diff --git a/advisories/unreviewed/2024/04/GHSA-2p97-c8vf-r4rf/GHSA-2p97-c8vf-r4rf.json b/advisories/unreviewed/2024/04/GHSA-2p97-c8vf-r4rf/GHSA-2p97-c8vf-r4rf.json index 040f4f84e8b..408c0ddeffe 100644 --- a/advisories/unreviewed/2024/04/GHSA-2p97-c8vf-r4rf/GHSA-2p97-c8vf-r4rf.json +++ b/advisories/unreviewed/2024/04/GHSA-2p97-c8vf-r4rf/GHSA-2p97-c8vf-r4rf.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-276", "CWE-277" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/04/GHSA-f636-m6gc-99ch/GHSA-f636-m6gc-99ch.json b/advisories/unreviewed/2024/04/GHSA-f636-m6gc-99ch/GHSA-f636-m6gc-99ch.json index bf6f847f1d2..8a1d78fc584 100644 --- a/advisories/unreviewed/2024/04/GHSA-f636-m6gc-99ch/GHSA-f636-m6gc-99ch.json +++ b/advisories/unreviewed/2024/04/GHSA-f636-m6gc-99ch/GHSA-f636-m6gc-99ch.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-276", "CWE-277" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/04/GHSA-gpf5-g943-4fxx/GHSA-gpf5-g943-4fxx.json b/advisories/unreviewed/2024/04/GHSA-gpf5-g943-4fxx/GHSA-gpf5-g943-4fxx.json index 6415b6d88a1..a6c9be03517 100644 --- a/advisories/unreviewed/2024/04/GHSA-gpf5-g943-4fxx/GHSA-gpf5-g943-4fxx.json +++ b/advisories/unreviewed/2024/04/GHSA-gpf5-g943-4fxx/GHSA-gpf5-g943-4fxx.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-639" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-pfrw-8j6p-xmx6/GHSA-pfrw-8j6p-xmx6.json b/advisories/unreviewed/2024/04/GHSA-pfrw-8j6p-xmx6/GHSA-pfrw-8j6p-xmx6.json index fd9ce8ffe28..2748c5e2863 100644 --- a/advisories/unreviewed/2024/04/GHSA-pfrw-8j6p-xmx6/GHSA-pfrw-8j6p-xmx6.json +++ b/advisories/unreviewed/2024/04/GHSA-pfrw-8j6p-xmx6/GHSA-pfrw-8j6p-xmx6.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-wgrq-q2w8-p9x4/GHSA-wgrq-q2w8-p9x4.json b/advisories/unreviewed/2024/04/GHSA-wgrq-q2w8-p9x4/GHSA-wgrq-q2w8-p9x4.json index 45b85566163..96c720af038 100644 --- a/advisories/unreviewed/2024/04/GHSA-wgrq-q2w8-p9x4/GHSA-wgrq-q2w8-p9x4.json +++ b/advisories/unreviewed/2024/04/GHSA-wgrq-q2w8-p9x4/GHSA-wgrq-q2w8-p9x4.json @@ -36,7 +36,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-125" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-wxvv-7x57-mjgj/GHSA-wxvv-7x57-mjgj.json b/advisories/unreviewed/2024/04/GHSA-wxvv-7x57-mjgj/GHSA-wxvv-7x57-mjgj.json index 150ed9e7cb9..c228e8e5ee1 100644 --- a/advisories/unreviewed/2024/04/GHSA-wxvv-7x57-mjgj/GHSA-wxvv-7x57-mjgj.json +++ b/advisories/unreviewed/2024/04/GHSA-wxvv-7x57-mjgj/GHSA-wxvv-7x57-mjgj.json @@ -36,7 +36,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-125" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-2c45-cjxr-vcxq/GHSA-2c45-cjxr-vcxq.json b/advisories/unreviewed/2024/10/GHSA-2c45-cjxr-vcxq/GHSA-2c45-cjxr-vcxq.json new file mode 100644 index 00000000000..cbb844a1e57 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-2c45-cjxr-vcxq/GHSA-2c45-cjxr-vcxq.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2c45-cjxr-vcxq", + "modified": "2024-10-28T15:31:16Z", + "published": "2024-10-28T15:31:16Z", + "aliases": [ + "CVE-2024-10450" + ], + "details": "A vulnerability has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /kortex_lite/control/edit_profile.php of the component POST Parameter Handler. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10450" + }, + { + "type": "WEB", + "url": "https://github.com/will121351/wenqin.webray.com.cn/blob/main/CVE-project/Advocate-office-management-system.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.282010" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.282010" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.432614" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-28T15:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-2mm8-fp6h-xwmf/GHSA-2mm8-fp6h-xwmf.json b/advisories/unreviewed/2024/10/GHSA-2mm8-fp6h-xwmf/GHSA-2mm8-fp6h-xwmf.json new file mode 100644 index 00000000000..53cd135bf21 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-2mm8-fp6h-xwmf/GHSA-2mm8-fp6h-xwmf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2mm8-fp6h-xwmf", + "modified": "2024-10-28T15:31:14Z", + "published": "2024-10-28T15:31:14Z", + "aliases": [ + "CVE-2024-50479" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mansur Ahamed Woocommerce Quote Calculator allows Blind SQL Injection.This issue affects Woocommerce Quote Calculator: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50479" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/woo-quote-calculator-order/wordpress-woocommerce-quote-calculator-plugin-1-1-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-28T13:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-36c4-85vg-5q9w/GHSA-36c4-85vg-5q9w.json b/advisories/unreviewed/2024/10/GHSA-36c4-85vg-5q9w/GHSA-36c4-85vg-5q9w.json new file mode 100644 index 00000000000..61e3840e048 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-36c4-85vg-5q9w/GHSA-36c4-85vg-5q9w.