diff --git a/advisories/unreviewed/2022/04/GHSA-6qpr-j96r-rh4v/GHSA-6qpr-j96r-rh4v.json b/advisories/unreviewed/2022/04/GHSA-6qpr-j96r-rh4v/GHSA-6qpr-j96r-rh4v.json index 24e400aba61..62f671a2f12 100644 --- a/advisories/unreviewed/2022/04/GHSA-6qpr-j96r-rh4v/GHSA-6qpr-j96r-rh4v.json +++ b/advisories/unreviewed/2022/04/GHSA-6qpr-j96r-rh4v/GHSA-6qpr-j96r-rh4v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6qpr-j96r-rh4v", - "modified": "2022-04-30T18:09:52Z", + "modified": "2024-08-02T00:31:24Z", "published": "2022-04-30T18:09:52Z", "aliases": [ "CVE-1999-0052" ], "details": "IP fragmentation denial of service in FreeBSD allows a remote attacker to cause a crash.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-ggcx-6xh6-rqfh/GHSA-ggcx-6xh6-rqfh.json b/advisories/unreviewed/2022/04/GHSA-ggcx-6xh6-rqfh/GHSA-ggcx-6xh6-rqfh.json index 430cc6d59c7..904192b649d 100644 --- a/advisories/unreviewed/2022/04/GHSA-ggcx-6xh6-rqfh/GHSA-ggcx-6xh6-rqfh.json +++ b/advisories/unreviewed/2022/04/GHSA-ggcx-6xh6-rqfh/GHSA-ggcx-6xh6-rqfh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ggcx-6xh6-rqfh", - "modified": "2022-04-30T18:09:54Z", + "modified": "2024-08-02T00:31:24Z", "published": "2022-04-30T18:09:54Z", "aliases": [ "CVE-1999-0066" ], "details": "AnyForm CGI remote execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/04/GHSA-j4g7-5mmf-c6g5/GHSA-j4g7-5mmf-c6g5.json b/advisories/unreviewed/2022/04/GHSA-j4g7-5mmf-c6g5/GHSA-j4g7-5mmf-c6g5.json index d8210416de5..c898ed9dd38 100644 --- a/advisories/unreviewed/2022/04/GHSA-j4g7-5mmf-c6g5/GHSA-j4g7-5mmf-c6g5.json +++ b/advisories/unreviewed/2022/04/GHSA-j4g7-5mmf-c6g5/GHSA-j4g7-5mmf-c6g5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j4g7-5mmf-c6g5", - "modified": "2022-04-30T18:09:52Z", + "modified": "2024-08-02T00:31:24Z", "published": "2022-04-30T18:09:52Z", "aliases": [ "CVE-1999-0059" ], "details": "IRIX fam service allows an attacker to obtain a list of all files on the server.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -33,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-v3vm-mf33-hv7v/GHSA-v3vm-mf33-hv7v.json b/advisories/unreviewed/2022/04/GHSA-v3vm-mf33-hv7v/GHSA-v3vm-mf33-hv7v.json index 5db81277a7a..03684603616 100644 --- a/advisories/unreviewed/2022/04/GHSA-v3vm-mf33-hv7v/GHSA-v3vm-mf33-hv7v.json +++ b/advisories/unreviewed/2022/04/GHSA-v3vm-mf33-hv7v/GHSA-v3vm-mf33-hv7v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v3vm-mf33-hv7v", - "modified": "2022-04-30T18:09:56Z", + "modified": "2024-08-02T00:31:24Z", "published": "2022-04-30T18:09:55Z", "aliases": [ "CVE-1999-0084" ], "details": "Certain NFS servers allow users to use mknod to gain privileges by creating a writable kmem device and setting the UID to 0.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-5444-vc88-hfjh/GHSA-5444-vc88-hfjh.json b/advisories/unreviewed/2024/03/GHSA-5444-vc88-hfjh/GHSA-5444-vc88-hfjh.json index 8e937388da8..bd9f58e9613 100644 --- a/advisories/unreviewed/2024/03/GHSA-5444-vc88-hfjh/GHSA-5444-vc88-hfjh.json +++ b/advisories/unreviewed/2024/03/GHSA-5444-vc88-hfjh/GHSA-5444-vc88-hfjh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5444-vc88-hfjh", - "modified": "2024-03-21T15:31:55Z", + "modified": "2024-08-02T00:31:25Z", "published": "2024-03-21T15:31:55Z", "aliases": [ "CVE-2024-2463" ], "details": "Weak password recovery mechanism in CDeX application allows to retrieve password reset token.This issue affects CDeX application versions through 5.7.1.\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-640" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-21T15:16:54Z" diff --git a/advisories/unreviewed/2024/03/GHSA-wpwv-j45h-pwcg/GHSA-wpwv-j45h-pwcg.json b/advisories/unreviewed/2024/03/GHSA-wpwv-j45h-pwcg/GHSA-wpwv-j45h-pwcg.json index 67178f695d8..464e0eaceb9 100644 --- a/advisories/unreviewed/2024/03/GHSA-wpwv-j45h-pwcg/GHSA-wpwv-j45h-pwcg.json +++ b/advisories/unreviewed/2024/03/GHSA-wpwv-j45h-pwcg/GHSA-wpwv-j45h-pwcg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wpwv-j45h-pwcg", - "modified": "2024-03-22T03:30:44Z", + "modified": "2024-08-02T00:31:25Z", "published": "2024-03-22T03:30:44Z", "aliases": [ "CVE-2024-25807" ], "details": "Cross Site Scripting (XSS) vulnerability in Lychee 3.1.6, allows remote attackers to execute arbitrary code and obtain sensitive information via the title parameter when creating an album.