From c2a3516ffb5f2e080566149541bf2657a24119b5 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 2 Dec 2024 15:33:32 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-pcw9-xw4x-jgj3.json | 4 +- .../GHSA-8rr2-455x-wf4x.json | 4 +- .../GHSA-w2cw-x77x-6h5f.json | 4 +- .../GHSA-7xjr-h9cq-3633.json | 4 +- .../GHSA-rc48-r6qm-2vg9.json | 4 +- .../GHSA-4q2m-qgp3-g9h6.json | 3 +- .../GHSA-52h5-6hgx-mqhx.json | 3 +- .../GHSA-cfjc-m7fv-63xj.json | 6 ++- .../GHSA-25hc-fw6g-7r5g.json | 36 +++++++++++++++ .../GHSA-28m2-22hr-gx8q.json | 36 +++++++++++++++ .../GHSA-2chq-h6gc-7vvc.json | 44 +++++++++++++++++++ .../GHSA-2rhc-gc9x-8vvf.json | 36 +++++++++++++++ .../GHSA-32wm-927m-gppc.json | 36 +++++++++++++++ .../GHSA-3769-fj8m-crfp.json | 37 ++++++++++++++++ .../GHSA-3f9w-974v-5vhv.json | 36 +++++++++++++++ .../GHSA-3hxh-mh53-wv9q.json | 36 +++++++++++++++ .../GHSA-3hxq-37g6-vgvh.json | 37 ++++++++++++++++ .../GHSA-46p5-2v62-6rxc.json | 36 +++++++++++++++ .../GHSA-48r2-m8h4-3vj3.json | 36 +++++++++++++++ .../GHSA-4g38-66f6-62h4.json | 36 +++++++++++++++ .../GHSA-4q7r-hx7m-7wrr.json | 36 +++++++++++++++ .../GHSA-5254-wg4c-992r.json | 36 +++++++++++++++ .../GHSA-54gc-vp68-q9q7.json | 36 +++++++++++++++ .../GHSA-568x-q8pf-86q3.json | 36 +++++++++++++++ .../GHSA-58qx-pwx2-gqm9.json | 41 +++++++++++++++++ .../GHSA-59x8-4cph-rjq9.json | 36 +++++++++++++++ .../GHSA-5wjj-xchx-55wf.json | 44 +++++++++++++++++++ .../GHSA-699w-2m8p-hw49.json | 37 ++++++++++++++++ .../GHSA-6fr7-h9mh-45f3.json | 33 ++++++++++++++ .../GHSA-6vjf-5pvr-cw5f.json | 36 +++++++++++++++ .../GHSA-736f-5x63-xxwq.json | 36 +++++++++++++++ .../GHSA-77wx-fjcv-pvpj.json | 36 +++++++++++++++ .../GHSA-7frc-4jcp-26pq.json | 36 +++++++++++++++ .../GHSA-7g6j-wq7c-h9w7.json | 36 +++++++++++++++ .../GHSA-7g77-959h-6723.json | 36 +++++++++++++++ .../GHSA-7xrr-rp3c-rp2h.json | 36 +++++++++++++++ .../GHSA-858x-g2gh-mq6p.json | 36 +++++++++++++++ .../GHSA-85hq-jvx8-v4hv.json | 36 +++++++++++++++ .../GHSA-86gj-xr8h-wjf6.json | 37 ++++++++++++++++ .../GHSA-88mc-pcqg-4446.json | 33 ++++++++++++++ .../GHSA-88w9-rm2q-8q3w.json | 36 +++++++++++++++ .../GHSA-89v6-qjfr-p5jm.json | 36 +++++++++++++++ .../GHSA-8cp5-xrc2-3cf6.json | 36 +++++++++++++++ .../GHSA-8gg9-8362-v53q.json | 36 +++++++++++++++ .../GHSA-8x6v-8q4g-xh9f.json | 41 +++++++++++++++++ .../GHSA-958w-v5jh-m736.json | 36 +++++++++++++++ .../GHSA-96gv-mmp8-mqx5.json | 41 +++++++++++++++++ .../GHSA-9jcj-c3px-4jc5.json | 36 +++++++++++++++ .../GHSA-9jmp-7pgh-x746.json | 36 +++++++++++++++ .../GHSA-9wgw-vwf8-8383.json | 36 +++++++++++++++ .../GHSA-9xfx-m8f5-3ch7.json | 36 +++++++++++++++ .../GHSA-c3fv-68c8-mgh8.json | 36 +++++++++++++++ .../GHSA-c6g8-rch8-xjjv.json | 33 ++++++++++++++ .../GHSA-c7fm-gwfm-q8c7.json | 33 ++++++++++++++ .../GHSA-c9r3-cjhr-q2xc.json | 36 +++++++++++++++ .../GHSA-cpfq-m4mm-9w57.json | 36 +++++++++++++++ .../GHSA-cpm5-vfmr-42j6.json | 36 +++++++++++++++ .../GHSA-cqgq-69xw-jf2x.json | 36 +++++++++++++++ .../GHSA-f679-5wx9-qfmm.json | 33 ++++++++++++++ .../GHSA-ffrj-45c9-c9w8.json | 36 +++++++++++++++ .../GHSA-fhcc-h55f-gv4f.json | 36 +++++++++++++++ .../GHSA-fhjx-vgjq-8pp9.json | 36 +++++++++++++++ .../GHSA-fjrh-q9q6-686w.json | 36 +++++++++++++++ .../GHSA-fm4v-96pc-pw3x.json | 36 +++++++++++++++ .../GHSA-fqh5-5gj6-jjx8.json | 36 +++++++++++++++ .../GHSA-fv8r-92cq-fm95.json | 36 +++++++++++++++ .../GHSA-fvhh-6wh3-m386.json | 41 +++++++++++++++++ .../GHSA-fwmv-f54w-2j92.json | 36 +++++++++++++++ .../GHSA-g85w-6wff-vc6j.json | 44 +++++++++++++++++++ .../GHSA-gh2q-9gh5-p9fx.json | 41 +++++++++++++++++ .../GHSA-gr9q-rvpp-f2vh.json | 36 +++++++++++++++ .../GHSA-gwx2-9h8p-phf8.json | 41 +++++++++++++++++ .../GHSA-h3v5-36cc-xmc7.json | 33 ++++++++++++++ .../GHSA-h5wg-g4jx-v5qp.json | 36 +++++++++++++++ .../GHSA-h6pm-5cq8-9j8g.json | 36 +++++++++++++++ .../GHSA-jc5x-2q9p-92fq.json | 36 +++++++++++++++ .../GHSA-jc74-h37v-66fx.json | 36 +++++++++++++++ .../GHSA-jcw6-vg2q-7w8m.json | 36 +++++++++++++++ .../GHSA-jmfh-cf2f-p74p.json | 42 ++++++++++++++++++ .../GHSA-jpmg-jp8c-8qpf.json | 36 +++++++++++++++ .../GHSA-jppf-x9c4-c8fj.json | 36 +++++++++++++++ .../GHSA-jrw9-qmpm-pwvq.json | 36 +++++++++++++++ .../GHSA-jw3v-5rhp-24pg.json | 44 +++++++++++++++++++ .../GHSA-m4gw-f5hf-hh6w.json | 36 +++++++++++++++ .../GHSA-mc4m-5rw2-vpwv.json | 36 +++++++++++++++ .../GHSA-mcc9-39v7-654c.json | 36 +++++++++++++++ .../GHSA-mh5g-q2mv-4wjm.json | 36 +++++++++++++++ .../GHSA-mqhp-x4g6-p6qc.json | 36 +++++++++++++++ .../GHSA-mv35-fc54-3wf7.json | 36 +++++++++++++++ .../GHSA-p8p6-69x2-5wqg.json | 36 +++++++++++++++ .../GHSA-pcg3-64vv-w6jf.json | 33 ++++++++++++++ .../GHSA-pffj-pwc5-gccm.json | 36 +++++++++++++++ .../GHSA-pxww-g48r-gw8m.json | 36 +++++++++++++++ .../GHSA-q3cp-cq94-pqh3.json | 36 +++++++++++++++ .../GHSA-q3v6-hm2v-pw99.json | 36 +++++++++++++++ .../GHSA-q56w-m7h5-j43f.json | 33 ++++++++++++++ .../GHSA-q6p5-37cf-777r.json | 36 +++++++++++++++ .../GHSA-q9wp-2pp6-j742.json | 36 +++++++++++++++ .../GHSA-qh5c-j5qq-2c7h.json | 36 +++++++++++++++ .../GHSA-qpmh-748w-8f69.json | 36 +++++++++++++++ .../GHSA-qq4j-h75v-549m.json | 36 +++++++++++++++ .../GHSA-qqqc-4q63-44f9.json | 36 +++++++++++++++ .../GHSA-qvq9-g9g9-hm4j.json | 36 +++++++++++++++ .../GHSA-r39w-239v-ph4m.json | 44 +++++++++++++++++++ .../GHSA-r3gq-2g92-5q88.json | 36 +++++++++++++++ .../GHSA-r5hg-qhj7-r89w.json | 36 +++++++++++++++ .../GHSA-r6cg-rqqp-3rqx.json | 36 +++++++++++++++ .../GHSA-rccm-3mp2-xc76.json | 36 +++++++++++++++ .../GHSA-rgw8-cw3p-qv66.json | 33 ++++++++++++++ .../GHSA-rpw2-v8gh-jmm4.json | 36 +++++++++++++++ .../GHSA-v2jr-j357-jwhf.json | 36 +++++++++++++++ .../GHSA-vjc9-5qjq-847w.json | 36 +++++++++++++++ .../GHSA-vr58-5gj9-563m.json | 33 ++++++++++++++ .../GHSA-vw9h-3h3h-jf8m.json | 36 +++++++++++++++ .../GHSA-vxwr-85cg-x3pq.json | 36 +++++++++++++++ .../GHSA-w78w-44c5-7mwx.json | 41 +++++++++++++++++ .../GHSA-w9xm-h8j7-2chv.json | 41 +++++++++++++++++ .../GHSA-wm7m-wv4x-65rq.json | 36 +++++++++++++++ .../GHSA-x27c-942p-5cpj.json | 36 +++++++++++++++ .../GHSA-x34g-xjxv-fc48.json | 41 +++++++++++++++++ .../GHSA-xffh-3x24-mr3c.json | 36 +++++++++++++++ .../GHSA-xmr8-m3g7-8q7w.json | 36 +++++++++++++++ 122 files changed, 4185 insertions(+), 16 deletions(-) create mode 100644 advisories/unreviewed/2024/12/GHSA-25hc-fw6g-7r5g/GHSA-25hc-fw6g-7r5g.json create mode 100644 advisories/unreviewed/2024/12/GHSA-28m2-22hr-gx8q/GHSA-28m2-22hr-gx8q.json create mode 100644 advisories/unreviewed/2024/12/GHSA-2chq-h6gc-7vvc/GHSA-2chq-h6gc-7vvc.json create mode 100644 advisories/unreviewed/2024/12/GHSA-2rhc-gc9x-8vvf/GHSA-2rhc-gc9x-8vvf.json create mode 100644 advisories/unreviewed/2024/12/GHSA-32wm-927m-gppc/GHSA-32wm-927m-gppc.json create mode 100644 advisories/unreviewed/2024/12/GHSA-3769-fj8m-crfp/GHSA-3769-fj8m-crfp.json create mode 100644 advisories/unreviewed/2024/12/GHSA-3f9w-974v-5vhv/GHSA-3f9w-974v-5vhv.json create mode 100644 advisories/unreviewed/2024/12/GHSA-3hxh-mh53-wv9q/GHSA-3hxh-mh53-wv9q.json create mode 100644 advisories/unreviewed/2024/12/GHSA-3hxq-37g6-vgvh/GHSA-3hxq-37g6-vgvh.json create mode 100644 advisories/unreviewed/2024/12/GHSA-46p5-2v62-6rxc/GHSA-46p5-2v62-6rxc.json create mode 100644 advisories/unreviewed/2024/12/GHSA-48r2-m8h4-3vj3/GHSA-48r2-m8h4-3vj3.json create mode 100644 advisories/unreviewed/2024/12/GHSA-4g38-66f6-62h4/GHSA-4g38-66f6-62h4.json create mode 100644 advisories/unreviewed/2024/12/GHSA-4q7r-hx7m-7wrr/GHSA-4q7r-hx7m-7wrr.json create mode 100644 advisories/unreviewed/2024/12/GHSA-5254-wg4c-992r/GHSA-5254-wg4c-992r.json create mode 100644 advisories/unreviewed/2024/12/GHSA-54gc-vp68-q9q7/GHSA-54gc-vp68-q9q7.json create mode 100644 advisories/unreviewed/2024/12/GHSA-568x-q8pf-86q3/GHSA-568x-q8pf-86q3.json create mode 100644 advisories/unreviewed/2024/12/GHSA-58qx-pwx2-gqm9/GHSA-58qx-pwx2-gqm9.json create mode 100644 advisories/unreviewed/2024/12/GHSA-59x8-4cph-rjq9/GHSA-59x8-4cph-rjq9.json create mode 100644 advisories/unreviewed/2024/12/GHSA-5wjj-xchx-55wf/GHSA-5wjj-xchx-55wf.json create mode 100644 advisories/unreviewed/2024/12/GHSA-699w-2m8p-hw49/GHSA-699w-2m8p-hw49.json create mode 100644 advisories/unreviewed/2024/12/GHSA-6fr7-h9mh-45f3/GHSA-6fr7-h9mh-45f3.json create mode 100644 advisories/unreviewed/2024/12/GHSA-6vjf-5pvr-cw5f/GHSA-6vjf-5pvr-cw5f.json create mode 100644 advisories/unreviewed/2024/12/GHSA-736f-5x63-xxwq/GHSA-736f-5x63-xxwq.json create mode 100644 advisories/unreviewed/2024/12/GHSA-77wx-fjcv-pvpj/GHSA-77wx-fjcv-pvpj.json create mode 100644 advisories/unreviewed/2024/12/GHSA-7frc-4jcp-26pq/GHSA-7frc-4jcp-26pq.json create mode 100644 advisories/unreviewed/2024/12/GHSA-7g6j-wq7c-h9w7/GHSA-7g6j-wq7c-h9w7.json create mode 100644 advisories/unreviewed/2024/12/GHSA-7g77-959h-6723/GHSA-7g77-959h-6723.json create mode 100644 advisories/unreviewed/2024/12/GHSA-7xrr-rp3c-rp2h/GHSA-7xrr-rp3c-rp2h.json create mode 100644 advisories/unreviewed/2024/12/GHSA-858x-g2gh-mq6p/GHSA-858x-g2gh-mq6p.json create mode 100644 advisories/unreviewed/2024/12/GHSA-85hq-jvx8-v4hv/GHSA-85hq-jvx8-v4hv.json create mode 100644 advisories/unreviewed/2024/12/GHSA-86gj-xr8h-wjf6/GHSA-86gj-xr8h-wjf6.json create mode 100644 advisories/unreviewed/2024/12/GHSA-88mc-pcqg-4446/GHSA-88mc-pcqg-4446.json create mode 100644 advisories/unreviewed/2024/12/GHSA-88w9-rm2q-8q3w/GHSA-88w9-rm2q-8q3w.json create mode 100644 advisories/unreviewed/2024/12/GHSA-89v6-qjfr-p5jm/GHSA-89v6-qjfr-p5jm.json create mode 100644 advisories/unreviewed/2024/12/GHSA-8cp5-xrc2-3cf6/GHSA-8cp5-xrc2-3cf6.json create mode 100644 advisories/unreviewed/2024/12/GHSA-8gg9-8362-v53q/GHSA-8gg9-8362-v53q.json create mode 100644 advisories/unreviewed/2024/12/GHSA-8x6v-8q4g-xh9f/GHSA-8x6v-8q4g-xh9f.json create mode 100644 advisories/unreviewed/2024/12/GHSA-958w-v5jh-m736/GHSA-958w-v5jh-m736.json create mode 100644 advisories/unreviewed/2024/12/GHSA-96gv-mmp8-mqx5/GHSA-96gv-mmp8-mqx5.json create mode 100644 advisories/unreviewed/2024/12/GHSA-9jcj-c3px-4jc5/GHSA-9jcj-c3px-4jc5.json create mode 100644 advisories/unreviewed/2024/12/GHSA-9jmp-7pgh-x746/GHSA-9jmp-7pgh-x746.json create mode 100644 advisories/unreviewed/2024/12/GHSA-9wgw-vwf8-8383/GHSA-9wgw-vwf8-8383.json create mode 100644 advisories/unreviewed/2024/12/GHSA-9xfx-m8f5-3ch7/GHSA-9xfx-m8f5-3ch7.json create mode 100644 advisories/unreviewed/2024/12/GHSA-c3fv-68c8-mgh8/GHSA-c3fv-68c8-mgh8.json create mode 100644 advisories/unreviewed/2024/12/GHSA-c6g8-rch8-xjjv/GHSA-c6g8-rch8-xjjv.json create mode 100644 advisories/unreviewed/2024/12/GHSA-c7fm-gwfm-q8c7/GHSA-c7fm-gwfm-q8c7.json create mode 100644 advisories/unreviewed/2024/12/GHSA-c9r3-cjhr-q2xc/GHSA-c9r3-cjhr-q2xc.json create mode 100644 advisories/unreviewed/2024/12/GHSA-cpfq-m4mm-9w57/GHSA-cpfq-m4mm-9w57.json create mode 100644 advisories/unreviewed/2024/12/GHSA-cpm5-vfmr-42j6/GHSA-cpm5-vfmr-42j6.json create mode 100644 advisories/unreviewed/2024/12/GHSA-cqgq-69xw-jf2x/GHSA-cqgq-69xw-jf2x.json create mode 100644 advisories/unreviewed/2024/12/GHSA-f679-5wx9-qfmm/GHSA-f679-5wx9-qfmm.json create mode 100644 advisories/unreviewed/2024/12/GHSA-ffrj-45c9-c9w8/GHSA-ffrj-45c9-c9w8.json create mode 100644 advisories/unreviewed/2024/12/GHSA-fhcc-h55f-gv4f/GHSA-fhcc-h55f-gv4f.json create mode 100644 advisories/unreviewed/2024/12/GHSA-fhjx-vgjq-8pp9/GHSA-fhjx-vgjq-8pp9.json create mode 100644 advisories/unreviewed/2024/12/GHSA-fjrh-q9q6-686w/GHSA-fjrh-q9q6-686w.json create mode 100644 advisories/unreviewed/2024/12/GHSA-fm4v-96pc-pw3x/GHSA-fm4v-96pc-pw3x.json create mode 100644 advisories/unreviewed/2024/12/GHSA-fqh5-5gj6-jjx8/GHSA-fqh5-5gj6-jjx8.json create mode 100644 advisories/unreviewed/2024/12/GHSA-fv8r-92cq-fm95/GHSA-fv8r-92cq-fm95.json create mode 100644 advisories/unreviewed/2024/12/GHSA-fvhh-6wh3-m386/GHSA-fvhh-6wh3-m386.json create mode 100644 advisories/unreviewed/2024/12/GHSA-fwmv-f54w-2j92/GHSA-fwmv-f54w-2j92.json create mode 100644 advisories/unreviewed/2024/12/GHSA-g85w-6wff-vc6j/GHSA-g85w-6wff-vc6j.json create mode 100644 advisories/unreviewed/2024/12/GHSA-gh2q-9gh5-p9fx/GHSA-gh2q-9gh5-p9fx.json create mode 100644 advisories/unreviewed/2024/12/GHSA-gr9q-rvpp-f2vh/GHSA-gr9q-rvpp-f2vh.json create mode 100644 advisories/unreviewed/2024/12/GHSA-gwx2-9h8p-phf8/GHSA-gwx2-9h8p-phf8.json create mode 100644 advisories/unreviewed/2024/12/GHSA-h3v5-36cc-xmc7/GHSA-h3v5-36cc-xmc7.json create mode 100644 advisories/unreviewed/2024/12/GHSA-h5wg-g4jx-v5qp/GHSA-h5wg-g4jx-v5qp.json create mode 100644 advisories/unreviewed/2024/12/GHSA-h6pm-5cq8-9j8g/GHSA-h6pm-5cq8-9j8g.json create mode 100644 advisories/unreviewed/2024/12/GHSA-jc5x-2q9p-92fq/GHSA-jc5x-2q9p-92fq.json create mode 100644 advisories/unreviewed/2024/12/GHSA-jc74-h37v-66fx/GHSA-jc74-h37v-66fx.json create mode 100644 advisories/unreviewed/2024/12/GHSA-jcw6-vg2q-7w8m/GHSA-jcw6-vg2q-7w8m.json create mode 100644 advisories/unreviewed/2024/12/GHSA-jmfh-cf2f-p74p/GHSA-jmfh-cf2f-p74p.json create mode 100644 advisories/unreviewed/2024/12/GHSA-jpmg-jp8c-8qpf/GHSA-jpmg-jp8c-8qpf.json create mode 100644 advisories/unreviewed/2024/12/GHSA-jppf-x9c4-c8fj/GHSA-jppf-x9c4-c8fj.json create mode 100644 advisories/unreviewed/2024/12/GHSA-jrw9-qmpm-pwvq/GHSA-jrw9-qmpm-pwvq.json create mode 100644 advisories/unreviewed/2024/12/GHSA-jw3v-5rhp-24pg/GHSA-jw3v-5rhp-24pg.json create mode 100644 advisories/unreviewed/2024/12/GHSA-m4gw-f5hf-hh6w/GHSA-m4gw-f5hf-hh6w.json create mode 100644 advisories/unreviewed/2024/12/GHSA-mc4m-5rw2-vpwv/GHSA-mc4m-5rw2-vpwv.json create mode 100644 advisories/unreviewed/2024/12/GHSA-mcc9-39v7-654c/GHSA-mcc9-39v7-654c.json create mode 100644 advisories/unreviewed/2024/12/GHSA-mh5g-q2mv-4wjm/GHSA-mh5g-q2mv-4wjm.json create mode 100644 advisories/unreviewed/2024/12/GHSA-mqhp-x4g6-p6qc/GHSA-mqhp-x4g6-p6qc.json create mode 100644 advisories/unreviewed/2024/12/GHSA-mv35-fc54-3wf7/GHSA-mv35-fc54-3wf7.json create mode 100644 advisories/unreviewed/2024/12/GHSA-p8p6-69x2-5wqg/GHSA-p8p6-69x2-5wqg.json create mode 100644 advisories/unreviewed/2024/12/GHSA-pcg3-64vv-w6jf/GHSA-pcg3-64vv-w6jf.json create mode 100644 advisories/unreviewed/2024/12/GHSA-pffj-pwc5-gccm/GHSA-pffj-pwc5-gccm.json create mode 100644 advisories/unreviewed/2024/12/GHSA-pxww-g48r-gw8m/GHSA-pxww-g48r-gw8m.json create mode 100644 advisories/unreviewed/2024/12/GHSA-q3cp-cq94-pqh3/GHSA-q3cp-cq94-pqh3.json create mode 100644 advisories/unreviewed/2024/12/GHSA-q3v6-hm2v-pw99/GHSA-q3v6-hm2v-pw99.json create mode 100644 advisories/unreviewed/2024/12/GHSA-q56w-m7h5-j43f/GHSA-q56w-m7h5-j43f.json create mode 100644 advisories/unreviewed/2024/12/GHSA-q6p5-37cf-777r/GHSA-q6p5-37cf-777r.json create mode 100644 advisories/unreviewed/2024/12/GHSA-q9wp-2pp6-j742/GHSA-q9wp-2pp6-j742.json create mode 100644 advisories/unreviewed/2024/12/GHSA-qh5c-j5qq-2c7h/GHSA-qh5c-j5qq-2c7h.json create mode 100644 advisories/unreviewed/2024/12/GHSA-qpmh-748w-8f69/GHSA-qpmh-748w-8f69.json create mode 100644 advisories/unreviewed/2024/12/GHSA-qq4j-h75v-549m/GHSA-qq4j-h75v-549m.json create mode 100644 advisories/unreviewed/2024/12/GHSA-qqqc-4q63-44f9/GHSA-qqqc-4q63-44f9.json create mode 100644 advisories/unreviewed/2024/12/GHSA-qvq9-g9g9-hm4j/GHSA-qvq9-g9g9-hm4j.json create mode 100644 advisories/unreviewed/2024/12/GHSA-r39w-239v-ph4m/GHSA-r39w-239v-ph4m.json create mode 100644 advisories/unreviewed/2024/12/GHSA-r3gq-2g92-5q88/GHSA-r3gq-2g92-5q88.json create mode 100644 advisories/unreviewed/2024/12/GHSA-r5hg-qhj7-r89w/GHSA-r5hg-qhj7-r89w.json create mode 100644 advisories/unreviewed/2024/12/GHSA-r6cg-rqqp-3rqx/GHSA-r6cg-rqqp-3rqx.json create mode 100644 advisories/unreviewed/2024/12/GHSA-rccm-3mp2-xc76/GHSA-rccm-3mp2-xc76.json create mode 100644 advisories/unreviewed/2024/12/GHSA-rgw8-cw3p-qv66/GHSA-rgw8-cw3p-qv66.json create mode 100644 advisories/unreviewed/2024/12/GHSA-rpw2-v8gh-jmm4/GHSA-rpw2-v8gh-jmm4.json create mode 100644 advisories/unreviewed/2024/12/GHSA-v2jr-j357-jwhf/GHSA-v2jr-j357-jwhf.json create mode 100644 advisories/unreviewed/2024/12/GHSA-vjc9-5qjq-847w/GHSA-vjc9-5qjq-847w.json create mode 100644 advisories/unreviewed/2024/12/GHSA-vr58-5gj9-563m/GHSA-vr58-5gj9-563m.json create mode 100644 advisories/unreviewed/2024/12/GHSA-vw9h-3h3h-jf8m/GHSA-vw9h-3h3h-jf8m.json create mode 100644 advisories/unreviewed/2024/12/GHSA-vxwr-85cg-x3pq/GHSA-vxwr-85cg-x3pq.json create mode 100644 advisories/unreviewed/2024/12/GHSA-w78w-44c5-7mwx/GHSA-w78w-44c5-7mwx.json create mode 100644 advisories/unreviewed/2024/12/GHSA-w9xm-h8j7-2chv/GHSA-w9xm-h8j7-2chv.json create mode 100644 advisories/unreviewed/2024/12/GHSA-wm7m-wv4x-65rq/GHSA-wm7m-wv4x-65rq.json create mode 100644 advisories/unreviewed/2024/12/GHSA-x27c-942p-5cpj/GHSA-x27c-942p-5cpj.json create mode 100644 advisories/unreviewed/2024/12/GHSA-x34g-xjxv-fc48/GHSA-x34g-xjxv-fc48.json create mode 100644 advisories/unreviewed/2024/12/GHSA-xffh-3x24-mr3c/GHSA-xffh-3x24-mr3c.json create mode 100644 advisories/unreviewed/2024/12/GHSA-xmr8-m3g7-8q7w/GHSA-xmr8-m3g7-8q7w.json diff --git a/advisories/unreviewed/2023/06/GHSA-pcw9-xw4x-jgj3/GHSA-pcw9-xw4x-jgj3.json b/advisories/unreviewed/2023/06/GHSA-pcw9-xw4x-jgj3/GHSA-pcw9-xw4x-jgj3.json index 023abfaed67..51e85bf97e1 100644 --- a/advisories/unreviewed/2023/06/GHSA-pcw9-xw4x-jgj3/GHSA-pcw9-xw4x-jgj3.json +++ b/advisories/unreviewed/2023/06/GHSA-pcw9-xw4x-jgj3/GHSA-pcw9-xw4x-jgj3.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-1284" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-8rr2-455x-wf4x/GHSA-8rr2-455x-wf4x.json b/advisories/unreviewed/2024/06/GHSA-8rr2-455x-wf4x/GHSA-8rr2-455x-wf4x.json index ebb3284b508..d65e24ab7aa 100644 --- a/advisories/unreviewed/2024/06/GHSA-8rr2-455x-wf4x/GHSA-8rr2-455x-wf4x.json +++ b/advisories/unreviewed/2024/06/GHSA-8rr2-455x-wf4x/GHSA-8rr2-455x-wf4x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-w2cw-x77x-6h5f/GHSA-w2cw-x77x-6h5f.json b/advisories/unreviewed/2024/06/GHSA-w2cw-x77x-6h5f/GHSA-w2cw-x77x-6h5f.json index ece876e49de..dfd0fd69aef 100644 --- a/advisories/unreviewed/2024/06/GHSA-w2cw-x77x-6h5f/GHSA-w2cw-x77x-6h5f.json +++ b/advisories/unreviewed/2024/06/GHSA-w2cw-x77x-6h5f/GHSA-w2cw-x77x-6h5f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-7xjr-h9cq-3633/GHSA-7xjr-h9cq-3633.json b/advisories/unreviewed/2024/10/GHSA-7xjr-h9cq-3633/GHSA-7xjr-h9cq-3633.json index 2e57423e9c2..23fa888035b 100644 --- a/advisories/unreviewed/2024/10/GHSA-7xjr-h9cq-3633/GHSA-7xjr-h9cq-3633.json +++ b/advisories/unreviewed/2024/10/GHSA-7xjr-h9cq-3633/GHSA-7xjr-h9cq-3633.