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-36c4-85vg-5q9w", + "modified": "2024-10-28T15:31:13Z", + "published": "2024-10-28T15:31:13Z", + "aliases": [ + "CVE-2024-10447" + ], + "details": "A vulnerability classified as critical was found in Project Worlds Online Time Table Generator 1.0. Affected by this vulnerability is an unknown functionality of the file /timetable/staff/staffdashboard.php?info=updateprofile. The manipulation of the argument n leads to sql injection. The attack can be launched remotely.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10447" + }, + { + "type": "WEB", + "url": "https://github.com/jadu101/CVE/blob/main/project_worlds_online_time_table_generator_update_profile_sqli.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.282007" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.282007" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.432372" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-28T13:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-3c3q-vw42-rfc2/GHSA-3c3q-vw42-rfc2.json b/advisories/unreviewed/2024/10/GHSA-3c3q-vw42-rfc2/GHSA-3c3q-vw42-rfc2.json new file mode 100644 index 00000000000..81a39e06870 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-3c3q-vw42-rfc2/GHSA-3c3q-vw42-rfc2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3c3q-vw42-rfc2", + "modified": "2024-10-28T15:31:14Z", + "published": "2024-10-28T15:31:14Z", + "aliases": [ + "CVE-2024-50488" + ], + "details": "Authentication Bypass Using an Alternate Path or Channel vulnerability in Priyabrata Sarkar Token Login allows Authentication Bypass.This issue affects Token Login: from n/a through 1.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50488" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/token-login/wordpress-token-login-plugin-1-0-3-broken-authentication-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-28T13:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-3c96-w4r4-hg26/GHSA-3c96-w4r4-hg26.json b/advisories/unreviewed/2024/10/GHSA-3c96-w4r4-hg26/GHSA-3c96-w4r4-hg26.json new file mode 100644 index 00000000000..28b0b20a61a --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-3c96-w4r4-hg26/GHSA-3c96-w4r4-hg26.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3c96-w4r4-hg26", + "modified": "2024-10-28T15:31:16Z", + "published": "2024-10-28T15:31:16Z", + "aliases": [ + "CVE-2024-10449" + ], + "details": "A vulnerability, which was classified as critical, was found in Codezips Hospital Appointment System 1.0. This affects an unknown part of the file /loginAction.php. The manipulation of the argument Username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10449" + }, + { + "type": "WEB", + "url": "https://github.com/ppp-src/CVE/issues/25" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.282009" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.282009" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.432564" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-28T15:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-3g37-ghfj-6c5g/GHSA-3g37-ghfj-6c5g.json b/advisories/unreviewed/2024/10/GHSA-3g37-ghfj-6c5g/GHSA-3g37-ghfj-6c5g.json new file mode 100644 index 00000000000..3d21ab00b87 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-3g37-ghfj-6c5g/GHSA-3g37-ghfj-6c5g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3g37-ghfj-6c5g", + "modified": "2024-10-28T15:31:15Z", + "published": "2024-10-28T15:31:15Z", + "aliases": [ + "CVE-2024-50576" + ], + "details": "In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via vendor URL in App manifest", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50576" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-28T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-45g4-3pq8-625w/GHSA-45g4-3pq8-625w.json b/advisories/unreviewed/2024/10/GHSA-45g4-3pq8-625w/GHSA-45g4-3pq8-625w.json new file mode 100644 index 00000000000..0a483f04514 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-45g4-3pq8-625w/GHSA-45g4-3pq8-625w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-45g4-3pq8-625w", + "modified": "2024-10-28T15:31:16Z", + "published": "2024-10-28T15:31:16Z", + "aliases": [ + "CVE-2024-48291" + ], + "details": "dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/doAdminAction.php?act=editAdmin&id=17", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48291" + }, + { + "type": "WEB", + "url": "https://github.com/Gxxxxxxxxxxxxxxxxxx/cms/tree/main/4/readme.