diff --git a/advisories/unreviewed/2024/06/GHSA-2frj-77vm-453x/GHSA-2frj-77vm-453x.json b/advisories/unreviewed/2024/06/GHSA-2frj-77vm-453x/GHSA-2frj-77vm-453x.json new file mode 100644 index 00000000000..70cef9970cb --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-2frj-77vm-453x/GHSA-2frj-77vm-453x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2frj-77vm-453x", + "modified": "2024-06-19T12:31:21Z", + "published": "2024-06-19T12:31:21Z", + "aliases": [ + "CVE-2024-35765" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wpsoul Greenshift – animation and page builder blocks allows Stored XSS.This issue affects Greenshift – animation and page builder blocks: from n/a through 8.8.9.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35765" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/greenshift-animation-and-page-builder-blocks/wordpress-greenshift-animation-and-page-builder-blocks-plugin-8-8-9-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-19T11:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-2x75-49mf-q8jq/GHSA-2x75-49mf-q8jq.json b/advisories/unreviewed/2024/06/GHSA-2x75-49mf-q8jq/GHSA-2x75-49mf-q8jq.json new file mode 100644 index 00000000000..6364acdd5fb --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-2x75-49mf-q8jq/GHSA-2x75-49mf-q8jq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2x75-49mf-q8jq", + "modified": "2024-06-19T12:31:21Z", + "published": "2024-06-19T12:31:21Z", + "aliases": [ + "CVE-2023-44151" + ], + "details": "Missing Authorization vulnerability in Brainstorm Force Pre-Publish Checklist.This issue affects Pre-Publish Checklist: from n/a through 1.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-44151" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/pre-publish-checklist/wordpress-pre-publish-checklist-plugin-1-1-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-19T12:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-3fxj-qpxv-j6qj/GHSA-3fxj-qpxv-j6qj.json b/advisories/unreviewed/2024/06/GHSA-3fxj-qpxv-j6qj/GHSA-3fxj-qpxv-j6qj.json index 222df488cfc..8ebaed086dc 100644 --- a/advisories/unreviewed/2024/06/GHSA-3fxj-qpxv-j6qj/GHSA-3fxj-qpxv-j6qj.json +++ b/advisories/unreviewed/2024/06/GHSA-3fxj-qpxv-j6qj/GHSA-3fxj-qpxv-j6qj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3fxj-qpxv-j6qj", - "modified": "2024-06-14T00:33:06Z", + "modified": "2024-06-19T12:31:21Z", "published": "2024-06-11T15:31:13Z", "aliases": [ "CVE-2024-5690" @@ -26,6 +26,10 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00000.html" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00010.html" + }, { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-25" diff --git a/advisories/unreviewed/2024/06/GHSA-3mcj-h4q6-5xgm/GHSA-3mcj-h4q6-5xgm.json b/advisories/unreviewed/2024/06/GHSA-3mcj-h4q6-5xgm/GHSA-3mcj-h4q6-5xgm.json new file mode 100644 index 00000000000..ef38339c58b --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-3mcj-h4q6-5xgm/GHSA-3mcj-h4q6-5xgm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3mcj-h4q6-5xgm", + "modified": "2024-06-19T12:31:21Z", + "published": "2024-06-19T12:31:21Z", + "aliases": [ + "CVE-2023-44148" + ], + "details": "Missing Authorization vulnerability in Brainstorm Force Astra Bulk Edit.This issue affects Astra Bulk Edit: from n/a through 1.2.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-44148" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/astra-bulk-edit/wordpress-astra-bulk-edit-plugin-1-2-7-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-19T12:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-4hpx-ff68-4g35/GHSA-4hpx-ff68-4g35.json b/advisories/unreviewed/2024/06/GHSA-4hpx-ff68-4g35/GHSA-4hpx-ff68-4g35.json new file mode 100644 index 00000000000..aaec231ad05 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-4hpx-ff68-4g35/GHSA-4hpx-ff68-4g35.