diff --git a/advisories/unreviewed/2024/05/GHSA-42g6-fx4g-4pxv/GHSA-42g6-fx4g-4pxv.json b/advisories/unreviewed/2024/05/GHSA-42g6-fx4g-4pxv/GHSA-42g6-fx4g-4pxv.json new file mode 100644 index 00000000000..482c2b52ac2 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-42g6-fx4g-4pxv/GHSA-42g6-fx4g-4pxv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-42g6-fx4g-4pxv", + "modified": "2024-05-22T15:31:01Z", + "published": "2024-05-22T15:31:01Z", + "aliases": [ + "CVE-2024-33219" + ], + "details": "An issue in the component AsIO64.sys of ASUSTeK Computer Inc ASUS SABERTOOTH X99 Driver v1.0.1.0 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33219" + }, + { + "type": "WEB", + "url": "https://github.com/DriverHunter/Win-Driver-EXP/tree/main/CVE-2024-33219" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T15:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-4rj5-hv6x-v84g/GHSA-4rj5-hv6x-v84g.json b/advisories/unreviewed/2024/05/GHSA-4rj5-hv6x-v84g/GHSA-4rj5-hv6x-v84g.json new file mode 100644 index 00000000000..8bd89a6b844 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-4rj5-hv6x-v84g/GHSA-4rj5-hv6x-v84g.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4rj5-hv6x-v84g", + "modified": "2024-05-22T15:31:01Z", + "published": "2024-05-22T15:31:01Z", + "aliases": [ + "CVE-2024-3926" + ], + "details": "The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom_attributes value in widgets in all versions up to, and including, 5.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3926" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/bdthemes-element-pack-lite/tags/5.6.0/modules/creative-button/widgets/creative-button.php#L648" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3066178" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f931cf8e-01dd-4f0b-ac86-6e0654fd1597?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T15:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-85f4-3cvc-fmrq/GHSA-85f4-3cvc-fmrq.json b/advisories/unreviewed/2024/05/GHSA-85f4-3cvc-fmrq/GHSA-85f4-3cvc-fmrq.json new file mode 100644 index 00000000000..ba9268fba7b --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-85f4-3cvc-fmrq/GHSA-85f4-3cvc-fmrq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-85f4-3cvc-fmrq", + "modified": "2024-05-22T15:31:00Z", + "published": "2024-05-22T15:31:00Z", + "aliases": [ + "CVE-2024-35475" + ], + "details": "A Cross-Site Request Forgery (CSRF) vulnerability was discovered in OpenKM Community Edition on or before version 6.3.12. The vulnerability exists in /admin/DatabaseQuery, which allows an attacker to manipulate a victim with administrative privileges to execute arbitrary SQL commands.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35475" + }, + { + "type": "WEB", + "url": "https://github.com/carsonchan12345/OpenKM-CSRF-PoC" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-924x-9wjq-6fqr/GHSA-924x-9wjq-6fqr.json b/advisories/unreviewed/2024/05/GHSA-924x-9wjq-6fqr/GHSA-924x-9wjq-6fqr.json new file mode 100644 index 00000000000..ecf8a40df7a --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-924x-9wjq-6fqr/GHSA-924x-9wjq-6fqr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-924x-9wjq-6fqr", + "modified": "2024-05-22T15:31:01Z", + "published": "2024-05-22T15:31:01Z", + "aliases": [ + "CVE-2024-35560" + ], + "details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ca_deal.php?mudi=del&dataType=&dataTypeCN.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35560" + }, + { + "type": "WEB", + "url": "https://github.com/bearman113/1.md/blob/main/25/csrf.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-9cm6-r59j-22jc/GHSA-9cm6-r59j-22jc.json b/advisories/unreviewed/2024/05/GHSA-9cm6-r59j-22jc/GHSA-9cm6-r59j-22jc.json new file mode 100644 index 00000000000..da1bd59cf9f --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-9cm6-r59j-22jc/GHSA-9cm6-r59j-22jc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9cm6-r59j-22jc", + "modified": "2024-05-22T15:31:01Z", + "published": "2024-05-22T15:31:01Z", + "aliases": [ + "CVE-2024-35561" + ], + "details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ca_deal.php?mudi=add&nohrefStr=close.