arbitrary file upload vulnerability in the component /main/fileupload.php of AVSCMS v8.2.0 allows attackers to execute arbitrary code via uploading a crafted file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-18T21:15:06Z" diff --git a/advisories/unreviewed/2024/11/GHSA-wp26-g22c-7r5j/GHSA-wp26-g22c-7r5j.json b/advisories/unreviewed/2024/11/GHSA-wp26-g22c-7r5j/GHSA-wp26-g22c-7r5j.json new file mode 100644 index 00000000000..36cd74c587a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-wp26-g22c-7r5j/GHSA-wp26-g22c-7r5j.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wp26-g22c-7r5j", + "modified": "2024-11-19T18:31:07Z", + "published": "2024-11-19T18:31:07Z", + "aliases": [ + "CVE-2024-53058" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: stmmac: TSO: Fix unbalanced DMA map/unmap for non-paged SKB data\n\nIn case the non-paged data of a SKB carries protocol header and protocol\npayload to be transmitted on a certain platform that the DMA AXI address\nwidth is configured to 40-bit/48-bit, or the size of the non-paged data\nis bigger than TSO_MAX_BUFF_SIZE on a certain platform that the DMA AXI\naddress width is configured to 32-bit, then this SKB requires at least\ntwo DMA transmit descriptors to serve it.\n\nFor example, three descriptors are allocated to split one DMA buffer\nmapped from one piece of non-paged data:\n dma_desc[N + 0],\n dma_desc[N + 1],\n dma_desc[N + 2].\nThen three elements of tx_q->tx_skbuff_dma[] will be allocated to hold\nextra information to be reused in stmmac_tx_clean():\n tx_q->tx_skbuff_dma[N + 0],\n tx_q->tx_skbuff_dma[N + 1],\n tx_q->tx_skbuff_dma[N + 2].\nNow we focus on tx_q->tx_skbuff_dma[entry].buf, which is the DMA buffer\naddress returned by DMA mapping call. stmmac_tx_clean() will try to\nunmap the DMA buffer _ONLY_IF_ tx_q->tx_skbuff_dma[entry].buf\nis a valid buffer address.\n\nThe expected behavior that saves DMA buffer address of this non-paged\ndata to tx_q->tx_skbuff_dma[entry].buf is:\n tx_q->tx_skbuff_dma[N + 0].buf = NULL;\n tx_q->tx_skbuff_dma[N + 1].buf = NULL;\n tx_q->tx_skbuff_dma[N + 2].buf = dma_map_single();\nUnfortunately, the current code misbehaves like this:\n tx_q->tx_skbuff_dma[N + 0].buf = dma_map_single();\n tx_q->tx_skbuff_dma[N + 1].buf = NULL;\n tx_q->tx_skbuff_dma[N + 2].buf = NULL;\n\nOn the stmmac_tx_clean() side, when dma_desc[N + 0] is closed by the\nDMA engine, tx_q->tx_skbuff_dma[N + 0].buf is a valid buffer address\nobviously, then the DMA buffer will be unmapped immediately.\nThere may be a rare case that the DMA engine does not finish the\npending dma_desc[N + 1], dma_desc[N + 2] yet. Now things will go\nhorribly wrong, DMA is going to access a unmapped/unreferenced memory\nregion, corrupted data will be transmited or iommu fault will be\ntriggered :(\n\nIn contrast, the for-loop that maps SKB fragments behaves perfectly\nas expected, and that is how the driver should do for both non-paged\ndata and paged frags actually.\n\nThis patch corrects DMA map/unmap sequences by fixing the array index\nfor tx_q->tx_skbuff_dma[entry].buf when assigning DMA buffer address.\n\nTested and verified on DWXGMAC CORE 3.20a", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53058" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/07c9c26e37542486e34d767505e842f48f29c3f6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/58d23d835eb498336716cca55b5714191a309286" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/66600fac7a984dea4ae095411f644770b2561ede" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a3ff23f7c3f0e13f718900803e090fd3997d6bc9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ece593fc9c00741b682869d3f3dc584d37b7c9df" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-wqrp-f4rh-26fr/GHSA-wqrp-f4rh-26fr.json b/advisories/unreviewed/2024/11/GHSA-wqrp-f4rh-26fr/GHSA-wqrp-f4rh-26fr.json new file mode 100644 index 00000000000..3b1360c2c15 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-wqrp-f4rh-26fr/GHSA-wqrp-f4rh-26fr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wqrp-f4rh-26fr", + "modified": "2024-11-19T18:31:05Z", + "published": "2024-11-19T18:31:05Z", + "aliases": [ + "CVE-2024-51914" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gopi Ramasamy drop in image slideshow gallery allows DOM-Based XSS.This issue affects drop in image slideshow gallery: from n/a through 12.