From ad615b35cc1c6bfefafbd63b4c708b858dcce800 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 16 Oct 2024 15:34:09 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-xhr3-wf7j-h255.json | 40 ++++++++++--- .../GHSA-pfq2-x69w-983r.json | 7 ++- .../GHSA-2hcr-94vw-mxjh.json | 7 ++- .../GHSA-mh87-x5p4-6j68.json | 9 ++- .../GHSA-5m9g-m2vj-47r4.json | 3 +- .../GHSA-qmff-49xc-7rf6.json | 3 +- .../GHSA-r894-pxpx-j3m6.json | 1 + .../GHSA-hwq5-4f7m-7wwg.json | 6 +- .../GHSA-7vc2-83c7-hfr6.json | 2 +- .../GHSA-26hp-m9gv-2j62.json | 38 ++++++++++++ .../GHSA-26qf-2r89-746r.json | 38 ++++++++++++ .../GHSA-3cr3-v8qm-wfcv.json | 11 ++-- .../GHSA-3f9p-f8r2-mqhp.json | 38 ++++++++++++ .../GHSA-3wm3-96hr-g3vq.json | 38 ++++++++++++ .../GHSA-45v4-893g-9x45.json | 38 ++++++++++++ .../GHSA-6hvm-8v29-cgp8.json | 42 ++++++++++++++ .../GHSA-74h9-7gm3-qv73.json | 38 ++++++++++++ .../GHSA-772r-h37x-x52x.json | 38 ++++++++++++ .../GHSA-7r7x-w2qg-cx77.json | 6 +- .../GHSA-88j8-mfjr-vw9q.json | 35 +++++++++++ .../GHSA-8j37-24m2-5x5f.json | 2 +- .../GHSA-8p2h-8vgw-6jmp.json | 38 ++++++++++++ .../GHSA-8p7f-wrwf-vh3p.json | 58 +++++++++++++++++++ .../GHSA-8xx5-ghfp-wg5c.json | 6 +- .../GHSA-938j-2fmp-8ggv.json | 38 ++++++++++++ .../GHSA-9jhf-qw2w-cpxx.json | 38 ++++++++++++ .../GHSA-c35v-rr33-7x25.json | 38 ++++++++++++ .../GHSA-c4h6-84f3-72cf.json | 38 ++++++++++++ .../GHSA-c6hq-rccc-7p5f.json | 58 +++++++++++++++++++ .../GHSA-cc35-6v6h-gx9c.json | 38 ++++++++++++ .../GHSA-cf97-87xx-c9w4.json | 38 ++++++++++++ .../GHSA-g783-p3gp-4q89.json | 38 ++++++++++++ .../GHSA-gfc8-6qcc-3mvm.json | 42 ++++++++++++++ .../GHSA-gm3v-m2w5-wm38.json | 38 ++++++++++++ .../GHSA-gq45-2xpx-vvv2.json | 42 ++++++++++++++ .../GHSA-h9vw-g3h9-6jvw.json | 38 ++++++++++++ .../GHSA-j6vx-9w7x-j8g7.json | 38 ++++++++++++ .../GHSA-mh59-qf67-hhp9.json | 38 ++++++++++++ .../GHSA-mhrc-c9xr-f633.json | 42 ++++++++++++++ .../GHSA-mwp6-vpg9-65vj.json | 38 ++++++++++++ .../GHSA-mwpp-f4jm-gfhf.json | 38 ++++++++++++ .../GHSA-q468-r36f-2v9x.json | 38 ++++++++++++ .../GHSA-q7q9-7mhx-gjww.json | 38 ++++++++++++ .../GHSA-r4mm-h2x4-63w3.json | 38 ++++++++++++ .../GHSA-rwrg-crcp-fr3p.json | 38 ++++++++++++ .../GHSA-v65q-q3ch-5jrg.json | 11 ++-- .../GHSA-v727-c3qh-388m.json | 38 ++++++++++++ .../GHSA-v7q3-h4r2-3g3j.json | 11 ++-- .../GHSA-vx6r-82hr-hr24.json | 6 +- .../GHSA-w2mv-76hq-6267.json | 38 ++++++++++++ .../GHSA-w6jf-24wj-w8xx.json | 38 ++++++++++++ .../GHSA-w8vw-x82m-vg68.json | 38 ++++++++++++ .../GHSA-w94f-hwr2-wfp4.json | 46 +++++++++++++++ .../GHSA-whhf-w6qf-q77v.json | 38 ++++++++++++ .../GHSA-x279-24jv-7gr3.json | 42 ++++++++++++++ .../GHSA-x6x8-x7qh-52jw.json | 38 ++++++++++++ .../GHSA-xc28-gw78-r3rv.json | 38 ++++++++++++ .../GHSA-xfh8-7hcx-ppfp.json | 6 +- .../GHSA-xm6p-38g9-7hh9.json | 38 ++++++++++++ .../GHSA-xm89-5c6f-pv99.json | 38 ++++++++++++ 60 files changed, 1801 insertions(+), 35 deletions(-) rename advisories/{unreviewed => github-reviewed}/2024/10/GHSA-xhr3-wf7j-h255/GHSA-xhr3-wf7j-h255.json (61%) create mode 100644 advisories/unreviewed/2024/10/GHSA-26hp-m9gv-2j62/GHSA-26hp-m9gv-2j62.json create mode 100644 advisories/unreviewed/2024/10/GHSA-26qf-2r89-746r/GHSA-26qf-2r89-746r.json create mode 100644 advisories/unreviewed/2024/10/GHSA-3f9p-f8r2-mqhp/GHSA-3f9p-f8r2-mqhp.json create mode 100644 advisories/unreviewed/2024/10/GHSA-3wm3-96hr-g3vq/GHSA-3wm3-96hr-g3vq.json create mode 100644 advisories/unreviewed/2024/10/GHSA-45v4-893g-9x45/GHSA-45v4-893g-9x45.json create mode 100644 advisories/unreviewed/2024/10/GHSA-6hvm-8v29-cgp8/GHSA-6hvm-8v29-cgp8.json create mode 100644 advisories/unreviewed/2024/10/GHSA-74h9-7gm3-qv73/GHSA-74h9-7gm3-qv73.json create mode 100644 advisories/unreviewed/2024/10/GHSA-772r-h37x-x52x/GHSA-772r-h37x-x52x.json create mode 100644 advisories/unreviewed/2024/10/GHSA-88j8-mfjr-vw9q/GHSA-88j8-mfjr-vw9q.json create mode 100644 advisories/unreviewed/2024/10/GHSA-8p2h-8vgw-6jmp/GHSA-8p2h-8vgw-6jmp.json create mode 100644 advisories/unreviewed/2024/10/GHSA-8p7f-wrwf-vh3p/GHSA-8p7f-wrwf-vh3p.json create mode 100644 advisories/unreviewed/2024/10/GHSA-938j-2fmp-8ggv/GHSA-938j-2fmp-8ggv.json create mode 100644 advisories/unreviewed/2024/10/GHSA-9jhf-qw2w-cpxx/GHSA-9jhf-qw2w-cpxx.json create mode 100644 advisories/unreviewed/2024/10/GHSA-c35v-rr33-7x25/GHSA-c35v-rr33-7x25.json create mode 100644 advisories/unreviewed/2024/10/GHSA-c4h6-84f3-72cf/GHSA-c4h6-84f3-72cf.json create mode 100644 advisories/unreviewed/2024/10/GHSA-c6hq-rccc-7p5f/GHSA-c6hq-rccc-7p5f.json create mode 100644 advisories/unreviewed/2024/10/GHSA-cc35-6v6h-gx9c/GHSA-cc35-6v6h-gx9c.json create mode 100644 advisories/unreviewed/2024/10/GHSA-cf97-87xx-c9w4/GHSA-cf97-87xx-c9w4.json create mode 100644 advisories/unreviewed/2024/10/GHSA-g783-p3gp-4q89/GHSA-g783-p3gp-4q89.json create mode 100644 advisories/unreviewed/2024/10/GHSA-gfc8-6qcc-3mvm/GHSA-gfc8-6qcc-3mvm.json create mode 100644 advisories/unreviewed/2024/10/GHSA-gm3v-m2w5-wm38/GHSA-gm3v-m2w5-wm38.json create mode 100644 advisories/unreviewed/2024/10/GHSA-gq45-2xpx-vvv2/GHSA-gq45-2xpx-vvv2.json create mode 100644 advisories/unreviewed/2024/10/GHSA-h9vw-g3h9-6jvw/GHSA-h9vw-g3h9-6jvw.json create mode 100644 advisories/unreviewed/2024/10/GHSA-j6vx-9w7x-j8g7/GHSA-j6vx-9w7x-j8g7.json create mode 100644 advisories/unreviewed/2024/10/GHSA-mh59-qf67-hhp9/GHSA-mh59-qf67-hhp9.json create mode 100644 advisories/unreviewed/2024/10/GHSA-mhrc-c9xr-f633/GHSA-mhrc-c9xr-f633.json create mode 100644 advisories/unreviewed/2024/10/GHSA-mwp6-vpg9-65vj/GHSA-mwp6-vpg9-65vj.json create mode 100644 advisories/unreviewed/2024/10/GHSA-mwpp-f4jm-gfhf/GHSA-mwpp-f4jm-gfhf.json create mode 100644 advisories/unreviewed/2024/10/GHSA-q468-r36f-2v9x/GHSA-q468-r36f-2v9x.json create mode 100644 advisories/unreviewed/2024/10/GHSA-q7q9-7mhx-gjww/GHSA-q7q9-7mhx-gjww.json create mode 100644 advisories/unreviewed/2024/10/GHSA-r4mm-h2x4-63w3/GHSA-r4mm-h2x4-63w3.json create mode 100644 advisories/unreviewed/2024/10/GHSA-rwrg-crcp-fr3p/GHSA-rwrg-crcp-fr3p.json create mode 100644 advisories/unreviewed/2024/10/GHSA-v727-c3qh-388m/GHSA-v727-c3qh-388m.json create mode 100644 advisories/unreviewed/2024/10/GHSA-w2mv-76hq-6267/GHSA-w2mv-76hq-6267.json create mode 100644 advisories/unreviewed/2024/10/GHSA-w6jf-24wj-w8xx/GHSA-w6jf-24wj-w8xx.json create mode 100644 advisories/unreviewed/2024/10/GHSA-w8vw-x82m-vg68/GHSA-w8vw-x82m-vg68.json create mode 100644 advisories/unreviewed/2024/10/GHSA-w94f-hwr2-wfp4/GHSA-w94f-hwr2-wfp4.json create mode 100644 advisories/unreviewed/2024/10/GHSA-whhf-w6qf-q77v/GHSA-whhf-w6qf-q77v.json create mode 100644 advisories/unreviewed/2024/10/GHSA-x279-24jv-7gr3/GHSA-x279-24jv-7gr3.json create mode 100644 advisories/unreviewed/2024/10/GHSA-x6x8-x7qh-52jw/GHSA-x6x8-x7qh-52jw.json create mode 100644 advisories/unreviewed/2024/10/GHSA-xc28-gw78-r3rv/GHSA-xc28-gw78-r3rv.json create mode 100644 advisories/unreviewed/2024/10/GHSA-xm6p-38g9-7hh9/GHSA-xm6p-38g9-7hh9.json create mode 100644 advisories/unreviewed/2024/10/GHSA-xm89-5c6f-pv99/GHSA-xm89-5c6f-pv99.json diff --git a/advisories/unreviewed/2024/10/GHSA-xhr3-wf7j-h255/GHSA-xhr3-wf7j-h255.json b/advisories/github-reviewed/2024/10/GHSA-xhr3-wf7j-h255/GHSA-xhr3-wf7j-h255.json similarity index 61% rename from advisories/unreviewed/2024/10/GHSA-xhr3-wf7j-h255/GHSA-xhr3-wf7j-h255.json rename to advisories/github-reviewed/2024/10/GHSA-xhr3-wf7j-h255/GHSA-xhr3-wf7j-h255.json index 66332f25c0a..0043af1d57d 100644 --- a/advisories/unreviewed/2024/10/GHSA-xhr3-wf7j-h255/GHSA-xhr3-wf7j-h255.json +++ b/advisories/github-reviewed/2024/10/GHSA-xhr3-wf7j-h255/GHSA-xhr3-wf7j-h255.json @@ -1,17 +1,39 @@ { "schema_version": "1.4.0", "id": "GHSA-xhr3-wf7j-h255", - "modified": "2024-10-15T21:30:39Z", + "modified": "2024-10-16T14:09:50Z", "published": "2024-10-15T21:30:39Z", "aliases": [ "CVE-2024-44337" ], + "summary": "Infinite loop in github.com/gomarkdown/markdown", "details": "The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Prior to pseudoversion `v0.0.0-20240729232818-a2a9c4f`, which corresponds with commit `a2a9c4f76ef5a5c32108e36f7c47f8d310322252`, there was a logical problem in the paragraph function of the parser/block.go file, which allowed a remote attacker to cause a denial of service (DoS) condition by providing a tailor-made input that caused an infinite loop, causing the program to hang and consume resources indefinitely. Submit `a2a9c4f76ef5a5c32108e36f7c47f8d310322252` contains fixes to this problem.", "severity": [ - + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N" + } ], "affected": [ - + { + "package": { + "ecosystem": "Go", + "name": "github.com/gomarkdown/markdown" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.0.0-20240729232818-a2a9c4f" + } + ] + } + ] + } ], "references": [ { @@ -25,15 +47,19 @@ { "type": "WEB", "url": "https://github.com/Brinmon/CVE-2024-44337" + }, + { + "type": "PACKAGE", + "url": "https://github.com/gomarkdown/markdown" } ], "database_specific": { "cwe_ids": [ - + "CWE-835" ], - "severity": null, - "github_reviewed": false, - "github_reviewed_at": null, + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-10-16T14:09:50Z", "nvd_published_at": "2024-10-15T20:15:21Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/01/GHSA-pfq2-x69w-983r/GHSA-pfq2-x69w-983r.json b/advisories/unreviewed/2022/01/GHSA-pfq2-x69w-983r/GHSA-pfq2-x69w-983r.json index 490f0460702..0661033f269 100644 --- a/advisories/unreviewed/2022/01/GHSA-pfq2-x69w-983r/GHSA-pfq2-x69w-983r.json +++ b/advisories/unreviewed/2022/01/GHSA-pfq2-x69w-983r/GHSA-pfq2-x69w-983r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pfq2-x69w-983r", - "modified": "2022-01-28T00:02:46Z", + "modified": "2024-10-16T15:32:05Z", "published": "2022-01-25T00:01:47Z", "aliases": [ "CVE-2021-24923" ], "details": "The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.25 does not escape the sib-statistics-date parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/02/GHSA-2hcr-94vw-mxjh/GHSA-2hcr-94vw-mxjh.json b/advisories/unreviewed/2022/02/GHSA-2hcr-94vw-mxjh/GHSA-2hcr-94vw-mxjh.json index 4ddbf619fda..9713081647f 100644 --- a/advisories/unreviewed/2022/02/GHSA-2hcr-94vw-mxjh/GHSA-2hcr-94vw-mxjh.json +++ b/advisories/unreviewed/2022/02/GHSA-2hcr-94vw-mxjh/GHSA-2hcr-94vw-mxjh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2hcr-94vw-mxjh", - "modified": "2022-02-23T00:01:19Z", + "modified": "2024-10-16T15:32:05Z", "published": "2022-02-15T00:02:50Z", "aliases": [ "CVE-2021-24874" ], "details": "The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.31 does not escape the lang and pid parameter before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-mh87-x5p4-6j68/GHSA-mh87-x5p4-6j68.json b/advisories/unreviewed/2022/05/GHSA-mh87-x5p4-6j68/GHSA-mh87-x5p4-6j68.json index 482a8308a7a..cf7454f3f29 100644 --- a/advisories/unreviewed/2022/05/GHSA-mh87-x5p4-6j68/GHSA-mh87-x5p4-6j68.json +++ b/advisories/unreviewed/2022/05/GHSA-mh87-x5p4-6j68/GHSA-mh87-x5p4-6j68.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mh87-x5p4-6j68", - "modified": "2022-05-24T17:17:12Z", + "modified": "2024-10-16T15:32:04Z", "published": "2022-05-24T17:17:12Z", "aliases": [ "CVE-2020-12104" ], "details": "The Import feature in the wp-advanced-search plugin 3.3.6 for WordPress is vulnerable to authenticated SQL injection via an uploaded .sql file. An attacker can use this to execute SQL commands without any validation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-5m9g-m2vj-47r4/GHSA-5m9g-m2vj-47r4.json b/advisories/unreviewed/2024/01/GHSA-5m9g-m2vj-47r4/GHSA-5m9g-m2vj-47r4.json index 0ad115e45e8..e26d67ee462 100644 --- a/advisories/unreviewed/2024/01/GHSA-5m9g-m2vj-47r4/GHSA-5m9g-m2vj-47r4.json +++ b/advisories/unreviewed/2024/01/GHSA-5m9g-m2vj-47r4/GHSA-5m9g-m2vj-47r4.json @@ -44,7 +44,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-203" + "CWE-203", + "CWE-99" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-qmff-49xc-7rf6/GHSA-qmff-49xc-7rf6.json b/advisories/unreviewed/2024/01/GHSA-qmff-49xc-7rf6/GHSA-qmff-49xc-7rf6.json index 56f8e966757..3a096f10043 100644 --- a/advisories/unreviewed/2024/01/GHSA-qmff-49xc-7rf6/GHSA-qmff-49xc-7rf6.json +++ b/advisories/unreviewed/2024/01/GHSA-qmff-49xc-7rf6/GHSA-qmff-49xc-7rf6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qmff-49xc-7rf6", - "modified": "2024-09-16T14:37:23Z", + "modified": "2024-10-16T15:32:05Z", "published": "2024-01-17T18:31:36Z", "aliases": [ "CVE-2024-0646" @@ -128,6 +128,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1314", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/04/GHSA-r894-pxpx-j3m6/GHSA-r894-pxpx-j3m6.json b/advisories/unreviewed/2024/04/GHSA-r894-pxpx-j3m6/GHSA-r894-pxpx-j3m6.json index 930918ac59b..510fa229dbc 100644 --- a/advisories/unreviewed/2024/04/GHSA-r894-pxpx-j3m6/GHSA-r894-pxpx-j3m6.json +++ b/advisories/unreviewed/2024/04/GHSA-r894-pxpx-j3m6/GHSA-r894-pxpx-j3m6.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-400", "CWE-434" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/08/GHSA-hwq5-4f7m-7wwg/GHSA-hwq5-4f7m-7wwg.json b/advisories/unreviewed/2024/08/GHSA-hwq5-4f7m-7wwg/GHSA-hwq5-4f7m-7wwg.json index 6c4ff82afd3..cbde43cd7d8 100644 --- a/advisories/unreviewed/2024/08/GHSA-hwq5-4f7m-7wwg/GHSA-hwq5-4f7m-7wwg.json +++ b/advisories/unreviewed/2024/08/GHSA-hwq5-4f7m-7wwg/GHSA-hwq5-4f7m-7wwg.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hwq5-4f7m-7wwg", - "modified": "2024-08-22T21:31:29Z", + "modified": "2024-10-16T15:32:06Z", "published": "2024-08-22T21:31:29Z", "aliases": [ "CVE-2023-7260" ], "details": "Path Traversal vulnerability discovered in OpenText™ CX-E Voice, \n\naffecting all version through 22.4. The vulnerability could allow arbitrarily access files on the system.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:A/V:C/RE:L/U:Amber" diff --git a/advisories/unreviewed/2024/09/GHSA-7vc2-83c7-hfr6/GHSA-7vc2-83c7-hfr6.json b/advisories/unreviewed/2024/09/GHSA-7vc2-83c7-hfr6/GHSA-7vc2-83c7-hfr6.json index 48c470917e0..bc72633273c 100644 --- a/advisories/unreviewed/2024/09/GHSA-7vc2-83c7-hfr6/GHSA-7vc2-83c7-hfr6.json +++ b/advisories/unreviewed/2024/09/GHSA-7vc2-83c7-hfr6/GHSA-7vc2-83c7-hfr6.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-26hp-m9gv-2j62/GHSA-26hp-m9gv-2j62.json b/advisories/unreviewed/2024/10/GHSA-26hp-m9gv-2j62/GHSA-26hp-m9gv-2j62.json new file mode 100644 index 00000000000..07219e7c3ca --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-26hp-m9gv-2j62/GHSA-26hp-m9gv-2j62.