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-28T15:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-4fc9-vhvw-cw2f/GHSA-4fc9-vhvw-cw2f.json b/advisories/unreviewed/2024/10/GHSA-4fc9-vhvw-cw2f/GHSA-4fc9-vhvw-cw2f.json index ab3328e9501..2c9a1da8ea0 100644 --- a/advisories/unreviewed/2024/10/GHSA-4fc9-vhvw-cw2f/GHSA-4fc9-vhvw-cw2f.json +++ b/advisories/unreviewed/2024/10/GHSA-4fc9-vhvw-cw2f/GHSA-4fc9-vhvw-cw2f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4fc9-vhvw-cw2f", - "modified": "2024-10-25T12:31:33Z", + "modified": "2024-10-28T15:31:10Z", "published": "2024-10-25T12:31:33Z", "aliases": [ "CVE-2024-47022" ], "details": "N/A", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-25T11:15:16Z" diff --git a/advisories/unreviewed/2024/10/GHSA-4pm8-rxv6-frfv/GHSA-4pm8-rxv6-frfv.json b/advisories/unreviewed/2024/10/GHSA-4pm8-rxv6-frfv/GHSA-4pm8-rxv6-frfv.json new file mode 100644 index 00000000000..473de31062d --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-4pm8-rxv6-frfv/GHSA-4pm8-rxv6-frfv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4pm8-rxv6-frfv", + "modified": "2024-10-28T15:31:15Z", + "published": "2024-10-28T15:31:15Z", + "aliases": [ + "CVE-2024-50574" + ], + "details": "In JetBrains YouTrack before 2024.3.47707 potential ReDoS exploit was possible via email header parsing in Helpdesk functionality", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50574" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1333" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-28T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-65xw-vg7q-v4cg/GHSA-65xw-vg7q-v4cg.json b/advisories/unreviewed/2024/10/GHSA-65xw-vg7q-v4cg/GHSA-65xw-vg7q-v4cg.json new file mode 100644 index 00000000000..92da5332d79 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-65xw-vg7q-v4cg/GHSA-65xw-vg7q-v4cg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-65xw-vg7q-v4cg", + "modified": "2024-10-28T15:31:15Z", + "published": "2024-10-28T15:31:15Z", + "aliases": [ + "CVE-2024-50582" + ], + "details": "In JetBrains YouTrack before 2024.3.47707 stored XSS was possible due to improper HTML sanitization in markdown elements", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50582" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-28T13:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-6h38-5xh4-ghc6/GHSA-6h38-5xh4-ghc6.json b/advisories/unreviewed/2024/10/GHSA-6h38-5xh4-ghc6/GHSA-6h38-5xh4-ghc6.json new file mode 100644 index 00000000000..bb3c303fb49 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-6h38-5xh4-ghc6/GHSA-6h38-5xh4-ghc6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6h38-5xh4-ghc6", + "modified": "2024-10-28T15:31:14Z", + "published": "2024-10-28T15:31:14Z", + "aliases": [ + "CVE-2024-50478" + ], + "details": "Authentication Bypass by Primary Weakness vulnerability in Swoop 1-Click Login: Passwordless Authentication allows Authentication Bypass.This issue affects 1-Click Login: Passwordless Authentication: 1.4.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50478" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/swoop-password-free-authentication/wordpress-1-click-login-passwordless-authentication-plugin-1-4-5-broken-authentication-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-305" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-28T13:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-7pcw-338g-2xgr/GHSA-7pcw-338g-2xgr.json b/advisories/unreviewed/2024/10/GHSA-7pcw-338g-2xgr/GHSA-7pcw-338g-2xgr.json index b23bacec344..0bb4bd3f7eb 100644 --- a/advisories/unreviewed/2024/10/GHSA-7pcw-338g-2xgr/GHSA-7pcw-338g-2xgr.json +++ b/advisories/unreviewed/2024/10/GHSA-7pcw-338g-2xgr/GHSA-7pcw-338g-2xgr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7pcw-338g-2xgr", - "modified": "2024-10-25T12:31:33Z", + "modified": "2024-10-28T15:31:10Z", "published": "2024-10-25T12:31:33Z", "aliases": [ "CVE-2024-47023" ], "details": "there is a possible man-in-the-middle attack due to a logic error in the code. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-25T11:15:17Z" diff --git a/advisories/unreviewed/2024/10/GHSA-843w-q978-4f26/GHSA-843w-q978-4f26.json b/advisories/unreviewed/2024/10/GHSA-843w-q978-4f26/GHSA-843w-q978-4f26.json new file mode 100644 index 00000000000..8ebd173ca15 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-843w-q978-4f26/GHSA-843w-q978-4f26.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-843w-q978-4f26", + "modified": "2024-10-28T15:31:14Z", + "published": "2024-10-28T15:31:14Z", + "aliases": [ + "CVE-2024-50472" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Martin Drapeau Amilia Store allows Stored XSS.This issue affects Amilia Store: from n/a through 2.9.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50472" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/amilia-store/wordpress-amilia-store-plugin-2-9-8-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-28T13:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-84f5-47c9-mwpg/GHSA-84f5-47c9-mwpg.json b/advisories/unreviewed/2024/10/GHSA-84f5-47c9-mwpg/GHSA-84f5-47c9-mwpg.json new file mode 100644 index 00000000000..c3e20d09c63 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-84f5-47c9-mwpg/GHSA-84f5-47c9-mwpg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-84f5-47c9-mwpg", + "modified": "2024-10-28T15:31:15Z", + "published": "2024-10-28T15:31:15Z", + "aliases": [ + "CVE-2024-50578" + ], + "details": "In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via sprint value on agile boards page", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50578" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-28T13:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-88gm-grvr-fqwf/GHSA-88gm-grvr-fqwf.json b/advisories/unreviewed/2024/10/GHSA-88gm-grvr-fqwf/GHSA-88gm-grvr-fqwf.json new file mode 100644 index 00000000000..cc9342fdef1 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-88gm-grvr-fqwf/GHSA-88gm-grvr-fqwf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-88gm-grvr-fqwf", + "modified": "2024-10-28T15:31:15Z", + "published": "2024-10-28T15:31:15Z", + "aliases": [ + "CVE-2024-50577" + ], + "details": "In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via Angular template injection in Hub settings", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50577" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-28T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-8rqm-m9fj-hxxc/GHSA-8rqm-m9fj-hxxc.json b/advisories/unreviewed/2024/10/GHSA-8rqm-m9fj-hxxc/GHSA-8rqm-m9fj-hxxc.json new file mode 100644 index 00000000000..df51ffd4ca5 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-8rqm-m9fj-hxxc/GHSA-8rqm-m9fj-hxxc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8rqm-m9fj-hxxc", + "modified": "2024-10-28T15:31:14Z", + "published": "2024-10-28T15:31:14Z", + "aliases": [ + "CVE-2024-50483" + ], + "details": "Authorization Bypass Through User-Controlled Key vulnerability in Meetup allows Privilege Escalation.This issue affects Meetup: from n/a through 0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50483" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/meetup/wordpress-meetup-plugin-0-1-broken-authentication-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-28T13:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-98qv-5frh-cx73/GHSA-98qv-5frh-cx73.json b/advisories/unreviewed/2024/10/GHSA-98qv-5frh-cx73/GHSA-98qv-5frh-cx73.json index 952d4ef1a36..e7f62ae7137 100644 --- a/advisories/unreviewed/2024/10/GHSA-98qv-5frh-cx73/GHSA-98qv-5frh-cx73.json +++ b/advisories/unreviewed/2024/10/GHSA-98qv-5frh-cx73/GHSA-98qv-5frh-cx73.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-98qv-5frh-cx73", - "modified": "2024-10-25T12:31:33Z", + "modified": "2024-10-28T15:31:10Z", "published": "2024-10-25T12:31:33Z", "aliases": [ "CVE-2024-47020" ], "details": "N/A", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-25T11:15:16Z" diff --git a/advisories/unreviewed/2024/10/GHSA-9wxg-rrgr-p9x6/GHSA-9wxg-rrgr-p9x6.json b/advisories/unreviewed/2024/10/GHSA-9wxg-rrgr-p9x6/GHSA-9wxg-rrgr-p9x6.json new file mode 100644 index 00000000000..eaad8f2bc81 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-9wxg-rrgr-p9x6/GHSA-9wxg-rrgr-p9x6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9wxg-rrgr-p9x6", + "modified": "2024-10-28T15:31:14Z", + "published": "2024-10-28T15:31:14Z", + "aliases": [ + "CVE-2024-50502" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CozyThemes Cozy Blocks allows Stored XSS.This issue affects Cozy Blocks: from n/a through 2.0.18.