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-rc48-r6qm-2vg9/GHSA-rc48-r6qm-2vg9.json b/advisories/unreviewed/2024/10/GHSA-rc48-r6qm-2vg9/GHSA-rc48-r6qm-2vg9.json index 4137e6e410a..b01c9ac3236 100644 --- a/advisories/unreviewed/2024/10/GHSA-rc48-r6qm-2vg9/GHSA-rc48-r6qm-2vg9.json +++ b/advisories/unreviewed/2024/10/GHSA-rc48-r6qm-2vg9/GHSA-rc48-r6qm-2vg9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-4q2m-qgp3-g9h6/GHSA-4q2m-qgp3-g9h6.json b/advisories/unreviewed/2024/11/GHSA-4q2m-qgp3-g9h6/GHSA-4q2m-qgp3-g9h6.json index 7ae59e7aa73..a1ad20c0e07 100644 --- a/advisories/unreviewed/2024/11/GHSA-4q2m-qgp3-g9h6/GHSA-4q2m-qgp3-g9h6.json +++ b/advisories/unreviewed/2024/11/GHSA-4q2m-qgp3-g9h6/GHSA-4q2m-qgp3-g9h6.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-52h5-6hgx-mqhx/GHSA-52h5-6hgx-mqhx.json b/advisories/unreviewed/2024/11/GHSA-52h5-6hgx-mqhx/GHSA-52h5-6hgx-mqhx.json index 384c20c2056..83500517c75 100644 --- a/advisories/unreviewed/2024/11/GHSA-52h5-6hgx-mqhx/GHSA-52h5-6hgx-mqhx.json +++ b/advisories/unreviewed/2024/11/GHSA-52h5-6hgx-mqhx/GHSA-52h5-6hgx-mqhx.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-cfjc-m7fv-63xj/GHSA-cfjc-m7fv-63xj.json b/advisories/unreviewed/2024/11/GHSA-cfjc-m7fv-63xj/GHSA-cfjc-m7fv-63xj.json index 585b0819c17..4f0f8000f8b 100644 --- a/advisories/unreviewed/2024/11/GHSA-cfjc-m7fv-63xj/GHSA-cfjc-m7fv-63xj.json +++ b/advisories/unreviewed/2024/11/GHSA-cfjc-m7fv-63xj/GHSA-cfjc-m7fv-63xj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cfjc-m7fv-63xj", - "modified": "2024-11-29T06:35:29Z", + "modified": "2024-12-02T15:31:37Z", "published": "2024-11-26T18:38:52Z", "aliases": [ "CVE-2024-52336" @@ -35,6 +35,10 @@ "type": "WEB", "url": "https://security.opensuse.org/2024/11/26/tuned-instance-create.html" }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2024/11/28/1" + }, { "type": "WEB", "url": "https://www.openwall.com/lists/oss-security/2024/11/28/2" diff --git a/advisories/unreviewed/2024/12/GHSA-25hc-fw6g-7r5g/GHSA-25hc-fw6g-7r5g.json b/advisories/unreviewed/2024/12/GHSA-25hc-fw6g-7r5g/GHSA-25hc-fw6g-7r5g.json new file mode 100644 index 00000000000..e023e0f6597 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-25hc-fw6g-7r5g/GHSA-25hc-fw6g-7r5g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-25hc-fw6g-7r5g", + "modified": "2024-12-02T15:31:40Z", + "published": "2024-12-02T15:31:40Z", + "aliases": [ + "CVE-2024-53754" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Arrow Design Out Of Stock Badge allows Cross Site Request Forgery.This issue affects Out Of Stock Badge: from n/a through 1.3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53754" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/out-of-stock-badge/vulnerability/wordpress-out-of-stock-badge-plugin-1-3-1-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-28m2-22hr-gx8q/GHSA-28m2-22hr-gx8q.json b/advisories/unreviewed/2024/12/GHSA-28m2-22hr-gx8q/GHSA-28m2-22hr-gx8q.json new file mode 100644 index 00000000000..d25c4546ded --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-28m2-22hr-gx8q/GHSA-28m2-22hr-gx8q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-28m2-22hr-gx8q", + "modified": "2024-12-02T15:31:40Z", + "published": "2024-12-02T15:31:40Z", + "aliases": [ + "CVE-2024-53761" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in P. Roy WP Revisions Manager allows Cross Site Request Forgery.This issue affects WP Revisions Manager: from n/a through 1.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53761" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-revisions-manager/vulnerability/wordpress-wp-revisions-manager-plugin-1-0-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-2chq-h6gc-7vvc/GHSA-2chq-h6gc-7vvc.json b/advisories/unreviewed/2024/12/GHSA-2chq-h6gc-7vvc/GHSA-2chq-h6gc-7vvc.json new file mode 100644 index 00000000000..c3e3f60af61 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-2chq-h6gc-7vvc/GHSA-2chq-h6gc-7vvc.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2chq-h6gc-7vvc", + "modified": "2024-12-02T15:31:41Z", + "published": "2024-12-02T15:31:41Z", + "aliases": [ + "CVE-2024-46905" + ], + "details": "In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated lower-privileged user (at least Network Manager permissions required) to achieve privilege escalation to the admin account.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46905" + }, + { + "type": "WEB", + "url": "https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-September-2024" + }, + { + "type": "WEB", + "url": "https://docs.progress.com/bundle/whatsupgold-release-notes-24-0/page/WhatsUp-Gold-2024.0-Release-Notes.html" + }, + { + "type": "WEB", + "url": "https://www.progress.com/network-monitoring" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-2rhc-gc9x-8vvf/GHSA-2rhc-gc9x-8vvf.json b/advisories/unreviewed/2024/12/GHSA-2rhc-gc9x-8vvf/GHSA-2rhc-gc9x-8vvf.json new file mode 100644 index 00000000000..f349f38a6e1 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-2rhc-gc9x-8vvf/GHSA-2rhc-gc9x-8vvf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2rhc-gc9x-8vvf", + "modified": "2024-12-02T15:31:40Z", + "published": "2024-12-02T15:31:40Z", + "aliases": [ + "CVE-2024-53755" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Andrea Pernici Third Party Cookie Eraser allows Stored XSS.This issue affects Third Party Cookie Eraser: from n/a through 1.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53755" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/third-party-cookie-eraser/vulnerability/wordpress-third-party-cookie-eraser-plugin-1-0-2-csrf-to-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-32wm-927m-gppc/GHSA-32wm-927m-gppc.json b/advisories/unreviewed/2024/12/GHSA-32wm-927m-gppc/GHSA-32wm-927m-gppc.json new file mode 100644 index 00000000000..bb41c965aa9 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-32wm-927m-gppc/GHSA-32wm-927m-gppc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-32wm-927m-gppc", + "modified": "2024-12-02T15:31:41Z", + "published": "2024-12-02T15:31:41Z", + "aliases": [ + "CVE-2024-53782" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in CMSaccount Photo Video Store allows Cross-Site Scripting (XSS).This issue affects Photo Video Store: from n/a through 21.07.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53782" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/photo-video-store/vulnerability/wordpress-photo-video-store-plugin-21-07-csrf-to-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-3769-fj8m-crfp/GHSA-3769-fj8m-crfp.json b/advisories/unreviewed/2024/12/GHSA-3769-fj8m-crfp/GHSA-3769-fj8m-crfp.json new file mode 100644 index 00000000000..ee6382d1e83 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-3769-fj8m-crfp/GHSA-3769-fj8m-crfp.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3769-fj8m-crfp", + "modified": "2024-12-02T15:31:41Z", + "published": "2024-12-02T15:31:41Z", + "aliases": [ + "CVE-2024-52732" + ], + "details": "Incorrect access control in wms-Warehouse management system-zeqp v2.20.9.1 due to the token value of the zeqp system being reused.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52732" + }, + { + "type": "WEB", + "url": "https://gist.github.com/LINF2009/fe2f0681389d4521d236a34ec2109a24" + }, + { + "type": "WEB", + "url": "https://github.com/dotNetTreasury/WMS/blob/master/README.md" + }, + { + "type": "WEB", + "url": "https://github.com/dotNetTreasury/WMS/tree/master/src" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-3f9w-974v-5vhv/GHSA-3f9w-974v-5vhv.json b/advisories/unreviewed/2024/12/GHSA-3f9w-974v-5vhv/GHSA-3f9w-974v-5vhv.json new file mode 100644 index 00000000000..f406fc9b42f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-3f9w-974v-5vhv/GHSA-3f9w-974v-5vhv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3f9w-974v-5vhv", + "modified": "2024-12-02T15:31:39Z", + "published": "2024-12-02T15:31:39Z", + "aliases": [ + "CVE-2024-53715" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Thomas Hoefter Simple Travel Map allows Stored XSS.This issue affects Simple Travel Map: from n/a through 0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53715" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/simple-travel-map/vulnerability/wordpress-simple-travel-map-plugin-0-1-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-3hxh-mh53-wv9q/GHSA-3hxh-mh53-wv9q.json b/advisories/unreviewed/2024/12/GHSA-3hxh-mh53-wv9q/GHSA-3hxh-mh53-wv9q.json new file mode 100644 index 00000000000..a537b281096 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-3hxh-mh53-wv9q/GHSA-3hxh-mh53-wv9q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3hxh-mh53-wv9q", + "modified": "2024-12-02T15:31:38Z", + "published": "2024-12-02T15:31:38Z", + "aliases": [ + "CVE-2024-52502" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Imbasynergy ImbaChat allows DOM-Based XSS.This issue affects ImbaChat: from n/a through 3.1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52502" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/imbachat-widget/vulnerability/wordpress-imbachat-plugin-3-1-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-3hxq-37g6-vgvh/GHSA-3hxq-37g6-vgvh.json b/advisories/unreviewed/2024/12/GHSA-3hxq-37g6-vgvh/GHSA-3hxq-37g6-vgvh.json new file mode 100644 index 00000000000..76edaf02988 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-3hxq-37g6-vgvh/GHSA-3hxq-37g6-vgvh.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3hxq-37g6-vgvh", + "modified": "2024-12-02T15:31:41Z", + "published": "2024-12-02T15:31:41Z", + "aliases": [ + "CVE-2024-29645" + ], + "details": "Buffer Overflow vulnerability in radarorg radare2 v.5.8.8 allows an attacker to execute arbitrary code via the parse_die function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29645" + }, + { + "type": "WEB", + "url": "https://github.com/radareorg/radare2/pull/22561" + }, + { + "type": "WEB", + "url": "https://github.com/radareorg/radare2/commit/72bf3a486fa851797aa21887a40ba0e3d3a6d620" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Crispy-fried-chicken/83f0f5e8a475284d64bf99fb342e9027" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-46p5-2v62-6rxc/GHSA-46p5-2v62-6rxc.json b/advisories/unreviewed/2024/12/GHSA-46p5-2v62-6rxc/GHSA-46p5-2v62-6rxc.json new file mode 100644 index 00000000000..16611e7cd44 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-46p5-2v62-6rxc/GHSA-46p5-2v62-6rxc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-46p5-2v62-6rxc", + "modified": "2024-12-02T15:31:38Z", + "published": "2024-12-02T15:31:38Z", + "aliases": [ + "CVE-2024-52477" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in No-nonsense Labs Document & Data Automation allows Stored XSS.This issue affects Document & Data Automation: from n/a through 1.6.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52477" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/document-data-automation/vulnerability/wordpress-document-data-automation-plugin-1-6-1-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-48r2-m8h4-3vj3/GHSA-48r2-m8h4-3vj3.json b/advisories/unreviewed/2024/12/GHSA-48r2-m8h4-3vj3/GHSA-48r2-m8h4-3vj3.json new file mode 100644 index 00000000000..eb2c7f2b8db --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-48r2-m8h4-3vj3/GHSA-48r2-m8h4-3vj3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-48r2-m8h4-3vj3", + "modified": "2024-12-02T15:31:39Z", + "published": "2024-12-02T15:31:39Z", + "aliases": [ + "CVE-2024-53714" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Arrow Design Continue Shopping From Cart allows Stored XSS.This issue affects Continue Shopping From Cart: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53714" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/continue-shopping-from-cart-page/vulnerability/wordpress-continue-shopping-from-cart-plugin-1-3-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-4g38-66f6-62h4/GHSA-4g38-66f6-62h4.json b/advisories/unreviewed/2024/12/GHSA-4g38-66f6-62h4/GHSA-4g38-66f6-62h4.json new file mode 100644 index 00000000000..b4a759c6cf5 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-4g38-66f6-62h4/GHSA-4g38-66f6-62h4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4g38-66f6-62h4", + "modified": "2024-12-02T15:31:39Z", + "published": "2024-12-02T15:31:39Z", + "aliases": [ + "CVE-2024-53711" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Jean-Marc BIANCA Hotlink2Watermark allows Stored XSS.This issue affects Hotlink2Watermark: from n/a through 0.3.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53711" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/hotlink2watermark/vulnerability/wordpress-hotlink2watermark-plugin-0-3-2-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-4q7r-hx7m-7wrr/GHSA-4q7r-hx7m-7wrr.json b/advisories/unreviewed/2024/12/GHSA-4q7r-hx7m-7wrr/GHSA-4q7r-hx7m-7wrr.json new file mode 100644 index 00000000000..cb0b6db86cf --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-4q7r-hx7m-7wrr/GHSA-4q7r-hx7m-7wrr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4q7r-hx7m-7wrr", + "modified": "2024-12-02T15:31:40Z", + "published": "2024-12-02T15:31:40Z", + "aliases": [ + "CVE-2024-53779" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Max Engel Yahoo! WebPlayer allows Stored XSS.This issue affects Yahoo! WebPlayer: from n/a through 2.0.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53779" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/yahoo-media-player/vulnerability/wordpress-yahoo-webplayer-plugin-2-0-6-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-5254-wg4c-992r/GHSA-5254-wg4c-992r.json b/advisories/unreviewed/2024/12/GHSA-5254-wg4c-992r/GHSA-5254-wg4c-992r.json new file mode 100644 index 00000000000..3777d66f87e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-5254-wg4c-992r/GHSA-5254-wg4c-992r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5254-wg4c-992r", + "modified": "2024-12-02T15:31:38Z", + "published": "2024-12-02T15:31:38Z", + "aliases": [ + "CVE-2024-52457" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Youneeq Youneeq Recommendations allows Reflected XSS.This issue affects Youneeq Recommendations: from n/a through 3.0.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52457" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/youneeq-panel/vulnerability/wordpress-youneeq-recommendations-plugin-3-0-7-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-54gc-vp68-q9q7/GHSA-54gc-vp68-q9q7.json b/advisories/unreviewed/2024/12/GHSA-54gc-vp68-q9q7/GHSA-54gc-vp68-q9q7.json new file mode 100644 index 00000000000..74eb17b7da6 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-54gc-vp68-q9q7/GHSA-54gc-vp68-q9q7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-54gc-vp68-q9q7", + "modified": "2024-12-02T15:31:37Z", + "published": "2024-12-02T15:31:37Z", + "aliases": [ + "CVE-2024-52454" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GoQSystem Inc. GoQMieruca allows Reflected XSS.This issue affects GoQMieruca: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52454" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/goqmieruca/vulnerability/wordpress-goqmieruca-plugin-1-0-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-568x-q8pf-86q3/GHSA-568x-q8pf-86q3.json b/advisories/unreviewed/2024/12/GHSA-568x-q8pf-86q3/GHSA-568x-q8pf-86q3.json new file mode 100644 index 00000000000..e645a4b96d4 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-568x-q8pf-86q3/GHSA-568x-q8pf-86q3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-568x-q8pf-86q3", + "modified": "2024-12-02T15:31:40Z", + "published": "2024-12-02T15:31:40Z", + "aliases": [ + "CVE-2024-53724" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Ronny L. Bull IceStats allows Stored XSS.This issue affects IceStats: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53724" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/icestats/vulnerability/wordpress-icestats-plugin-1-3-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-58qx-pwx2-gqm9/GHSA-58qx-pwx2-gqm9.json b/advisories/unreviewed/2024/12/GHSA-58qx-pwx2-gqm9/GHSA-58qx-pwx2-gqm9.json new file mode 100644 index 00000000000..c83e053a095 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-58qx-pwx2-gqm9/GHSA-58qx-pwx2-gqm9.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-58qx-pwx2-gqm9", + "modified": "2024-12-02T15:31:39Z", + "published": "2024-12-02T15:31:39Z", + "aliases": [ + "CVE-2024-53123" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: error out earlier on disconnect\n\nEric reported a division by zero splat in the MPTCP protocol:\n\nOops: divide error: 0000 [#1] PREEMPT SMP KASAN PTI\nCPU: 1 UID: 0 PID: 6094 Comm: syz-executor317 Not tainted\n6.12.0-rc5-syzkaller-00291-g05b92660cdfe #0\nHardware name: Google Google Compute Engine/Google Compute Engine,\nBIOS Google 09/13/2024\nRIP: 0010:__tcp_select_window+0x5b4/0x1310 net/ipv4/tcp_output.c:3163\nCode: f6 44 01 e3 89 df e8 9b 75 09 f8 44 39 f3 0f 8d 11 ff ff ff e8\n0d 74 09 f8 45 89 f4 e9 04 ff ff ff e8 00 74 09 f8 44 89 f0 99 7c\n24 14 41 29 d6 45 89 f4 e9 ec fe ff ff e8 e8 73 09 f8 48 89\nRSP: 0018:ffffc900041f7930 EFLAGS: 00010293\nRAX: 0000000000017e67 RBX: 0000000000017e67 RCX: ffffffff8983314b\nRDX: 0000000000000000 RSI: ffffffff898331b0 RDI: 0000000000000004\nRBP: 00000000005d6000 R08: 0000000000000004 R09: 0000000000017e67\nR10: 0000000000003e80 R11: 0000000000000000 R12: 0000000000003e80\nR13: ffff888031d9b440 R14: 0000000000017e67 R15: 00000000002eb000\nFS: 00007feb5d7f16c0(0000) GS:ffff8880b8700000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007feb5d8adbb8 CR3: 0000000074e4c000 CR4: 00000000003526f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n\n__tcp_cleanup_rbuf+0x3e7/0x4b0 net/ipv4/tcp.c:1493\nmptcp_rcv_space_adjust net/mptcp/protocol.c:2085 [inline]\nmptcp_recvmsg+0x2156/0x2600 net/mptcp/protocol.c:2289\ninet_recvmsg+0x469/0x6a0 net/ipv4/af_inet.c:885\nsock_recvmsg_nosec net/socket.c:1051 [inline]\nsock_recvmsg+0x1b2/0x250 net/socket.c:1073\n__sys_recvfrom+0x1a5/0x2e0 net/socket.c:2265\n__do_sys_recvfrom net/socket.c:2283 [inline]\n__se_sys_recvfrom net/socket.c:2279 [inline]\n__x64_sys_recvfrom+0xe0/0x1c0 net/socket.c:2279\ndo_syscall_x64 arch/x86/entry/common.c:52 [inline]\ndo_syscall_64+0xcd/0x250 arch/x86/entry/common.c:83\nentry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0033:0x7feb5d857559\nCode: 28 00 00 00 75 05 48 83 c4 28 c3 e8 51 18 00 00 90 48 89 f8 48\n89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d\n01 f0 ff ff 73 01 c3 48 c7 c1 b0 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007feb5d7f1208 EFLAGS: 00000246 ORIG_RAX: 000000000000002d\nRAX: ffffffffffffffda RBX: 00007feb5d8e1318 RCX: 00007feb5d857559\nRDX: 000000800000000e RSI: 0000000000000000 RDI: 0000000000000003\nRBP: 00007feb5d8e1310 R08: 0000000000000000 R09: ffffffff81000000\nR10: 0000000000000100 R11: 0000000000000246 R12: 00007feb5d8e131c\nR13: 00007feb5d8ae074 R14: 000000800000000e R15: 00000000fffffdef\n\nand provided a nice reproducer.