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-26hp-m9gv-2j62", + "modified": "2024-10-16T15:32:07Z", + "published": "2024-10-16T15:32:07Z", + "aliases": [ + "CVE-2024-48030" + ], + "details": "Deserialization of Untrusted Data vulnerability in Gabriele Valenti Telecash Ricaricaweb allows Object Injection.This issue affects Telecash Ricaricaweb: from n/a through 2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48030" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/telecash-ricaricaweb/wordpress-telecash-ricaricaweb-plugin-2-2-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T14:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-26qf-2r89-746r/GHSA-26qf-2r89-746r.json b/advisories/unreviewed/2024/10/GHSA-26qf-2r89-746r/GHSA-26qf-2r89-746r.json new file mode 100644 index 00000000000..49eb702e2b0 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-26qf-2r89-746r/GHSA-26qf-2r89-746r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-26qf-2r89-746r", + "modified": "2024-10-16T15:32:07Z", + "published": "2024-10-16T15:32:07Z", + "aliases": [ + "CVE-2024-49242" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Shafiq Digital Lottery allows Upload a Web Shell to a Web Server.This issue affects Digital Lottery: from n/a through 3.0.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49242" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/digital-lottery/wordpress-digital-lottery-plugin-3-0-5-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-3cr3-v8qm-wfcv/GHSA-3cr3-v8qm-wfcv.json b/advisories/unreviewed/2024/10/GHSA-3cr3-v8qm-wfcv/GHSA-3cr3-v8qm-wfcv.json index dfe351dcd4e..c2ac9ba8c99 100644 --- a/advisories/unreviewed/2024/10/GHSA-3cr3-v8qm-wfcv/GHSA-3cr3-v8qm-wfcv.json +++ b/advisories/unreviewed/2024/10/GHSA-3cr3-v8qm-wfcv/GHSA-3cr3-v8qm-wfcv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3cr3-v8qm-wfcv", - "modified": "2024-10-14T15:30:46Z", + "modified": "2024-10-16T15:32:06Z", "published": "2024-10-14T15:30:46Z", "aliases": [ "CVE-2024-48251" ], "details": "Wavelog 1.8.5 allows Activated_gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-14T15:15:13Z" diff --git a/advisories/unreviewed/2024/10/GHSA-3f9p-f8r2-mqhp/GHSA-3f9p-f8r2-mqhp.json b/advisories/unreviewed/2024/10/GHSA-3f9p-f8r2-mqhp/GHSA-3f9p-f8r2-mqhp.json new file mode 100644 index 00000000000..1bdb3163515 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-3f9p-f8r2-mqhp/GHSA-3f9p-f8r2-mqhp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3f9p-f8r2-mqhp", + "modified": "2024-10-16T15:32:07Z", + "published": "2024-10-16T15:32:07Z", + "aliases": [ + "CVE-2024-49247" + ], + "details": ": Authentication Bypass Using an Alternate Path or Channel vulnerability in sooskriszta, webforza BuddyPress Better Registration allows : Authentication Bypass.This issue affects BuddyPress Better Registration: from n/a through 1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49247" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/better-bp-registration/wordpress-buddypress-better-registration-plugin-1-6-broken-authentication-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T13:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-3wm3-96hr-g3vq/GHSA-3wm3-96hr-g3vq.json b/advisories/unreviewed/2024/10/GHSA-3wm3-96hr-g3vq/GHSA-3wm3-96hr-g3vq.json new file mode 100644 index 00000000000..77512705b6d --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-3wm3-96hr-g3vq/GHSA-3wm3-96hr-g3vq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3wm3-96hr-g3vq", + "modified": "2024-10-16T15:32:07Z", + "published": "2024-10-16T15:32:07Z", + "aliases": [ + "CVE-2024-49216" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Joshua Clayton Feed Comments Number allows Upload a Web Shell to a Web Server.This issue affects Feed Comments Number: from n/a through 0.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49216" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/feed-comments-number/wordpress-feed-comments-number-plugin-0-2-1-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-45v4-893g-9x45/GHSA-45v4-893g-9x45.json b/advisories/unreviewed/2024/10/GHSA-45v4-893g-9x45/GHSA-45v4-893g-9x45.json new file mode 100644 index 00000000000..56c84897d11 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-45v4-893g-9x45/GHSA-45v4-893g-9x45.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-45v4-893g-9x45", + "modified": "2024-10-16T15:32:07Z", + "published": "2024-10-16T15:32:07Z", + "aliases": [ + "CVE-2024-48028" + ], + "details": "Deserialization of Untrusted Data vulnerability in Boyan Raichev IP Loc8 allows Object Injection.This issue affects IP Loc8: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48028" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ip-loc8/wordpress-ip-loc8-plugin-1-1-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T14:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-6hvm-8v29-cgp8/GHSA-6hvm-8v29-cgp8.json b/advisories/unreviewed/2024/10/GHSA-6hvm-8v29-cgp8/GHSA-6hvm-8v29-cgp8.json new file mode 100644 index 00000000000..f3d1c056db1 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-6hvm-8v29-cgp8/GHSA-6hvm-8v29-cgp8.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6hvm-8v29-cgp8", + "modified": "2024-10-16T15:32:07Z", + "published": "2024-10-16T15:32:07Z", + "aliases": [ + "CVE-2023-32189" + ], + "details": "Insecure handling of ssh keys used to bootstrap clients allows local attackers to potentially gain access to the keys", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32189" + }, + { + "type": "WEB", + "url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2023-32189" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T14:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-74h9-7gm3-qv73/GHSA-74h9-7gm3-qv73.json b/advisories/unreviewed/2024/10/GHSA-74h9-7gm3-qv73/GHSA-74h9-7gm3-qv73.json new file mode 100644 index 00000000000..f03b41c0cc1 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-74h9-7gm3-qv73/GHSA-74h9-7gm3-qv73.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-74h9-7gm3-qv73", + "modified": "2024-10-16T15:32:07Z", + "published": "2024-10-16T15:32:07Z", + "aliases": [ + "CVE-2024-48035" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Takayuki Imanishi ACF Images Search And Insert allows Upload a Web Shell to a Web Server.This issue affects ACF Images Search And Insert: from n/a through 1.1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48035" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/acf-images-search-and-insert/wordpress-acf-images-search-and-insert-plugin-1-1-4-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-772r-h37x-x52x/GHSA-772r-h37x-x52x.json b/advisories/unreviewed/2024/10/GHSA-772r-h37x-x52x/GHSA-772r-h37x-x52x.json new file mode 100644 index 00000000000..d353a035cbe --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-772r-h37x-x52x/GHSA-772r-h37x-x52x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-772r-h37x-x52x", + "modified": "2024-10-16T15:32:08Z", + "published": "2024-10-16T15:32:08Z", + "aliases": [ + "CVE-2024-49267" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in nayon46 Unlimited Addon For Elementor allows Stored XSS.This issue affects Unlimited Addon For Elementor: from n/a through 2.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49267" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/unlimited-addon-for-elementor/wordpress-unlimited-addon-for-elementor-plugin-2-0-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-7r7x-w2qg-cx77/GHSA-7r7x-w2qg-cx77.json b/advisories/unreviewed/2024/10/GHSA-7r7x-w2qg-cx77/GHSA-7r7x-w2qg-cx77.json index fd080e48019..dd5963c7dfb 100644 --- a/advisories/unreviewed/2024/10/GHSA-7r7x-w2qg-cx77/GHSA-7r7x-w2qg-cx77.json +++ b/advisories/unreviewed/2024/10/GHSA-7r7x-w2qg-cx77/GHSA-7r7x-w2qg-cx77.