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50502" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/cozy-addons/wordpress-cozy-blocks-plugin-2-0-18-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-28T13:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-c2j6-7h49-7vrf/GHSA-c2j6-7h49-7vrf.json b/advisories/unreviewed/2024/10/GHSA-c2j6-7h49-7vrf/GHSA-c2j6-7h49-7vrf.json index 6392de6e03d..9c1ee04ba45 100644 --- a/advisories/unreviewed/2024/10/GHSA-c2j6-7h49-7vrf/GHSA-c2j6-7h49-7vrf.json +++ b/advisories/unreviewed/2024/10/GHSA-c2j6-7h49-7vrf/GHSA-c2j6-7h49-7vrf.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-502" + "CWE-502", + "CWE-89" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-c3c4-x529-6x9q/GHSA-c3c4-x529-6x9q.json b/advisories/unreviewed/2024/10/GHSA-c3c4-x529-6x9q/GHSA-c3c4-x529-6x9q.json new file mode 100644 index 00000000000..6c775e0821c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-c3c4-x529-6x9q/GHSA-c3c4-x529-6x9q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c3c4-x529-6x9q", + "modified": "2024-10-28T15:31:15Z", + "published": "2024-10-28T15:31:15Z", + "aliases": [ + "CVE-2024-50575" + ], + "details": "In JetBrains YouTrack before 2024.3.47707 reflected XSS was possible in Widget API", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50575" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-28T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-cpcx-www7-v9f3/GHSA-cpcx-www7-v9f3.json b/advisories/unreviewed/2024/10/GHSA-cpcx-www7-v9f3/GHSA-cpcx-www7-v9f3.json new file mode 100644 index 00000000000..52b4cd9f4f2 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-cpcx-www7-v9f3/GHSA-cpcx-www7-v9f3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cpcx-www7-v9f3", + "modified": "2024-10-28T15:31:16Z", + "published": "2024-10-28T15:31:16Z", + "aliases": [ + "CVE-2024-10455" + ], + "details": "Reachable Assertion in BPv7 parser in µD3TN v0.14.0 allows attacker to disrupt service via malformed Extension Block", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10455" + }, + { + "type": "WEB", + "url": "https://gitlab.com/d3tn/ud3tn/-/issues/227" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-617" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-28T14:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-f4xx-fhcp-433m/GHSA-f4xx-fhcp-433m.json b/advisories/unreviewed/2024/10/GHSA-f4xx-fhcp-433m/GHSA-f4xx-fhcp-433m.json new file mode 100644 index 00000000000..e74c960be4c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-f4xx-fhcp-433m/GHSA-f4xx-fhcp-433m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f4xx-fhcp-433m", + "modified": "2024-10-28T15:31:14Z", + "published": "2024-10-28T15:31:14Z", + "aliases": [ + "CVE-2024-50470" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themes4WP Themes4WP YouTube External Subtitles allows Stored XSS.This issue affects Themes4WP YouTube External Subtitles: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50470" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/themes4wp-youtube-external-subtitles/wordpress-themes4wp-youtube-external-subtitles-plugin-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-28T13:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-fm77-2jxq-m577/GHSA-fm77-2jxq-m577.json b/advisories/unreviewed/2024/10/GHSA-fm77-2jxq-m577/GHSA-fm77-2jxq-m577.json new file mode 100644 index 00000000000..86d29334d01 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-fm77-2jxq-m577/GHSA-fm77-2jxq-m577.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fm77-2jxq-m577", + "modified": "2024-10-28T15:31:14Z", + "published": "2024-10-28T15:31:14Z", + "aliases": [ + "CVE-2024-50501" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Climax Themes Kata Plus allows Stored XSS.This issue affects Kata Plus: from n/a through 1.4.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50501" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/kata-plus/wordpress-kata-plus-plugin-1-4-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-28T13:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-hm57-h27x-599c/GHSA-hm57-h27x-599c.json b/advisories/unreviewed/2024/10/GHSA-hm57-h27x-599c/GHSA-hm57-h27x-599c.json new file mode 100644 index 00000000000..00f42108b43 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-hm57-h27x-599c/GHSA-hm57-h27x-599c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hm57-h27x-599c", + "modified": "2024-10-28T15:31:16Z", + "published": "2024-10-28T15:31:16Z", + "aliases": [ + "CVE-2024-10214" + ], + "details": "Mattermost versions 9.11.X <= 9.11.1, 9.5.x <= 9.5.9 icorrectly issues two sessions when using desktop SSO - one in the browser and one in desktop with incorrect settings.