\n\nThe root cause is the current bad handling of racing disconnect.\nAfter the blamed commit below, sk_wait_data() can return (with\nerror) with the underlying socket disconnected and a zero rcv_mss.\n\nCatch the error and return without performing any additional\noperations on the current socket.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53123" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/581302298524e9d77c4c44ff5156a6cd112227ae" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/955388e1d5d222c4101c596b536d41b91a8b212e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a66805c9b22caf4e42af7a616f6c6b83c90d1010" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a749b23059b43a9b1787eb36c5d9d44150a34238" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-59x8-4cph-rjq9/GHSA-59x8-4cph-rjq9.json b/advisories/unreviewed/2024/12/GHSA-59x8-4cph-rjq9/GHSA-59x8-4cph-rjq9.json new file mode 100644 index 00000000000..0ee8ef8b2f9 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-59x8-4cph-rjq9/GHSA-59x8-4cph-rjq9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-59x8-4cph-rjq9", + "modified": "2024-12-02T15:31:41Z", + "published": "2024-12-02T15:31:41Z", + "aliases": [ + "CVE-2024-53792" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kiboko Labs Watu Quiz allows SQL Injection.This issue affects Watu Quiz: from n/a through 3.4.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53792" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/watu/vulnerability/wordpress-watu-quiz-plugin-3-4-2-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-5wjj-xchx-55wf/GHSA-5wjj-xchx-55wf.json b/advisories/unreviewed/2024/12/GHSA-5wjj-xchx-55wf/GHSA-5wjj-xchx-55wf.json new file mode 100644 index 00000000000..f56a709b706 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-5wjj-xchx-55wf/GHSA-5wjj-xchx-55wf.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5wjj-xchx-55wf", + "modified": "2024-12-02T15:31:41Z", + "published": "2024-12-02T15:31:41Z", + "aliases": [ + "CVE-2024-8785" + ], + "details": "In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage NmAPI.exe to create or change an existing registry value in registry path HKEY_LOCAL_MACHINE\\SOFTWARE\\WOW6432Node\\Ipswitch\\.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8785" + }, + { + "type": "WEB", + "url": "https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-September-2024" + }, + { + "type": "WEB", + "url": "https://docs.progress.com/bundle/whatsupgold-release-notes-24-0/page/WhatsUp-Gold-2024.0-Release-Notes.html" + }, + { + "type": "WEB", + "url": "https://www.progress.com/network-monitoring" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-648" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-699w-2m8p-hw49/GHSA-699w-2m8p-hw49.json b/advisories/unreviewed/2024/12/GHSA-699w-2m8p-hw49/GHSA-699w-2m8p-hw49.json new file mode 100644 index 00000000000..c2ef618facf --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-699w-2m8p-hw49/GHSA-699w-2m8p-hw49.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-699w-2m8p-hw49", + "modified": "2024-12-02T15:31:39Z", + "published": "2024-12-02T15:31:39Z", + "aliases": [ + "CVE-2024-53108" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Adjust VSDB parser for replay feature\n\nAt some point, the IEEE ID identification for the replay check in the\nAMD EDID was added. However, this check causes the following\nout-of-bounds issues when using KASAN:\n\n[ 27.804016] BUG: KASAN: slab-out-of-bounds in amdgpu_dm_update_freesync_caps+0xefa/0x17a0 [amdgpu]\n[ 27.804788] Read of size 1 at addr ffff8881647fdb00 by task systemd-udevd/383\n\n...\n\n[ 27.821207] Memory state around the buggy address:\n[ 27.821215] ffff8881647fda00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n[ 27.821224] ffff8881647fda80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n[ 27.821234] >ffff8881647fdb00: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc\n[ 27.821243] ^\n[ 27.821250] ffff8881647fdb80: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc\n[ 27.821259] ffff8881647fdc00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n[ 27.821268] ==================================================================\n\nThis is caused because the ID extraction happens outside of the range of\nthe edid lenght. This commit addresses this issue by considering the\namd_vsdb_block size.\n\n(cherry picked from commit b7e381b1ccd5e778e3d9c44c669ad38439a861d8)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53108" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0a326fbc8f72a320051f27328d4d4e7abdfe68d7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/16dd2825c23530f2259fc671960a3a65d2af69bd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8db867061f4c76505ad62422b65d666b45289217" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-6fr7-h9mh-45f3/GHSA-6fr7-h9mh-45f3.json b/advisories/unreviewed/2024/12/GHSA-6fr7-h9mh-45f3/GHSA-6fr7-h9mh-45f3.json new file mode 100644 index 00000000000..c98cd65a3ee --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-6fr7-h9mh-45f3/GHSA-6fr7-h9mh-45f3.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6fr7-h9mh-45f3", + "modified": "2024-12-02T15:31:39Z", + "published": "2024-12-02T15:31:39Z", + "aliases": [ + "CVE-2024-53115" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vmwgfx: avoid null_ptr_deref in vmw_framebuffer_surface_create_handle\n\nThe 'vmw_user_object_buffer' function may return NULL with incorrect\ninputs. To avoid possible null pointer dereference, add a check whether\nthe 'bo' is NULL in the vmw_framebuffer_surface_create_handle.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53115" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/36f64da080555175b58d85f99f5f90435e274e56" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/93d1f41a82de382845af460bf03bcb17dcbf08c5" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-6vjf-5pvr-cw5f/GHSA-6vjf-5pvr-cw5f.json b/advisories/unreviewed/2024/12/GHSA-6vjf-5pvr-cw5f/GHSA-6vjf-5pvr-cw5f.json new file mode 100644 index 00000000000..2e6d3c9e9da --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-6vjf-5pvr-cw5f/GHSA-6vjf-5pvr-cw5f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6vjf-5pvr-cw5f", + "modified": "2024-12-02T15:31:38Z", + "published": "2024-12-02T15:31:38Z", + "aliases": [ + "CVE-2024-52476" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in stefanbohacek Fediverse Embeds allows Upload a Web Shell to a Web Server.This issue affects Fediverse Embeds: from n/a through 1.5.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52476" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/fediverse-embeds/vulnerability/wordpress-fediverse-embeds-plugin-1-5-3-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-736f-5x63-xxwq/GHSA-736f-5x63-xxwq.json b/advisories/unreviewed/2024/12/GHSA-736f-5x63-xxwq/GHSA-736f-5x63-xxwq.json new file mode 100644 index 00000000000..71677a72580 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-736f-5x63-xxwq/GHSA-736f-5x63-xxwq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-736f-5x63-xxwq", + "modified": "2024-12-02T15:31:38Z", + "published": "2024-12-02T15:31:38Z", + "aliases": [ + "CVE-2024-52489" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Udi Dollberg Add Chat App Button allows Stored XSS.This issue affects Add Chat App Button: from n/a through 2.1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52489" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/add-whatsapp-button/vulnerability/wordpress-add-chat-app-button-plugin-2-1-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-77wx-fjcv-pvpj/GHSA-77wx-fjcv-pvpj.json b/advisories/unreviewed/2024/12/GHSA-77wx-fjcv-pvpj/GHSA-77wx-fjcv-pvpj.json new file mode 100644 index 00000000000..87dee41ecd5 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-77wx-fjcv-pvpj/GHSA-77wx-fjcv-pvpj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-77wx-fjcv-pvpj", + "modified": "2024-12-02T15:31:39Z", + "published": "2024-12-02T15:31:39Z", + "aliases": [ + "CVE-2024-53713" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Alain Diart for les-sushi-codeurs.fr & Eric Ambrosi for regart.net Silverlight Video Player allows Stored XSS.This issue affects Silverlight Video Player: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53713" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/smooth-streaming-player/vulnerability/wordpress-silverlight-video-player-plugin-1-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-7frc-4jcp-26pq/GHSA-7frc-4jcp-26pq.json b/advisories/unreviewed/2024/12/GHSA-7frc-4jcp-26pq/GHSA-7frc-4jcp-26pq.json new file mode 100644 index 00000000000..07a0f7493db --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-7frc-4jcp-26pq/GHSA-7frc-4jcp-26pq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7frc-4jcp-26pq", + "modified": "2024-12-02T15:31:38Z", + "published": "2024-12-02T15:31:38Z", + "aliases": [ + "CVE-2024-52503" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tailored Web Services Tailored Tools allows Stored XSS.This issue affects Tailored Tools: from n/a through 1.8.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52503" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/tailored-tools/vulnerability/wordpress-tailored-tools-plugin-1-8-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-7g6j-wq7c-h9w7/GHSA-7g6j-wq7c-h9w7.json b/advisories/unreviewed/2024/12/GHSA-7g6j-wq7c-h9w7/GHSA-7g6j-wq7c-h9w7.json new file mode 100644 index 00000000000..5f3bd2130b2 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-7g6j-wq7c-h9w7/GHSA-7g6j-wq7c-h9w7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7g6j-wq7c-h9w7", + "modified": "2024-12-02T15:31:38Z", + "published": "2024-12-02T15:31:38Z", + "aliases": [ + "CVE-2024-52467" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in August Infotech AI Responsive Gallery Album allows Reflected XSS.This issue affects AI Responsive Gallery Album: from n/a through 1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52467" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ai-responsive-gallery-album/vulnerability/wordpress-ai-responsive-gallery-album-plugin-1-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-7g77-959h-6723/GHSA-7g77-959h-6723.json b/advisories/unreviewed/2024/12/GHSA-7g77-959h-6723/GHSA-7g77-959h-6723.json new file mode 100644 index 00000000000..351c39535d0 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-7g77-959h-6723/GHSA-7g77-959h-6723.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7g77-959h-6723", + "modified": "2024-12-02T15:31:40Z", + "published": "2024-12-02T15:31:40Z", + "aliases": [ + "CVE-2024-53753" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in CultBooking CultBooking Hotel Booking Engine allows Stored XSS.This issue affects CultBooking Hotel Booking Engine: from n/a through 2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53753" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cultbooking-booking-engine/vulnerability/wordpress-cultbooking-hotel-booking-engine-plugin-2-1-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-7xrr-rp3c-rp2h/GHSA-7xrr-rp3c-rp2h.json b/advisories/unreviewed/2024/12/GHSA-7xrr-rp3c-rp2h/GHSA-7xrr-rp3c-rp2h.json new file mode 100644 index 00000000000..4b1a05bb924 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-7xrr-rp3c-rp2h/GHSA-7xrr-rp3c-rp2h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7xrr-rp3c-rp2h", + "modified": "2024-12-02T15:31:40Z", + "published": "2024-12-02T15:31:40Z", + "aliases": [ + "CVE-2024-53759" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Planet Studio team ArCa Payment Gateway allows Stored XSS.This issue affects ArCa Payment Gateway: from n/a through 1.3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53759" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/arca-payment-gateway/vulnerability/wordpress-arca-payment-gateway-plugin-1-3-1-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-858x-g2gh-mq6p/GHSA-858x-g2gh-mq6p.json b/advisories/unreviewed/2024/12/GHSA-858x-g2gh-mq6p/GHSA-858x-g2gh-mq6p.json new file mode 100644 index 00000000000..48b47822399 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-858x-g2gh-mq6p/GHSA-858x-g2gh-mq6p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-858x-g2gh-mq6p", + "modified": "2024-12-02T15:31:40Z", + "published": "2024-12-02T15:31:40Z", + "aliases": [ + "CVE-2024-53727" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in LinkLaunder.com LinkLaunder SEO allows Stored XSS.This issue affects LinkLaunder SEO: from n/a through 0.92.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53727" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/linklaunder-seo-plugin/vulnerability/wordpress-linklaunder-seo-plugin-0-92-1-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-85hq-jvx8-v4hv/GHSA-85hq-jvx8-v4hv.json b/advisories/unreviewed/2024/12/GHSA-85hq-jvx8-v4hv/GHSA-85hq-jvx8-v4hv.json new file mode 100644 index 00000000000..4e17a854a59 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-85hq-jvx8-v4hv/GHSA-85hq-jvx8-v4hv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-85hq-jvx8-v4hv", + "modified": "2024-12-02T15:31:40Z", + "published": "2024-12-02T15:31:40Z", + "aliases": [ + "CVE-2024-53723" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in A.Cihangir BALTACI Google Plus Share and +1 Button allows Stored XSS.This issue affects Google Plus Share and +1 Button: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53723" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/google-plus-share-and-plusone-button/vulnerability/wordpress-google-plus-share-and-1-button-plugin-1-0-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-86gj-xr8h-wjf6/GHSA-86gj-xr8h-wjf6.json b/advisories/unreviewed/2024/12/GHSA-86gj-xr8h-wjf6/GHSA-86gj-xr8h-wjf6.json new file mode 100644 index 00000000000..b9b29bbb061 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-86gj-xr8h-wjf6/GHSA-86gj-xr8h-wjf6.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-86gj-xr8h-wjf6", + "modified": "2024-12-02T15:31:39Z", + "published": "2024-12-02T15:31:39Z", + "aliases": [ + "CVE-2024-53109" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnommu: pass NULL argument to vma_iter_prealloc()\n\nWhen deleting a vma entry from a maple tree, it has to pass NULL to\nvma_iter_prealloc() in order to calculate internal state of the tree, but\nit passed a wrong argument. As a result, nommu kernels crashed upon\naccessing a vma iterator, such as acct_collect() reading the size of vma\nentries after do_munmap().\n\nThis commit fixes this issue by passing a right argument to the\npreallocation call.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53109" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/247d720b2c5d22f7281437fd6054a138256986ba" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8bbf0ab631cdf1dade6745f137cff98751e6ced7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/aceaf33b7666b72dfb86e0aa977be81e3bcbc727" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-88mc-pcqg-4446/GHSA-88mc-pcqg-4446.json b/advisories/unreviewed/2024/12/GHSA-88mc-pcqg-4446/GHSA-88mc-pcqg-4446.json new file mode 100644 index 00000000000..e7b51aed29b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-88mc-pcqg-4446/GHSA-88mc-pcqg-4446.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-88mc-pcqg-4446", + "modified": "2024-12-02T15:31:39Z", + "published": "2024-12-02T15:31:39Z", + "aliases": [ + "CVE-2024-53117" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvirtio/vsock: Improve MSG_ZEROCOPY error handling\n\nAdd a missing kfree_skb() to prevent memory leaks.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53117" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/50061d7319e21165d04e3024354c1b43b6137821" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/60cf6206a1f513512f5d73fa4d3dbbcad2e7dcd6" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-88w9-rm2q-8q3w/GHSA-88w9-rm2q-8q3w.json b/advisories/unreviewed/2024/12/GHSA-88w9-rm2q-8q3w/GHSA-88w9-rm2q-8q3w.json new file mode 100644 index 00000000000..690685ad252 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-88w9-rm2q-8q3w/GHSA-88w9-rm2q-8q3w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-88w9-rm2q-8q3w", + "modified": "2024-12-02T15:31:38Z", + "published": "2024-12-02T15:31:38Z", + "aliases": [ + "CVE-2024-52464" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in anmari amr shortcodes allows Reflected XSS.This issue affects amr shortcodes: from n/a through 1.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52464" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/amr-shortcodes/vulnerability/wordpress-amr-shortcodes-plugin-1-7-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-89v6-qjfr-p5jm/GHSA-89v6-qjfr-p5jm.json b/advisories/unreviewed/2024/12/GHSA-89v6-qjfr-p5jm/GHSA-89v6-qjfr-p5jm.json new file mode 100644 index 00000000000..3eea77e5205 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-89v6-qjfr-p5jm/GHSA-89v6-qjfr-p5jm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-89v6-qjfr-p5jm", + "modified": "2024-12-02T15:31:40Z", + "published": "2024-12-02T15:31:39Z", + "aliases": [ + "CVE-2024-53717" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Yonatan Reinberg yPHPlista allows Stored XSS.This issue affects yPHPlista: from n/a through 1.