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51914" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/drop-in-image-slideshow-gallery/wordpress-drop-in-image-slideshow-gallery-plugin-12-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-wqw7-mcpw-gfgp/GHSA-wqw7-mcpw-gfgp.json b/advisories/unreviewed/2024/11/GHSA-wqw7-mcpw-gfgp/GHSA-wqw7-mcpw-gfgp.json new file mode 100644 index 00000000000..14b056ab1cc --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-wqw7-mcpw-gfgp/GHSA-wqw7-mcpw-gfgp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wqw7-mcpw-gfgp", + "modified": "2024-11-19T18:31:05Z", + "published": "2024-11-19T18:31:05Z", + "aliases": [ + "CVE-2024-51925" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sazzad Hu Testimonial Slider Shortcode allows Stored XSS.This issue affects Testimonial Slider Shortcode: from n/a through 1.1.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51925" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/testimonial-slider-shortcode/wordpress-testimonial-slider-shortcode-plugin-1-1-9-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-wr8m-prmg-jgh7/GHSA-wr8m-prmg-jgh7.json b/advisories/unreviewed/2024/11/GHSA-wr8m-prmg-jgh7/GHSA-wr8m-prmg-jgh7.json new file mode 100644 index 00000000000..eccd41f87fa --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-wr8m-prmg-jgh7/GHSA-wr8m-prmg-jgh7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wr8m-prmg-jgh7", + "modified": "2024-11-19T18:31:04Z", + "published": "2024-11-19T18:31:04Z", + "aliases": [ + "CVE-2024-51873" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in matorel Multi-day Booking Calendar allows DOM-Based XSS.This issue affects Multi-day Booking Calendar: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51873" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/multi-day-booking-calendar/wordpress-multi-day-booking-calendar-plugin-1-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-wrm6-cj5m-64m9/GHSA-wrm6-cj5m-64m9.json b/advisories/unreviewed/2024/11/GHSA-wrm6-cj5m-64m9/GHSA-wrm6-cj5m-64m9.json new file mode 100644 index 00000000000..8bef02a9b6e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-wrm6-cj5m-64m9/GHSA-wrm6-cj5m-64m9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wrm6-cj5m-64m9", + "modified": "2024-11-19T18:31:03Z", + "published": "2024-11-19T18:31:03Z", + "aliases": [ + "CVE-2024-51838" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jon Smajda Pull This allows DOM-Based XSS.This issue affects Pull This: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51838" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/pull-this/wordpress-pull-this-plugin-1-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-wrr4-ffgm-8pqx/GHSA-wrr4-ffgm-8pqx.json b/advisories/unreviewed/2024/11/GHSA-wrr4-ffgm-8pqx/GHSA-wrr4-ffgm-8pqx.json new file mode 100644 index 00000000000..9417c897a9c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-wrr4-ffgm-8pqx/GHSA-wrr4-ffgm-8pqx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wrr4-ffgm-8pqx", + "modified": "2024-11-19T18:31:04Z", + "published": "2024-11-19T18:31:04Z", + "aliases": [ + "CVE-2024-51885" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Takashi Matsuyama Browsing History allows Stored XSS.This issue affects Browsing History: from n/a through 1.3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51885" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/browsing-history/wordpress-browsing-history-plugin-1-3-1-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-wrrw-gvg8-cw7v/GHSA-wrrw-gvg8-cw7v.json b/advisories/unreviewed/2024/11/GHSA-wrrw-gvg8-cw7v/GHSA-wrrw-gvg8-cw7v.json new file mode 100644 index 00000000000..385787acec5 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-wrrw-gvg8-cw7v/GHSA-wrrw-gvg8-cw7v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wrrw-gvg8-cw7v", + "modified": "2024-11-19T18:31:04Z", + "published": "2024-11-19T18:31:04Z", + "aliases": [ + "CVE-2024-51875" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nazmul Ahsan MDC YouTube Downloader allows DOM-Based XSS.This issue affects MDC YouTube Downloader: from n/a through 3.