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35561" + }, + { + "type": "WEB", + "url": "https://github.com/bearman113/1.md/blob/main/23/csrf.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-9rr6-j7h7-p29p/GHSA-9rr6-j7h7-p29p.json b/advisories/unreviewed/2024/05/GHSA-9rr6-j7h7-p29p/GHSA-9rr6-j7h7-p29p.json new file mode 100644 index 00000000000..900e8b7efc9 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-9rr6-j7h7-p29p/GHSA-9rr6-j7h7-p29p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9rr6-j7h7-p29p", + "modified": "2024-05-22T15:31:00Z", + "published": "2024-05-22T15:31:00Z", + "aliases": [ + "CVE-2024-35553" + ], + "details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoMove_deal.php?mudi=add&nohrefStr=close.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35553" + }, + { + "type": "WEB", + "url": "https://github.com/bearman113/1.md/blob/main/21/csrf.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-c8h5-gmvf-fxhw/GHSA-c8h5-gmvf-fxhw.json b/advisories/unreviewed/2024/05/GHSA-c8h5-gmvf-fxhw/GHSA-c8h5-gmvf-fxhw.json new file mode 100644 index 00000000000..32e304bcbef --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-c8h5-gmvf-fxhw/GHSA-c8h5-gmvf-fxhw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c8h5-gmvf-fxhw", + "modified": "2024-05-22T15:31:01Z", + "published": "2024-05-22T15:31:01Z", + "aliases": [ + "CVE-2024-33218" + ], + "details": "An issue in the component AsUpIO64.sys of ASUSTeK Computer Inc ASUS USB 3.0 Boost Storage Driver 5.30.20.0 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33218" + }, + { + "type": "WEB", + "url": "https://github.com/DriverHunter/Win-Driver-EXP/tree/main/CVE-2024-33218" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T15:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-cr2c-p6wc-8hfh/GHSA-cr2c-p6wc-8hfh.json b/advisories/unreviewed/2024/05/GHSA-cr2c-p6wc-8hfh/GHSA-cr2c-p6wc-8hfh.json index 78f7a03a223..a3b86bf5988 100644 --- a/advisories/unreviewed/2024/05/GHSA-cr2c-p6wc-8hfh/GHSA-cr2c-p6wc-8hfh.json +++ b/advisories/unreviewed/2024/05/GHSA-cr2c-p6wc-8hfh/GHSA-cr2c-p6wc-8hfh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cr2c-p6wc-8hfh", - "modified": "2024-05-22T12:32:28Z", + "modified": "2024-05-22T15:30:59Z", "published": "2024-05-22T12:32:28Z", "aliases": [ "CVE-2024-36010" diff --git a/advisories/unreviewed/2024/05/GHSA-cx9m-x7w8-76m2/GHSA-cx9m-x7w8-76m2.json b/advisories/unreviewed/2024/05/GHSA-cx9m-x7w8-76m2/GHSA-cx9m-x7w8-76m2.json new file mode 100644 index 00000000000..2a8170d2e41 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-cx9m-x7w8-76m2/GHSA-cx9m-x7w8-76m2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cx9m-x7w8-76m2", + "modified": "2024-05-22T15:31:01Z", + "published": "2024-05-22T15:31:01Z", + "aliases": [ + "CVE-2024-33220" + ], + "details": "An issue in the component AslO3_64.sys of ASUSTeK Computer Inc AISuite3 v3.03.36 3.03.36 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33220" + }, + { + "type": "WEB", + "url": "https://github.com/DriverHunter/Win-Driver-EXP/tree/main/CVE-2024-33220" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T15:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-fpmf-fc9x-9w73/GHSA-fpmf-fc9x-9w73.json b/advisories/unreviewed/2024/05/GHSA-fpmf-fc9x-9w73/GHSA-fpmf-fc9x-9w73.json new file mode 100644 index 00000000000..933ac032f37 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-fpmf-fc9x-9w73/GHSA-fpmf-fc9x-9w73.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fpmf-fc9x-9w73", + "modified": "2024-05-22T15:31:01Z", + "published": "2024-05-22T15:31:01Z", + "aliases": [ + "CVE-2024-33221" + ], + "details": "An issue in the component AsusBSItf.sys of ASUSTeK Computer Inc ASUS BIOS Flash Driver v3.2.12.0 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33221" + }, + { + "type": "WEB", + "url": "https://github.com/DriverHunter/Win-Driver-EXP/tree/main/CVE-2024-33221" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T15:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-h9h4-qmr7-m6fj/GHSA-h9h4-qmr7-m6fj.json b/advisories/unreviewed/2024/05/GHSA-h9h4-qmr7-m6fj/GHSA-h9h4-qmr7-m6fj.json new file mode 100644 index 00000000000..c6d5da69429 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-h9h4-qmr7-m6fj/GHSA-h9h4-qmr7-m6fj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h9h4-qmr7-m6fj", + "modified": "2024-05-22T15:31:00Z", + "published": "2024-05-22T15:31:00Z", + "aliases": [ + "CVE-2024-35555" + ], + "details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/share_switch.php?mudi=switch&dataType=newsWeb&fieldName=state&fieldName2=state&tabName=infoWeb&dataID=40.