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53717" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/yphplista/vulnerability/wordpress-yphplista-plugin-1-1-1-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8cp5-xrc2-3cf6/GHSA-8cp5-xrc2-3cf6.json b/advisories/unreviewed/2024/12/GHSA-8cp5-xrc2-3cf6/GHSA-8cp5-xrc2-3cf6.json new file mode 100644 index 00000000000..c4aef5e4632 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8cp5-xrc2-3cf6/GHSA-8cp5-xrc2-3cf6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8cp5-xrc2-3cf6", + "modified": "2024-12-02T15:31:38Z", + "published": "2024-12-02T15:31:38Z", + "aliases": [ + "CVE-2024-52483" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Igor Benić LeanPress allows Reflected XSS.This issue affects LeanPress: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52483" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/leanpress/vulnerability/wordpress-leanpress-plugin-1-0-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8gg9-8362-v53q/GHSA-8gg9-8362-v53q.json b/advisories/unreviewed/2024/12/GHSA-8gg9-8362-v53q/GHSA-8gg9-8362-v53q.json new file mode 100644 index 00000000000..006b26acb21 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8gg9-8362-v53q/GHSA-8gg9-8362-v53q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8gg9-8362-v53q", + "modified": "2024-12-02T15:31:38Z", + "published": "2024-12-02T15:31:38Z", + "aliases": [ + "CVE-2024-52492" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gopi Ramasamy Image horizontal reel scroll slideshow allows Stored XSS.This issue affects Image horizontal reel scroll slideshow: from n/a through 13.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52492" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/image-horizontal-reel-scroll-slideshow/vulnerability/wordpress-image-horizontal-reel-scroll-slideshow-plugin-13-4-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8x6v-8q4g-xh9f/GHSA-8x6v-8q4g-xh9f.json b/advisories/unreviewed/2024/12/GHSA-8x6v-8q4g-xh9f/GHSA-8x6v-8q4g-xh9f.json new file mode 100644 index 00000000000..5149595d6e1 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8x6v-8q4g-xh9f/GHSA-8x6v-8q4g-xh9f.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8x6v-8q4g-xh9f", + "modified": "2024-12-02T15:31:39Z", + "published": "2024-12-02T15:31:39Z", + "aliases": [ + "CVE-2024-53113" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm: fix NULL pointer dereference in alloc_pages_bulk_noprof\n\nWe triggered a NULL pointer dereference for ac.preferred_zoneref->zone in\nalloc_pages_bulk_noprof() when the task is migrated between cpusets.\n\nWhen cpuset is enabled, in prepare_alloc_pages(), ac->nodemask may be\n¤t->mems_allowed. when first_zones_zonelist() is called to find\npreferred_zoneref, the ac->nodemask may be modified concurrently if the\ntask is migrated between different cpusets. Assuming we have 2 NUMA Node,\nwhen traversing Node1 in ac->zonelist, the nodemask is 2, and when\ntraversing Node2 in ac->zonelist, the nodemask is 1. As a result, the\nac->preferred_zoneref points to NULL zone.\n\nIn alloc_pages_bulk_noprof(), for_each_zone_zonelist_nodemask() finds a\nallowable zone and calls zonelist_node_idx(ac.preferred_zoneref), leading\nto NULL pointer dereference.\n\n__alloc_pages_noprof() fixes this issue by checking NULL pointer in commit\nea57485af8f4 (\"mm, page_alloc: fix check for NULL preferred_zone\") and\ncommit df76cee6bbeb (\"mm, page_alloc: remove redundant checks from alloc\nfastpath\").\n\nTo fix it, check NULL pointer for preferred_zoneref->zone.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53113" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/31502374627ba9ec3e710dbd0bb00457cc6d2c19" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6addb2d9501ec866d7b3a3b4e665307c437e9be2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8ce41b0f9d77cca074df25afd39b86e2ee3aa68e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d0f16cec79774c3132df006cf771eddd89d08f58" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-958w-v5jh-m736/GHSA-958w-v5jh-m736.json b/advisories/unreviewed/2024/12/GHSA-958w-v5jh-m736/GHSA-958w-v5jh-m736.json new file mode 100644 index 00000000000..513fecc244d --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-958w-v5jh-m736/GHSA-958w-v5jh-m736.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-958w-v5jh-m736", + "modified": "2024-12-02T15:31:40Z", + "published": "2024-12-02T15:31:40Z", + "aliases": [ + "CVE-2024-53780" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Rajeev Chauhan Load More Posts allows Stored XSS.This issue affects Load More Posts: from n/a through 1.4.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53780" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/load-more-posts/vulnerability/wordpress-load-more-posts-plugin-1-4-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-96gv-mmp8-mqx5/GHSA-96gv-mmp8-mqx5.json b/advisories/unreviewed/2024/12/GHSA-96gv-mmp8-mqx5/GHSA-96gv-mmp8-mqx5.json new file mode 100644 index 00000000000..8bc9457781a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-96gv-mmp8-mqx5/GHSA-96gv-mmp8-mqx5.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-96gv-mmp8-mqx5", + "modified": "2024-12-02T15:31:39Z", + "published": "2024-12-02T15:31:39Z", + "aliases": [ + "CVE-2024-53119" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvirtio/vsock: Fix accept_queue memory leak\n\nAs the final stages of socket destruction may be delayed, it is possible\nthat virtio_transport_recv_listen() will be called after the accept_queue\nhas been flushed, but before the SOCK_DONE flag has been set. As a result,\nsockets enqueued after the flush would remain unremoved, leading to a\nmemory leak.\n\nvsock_release\n __vsock_release\n lock\n virtio_transport_release\n virtio_transport_close\n schedule_delayed_work(close_work)\n sk_shutdown = SHUTDOWN_MASK\n(!) flush accept_queue\n release\n virtio_transport_recv_pkt\n vsock_find_bound_socket\n lock\n if flag(SOCK_DONE) return\n virtio_transport_recv_listen\n child = vsock_create_connected\n (!) vsock_enqueue_accept(child)\n release\nclose_work\n lock\n virtio_transport_do_close\n set_flag(SOCK_DONE)\n virtio_transport_remove_sock\n vsock_remove_sock\n vsock_remove_bound\n release\n\nIntroduce a sk_shutdown check to disallow vsock_enqueue_accept() during\nsocket destruction.\n\nunreferenced object 0xffff888109e3f800 (size 2040):\n comm \"kworker/5:2\", pid 371, jiffies 4294940105\n hex dump (first 32 bytes):\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n 28 00 0b 40 00 00 00 00 00 00 00 00 00 00 00 00 (..@............\n backtrace (crc 9e5f4e84):\n [] kmem_cache_alloc_noprof+0x2c1/0x360\n [] sk_prot_alloc+0x30/0x120\n [] sk_alloc+0x2c/0x4b0\n [] __vsock_create.constprop.0+0x2a/0x310\n [] virtio_transport_recv_pkt+0x4dc/0x9a0\n [] vsock_loopback_work+0xfd/0x140\n [] process_one_work+0x20c/0x570\n [] worker_thread+0x1bf/0x3a0\n [] kthread+0xdd/0x110\n [] ret_from_fork+0x2d/0x50\n [] ret_from_fork_asm+0x1a/0x30", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53119" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2415345042245de7601dcc6eafdbe3a3dcc9e379" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/897617a413e0bf1c6380e3b34b2f28f450508549" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/946c7600fa2207cc8d3fbc86a518ec56f98a5813" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d7b0ff5a866724c3ad21f2628c22a63336deec3f" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-9jcj-c3px-4jc5/GHSA-9jcj-c3px-4jc5.json b/advisories/unreviewed/2024/12/GHSA-9jcj-c3px-4jc5/GHSA-9jcj-c3px-4jc5.json new file mode 100644 index 00000000000..7da04045f4a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-9jcj-c3px-4jc5/GHSA-9jcj-c3px-4jc5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9jcj-c3px-4jc5", + "modified": "2024-12-02T15:31:41Z", + "published": "2024-12-02T15:31:41Z", + "aliases": [ + "CVE-2024-10905" + ], + "details": "IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p2, IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p5, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p8, and all prior versions allows HTTP access to static content in the IdentityIQ application directory that should be protected.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10905" + }, + { + "type": "WEB", + "url": "https://www.sailpoint.com/security-advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-66" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-9jmp-7pgh-x746/GHSA-9jmp-7pgh-x746.json b/advisories/unreviewed/2024/12/GHSA-9jmp-7pgh-x746/GHSA-9jmp-7pgh-x746.json new file mode 100644 index 00000000000..6a8a0b36cf1 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-9jmp-7pgh-x746/GHSA-9jmp-7pgh-x746.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9jmp-7pgh-x746", + "modified": "2024-12-02T15:31:40Z", + "published": "2024-12-02T15:31:40Z", + "aliases": [ + "CVE-2024-53775" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in TannerRitchie Web Applications/DancePress DancePress (TRWA) allows Cross Site Request Forgery.This issue affects DancePress (TRWA): from n/a through 3.1.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53775" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/dancepress-trwa/vulnerability/wordpress-dancepress-trwa-plugin-3-1-11-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-9wgw-vwf8-8383/GHSA-9wgw-vwf8-8383.json b/advisories/unreviewed/2024/12/GHSA-9wgw-vwf8-8383/GHSA-9wgw-vwf8-8383.json new file mode 100644 index 00000000000..b30c04b4996 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-9wgw-vwf8-8383/GHSA-9wgw-vwf8-8383.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9wgw-vwf8-8383", + "modified": "2024-12-02T15:31:40Z", + "published": "2024-12-02T15:31:40Z", + "aliases": [ + "CVE-2024-53769" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Ludovic RIAUDEL Custom Post Type to Map Store allows Stored XSS.This issue affects Custom Post Type to Map Store: from n/a through 1.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53769" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cpt-to-map-store/vulnerability/wordpress-custom-post-type-to-map-store-plugin-1-1-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-9xfx-m8f5-3ch7/GHSA-9xfx-m8f5-3ch7.json b/advisories/unreviewed/2024/12/GHSA-9xfx-m8f5-3ch7/GHSA-9xfx-m8f5-3ch7.json new file mode 100644 index 00000000000..4f52b9da802 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-9xfx-m8f5-3ch7/GHSA-9xfx-m8f5-3ch7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9xfx-m8f5-3ch7", + "modified": "2024-12-02T15:31:40Z", + "published": "2024-12-02T15:31:40Z", + "aliases": [ + "CVE-2024-53718" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Eric Teubert Multi Feed Reader allows Stored XSS.This issue affects Multi Feed Reader: from n/a through 2.2.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53718" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/multi-feed-reader/vulnerability/wordpress-multi-feed-reader-plugin-2-2-4-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-c3fv-68c8-mgh8/GHSA-c3fv-68c8-mgh8.json b/advisories/unreviewed/2024/12/GHSA-c3fv-68c8-mgh8/GHSA-c3fv-68c8-mgh8.json new file mode 100644 index 00000000000..3e37b31e8b4 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-c3fv-68c8-mgh8/GHSA-c3fv-68c8-mgh8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c3fv-68c8-mgh8", + "modified": "2024-12-02T15:31:38Z", + "published": "2024-12-02T15:31:38Z", + "aliases": [ + "CVE-2024-52465" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Data443 LGPD Framework allows Reflected XSS.This issue affects LGPD Framework: from n/a through 2.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52465" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/lgpd-framework/vulnerability/wordpress-lgpd-framework-plugin-2-0-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-c6g8-rch8-xjjv/GHSA-c6g8-rch8-xjjv.json b/advisories/unreviewed/2024/12/GHSA-c6g8-rch8-xjjv/GHSA-c6g8-rch8-xjjv.json new file mode 100644 index 00000000000..644658666c5 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-c6g8-rch8-xjjv/GHSA-c6g8-rch8-xjjv.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c6g8-rch8-xjjv", + "modified": "2024-12-02T15:31:39Z", + "published": "2024-12-02T15:31:39Z", + "aliases": [ + "CVE-2024-53107" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/proc/task_mmu: prevent integer overflow in pagemap_scan_get_args()\n\nThe \"arg->vec_len\" variable is a u64 that comes from the user at the start\nof the function. The \"arg->vec_len * sizeof(struct page_region))\"\nmultiplication can lead to integer wrapping. Use size_mul() to avoid\nthat.\n\nAlso the size_add/mul() functions work on unsigned long so for 32bit\nsystems we need to ensure that \"arg->vec_len\" fits in an unsigned long.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53107" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/669b0cb81e4e4e78cff77a5b367c7f70c0c6c05e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/adee03f8903c58a6a559f21388a430211fac8ce9" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-c7fm-gwfm-q8c7/GHSA-c7fm-gwfm-q8c7.json b/advisories/unreviewed/2024/12/GHSA-c7fm-gwfm-q8c7/GHSA-c7fm-gwfm-q8c7.json new file mode 100644 index 00000000000..af27b0d77a1 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-c7fm-gwfm-q8c7/GHSA-c7fm-gwfm-q8c7.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c7fm-gwfm-q8c7", + "modified": "2024-12-02T15:31:39Z", + "published": "2024-12-02T15:31:39Z", + "aliases": [ + "CVE-2024-53124" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: fix data-races around sk->sk_forward_alloc\n\nSyzkaller reported this warning:\n ------------[ cut here ]------------\n WARNING: CPU: 0 PID: 16 at net/ipv4/af_inet.c:156 inet_sock_destruct+0x1c5/0x1e0\n Modules linked in:\n CPU: 0 UID: 0 PID: 16 Comm: ksoftirqd/0 Not tainted 6.12.0-rc5 #26\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014\n RIP: 0010:inet_sock_destruct+0x1c5/0x1e0\n Code: 24 12 4c 89 e2 5b 48 c7 c7 98 ec bb 82 41 5c e9 d1 18 17 ff 4c 89 e6 5b 48 c7 c7 d0 ec bb 82 41 5c e9 bf 18 17 ff 0f 0b eb 83 <0f> 0b eb 97 0f 0b eb 87 0f 0b e9 68 ff ff ff 66 66 2e 0f 1f 84 00\n RSP: 0018:ffffc9000008bd90 EFLAGS: 00010206\n RAX: 0000000000000300 RBX: ffff88810b172a90 RCX: 0000000000000007\n RDX: 0000000000000002 RSI: 0000000000000300 RDI: ffff88810b172a00\n RBP: ffff88810b172a00 R08: ffff888104273c00 R09: 0000000000100007\n R10: 0000000000020000 R11: 0000000000000006 R12: ffff88810b172a00\n R13: 0000000000000004 R14: 0000000000000000 R15: ffff888237c31f78\n FS: 0000000000000000(0000) GS:ffff888237c00000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007ffc63fecac8 CR3: 000000000342e000 CR4: 00000000000006f0\n DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n Call Trace:\n \n ? __warn+0x88/0x130\n ? inet_sock_destruct+0x1c5/0x1e0\n ? report_bug+0x18e/0x1a0\n ? handle_bug+0x53/0x90\n ? exc_invalid_op+0x18/0x70\n ? asm_exc_invalid_op+0x1a/0x20\n ? inet_sock_destruct+0x1c5/0x1e0\n __sk_destruct+0x2a/0x200\n rcu_do_batch+0x1aa/0x530\n ? rcu_do_batch+0x13b/0x530\n rcu_core+0x159/0x2f0\n handle_softirqs+0xd3/0x2b0\n ? __pfx_smpboot_thread_fn+0x10/0x10\n run_ksoftirqd+0x25/0x30\n smpboot_thread_fn+0xdd/0x1d0\n kthread+0xd3/0x100\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x34/0x50\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1a/0x30\n \n ---[ end trace 0000000000000000 ]---\n\nIts possible that two threads call tcp_v6_do_rcv()/sk_forward_alloc_add()\nconcurrently when sk->sk_state == TCP_LISTEN with sk->sk_lock unlocked,\nwhich triggers a data-race around sk->sk_forward_alloc:\ntcp_v6_rcv\n tcp_v6_do_rcv\n skb_clone_and_charge_r\n sk_rmem_schedule\n __sk_mem_schedule\n sk_forward_alloc_add()\n skb_set_owner_r\n sk_mem_charge\n sk_forward_alloc_add()\n __kfree_skb\n skb_release_all\n skb_release_head_state\n sock_rfree\n sk_mem_uncharge\n sk_forward_alloc_add()\n sk_mem_reclaim\n // set local var reclaimable\n __sk_mem_reclaim\n sk_forward_alloc_add()\n\nIn this syzkaller testcase, two threads call\ntcp_v6_do_rcv() with skb->truesize=768, the sk_forward_alloc changes like\nthis:\n (cpu 1) | (cpu 2) | sk_forward_alloc\n ... | ... | 0\n __sk_mem_schedule() | | +4096 = 4096\n | __sk_mem_schedule() | +4096 = 8192\n sk_mem_charge() | | -768 = 7424\n | sk_mem_charge() | -768 = 6656\n ... | ... |\n sk_mem_uncharge() | | +768 = 7424\n reclaimable=7424 | |\n | sk_mem_uncharge() | +768 = 8192\n | reclaimable=8192 |\n __sk_mem_reclaim() | | -4096 = 4096\n | __sk_mem_reclaim() | -8192 = -4096 != 0\n\nThe skb_clone_and_charge_r() should not be called in tcp_v6_do_rcv() when\nsk->sk_state is TCP_LISTEN, it happens later in tcp_v6_syn_recv_sock().\nFix the same issue in dccp_v6_do_rcv().", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53124" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/073d89808c065ac4c672c0a613a71b27a80691cb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d285eb9d0641c8344f2836081b4ccb7b3c5cc1b6" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-c9r3-cjhr-q2xc/GHSA-c9r3-cjhr-q2xc.json b/advisories/unreviewed/2024/12/GHSA-c9r3-cjhr-q2xc/GHSA-c9r3-cjhr-q2xc.json new file mode 100644 index 00000000000..1d17c8561ac --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-c9r3-cjhr-q2xc/GHSA-c9r3-cjhr-q2xc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c9r3-cjhr-q2xc", + "modified": "2024-12-02T15:31:38Z", + "published": "2024-12-02T15:31:38Z", + "aliases": [ + "CVE-2024-52482" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ortto Ortto allows Reflected XSS.This issue affects Ortto: from n/a through 1.0.19.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52482" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/autopilot/vulnerability/wordpress-ortto-plugin-1-0-19-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-cpfq-m4mm-9w57/GHSA-cpfq-m4mm-9w57.json b/advisories/unreviewed/2024/12/GHSA-cpfq-m4mm-9w57/GHSA-cpfq-m4mm-9w57.json new file mode 100644 index 00000000000..8a59b25d6e1 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-cpfq-m4mm-9w57/GHSA-cpfq-m4mm-9w57.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cpfq-m4mm-9w57", + "modified": "2024-12-02T15:31:38Z", + "published": "2024-12-02T15:31:38Z", + "aliases": [ + "CVE-2024-52462" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jacob Schwartz WP e-Commerce Style Email allows Reflected XSS.This issue affects WP e-Commerce Style Email: from n/a through 0.6.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52462" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-e-commerce-style-email/vulnerability/wordpress-wp-e-commerce-style-email-plugin-0-6-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-cpm5-vfmr-42j6/GHSA-cpm5-vfmr-42j6.json b/advisories/unreviewed/2024/12/GHSA-cpm5-vfmr-42j6/GHSA-cpm5-vfmr-42j6.json new file mode 100644 index 00000000000..ef74697195a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-cpm5-vfmr-42j6/GHSA-cpm5-vfmr-42j6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cpm5-vfmr-42j6", + "modified": "2024-12-02T15:31:41Z", + "published": "2024-12-02T15:31:41Z", + "aliases": [ + "CVE-2024-53793" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in eDoc Intelligence LLC eDoc Easy Tables allows Blind SQL Injection.This issue affects eDoc Easy Tables: from n/a through 1.29.