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4hpx-ff68-4g35", + "modified": "2024-06-19T12:31:21Z", + "published": "2024-06-19T12:31:21Z", + "aliases": [ + "CVE-2023-45658" + ], + "details": "Missing Authorization vulnerability in POSIMYTH Nexter.This issue affects Nexter: from n/a through 2.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45658" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/nexter/wordpress-nexter-theme-2-0-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-19T12:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-4rwm-74mf-prpv/GHSA-4rwm-74mf-prpv.json b/advisories/unreviewed/2024/06/GHSA-4rwm-74mf-prpv/GHSA-4rwm-74mf-prpv.json new file mode 100644 index 00000000000..dd251bc4c09 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-4rwm-74mf-prpv/GHSA-4rwm-74mf-prpv.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4rwm-74mf-prpv", + "modified": "2024-06-19T12:31:21Z", + "published": "2024-06-19T12:31:21Z", + "aliases": [ + "CVE-2023-40004" + ], + "details": "Missing Authorization vulnerability in ServMask All-in-One WP Migration Box Extension, ServMask All-in-One WP Migration OneDrive Extension, ServMask All-in-One WP Migration Dropbox Extension, ServMask All-in-One WP Migration Google Drive Extension.This issue affects All-in-One WP Migration Box Extension: from n/a through 1.53; All-in-One WP Migration OneDrive Extension: from n/a through 1.66; All-in-One WP Migration Dropbox Extension: from n/a through 3.75; All-in-One WP Migration Google Drive Extension: from n/a through 2.79.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40004" + }, + { + "type": "WEB", + "url": "https://patchstack.com/articles/pre-auth-access-token-manipulation-in-all-in-one-wp-migration-extensions?_s_id=cve" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/all-in-one-wp-migration-box-extension/wordpress-all-in-one-wp-migration-box-extension-plugin-1-53-unauthenticated-access-token-manipulation-vulnerability?_s_id=cve" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/all-in-one-wp-migration-dropbox-extension/wordpress-all-in-one-wp-migration-dropbox-extension-plugin-3-75-unauthenticated-access-token-manipulation-vulnerability?_s_id=cve" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/all-in-one-wp-migration-gdrive-extension/wordpress-all-in-one-wp-migration-google-drive-extension-plugin-2-79-unauthenticated-access-token-manipulation-vulnerability?_s_id=cve" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/all-in-one-wp-migration-onedrive-extension/wordpress-all-in-one-wp-migration-onedrive-extension-plugin-1-66-unauthenticated-access-token-manipulation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-19T12:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-8hm5-5jvw-x4w5/GHSA-8hm5-5jvw-x4w5.json b/advisories/unreviewed/2024/06/GHSA-8hm5-5jvw-x4w5/GHSA-8hm5-5jvw-x4w5.json new file mode 100644 index 00000000000..b58930bfadd --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-8hm5-5jvw-x4w5/GHSA-8hm5-5jvw-x4w5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8hm5-5jvw-x4w5", + "modified": "2024-06-19T12:31:22Z", + "published": "2024-06-19T12:31:21Z", + "aliases": [ + "CVE-2023-47681" + ], + "details": "Missing Authorization vulnerability in QuadLayers WooCommerce Checkout Manager.This issue affects WooCommerce Checkout Manager: from n/a through 7.3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47681" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/woocommerce-checkout-manager/wordpress-woocommerce-checkout-manager-plugin-7-3-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-19T12:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-96f7-v5h7-xq9g/GHSA-96f7-v5h7-xq9g.json b/advisories/unreviewed/2024/06/GHSA-96f7-v5h7-xq9g/GHSA-96f7-v5h7-xq9g.json new file mode 100644 index 00000000000..b534ce71f4e --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-96f7-v5h7-xq9g/GHSA-96f7-v5h7-xq9g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-96f7-v5h7-xq9g", + "modified": "2024-06-19T12:31:21Z", + "published": "2024-06-19T12:31:21Z", + "aliases": [ + "CVE-2023-50900" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Averta Master Slider.This issue affects Master Slider: from n/a through 3.9.