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35555" + }, + { + "type": "WEB", + "url": "https://github.com/bearman113/1.md/blob/main/18/csrf.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-j9h6-5r2h-wq4m/GHSA-j9h6-5r2h-wq4m.json b/advisories/unreviewed/2024/05/GHSA-j9h6-5r2h-wq4m/GHSA-j9h6-5r2h-wq4m.json new file mode 100644 index 00000000000..220fb9dd513 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-j9h6-5r2h-wq4m/GHSA-j9h6-5r2h-wq4m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j9h6-5r2h-wq4m", + "modified": "2024-05-22T15:31:00Z", + "published": "2024-05-22T15:31:00Z", + "aliases": [ + "CVE-2024-35552" + ], + "details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoMove_deal.php?mudi=del&dataType=logo&dataTypeCN.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35552" + }, + { + "type": "WEB", + "url": "https://github.com/bearman113/1.md/blob/main/20/csrf.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-jq74-w56w-cjqw/GHSA-jq74-w56w-cjqw.json b/advisories/unreviewed/2024/05/GHSA-jq74-w56w-cjqw/GHSA-jq74-w56w-cjqw.json new file mode 100644 index 00000000000..b25a8607a23 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-jq74-w56w-cjqw/GHSA-jq74-w56w-cjqw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jq74-w56w-cjqw", + "modified": "2024-05-22T15:31:01Z", + "published": "2024-05-22T15:31:01Z", + "aliases": [ + "CVE-2024-35559" + ], + "details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoMove_deal.php?mudi=rev&nohrefStr=close.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35559" + }, + { + "type": "WEB", + "url": "https://github.com/bearman113/1.md/blob/main/22/csrf.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-mgj2-4fwc-v47j/GHSA-mgj2-4fwc-v47j.json b/advisories/unreviewed/2024/05/GHSA-mgj2-4fwc-v47j/GHSA-mgj2-4fwc-v47j.json new file mode 100644 index 00000000000..06137159b86 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-mgj2-4fwc-v47j/GHSA-mgj2-4fwc-v47j.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mgj2-4fwc-v47j", + "modified": "2024-05-22T15:30:59Z", + "published": "2024-05-22T15:30:59Z", + "aliases": [ + "CVE-2024-35409" + ], + "details": "WeBid 1.1.2 is vulnerable to SQL Injection via admin/tax.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35409" + }, + { + "type": "WEB", + "url": "https://github.com/ixpqxi/CVE_LIST/blob/master/WeBid_sqli/WeBid_v1.1.2_sql_injection_vulnerability.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-mm62-pv5h-xg4v/GHSA-mm62-pv5h-xg4v.json b/advisories/unreviewed/2024/05/GHSA-mm62-pv5h-xg4v/GHSA-mm62-pv5h-xg4v.json new file mode 100644 index 00000000000..db0bb5fd9d4 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-mm62-pv5h-xg4v/GHSA-mm62-pv5h-xg4v.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mm62-pv5h-xg4v", + "modified": "2024-05-22T15:31:00Z", + "published": "2024-05-22T15:31:00Z", + "aliases": [ + "CVE-2024-35551" + ], + "details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoWeb_deal.php?mudi=add.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35551" + }, + { + "type": "WEB", + "url": "https://github.com/bearman113/1.md/blob/main/16/csrf.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-pc2v-g9xh-4hcw/GHSA-pc2v-g9xh-4hcw.json b/advisories/unreviewed/2024/05/GHSA-pc2v-g9xh-4hcw/GHSA-pc2v-g9xh-4hcw.json new file mode 100644 index 00000000000..2ae60b28d1e --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-pc2v-g9xh-4hcw/GHSA-pc2v-g9xh-4hcw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pc2v-g9xh-4hcw", + "modified": "2024-05-22T15:31:01Z", + "published": "2024-05-22T15:31:00Z", + "aliases": [ + "CVE-2024-35557" + ], + "details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/vpsApi_deal.php?mudi=rev&nohrefStr=close.