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-22T03:15:07Z" diff --git a/advisories/unreviewed/2024/08/GHSA-23x9-2qmf-qr95/GHSA-23x9-2qmf-qr95.json b/advisories/unreviewed/2024/08/GHSA-23x9-2qmf-qr95/GHSA-23x9-2qmf-qr95.json new file mode 100644 index 00000000000..7db1593ddc9 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-23x9-2qmf-qr95/GHSA-23x9-2qmf-qr95.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-23x9-2qmf-qr95", + "modified": "2024-08-02T00:31:25Z", + "published": "2024-08-02T00:31:25Z", + "aliases": [ + "CVE-2024-39661" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ExtendThemes Kubio AI Page Builder.This issue affects Kubio AI Page Builder: from n/a through 2.2.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39661" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/kubio/wordpress-kubio-ai-page-builder-plugin-2-2-4-authenticated-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T22:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-2f23-9vw3-564h/GHSA-2f23-9vw3-564h.json b/advisories/unreviewed/2024/08/GHSA-2f23-9vw3-564h/GHSA-2f23-9vw3-564h.json new file mode 100644 index 00000000000..dc84fc5ba59 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-2f23-9vw3-564h/GHSA-2f23-9vw3-564h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2f23-9vw3-564h", + "modified": "2024-08-02T00:31:25Z", + "published": "2024-08-02T00:31:25Z", + "aliases": [ + "CVE-2024-39636" + ], + "details": "Deserialization of Untrusted Data vulnerability in CodeSolz Better Find and Replace.This issue affects Better Find and Replace: from n/a through 1.6.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39636" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/real-time-auto-find-and-replace/wordpress-better-find-and-replace-plugin-1-6-1-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T22:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-4g7c-qjqw-rvrq/GHSA-4g7c-qjqw-rvrq.json b/advisories/unreviewed/2024/08/GHSA-4g7c-qjqw-rvrq/GHSA-4g7c-qjqw-rvrq.json new file mode 100644 index 00000000000..4255d667a78 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-4g7c-qjqw-rvrq/GHSA-4g7c-qjqw-rvrq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4g7c-qjqw-rvrq", + "modified": "2024-08-02T00:31:25Z", + "published": "2024-08-02T00:31:25Z", + "aliases": [ + "CVE-2024-38761" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.99.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38761" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/zephyr-project-manager/wordpress-zephyr-project-manager-plugin-3-3-99-sensitive-data-exposure-via-export-file-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T22:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-4mjp-p7h5-xhfj/GHSA-4mjp-p7h5-xhfj.json b/advisories/unreviewed/2024/08/GHSA-4mjp-p7h5-xhfj/GHSA-4mjp-p7h5-xhfj.json new file mode 100644 index 00000000000..c8f5ca8253a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-4mjp-p7h5-xhfj/GHSA-4mjp-p7h5-xhfj.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4mjp-p7h5-xhfj", + "modified": "2024-08-02T00:31:25Z", + "published": "2024-08-02T00:31:25Z", + "aliases": [ + "CVE-2024-32758" + ], + "details": "Under certain circumstances the communication between exacqVision Client and exacqVision Server will use insufficient key length and exchange", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32758" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-214-01" + }, + { + "type": "WEB", + "url": "https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-326" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T22:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-4p5p-hc8f-q6m8/GHSA-4p5p-hc8f-q6m8.json b/advisories/unreviewed/2024/08/GHSA-4p5p-hc8f-q6m8/GHSA-4p5p-hc8f-q6m8.json new file mode 100644 index 00000000000..a1fd7ff0831 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-4p5p-hc8f-q6m8/GHSA-4p5p-hc8f-q6m8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4p5p-hc8f-q6m8", + "modified": "2024-08-02T00:31:25Z", + "published": "2024-08-02T00:31:25Z", + "aliases": [ + "CVE-2024-39652" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPWeb Elite WooCommerce PDF Vouchers allows Reflected XSS.This issue affects WooCommerce PDF Vouchers: from n/a before 4.9.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39652" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/woocommerce-pdf-vouchers/wordpress-woocommerce-pdf-vouchers-plugin-4-9-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T22:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-5cw9-ffvm-v9jx/GHSA-5cw9-ffvm-v9jx.json b/advisories/unreviewed/2024/08/GHSA-5cw9-ffvm-v9jx/GHSA-5cw9-ffvm-v9jx.json new file mode 100644 index 00000000000..eddd841f65e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-5cw9-ffvm-v9jx/GHSA-5cw9-ffvm-v9jx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5cw9-ffvm-v9jx", + "modified": "2024-08-02T00:31:25Z", + "published": "2024-08-02T00:31:25Z", + "aliases": [ + "CVE-2024-39668" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in petesheppard84 Extensions for Elementor allows Stored XSS.This issue affects Extensions for Elementor: from n/a through 2.0.31.