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50900" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/master-slider/wordpress-master-slider-plugin-3-9-10-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-19T10:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-cvh2-grpw-4xrw/GHSA-cvh2-grpw-4xrw.json b/advisories/unreviewed/2024/06/GHSA-cvh2-grpw-4xrw/GHSA-cvh2-grpw-4xrw.json new file mode 100644 index 00000000000..09119f27076 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-cvh2-grpw-4xrw/GHSA-cvh2-grpw-4xrw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cvh2-grpw-4xrw", + "modified": "2024-06-19T12:31:21Z", + "published": "2024-06-19T12:31:21Z", + "aliases": [ + "CVE-2023-48761" + ], + "details": "Missing Authorization vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.13.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48761" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/jet-elements/wordpress-jetelements-for-elementor-plugin-2-6-13-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-19T11:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-fcmg-g937-8wc8/GHSA-fcmg-g937-8wc8.json b/advisories/unreviewed/2024/06/GHSA-fcmg-g937-8wc8/GHSA-fcmg-g937-8wc8.json new file mode 100644 index 00000000000..59fe22628ec --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-fcmg-g937-8wc8/GHSA-fcmg-g937-8wc8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fcmg-g937-8wc8", + "modified": "2024-06-19T12:31:21Z", + "published": "2024-06-19T12:31:21Z", + "aliases": [ + "CVE-2023-47783" + ], + "details": "Missing Authorization vulnerability in Thrive Themes Thrive Theme Builder.This issue affects Thrive Theme Builder: from n/a before 3.24.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47783" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/thrive-theme/wordpress-thrive-theme-builder-theme-3-20-1-multiple-authenticated-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-19T11:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-g23m-h4v3-g2qq/GHSA-g23m-h4v3-g2qq.json b/advisories/unreviewed/2024/06/GHSA-g23m-h4v3-g2qq/GHSA-g23m-h4v3-g2qq.json index 486b451fef0..58a4b4770d5 100644 --- a/advisories/unreviewed/2024/06/GHSA-g23m-h4v3-g2qq/GHSA-g23m-h4v3-g2qq.json +++ b/advisories/unreviewed/2024/06/GHSA-g23m-h4v3-g2qq/GHSA-g23m-h4v3-g2qq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g23m-h4v3-g2qq", - "modified": "2024-06-14T00:33:06Z", + "modified": "2024-06-19T12:31:21Z", "published": "2024-06-11T15:31:13Z", "aliases": [ "CVE-2024-5688" @@ -26,6 +26,10 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00000.html" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00010.html" + }, { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-25" diff --git a/advisories/unreviewed/2024/06/GHSA-g4hp-vh46-5gw6/GHSA-g4hp-vh46-5gw6.json b/advisories/unreviewed/2024/06/GHSA-g4hp-vh46-5gw6/GHSA-g4hp-vh46-5gw6.json new file mode 100644 index 00000000000..215f89e88f9 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-g4hp-vh46-5gw6/GHSA-g4hp-vh46-5gw6.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g4hp-vh46-5gw6", + "modified": "2024-06-19T12:31:21Z", + "published": "2024-06-19T12:31:21Z", + "aliases": [ + "CVE-2024-5676" + ], + "details": "The Paradox IP150 Internet Module in version 1.40.00 is vulnerable to Cross-Site Request Forgery (CSRF) attacks due to a lack of countermeasures and the use of the HTTP method `GET` to introduce changes in the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5676" + }, + { + "type": "WEB", + "url": "https://github.com/sbaresearch/advisories/tree/public/2024/SBA-ADV-20240321-01_Paradox_Cross_Site_Request_Forgery" + }, + { + "type": "WEB", + "url": "https://www.paradox.com/Products/default.asp?CATID=3&SUBCATID=38&PRD=563" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-19T10:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-g5g4-3wq4-6784/GHSA-g5g4-3wq4-6784.json b/advisories/unreviewed/2024/06/GHSA-g5g4-3wq4-6784/GHSA-g5g4-3wq4-6784.json new file mode 100644 index 00000000000..99c8aabf0d1 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-g5g4-3wq4-6784/GHSA-g5g4-3wq4-6784.