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10214" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-303" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-28T15:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-jc3p-f86q-23rh/GHSA-jc3p-f86q-23rh.json b/advisories/unreviewed/2024/10/GHSA-jc3p-f86q-23rh/GHSA-jc3p-f86q-23rh.json index 2a805c16ade..706e6355fc1 100644 --- a/advisories/unreviewed/2024/10/GHSA-jc3p-f86q-23rh/GHSA-jc3p-f86q-23rh.json +++ b/advisories/unreviewed/2024/10/GHSA-jc3p-f86q-23rh/GHSA-jc3p-f86q-23rh.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-276" + "CWE-276", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-jxjm-crgh-jq3f/GHSA-jxjm-crgh-jq3f.json b/advisories/unreviewed/2024/10/GHSA-jxjm-crgh-jq3f/GHSA-jxjm-crgh-jq3f.json index 6deb707b881..accc6bfde84 100644 --- a/advisories/unreviewed/2024/10/GHSA-jxjm-crgh-jq3f/GHSA-jxjm-crgh-jq3f.json +++ b/advisories/unreviewed/2024/10/GHSA-jxjm-crgh-jq3f/GHSA-jxjm-crgh-jq3f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jxjm-crgh-jq3f", - "modified": "2024-10-25T21:31:27Z", + "modified": "2024-10-28T15:31:10Z", "published": "2024-10-25T21:31:27Z", "aliases": [ "CVE-2024-37844" ], "details": "A stored cross-site scripting (XSS) vulnerability in MangoOS before 5.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-25T19:15:03Z" diff --git a/advisories/unreviewed/2024/10/GHSA-m66w-9x3j-hw3r/GHSA-m66w-9x3j-hw3r.json b/advisories/unreviewed/2024/10/GHSA-m66w-9x3j-hw3r/GHSA-m66w-9x3j-hw3r.json new file mode 100644 index 00000000000..2a4b513f607 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-m66w-9x3j-hw3r/GHSA-m66w-9x3j-hw3r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m66w-9x3j-hw3r", + "modified": "2024-10-28T15:31:14Z", + "published": "2024-10-28T15:31:14Z", + "aliases": [ + "CVE-2024-50465" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP SEO – Calin Vingan Premium SEO Pack allows SQL Injection.This issue affects Premium SEO Pack: from n/a through 1.6.001.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50465" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/premium-seo-pack/wordpress-premium-seo-pack-plugin-1-6-001-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-28T13:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-mpw3-23h3-rhrx/GHSA-mpw3-23h3-rhrx.json b/advisories/unreviewed/2024/10/GHSA-mpw3-23h3-rhrx/GHSA-mpw3-23h3-rhrx.json new file mode 100644 index 00000000000..816bf20ec53 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-mpw3-23h3-rhrx/GHSA-mpw3-23h3-rhrx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mpw3-23h3-rhrx", + "modified": "2024-10-28T15:31:15Z", + "published": "2024-10-28T15:31:15Z", + "aliases": [ + "CVE-2024-8013" + ], + "details": "A bug in query analysis of certain complex self-referential $lookup subpipelines may result in literal values in expressions for encrypted fields to be sent to the server as plaintext instead of ciphertext. Should this occur, no documents would be returned or written. This issue affects mongocryptd binary (v5.0 versions prior to 5.0.29, v6.0 versions prior to 6.0.17, v7.0 versions prior to 7.0.12 and v7.3 versions prior to 7.3.4) and mongo_crypt_v1.so shared libraries (v6.0 versions prior to 6.0.17, v7.0 versions prior to 7.0.12 and v7.3 versions prior to 7.3.4) released alongside MongoDB Enterprise Server versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8013" + }, + { + "type": "WEB", + "url": "https://jira.mongodb.org/browse/SERVER-96254" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-319" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-28T13:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-pmr5-3pp2-mjf9/GHSA-pmr5-3pp2-mjf9.json b/advisories/unreviewed/2024/10/GHSA-pmr5-3pp2-mjf9/GHSA-pmr5-3pp2-mjf9.json new file mode 100644 index 00000000000..0a33a7f731b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-pmr5-3pp2-mjf9/GHSA-pmr5-3pp2-mjf9.