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53793" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/edoc-easy-tables/vulnerability/wordpress-edoc-easy-tables-plugin-1-29-csrf-to-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-cqgq-69xw-jf2x/GHSA-cqgq-69xw-jf2x.json b/advisories/unreviewed/2024/12/GHSA-cqgq-69xw-jf2x/GHSA-cqgq-69xw-jf2x.json new file mode 100644 index 00000000000..d3b470efd25 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-cqgq-69xw-jf2x/GHSA-cqgq-69xw-jf2x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cqgq-69xw-jf2x", + "modified": "2024-12-02T15:31:38Z", + "published": "2024-12-02T15:31:38Z", + "aliases": [ + "CVE-2024-52493" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Josh Leuze Meteor Slides allows Stored XSS.This issue affects Meteor Slides: from n/a through 1.5.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52493" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/meteor-slides/vulnerability/wordpress-meteor-slides-plugin-1-5-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-f679-5wx9-qfmm/GHSA-f679-5wx9-qfmm.json b/advisories/unreviewed/2024/12/GHSA-f679-5wx9-qfmm/GHSA-f679-5wx9-qfmm.json new file mode 100644 index 00000000000..6aaa26254f4 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-f679-5wx9-qfmm/GHSA-f679-5wx9-qfmm.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f679-5wx9-qfmm", + "modified": "2024-12-02T15:31:39Z", + "published": "2024-12-02T15:31:39Z", + "aliases": [ + "CVE-2024-53118" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvsock: Fix sk_error_queue memory leak\n\nKernel queues MSG_ZEROCOPY completion notifications on the error queue.\nWhere they remain, until explicitly recv()ed. To prevent memory leaks,\nclean up the queue when the socket is destroyed.\n\nunreferenced object 0xffff8881028beb00 (size 224):\n comm \"vsock_test\", pid 1218, jiffies 4294694897\n hex dump (first 32 bytes):\n 90 b0 21 17 81 88 ff ff 90 b0 21 17 81 88 ff ff ..!.......!.....\n 00 00 00 00 00 00 00 00 00 b0 21 17 81 88 ff ff ..........!.....\n backtrace (crc 6c7031ca):\n [] kmem_cache_alloc_node_noprof+0x2f7/0x370\n [] __alloc_skb+0x132/0x180\n [] sock_omalloc+0x4b/0x80\n [] msg_zerocopy_realloc+0x9e/0x240\n [] virtio_transport_send_pkt_info+0x412/0x4c0\n [] virtio_transport_stream_enqueue+0x43/0x50\n [] vsock_connectible_sendmsg+0x373/0x450\n [] ____sys_sendmsg+0x365/0x3a0\n [] ___sys_sendmsg+0x84/0xd0\n [] __sys_sendmsg+0x47/0x80\n [] do_syscall_64+0x93/0x180\n [] entry_SYSCALL_64_after_hwframe+0x76/0x7e", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53118" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bea4779a45f49275b1e1b1bd9de03cd3727244d8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fbf7085b3ad1c7cc0677834c90f985f1b4f77a33" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-ffrj-45c9-c9w8/GHSA-ffrj-45c9-c9w8.json b/advisories/unreviewed/2024/12/GHSA-ffrj-45c9-c9w8/GHSA-ffrj-45c9-c9w8.json new file mode 100644 index 00000000000..bb0e933c668 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-ffrj-45c9-c9w8/GHSA-ffrj-45c9-c9w8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ffrj-45c9-c9w8", + "modified": "2024-12-02T15:31:39Z", + "published": "2024-12-02T15:31:39Z", + "aliases": [ + "CVE-2024-53710" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in ITERAS ITERAS allows Stored XSS.This issue affects ITERAS: from n/a through 1.7.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53710" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/iteras/vulnerability/wordpress-iteras-plugin-1-7-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-fhcc-h55f-gv4f/GHSA-fhcc-h55f-gv4f.json b/advisories/unreviewed/2024/12/GHSA-fhcc-h55f-gv4f/GHSA-fhcc-h55f-gv4f.json new file mode 100644 index 00000000000..8282eab5838 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-fhcc-h55f-gv4f/GHSA-fhcc-h55f-gv4f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fhcc-h55f-gv4f", + "modified": "2024-12-02T15:31:37Z", + "published": "2024-12-02T15:31:37Z", + "aliases": [ + "CVE-2024-52453" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jon Lorang Library Bookshelves allows Reflected XSS.This issue affects Library Bookshelves: from n/a through 5.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52453" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/library-bookshelves/vulnerability/wordpress-library-bookshelves-plugin-5-8-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-fhjx-vgjq-8pp9/GHSA-fhjx-vgjq-8pp9.json b/advisories/unreviewed/2024/12/GHSA-fhjx-vgjq-8pp9/GHSA-fhjx-vgjq-8pp9.json new file mode 100644 index 00000000000..dfd64357070 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-fhjx-vgjq-8pp9/GHSA-fhjx-vgjq-8pp9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fhjx-vgjq-8pp9", + "modified": "2024-12-02T15:31:38Z", + "published": "2024-12-02T15:31:38Z", + "aliases": [ + "CVE-2024-52461" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kinsta WordPress Hosting Infinite Slider allows Reflected XSS.This issue affects Infinite Slider: from n/a through 2.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52461" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/infinite-slider/vulnerability/wordpress-infinite-slider-plugin-2-0-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-fjrh-q9q6-686w/GHSA-fjrh-q9q6-686w.json b/advisories/unreviewed/2024/12/GHSA-fjrh-q9q6-686w/GHSA-fjrh-q9q6-686w.json new file mode 100644 index 00000000000..26c74dce0e9 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-fjrh-q9q6-686w/GHSA-fjrh-q9q6-686w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fjrh-q9q6-686w", + "modified": "2024-12-02T15:31:40Z", + "published": "2024-12-02T15:31:40Z", + "aliases": [ + "CVE-2024-53776" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Raphael Heide Donate Me allows Stored XSS.This issue affects Donate Me: from n/a through 1.2.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53776" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/donate-me/vulnerability/wordpress-donate-me-plugin-1-2-5-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-fm4v-96pc-pw3x/GHSA-fm4v-96pc-pw3x.json b/advisories/unreviewed/2024/12/GHSA-fm4v-96pc-pw3x/GHSA-fm4v-96pc-pw3x.json new file mode 100644 index 00000000000..e443c3acdf2 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-fm4v-96pc-pw3x/GHSA-fm4v-96pc-pw3x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fm4v-96pc-pw3x", + "modified": "2024-12-02T15:31:38Z", + "published": "2024-12-02T15:31:38Z", + "aliases": [ + "CVE-2024-52484" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Subhasish Manna Wc Recently viewed products allows Reflected XSS.This issue affects Wc Recently viewed products: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52484" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wc-recently-viewed-products/vulnerability/wordpress-wc-recently-viewed-products-plugin-1-0-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-fqh5-5gj6-jjx8/GHSA-fqh5-5gj6-jjx8.json b/advisories/unreviewed/2024/12/GHSA-fqh5-5gj6-jjx8/GHSA-fqh5-5gj6-jjx8.json new file mode 100644 index 00000000000..6e26b24fdc8 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-fqh5-5gj6-jjx8/GHSA-fqh5-5gj6-jjx8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fqh5-5gj6-jjx8", + "modified": "2024-12-02T15:31:40Z", + "published": "2024-12-02T15:31:40Z", + "aliases": [ + "CVE-2024-53789" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Ritesh Sanap Advanced What should we write next about allows Stored XSS.This issue affects Advanced What should we write next about: from n/a through 1.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53789" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/advanced-what-should-we-write-about-next/vulnerability/wordpress-advanced-what-should-we-write-next-about-plugin-1-0-3-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-fv8r-92cq-fm95/GHSA-fv8r-92cq-fm95.json b/advisories/unreviewed/2024/12/GHSA-fv8r-92cq-fm95/GHSA-fv8r-92cq-fm95.json new file mode 100644 index 00000000000..cf6b613589c --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-fv8r-92cq-fm95/GHSA-fv8r-92cq-fm95.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fv8r-92cq-fm95", + "modified": "2024-12-02T15:31:39Z", + "published": "2024-12-02T15:31:39Z", + "aliases": [ + "CVE-2024-53708" + ], + "details": "Missing Authorization vulnerability in AutoQuiz AI Quiz allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects AI Quiz: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53708" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ai-quiz/vulnerability/wordpress-ai-quiz-plugin-1-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-fvhh-6wh3-m386/GHSA-fvhh-6wh3-m386.json b/advisories/unreviewed/2024/12/GHSA-fvhh-6wh3-m386/GHSA-fvhh-6wh3-m386.json new file mode 100644 index 00000000000..de2ad5db1ea --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-fvhh-6wh3-m386/GHSA-fvhh-6wh3-m386.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fvhh-6wh3-m386", + "modified": "2024-12-02T15:31:39Z", + "published": "2024-12-02T15:31:39Z", + "aliases": [ + "CVE-2024-53120" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: CT: Fix null-ptr-deref in add rule err flow\n\nIn error flow of mlx5_tc_ct_entry_add_rule(), in case ct_rule_add()\ncallback returns error, zone_rule->attr is used uninitiated. Fix it to\nuse attr which has the needed pointer value.\n\nKernel log:\n BUG: kernel NULL pointer dereference, address: 0000000000000110\n RIP: 0010:mlx5_tc_ct_entry_add_rule+0x2b1/0x2f0 [mlx5_core]\n…\n Call Trace:\n \n ? __die+0x20/0x70\n ? page_fault_oops+0x150/0x3e0\n ? exc_page_fault+0x74/0x140\n ? asm_exc_page_fault+0x22/0x30\n ? mlx5_tc_ct_entry_add_rule+0x2b1/0x2f0 [mlx5_core]\n ? mlx5_tc_ct_entry_add_rule+0x1d5/0x2f0 [mlx5_core]\n mlx5_tc_ct_block_flow_offload+0xc6a/0xf90 [mlx5_core]\n ? nf_flow_offload_tuple+0xd8/0x190 [nf_flow_table]\n nf_flow_offload_tuple+0xd8/0x190 [nf_flow_table]\n flow_offload_work_handler+0x142/0x320 [nf_flow_table]\n ? finish_task_switch.isra.0+0x15b/0x2b0\n process_one_work+0x16c/0x320\n worker_thread+0x28c/0x3a0\n ? __pfx_worker_thread+0x10/0x10\n kthread+0xb8/0xf0\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x2d/0x50\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1a/0x30\n ", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53120" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/06dc488a593020bd2f006798557d2a32104d8359" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0c7c70ff8b696cfedba350411dca736361ef9a0f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6030f8bd7902e9e276a0edc09bf11979e4e2bc2e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e99c6873229fe0482e7ceb7d5600e32d623ed9d9" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-fwmv-f54w-2j92/GHSA-fwmv-f54w-2j92.json b/advisories/unreviewed/2024/12/GHSA-fwmv-f54w-2j92/GHSA-fwmv-f54w-2j92.json new file mode 100644 index 00000000000..4137bb6fdae --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-fwmv-f54w-2j92/GHSA-fwmv-f54w-2j92.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fwmv-f54w-2j92", + "modified": "2024-12-02T15:31:40Z", + "published": "2024-12-02T15:31:40Z", + "aliases": [ + "CVE-2024-53781" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Home Junction SpatialMatch IDX allows Stored XSS.This issue affects SpatialMatch IDX: from n/a through 3.0.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53781" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/spatialmatch-free-lifestyle-search/vulnerability/wordpress-spatialmatch-idx-plugin-3-0-9-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-g85w-6wff-vc6j/GHSA-g85w-6wff-vc6j.json b/advisories/unreviewed/2024/12/GHSA-g85w-6wff-vc6j/GHSA-g85w-6wff-vc6j.json new file mode 100644 index 00000000000..a8bdb673ef1 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-g85w-6wff-vc6j/GHSA-g85w-6wff-vc6j.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g85w-6wff-vc6j", + "modified": "2024-12-02T15:31:41Z", + "published": "2024-12-02T15:31:41Z", + "aliases": [ + "CVE-2024-46907" + ], + "details": "In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer permissions required) to achieve privilege escalation to the admin account.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46907" + }, + { + "type": "WEB", + "url": "https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-September-2024" + }, + { + "type": "WEB", + "url": "https://docs.progress.com/bundle/whatsupgold-release-notes-24-0/page/WhatsUp-Gold-2024.0-Release-Notes.html" + }, + { + "type": "WEB", + "url": "https://www.progress.com/network-monitoring" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-gh2q-9gh5-p9fx/GHSA-gh2q-9gh5-p9fx.json b/advisories/unreviewed/2024/12/GHSA-gh2q-9gh5-p9fx/GHSA-gh2q-9gh5-p9fx.json new file mode 100644 index 00000000000..86068426c13 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-gh2q-9gh5-p9fx/GHSA-gh2q-9gh5-p9fx.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gh2q-9gh5-p9fx", + "modified": "2024-12-02T15:31:39Z", + "published": "2024-12-02T15:31:39Z", + "aliases": [ + "CVE-2024-53112" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: uncache inode which has failed entering the group\n\nSyzbot has reported the following BUG:\n\nkernel BUG at fs/ocfs2/uptodate.c:509!\n...\nCall Trace:\n \n ? __die_body+0x5f/0xb0\n ? die+0x9e/0xc0\n ? do_trap+0x15a/0x3a0\n ? ocfs2_set_new_buffer_uptodate+0x145/0x160\n ? do_error_trap+0x1dc/0x2c0\n ? ocfs2_set_new_buffer_uptodate+0x145/0x160\n ? __pfx_do_error_trap+0x10/0x10\n ? handle_invalid_op+0x34/0x40\n ? ocfs2_set_new_buffer_uptodate+0x145/0x160\n ? exc_invalid_op+0x38/0x50\n ? asm_exc_invalid_op+0x1a/0x20\n ? ocfs2_set_new_buffer_uptodate+0x2e/0x160\n ? ocfs2_set_new_buffer_uptodate+0x144/0x160\n ? ocfs2_set_new_buffer_uptodate+0x145/0x160\n ocfs2_group_add+0x39f/0x15a0\n ? __pfx_ocfs2_group_add+0x10/0x10\n ? __pfx_lock_acquire+0x10/0x10\n ? mnt_get_write_access+0x68/0x2b0\n ? __pfx_lock_release+0x10/0x10\n ? rcu_read_lock_any_held+0xb7/0x160\n ? __pfx_rcu_read_lock_any_held+0x10/0x10\n ? smack_log+0x123/0x540\n ? mnt_get_write_access+0x68/0x2b0\n ? mnt_get_write_access+0x68/0x2b0\n ? mnt_get_write_access+0x226/0x2b0\n ocfs2_ioctl+0x65e/0x7d0\n ? __pfx_ocfs2_ioctl+0x10/0x10\n ? smack_file_ioctl+0x29e/0x3a0\n ? __pfx_smack_file_ioctl+0x10/0x10\n ? lockdep_hardirqs_on_prepare+0x43d/0x780\n ? __pfx_lockdep_hardirqs_on_prepare+0x10/0x10\n ? __pfx_ocfs2_ioctl+0x10/0x10\n __se_sys_ioctl+0xfb/0x170\n do_syscall_64+0xf3/0x230\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n...\n \n\nWhen 'ioctl(OCFS2_IOC_GROUP_ADD, ...)' has failed for the particular\ninode in 'ocfs2_verify_group_and_input()', corresponding buffer head\nremains cached and subsequent call to the same 'ioctl()' for the same\ninode issues the BUG() in 'ocfs2_set_new_buffer_uptodate()' (trying\nto cache the same buffer head of that inode). Fix this by uncaching\nthe buffer head with 'ocfs2_remove_from_cache()' on error path in\n'ocfs2_group_add()'.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53112" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/620d22598110b0d0cb97a3fcca65fc473ea86e73" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/737f34137844d6572ab7d473c998c7f977ff30eb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/843dfc804af4b338ead42331dd58081b428ecdf8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b751c50e19d66cfb7360c0b55cf17b0722252d12" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-gr9q-rvpp-f2vh/GHSA-gr9q-rvpp-f2vh.json b/advisories/unreviewed/2024/12/GHSA-gr9q-rvpp-f2vh/GHSA-gr9q-rvpp-f2vh.json new file mode 100644 index 00000000000..7cd1ea1db72 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-gr9q-rvpp-f2vh/GHSA-gr9q-rvpp-f2vh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gr9q-rvpp-f2vh", + "modified": "2024-12-02T15:31:38Z", + "published": "2024-12-02T15:31:38Z", + "aliases": [ + "CVE-2024-52463" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kat Hagan Post By Email allows Reflected XSS.This issue affects Post By Email: from n/a through 1.0.4b.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52463" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/post-by-email/vulnerability/wordpress-post-by-email-plugin-1-0-4b-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-gwx2-9h8p-phf8/GHSA-gwx2-9h8p-phf8.json b/advisories/unreviewed/2024/12/GHSA-gwx2-9h8p-phf8/GHSA-gwx2-9h8p-phf8.json new file mode 100644 index 00000000000..c9803d353b4 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-gwx2-9h8p-phf8/GHSA-gwx2-9h8p-phf8.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gwx2-9h8p-phf8", + "modified": "2024-12-02T15:31:39Z", + "published": "2024-12-02T15:31:39Z", + "aliases": [ + "CVE-2024-53121" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: fs, lock FTE when checking if active\n\nThe referenced commits introduced a two-step process for deleting FTEs:\n\n- Lock the FTE, delete it from hardware, set the hardware deletion function\n to NULL and unlock the FTE.\n- Lock the parent flow group, delete the software copy of the FTE, and\n remove it from the xarray.\n\nHowever, this approach encounters a race condition if a rule with the same\nmatch value is added simultaneously. In this scenario, fs_core may set the\nhardware deletion function to NULL prematurely, causing a panic during\nsubsequent rule deletions.\n\nTo prevent this, ensure the active flag of the FTE is checked under a lock,\nwhich will prevent the fs_core layer from attaching a new steering rule to\nan FTE that is in the process of deletion.\n\n[ 438.967589] MOSHE: 2496 mlx5_del_flow_rules del_hw_func\n[ 438.968205] ------------[ cut here ]------------\n[ 438.968654] refcount_t: decrement hit 0; leaking memory.