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39668" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/extensions-for-elementor/wordpress-extensions-for-elementor-plugin-2-0-31-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T22:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-6q58-m3qf-67px/GHSA-6q58-m3qf-67px.json b/advisories/unreviewed/2024/08/GHSA-6q58-m3qf-67px/GHSA-6q58-m3qf-67px.json new file mode 100644 index 00000000000..04d72fe22b1 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6q58-m3qf-67px/GHSA-6q58-m3qf-67px.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6q58-m3qf-67px", + "modified": "2024-08-02T00:31:26Z", + "published": "2024-08-02T00:31:26Z", + "aliases": [ + "CVE-2024-7369" + ], + "details": "A vulnerability was found in SourceCodester Simple Realtime Quiz System 1.0 and classified as critical. This issue affects some unknown processing of the file /ajax.php?action=login of the component Login. The manipulation of the argument username leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273353 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7369" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/5e805f42f51224bdd52cfd099f44001d" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.273353" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.273353" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.383517" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T22:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7gp6-8jgj-qfpf/GHSA-7gp6-8jgj-qfpf.json b/advisories/unreviewed/2024/08/GHSA-7gp6-8jgj-qfpf/GHSA-7gp6-8jgj-qfpf.json new file mode 100644 index 00000000000..2d8116a62bc --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-7gp6-8jgj-qfpf/GHSA-7gp6-8jgj-qfpf.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7gp6-8jgj-qfpf", + "modified": "2024-08-02T00:31:26Z", + "published": "2024-08-02T00:31:26Z", + "aliases": [ + "CVE-2024-7372" + ], + "details": "A vulnerability was found in SourceCodester Simple Realtime Quiz System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /quiz_board.php. The manipulation of the argument quiz leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273356.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7372" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/6437f7c2f86d309ca000d0a33885d7bc" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.273356" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.273356" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.383520" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-02T00:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7q45-jp5q-j29q/GHSA-7q45-jp5q-j29q.json b/advisories/unreviewed/2024/08/GHSA-7q45-jp5q-j29q/GHSA-7q45-jp5q-j29q.json new file mode 100644 index 00000000000..8ee753693b3 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-7q45-jp5q-j29q/GHSA-7q45-jp5q-j29q.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7q45-jp5q-j29q", + "modified": "2024-08-02T00:31:26Z", + "published": "2024-08-02T00:31:26Z", + "aliases": [ + "CVE-2024-7373" + ], + "details": "A vulnerability classified as critical has been found in SourceCodester Simple Realtime Quiz System 1.0. This affects an unknown part of the file /ajax.php?action=load_answered. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273357 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7373" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/9bcb8b09acce0d5a8a453dfd5093881d" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.273357" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.273357" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.383521" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-02T00:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-89fp-7f25-27m5/GHSA-89fp-7f25-27m5.json b/advisories/unreviewed/2024/08/GHSA-89fp-7f25-27m5/GHSA-89fp-7f25-27m5.json new file mode 100644 index 00000000000..e59f2b36641 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-89fp-7f25-27m5/GHSA-89fp-7f25-27m5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-89fp-7f25-27m5", + "modified": "2024-08-02T00:31:26Z", + "published": "2024-08-02T00:31:26Z", + "aliases": [ + "CVE-2024-39627" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Imagely NextGEN Gallery allows Stored XSS.This issue affects NextGEN Gallery: from n/a through 3.59.