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7r7x-w2qg-cx77", - "modified": "2024-10-04T15:31:20Z", + "modified": "2024-10-16T15:32:06Z", "published": "2024-10-04T15:31:20Z", "aliases": [ "CVE-2024-47653" ], "details": "This vulnerability exists in Shilpi Client Dashboard due to lack of authorization for modification and cancellation requests through certain API endpoints. An authenticated remote attacker could exploit this vulnerability by placing or cancelling requests through API request body leading to unauthorized modification of requests belonging to the other users.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/10/GHSA-88j8-mfjr-vw9q/GHSA-88j8-mfjr-vw9q.json b/advisories/unreviewed/2024/10/GHSA-88j8-mfjr-vw9q/GHSA-88j8-mfjr-vw9q.json new file mode 100644 index 00000000000..399d73312b2 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-88j8-mfjr-vw9q/GHSA-88j8-mfjr-vw9q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-88j8-mfjr-vw9q", + "modified": "2024-10-16T15:32:08Z", + "published": "2024-10-16T15:32:08Z", + "aliases": [ + "CVE-2024-48744" + ], + "details": "A Reflected Cross Site Scripting (XSS) vulnerability was found in /trms/listed- teachers.php in PHPGurukul Teachers Record Management System v2.1, which allows remote attackers to execute arbitrary code via \"searchinput\" POST request parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48744" + }, + { + "type": "WEB", + "url": "https://github.com/vkcyberexpert/CVE-Writeup/blob/main/PHPGurukul/Teachers%20Record/Reflected%20XSS.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-8j37-24m2-5x5f/GHSA-8j37-24m2-5x5f.json b/advisories/unreviewed/2024/10/GHSA-8j37-24m2-5x5f/GHSA-8j37-24m2-5x5f.json index dd8e2a0920f..600e787cba7 100644 --- a/advisories/unreviewed/2024/10/GHSA-8j37-24m2-5x5f/GHSA-8j37-24m2-5x5f.json +++ b/advisories/unreviewed/2024/10/GHSA-8j37-24m2-5x5f/GHSA-8j37-24m2-5x5f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8j37-24m2-5x5f", - "modified": "2024-10-04T06:30:45Z", + "modified": "2024-10-16T15:32:06Z", "published": "2024-10-04T06:30:45Z", "aliases": [ "CVE-2024-8519" diff --git a/advisories/unreviewed/2024/10/GHSA-8p2h-8vgw-6jmp/GHSA-8p2h-8vgw-6jmp.json b/advisories/unreviewed/2024/10/GHSA-8p2h-8vgw-6jmp/GHSA-8p2h-8vgw-6jmp.json new file mode 100644 index 00000000000..184d192272b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-8p2h-8vgw-6jmp/GHSA-8p2h-8vgw-6jmp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8p2h-8vgw-6jmp", + "modified": "2024-10-16T15:32:07Z", + "published": "2024-10-16T15:32:07Z", + "aliases": [ + "CVE-2024-48034" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Fliperrr Team Creates 3D Flipbook, PDF Flipbook allows Upload a Web Shell to a Web Server.This issue affects Creates 3D Flipbook, PDF Flipbook: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48034" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/create-flipbook-from-pdf/wordpress-creates-3d-flipbook-pdf-flipbook-plugin-1-2-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-8p7f-wrwf-vh3p/GHSA-8p7f-wrwf-vh3p.json b/advisories/unreviewed/2024/10/GHSA-8p7f-wrwf-vh3p/GHSA-8p7f-wrwf-vh3p.json new file mode 100644 index 00000000000..bbe81cd54dd --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-8p7f-wrwf-vh3p/GHSA-8p7f-wrwf-vh3p.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8p7f-wrwf-vh3p", + "modified": "2024-10-16T15:32:07Z", + "published": "2024-10-16T15:32:07Z", + "aliases": [ + "CVE-2024-10024" + ], + "details": "A vulnerability, which was classified as critical, has been found in code-projects Pharmacy Management System 1.0. This issue affects some unknown processing of the file /php/manage_medicine_stock.php. The manipulation of the argument name/packing/generic_name/suppliers_name leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10024" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://gist.github.com/higordiego/b0083f7f12dee245c2fbe7102e31d9a4" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.280559" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.280559" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.424529" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T13:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-8xx5-ghfp-wg5c/GHSA-8xx5-ghfp-wg5c.json b/advisories/unreviewed/2024/10/GHSA-8xx5-ghfp-wg5c/GHSA-8xx5-ghfp-wg5c.json index da1c6e35989..8b1ee6f4013 100644 --- a/advisories/unreviewed/2024/10/GHSA-8xx5-ghfp-wg5c/GHSA-8xx5-ghfp-wg5c.json +++ b/advisories/unreviewed/2024/10/GHSA-8xx5-ghfp-wg5c/GHSA-8xx5-ghfp-wg5c.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8xx5-ghfp-wg5c", - "modified": "2024-10-04T15:31:20Z", + "modified": "2024-10-16T15:32:06Z", "published": "2024-10-04T15:31:20Z", "aliases": [ "CVE-2024-47654" ], "details": "This vulnerability exists in Shilpi Client Dashboard due to lack of rate limiting and Captcha protection for OTP requests in certain API endpoint. An unauthenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoints, which could lead to the OTP bombing on the targeted system.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/10/GHSA-938j-2fmp-8ggv/GHSA-938j-2fmp-8ggv.json b/advisories/unreviewed/2024/10/GHSA-938j-2fmp-8ggv/GHSA-938j-2fmp-8ggv.json new file mode 100644 index 00000000000..1676212646e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-938j-2fmp-8ggv/GHSA-938j-2fmp-8ggv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-938j-2fmp-8ggv", + "modified": "2024-10-16T15:32:08Z", + "published": "2024-10-16T15:32:08Z", + "aliases": [ + "CVE-2024-49254" + ], + "details": "Improper Control of Generation of Code ('Code Injection') vulnerability in Sunjianle allows Code Injection.This issue affects ajax-extend: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49254" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ajax-extend/wordpress-ajax-extend-plugin-1-0-remote-code-execution-rce-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-9jhf-qw2w-cpxx/GHSA-9jhf-qw2w-cpxx.json b/advisories/unreviewed/2024/10/GHSA-9jhf-qw2w-cpxx/GHSA-9jhf-qw2w-cpxx.json new file mode 100644 index 00000000000..e40ea83092e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-9jhf-qw2w-cpxx/GHSA-9jhf-qw2w-cpxx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9jhf-qw2w-cpxx", + "modified": "2024-10-16T15:32:07Z", + "published": "2024-10-16T15:32:07Z", + "aliases": [ + "CVE-2024-47645" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sajid Javed Top Bar – PopUps – by WPOptin allows PHP Local File Inclusion.This issue affects Top Bar – PopUps – by WPOptin: from n/a through 2.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47645" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wpoptin/wordpress-wpoptin-plugin-2-0-1-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T14:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-c35v-rr33-7x25/GHSA-c35v-rr33-7x25.json b/advisories/unreviewed/2024/10/GHSA-c35v-rr33-7x25/GHSA-c35v-rr33-7x25.json new file mode 100644 index 00000000000..c84fa2b814b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-c35v-rr33-7x25/GHSA-c35v-rr33-7x25.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c35v-rr33-7x25", + "modified": "2024-10-16T15:32:07Z", + "published": "2024-10-16T15:32:07Z", + "aliases": [ + "CVE-2024-47649" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in THATplugin Iconize.This issue affects Iconize: from n/a through 1.2.