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g5g4-3wq4-6784", + "modified": "2024-06-19T12:31:21Z", + "published": "2024-06-19T12:31:21Z", + "aliases": [ + "CVE-2023-48760" + ], + "details": "Missing Authorization vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.13.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48760" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/jet-elements/wordpress-jetelements-for-elementor-plugin-2-6-13-unauthenticated-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-19T11:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-gc3q-f2fq-g2xq/GHSA-gc3q-f2fq-g2xq.json b/advisories/unreviewed/2024/06/GHSA-gc3q-f2fq-g2xq/GHSA-gc3q-f2fq-g2xq.json index 694deccaf5d..2905f668e9f 100644 --- a/advisories/unreviewed/2024/06/GHSA-gc3q-f2fq-g2xq/GHSA-gc3q-f2fq-g2xq.json +++ b/advisories/unreviewed/2024/06/GHSA-gc3q-f2fq-g2xq/GHSA-gc3q-f2fq-g2xq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gc3q-f2fq-g2xq", - "modified": "2024-06-14T00:33:06Z", + "modified": "2024-06-19T12:31:21Z", "published": "2024-06-11T15:31:14Z", "aliases": [ "CVE-2024-5702" @@ -26,6 +26,10 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00000.html" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00010.html" + }, { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-18" diff --git a/advisories/unreviewed/2024/06/GHSA-gmgg-93h8-cp32/GHSA-gmgg-93h8-cp32.json b/advisories/unreviewed/2024/06/GHSA-gmgg-93h8-cp32/GHSA-gmgg-93h8-cp32.json index 7dfa415cdf4..07355969791 100644 --- a/advisories/unreviewed/2024/06/GHSA-gmgg-93h8-cp32/GHSA-gmgg-93h8-cp32.json +++ b/advisories/unreviewed/2024/06/GHSA-gmgg-93h8-cp32/GHSA-gmgg-93h8-cp32.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gmgg-93h8-cp32", - "modified": "2024-06-14T00:33:06Z", + "modified": "2024-06-19T12:31:21Z", "published": "2024-06-11T15:31:14Z", "aliases": [ "CVE-2024-5696" @@ -26,6 +26,10 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00000.html" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00010.html" + }, { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-25" diff --git a/advisories/unreviewed/2024/06/GHSA-gqc7-6x42-qc68/GHSA-gqc7-6x42-qc68.json b/advisories/unreviewed/2024/06/GHSA-gqc7-6x42-qc68/GHSA-gqc7-6x42-qc68.json new file mode 100644 index 00000000000..a751fe59908 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-gqc7-6x42-qc68/GHSA-gqc7-6x42-qc68.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gqc7-6x42-qc68", + "modified": "2024-06-19T12:31:21Z", + "published": "2024-06-19T12:31:21Z", + "aliases": [ + "CVE-2023-48759" + ], + "details": "Missing Authorization vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.13.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48759" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/jet-elements/wordpress-jetelements-for-elementor-plugin-2-6-13-unauthenticated-arbitrary-attachment-download-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-19T11:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-h39g-8hj5-3r27/GHSA-h39g-8hj5-3r27.json b/advisories/unreviewed/2024/06/GHSA-h39g-8hj5-3r27/GHSA-h39g-8hj5-3r27.json new file mode 100644 index 00000000000..cdc0e04de2e --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-h39g-8hj5-3r27/GHSA-h39g-8hj5-3r27.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h39g-8hj5-3r27", + "modified": "2024-06-19T12:31:21Z", + "published": "2024-06-19T12:31:21Z", + "aliases": [ + "CVE-2023-47788" + ], + "details": "Missing Authorization vulnerability in Automattic Jetpack.This issue affects Jetpack: from n/a before 12.