\n[ 438.969249] WARNING: CPU: 0 PID: 8957 at lib/refcount.c:31 refcount_warn_saturate+0xfb/0x110\n[ 438.970054] Modules linked in: act_mirred cls_flower act_gact sch_ingress openvswitch nsh mlx5_vdpa vringh vhost_iotlb vdpa mlx5_ib mlx5_core xt_conntrack xt_MASQUERADE nf_conntrack_netlink nfnetlink xt_addrtype iptable_nat nf_nat br_netfilter rpcsec_gss_krb5 auth_rpcgss oid_registry overlay rpcrdma rdma_ucm ib_iser libiscsi scsi_transport_iscsi ib_umad rdma_cm ib_ipoib iw_cm ib_cm ib_uverbs ib_core zram zsmalloc fuse [last unloaded: cls_flower]\n[ 438.973288] CPU: 0 UID: 0 PID: 8957 Comm: tc Not tainted 6.12.0-rc1+ #8\n[ 438.973888] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014\n[ 438.974874] RIP: 0010:refcount_warn_saturate+0xfb/0x110\n[ 438.975363] Code: 40 66 3b 82 c6 05 16 e9 4d 01 01 e8 1f 7c a0 ff 0f 0b c3 cc cc cc cc 48 c7 c7 10 66 3b 82 c6 05 fd e8 4d 01 01 e8 05 7c a0 ff <0f> 0b c3 cc cc cc cc 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 00 90\n[ 438.976947] RSP: 0018:ffff888124a53610 EFLAGS: 00010286\n[ 438.977446] RAX: 0000000000000000 RBX: ffff888119d56de0 RCX: 0000000000000000\n[ 438.978090] RDX: ffff88852c828700 RSI: ffff88852c81b3c0 RDI: ffff88852c81b3c0\n[ 438.978721] RBP: ffff888120fa0e88 R08: 0000000000000000 R09: ffff888124a534b0\n[ 438.979353] R10: 0000000000000001 R11: 0000000000000001 R12: ffff888119d56de0\n[ 438.979979] R13: ffff888120fa0ec0 R14: ffff888120fa0ee8 R15: ffff888119d56de0\n[ 438.980607] FS: 00007fe6dcc0f800(0000) GS:ffff88852c800000(0000) knlGS:0000000000000000\n[ 438.983984] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 438.984544] CR2: 00000000004275e0 CR3: 0000000186982001 CR4: 0000000000372eb0\n[ 438.985205] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n[ 438.985842] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n[ 438.986507] Call Trace:\n[ 438.986799] \n[ 438.987070] ? __warn+0x7d/0x110\n[ 438.987426] ? refcount_warn_saturate+0xfb/0x110\n[ 438.987877] ? report_bug+0x17d/0x190\n[ 438.988261] ? prb_read_valid+0x17/0x20\n[ 438.988659] ? handle_bug+0x53/0x90\n[ 438.989054] ? exc_invalid_op+0x14/0x70\n[ 438.989458] ? asm_exc_invalid_op+0x16/0x20\n[ 438.989883] ? refcount_warn_saturate+0xfb/0x110\n[ 438.990348] mlx5_del_flow_rules+0x2f7/0x340 [mlx5_core]\n[ 438.990932] __mlx5_eswitch_del_rule+0x49/0x170 [mlx5_core]\n[ 438.991519] ? mlx5_lag_is_sriov+0x3c/0x50 [mlx5_core]\n[ 438.992054] ? xas_load+0x9/0xb0\n[ 438.992407] mlx5e_tc_rule_unoffload+0x45/0xe0 [mlx5_core]\n[ 438.993037] mlx5e_tc_del_fdb_flow+0x2a6/0x2e0 [mlx5_core]\n[ 438.993623] mlx5e_flow_put+0x29/0x60 [mlx5_core]\n[ 438.994161] mlx5e_delete_flower+0x261/0x390 [mlx5_core]\n[ 438.994728] tc_setup_cb_destroy+0xb9/0x190\n[ 438.995150] fl_hw_destroy_filter+0x94/0xc0 [cls_flower]\n[ 438.995650] fl_change+0x11a4/0x13c0 [cls_flower]\n[ 438.996105] tc_new_tfilter+0x347/0xbc0\n[ 438.996503] ? __\n---truncated---", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53121" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/094d1a2121cee1e85ab07d74388f94809dcfb5b9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/933ef0d17f012b653e9e6006e3f50c8d0238b5ed" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9ca314419930f9135727e39d77e66262d5f7bef6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bfba288f53192db08c68d4c568db9783fb9cb838" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-h3v5-36cc-xmc7/GHSA-h3v5-36cc-xmc7.json b/advisories/unreviewed/2024/12/GHSA-h3v5-36cc-xmc7/GHSA-h3v5-36cc-xmc7.json new file mode 100644 index 00000000000..8b44202b352 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-h3v5-36cc-xmc7/GHSA-h3v5-36cc-xmc7.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h3v5-36cc-xmc7", + "modified": "2024-12-02T15:31:39Z", + "published": "2024-12-02T15:31:39Z", + "aliases": [ + "CVE-2024-53105" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm: page_alloc: move mlocked flag clearance into free_pages_prepare()\n\nSyzbot reported a bad page state problem caused by a page being freed\nusing free_page() still having a mlocked flag at free_pages_prepare()\nstage:\n\n BUG: Bad page state in process syz.5.504 pfn:61f45\n page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x61f45\n flags: 0xfff00000080204(referenced|workingset|mlocked|node=0|zone=1|lastcpupid=0x7ff)\n raw: 00fff00000080204 0000000000000000 dead000000000122 0000000000000000\n raw: 0000000000000000 0000000000000000 00000000ffffffff 0000000000000000\n page dumped because: PAGE_FLAGS_CHECK_AT_FREE flag(s) set\n page_owner tracks the page as allocated\n page last allocated via order 0, migratetype Unmovable, gfp_mask 0x400dc0(GFP_KERNEL_ACCOUNT|__GFP_ZERO), pid 8443, tgid 8442 (syz.5.504), ts 201884660643, free_ts 201499827394\n set_page_owner include/linux/page_owner.h:32 [inline]\n post_alloc_hook+0x1f3/0x230 mm/page_alloc.c:1537\n prep_new_page mm/page_alloc.c:1545 [inline]\n get_page_from_freelist+0x303f/0x3190 mm/page_alloc.c:3457\n __alloc_pages_noprof+0x292/0x710 mm/page_alloc.c:4733\n alloc_pages_mpol_noprof+0x3e8/0x680 mm/mempolicy.c:2265\n kvm_coalesced_mmio_init+0x1f/0xf0 virt/kvm/coalesced_mmio.c:99\n kvm_create_vm virt/kvm/kvm_main.c:1235 [inline]\n kvm_dev_ioctl_create_vm virt/kvm/kvm_main.c:5488 [inline]\n kvm_dev_ioctl+0x12dc/0x2240 virt/kvm/kvm_main.c:5530\n __do_compat_sys_ioctl fs/ioctl.c:1007 [inline]\n __se_compat_sys_ioctl+0x510/0xc90 fs/ioctl.c:950\n do_syscall_32_irqs_on arch/x86/entry/common.c:165 [inline]\n __do_fast_syscall_32+0xb4/0x110 arch/x86/entry/common.c:386\n do_fast_syscall_32+0x34/0x80 arch/x86/entry/common.c:411\n entry_SYSENTER_compat_after_hwframe+0x84/0x8e\n page last free pid 8399 tgid 8399 stack trace:\n reset_page_owner include/linux/page_owner.h:25 [inline]\n free_pages_prepare mm/page_alloc.c:1108 [inline]\n free_unref_folios+0xf12/0x18d0 mm/page_alloc.c:2686\n folios_put_refs+0x76c/0x860 mm/swap.c:1007\n free_pages_and_swap_cache+0x5c8/0x690 mm/swap_state.c:335\n __tlb_batch_free_encoded_pages mm/mmu_gather.c:136 [inline]\n tlb_batch_pages_flush mm/mmu_gather.c:149 [inline]\n tlb_flush_mmu_free mm/mmu_gather.c:366 [inline]\n tlb_flush_mmu+0x3a3/0x680 mm/mmu_gather.c:373\n tlb_finish_mmu+0xd4/0x200 mm/mmu_gather.c:465\n exit_mmap+0x496/0xc40 mm/mmap.c:1926\n __mmput+0x115/0x390 kernel/fork.c:1348\n exit_mm+0x220/0x310 kernel/exit.c:571\n do_exit+0x9b2/0x28e0 kernel/exit.c:926\n do_group_exit+0x207/0x2c0 kernel/exit.c:1088\n __do_sys_exit_group kernel/exit.c:1099 [inline]\n __se_sys_exit_group kernel/exit.c:1097 [inline]\n __x64_sys_exit_group+0x3f/0x40 kernel/exit.c:1097\n x64_sys_call+0x2634/0x2640 arch/x86/include/generated/asm/syscalls_64.h:232\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n Modules linked in:\n CPU: 0 UID: 0 PID: 8442 Comm: syz.5.504 Not tainted 6.12.0-rc6-syzkaller #0\n Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024\n Call Trace:\n \n __dump_stack lib/dump_stack.c:94 [inline]\n dump_stack_lvl+0x241/0x360 lib/dump_stack.c:120\n bad_page+0x176/0x1d0 mm/page_alloc.c:501\n free_page_is_bad mm/page_alloc.c:918 [inline]\n free_pages_prepare mm/page_alloc.c:1100 [inline]\n free_unref_page+0xed0/0xf20 mm/page_alloc.c:2638\n kvm_destroy_vm virt/kvm/kvm_main.c:1327 [inline]\n kvm_put_kvm+0xc75/0x1350 virt/kvm/kvm_main.c:1386\n kvm_vcpu_release+0x54/0x60 virt/kvm/kvm_main.c:4143\n __fput+0x23f/0x880 fs/file_table.c:431\n task_work_run+0x24f/0x310 kernel/task_work.c:239\n exit_task_work include/linux/task_work.h:43 [inline]\n do_exit+0xa2f/0x28e0 kernel/exit.c:939\n do_group_exit+0x207/0x2c0 kernel/exit.c:1088\n __do_sys_exit_group kernel/exit.c:1099 [in\n---truncated---", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53105" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/66edc3a5894c74f8887c8af23b97593a0dd0df4d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7873d11911cd1d21e25c354eb130d8c3b5cb3ca5" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-h5wg-g4jx-v5qp/GHSA-h5wg-g4jx-v5qp.json b/advisories/unreviewed/2024/12/GHSA-h5wg-g4jx-v5qp/GHSA-h5wg-g4jx-v5qp.json new file mode 100644 index 00000000000..1165e8e0fd6 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-h5wg-g4jx-v5qp/GHSA-h5wg-g4jx-v5qp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h5wg-g4jx-v5qp", + "modified": "2024-12-02T15:31:38Z", + "published": "2024-12-02T15:31:38Z", + "aliases": [ + "CVE-2024-52468" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LeadBoxer LeadBoxer allows Reflected XSS.This issue affects LeadBoxer: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52468" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/leadboxer/vulnerability/wordpress-leadboxer-plugin-1-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-h6pm-5cq8-9j8g/GHSA-h6pm-5cq8-9j8g.json b/advisories/unreviewed/2024/12/GHSA-h6pm-5cq8-9j8g/GHSA-h6pm-5cq8-9j8g.json new file mode 100644 index 00000000000..8681f35ba49 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-h6pm-5cq8-9j8g/GHSA-h6pm-5cq8-9j8g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h6pm-5cq8-9j8g", + "modified": "2024-12-02T15:31:39Z", + "published": "2024-12-02T15:31:39Z", + "aliases": [ + "CVE-2024-53709" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bdevs Generic Elements allows DOM-Based XSS.This issue affects Generic Elements: from n/a through 1.2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53709" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/generic-elements-for-elementor/vulnerability/wordpress-generic-elements-plugin-1-2-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-jc5x-2q9p-92fq/GHSA-jc5x-2q9p-92fq.json b/advisories/unreviewed/2024/12/GHSA-jc5x-2q9p-92fq/GHSA-jc5x-2q9p-92fq.json new file mode 100644 index 00000000000..e67f1b16c94 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-jc5x-2q9p-92fq/GHSA-jc5x-2q9p-92fq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jc5x-2q9p-92fq", + "modified": "2024-12-02T15:31:37Z", + "published": "2024-12-02T15:31:37Z", + "aliases": [ + "CVE-2024-52452" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eduNEXT Open edX LMS allows Reflected XSS.This issue affects Open edX LMS: from n/a through 2.6.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52452" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/edunext-openedx-integrator/vulnerability/wordpress-open-edx-lms-plugin-2-6-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-jc74-h37v-66fx/GHSA-jc74-h37v-66fx.json b/advisories/unreviewed/2024/12/GHSA-jc74-h37v-66fx/GHSA-jc74-h37v-66fx.json new file mode 100644 index 00000000000..31db284828f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-jc74-h37v-66fx/GHSA-jc74-h37v-66fx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jc74-h37v-66fx", + "modified": "2024-12-02T15:31:38Z", + "published": "2024-12-02T15:31:38Z", + "aliases": [ + "CVE-2024-52486" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SolverWP Elementor Portfolio Builder allows DOM-Based XSS.This issue affects Elementor Portfolio Builder: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52486" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/portfolio-builder-elementor/vulnerability/wordpress-elementor-portfolio-builder-plugin-1-0-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-jcw6-vg2q-7w8m/GHSA-jcw6-vg2q-7w8m.json b/advisories/unreviewed/2024/12/GHSA-jcw6-vg2q-7w8m/GHSA-jcw6-vg2q-7w8m.json new file mode 100644 index 00000000000..8669d278033 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-jcw6-vg2q-7w8m/GHSA-jcw6-vg2q-7w8m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jcw6-vg2q-7w8m", + "modified": "2024-12-02T15:31:38Z", + "published": "2024-12-02T15:31:38Z", + "aliases": [ + "CVE-2024-52460" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AtaraPay AtaraPay WooCommerce Payment Gateway allows Reflected XSS.This issue affects AtaraPay WooCommerce Payment Gateway: from n/a through 2.0.13.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52460" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/atarapay-woocommerce/vulnerability/wordpress-atarapay-woocommerce-payment-gateway-plugin-2-0-13-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-jmfh-cf2f-p74p/GHSA-jmfh-cf2f-p74p.json b/advisories/unreviewed/2024/12/GHSA-jmfh-cf2f-p74p/GHSA-jmfh-cf2f-p74p.json new file mode 100644 index 00000000000..d9e0ebc8495 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-jmfh-cf2f-p74p/GHSA-jmfh-cf2f-p74p.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jmfh-cf2f-p74p", + "modified": "2024-12-02T15:31:41Z", + "published": "2024-12-02T15:31:41Z", + "aliases": [ + "CVE-2024-46909" + ], + "details": "In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage this vulnerability to execute code in the context of the service account.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46909" + }, + { + "type": "WEB", + "url": "https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-September-2024" + }, + { + "type": "WEB", + "url": "https://docs.progress.com/bundle/whatsupgold-release-notes-24-0/page/WhatsUp-Gold-2024.0-Release-Notes.html" + }, + { + "type": "WEB", + "url": "https://www.progress.com/network-monitoring" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-jpmg-jp8c-8qpf/GHSA-jpmg-jp8c-8qpf.json b/advisories/unreviewed/2024/12/GHSA-jpmg-jp8c-8qpf/GHSA-jpmg-jp8c-8qpf.json new file mode 100644 index 00000000000..1ec72d2d757 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-jpmg-jp8c-8qpf/GHSA-jpmg-jp8c-8qpf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jpmg-jp8c-8qpf", + "modified": "2024-12-02T15:31:40Z", + "published": "2024-12-02T15:31:40Z", + "aliases": [ + "CVE-2024-53721" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stachethemes Advanced Event Manager allows Stored XSS.This issue affects Advanced Event Manager: from n/a through 1.1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53721" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/advanced-event-manager/vulnerability/wordpress-advanced-event-manager-plugin-1-1-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-jppf-x9c4-c8fj/GHSA-jppf-x9c4-c8fj.json b/advisories/unreviewed/2024/12/GHSA-jppf-x9c4-c8fj/GHSA-jppf-x9c4-c8fj.json new file mode 100644 index 00000000000..6c7e94c1777 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-jppf-x9c4-c8fj/GHSA-jppf-x9c4-c8fj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jppf-x9c4-c8fj", + "modified": "2024-12-02T15:31:39Z", + "published": "2024-12-02T15:31:39Z", + "aliases": [ + "CVE-2024-53707" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Ahmet İmamoğlu Ahmeti Wp Güzel Sözler allows Cross Site Request Forgery.This issue affects Ahmeti Wp Güzel Sözler: from n/a through 4.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53707" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ahmeti-wp-guzel-sozler/vulnerability/wordpress-ahmeti-wp-guezel-soezler-plugin-4-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-jrw9-qmpm-pwvq/GHSA-jrw9-qmpm-pwvq.json b/advisories/unreviewed/2024/12/GHSA-jrw9-qmpm-pwvq/GHSA-jrw9-qmpm-pwvq.json new file mode 100644 index 00000000000..d9212764939 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-jrw9-qmpm-pwvq/GHSA-jrw9-qmpm-pwvq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jrw9-qmpm-pwvq", + "modified": "2024-12-02T15:31:40Z", + "published": "2024-12-02T15:31:40Z", + "aliases": [ + "CVE-2024-53726" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Realty Candy RealtyCandy IDX Broker Extended allows Stored XSS.This issue affects RealtyCandy IDX Broker Extended: from n/a through 1.5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53726" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/realtycandy-idx-broker-extended/vulnerability/wordpress-realtycandy-idx-broker-extended-plugin-1-5-1-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-jw3v-5rhp-24pg/GHSA-jw3v-5rhp-24pg.json b/advisories/unreviewed/2024/12/GHSA-jw3v-5rhp-24pg/GHSA-jw3v-5rhp-24pg.json new file mode 100644 index 00000000000..05cdb4b5f43 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-jw3v-5rhp-24pg/GHSA-jw3v-5rhp-24pg.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jw3v-5rhp-24pg", + "modified": "2024-12-02T15:31:41Z", + "published": "2024-12-02T15:31:41Z", + "aliases": [ + "CVE-2024-46906" + ], + "details": "In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer permissions required) to achieve privilege escalation to the admin account.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46906" + }, + { + "type": "WEB", + "url": "https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-September-2024" + }, + { + "type": "WEB", + "url": "https://docs.progress.com/bundle/whatsupgold-release-notes-24-0/page/WhatsUp-Gold-2024.0-Release-Notes.html" + }, + { + "type": "WEB", + "url": "https://www.progress.com/network-monitoring" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-m4gw-f5hf-hh6w/GHSA-m4gw-f5hf-hh6w.json b/advisories/unreviewed/2024/12/GHSA-m4gw-f5hf-hh6w/GHSA-m4gw-f5hf-hh6w.json new file mode 100644 index 00000000000..3c5ad068dcb --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-m4gw-f5hf-hh6w/GHSA-m4gw-f5hf-hh6w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m4gw-f5hf-hh6w", + "modified": "2024-12-02T15:31:40Z", + "published": "2024-12-02T15:31:40Z", + "aliases": [ + "CVE-2024-53719" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in onigetoc Zajax – Ajax Navigation allows Stored XSS.This issue affects Zajax – Ajax Navigation: from n/a through 0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53719" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/zajax-ajax-navigation/vulnerability/wordpress-zajax-ajax-navigation-plugin-0-4-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-mc4m-5rw2-vpwv/GHSA-mc4m-5rw2-vpwv.json b/advisories/unreviewed/2024/12/GHSA-mc4m-5rw2-vpwv/GHSA-mc4m-5rw2-vpwv.json new file mode 100644 index 00000000000..354f716e7fe --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-mc4m-5rw2-vpwv/GHSA-mc4m-5rw2-vpwv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mc4m-5rw2-vpwv", + "modified": "2024-12-02T15:31:38Z", + "published": "2024-12-02T15:31:38Z", + "aliases": [ + "CVE-2024-52458" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Templines TM Islamic Helper allows Reflected XSS.This issue affects TM Islamic Helper: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52458" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/tm-islamic-helper/vulnerability/wordpress-tm-islamic-helper-plugin-1-0-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-mcc9-39v7-654c/GHSA-mcc9-39v7-654c.json b/advisories/unreviewed/2024/12/GHSA-mcc9-39v7-654c/GHSA-mcc9-39v7-654c.json new file mode 100644 index 00000000000..1137894a63e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-mcc9-39v7-654c/GHSA-mcc9-39v7-654c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mcc9-39v7-654c", + "modified": "2024-12-02T15:31:40Z", + "published": "2024-12-02T15:31:40Z", + "aliases": [ + "CVE-2024-53784" + ], + "details": "Missing Authorization vulnerability in E-goi Smart Marketing SMS and Newsletters Forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Smart Marketing SMS and Newsletters Forms: from n/a through 5.0.