Publish Advisories

GHSA-42g6-fx4g-4pxv
GHSA-4rj5-hv6x-v84g
GHSA-85f4-3cvc-fmrq
GHSA-924x-9wjq-6fqr
GHSA-9cm6-r59j-22jc
GHSA-9rr6-j7h7-p29p
GHSA-c8h5-gmvf-fxhw
GHSA-cr2c-p6wc-8hfh
GHSA-cx9m-x7w8-76m2
GHSA-fpmf-fc9x-9w73
GHSA-h9h4-qmr7-m6fj
GHSA-j9h6-5r2h-wq4m
GHSA-jq74-w56w-cjqw
GHSA-mgj2-4fwc-v47j
GHSA-mm62-pv5h-xg4v
GHSA-pc2v-g9xh-4hcw
GHSA-r8g7-9pvc-p6p6
GHSA-rm96-h83h-vg96
GHSA-v4m9-9x56-7gh6
GHSA-v5pv-v2xp-jjp2
GHSA-v5r5-978f-9w52
This commit is contained in:
advisory-database[bot]
2024-05-22 15:32:25 +00:00
parent ba7403d78b
commit f132f13464
21 changed files with 719 additions and 1 deletions
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-42g6-fx4g-4pxv",
"modified": "2024-05-22T15:31:01Z",
"published": "2024-05-22T15:31:01Z",
"aliases": [
"CVE-2024-33219"
],
"details": "An issue in the component AsIO64.sys of ASUSTeK Computer Inc ASUS SABERTOOTH X99 Driver v1.0.1.0 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33219"
},
{
"type": "WEB",
"url": "https://github.com/DriverHunter/Win-Driver-EXP/tree/main/CVE-2024-33219"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-22T15:15:28Z"
}
}
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4rj5-hv6x-v84g",
"modified": "2024-05-22T15:31:01Z",
"published": "2024-05-22T15:31:01Z",
"aliases": [
"CVE-2024-3926"
],
"details": "The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom_attributes value in widgets in all versions up to, and including, 5.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3926"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/bdthemes-element-pack-lite/tags/5.6.0/modules/creative-button/widgets/creative-button.php#L648"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/3066178"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f931cf8e-01dd-4f0b-ac86-6e0654fd1597?source=cve"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-22T15:15:28Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-85f4-3cvc-fmrq",
"modified": "2024-05-22T15:31:00Z",
"published": "2024-05-22T15:31:00Z",
"aliases": [
"CVE-2024-35475"
],
"details": "A Cross-Site Request Forgery (CSRF) vulnerability was discovered in OpenKM Community Edition on or before version 6.3.12. The vulnerability exists in /admin/DatabaseQuery, which allows an attacker to manipulate a victim with administrative privileges to execute arbitrary SQL commands.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35475"
},
{
"type": "WEB",
"url": "https://github.com/carsonchan12345/OpenKM-CSRF-PoC"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-22T14:15:08Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-924x-9wjq-6fqr",
"modified": "2024-05-22T15:31:01Z",
"published": "2024-05-22T15:31:01Z",
"aliases": [
"CVE-2024-35560"
],
"details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ca_deal.php?mudi=del&dataType=&dataTypeCN.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35560"
},
{
"type": "WEB",
"url": "https://github.com/bearman113/1.md/blob/main/25/csrf.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-22T14:15:09Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9cm6-r59j-22jc",
"modified": "2024-05-22T15:31:01Z",
"published": "2024-05-22T15:31:01Z",
"aliases": [
"CVE-2024-35561"
],
"details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ca_deal.php?mudi=add&nohrefStr=close.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35561"
},
{
"type": "WEB",
"url": "https://github.com/bearman113/1.md/blob/main/23/csrf.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-22T14:15:09Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9rr6-j7h7-p29p",
"modified": "2024-05-22T15:31:00Z",
"published": "2024-05-22T15:31:00Z",
"aliases": [
"CVE-2024-35553"
],
"details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoMove_deal.php?mudi=add&nohrefStr=close.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35553"
},
{
"type": "WEB",
"url": "https://github.com/bearman113/1.md/blob/main/21/csrf.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-22T14:15:09Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c8h5-gmvf-fxhw",
"modified": "2024-05-22T15:31:01Z",
"published": "2024-05-22T15:31:01Z",
"aliases": [
"CVE-2024-33218"
],
"details": "An issue in the component AsUpIO64.sys of ASUSTeK Computer Inc ASUS USB 3.0 Boost Storage Driver 5.30.20.0 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33218"
},
{
"type": "WEB",
"url": "https://github.com/DriverHunter/Win-Driver-EXP/tree/main/CVE-2024-33218"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-22T15:15:28Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cr2c-p6wc-8hfh",
"modified": "2024-05-22T12:32:28Z",
"modified": "2024-05-22T15:30:59Z",
"published": "2024-05-22T12:32:28Z",
"aliases": [
"CVE-2024-36010"
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cx9m-x7w8-76m2",
"modified": "2024-05-22T15:31:01Z",
"published": "2024-05-22T15:31:01Z",
"aliases": [
"CVE-2024-33220"
],
"details": "An issue in the component AslO3_64.sys of ASUSTeK Computer Inc AISuite3 v3.03.36 3.03.36 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33220"
},
{
"type": "WEB",
"url": "https://github.com/DriverHunter/Win-Driver-EXP/tree/main/CVE-2024-33220"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-22T15:15:28Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fpmf-fc9x-9w73",
"modified": "2024-05-22T15:31:01Z",
"published": "2024-05-22T15:31:01Z",
"aliases": [
"CVE-2024-33221"
],
