diff --git a/advisories/unreviewed/2024/10/GHSA-23cv-7mvx-jcq6/GHSA-23cv-7mvx-jcq6.json b/advisories/unreviewed/2024/10/GHSA-23cv-7mvx-jcq6/GHSA-23cv-7mvx-jcq6.json new file mode 100644 index 00000000000..22ce0b79b3f --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-23cv-7mvx-jcq6/GHSA-23cv-7mvx-jcq6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-23cv-7mvx-jcq6", + "modified": "2024-10-28T12:30:55Z", + "published": "2024-10-28T12:30:55Z", + "aliases": [ + "CVE-2024-50489" + ], + "details": "Authentication Bypass Using an Alternate Path or Channel vulnerability in Realty Workstation allows Authentication Bypass.This issue affects Realty Workstation: from n/a through 1.0.45.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50489" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/realty-workstation/wordpress-realty-workstation-plugin-1-0-45-account-takeover-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-28T12:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-266v-q3gx-4vx4/GHSA-266v-q3gx-4vx4.json b/advisories/unreviewed/2024/10/GHSA-266v-q3gx-4vx4/GHSA-266v-q3gx-4vx4.json new file mode 100644 index 00000000000..250e9f86f33 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-266v-q3gx-4vx4/GHSA-266v-q3gx-4vx4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-266v-q3gx-4vx4", + "modified": "2024-10-28T12:30:55Z", + "published": "2024-10-28T12:30:55Z", + "aliases": [ + "CVE-2024-50487" + ], + "details": "Authentication Bypass Using an Alternate Path or Channel vulnerability in MaanTheme MaanStore API allows Authentication Bypass.This issue affects MaanStore API: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50487" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/maanstore-api/wordpress-maanstore-api-plugin-1-0-1-account-takeover-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-28T12:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-2wqh-23wf-9qr9/GHSA-2wqh-23wf-9qr9.json b/advisories/unreviewed/2024/10/GHSA-2wqh-23wf-9qr9/GHSA-2wqh-23wf-9qr9.json new file mode 100644 index 00000000000..cbe7d02c66c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-2wqh-23wf-9qr9/GHSA-2wqh-23wf-9qr9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2wqh-23wf-9qr9", + "modified": "2024-10-28T12:30:54Z", + "published": "2024-10-28T12:30:54Z", + "aliases": [ + "CVE-2024-50416" + ], + "details": "Deserialization of Untrusted Data vulnerability in WPClever WPC Shop as a Customer for WooCommerce allows Object Injection.This issue affects WPC Shop as a Customer for WooCommerce: from n/a through 1.2.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50416" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wpc-shop-as-customer/wordpress-wpc-shop-as-a-customer-for-woocommerce-plugin-1-2-6-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-28T12:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-36p8-9jxx-p4v9/GHSA-36p8-9jxx-p4v9.json b/advisories/unreviewed/2024/10/GHSA-36p8-9jxx-p4v9/GHSA-36p8-9jxx-p4v9.json new file mode 100644 index 00000000000..82d3a70202c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-36p8-9jxx-p4v9/GHSA-36p8-9jxx-p4v9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-36p8-9jxx-p4v9", + "modified": "2024-10-28T12:30:55Z", + "published": "2024-10-28T12:30:55Z", + "aliases": [ + "CVE-2024-50498" + ], + "details": "Improper Control of Generation of Code ('Code Injection') vulnerability in LUBUS WP Query Console allows Code Injection.This issue affects WP Query Console: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50498" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-query-console/wordpress-wp-query-console-plugin-1-0-remote-code-execution-rce-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-28T12:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-3p7m-4mc5-m3g5/GHSA-3p7m-4mc5-m3g5.json b/advisories/unreviewed/2024/10/GHSA-3p7m-4mc5-m3g5/GHSA-3p7m-4mc5-m3g5.json new file mode 100644 index 00000000000..9abaf978649 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-3p7m-4mc5-m3g5/GHSA-3p7m-4mc5-m3g5.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3p7m-4mc5-m3g5", + "modified": "2024-10-28T12:30:54Z", + "published": "2024-10-28T12:30:54Z", + "aliases": [ + "CVE-2024-10446" + ], + "details": "A vulnerability classified as critical has been found in Project Worlds Online Time Table Generator 1.0. Affected is an unknown function of the file /timetable/admin/admindashboard.php?info=add_course. The manipulation of the argument c leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10446" + }, + { + "type": "WEB", + "url": "https://github.com/jadu101/CVE/blob/main/project_worlds_online_time_table_generator_add_department_sqli.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.282006" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.282006" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.432371" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-28T12:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-5q53-766v-93h8/GHSA-5q53-766v-93h8.json b/advisories/unreviewed/2024/10/GHSA-5q53-766v-93h8/GHSA-5q53-766v-93h8.json new file mode 100644 index 00000000000..303c9dccfba --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-5q53-766v-93h8/GHSA-5q53-766v-93h8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5q53-766v-93h8", + "modified": "2024-10-28T12:30:55Z", + "published": "2024-10-28T12:30:54Z", + "aliases": [ + "CVE-2024-50477" + ], + "details": "Authentication Bypass Using an Alternate Path or Channel vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Authentication Bypass.This issue affects Stacks Mobile App Builder: from n/a through 5.2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50477" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/stacks-mobile-app-builder/wordpress-stacks-mobile-app-builder-plugin-5-2-3-account-takeover-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-28T12:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-c2j6-7h49-7vrf/GHSA-c2j6-7h49-7vrf.json b/advisories/unreviewed/2024/10/GHSA-c2j6-7h49-7vrf/GHSA-c2j6-7h49-7vrf.json new file mode 100644 index 00000000000..6392de6e03d --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-c2j6-7h49-7vrf/GHSA-c2j6-7h49-7vrf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c2j6-7h49-7vrf", + "modified": "2024-10-28T12:30:54Z", + "published": "2024-10-28T12:30:54Z", + "aliases": [ + "CVE-2024-50408" + ], + "details": "Deserialization of Untrusted Data vulnerability in Kiboko Labs Namaste! LMS allows Object Injection.This issue affects Namaste! LMS: from n/a through 2.6.