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47649" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/iconize/wordpress-iconize-plugin-1-2-4-remote-code-execution-rce-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T14:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-c4h6-84f3-72cf/GHSA-c4h6-84f3-72cf.json b/advisories/unreviewed/2024/10/GHSA-c4h6-84f3-72cf/GHSA-c4h6-84f3-72cf.json new file mode 100644 index 00000000000..b26958cde4a --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-c4h6-84f3-72cf/GHSA-c4h6-84f3-72cf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c4h6-84f3-72cf", + "modified": "2024-10-16T15:32:08Z", + "published": "2024-10-16T15:32:08Z", + "aliases": [ + "CVE-2024-49266" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Thimo Grauerholz WP-Spreadplugin allows Stored XSS.This issue affects WP-Spreadplugin: from n/a through 4.8.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49266" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-spreadplugin/wordpress-wp-spreadplugin-plugin-4-8-9-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-c6hq-rccc-7p5f/GHSA-c6hq-rccc-7p5f.json b/advisories/unreviewed/2024/10/GHSA-c6hq-rccc-7p5f/GHSA-c6hq-rccc-7p5f.json new file mode 100644 index 00000000000..df2082f273d --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-c6hq-rccc-7p5f/GHSA-c6hq-rccc-7p5f.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c6hq-rccc-7p5f", + "modified": "2024-10-16T15:32:07Z", + "published": "2024-10-16T15:32:07Z", + "aliases": [ + "CVE-2024-10023" + ], + "details": "A vulnerability classified as critical was found in code-projects Pharmacy Management System 1.0. This vulnerability affects unknown code of the file /php/add_new_medicine.php. The manipulation of the argument name/packing/generic_name/suppliers_name leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10023" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://gist.github.com/higordiego/01a35a20a4e20e937d384b677c000921" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.280558" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.280558" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.424483" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T13:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-cc35-6v6h-gx9c/GHSA-cc35-6v6h-gx9c.json b/advisories/unreviewed/2024/10/GHSA-cc35-6v6h-gx9c/GHSA-cc35-6v6h-gx9c.json new file mode 100644 index 00000000000..115ca975e75 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-cc35-6v6h-gx9c/GHSA-cc35-6v6h-gx9c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cc35-6v6h-gx9c", + "modified": "2024-10-16T15:32:07Z", + "published": "2024-10-16T15:32:07Z", + "aliases": [ + "CVE-2024-48026" + ], + "details": "Deserialization of Untrusted Data vulnerability in Grayson Robbins Disc Golf Manager allows Object Injection.This issue affects Disc Golf Manager: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48026" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/disc-golf-manager/wordpress-disc-golf-manager-plugin-1-0-0-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T14:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-cf97-87xx-c9w4/GHSA-cf97-87xx-c9w4.json b/advisories/unreviewed/2024/10/GHSA-cf97-87xx-c9w4/GHSA-cf97-87xx-c9w4.json new file mode 100644 index 00000000000..1f2f5b4ec51 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-cf97-87xx-c9w4/GHSA-cf97-87xx-c9w4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cf97-87xx-c9w4", + "modified": "2024-10-16T15:32:07Z", + "published": "2024-10-16T15:32:07Z", + "aliases": [ + "CVE-2024-48027" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in xaraartech External featured image from bing allows Upload a Web Shell to a Web Server.This issue affects External featured image from bing: from n/a through 1.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48027" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/external-featured-image-from-bing/wordpress-external-featured-image-from-bing-plugin-1-0-2-remote-code-execution-rce-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T14:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-g783-p3gp-4q89/GHSA-g783-p3gp-4q89.json b/advisories/unreviewed/2024/10/GHSA-g783-p3gp-4q89/GHSA-g783-p3gp-4q89.json new file mode 100644 index 00000000000..a92fe5813bf --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-g783-p3gp-4q89/GHSA-g783-p3gp-4q89.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g783-p3gp-4q89", + "modified": "2024-10-16T15:32:07Z", + "published": "2024-10-16T15:32:07Z", + "aliases": [ + "CVE-2024-49271" + ], + "details": ": Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows : Command Injection.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 1.5.121.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49271" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/unlimited-elements-for-elementor/wordpress-unlimited-elements-for-elementor-free-widgets-addons-templates-plugin-1-5-121-remote-code-execution-rce-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1336" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T13:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-gfc8-6qcc-3mvm/GHSA-gfc8-6qcc-3mvm.json b/advisories/unreviewed/2024/10/GHSA-gfc8-6qcc-3mvm/GHSA-gfc8-6qcc-3mvm.json new file mode 100644 index 00000000000..ee2989746d0 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-gfc8-6qcc-3mvm/GHSA-gfc8-6qcc-3mvm.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gfc8-6qcc-3mvm", + "modified": "2024-10-16T15:32:08Z", + "published": "2024-10-16T15:32:08Z", + "aliases": [ + "CVE-2024-45844" + ], + "details": "BIG-IP monitor functionality may allow an attacker to bypass access control restrictions, regardless of the port lockdown settings.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45844" + }, + { + "type": "WEB", + "url": "https://my.f5.com/manage/s/article/K000140061" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-gm3v-m2w5-wm38/GHSA-gm3v-m2w5-wm38.json b/advisories/unreviewed/2024/10/GHSA-gm3v-m2w5-wm38/GHSA-gm3v-m2w5-wm38.json new file mode 100644 index 00000000000..7c5a438ca16 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-gm3v-m2w5-wm38/GHSA-gm3v-m2w5-wm38.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gm3v-m2w5-wm38", + "modified": "2024-10-16T15:32:07Z", + "published": "2024-10-16T15:32:07Z", + "aliases": [ + "CVE-2024-22034" + ], + "details": "Attackers could put the special files in .osc into the actual package sources (e.g. _apiurl). This allows the attacker to change the configuration of osc for the victim", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22034" + }, + { + "type": "WEB", + "url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2024-22034" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T14:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-gq45-2xpx-vvv2/GHSA-gq45-2xpx-vvv2.json b/advisories/unreviewed/2024/10/GHSA-gq45-2xpx-vvv2/GHSA-gq45-2xpx-vvv2.json new file mode 100644 index 00000000000..a2931dc84ac --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-gq45-2xpx-vvv2/GHSA-gq45-2xpx-vvv2.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gq45-2xpx-vvv2", + "modified": "2024-10-16T15:32:07Z", + "published": "2024-10-16T15:32:07Z", + "aliases": [ + "CVE-2024-22033" + ], + "details": "The OBS service obs-service-download_url was vulnerable to a command injection vulnerability. The attacker could provide a configuration to the service that allowed to execute command in later steps", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22033" + }, + { + "type": "WEB", + "url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2024-22033" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T14:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-h9vw-g3h9-6jvw/GHSA-h9vw-g3h9-6jvw.json b/advisories/unreviewed/2024/10/GHSA-h9vw-g3h9-6jvw/GHSA-h9vw-g3h9-6jvw.json new file mode 100644 index 00000000000..3f0b2bee925 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-h9vw-g3h9-6jvw/GHSA-h9vw-g3h9-6jvw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h9vw-g3h9-6jvw", + "modified": "2024-10-16T15:32:07Z", + "published": "2024-10-16T15:32:07Z", + "aliases": [ + "CVE-2024-48042" + ], + "details": "Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Supsystic Contact Form by Supsystic allows Command Injection.This issue affects Contact Form by Supsystic: from n/a through 1.7.28.