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39627" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/nextgen-gallery/wordpress-photo-gallery-sliders-proofing-and-themes-nextgen-gallery-plugin-3-59-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T23:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-99rv-792c-46f6/GHSA-99rv-792c-46f6.json b/advisories/unreviewed/2024/08/GHSA-99rv-792c-46f6/GHSA-99rv-792c-46f6.json new file mode 100644 index 00000000000..ca3615ab7c4 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-99rv-792c-46f6/GHSA-99rv-792c-46f6.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-99rv-792c-46f6", + "modified": "2024-08-02T00:31:26Z", + "published": "2024-08-02T00:31:26Z", + "aliases": [ + "CVE-2024-7370" + ], + "details": "A vulnerability was found in SourceCodester Simple Realtime Quiz System 1.0. It has been classified as critical. Affected is an unknown function of the file /manage_quiz.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-273354 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7370" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/df0a5328ddb5b43ab7fa933aee500155" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.273354" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.273354" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.383518" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T23:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-9p4j-3hc4-v72r/GHSA-9p4j-3hc4-v72r.json b/advisories/unreviewed/2024/08/GHSA-9p4j-3hc4-v72r/GHSA-9p4j-3hc4-v72r.json new file mode 100644 index 00000000000..48e6cb936fd --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-9p4j-3hc4-v72r/GHSA-9p4j-3hc4-v72r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9p4j-3hc4-v72r", + "modified": "2024-08-02T00:31:25Z", + "published": "2024-08-02T00:31:25Z", + "aliases": [ + "CVE-2024-39655" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in LiquidPoll LiquidPoll – Advanced Polls for Creators and Brands.This issue affects LiquidPoll – Advanced Polls for Creators and Brands: from n/a through 3.3.77.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39655" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-poll/wordpress-liquidpoll-plugin-3-3-77-unauthenticated-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T22:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-c8p5-pv85-r8m8/GHSA-c8p5-pv85-r8m8.json b/advisories/unreviewed/2024/08/GHSA-c8p5-pv85-r8m8/GHSA-c8p5-pv85-r8m8.json new file mode 100644 index 00000000000..be4dc0539eb --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-c8p5-pv85-r8m8/GHSA-c8p5-pv85-r8m8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c8p5-pv85-r8m8", + "modified": "2024-08-02T00:31:26Z", + "published": "2024-08-02T00:31:26Z", + "aliases": [ + "CVE-2024-39647" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kofi Mokome Message Filter for Contact Form 7 allows Reflected XSS.This issue affects Message Filter for Contact Form 7: from n/a through 1.6.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39647" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/cf7-message-filter/wordpress-message-filter-for-contact-form-7-plugin-1-6-1-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T23:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-cjm7-rmgv-2xvx/GHSA-cjm7-rmgv-2xvx.json b/advisories/unreviewed/2024/08/GHSA-cjm7-rmgv-2xvx/GHSA-cjm7-rmgv-2xvx.json new file mode 100644 index 00000000000..e059dacf6c4 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-cjm7-rmgv-2xvx/GHSA-cjm7-rmgv-2xvx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cjm7-rmgv-2xvx", + "modified": "2024-08-02T00:31:25Z", + "published": "2024-08-02T00:31:25Z", + "aliases": [ + "CVE-2024-39648" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themewinter Eventin allows Stored XSS.This issue affects Eventin: from n/a through 4.0.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39648" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-event-solution/wordpress-eventin-plugin-4-0-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T22:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-cv7w-57fr-fp46/GHSA-cv7w-57fr-fp46.json b/advisories/unreviewed/2024/08/GHSA-cv7w-57fr-fp46/GHSA-cv7w-57fr-fp46.json new file mode 100644 index 00000000000..86fcea15b3f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-cv7w-57fr-fp46/GHSA-cv7w-57fr-fp46.