"details": "An issue in the component AsusBSItf.sys of ASUSTeK Computer Inc ASUS BIOS Flash Driver v3.2.12.0 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33221"
},
{
"type": "WEB",
"url": "https://github.com/DriverHunter/Win-Driver-EXP/tree/main/CVE-2024-33221"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-22T15:15:28Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h9h4-qmr7-m6fj",
"modified": "2024-05-22T15:31:00Z",
"published": "2024-05-22T15:31:00Z",
"aliases": [
"CVE-2024-35555"
],
"details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/share_switch.php?mudi=switch&dataType=newsWeb&fieldName=state&fieldName2=state&tabName=infoWeb&dataID=40.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35555"
},
{
"type": "WEB",
"url": "https://github.com/bearman113/1.md/blob/main/18/csrf.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-22T14:15:09Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j9h6-5r2h-wq4m",
"modified": "2024-05-22T15:31:00Z",
"published": "2024-05-22T15:31:00Z",
"aliases": [
"CVE-2024-35552"
],
"details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoMove_deal.php?mudi=del&dataType=logo&dataTypeCN.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35552"
},
{
"type": "WEB",
"url": "https://github.com/bearman113/1.md/blob/main/20/csrf.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-22T14:15:09Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jq74-w56w-cjqw",
"modified": "2024-05-22T15:31:01Z",
"published": "2024-05-22T15:31:01Z",
"aliases": [
"CVE-2024-35559"
],
"details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoMove_deal.php?mudi=rev&nohrefStr=close.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35559"
},
{
"type": "WEB",
"url": "https://github.com/bearman113/1.md/blob/main/22/csrf.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-22T14:15:09Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mgj2-4fwc-v47j",
"modified": "2024-05-22T15:30:59Z",
"published": "2024-05-22T15:30:59Z",
"aliases": [
"CVE-2024-35409"
],
"details": "WeBid 1.1.2 is vulnerable to SQL Injection via admin/tax.php.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35409"
},
{
"type": "WEB",
"url": "https://github.com/ixpqxi/CVE_LIST/blob/master/WeBid_sqli/WeBid_v1.1.2_sql_injection_vulnerability.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-22T14:15:08Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mm62-pv5h-xg4v",
"modified": "2024-05-22T15:31:00Z",
"published": "2024-05-22T15:31:00Z",
"aliases": [
"CVE-2024-35551"
],
"details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoWeb_deal.php?mudi=add.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35551"
},
{
"type": "WEB",
"url": "https://github.com/bearman113/1.md/blob/main/16/csrf.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-22T14:15:09Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pc2v-g9xh-4hcw",
"modified": "2024-05-22T15:31:01Z",
"published": "2024-05-22T15:31:00Z",
"aliases": [
"CVE-2024-35557"
],
"details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/vpsApi_deal.php?mudi=rev&nohrefStr=close.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35557"
},
{
"type": "WEB",
"url": "https://github.com/bearman113/1.md/blob/main/27/csrf.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-22T14:15:09Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r8g7-9pvc-p6p6",
"modified": "2024-05-22T15:31:01Z",
"published": "2024-05-22T15:31:01Z",
"aliases": [
"CVE-2024-35558"
],
"details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ca_deal.php?mudi=rev&nohrefStr=close.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35558"
},
{
"type": "WEB",
"url": "https://github.com/bearman113/1.md/blob/main/24/csrf.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-22T14:15:09Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rm96-h83h-vg96",
"modified": "2024-05-22T15:31:00Z",
"published": "2024-05-22T15:31:00Z",
"aliases": [
"CVE-2024-35550"
],
"details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoWeb_deal.php?mudi=rev.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35550"
},
{
"type": "WEB",
"url": "https://github.com/bearman113/1.md/blob/main/17/csrf.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-22T14:15:08Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v4m9-9x56-7gh6",
"modified": "2024-05-22T15:30:59Z",
"published": "2024-05-22T15:30:59Z",
"aliases": [
"CVE-2024-4261"
],
"details": "The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.9.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute arbitrary shortcodes.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4261"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/lead-form-builder/trunk/block/app.php#L24"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/858d8641-7455-47c2-9639-480ce4ec3540?source=cve"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-22T13:15:27Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v5pv-v2xp-jjp2",
"modified": "2024-05-22T15:31:00Z",
"published": "2024-05-22T15:31:00Z",
"aliases": [
"CVE-2024-35554"
],
"details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoWeb_deal.php?mudi=del&dataType=newsWeb&dataTypeCN.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35554"
},
{
"type": "WEB",
"url": "https://github.com/bearman113/1.md/blob/main/19/csrf.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-22T14:15:09Z"
}
}

Some files were not shown because too many files have changed in this diff Show More