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pmr5-3pp2-mjf9", + "modified": "2024-10-28T15:31:16Z", + "published": "2024-10-28T15:31:16Z", + "aliases": [ + "CVE-2024-10448" + ], + "details": "A vulnerability, which was classified as problematic, has been found in code-projects Blood Bank Management System 1.0. Affected by this issue is some unknown functionality of the file /file/delete.php. The manipulation of the argument bid leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Other endpoints might be affected as well.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10448" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/bevennyamande/bloodbank_delete_csrf_attack" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.282008" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.282008" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.432501" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-28T14:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-q2mc-p2rh-669x/GHSA-q2mc-p2rh-669x.json b/advisories/unreviewed/2024/10/GHSA-q2mc-p2rh-669x/GHSA-q2mc-p2rh-669x.json new file mode 100644 index 00000000000..d9b19f3b86b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-q2mc-p2rh-669x/GHSA-q2mc-p2rh-669x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q2mc-p2rh-669x", + "modified": "2024-10-28T15:31:15Z", + "published": "2024-10-28T15:31:15Z", + "aliases": [ + "CVE-2024-50581" + ], + "details": "In JetBrains YouTrack before 2024.3.47707 improper HTML sanitization could lead to XSS attack via comment tag", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50581" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-28T13:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-q58q-j8gc-gvjh/GHSA-q58q-j8gc-gvjh.json b/advisories/unreviewed/2024/10/GHSA-q58q-j8gc-gvjh/GHSA-q58q-j8gc-gvjh.json new file mode 100644 index 00000000000..734e49a732f --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-q58q-j8gc-gvjh/GHSA-q58q-j8gc-gvjh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q58q-j8gc-gvjh", + "modified": "2024-10-28T15:31:14Z", + "published": "2024-10-28T15:31:13Z", + "aliases": [ + "CVE-2024-50463" + ], + "details": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in WP Sunshine Sunshine Photo Cart.This issue affects Sunshine Photo Cart: from n/a through 3.2.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50463" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/sunshine-photo-cart/wordpress-sunshine-photo-cart-plugin-3-2-9-open-redirection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-28T13:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-q5cj-8jcp-gxw4/GHSA-q5cj-8jcp-gxw4.json b/advisories/unreviewed/2024/10/GHSA-q5cj-8jcp-gxw4/GHSA-q5cj-8jcp-gxw4.json new file mode 100644 index 00000000000..18163489090 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-q5cj-8jcp-gxw4/GHSA-q5cj-8jcp-gxw4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q5cj-8jcp-gxw4", + "modified": "2024-10-28T15:31:15Z", + "published": "2024-10-28T15:31:15Z", + "aliases": [ + "CVE-2024-50580" + ], + "details": "In JetBrains YouTrack before 2024.3.47707 multiple XSS were possible due to insecure markdown parsing and custom rendering rule", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50580" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-28T13:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-q68q-7rrh-j62p/GHSA-q68q-7rrh-j62p.json b/advisories/unreviewed/2024/10/GHSA-q68q-7rrh-j62p/GHSA-q68q-7rrh-j62p.json new file mode 100644 index 00000000000..680b12ef023 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-q68q-7rrh-j62p/GHSA-q68q-7rrh-j62p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q68q-7rrh-j62p", + "modified": "2024-10-28T15:31:16Z", + "published": "2024-10-28T15:31:16Z", + "aliases": [ + "CVE-2024-48191" + ], + "details": "dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/doAdminAction.php?act=delAdmin&id=17", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48191" + }, + { + "type": "WEB", + "url": "https://github.com/xiaoyin0226/cms/tree/main/5/readme.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-28T14:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-qrjg-cmwm-3465/GHSA-qrjg-cmwm-3465.json b/advisories/unreviewed/2024/10/GHSA-qrjg-cmwm-3465/GHSA-qrjg-cmwm-3465.json new file mode 100644 index 00000000000..e0db987a7cc --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-qrjg-cmwm-3465/GHSA-qrjg-cmwm-3465.