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51875" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/mdc-youtube-downloader/wordpress-mdc-youtube-downloader-plugin-3-0-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-ww39-c4gp-m7pr/GHSA-ww39-c4gp-m7pr.json b/advisories/unreviewed/2024/11/GHSA-ww39-c4gp-m7pr/GHSA-ww39-c4gp-m7pr.json new file mode 100644 index 00000000000..885cd1f31cc --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-ww39-c4gp-m7pr/GHSA-ww39-c4gp-m7pr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ww39-c4gp-m7pr", + "modified": "2024-11-19T18:31:02Z", + "published": "2024-11-19T18:31:02Z", + "aliases": [ + "CVE-2024-51650" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Scott @ MyDollarPlan.com Random Featured Post allows Stored XSS.This issue affects Random Featured Post: from n/a through 1.1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51650" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/random-featured-post-plugin/wordpress-random-featured-post-plugin-1-1-3-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-wx56-ff7p-8j6f/GHSA-wx56-ff7p-8j6f.json b/advisories/unreviewed/2024/11/GHSA-wx56-ff7p-8j6f/GHSA-wx56-ff7p-8j6f.json index c644d0b4ee1..51c8d9d2efb 100644 --- a/advisories/unreviewed/2024/11/GHSA-wx56-ff7p-8j6f/GHSA-wx56-ff7p-8j6f.json +++ b/advisories/unreviewed/2024/11/GHSA-wx56-ff7p-8j6f/GHSA-wx56-ff7p-8j6f.json @@ -48,7 +48,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-wx59-9gp6-398v/GHSA-wx59-9gp6-398v.json b/advisories/unreviewed/2024/11/GHSA-wx59-9gp6-398v/GHSA-wx59-9gp6-398v.json index 20161da1a67..81ec875d6d8 100644 --- a/advisories/unreviewed/2024/11/GHSA-wx59-9gp6-398v/GHSA-wx59-9gp6-398v.json +++ b/advisories/unreviewed/2024/11/GHSA-wx59-9gp6-398v/GHSA-wx59-9gp6-398v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wx59-9gp6-398v", - "modified": "2024-11-19T00:32:44Z", + "modified": "2024-11-19T18:31:00Z", "published": "2024-11-19T00:32:44Z", "aliases": [ "CVE-2024-33231" ], "details": "Cross Site Scripting vulnerability in Ferozo Email version 1.1 allows a local attacker to execute arbitrary code via a crafted payload to the PDF preview component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-18T23:15:04Z" diff --git a/advisories/unreviewed/2024/11/GHSA-wxxr-rfhp-3pg5/GHSA-wxxr-rfhp-3pg5.json b/advisories/unreviewed/2024/11/GHSA-wxxr-rfhp-3pg5/GHSA-wxxr-rfhp-3pg5.json new file mode 100644 index 00000000000..d17d07a9192 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-wxxr-rfhp-3pg5/GHSA-wxxr-rfhp-3pg5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wxxr-rfhp-3pg5", + "modified": "2024-11-19T18:31:04Z", + "published": "2024-11-19T18:31:04Z", + "aliases": [ + "CVE-2024-51903" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in imFORZA WP Listings Pro allows Stored XSS.This issue affects WP Listings Pro: from n/a through 3.0.14.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51903" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-listings-pro/wordpress-wp-listings-pro-plugin-3-0-14-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-x2f7-hh2h-82c7/GHSA-x2f7-hh2h-82c7.json b/advisories/unreviewed/2024/11/GHSA-x2f7-hh2h-82c7/GHSA-x2f7-hh2h-82c7.json new file mode 100644 index 00000000000..132f7708e95 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-x2f7-hh2h-82c7/GHSA-x2f7-hh2h-82c7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x2f7-hh2h-82c7", + "modified": "2024-11-19T18:31:05Z", + "published": "2024-11-19T18:31:05Z", + "aliases": [ + "CVE-2024-52420" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Creative Motion Disable Admin Notices individually allows Cross Site Request Forgery.This issue affects Disable Admin Notices individually: from n/a through 1.3.