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47788" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/jetpack/wordpress-jetpack-plugin-12-7-contributor-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-19T11:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-j4qm-q589-994x/GHSA-j4qm-q589-994x.json b/advisories/unreviewed/2024/06/GHSA-j4qm-q589-994x/GHSA-j4qm-q589-994x.json new file mode 100644 index 00000000000..c33e38c89a7 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-j4qm-q589-994x/GHSA-j4qm-q589-994x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j4qm-q589-994x", + "modified": "2024-06-19T12:31:21Z", + "published": "2024-06-19T12:31:21Z", + "aliases": [ + "CVE-2023-46148" + ], + "details": "Missing Authorization vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46148" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/themify-ultra/wordpress-themify-ultra-theme-7-3-3-authenticated-arbitrary-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-19T12:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-j9cw-mqxj-rmxf/GHSA-j9cw-mqxj-rmxf.json b/advisories/unreviewed/2024/06/GHSA-j9cw-mqxj-rmxf/GHSA-j9cw-mqxj-rmxf.json new file mode 100644 index 00000000000..dcd11860e98 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-j9cw-mqxj-rmxf/GHSA-j9cw-mqxj-rmxf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j9cw-mqxj-rmxf", + "modified": "2024-06-19T12:31:21Z", + "published": "2024-06-19T12:31:21Z", + "aliases": [ + "CVE-2023-46146" + ], + "details": "Missing Authorization vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46146" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/themify-ultra/wordpress-themify-ultra-theme-7-3-3-multiple-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-19T12:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-m4wx-v2r3-84vx/GHSA-m4wx-v2r3-84vx.json b/advisories/unreviewed/2024/06/GHSA-m4wx-v2r3-84vx/GHSA-m4wx-v2r3-84vx.json new file mode 100644 index 00000000000..03b5a0db993 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-m4wx-v2r3-84vx/GHSA-m4wx-v2r3-84vx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m4wx-v2r3-84vx", + "modified": "2024-06-19T12:31:21Z", + "published": "2024-06-19T12:31:21Z", + "aliases": [ + "CVE-2023-40608" + ], + "details": "Missing Authorization vulnerability in Paid Memberships Pro Paid Memberships Pro CCBill Gateway.This issue affects Paid Memberships Pro CCBill Gateway: from n/a through 0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40608" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/pmpro-ccbill/wordpress-paid-memberships-pro-ccbill-gateway-plugin-0-3-unauthenticated-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-19T12:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-mm22-phj8-4fx9/GHSA-mm22-phj8-4fx9.json b/advisories/unreviewed/2024/06/GHSA-mm22-phj8-4fx9/GHSA-mm22-phj8-4fx9.json new file mode 100644 index 00000000000..eb5e471c56e --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-mm22-phj8-4fx9/GHSA-mm22-phj8-4fx9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mm22-phj8-4fx9", + "modified": "2024-06-19T12:31:21Z", + "published": "2024-06-19T12:31:21Z", + "aliases": [ + "CVE-2023-47771" + ], + "details": "Missing Authorization vulnerability in ThemePunch OHG Essential Grid.This issue affects Essential Grid: from n/a through 3.0.18.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47771" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/essential-grid/wordpress-essential-grid-plugin-3-0-18-multiple-authenticated-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-19T11:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-pq6v-hjqm-frww/GHSA-pq6v-hjqm-frww.json b/advisories/unreviewed/2024/06/GHSA-pq6v-hjqm-frww/GHSA-pq6v-hjqm-frww.json index 751d4ebb258..e5bddee5372 100644 --- a/advisories/unreviewed/2024/06/GHSA-pq6v-hjqm-frww/GHSA-pq6v-hjqm-frww.json +++ b/advisories/unreviewed/2024/06/GHSA-pq6v-hjqm-frww/GHSA-pq6v-hjqm-frww.