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53784" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/smart-marketing-for-wp/vulnerability/wordpress-smart-marketing-sms-and-newsletters-forms-plugin-5-0-9-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-mh5g-q2mv-4wjm/GHSA-mh5g-q2mv-4wjm.json b/advisories/unreviewed/2024/12/GHSA-mh5g-q2mv-4wjm/GHSA-mh5g-q2mv-4wjm.json new file mode 100644 index 00000000000..b11582f2555 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-mh5g-q2mv-4wjm/GHSA-mh5g-q2mv-4wjm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mh5g-q2mv-4wjm", + "modified": "2024-12-02T15:31:40Z", + "published": "2024-12-02T15:31:40Z", + "aliases": [ + "CVE-2024-53751" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Abdul Hakeem Build App Online allows Cross Site Request Forgery.This issue affects Build App Online: from n/a through 1.0.22.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53751" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/build-app-online/vulnerability/wordpress-build-app-online-plugin-1-0-22-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-mqhp-x4g6-p6qc/GHSA-mqhp-x4g6-p6qc.json b/advisories/unreviewed/2024/12/GHSA-mqhp-x4g6-p6qc/GHSA-mqhp-x4g6-p6qc.json new file mode 100644 index 00000000000..fce9cba05f1 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-mqhp-x4g6-p6qc/GHSA-mqhp-x4g6-p6qc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mqhp-x4g6-p6qc", + "modified": "2024-12-02T15:31:37Z", + "published": "2024-12-02T15:31:37Z", + "aliases": [ + "CVE-2024-52455" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GoQSystem Inc. GoQSmile allows Reflected XSS.This issue affects GoQSmile: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52455" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/goqsmile/vulnerability/wordpress-goqsmile-plugin-1-0-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-mv35-fc54-3wf7/GHSA-mv35-fc54-3wf7.json b/advisories/unreviewed/2024/12/GHSA-mv35-fc54-3wf7/GHSA-mv35-fc54-3wf7.json new file mode 100644 index 00000000000..6db1cfc2b23 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-mv35-fc54-3wf7/GHSA-mv35-fc54-3wf7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mv35-fc54-3wf7", + "modified": "2024-12-02T15:31:40Z", + "published": "2024-12-02T15:31:40Z", + "aliases": [ + "CVE-2024-53730" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Aaron Hodge Silver April's Call Posts allows Stored XSS.\n\nThis issue affects April's Call Posts: from n/a through 2.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53730" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/aprils-call-posts/vulnerability/wordpress-april-s-call-posts-plugin-2-1-1-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-p8p6-69x2-5wqg/GHSA-p8p6-69x2-5wqg.json b/advisories/unreviewed/2024/12/GHSA-p8p6-69x2-5wqg/GHSA-p8p6-69x2-5wqg.json new file mode 100644 index 00000000000..b77614b2192 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-p8p6-69x2-5wqg/GHSA-p8p6-69x2-5wqg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p8p6-69x2-5wqg", + "modified": "2024-12-02T15:31:38Z", + "published": "2024-12-02T15:31:38Z", + "aliases": [ + "CVE-2024-52494" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matt Varone, Tim Berneman Dynamic \"To Top\" allows Stored XSS.This issue affects Dynamic \"To Top\": from 3.5.2 through n/a.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52494" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/dynamic-to-top/vulnerability/wordpress-dynamic-to-top-plugin-3-5-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-pcg3-64vv-w6jf/GHSA-pcg3-64vv-w6jf.json b/advisories/unreviewed/2024/12/GHSA-pcg3-64vv-w6jf/GHSA-pcg3-64vv-w6jf.json new file mode 100644 index 00000000000..809217e6bd5 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-pcg3-64vv-w6jf/GHSA-pcg3-64vv-w6jf.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pcg3-64vv-w6jf", + "modified": "2024-12-02T15:31:41Z", + "published": "2024-12-02T15:31:41Z", + "aliases": [ + "CVE-2024-31669" + ], + "details": "rizin before Release v0.6.3 is vulnerable to Uncontrolled Resource Consumption via bin_pe_parse_imports, Pe_r_bin_pe_parse_var, and estimate_slide.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31669" + }, + { + "type": "WEB", + "url": "https://github.com/rizinorg/rizin/commit/e42999dda0be7737fafaf5e63c1c5833a72fd9c9" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Crispy-fried-chicken/fb9f7000f0517a085483f7f2a60f0f08" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-pffj-pwc5-gccm/GHSA-pffj-pwc5-gccm.json b/advisories/unreviewed/2024/12/GHSA-pffj-pwc5-gccm/GHSA-pffj-pwc5-gccm.json new file mode 100644 index 00000000000..cc736625e2c --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-pffj-pwc5-gccm/GHSA-pffj-pwc5-gccm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pffj-pwc5-gccm", + "modified": "2024-12-02T15:31:38Z", + "published": "2024-12-02T15:31:38Z", + "aliases": [ + "CVE-2024-52491" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sanil Shakya Sticky Social Icons allows Stored XSS.This issue affects Sticky Social Icons: from n/a through 1.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52491" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/sticky-social-icons/vulnerability/wordpress-sticky-social-icons-plugin-1-2-1-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-pxww-g48r-gw8m/GHSA-pxww-g48r-gw8m.json b/advisories/unreviewed/2024/12/GHSA-pxww-g48r-gw8m/GHSA-pxww-g48r-gw8m.json new file mode 100644 index 00000000000..8d7ce40549a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-pxww-g48r-gw8m/GHSA-pxww-g48r-gw8m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pxww-g48r-gw8m", + "modified": "2024-12-02T15:31:40Z", + "published": "2024-12-02T15:31:40Z", + "aliases": [ + "CVE-2024-53770" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Peter MacIntyre RingCentral Communications allows Stored XSS.This issue affects RingCentral Communications: from n/a through 1.6.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53770" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/rccp-free/vulnerability/wordpress-ringcentral-communications-plugin-1-6-1-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-q3cp-cq94-pqh3/GHSA-q3cp-cq94-pqh3.json b/advisories/unreviewed/2024/12/GHSA-q3cp-cq94-pqh3/GHSA-q3cp-cq94-pqh3.json new file mode 100644 index 00000000000..7c51056853b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-q3cp-cq94-pqh3/GHSA-q3cp-cq94-pqh3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q3cp-cq94-pqh3", + "modified": "2024-12-02T15:31:40Z", + "published": "2024-12-02T15:31:40Z", + "aliases": [ + "CVE-2024-53722" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Rockemmusic Favicon My Blog allows Stored XSS.This issue affects Favicon My Blog: from n/a through 1.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53722" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/favicon-my-blog/vulnerability/wordpress-favicon-my-blog-plugin-1-0-2-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-q3v6-hm2v-pw99/GHSA-q3v6-hm2v-pw99.json b/advisories/unreviewed/2024/12/GHSA-q3v6-hm2v-pw99/GHSA-q3v6-hm2v-pw99.json new file mode 100644 index 00000000000..1242f8d81b6 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-q3v6-hm2v-pw99/GHSA-q3v6-hm2v-pw99.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q3v6-hm2v-pw99", + "modified": "2024-12-02T15:31:41Z", + "published": "2024-12-02T15:31:41Z", + "aliases": [ + "CVE-2024-38827" + ], + "details": "The usage of String.toLowerCase() and String.toUpperCase() has some Locale dependent exceptions that could potentially result in authorization rules not working properly.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38827" + }, + { + "type": "WEB", + "url": "https://spring.io/security/cve-2024-38827" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-q56w-m7h5-j43f/GHSA-q56w-m7h5-j43f.json b/advisories/unreviewed/2024/12/GHSA-q56w-m7h5-j43f/GHSA-q56w-m7h5-j43f.json new file mode 100644 index 00000000000..3e506cd8ef3 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-q56w-m7h5-j43f/GHSA-q56w-m7h5-j43f.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q56w-m7h5-j43f", + "modified": "2024-12-02T15:31:39Z", + "published": "2024-12-02T15:31:39Z", + "aliases": [ + "CVE-2024-53111" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/mremap: fix address wraparound in move_page_tables()\n\nOn 32-bit platforms, it is possible for the expression `len + old_addr <\nold_end` to be false-positive if `len + old_addr` wraps around. \n`old_addr` is the cursor in the old range up to which page table entries\nhave been moved; so if the operation succeeded, `old_addr` is the *end* of\nthe old region, and adding `len` to it can wrap.\n\nThe overflow causes mremap() to mistakenly believe that PTEs have been\ncopied; the consequence is that mremap() bails out, but doesn't move the\nPTEs back before the new VMA is unmapped, causing anonymous pages in the\nregion to be lost. So basically if userspace tries to mremap() a\nprivate-anon region and hits this bug, mremap() will return an error and\nthe private-anon region's contents appear to have been zeroed.\n\nThe idea of this check is that `old_end - len` is the original start\naddress, and writing the check that way also makes it easier to read; so\nfix the check by rearranging the comparison accordingly.\n\n(An alternate fix would be to refactor this function by introducing an\n\"orig_old_start\" variable or such.)\n\n\nTested in a VM with a 32-bit X86 kernel; without the patch:\n\n```\nuser@horn:~/big_mremap$ cat test.c\n#define _GNU_SOURCE\n#include \n#include \n#include \n#include \n\n#define ADDR1 ((void*)0x60000000)\n#define ADDR2 ((void*)0x10000000)\n#define SIZE 0x50000000uL\n\nint main(void) {\n unsigned char *p1 = mmap(ADDR1, SIZE, PROT_READ|PROT_WRITE,\n MAP_ANONYMOUS|MAP_PRIVATE|MAP_FIXED_NOREPLACE, -1, 0);\n if (p1 == MAP_FAILED)\n err(1, \"mmap 1\");\n unsigned char *p2 = mmap(ADDR2, SIZE, PROT_NONE,\n MAP_ANONYMOUS|MAP_PRIVATE|MAP_FIXED_NOREPLACE, -1, 0);\n if (p2 == MAP_FAILED)\n err(1, \"mmap 2\");\n *p1 = 0x41;\n printf(\"first char is 0x%02hhx\\n\", *p1);\n unsigned char *p3 = mremap(p1, SIZE, SIZE,\n MREMAP_MAYMOVE|MREMAP_FIXED, p2);\n if (p3 == MAP_FAILED) {\n printf(\"mremap() failed; first char is 0x%02hhx\\n\", *p1);\n } else {\n printf(\"mremap() succeeded; first char is 0x%02hhx\\n\", *p3);\n }\n}\nuser@horn:~/big_mremap$ gcc -static -o test test.c\nuser@horn:~/big_mremap$ setarch -R ./test\nfirst char is 0x41\nmremap() failed; first char is 0x00\n```\n\nWith the patch:\n\n```\nuser@horn:~/big_mremap$ setarch -R ./test\nfirst char is 0x41\nmremap() succeeded; first char is 0x41\n```", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53111" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/909543dc279a91122fb08e4653a72b82f0ad28f4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a4a282daf1a190f03790bf163458ea3c8d28d217" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-q6p5-37cf-777r/GHSA-q6p5-37cf-777r.json b/advisories/unreviewed/2024/12/GHSA-q6p5-37cf-777r/GHSA-q6p5-37cf-777r.json new file mode 100644 index 00000000000..58357548a8c --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-q6p5-37cf-777r/GHSA-q6p5-37cf-777r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q6p5-37cf-777r", + "modified": "2024-12-02T15:31:40Z", + "published": "2024-12-02T15:31:40Z", + "aliases": [ + "CVE-2024-53725" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Script-Recipes Post Hits Counter allows Reflected XSS.This issue affects Post Hits Counter: from n/a through 2.8.23.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53725" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/hits-counter/vulnerability/wordpress-post-hits-counter-plugin-2-8-23-csrf-to-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-q9wp-2pp6-j742/GHSA-q9wp-2pp6-j742.json b/advisories/unreviewed/2024/12/GHSA-q9wp-2pp6-j742/GHSA-q9wp-2pp6-j742.json new file mode 100644 index 00000000000..fcb601d8344 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-q9wp-2pp6-j742/GHSA-q9wp-2pp6-j742.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q9wp-2pp6-j742", + "modified": "2024-12-02T15:31:37Z", + "published": "2024-12-02T15:31:37Z", + "aliases": [ + "CVE-2024-51900" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Richard K Miller What Would Seth Godin Do allows Stored XSS.This issue affects What Would Seth Godin Do: from n/a through 2.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51900" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/what-would-seth-godin-do/vulnerability/wordpress-what-would-seth-godin-do-plugin-2-1-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-qh5c-j5qq-2c7h/GHSA-qh5c-j5qq-2c7h.json b/advisories/unreviewed/2024/12/GHSA-qh5c-j5qq-2c7h/GHSA-qh5c-j5qq-2c7h.json new file mode 100644 index 00000000000..cda0f7feeff --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-qh5c-j5qq-2c7h/GHSA-qh5c-j5qq-2c7h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qh5c-j5qq-2c7h", + "modified": "2024-12-02T15:31:38Z", + "published": "2024-12-02T15:31:38Z", + "aliases": [ + "CVE-2024-52469" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dhrubok Infotech WooCommerce Price Alert allows Reflected XSS.This issue affects WooCommerce Price Alert: from n/a through 1.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52469" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/price-alert-woocommerce/vulnerability/wordpress-woocommerce-price-alert-plugin-1-0-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-qpmh-748w-8f69/GHSA-qpmh-748w-8f69.json b/advisories/unreviewed/2024/12/GHSA-qpmh-748w-8f69/GHSA-qpmh-748w-8f69.json new file mode 100644 index 00000000000..d6b902372a6 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-qpmh-748w-8f69/GHSA-qpmh-748w-8f69.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qpmh-748w-8f69", + "modified": "2024-12-02T15:31:40Z", + "published": "2024-12-02T15:31:39Z", + "aliases": [ + "CVE-2024-53716" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in overtrue wp auto top allows Stored XSS.This issue affects wp auto top: from n/a through 2.9.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53716" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-auto-top/vulnerability/wordpress-wp-auto-top-plugin-2-9-3-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-qq4j-h75v-549m/GHSA-qq4j-h75v-549m.json b/advisories/unreviewed/2024/12/GHSA-qq4j-h75v-549m/GHSA-qq4j-h75v-549m.json new file mode 100644 index 00000000000..e30921c7f3d --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-qq4j-h75v-549m/GHSA-qq4j-h75v-549m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qq4j-h75v-549m", + "modified": "2024-12-02T15:31:40Z", + "published": "2024-12-02T15:31:40Z", + "aliases": [ + "CVE-2024-53765" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Think201 Mins To Read allows Stored XSS.This issue affects Mins To Read: from n/a through 1.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53765" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mins-to-read/vulnerability/wordpress-mins-to-read-plugin-1-2-2-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-qqqc-4q63-44f9/GHSA-qqqc-4q63-44f9.json b/advisories/unreviewed/2024/12/GHSA-qqqc-4q63-44f9/GHSA-qqqc-4q63-44f9.json new file mode 100644 index 00000000000..560266517e2 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-qqqc-4q63-44f9/GHSA-qqqc-4q63-44f9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qqqc-4q63-44f9", + "modified": "2024-12-02T15:31:37Z", + "published": "2024-12-02T15:31:37Z", + "aliases": [ + "CVE-2024-52456" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPoets Awesome Studio allows Reflected XSS.This issue affects Awesome Studio: from n/a through 2.4.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52456" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/awesome-studio/vulnerability/wordpress-awesome-studio-plugin-2-4-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-qvq9-g9g9-hm4j/GHSA-qvq9-g9g9-hm4j.json b/advisories/unreviewed/2024/12/GHSA-qvq9-g9g9-hm4j/GHSA-qvq9-g9g9-hm4j.json new file mode 100644 index 00000000000..96af34f7039 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-qvq9-g9g9-hm4j/GHSA-qvq9-g9g9-hm4j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qvq9-g9g9-hm4j", + "modified": "2024-12-02T15:31:38Z", + "published": "2024-12-02T15:31:38Z", + "aliases": [ + "CVE-2024-52459" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chameleoni.com Chameleoni Jobs allows Reflected XSS.This issue affects Chameleoni Jobs: from n/a through 2.5.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52459" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/chameleon-jobs/vulnerability/wordpress-chameleoni-jobs-plugin-2-5-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-r39w-239v-ph4m/GHSA-r39w-239v-ph4m.json b/advisories/unreviewed/2024/12/GHSA-r39w-239v-ph4m/GHSA-r39w-239v-ph4m.json new file mode 100644 index 00000000000..a3426ca33d7 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-r39w-239v-ph4m/GHSA-r39w-239v-ph4m.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r39w-239v-ph4m", + "modified": "2024-12-02T15:31:41Z", + "published": "2024-12-02T15:31:41Z", + "aliases": [ + "CVE-2024-46908" + ], + "details": "In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer permissions required)\n\n to achieve privilege escalation to the admin account.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46908" + }, + { + "type": "WEB", + "url": "https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-September-2024" + }, + { + "type": "WEB", + "url": "https://docs.progress.com/bundle/whatsupgold-release-notes-24-0/page/WhatsUp-Gold-2024.0-Release-Notes.html" + }, + { + "type": "WEB", + "url": "https://www.progress.com/network-monitoring" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-r3gq-2g92-5q88/GHSA-r3gq-2g92-5q88.json b/advisories/unreviewed/2024/12/GHSA-r3gq-2g92-5q88/GHSA-r3gq-2g92-5q88.json new file mode 100644 index 00000000000..62002deb98c --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-r3gq-2g92-5q88/GHSA-r3gq-2g92-5q88.