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52420" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/disable-admin-notices/wordpress-disable-admin-notices-individually-plugin-1-3-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-x3ch-xq4h-88x8/GHSA-x3ch-xq4h-88x8.json b/advisories/unreviewed/2024/11/GHSA-x3ch-xq4h-88x8/GHSA-x3ch-xq4h-88x8.json new file mode 100644 index 00000000000..5eda8ced8b3 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-x3ch-xq4h-88x8/GHSA-x3ch-xq4h-88x8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x3ch-xq4h-88x8", + "modified": "2024-11-19T18:31:01Z", + "published": "2024-11-19T18:31:01Z", + "aliases": [ + "CVE-2024-50535" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kyle M. Brown Step by Step allows Stored XSS.This issue affects Step by Step: from n/a through 0.4.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50535" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/step-by-step/wordpress-step-by-step-plugin-0-4-5-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-x3h6-m99c-xwp8/GHSA-x3h6-m99c-xwp8.json b/advisories/unreviewed/2024/11/GHSA-x3h6-m99c-xwp8/GHSA-x3h6-m99c-xwp8.json new file mode 100644 index 00000000000..9a3b87e2f22 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-x3h6-m99c-xwp8/GHSA-x3h6-m99c-xwp8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x3h6-m99c-xwp8", + "modified": "2024-11-19T18:31:02Z", + "published": "2024-11-19T18:31:02Z", + "aliases": [ + "CVE-2024-51803" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magnetic Creative Inline Click To Tweet allows DOM-Based XSS.This issue affects Inline Click To Tweet: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51803" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/inline-click-to-tweet/wordpress-inline-click-to-tweet-plugin-1-0-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-xfrj-fcpr-f4m8/GHSA-xfrj-fcpr-f4m8.json b/advisories/unreviewed/2024/11/GHSA-xfrj-fcpr-f4m8/GHSA-xfrj-fcpr-f4m8.json new file mode 100644 index 00000000000..d6760d76f35 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-xfrj-fcpr-f4m8/GHSA-xfrj-fcpr-f4m8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xfrj-fcpr-f4m8", + "modified": "2024-11-19T18:31:01Z", + "published": "2024-11-19T18:31:01Z", + "aliases": [ + "CVE-2024-50542" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zach Silberstein RLM Elementor Widgets Pack allows DOM-Based XSS.This issue affects RLM Elementor Widgets Pack: from n/a through 1.3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50542" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/rlm-elementor-widgets-pack/wordpress-rlm-elementor-widgets-pack-plugin-1-3-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-xgfv-v34v-46vm/GHSA-xgfv-v34v-46vm.json b/advisories/unreviewed/2024/11/GHSA-xgfv-v34v-46vm/GHSA-xgfv-v34v-46vm.json new file mode 100644 index 00000000000..0e39967692b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-xgfv-v34v-46vm/GHSA-xgfv-v34v-46vm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xgfv-v34v-46vm", + "modified": "2024-11-19T18:31:00Z", + "published": "2024-11-19T18:31:00Z", + "aliases": [ + "CVE-2024-43338" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Automattic, Inc. Crowdsignal Dashboard – Polls, Surveys & more allows Cross Site Request Forgery.This issue affects Crowdsignal Dashboard – Polls, Surveys & more: from n/a through 3.