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cv7w-57fr-fp46", + "modified": "2024-08-02T00:31:26Z", + "published": "2024-08-02T00:31:26Z", + "aliases": [ + "CVE-2024-7371" + ], + "details": "A vulnerability was found in SourceCodester Simple Realtime Quiz System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /quiz_view.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273355.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7371" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/e45c2b283d29bc0a2f3551ca9cb45999" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.273355" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.273355" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.383519" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T23:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-cvv3-vch8-mp39/GHSA-cvv3-vch8-mp39.json b/advisories/unreviewed/2024/08/GHSA-cvv3-vch8-mp39/GHSA-cvv3-vch8-mp39.json new file mode 100644 index 00000000000..c3f7781c017 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-cvv3-vch8-mp39/GHSA-cvv3-vch8-mp39.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cvv3-vch8-mp39", + "modified": "2024-08-02T00:31:25Z", + "published": "2024-08-02T00:31:25Z", + "aliases": [ + "CVE-2024-32862" + ], + "details": "Under certain circumstances the ExacqVision Web Services does not provide sufficient protection from untrusted domains.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32862" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-214-02" + }, + { + "type": "WEB", + "url": "https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-942" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T22:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-cwqj-wjpc-hr2x/GHSA-cwqj-wjpc-hr2x.json b/advisories/unreviewed/2024/08/GHSA-cwqj-wjpc-hr2x/GHSA-cwqj-wjpc-hr2x.json new file mode 100644 index 00000000000..876e2565396 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-cwqj-wjpc-hr2x/GHSA-cwqj-wjpc-hr2x.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cwqj-wjpc-hr2x", + "modified": "2024-08-02T00:31:25Z", + "published": "2024-08-02T00:31:25Z", + "aliases": [ + "CVE-2024-32865" + ], + "details": "Under certain circumstances the exacqVision Server will not properly validate TLS certificates provided by connected devices.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32865" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-214-05" + }, + { + "type": "WEB", + "url": "https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-295" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T22:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-f34v-3642-4mw8/GHSA-f34v-3642-4mw8.json b/advisories/unreviewed/2024/08/GHSA-f34v-3642-4mw8/GHSA-f34v-3642-4mw8.json new file mode 100644 index 00000000000..0bb1f6f50d5 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-f34v-3642-4mw8/GHSA-f34v-3642-4mw8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f34v-3642-4mw8", + "modified": "2024-08-02T00:31:25Z", + "published": "2024-08-02T00:31:25Z", + "aliases": [ + "CVE-2024-39660" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jordy Meow Photo Engine allows Stored XSS.This issue affects Photo Engine: from n/a through 6.3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39660" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wplr-sync/wordpress-photo-engine-media-organizer-lightroom-plugin-6-3-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T22:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-f97v-4q2m-vp42/GHSA-f97v-4q2m-vp42.json b/advisories/unreviewed/2024/08/GHSA-f97v-4q2m-vp42/GHSA-f97v-4q2m-vp42.json new file mode 100644 index 00000000000..a11ddade75d --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-f97v-4q2m-vp42/GHSA-f97v-4q2m-vp42.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f97v-4q2m-vp42", + "modified": "2024-08-02T00:31:26Z", + "published": "2024-08-02T00:31:26Z", + "aliases": [ + "CVE-2024-39643" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in RegistrationMagic Forms RegistrationMagic allows Stored XSS.This issue affects RegistrationMagic: from n/a through 6.0.