diff --git a/advisories/unreviewed/2024/03/GHSA-4pg2-jrch-m6p4/GHSA-4pg2-jrch-m6p4.json b/advisories/unreviewed/2024/03/GHSA-4pg2-jrch-m6p4/GHSA-4pg2-jrch-m6p4.json index c09e0c15c5d..cca85e1d99b 100644 --- a/advisories/unreviewed/2024/03/GHSA-4pg2-jrch-m6p4/GHSA-4pg2-jrch-m6p4.json +++ b/advisories/unreviewed/2024/03/GHSA-4pg2-jrch-m6p4/GHSA-4pg2-jrch-m6p4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4pg2-jrch-m6p4", - "modified": "2024-09-30T12:30:32Z", + "modified": "2024-10-17T12:30:51Z", "published": "2024-03-05T12:30:32Z", "aliases": [ "CVE-2023-45596" diff --git a/advisories/unreviewed/2024/03/GHSA-j594-4mw2-8pmc/GHSA-j594-4mw2-8pmc.json b/advisories/unreviewed/2024/03/GHSA-j594-4mw2-8pmc/GHSA-j594-4mw2-8pmc.json index 3f3293a1c4c..eed92c0849c 100644 --- a/advisories/unreviewed/2024/03/GHSA-j594-4mw2-8pmc/GHSA-j594-4mw2-8pmc.json +++ b/advisories/unreviewed/2024/03/GHSA-j594-4mw2-8pmc/GHSA-j594-4mw2-8pmc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j594-4mw2-8pmc", - "modified": "2024-09-30T12:30:32Z", + "modified": "2024-10-17T12:30:51Z", "published": "2024-03-05T12:30:31Z", "aliases": [ "CVE-2023-45593" diff --git a/advisories/unreviewed/2024/03/GHSA-m7p8-hcw4-p377/GHSA-m7p8-hcw4-p377.json b/advisories/unreviewed/2024/03/GHSA-m7p8-hcw4-p377/GHSA-m7p8-hcw4-p377.json index 50f5b4dbb0a..a6749429882 100644 --- a/advisories/unreviewed/2024/03/GHSA-m7p8-hcw4-p377/GHSA-m7p8-hcw4-p377.json +++ b/advisories/unreviewed/2024/03/GHSA-m7p8-hcw4-p377/GHSA-m7p8-hcw4-p377.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m7p8-hcw4-p377", - "modified": "2024-09-30T12:30:32Z", + "modified": "2024-10-17T12:30:51Z", "published": "2024-03-05T12:30:32Z", "aliases": [ "CVE-2023-45598" diff --git a/advisories/unreviewed/2024/10/GHSA-3m79-x4pj-g3g2/GHSA-3m79-x4pj-g3g2.json b/advisories/unreviewed/2024/10/GHSA-3m79-x4pj-g3g2/GHSA-3m79-x4pj-g3g2.json new file mode 100644 index 00000000000..d876cd0a1ec --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-3m79-x4pj-g3g2/GHSA-3m79-x4pj-g3g2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3m79-x4pj-g3g2", + "modified": "2024-10-17T12:30:51Z", + "published": "2024-10-17T12:30:51Z", + "aliases": [ + "CVE-2024-48024" + ], + "details": ": Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Fahad Mahmood Keep Backup Daily allows Retrieve Embedded Sensitive Data.This issue affects Keep Backup Daily: from n/a through 2.0.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48024" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/keep-backup-daily/wordpress-keep-backup-daily-plugin-2-0-7-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T12:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-3x34-6x7v-gx9x/GHSA-3x34-6x7v-gx9x.json b/advisories/unreviewed/2024/10/GHSA-3x34-6x7v-gx9x/GHSA-3x34-6x7v-gx9x.json new file mode 100644 index 00000000000..70f7bfc33b7 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-3x34-6x7v-gx9x/GHSA-3x34-6x7v-gx9x.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3x34-6x7v-gx9x", + "modified": "2024-10-17T12:30:51Z", + "published": "2024-10-17T12:30:51Z", + "aliases": [ + "CVE-2024-9184" + ], + "details": "The SendPulse Free Web Push plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.3.6 due to incorrect use of the wp_kses_allowed_html function. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9184" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/sendpulse-web-push/trunk/settings.php#L10" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3169899" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/sendpulse-web-push/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/74831bf8-0a30-4758-bfe6-5a5b4ee7ec24?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T10:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-48cm-7wff-qj95/GHSA-48cm-7wff-qj95.json b/advisories/unreviewed/2024/10/GHSA-48cm-7wff-qj95/GHSA-48cm-7wff-qj95.json new file mode 100644 index 00000000000..c05db459d9a --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-48cm-7wff-qj95/GHSA-48cm-7wff-qj95.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-48cm-7wff-qj95", + "modified": "2024-10-17T12:30:51Z", + "published": "2024-10-17T12:30:51Z", + "aliases": [ + "CVE-2024-49392" + ], + "details": "Stored cross-site scripting (XSS) vulnerability on enrollment invitation page. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0x24.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49392" + }, + { + "type": "WEB", + "url": "https://security-advisory.acronis.com/advisories/SEC-7554" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T10:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-5vxc-2qqr-5x28/GHSA-5vxc-2qqr-5x28.json b/advisories/unreviewed/2024/10/GHSA-5vxc-2qqr-5x28/GHSA-5vxc-2qqr-5x28.json new file mode 100644 index 00000000000..3b4364d4fff --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-5vxc-2qqr-5x28/GHSA-5vxc-2qqr-5x28.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5vxc-2qqr-5x28", + "modified": "2024-10-17T12:30:51Z", + "published": "2024-10-17T12:30:51Z", + "aliases": [ + "CVE-2024-8920" + ], + "details": "The Fonto – Custom Web Fonts Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8920" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/fonto/trunk/includes/class-fonto.php#L373" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3169936" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3169936/#file2" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/fonto/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/358be91d-cb00-429b-a4ed-69bf81e4d19e?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T10:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-7rg4-m9mf-m8jc/GHSA-7rg4-m9mf-m8jc.json b/advisories/unreviewed/2024/10/GHSA-7rg4-m9mf-m8jc/GHSA-7rg4-m9mf-m8jc.json new file mode 100644 index 00000000000..2858f1f2f53 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-7rg4-m9mf-m8jc/GHSA-7rg4-m9mf-m8jc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7rg4-m9mf-m8jc", + "modified": "2024-10-17T12:30:51Z", + "published": "2024-10-17T12:30:51Z", + "aliases": [ + "CVE-2024-48038" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Hans Matzen wp-Monalisa allows Cross Site Request Forgery.This issue affects wp-Monalisa: from n/a through 6.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48038" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-monalisa/wordpress-wp-monalisa-plugin-6-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T12:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-88q9-p7rf-93g4/GHSA-88q9-p7rf-93g4.json b/advisories/unreviewed/2024/10/GHSA-88q9-p7rf-93g4/GHSA-88q9-p7rf-93g4.json new file mode 100644 index 00000000000..24adf571a24 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-88q9-p7rf-93g4/GHSA-88q9-p7rf-93g4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-88q9-p7rf-93g4", + "modified": "2024-10-17T12:30:51Z", + "published": "2024-10-17T12:30:51Z", + "aliases": [ + "CVE-2024-49390" + ], + "details": "Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0x24.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49390" + }, + { + "type": "WEB", + "url": "https://security-advisory.acronis.com/advisories/SEC-5845" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T10:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-8cwh-xhw2-5v68/GHSA-8cwh-xhw2-5v68.json b/advisories/unreviewed/2024/10/GHSA-8cwh-xhw2-5v68/GHSA-8cwh-xhw2-5v68.json new file mode 100644 index 00000000000..6ae341e3322 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-8cwh-xhw2-5v68/GHSA-8cwh-xhw2-5v68.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8cwh-xhw2-5v68", + "modified": "2024-10-17T12:30:51Z", + "published": "2024-10-17T12:30:51Z", + "aliases": [ + "CVE-2024-45713" + ], + "details": "SolarWinds Kiwi CatTools is susceptible to a sensitive data disclosure vulnerability when a non-default setting has been enabled for troubleshooting purposes.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45713" + }, + { + "type": "WEB", + "url": "https://www.solarwinds.com/trust-center/security-advisories/CVE-2024-45713" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-209" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T11:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-f342-w972-f7wp/GHSA-f342-w972-f7wp.json b/advisories/unreviewed/2024/10/GHSA-f342-w972-f7wp/GHSA-f342-w972-f7wp.json new file mode 100644 index 00000000000..f71c029c963 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-f342-w972-f7wp/GHSA-f342-w972-f7wp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f342-w972-f7wp", + "modified": "2024-10-17T12:30:52Z", + "published": "2024-10-17T12:30:52Z", + "aliases": [ + "CVE-2024-48047" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Razon Komar Pal Linked Variation for WooCommerce allows Cross Site Request Forgery.This issue affects Linked Variation for WooCommerce: from n/a through 1.0.