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qrjg-cmwm-3465", + "modified": "2024-10-28T15:31:14Z", + "published": "2024-10-28T15:31:14Z", + "aliases": [ + "CVE-2024-50497" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in BuyNowDepot Advanced Online Ordering and Delivery Platform allows PHP Local File Inclusion.This issue affects Advanced Online Ordering and Delivery Platform: from n/a through 2.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50497" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/advanced-online-ordering-and-delivery-platform/wordpress-advanced-online-ordering-and-delivery-platform-plugin-2-0-0-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-28T13:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-v3gq-vrpv-476w/GHSA-v3gq-vrpv-476w.json b/advisories/unreviewed/2024/10/GHSA-v3gq-vrpv-476w/GHSA-v3gq-vrpv-476w.json new file mode 100644 index 00000000000..5a66bc9adee --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-v3gq-vrpv-476w/GHSA-v3gq-vrpv-476w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v3gq-vrpv-476w", + "modified": "2024-10-28T15:31:14Z", + "published": "2024-10-28T15:31:14Z", + "aliases": [ + "CVE-2024-50491" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Micah Blu RSVP ME allows SQL Injection.This issue affects RSVP ME: from n/a through 1.9.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50491" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/rsvp-me/wordpress-rsvp-me-plugin-1-9-9-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-28T13:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-vh43-qg6g-8gcm/GHSA-vh43-qg6g-8gcm.json b/advisories/unreviewed/2024/10/GHSA-vh43-qg6g-8gcm/GHSA-vh43-qg6g-8gcm.json index 6d96b0e39c4..d18d1e46ed9 100644 --- a/advisories/unreviewed/2024/10/GHSA-vh43-qg6g-8gcm/GHSA-vh43-qg6g-8gcm.json +++ b/advisories/unreviewed/2024/10/GHSA-vh43-qg6g-8gcm/GHSA-vh43-qg6g-8gcm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vh43-qg6g-8gcm", - "modified": "2024-10-25T12:31:33Z", + "modified": "2024-10-28T15:31:10Z", "published": "2024-10-25T12:31:33Z", "aliases": [ "CVE-2024-47021" ], "details": "In sms_ExtractCbLanguage of sms_CellBroadcast.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-25T11:15:16Z" diff --git a/advisories/unreviewed/2024/10/GHSA-vh8w-p5mj-44gq/GHSA-vh8w-p5mj-44gq.json b/advisories/unreviewed/2024/10/GHSA-vh8w-p5mj-44gq/GHSA-vh8w-p5mj-44gq.json new file mode 100644 index 00000000000..c6162124fba --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-vh8w-p5mj-44gq/GHSA-vh8w-p5mj-44gq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vh8w-p5mj-44gq", + "modified": "2024-10-28T15:31:15Z", + "published": "2024-10-28T15:31:15Z", + "aliases": [ + "CVE-2024-50579" + ], + "details": "In JetBrains YouTrack before 2024.3.47707 reflected XSS due to insecure link sanitization was possible", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50579" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-28T13:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-wxrv-rphj-qfqf/GHSA-wxrv-rphj-qfqf.json b/advisories/unreviewed/2024/10/GHSA-wxrv-rphj-qfqf/GHSA-wxrv-rphj-qfqf.json new file mode 100644 index 00000000000..c375cd64cde --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-wxrv-rphj-qfqf/GHSA-wxrv-rphj-qfqf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wxrv-rphj-qfqf", + "modified": "2024-10-28T15:31:14Z", + "published": "2024-10-28T15:31:14Z", + "aliases": [ + "CVE-2024-50471" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Checklist Trip Plan allows Stored XSS.This issue affects Trip Plan: from n/a through 1.0.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50471" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/tripplan/wordpress-trip-plan-plugin-1-0-10-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-28T13:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-xrq3-qh6q-h4xq/GHSA-xrq3-qh6q-h4xq.json b/advisories/unreviewed/2024/10/GHSA-xrq3-qh6q-h4xq/GHSA-xrq3-qh6q-h4xq.json new file mode 100644 index 00000000000..856621bdeaa --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-xrq3-qh6q-h4xq/GHSA-xrq3-qh6q-h4xq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xrq3-qh6q-h4xq", + "modified": "2024-10-28T15:31:15Z", + "published": "2024-10-28T15:31:15Z", + "aliases": [ + "CVE-2024-50573" + ], + "details": "In JetBrains Hub before 2024.3.47707 improper access control allowed users to generate permanent tokens for unauthorized services", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50573" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-28T13:15:08Z" + } +} \ No newline at end of file