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39643" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/custom-registration-form-builder-with-submission-manager/wordpress-registrationmagic-custom-registration-forms-user-registration-payment-and-user-login-plugin-6-0-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T23:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-fxpg-42g8-chm6/GHSA-fxpg-42g8-chm6.json b/advisories/unreviewed/2024/08/GHSA-fxpg-42g8-chm6/GHSA-fxpg-42g8-chm6.json new file mode 100644 index 00000000000..f4e6e1aecd8 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-fxpg-42g8-chm6/GHSA-fxpg-42g8-chm6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fxpg-42g8-chm6", + "modified": "2024-08-02T00:31:26Z", + "published": "2024-08-02T00:31:26Z", + "aliases": [ + "CVE-2024-39631" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Contest Gallery allows Stored XSS.This issue affects Contest Gallery: from n/a through 23.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39631" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/contest-gallery/wordpress-contest-gallery-plugin-23-1-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T23:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-g3gw-72qx-2fpg/GHSA-g3gw-72qx-2fpg.json b/advisories/unreviewed/2024/08/GHSA-g3gw-72qx-2fpg/GHSA-g3gw-72qx-2fpg.json new file mode 100644 index 00000000000..03d760983c7 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-g3gw-72qx-2fpg/GHSA-g3gw-72qx-2fpg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g3gw-72qx-2fpg", + "modified": "2024-08-02T00:31:25Z", + "published": "2024-08-02T00:31:25Z", + "aliases": [ + "CVE-2024-39667" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BdThemes Element Pack Elementor Addons allows Stored XSS.This issue affects Element Pack Elementor Addons: from n/a through 5.6.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39667" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/bdthemes-element-pack-lite/wordpress-element-pack-elementor-addons-plugin-5-6-11-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T22:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-hqf8-3w52-4344/GHSA-hqf8-3w52-4344.json b/advisories/unreviewed/2024/08/GHSA-hqf8-3w52-4344/GHSA-hqf8-3w52-4344.json new file mode 100644 index 00000000000..0aa9fae58ec --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-hqf8-3w52-4344/GHSA-hqf8-3w52-4344.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hqf8-3w52-4344", + "modified": "2024-08-02T00:31:25Z", + "published": "2024-08-02T00:31:25Z", + "aliases": [ + "CVE-2024-32931" + ], + "details": "Under certain circumstances the exacqVision Web Service can expose authentication token details within communications.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32931" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-214-06" + }, + { + "type": "WEB", + "url": "https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-598" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T22:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-j37w-6f9h-3r4c/GHSA-j37w-6f9h-3r4c.json b/advisories/unreviewed/2024/08/GHSA-j37w-6f9h-3r4c/GHSA-j37w-6f9h-3r4c.json new file mode 100644 index 00000000000..201edc75955 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-j37w-6f9h-3r4c/GHSA-j37w-6f9h-3r4c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j37w-6f9h-3r4c", + "modified": "2024-08-02T00:31:26Z", + "published": "2024-08-02T00:31:26Z", + "aliases": [ + "CVE-2024-39626" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in 5 Star Plugins Pretty Simple Popup Builder allows Stored XSS.This issue affects Pretty Simple Popup Builder: from n/a through 1.0.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39626" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/pretty-simple-popup-builder/wordpress-pretty-simple-popup-builder-plugin-1-0-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T23:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-j6mx-j4mf-grmg/GHSA-j6mx-j4mf-grmg.json b/advisories/unreviewed/2024/08/GHSA-j6mx-j4mf-grmg/GHSA-j6mx-j4mf-grmg.json new file mode 100644 index 00000000000..47c108a5ec0 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-j6mx-j4mf-grmg/GHSA-j6mx-j4mf-grmg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6mx-j4mf-grmg", + "modified": "2024-08-02T00:31:25Z", + "published": "2024-08-02T00:31:25Z", + "aliases": [ + "CVE-2024-39656" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Uncanny Owl Tin Canny Reporting for LearnDash allows Reflected XSS.This issue affects Tin Canny Reporting for LearnDash: from n/a through 4.3.0.