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48042" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/contact-form-by-supsystic/wordpress-contact-form-by-supsystic-plugin-1-7-28-remote-code-execution-rce-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1336" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T13:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-j6vx-9w7x-j8g7/GHSA-j6vx-9w7x-j8g7.json b/advisories/unreviewed/2024/10/GHSA-j6vx-9w7x-j8g7/GHSA-j6vx-9w7x-j8g7.json new file mode 100644 index 00000000000..cff2bd72b55 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-j6vx-9w7x-j8g7/GHSA-j6vx-9w7x-j8g7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6vx-9w7x-j8g7", + "modified": "2024-10-16T15:32:07Z", + "published": "2024-10-16T15:32:07Z", + "aliases": [ + "CVE-2024-48029" + ], + "details": ": Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Hung Trang Si SB Random Posts Widget allows PHP Local File Inclusion.This issue affects SB Random Posts Widget: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48029" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/sb-random-posts-widget/wordpress-sb-random-posts-widget-plugin-1-0-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T14:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-mh59-qf67-hhp9/GHSA-mh59-qf67-hhp9.json b/advisories/unreviewed/2024/10/GHSA-mh59-qf67-hhp9/GHSA-mh59-qf67-hhp9.json new file mode 100644 index 00000000000..3a41e2cef0c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-mh59-qf67-hhp9/GHSA-mh59-qf67-hhp9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mh59-qf67-hhp9", + "modified": "2024-10-16T15:32:07Z", + "published": "2024-10-16T15:32:07Z", + "aliases": [ + "CVE-2024-49218" + ], + "details": "Deserialization of Untrusted Data vulnerability in Al Imran Akash Recently allows Object Injection.This issue affects Recently: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49218" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/recently-viewed-most-viewed-and-sold-products-for-woocommerce/wordpress-recently-plugin-1-1-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-mhrc-c9xr-f633/GHSA-mhrc-c9xr-f633.json b/advisories/unreviewed/2024/10/GHSA-mhrc-c9xr-f633/GHSA-mhrc-c9xr-f633.json new file mode 100644 index 00000000000..1e9696591b4 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-mhrc-c9xr-f633/GHSA-mhrc-c9xr-f633.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mhrc-c9xr-f633", + "modified": "2024-10-16T15:32:08Z", + "published": "2024-10-16T15:32:08Z", + "aliases": [ + "CVE-2024-47139" + ], + "details": "A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IQ Configuration utility that allows an attacker with the Administrator role to run JavaScript in the context of the currently logged-in user.\n\n \n\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47139" + }, + { + "type": "WEB", + "url": "https://my.f5.com/manage/s/article/K000141080" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-80" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-mwp6-vpg9-65vj/GHSA-mwp6-vpg9-65vj.json b/advisories/unreviewed/2024/10/GHSA-mwp6-vpg9-65vj/GHSA-mwp6-vpg9-65vj.json new file mode 100644 index 00000000000..afae14908e8 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-mwp6-vpg9-65vj/GHSA-mwp6-vpg9-65vj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mwp6-vpg9-65vj", + "modified": "2024-10-16T15:32:07Z", + "published": "2024-10-16T15:32:07Z", + "aliases": [ + "CVE-2024-49257" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Denis Azz Anonim Posting allows Upload a Web Shell to a Web Server.This issue affects Azz Anonim Posting: from n/a through 0.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49257" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/azz-anonim-posting/wordpress-azz-anonim-posting-plugin-0-9-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T13:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-mwpp-f4jm-gfhf/GHSA-mwpp-f4jm-gfhf.json b/advisories/unreviewed/2024/10/GHSA-mwpp-f4jm-gfhf/GHSA-mwpp-f4jm-gfhf.json new file mode 100644 index 00000000000..8b280757823 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-mwpp-f4jm-gfhf/GHSA-mwpp-f4jm-gfhf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mwpp-f4jm-gfhf", + "modified": "2024-10-16T15:32:07Z", + "published": "2024-10-16T15:32:07Z", + "aliases": [ + "CVE-2024-49227" + ], + "details": "Deserialization of Untrusted Data vulnerability in Innovaweb Sp. Z o.O. Free Stock Photos Foter allows Object Injection.This issue affects Free Stock Photos Foter: from n/a through 1.5.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49227" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/free-stock-photos-foter/wordpress-free-stock-photos-foter-plugin-1-5-4-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-q468-r36f-2v9x/GHSA-q468-r36f-2v9x.json b/advisories/unreviewed/2024/10/GHSA-q468-r36f-2v9x/GHSA-q468-r36f-2v9x.json new file mode 100644 index 00000000000..af9f5b030c5 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-q468-r36f-2v9x/GHSA-q468-r36f-2v9x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q468-r36f-2v9x", + "modified": "2024-10-16T15:32:07Z", + "published": "2024-10-16T15:32:07Z", + "aliases": [ + "CVE-2024-49245" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ahime Ahime Image Printer.This issue affects Ahime Image Printer: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49245" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ahime-image-printer/wordpress-ahime-image-printer-plugin-1-0-0-arbitrary-file-download-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T14:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-q7q9-7mhx-gjww/GHSA-q7q9-7mhx-gjww.json b/advisories/unreviewed/2024/10/GHSA-q7q9-7mhx-gjww/GHSA-q7q9-7mhx-gjww.json new file mode 100644 index 00000000000..e4dce0b94bf --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-q7q9-7mhx-gjww/GHSA-q7q9-7mhx-gjww.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q7q9-7mhx-gjww", + "modified": "2024-10-16T15:32:07Z", + "published": "2024-10-16T15:32:07Z", + "aliases": [ + "CVE-2024-49252" + ], + "details": ": Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Teplitsa of social technologies Leyka.This issue affects Leyka: from n/a through 3.31.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49252" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/leyka/wordpress-leyka-plugin-3-31-6-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T14:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-r4mm-h2x4-63w3/GHSA-r4mm-h2x4-63w3.json b/advisories/unreviewed/2024/10/GHSA-r4mm-h2x4-63w3/GHSA-r4mm-h2x4-63w3.json new file mode 100644 index 00000000000..e89c9ae3de3 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-r4mm-h2x4-63w3/GHSA-r4mm-h2x4-63w3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r4mm-h2x4-63w3", + "modified": "2024-10-16T15:32:08Z", + "published": "2024-10-16T15:32:08Z", + "aliases": [ + "CVE-2024-49260" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Limb WordPress Gallery Plugin – Limb Image Gallery allows Code Injection.This issue affects WordPress Gallery Plugin – Limb Image Gallery: from n/a through 1.5.