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48047" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/linked-variation-for-woocommerce/wordpress-linked-variation-for-woocommerce-plugin-1-0-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T12:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-g487-gqfx-jgg8/GHSA-g487-gqfx-jgg8.json b/advisories/unreviewed/2024/10/GHSA-g487-gqfx-jgg8/GHSA-g487-gqfx-jgg8.json new file mode 100644 index 00000000000..68b05170d3d --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-g487-gqfx-jgg8/GHSA-g487-gqfx-jgg8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g487-gqfx-jgg8", + "modified": "2024-10-17T12:30:51Z", + "published": "2024-10-17T12:30:51Z", + "aliases": [ + "CVE-2024-48043" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ShortPixel ShortPixel Image Optimizer allows Blind SQL Injection.This issue affects ShortPixel Image Optimizer: from n/a through 5.6.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48043" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/shortpixel-image-optimiser/wordpress-shortpixel-image-optimizer-plugin-5-6-3-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T12:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-g772-q8cg-3fp5/GHSA-g772-q8cg-3fp5.json b/advisories/unreviewed/2024/10/GHSA-g772-q8cg-3fp5/GHSA-g772-q8cg-3fp5.json new file mode 100644 index 00000000000..712617fc2e7 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-g772-q8cg-3fp5/GHSA-g772-q8cg-3fp5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g772-q8cg-3fp5", + "modified": "2024-10-17T12:30:51Z", + "published": "2024-10-17T12:30:51Z", + "aliases": [ + "CVE-2024-49389" + ], + "details": "Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0x24.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49389" + }, + { + "type": "WEB", + "url": "https://security-advisory.acronis.com/advisories/SEC-5319" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T10:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-h35x-c82g-hxx8/GHSA-h35x-c82g-hxx8.json b/advisories/unreviewed/2024/10/GHSA-h35x-c82g-hxx8/GHSA-h35x-c82g-hxx8.json new file mode 100644 index 00000000000..17b7b067f72 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-h35x-c82g-hxx8/GHSA-h35x-c82g-hxx8.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h35x-c82g-hxx8", + "modified": "2024-10-17T12:30:51Z", + "published": "2024-10-17T12:30:51Z", + "aliases": [ + "CVE-2024-10068" + ], + "details": "A vulnerability was found in OpenSight Software FlashFXP 5.4.0.3970. It has been classified as critical. Affected is an unknown function in the library libcrypto-1_1.dll of the file FlashFXP.exe. The manipulation leads to uncontrolled search path. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10068" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.280716" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.280716" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.419684" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T11:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-jrgj-8969-92hw/GHSA-jrgj-8969-92hw.json b/advisories/unreviewed/2024/10/GHSA-jrgj-8969-92hw/GHSA-jrgj-8969-92hw.json new file mode 100644 index 00000000000..15d159b9ba6 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-jrgj-8969-92hw/GHSA-jrgj-8969-92hw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jrgj-8969-92hw", + "modified": "2024-10-17T12:30:51Z", + "published": "2024-10-17T12:30:51Z", + "aliases": [ + "CVE-2024-49386" + ], + "details": "Sensitive information disclosure due to spell-jacking. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0x24.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49386" + }, + { + "type": "WEB", + "url": "https://security-advisory.acronis.com/advisories/SEC-5129" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-359" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T10:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-m3p3-rf2c-fxw8/GHSA-m3p3-rf2c-fxw8.json b/advisories/unreviewed/2024/10/GHSA-m3p3-rf2c-fxw8/GHSA-m3p3-rf2c-fxw8.json new file mode 100644 index 00000000000..ae02dd91f7d --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-m3p3-rf2c-fxw8/GHSA-m3p3-rf2c-fxw8.