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43338" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/polldaddy/wordpress-crowdsignal-polls-ratings-plugin-3-1-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-xmg5-qqq4-wfw3/GHSA-xmg5-qqq4-wfw3.json b/advisories/unreviewed/2024/11/GHSA-xmg5-qqq4-wfw3/GHSA-xmg5-qqq4-wfw3.json new file mode 100644 index 00000000000..118ed9b2f0e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-xmg5-qqq4-wfw3/GHSA-xmg5-qqq4-wfw3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xmg5-qqq4-wfw3", + "modified": "2024-11-19T18:31:01Z", + "published": "2024-11-19T18:31:01Z", + "aliases": [ + "CVE-2024-50522" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Redy Ru WeChat Subscribers Lite allows Reflected XSS.This issue affects WeChat Subscribers Lite : from n/a through 1.6.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50522" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wechat-subscribers-lite/wordpress-wechat-subscribers-lite-plugin-1-6-6-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-xmgx-2283-p55h/GHSA-xmgx-2283-p55h.json b/advisories/unreviewed/2024/11/GHSA-xmgx-2283-p55h/GHSA-xmgx-2283-p55h.json new file mode 100644 index 00000000000..dd9284b575a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-xmgx-2283-p55h/GHSA-xmgx-2283-p55h.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xmgx-2283-p55h", + "modified": "2024-11-19T18:31:06Z", + "published": "2024-11-19T18:31:06Z", + "aliases": [ + "CVE-2024-48992" + ], + "details": "Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Ruby interpreter with an attacker-controlled RUBYLIB environment variable.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48992" + }, + { + "type": "WEB", + "url": "https://github.com/liske/needrestart/commit/b5f25f6ec6e7dd0c5be249e4e45de4ee9ffe594f" + }, + { + "type": "WEB", + "url": "https://www.cve.org/CVERecord?id=CVE-2024-48992" + }, + { + "type": "WEB", + "url": "https://www.qualys.com/2024/11/19/needrestart/needrestart.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-xmvp-3p7r-g4vm/GHSA-xmvp-3p7r-g4vm.json b/advisories/unreviewed/2024/11/GHSA-xmvp-3p7r-g4vm/GHSA-xmvp-3p7r-g4vm.json new file mode 100644 index 00000000000..3b7ccb04173 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-xmvp-3p7r-g4vm/GHSA-xmvp-3p7r-g4vm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xmvp-3p7r-g4vm", + "modified": "2024-11-19T18:31:01Z", + "published": "2024-11-19T18:31:01Z", + "aliases": [ + "CVE-2024-51634" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Webriti WordPress Themes & Plugins Shop Webriti Custom Login allows Reflected XSS.This issue affects Webriti Custom Login: from n/a through 0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51634" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/webriti-custom-login-page/wordpress-webriti-custom-login-plugin-0-3-csrf-to-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-xq44-wcjx-g3w9/GHSA-xq44-wcjx-g3w9.json b/advisories/unreviewed/2024/11/GHSA-xq44-wcjx-g3w9/GHSA-xq44-wcjx-g3w9.json index 0160f12c33b..a7e9aaecf46 100644 --- a/advisories/unreviewed/2024/11/GHSA-xq44-wcjx-g3w9/GHSA-xq44-wcjx-g3w9.json +++ b/advisories/unreviewed/2024/11/GHSA-xq44-wcjx-g3w9/GHSA-xq44-wcjx-g3w9.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-xqj5-wxw2-5ww9/GHSA-xqj5-wxw2-5ww9.json b/advisories/unreviewed/2024/11/GHSA-xqj5-wxw2-5ww9/GHSA-xqj5-wxw2-5ww9.json new file mode 100644 index 00000000000..5406139cc3b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-xqj5-wxw2-5ww9/GHSA-xqj5-wxw2-5ww9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xqj5-wxw2-5ww9", + "modified": "2024-11-19T18:31:00Z", + "published": "2024-11-19T18:31:00Z", + "aliases": [ + "CVE-2024-50515" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saturday Drive Ninja Forms allows Stored XSS.This issue affects Ninja Forms: from n/a through 3.8.16.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50515" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ninja-forms/wordpress-ninja-forms-the-contact-form-builder-that-grows-with-you-plugin-3-8-16-cross-site-scripting-xss-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-xrg9-2q4w-gf5c/GHSA-xrg9-2q4w-gf5c.json b/advisories/unreviewed/2024/11/GHSA-xrg9-2q4w-gf5c/GHSA-xrg9-2q4w-gf5c.json new file mode 100644 index 00000000000..88bebe15aa9 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-xrg9-2q4w-gf5c/GHSA-xrg9-2q4w-gf5c.