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r3gq-2g92-5q88", + "modified": "2024-12-02T15:31:38Z", + "published": "2024-12-02T15:31:38Z", + "aliases": [ + "CVE-2024-52479" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Ben Marshall Jobify - Job Board WordPress Theme allows Cross Site Request Forgery.This issue affects Jobify - Job Board WordPress Theme: from n/a through 4.2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52479" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/jobify/vulnerability/wordpress-jobify-plugin-4-2-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-r5hg-qhj7-r89w/GHSA-r5hg-qhj7-r89w.json b/advisories/unreviewed/2024/12/GHSA-r5hg-qhj7-r89w/GHSA-r5hg-qhj7-r89w.json new file mode 100644 index 00000000000..eb648b03769 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-r5hg-qhj7-r89w/GHSA-r5hg-qhj7-r89w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r5hg-qhj7-r89w", + "modified": "2024-12-02T15:31:40Z", + "published": "2024-12-02T15:31:40Z", + "aliases": [ + "CVE-2024-53762" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Faster Themes FastBook – Responsive Appointment Booking and Scheduling System allows Stored XSS.This issue affects FastBook – Responsive Appointment Booking and Scheduling System: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53762" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/fastbook-responsive-appointment-booking-and-scheduling-system/vulnerability/wordpress-fastbook-plugin-1-1-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-r6cg-rqqp-3rqx/GHSA-r6cg-rqqp-3rqx.json b/advisories/unreviewed/2024/12/GHSA-r6cg-rqqp-3rqx/GHSA-r6cg-rqqp-3rqx.json new file mode 100644 index 00000000000..1bcd075d8d6 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-r6cg-rqqp-3rqx/GHSA-r6cg-rqqp-3rqx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r6cg-rqqp-3rqx", + "modified": "2024-12-02T15:31:37Z", + "published": "2024-12-02T15:31:37Z", + "aliases": [ + "CVE-2024-12015" + ], + "details": "The 'Project Manager' WordPress Plugin is affected by an authenticated SQL injection vulnerability in the 'orderby' parameter in the '/pm/v2/activites' route.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12015" + }, + { + "type": "WEB", + "url": "https://www.tenable.com/security/research/tra-2024-47" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-rccm-3mp2-xc76/GHSA-rccm-3mp2-xc76.json b/advisories/unreviewed/2024/12/GHSA-rccm-3mp2-xc76/GHSA-rccm-3mp2-xc76.json new file mode 100644 index 00000000000..a34801ad007 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-rccm-3mp2-xc76/GHSA-rccm-3mp2-xc76.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rccm-3mp2-xc76", + "modified": "2024-12-02T15:31:40Z", + "published": "2024-12-02T15:31:40Z", + "aliases": [ + "CVE-2024-53777" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Alberto Reineri Simple Header and Footer allows Stored XSS.This issue affects Simple Header and Footer: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53777" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/simple-header-and-footer/vulnerability/wordpress-simple-header-and-footer-plugin-1-0-0-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-rgw8-cw3p-qv66/GHSA-rgw8-cw3p-qv66.json b/advisories/unreviewed/2024/12/GHSA-rgw8-cw3p-qv66/GHSA-rgw8-cw3p-qv66.json new file mode 100644 index 00000000000..a4817b362a6 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-rgw8-cw3p-qv66/GHSA-rgw8-cw3p-qv66.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rgw8-cw3p-qv66", + "modified": "2024-12-02T15:31:39Z", + "published": "2024-12-02T15:31:39Z", + "aliases": [ + "CVE-2024-53114" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/CPU/AMD: Clear virtualized VMLOAD/VMSAVE on Zen4 client\n\nA number of Zen4 client SoCs advertise the ability to use virtualized\nVMLOAD/VMSAVE, but using these instructions is reported to be a cause\nof a random host reboot.\n\nThese instructions aren't intended to be advertised on Zen4 client\nso clear the capability.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53114" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/00c713f84f477a85e524f34aad8fbd11a1c051f0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a5ca1dc46a6b610dd4627d8b633d6c84f9724ef0" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-rpw2-v8gh-jmm4/GHSA-rpw2-v8gh-jmm4.json b/advisories/unreviewed/2024/12/GHSA-rpw2-v8gh-jmm4/GHSA-rpw2-v8gh-jmm4.json new file mode 100644 index 00000000000..f9c96d374c8 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-rpw2-v8gh-jmm4/GHSA-rpw2-v8gh-jmm4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rpw2-v8gh-jmm4", + "modified": "2024-12-02T15:31:40Z", + "published": "2024-12-02T15:31:40Z", + "aliases": [ + "CVE-2024-53720" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in ole1986 , MachineITSvcs WP-ISPConfig 3 allows Stored XSS.This issue affects WP-ISPConfig 3: from n/a through 1.5.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53720" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-ispconfig3/vulnerability/wordpress-wp-ispconfig-3-plugin-1-5-6-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-v2jr-j357-jwhf/GHSA-v2jr-j357-jwhf.json b/advisories/unreviewed/2024/12/GHSA-v2jr-j357-jwhf/GHSA-v2jr-j357-jwhf.json new file mode 100644 index 00000000000..2fc61c3e066 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-v2jr-j357-jwhf/GHSA-v2jr-j357-jwhf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v2jr-j357-jwhf", + "modified": "2024-12-02T15:31:38Z", + "published": "2024-12-02T15:31:38Z", + "aliases": [ + "CVE-2024-52466" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Explara Explara Events allows Reflected XSS.This issue affects Explara Events: from n/a through 0.1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52466" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/explara-events/vulnerability/wordpress-explara-events-plugin-0-1-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-vjc9-5qjq-847w/GHSA-vjc9-5qjq-847w.json b/advisories/unreviewed/2024/12/GHSA-vjc9-5qjq-847w/GHSA-vjc9-5qjq-847w.json new file mode 100644 index 00000000000..028a5c70df3 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-vjc9-5qjq-847w/GHSA-vjc9-5qjq-847w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vjc9-5qjq-847w", + "modified": "2024-12-02T15:31:40Z", + "published": "2024-12-02T15:31:40Z", + "aliases": [ + "CVE-2024-53740" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WooCommerce Ultimate Gift Card - Create, Sell and Manage Gift Cards with Customized Email Templates allows Reflected XSS.This issue affects WooCommerce Ultimate Gift Card - Create, Sell and Manage Gift Cards with Customized Email Templates: from n/a through n/a.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53740" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woocommerce-ultimate-gift-card/vulnerability/wordpress-woocommerce-ultimate-gift-card-plugin-2-9-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-vr58-5gj9-563m/GHSA-vr58-5gj9-563m.json b/advisories/unreviewed/2024/12/GHSA-vr58-5gj9-563m/GHSA-vr58-5gj9-563m.json new file mode 100644 index 00000000000..454aec6d4a6 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-vr58-5gj9-563m/GHSA-vr58-5gj9-563m.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vr58-5gj9-563m", + "modified": "2024-12-02T15:31:39Z", + "published": "2024-12-02T15:31:39Z", + "aliases": [ + "CVE-2024-53116" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/panthor: Fix handling of partial GPU mapping of BOs\n\nThis commit fixes the bug in the handling of partial mapping of the\nbuffer objects to the GPU, which caused kernel warnings.\n\nPanthor didn't correctly handle the case where the partial mapping\nspanned multiple scatterlists and the mapping offset didn't point\nto the 1st page of starting scatterlist. The offset variable was\nnot cleared after reaching the starting scatterlist.\n\nFollowing warning messages were seen.\nWARNING: CPU: 1 PID: 650 at drivers/iommu/io-pgtable-arm.c:659 __arm_lpae_unmap+0x254/0x5a0\n\npc : __arm_lpae_unmap+0x254/0x5a0\nlr : __arm_lpae_unmap+0x2cc/0x5a0\n\nCall trace:\n __arm_lpae_unmap+0x254/0x5a0\n __arm_lpae_unmap+0x108/0x5a0\n __arm_lpae_unmap+0x108/0x5a0\n __arm_lpae_unmap+0x108/0x5a0\n arm_lpae_unmap_pages+0x80/0xa0\n panthor_vm_unmap_pages+0xac/0x1c8 [panthor]\n panthor_gpuva_sm_step_unmap+0x4c/0xc8 [panthor]\n op_unmap_cb.isra.23.constprop.30+0x54/0x80\n __drm_gpuvm_sm_unmap+0x184/0x1c8\n drm_gpuvm_sm_unmap+0x40/0x60\n panthor_vm_exec_op+0xa8/0x120 [panthor]\n panthor_vm_bind_exec_sync_op+0xc4/0xe8 [panthor]\n panthor_ioctl_vm_bind+0x10c/0x170 [panthor]\n drm_ioctl_kernel+0xbc/0x138\n drm_ioctl+0x210/0x4b0\n __arm64_sys_ioctl+0xb0/0xf8\n invoke_syscall+0x4c/0x110\n el0_svc_common.constprop.1+0x98/0xf8\n do_el0_svc+0x24/0x38\n el0_svc+0x34/0xc8\n el0t_64_sync_handler+0xa0/0xc8\n el0t_64_sync+0x174/0x178\n\npanthor : [drm] drm_WARN_ON(unmapped_sz != pgsize * pgcount)\nWARNING: CPU: 1 PID: 650 at drivers/gpu/drm/panthor/panthor_mmu.c:922 panthor_vm_unmap_pages+0x124/0x1c8 [panthor]\n\npc : panthor_vm_unmap_pages+0x124/0x1c8 [panthor]\nlr : panthor_vm_unmap_pages+0x124/0x1c8 [panthor]\n\npanthor : [drm] *ERROR* failed to unmap range ffffa388f000-ffffa3890000 (requested range ffffa388c000-ffffa3890000)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53116" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3387e043918e154ca08d83954966a8b087fe2835" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d3e61af64b770e0038470c81f42bd1d0598f6bcc" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-vw9h-3h3h-jf8m/GHSA-vw9h-3h3h-jf8m.json b/advisories/unreviewed/2024/12/GHSA-vw9h-3h3h-jf8m/GHSA-vw9h-3h3h-jf8m.json new file mode 100644 index 00000000000..aaea25223aa --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-vw9h-3h3h-jf8m/GHSA-vw9h-3h3h-jf8m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vw9h-3h3h-jf8m", + "modified": "2024-12-02T15:31:40Z", + "published": "2024-12-02T15:31:40Z", + "aliases": [ + "CVE-2024-53729" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Plumeria Web Design Blizzard Quotes allows Stored XSS.This issue affects Blizzard Quotes: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53729" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/blizzard-quotes/vulnerability/wordpress-blizzard-quotes-plugin-1-3-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-vxwr-85cg-x3pq/GHSA-vxwr-85cg-x3pq.json b/advisories/unreviewed/2024/12/GHSA-vxwr-85cg-x3pq/GHSA-vxwr-85cg-x3pq.json new file mode 100644 index 00000000000..189393cf772 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-vxwr-85cg-x3pq/GHSA-vxwr-85cg-x3pq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vxwr-85cg-x3pq", + "modified": "2024-12-02T15:31:40Z", + "published": "2024-12-02T15:31:40Z", + "aliases": [ + "CVE-2024-53728" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in SEO-Küche Internet Marketing GmbH & Co. KG Protect Your Content allows Stored XSS.This issue affects Protect Your Content: from n/a through 1.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53728" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/protect-your-content/vulnerability/wordpress-protect-your-content-plugin-1-0-2-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-w78w-44c5-7mwx/GHSA-w78w-44c5-7mwx.json b/advisories/unreviewed/2024/12/GHSA-w78w-44c5-7mwx/GHSA-w78w-44c5-7mwx.json new file mode 100644 index 00000000000..4f3ab7ad814 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-w78w-44c5-7mwx/GHSA-w78w-44c5-7mwx.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w78w-44c5-7mwx", + "modified": "2024-12-02T15:31:39Z", + "published": "2024-12-02T15:31:39Z", + "aliases": [ + "CVE-2024-53110" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvp_vdpa: fix id_table array not null terminated error\n\nAllocate one extra virtio_device_id as null terminator, otherwise\nvdpa_mgmtdev_get_classes() may iterate multiple times and visit\nundefined memory.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53110" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0a886489d274596ad1a80789d3a773503210a615" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4e39ecadf1d2a08187139619f1f314b64ba7d947" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/870d68fe17b5d9032049dcad98b5781a344a8657" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c4d64534d4b1c47d2f1ce427497f971ad4735aae" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-w9xm-h8j7-2chv/GHSA-w9xm-h8j7-2chv.json b/advisories/unreviewed/2024/12/GHSA-w9xm-h8j7-2chv/GHSA-w9xm-h8j7-2chv.json new file mode 100644 index 00000000000..65c00c37f0d --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-w9xm-h8j7-2chv/GHSA-w9xm-h8j7-2chv.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w9xm-h8j7-2chv", + "modified": "2024-12-02T15:31:39Z", + "published": "2024-12-02T15:31:39Z", + "aliases": [ + "CVE-2024-53106" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nima: fix buffer overrun in ima_eventdigest_init_common\n\nFunction ima_eventdigest_init() calls ima_eventdigest_init_common()\nwith HASH_ALGO__LAST which is then used to access the array\nhash_digest_size[] leading to buffer overrun. Have a conditional\nstatement to handle this.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53106" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1ecf0df5205cfb0907eb7984b8671257965a5232" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8a84765c62cc0469864e2faee43aae253ad16082" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/923168a0631bc42fffd55087b337b1b6c54dcff5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e01aae58e818503f2ffcd34c6f7dc6f90af1057e" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-wm7m-wv4x-65rq/GHSA-wm7m-wv4x-65rq.json b/advisories/unreviewed/2024/12/GHSA-wm7m-wv4x-65rq/GHSA-wm7m-wv4x-65rq.json new file mode 100644 index 00000000000..f2cd4c5b7c8 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-wm7m-wv4x-65rq/GHSA-wm7m-wv4x-65rq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wm7m-wv4x-65rq", + "modified": "2024-12-02T15:31:38Z", + "published": "2024-12-02T15:31:38Z", + "aliases": [ + "CVE-2024-52487" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebCodingPlace Ultimate Classified Listings allows Stored XSS.This issue affects Ultimate Classified Listings: from n/a through 1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52487" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ultimate-classified-listings/vulnerability/wordpress-ultimate-classified-listings-plugin-1-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-x27c-942p-5cpj/GHSA-x27c-942p-5cpj.json b/advisories/unreviewed/2024/12/GHSA-x27c-942p-5cpj/GHSA-x27c-942p-5cpj.json new file mode 100644 index 00000000000..93901fc0c77 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-x27c-942p-5cpj/GHSA-x27c-942p-5cpj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x27c-942p-5cpj", + "modified": "2024-12-02T15:31:38Z", + "published": "2024-12-02T15:31:38Z", + "aliases": [ + "CVE-2024-52478" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ben Marshall Jobify - Job Board WordPress Theme allows Stored XSS.This issue affects Jobify - Job Board WordPress Theme: from n/a through 4.2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52478" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/jobify/vulnerability/wordpress-jobify-theme-4-2-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-x34g-xjxv-fc48/GHSA-x34g-xjxv-fc48.json b/advisories/unreviewed/2024/12/GHSA-x34g-xjxv-fc48/GHSA-x34g-xjxv-fc48.json new file mode 100644 index 00000000000..2fff0ed3b99 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-x34g-xjxv-fc48/GHSA-x34g-xjxv-fc48.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x34g-xjxv-fc48", + "modified": "2024-12-02T15:31:39Z", + "published": "2024-12-02T15:31:39Z", + "aliases": [ + "CVE-2024-53122" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: cope racing subflow creation in mptcp_rcv_space_adjust\n\nAdditional active subflows - i.e. created by the in kernel path\nmanager - are included into the subflow list before starting the\n3whs.\n\nA racing recvmsg() spooling data received on an already established\nsubflow would unconditionally call tcp_cleanup_rbuf() on all the\ncurrent subflows, potentially hitting a divide by zero error on\nthe newly created ones.\n\nExplicitly check that the subflow is in a suitable state before\ninvoking tcp_cleanup_rbuf().", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53122" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/24995851d58c4a205ad0ffa7b2f21e479a9c8527" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/aad6412c63baa39dd813e81f16a14d976b3de2e8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ce7356ae35943cc6494cc692e62d51a734062b7d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ff825ab2f455299c0c7287550915a8878e2a66e0" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-xffh-3x24-mr3c/GHSA-xffh-3x24-mr3c.json b/advisories/unreviewed/2024/12/GHSA-xffh-3x24-mr3c/GHSA-xffh-3x24-mr3c.json new file mode 100644 index 00000000000..8bf8f8d9337 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-xffh-3x24-mr3c/GHSA-xffh-3x24-mr3c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xffh-3x24-mr3c", + "modified": "2024-12-02T15:31:40Z", + "published": "2024-12-02T15:31:40Z", + "aliases": [ + "CVE-2024-53741" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Garrett Grimm Simple Popup allows DOM-Based XSS.This issue affects Simple Popup: from n/a through 4.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53741" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/simple-popup-plugin/vulnerability/wordpress-simple-popup-plugin-4-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-xmr8-m3g7-8q7w/GHSA-xmr8-m3g7-8q7w.json b/advisories/unreviewed/2024/12/GHSA-xmr8-m3g7-8q7w/GHSA-xmr8-m3g7-8q7w.json new file mode 100644 index 00000000000..9096ef4ba92 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-xmr8-m3g7-8q7w/GHSA-xmr8-m3g7-8q7w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xmr8-m3g7-8q7w", + "modified": "2024-12-02T15:31:39Z", + "published": "2024-12-02T15:31:39Z", + "aliases": [ + "CVE-2024-53712" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Kevin McCabe Kevin's allows Stored XSS.This issue affects Kevin's: from n/a through 2.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53712" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/kevins-plugin/vulnerability/wordpress-kevin-s-plugin-2-0-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T14:15:14Z" + } +} \ No newline at end of file