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pq6v-hjqm-frww", - "modified": "2024-06-14T00:33:06Z", + "modified": "2024-06-19T12:31:21Z", "published": "2024-06-11T15:31:14Z", "aliases": [ "CVE-2024-5700" @@ -26,6 +26,10 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00000.html" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00010.html" + }, { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-25" diff --git a/advisories/unreviewed/2024/06/GHSA-pxf8-583j-3rmh/GHSA-pxf8-583j-3rmh.json b/advisories/unreviewed/2024/06/GHSA-pxf8-583j-3rmh/GHSA-pxf8-583j-3rmh.json index 6c37cd132e1..14d7bd55212 100644 --- a/advisories/unreviewed/2024/06/GHSA-pxf8-583j-3rmh/GHSA-pxf8-583j-3rmh.json +++ b/advisories/unreviewed/2024/06/GHSA-pxf8-583j-3rmh/GHSA-pxf8-583j-3rmh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pxf8-583j-3rmh", - "modified": "2024-06-14T00:33:06Z", + "modified": "2024-06-19T12:31:21Z", "published": "2024-06-11T15:31:13Z", "aliases": [ "CVE-2024-5693" @@ -26,6 +26,10 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00000.html" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00010.html" + }, { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-25" diff --git a/advisories/unreviewed/2024/06/GHSA-qhv7-vr66-j5ff/GHSA-qhv7-vr66-j5ff.json b/advisories/unreviewed/2024/06/GHSA-qhv7-vr66-j5ff/GHSA-qhv7-vr66-j5ff.json new file mode 100644 index 00000000000..3ef31bb43a2 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-qhv7-vr66-j5ff/GHSA-qhv7-vr66-j5ff.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qhv7-vr66-j5ff", + "modified": "2024-06-19T12:31:21Z", + "published": "2024-06-19T12:31:21Z", + "aliases": [ + "CVE-2024-35780" + ], + "details": "Deserialization of Untrusted Data vulnerability in Live Composer Team Page Builder: Live Composer.This issue affects Page Builder: Live Composer: from n/a through 1.5.42.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35780" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/live-composer-page-builder/wordpress-page-builder-live-composer-plugin-1-5-42-contributor-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-19T11:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-vhfx-77qc-h5hr/GHSA-vhfx-77qc-h5hr.json b/advisories/unreviewed/2024/06/GHSA-vhfx-77qc-h5hr/GHSA-vhfx-77qc-h5hr.json new file mode 100644 index 00000000000..ede5ed2e70c --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-vhfx-77qc-h5hr/GHSA-vhfx-77qc-h5hr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vhfx-77qc-h5hr", + "modified": "2024-06-19T12:31:21Z", + "published": "2024-06-19T12:31:21Z", + "aliases": [ + "CVE-2023-47770" + ], + "details": "Missing Authorization vulnerability in Muffin Group Betheme.This issue affects Betheme: from n/a through 27.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47770" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/betheme/wordpress-betheme-theme-27-1-1-contributor-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-19T12:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-xhxm-p3qv-qprc/GHSA-xhxm-p3qv-qprc.json b/advisories/unreviewed/2024/06/GHSA-xhxm-p3qv-qprc/GHSA-xhxm-p3qv-qprc.json index 2ba2054a094..d435a8624f3 100644 --- a/advisories/unreviewed/2024/06/GHSA-xhxm-p3qv-qprc/GHSA-xhxm-p3qv-qprc.json +++ b/advisories/unreviewed/2024/06/GHSA-xhxm-p3qv-qprc/GHSA-xhxm-p3qv-qprc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xhxm-p3qv-qprc", - "modified": "2024-06-14T00:33:06Z", + "modified": "2024-06-19T12:31:21Z", "published": "2024-06-11T15:31:13Z", "aliases": [ "CVE-2024-5691" @@ -26,6 +26,10 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00000.html" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00010.html" + }, { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-25"