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xrg9-2q4w-gf5c", + "modified": "2024-11-19T18:31:06Z", + "published": "2024-11-19T18:31:06Z", + "aliases": [ + "CVE-2024-53045" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: dapm: fix bounds checker error in dapm_widget_list_create\n\nThe widgets array in the snd_soc_dapm_widget_list has a __counted_by\nattribute attached to it, which points to the num_widgets variable. This\nattribute is used in bounds checking, and if it is not set before the\narray is filled, then the bounds sanitizer will issue a warning or a\nkernel panic if CONFIG_UBSAN_TRAP is set.\n\nThis patch sets the size of the widgets list calculated with\nlist_for_each as the initial value for num_widgets as it is used for\nallocating memory for the array. It is updated with the actual number of\nadded elements after the array is filled.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53045" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2ef9439f7a19fd3d43b288d38b1c6e55b668a4fe" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c549cb66e8de0ba1936fc97a59f0156741d3492a" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-xvcg-crx7-qcjv/GHSA-xvcg-crx7-qcjv.json b/advisories/unreviewed/2024/11/GHSA-xvcg-crx7-qcjv/GHSA-xvcg-crx7-qcjv.json new file mode 100644 index 00000000000..7242c66ded5 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-xvcg-crx7-qcjv/GHSA-xvcg-crx7-qcjv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xvcg-crx7-qcjv", + "modified": "2024-11-19T18:31:06Z", + "published": "2024-11-19T18:31:06Z", + "aliases": [ + "CVE-2024-48070" + ], + "details": "Weaver Ecology v9* was discovered to contain a SQL injection vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48070" + }, + { + "type": "WEB", + "url": "https://gist.github.com/CoinIsMoney/ec863c35dfd05c7deea2afea11bf2446" + }, + { + "type": "WEB", + "url": "https://github.com/stuven1989/TemporaryGuild/blob/main/files/exp2-eng.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-xxcq-q4px-9ggw/GHSA-xxcq-q4px-9ggw.json b/advisories/unreviewed/2024/11/GHSA-xxcq-q4px-9ggw/GHSA-xxcq-q4px-9ggw.json new file mode 100644 index 00000000000..adf5819ee14 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-xxcq-q4px-9ggw/GHSA-xxcq-q4px-9ggw.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xxcq-q4px-9ggw", + "modified": "2024-11-19T18:31:06Z", + "published": "2024-11-19T18:31:06Z", + "aliases": [ + "CVE-2024-53049" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nslub/kunit: fix a WARNING due to unwrapped __kmalloc_cache_noprof\n\n'modprobe slub_kunit' will have a warning as shown below. The root cause\nis that __kmalloc_cache_noprof was directly used, which resulted in no\nalloc_tag being allocated. This caused current->alloc_tag to be null,\nleading to a warning in alloc_tag_add_check.\n\nLet's add an alloc_hook layer to __kmalloc_cache_noprof specifically\nwithin lib/slub_kunit.c, which is the only user of this internal slub\nfunction outside kmalloc implementation itself.\n\n[58162.947016] WARNING: CPU: 2 PID: 6210 at\n./include/linux/alloc_tag.h:125 alloc_tagging_slab_alloc_hook+0x268/0x27c\n[58162.957721] Call trace:\n[58162.957919] alloc_tagging_slab_alloc_hook+0x268/0x27c\n[58162.958286] __kmalloc_cache_noprof+0x14c/0x344\n[58162.958615] test_kmalloc_redzone_access+0x50/0x10c [slub_kunit]\n[58162.959045] kunit_try_run_case+0x74/0x184 [kunit]\n[58162.959401] kunit_generic_run_threadfn_adapter+0x2c/0x4c [kunit]\n[58162.959841] kthread+0x10c/0x118\n[58162.960093] ret_from_fork+0x10/0x20\n[58162.960363] ---[ end trace 0000000000000000 ]---", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53049" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2b059d0d1e624adc6e69a754bc48057f8bf459dc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/79aea7dfd98fbbf282d1408fc21849fc9a677768" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T18:15:25Z" + } +} \ No newline at end of file