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49260" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/limb-gallery/wordpress-limb-gallery-plugin-1-5-7-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-rwrg-crcp-fr3p/GHSA-rwrg-crcp-fr3p.json b/advisories/unreviewed/2024/10/GHSA-rwrg-crcp-fr3p/GHSA-rwrg-crcp-fr3p.json new file mode 100644 index 00000000000..6c04a0051ec --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-rwrg-crcp-fr3p/GHSA-rwrg-crcp-fr3p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rwrg-crcp-fr3p", + "modified": "2024-10-16T15:32:07Z", + "published": "2024-10-16T15:32:07Z", + "aliases": [ + "CVE-2024-49251" + ], + "details": ": Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Maantheme Maan Addons For Elementor allows Local Code Inclusion.This issue affects Maan Addons For Elementor: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49251" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/maan-elementor-addons/wordpress-maan-addons-for-elementor-plugin-1-0-1-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T14:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-v65q-q3ch-5jrg/GHSA-v65q-q3ch-5jrg.json b/advisories/unreviewed/2024/10/GHSA-v65q-q3ch-5jrg/GHSA-v65q-q3ch-5jrg.json index 34e14ae720d..9a4c97bab24 100644 --- a/advisories/unreviewed/2024/10/GHSA-v65q-q3ch-5jrg/GHSA-v65q-q3ch-5jrg.json +++ b/advisories/unreviewed/2024/10/GHSA-v65q-q3ch-5jrg/GHSA-v65q-q3ch-5jrg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v65q-q3ch-5jrg", - "modified": "2024-10-02T18:31:32Z", + "modified": "2024-10-16T15:32:06Z", "published": "2024-10-02T18:31:32Z", "aliases": [ "CVE-2024-33209" ], "details": "FlatPress v1.3 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into the \"Add New Entry\" section, which allows them to execute arbitrary code in the context of a victim's web browser.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-02T16:15:10Z" diff --git a/advisories/unreviewed/2024/10/GHSA-v727-c3qh-388m/GHSA-v727-c3qh-388m.json b/advisories/unreviewed/2024/10/GHSA-v727-c3qh-388m/GHSA-v727-c3qh-388m.json new file mode 100644 index 00000000000..513d9e5f944 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-v727-c3qh-388m/GHSA-v727-c3qh-388m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v727-c3qh-388m", + "modified": "2024-10-16T15:32:08Z", + "published": "2024-10-16T15:32:08Z", + "aliases": [ + "CVE-2024-49268" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in sunburntkamel disconnected allows Reflected XSS.This issue affects disconnected: from n/a through 1.3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49268" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/disconnected/wordpress-disconnected-theme-1-3-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-v7q3-h4r2-3g3j/GHSA-v7q3-h4r2-3g3j.json b/advisories/unreviewed/2024/10/GHSA-v7q3-h4r2-3g3j/GHSA-v7q3-h4r2-3g3j.json index e319c2042b0..e9c0773166d 100644 --- a/advisories/unreviewed/2024/10/GHSA-v7q3-h4r2-3g3j/GHSA-v7q3-h4r2-3g3j.json +++ b/advisories/unreviewed/2024/10/GHSA-v7q3-h4r2-3g3j/GHSA-v7q3-h4r2-3g3j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v7q3-h4r2-3g3j", - "modified": "2024-10-14T15:30:45Z", + "modified": "2024-10-16T15:32:06Z", "published": "2024-10-14T15:30:45Z", "aliases": [ "CVE-2024-48255" ], "details": "Cloudlog 2.6.15 allows Oqrs.php get_station_info station_id SQL injection.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-14T14:15:11Z" diff --git a/advisories/unreviewed/2024/10/GHSA-vx6r-82hr-hr24/GHSA-vx6r-82hr-hr24.json b/advisories/unreviewed/2024/10/GHSA-vx6r-82hr-hr24/GHSA-vx6r-82hr-hr24.json index 6651eb0d035..d701bc612ff 100644 --- a/advisories/unreviewed/2024/10/GHSA-vx6r-82hr-hr24/GHSA-vx6r-82hr-hr24.json +++ b/advisories/unreviewed/2024/10/GHSA-vx6r-82hr-hr24/GHSA-vx6r-82hr-hr24.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vx6r-82hr-hr24", - "modified": "2024-10-04T15:31:20Z", + "modified": "2024-10-16T15:32:06Z", "published": "2024-10-04T15:31:20Z", "aliases": [ "CVE-2024-47652" ], "details": "This vulnerability exists in Shilpi Client Dashboard due to implementation of inadequate authentication mechanism in the login module wherein access to any users account is granted with just their corresponding mobile number. A remote attacker could exploit this vulnerability by providing mobile number of targeted user, to obtain complete access to the targeted user account.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/10/GHSA-w2mv-76hq-6267/GHSA-w2mv-76hq-6267.json b/advisories/unreviewed/2024/10/GHSA-w2mv-76hq-6267/GHSA-w2mv-76hq-6267.json new file mode 100644 index 00000000000..90ab246d185 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-w2mv-76hq-6267/GHSA-w2mv-76hq-6267.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w2mv-76hq-6267", + "modified": "2024-10-16T15:32:08Z", + "published": "2024-10-16T15:32:08Z", + "aliases": [ + "CVE-2024-49270" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in HashThemes Smart Blocks allows Stored XSS.This issue affects Smart Blocks: from n/a through 2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49270" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/smart-blocks/wordpress-smart-blocks-plugin-2-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-w6jf-24wj-w8xx/GHSA-w6jf-24wj-w8xx.json b/advisories/unreviewed/2024/10/GHSA-w6jf-24wj-w8xx/GHSA-w6jf-24wj-w8xx.json new file mode 100644 index 00000000000..6009f7c8e73 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-w6jf-24wj-w8xx/GHSA-w6jf-24wj-w8xx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w6jf-24wj-w8xx", + "modified": "2024-10-16T15:32:08Z", + "published": "2024-10-16T15:32:08Z", + "aliases": [ + "CVE-2024-49253" + ], + "details": "Relative Path Traversal vulnerability in James Park Analyse Uploads allows Relative Path Traversal.This issue affects Analyse Uploads: from n/a through 0.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49253" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/analyse-uploads/wordpress-analyse-uploads-plugin-0-5-arbitrary-file-deletion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-23" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T14:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-w8vw-x82m-vg68/GHSA-w8vw-x82m-vg68.json b/advisories/unreviewed/2024/10/GHSA-w8vw-x82m-vg68/GHSA-w8vw-x82m-vg68.json new file mode 100644 index 00000000000..f88f7e0492e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-w8vw-x82m-vg68/GHSA-w8vw-x82m-vg68.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w8vw-x82m-vg68", + "modified": "2024-10-16T15:32:07Z", + "published": "2024-10-16T15:32:07Z", + "aliases": [ + "CVE-2024-22029" + ], + "details": "Insecure permissions in the packaging of tomcat allow local users that win a race during package installation to escalate to root", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22029" + }, + { + "type": "WEB", + "url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2024-22029" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T14:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-w94f-hwr2-wfp4/GHSA-w94f-hwr2-wfp4.json b/advisories/unreviewed/2024/10/GHSA-w94f-hwr2-wfp4/GHSA-w94f-hwr2-wfp4.json new file mode 100644 index 00000000000..e847926a313 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-w94f-hwr2-wfp4/GHSA-w94f-hwr2-wfp4.