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39656" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/tin-canny-learndash-reporting/wordpress-tin-canny-reporting-for-learndash-plugin-4-3-0-7-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T22:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-jphg-q3wq-cw42/GHSA-jphg-q3wq-cw42.json b/advisories/unreviewed/2024/08/GHSA-jphg-q3wq-cw42/GHSA-jphg-q3wq-cw42.json new file mode 100644 index 00000000000..db4ce37c29c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-jphg-q3wq-cw42/GHSA-jphg-q3wq-cw42.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jphg-q3wq-cw42", + "modified": "2024-08-02T00:31:25Z", + "published": "2024-08-02T00:31:25Z", + "aliases": [ + "CVE-2024-39649" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor allows Stored XSS.This issue affects Essential Addons for Elementor: from n/a through 5.9.26.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39649" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/essential-addons-for-elementor-lite/wordpress-essential-addons-for-elementor-plugin-5-9-26-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T22:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-mg9x-hp2r-28xj/GHSA-mg9x-hp2r-28xj.json b/advisories/unreviewed/2024/08/GHSA-mg9x-hp2r-28xj/GHSA-mg9x-hp2r-28xj.json new file mode 100644 index 00000000000..17ff15f7411 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-mg9x-hp2r-28xj/GHSA-mg9x-hp2r-28xj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mg9x-hp2r-28xj", + "modified": "2024-08-02T00:31:25Z", + "published": "2024-08-02T00:31:25Z", + "aliases": [ + "CVE-2024-39665" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in YMC Filter & Grids allows Stored XSS.This issue affects Filter & Grids: from n/a through 2.9.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39665" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ymc-smart-filter/wordpress-filter-grids-plugin-2-9-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T22:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-p34q-fj6q-86m9/GHSA-p34q-fj6q-86m9.json b/advisories/unreviewed/2024/08/GHSA-p34q-fj6q-86m9/GHSA-p34q-fj6q-86m9.json new file mode 100644 index 00000000000..e7c51ce515b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-p34q-fj6q-86m9/GHSA-p34q-fj6q-86m9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p34q-fj6q-86m9", + "modified": "2024-08-02T00:31:25Z", + "published": "2024-08-02T00:31:25Z", + "aliases": [ + "CVE-2024-39663" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Epsiloncool WP Fast Total Search allows Stored XSS.This issue affects WP Fast Total Search: from n/a through 1.68.232.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39663" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/fulltext-search/wordpress-wp-fast-total-search-plugin-1-68-232-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T22:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-phwc-7hvm-qv33/GHSA-phwc-7hvm-qv33.json b/advisories/unreviewed/2024/08/GHSA-phwc-7hvm-qv33/GHSA-phwc-7hvm-qv33.json new file mode 100644 index 00000000000..9d319bc58db --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-phwc-7hvm-qv33/GHSA-phwc-7hvm-qv33.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phwc-7hvm-qv33", + "modified": "2024-08-02T00:31:26Z", + "published": "2024-08-02T00:31:26Z", + "aliases": [ + "CVE-2024-7368" + ], + "details": "A vulnerability has been found in SourceCodester Simple Realtime Quiz System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /ajax.php?action=save_quiz. The manipulation of the argument title leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273352.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7368" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/ad93f7046d905cef9277304dd3ac8061" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.273352" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.273352" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.383516" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T22:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-ppfv-j8g7-xg43/GHSA-ppfv-j8g7-xg43.json b/advisories/unreviewed/2024/08/GHSA-ppfv-j8g7-xg43/GHSA-ppfv-j8g7-xg43.json new file mode 100644 index 00000000000..d084f36de50 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-ppfv-j8g7-xg43/GHSA-ppfv-j8g7-xg43.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ppfv-j8g7-xg43", + "modified": "2024-08-02T00:31:26Z", + "published": "2024-08-02T00:31:26Z", + "aliases": [ + "CVE-2024-39646" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kunal Nagar Custom 404 Pro allows Reflected XSS.This issue affects Custom 404 Pro: from n/a through 3.11.