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50408" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/namaste-lms/wordpress-namaste-lms-plugin-2-6-3-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-28T12:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-c8pf-2pv8-v359/GHSA-c8pf-2pv8-v359.json b/advisories/unreviewed/2024/10/GHSA-c8pf-2pv8-v359/GHSA-c8pf-2pv8-v359.json new file mode 100644 index 00000000000..5b1d8413266 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-c8pf-2pv8-v359/GHSA-c8pf-2pv8-v359.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c8pf-2pv8-v359", + "modified": "2024-10-28T12:30:54Z", + "published": "2024-10-28T12:30:54Z", + "aliases": [ + "CVE-2024-50450" + ], + "details": "Improper Control of Generation of Code ('Code Injection') vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF) allows Code Injection.This issue affects WordPress Meta Data and Taxonomies Filter (MDTF): from n/a through 1.3.3.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50450" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-meta-data-filter-and-taxonomy-filter/wordpress-mdtf-meta-data-and-taxonomies-filter-plugin-1-3-3-4-bypass-vulnerability-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-28T12:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-m3r3-r24f-8hj4/GHSA-m3r3-r24f-8hj4.json b/advisories/unreviewed/2024/10/GHSA-m3r3-r24f-8hj4/GHSA-m3r3-r24f-8hj4.json new file mode 100644 index 00000000000..39223efd7cf --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-m3r3-r24f-8hj4/GHSA-m3r3-r24f-8hj4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m3r3-r24f-8hj4", + "modified": "2024-10-28T12:30:55Z", + "published": "2024-10-28T12:30:55Z", + "aliases": [ + "CVE-2024-50492" + ], + "details": "Improper Control of Generation of Code ('Code Injection') vulnerability in Scott Paterson ScottCart allows Code Injection.This issue affects ScottCart: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50492" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/scottcart/wordpress-scottcart-plugin-1-1-remote-code-execution-rce-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-28T12:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-m4fc-wmq3-h3jq/GHSA-m4fc-wmq3-h3jq.json b/advisories/unreviewed/2024/10/GHSA-m4fc-wmq3-h3jq/GHSA-m4fc-wmq3-h3jq.json new file mode 100644 index 00000000000..ab0387c7d9b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-m4fc-wmq3-h3jq/GHSA-m4fc-wmq3-h3jq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m4fc-wmq3-h3jq", + "modified": "2024-10-28T12:30:55Z", + "published": "2024-10-28T12:30:54Z", + "aliases": [ + "CVE-2024-50486" + ], + "details": "Authentication Bypass Using an Alternate Path or Channel vulnerability in Acnoo Acnoo Flutter API allows Authentication Bypass.This issue affects Acnoo Flutter API: from n/a through 1.0.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50486" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/acnoo-flutter-api/wordpress-acnoo-flutter-api-plugin-1-0-5-account-takeover-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-28T12:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-pf54-3ggm-97rv/GHSA-pf54-3ggm-97rv.json b/advisories/unreviewed/2024/10/GHSA-pf54-3ggm-97rv/GHSA-pf54-3ggm-97rv.json new file mode 100644 index 00000000000..ec8fe9871a8 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-pf54-3ggm-97rv/GHSA-pf54-3ggm-97rv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pf54-3ggm-97rv", + "modified": "2024-10-28T12:30:54Z", + "published": "2024-10-28T12:30:54Z", + "aliases": [ + "CVE-2024-50442" + ], + "details": "Improper Restriction of XML External Entity Reference vulnerability in WP Royal Royal Elementor Addons allows XML Injection.This issue affects Royal Elementor Addons: from n/a through 1.3.980.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50442" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/royal-elementor-addons/wordpress-royal-elementor-addons-and-templates-plugin-1-3-980-xml-external-entity-xxe-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-611" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-28T12:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-xv9c-x9pp-8xwg/GHSA-xv9c-x9pp-8xwg.json b/advisories/unreviewed/2024/10/GHSA-xv9c-x9pp-8xwg/GHSA-xv9c-x9pp-8xwg.json new file mode 100644 index 00000000000..ed8c376f664 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-xv9c-x9pp-8xwg/GHSA-xv9c-x9pp-8xwg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xv9c-x9pp-8xwg", + "modified": "2024-10-28T12:30:54Z", + "published": "2024-10-28T12:30:54Z", + "aliases": [ + "CVE-2024-48074" + ], + "details": "An authorized RCE vulnerability exists in the DrayTek Vigor2960 router version 1.4.4, where an attacker can place a malicious command into the table parameter of the doPPPoE function in the cgi-bin/mainfunction.cgi route, and finally the command is executed by the system function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48074" + }, + { + "type": "WEB", + "url": "https://github.com/Giles-one/Vigor2960Crack" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-28T12:15:15Z" + } +} \ No newline at end of file