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m3p3-rf2c-fxw8", + "modified": "2024-10-17T12:30:51Z", + "published": "2024-10-17T12:30:51Z", + "aliases": [ + "CVE-2024-10025" + ], + "details": "A vulnerability in the .sdd file allows an attacker to read default passwords stored in plain text within the code. By exploiting these plaintext credentials, an attacker can log into affected SICK products as an “Authorized Client” if the customer has not changed the default password.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10025" + }, + { + "type": "WEB", + "url": "https://cdn.sick.com/media/docs/1/11/411/Special_information_CYBERSECURITY_BY_SICK_en_IM0084411.PDF" + }, + { + "type": "WEB", + "url": "https://sick.com/psirt" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" + }, + { + "type": "WEB", + "url": "https://www.first.org/cvss/calculator/3.1" + }, + { + "type": "WEB", + "url": "https://www.sick.com/.well-known/csaf/white/2024/sca-2024-0003.json" + }, + { + "type": "WEB", + "url": "https://www.sick.com/.well-known/csaf/white/2024/sca-2024-0003.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-798" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T10:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-pv75-hpv2-pc9m/GHSA-pv75-hpv2-pc9m.json b/advisories/unreviewed/2024/10/GHSA-pv75-hpv2-pc9m/GHSA-pv75-hpv2-pc9m.json new file mode 100644 index 00000000000..6c30c5a6cac --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-pv75-hpv2-pc9m/GHSA-pv75-hpv2-pc9m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pv75-hpv2-pc9m", + "modified": "2024-10-17T12:30:52Z", + "published": "2024-10-17T12:30:52Z", + "aliases": [ + "CVE-2024-49320" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dennis Hoppe Encyclopedia / Glossary / Wiki allows Reflected XSS.This issue affects Encyclopedia / Glossary / Wiki: from n/a through 1.7.60.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49320" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/encyclopedia-lexicon-glossary-wiki-dictionary/wordpress-encyclopedia-glossary-wiki-plugin-1-7-60-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T12:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-qmp9-38cm-qhwr/GHSA-qmp9-38cm-qhwr.json b/advisories/unreviewed/2024/10/GHSA-qmp9-38cm-qhwr/GHSA-qmp9-38cm-qhwr.json new file mode 100644 index 00000000000..d2f4dcadfef --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-qmp9-38cm-qhwr/GHSA-qmp9-38cm-qhwr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qmp9-38cm-qhwr", + "modified": "2024-10-17T12:30:51Z", + "published": "2024-10-17T12:30:51Z", + "aliases": [ + "CVE-2024-49391" + ], + "details": "Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0x24.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49391" + }, + { + "type": "WEB", + "url": "https://security-advisory.acronis.com/advisories/SEC-7220" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T10:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-w94j-vp6v-8fr5/GHSA-w94j-vp6v-8fr5.json b/advisories/unreviewed/2024/10/GHSA-w94j-vp6v-8fr5/GHSA-w94j-vp6v-8fr5.json new file mode 100644 index 00000000000..f7d6ef67c77 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-w94j-vp6v-8fr5/GHSA-w94j-vp6v-8fr5.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w94j-vp6v-8fr5", + "modified": "2024-10-17T12:30:51Z", + "published": "2024-10-17T12:30:51Z", + "aliases": [ + "CVE-2024-9898" + ], + "details": "The Parallax Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's dd-parallax shortcode in all versions up to, and including, 1.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9898" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/parallax-image/trunk/assets/shortcode.php#L145" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3170176" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3170176/#file16" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/parallax-image/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/57641366-85d3-4375-8cde-041227c9f811?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T11:15:11Z" + } +} \ No newline at end of file