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39646" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/custom-404-pro/wordpress-custom-404-pro-plugin-3-11-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T23:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-pwrj-w99j-qxmh/GHSA-pwrj-w99j-qxmh.json b/advisories/unreviewed/2024/08/GHSA-pwrj-w99j-qxmh/GHSA-pwrj-w99j-qxmh.json new file mode 100644 index 00000000000..1b803447b50 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-pwrj-w99j-qxmh/GHSA-pwrj-w99j-qxmh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pwrj-w99j-qxmh", + "modified": "2024-08-02T00:31:25Z", + "published": "2024-08-02T00:31:25Z", + "aliases": [ + "CVE-2024-39659" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Lester ‘GaMerZ’ Chan WP-PostRatings allows Stored XSS.This issue affects WP-PostRatings: from n/a through 1.91.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39659" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-postratings/wordpress-wp-postratings-plugin-1-91-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T22:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-rmmg-jpmw-c98j/GHSA-rmmg-jpmw-c98j.json b/advisories/unreviewed/2024/08/GHSA-rmmg-jpmw-c98j/GHSA-rmmg-jpmw-c98j.json new file mode 100644 index 00000000000..d8954ff0b30 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-rmmg-jpmw-c98j/GHSA-rmmg-jpmw-c98j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rmmg-jpmw-c98j", + "modified": "2024-08-02T00:31:26Z", + "published": "2024-08-02T00:31:26Z", + "aliases": [ + "CVE-2024-39644" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Modernaweb Studio Black Widgets For Elementor allows Stored XSS.This issue affects Black Widgets For Elementor: from n/a through 1.3.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39644" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/black-widgets/wordpress-black-widgets-for-elementor-plugin-1-3-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T23:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-vrq5-q7cf-pv79/GHSA-vrq5-q7cf-pv79.json b/advisories/unreviewed/2024/08/GHSA-vrq5-q7cf-pv79/GHSA-vrq5-q7cf-pv79.json new file mode 100644 index 00000000000..4650d8bf29e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-vrq5-q7cf-pv79/GHSA-vrq5-q7cf-pv79.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vrq5-q7cf-pv79", + "modified": "2024-08-02T00:31:25Z", + "published": "2024-08-02T00:31:25Z", + "aliases": [ + "CVE-2024-39637" + ], + "details": "Server Side Request Forgery (SSRF) vulnerability in Pixelcurve Edubin edubin.This issue affects Edubin: from n/a through 9.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39637" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/edubin/wordpress-edubin-theme-9-2-0-server-side-request-forgery-ssrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T22:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-w8m2-fjpm-xwwh/GHSA-w8m2-fjpm-xwwh.json b/advisories/unreviewed/2024/08/GHSA-w8m2-fjpm-xwwh/GHSA-w8m2-fjpm-xwwh.json new file mode 100644 index 00000000000..9c82d8687a4 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-w8m2-fjpm-xwwh/GHSA-w8m2-fjpm-xwwh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w8m2-fjpm-xwwh", + "modified": "2024-08-02T00:31:26Z", + "published": "2024-08-02T00:31:26Z", + "aliases": [ + "CVE-2024-39629" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemeGrill Himalayas allows Stored XSS.This issue affects Himalayas: from n/a through 1.3.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39629" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/himalayas/wordpress-himalayas-theme-1-3-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T23:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-xw52-cr9c-4r6m/GHSA-xw52-cr9c-4r6m.json b/advisories/unreviewed/2024/08/GHSA-xw52-cr9c-4r6m/GHSA-xw52-cr9c-4r6m.json new file mode 100644 index 00000000000..21677453f95 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-xw52-cr9c-4r6m/GHSA-xw52-cr9c-4r6m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xw52-cr9c-4r6m", + "modified": "2024-08-02T00:31:25Z", + "published": "2024-08-02T00:31:25Z", + "aliases": [ + "CVE-2024-39662" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Modernaweb Studio Black Widgets For Elementor allows Stored XSS.This issue affects Black Widgets For Elementor: from n/a through 1.3.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39662" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/black-widgets/wordpress-black-widgets-for-elementor-plugin-1-3-5-cross-site-scripting-xss-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T22:15:27Z" + } +} \ No newline at end of file