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35557" + }, + { + "type": "WEB", + "url": "https://github.com/bearman113/1.md/blob/main/27/csrf.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-r8g7-9pvc-p6p6/GHSA-r8g7-9pvc-p6p6.json b/advisories/unreviewed/2024/05/GHSA-r8g7-9pvc-p6p6/GHSA-r8g7-9pvc-p6p6.json new file mode 100644 index 00000000000..30e3a08da4d --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-r8g7-9pvc-p6p6/GHSA-r8g7-9pvc-p6p6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r8g7-9pvc-p6p6", + "modified": "2024-05-22T15:31:01Z", + "published": "2024-05-22T15:31:01Z", + "aliases": [ + "CVE-2024-35558" + ], + "details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ca_deal.php?mudi=rev&nohrefStr=close.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35558" + }, + { + "type": "WEB", + "url": "https://github.com/bearman113/1.md/blob/main/24/csrf.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-rm96-h83h-vg96/GHSA-rm96-h83h-vg96.json b/advisories/unreviewed/2024/05/GHSA-rm96-h83h-vg96/GHSA-rm96-h83h-vg96.json new file mode 100644 index 00000000000..d86f22f6cff --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-rm96-h83h-vg96/GHSA-rm96-h83h-vg96.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rm96-h83h-vg96", + "modified": "2024-05-22T15:31:00Z", + "published": "2024-05-22T15:31:00Z", + "aliases": [ + "CVE-2024-35550" + ], + "details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoWeb_deal.php?mudi=rev.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35550" + }, + { + "type": "WEB", + "url": "https://github.com/bearman113/1.md/blob/main/17/csrf.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-v4m9-9x56-7gh6/GHSA-v4m9-9x56-7gh6.json b/advisories/unreviewed/2024/05/GHSA-v4m9-9x56-7gh6/GHSA-v4m9-9x56-7gh6.json new file mode 100644 index 00000000000..399fdd9b78e --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-v4m9-9x56-7gh6/GHSA-v4m9-9x56-7gh6.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v4m9-9x56-7gh6", + "modified": "2024-05-22T15:30:59Z", + "published": "2024-05-22T15:30:59Z", + "aliases": [ + "CVE-2024-4261" + ], + "details": "The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.9.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute arbitrary shortcodes.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4261" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/lead-form-builder/trunk/block/app.php#L24" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/858d8641-7455-47c2-9639-480ce4ec3540?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T13:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-v5pv-v2xp-jjp2/GHSA-v5pv-v2xp-jjp2.json b/advisories/unreviewed/2024/05/GHSA-v5pv-v2xp-jjp2/GHSA-v5pv-v2xp-jjp2.json new file mode 100644 index 00000000000..4a583d8f285 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-v5pv-v2xp-jjp2/GHSA-v5pv-v2xp-jjp2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v5pv-v2xp-jjp2", + "modified": "2024-05-22T15:31:00Z", + "published": "2024-05-22T15:31:00Z", + "aliases": [ + "CVE-2024-35554" + ], + "details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoWeb_deal.php?mudi=del&dataType=newsWeb&dataTypeCN.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35554" + }, + { + "type": "WEB", + "url": "https://github.com/bearman113/1.md/blob/main/19/csrf.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-v5r5-978f-9w52/GHSA-v5r5-978f-9w52.json b/advisories/unreviewed/2024/05/GHSA-v5r5-978f-9w52/GHSA-v5r5-978f-9w52.json new file mode 100644 index 00000000000..c21f0c54fa1 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-v5r5-978f-9w52/GHSA-v5r5-978f-9w52.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v5r5-978f-9w52", + "modified": "2024-05-22T15:31:00Z", + "published": "2024-05-22T15:31:00Z", + "aliases": [ + "CVE-2024-35556" + ], + "details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/vpsSys_deal.php?mudi=infoSet.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35556" + }, + { + "type": "WEB", + "url": "https://github.com/bearman113/1.md/blob/main/26/csrf.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T14:15:09Z" + } +} \ No newline at end of file