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w94f-hwr2-wfp4", + "modified": "2024-10-16T15:32:08Z", + "published": "2024-10-16T15:32:08Z", + "aliases": [ + "CVE-2024-9893" + ], + "details": "The Nextend Social Login Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.1.14. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email and the user does not have an already-existing account for the service returning the token.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9893" + }, + { + "type": "WEB", + "url": "https://nextendweb.com/social-login" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/nextend-facebook-connect/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0e4588d1-f21e-48ba-a8cb-d18c421f000a?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-whhf-w6qf-q77v/GHSA-whhf-w6qf-q77v.json b/advisories/unreviewed/2024/10/GHSA-whhf-w6qf-q77v/GHSA-whhf-w6qf-q77v.json new file mode 100644 index 00000000000..89aef8b4258 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-whhf-w6qf-q77v/GHSA-whhf-w6qf-q77v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-whhf-w6qf-q77v", + "modified": "2024-10-16T15:32:07Z", + "published": "2024-10-16T15:32:07Z", + "aliases": [ + "CVE-2024-49226" + ], + "details": "Deserialization of Untrusted Data vulnerability in TAKETIN TAKETIN To WP Membership allows Object Injection.This issue affects TAKETIN To WP Membership: from n/a through 2.8.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49226" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/taketin-to-wp-membership/wordpress-taketin-to-wp-membership-plugin-2-8-0-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-x279-24jv-7gr3/GHSA-x279-24jv-7gr3.json b/advisories/unreviewed/2024/10/GHSA-x279-24jv-7gr3/GHSA-x279-24jv-7gr3.json new file mode 100644 index 00000000000..9b1b70a5346 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-x279-24jv-7gr3/GHSA-x279-24jv-7gr3.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x279-24jv-7gr3", + "modified": "2024-10-16T15:32:07Z", + "published": "2024-10-16T15:32:07Z", + "aliases": [ + "CVE-2020-36841" + ], + "details": "The WooCommerce Smart Coupons plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the woocommerce_coupon_admin_init function in versions up to, and including, 4.6.0. This makes it possible for unauthenticated attackers to send themselves gift certificates of any value, which could be redeemed for products sold on the victim’s storefront.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-36841" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/blog/2020/03/coupon-creation-vulnerability-patched-in-woocommerce-smart-coupons" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/eeeb03f7-5f78-4462-b0b4-5080bbc419a3?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T13:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-x6x8-x7qh-52jw/GHSA-x6x8-x7qh-52jw.json b/advisories/unreviewed/2024/10/GHSA-x6x8-x7qh-52jw/GHSA-x6x8-x7qh-52jw.json new file mode 100644 index 00000000000..08f3f76a49c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-x6x8-x7qh-52jw/GHSA-x6x8-x7qh-52jw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x6x8-x7qh-52jw", + "modified": "2024-10-16T15:32:08Z", + "published": "2024-10-16T15:32:08Z", + "aliases": [ + "CVE-2024-9348" + ], + "details": "Docker Desktop before v4.34.3 allows RCE via unsanitized GitHub source link in Build view.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9348" + }, + { + "type": "WEB", + "url": "https://docs.docker.com/desktop/release-notes/#4343" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-xc28-gw78-r3rv/GHSA-xc28-gw78-r3rv.json b/advisories/unreviewed/2024/10/GHSA-xc28-gw78-r3rv/GHSA-xc28-gw78-r3rv.json new file mode 100644 index 00000000000..fd32c75bfc5 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-xc28-gw78-r3rv/GHSA-xc28-gw78-r3rv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xc28-gw78-r3rv", + "modified": "2024-10-16T15:32:07Z", + "published": "2024-10-16T15:32:07Z", + "aliases": [ + "CVE-2024-47637" + ], + "details": ": Relative Path Traversal vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Path Traversal.This issue affects LiteSpeed Cache: from n/a through 6.4.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47637" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/litespeed-cache/wordpress-litespeed-cache-plugin-6-4-1-path-traversal-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-23" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T14:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-xfh8-7hcx-ppfp/GHSA-xfh8-7hcx-ppfp.json b/advisories/unreviewed/2024/10/GHSA-xfh8-7hcx-ppfp/GHSA-xfh8-7hcx-ppfp.json index 8a137acb1b2..21bc11db698 100644 --- a/advisories/unreviewed/2024/10/GHSA-xfh8-7hcx-ppfp/GHSA-xfh8-7hcx-ppfp.json +++ b/advisories/unreviewed/2024/10/GHSA-xfh8-7hcx-ppfp/GHSA-xfh8-7hcx-ppfp.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xfh8-7hcx-ppfp", - "modified": "2024-10-04T15:31:21Z", + "modified": "2024-10-16T15:32:06Z", "published": "2024-10-04T15:31:21Z", "aliases": [ "CVE-2024-47655" ], "details": "This vulnerability exists in the Shilpi Client Dashboard due to improper validation of files being uploaded other than the specified extension. An authenticated remote attacker could exploit this vulnerability by uploading malicious file, which could lead to remote code execution on targeted application.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/10/GHSA-xm6p-38g9-7hh9/GHSA-xm6p-38g9-7hh9.json b/advisories/unreviewed/2024/10/GHSA-xm6p-38g9-7hh9/GHSA-xm6p-38g9-7hh9.json new file mode 100644 index 00000000000..33ab5b32c61 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-xm6p-38g9-7hh9/GHSA-xm6p-38g9-7hh9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xm6p-38g9-7hh9", + "modified": "2024-10-16T15:32:07Z", + "published": "2024-10-16T15:32:07Z", + "aliases": [ + "CVE-2024-47351" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The CSSIgniter Team MaxSlider allows Path Traversal.This issue affects MaxSlider: from n/a through 1.2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47351" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/maxslider/wordpress-maxslider-plugin-1-2-3-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T14:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-xm89-5c6f-pv99/GHSA-xm89-5c6f-pv99.json b/advisories/unreviewed/2024/10/GHSA-xm89-5c6f-pv99/GHSA-xm89-5c6f-pv99.json new file mode 100644 index 00000000000..3a64ce24a50 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-xm89-5c6f-pv99/GHSA-xm89-5c6f-pv99.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xm89-5c6f-pv99", + "modified": "2024-10-16T15:32:08Z", + "published": "2024-10-16T15:32:08Z", + "aliases": [ + "CVE-2024-49258" + ], + "details": "Path Traversal: '.../...//' vulnerability in Limb WordPress Gallery Plugin – Limb Image Gallery.This issue affects WordPress Gallery Plugin – Limb Image Gallery: from n/a through 1.5.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49258" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/limb-gallery/wordpress-limb-gallery-plugin-1-5-7-arbitrary-file-download-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-35" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T14:15:11Z" + } +} \ No newline at end of file