Skip to content

Commit

Permalink
generated content from 2024-11-20
Browse files Browse the repository at this point in the history
  • Loading branch information
github-actions[bot] committed Nov 20, 2024
1 parent db49ca7 commit 3f9fac2
Show file tree
Hide file tree
Showing 357 changed files with 8,188 additions and 0 deletions.
356 changes: 356 additions & 0 deletions mapping.csv

Large diffs are not rendered by default.

Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
{
"type": "bundle",
"id": "bundle--3a7fbfb7-deab-442c-ba86-9dc6332f36a7",
"objects": [
{
"type": "vulnerability",
"spec_version": "2.1",
"id": "vulnerability--00a55bae-dab2-4403-9936-eb54b016b9b0",
"created_by_ref": "identity--8ce3f695-d5a4-4dc8-9e93-a65af453a31a",
"created": "2024-11-20T00:21:28.995091Z",
"modified": "2024-11-20T00:21:28.995091Z",
"name": "CVE-2024-51866",
"description": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mr. Riponshah Social button allows Stored XSS.This issue affects Social button: from n/a through 1.3.",
"external_references": [
{
"source_name": "cve",
"external_id": "CVE-2024-51866"
}
]
}
]
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
{
"type": "bundle",
"id": "bundle--6f94c658-e779-4d65-a742-acb0e5f1ba44",
"objects": [
{
"type": "vulnerability",
"spec_version": "2.1",
"id": "vulnerability--00ae4c90-a1e4-443d-9330-5235a706d720",
"created_by_ref": "identity--8ce3f695-d5a4-4dc8-9e93-a65af453a31a",
"created": "2024-11-20T00:21:28.895442Z",
"modified": "2024-11-20T00:21:28.895442Z",
"name": "CVE-2024-51881",
"description": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Beautimour Be Shortcodes allows DOM-Based XSS.This issue affects Be Shortcodes: from n/a through 1.0.0.",
"external_references": [
{
"source_name": "cve",
"external_id": "CVE-2024-51881"
}
]
}
]
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
{
"type": "bundle",
"id": "bundle--6d784341-a33c-4657-8283-80597a9b2180",
"objects": [
{
"type": "vulnerability",
"spec_version": "2.1",
"id": "vulnerability--00c34754-1640-48f5-9015-3b23d81bca04",
"created_by_ref": "identity--8ce3f695-d5a4-4dc8-9e93-a65af453a31a",
"created": "2024-11-20T00:21:29.00611Z",
"modified": "2024-11-20T00:21:29.00611Z",
"name": "CVE-2024-51852",
"description": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DynamicWebLab Dynamic Post Grid Elementor Addon allows DOM-Based XSS.This issue affects Dynamic Post Grid Elementor Addon: from n/a through 1.0.6.",
"external_references": [
{
"source_name": "cve",
"external_id": "CVE-2024-51852"
}
]
}
]
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
{
"type": "bundle",
"id": "bundle--a8c9ff70-15b1-4624-8e9a-c2effea525d4",
"objects": [
{
"type": "vulnerability",
"spec_version": "2.1",
"id": "vulnerability--013e3015-f46d-4993-9d8a-facb9415bfd0",
"created_by_ref": "identity--8ce3f695-d5a4-4dc8-9e93-a65af453a31a",
"created": "2024-11-20T00:21:28.947417Z",
"modified": "2024-11-20T00:21:28.947417Z",
"name": "CVE-2024-51907",
"description": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codemenschen WP Virtual Room Configurator allows Stored XSS.This issue affects WP Virtual Room Configurator: from n/a through 1.0.0.",
"external_references": [
{
"source_name": "cve",
"external_id": "CVE-2024-51907"
}
]
}
]
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
{
"type": "bundle",
"id": "bundle--19cdf686-c972-4876-9c1a-4c9e7ced6830",
"objects": [
{
"type": "vulnerability",
"spec_version": "2.1",
"id": "vulnerability--01cc92b9-8428-4083-a281-ddd7b20221dc",
"created_by_ref": "identity--8ce3f695-d5a4-4dc8-9e93-a65af453a31a",
"created": "2024-11-20T00:21:29.058274Z",
"modified": "2024-11-20T00:21:29.058274Z",
"name": "CVE-2024-51847",
"description": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in giovanebribeiro WP PagSeguro Payments allows Stored XSS.This issue affects WP PagSeguro Payments: from n/a through 1.0.",
"external_references": [
{
"source_name": "cve",
"external_id": "CVE-2024-51847"
}
]
}
]
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
{
"type": "bundle",
"id": "bundle--d157f7e1-97b7-4e0e-9f2f-d5454717c89a",
"objects": [
{
"type": "vulnerability",
"spec_version": "2.1",
"id": "vulnerability--032489b4-1876-4142-9a73-887d59728875",
"created_by_ref": "identity--8ce3f695-d5a4-4dc8-9e93-a65af453a31a",
"created": "2024-11-20T00:21:29.052578Z",
"modified": "2024-11-20T00:21:29.052578Z",
"name": "CVE-2024-51905",
"description": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ravi & Suma RSV PDF Preview allows Stored XSS.This issue affects RSV PDF Preview: from n/a through 1.0.",
"external_references": [
{
"source_name": "cve",
"external_id": "CVE-2024-51905"
}
]
}
]
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
{
"type": "bundle",
"id": "bundle--489efd2f-5a73-4c89-a539-112da5289be4",
"objects": [
{
"type": "vulnerability",
"spec_version": "2.1",
"id": "vulnerability--034b86df-7883-4302-95bf-a8961a48fe25",
"created_by_ref": "identity--8ce3f695-d5a4-4dc8-9e93-a65af453a31a",
"created": "2024-11-20T00:21:29.301438Z",
"modified": "2024-11-20T00:21:29.301438Z",
"name": "CVE-2024-45422",
"description": "Improper input validation in some Zoom Apps before version 6.2.0 may allow an unauthenticated user to conduct a denial of service via network access.",
"external_references": [
{
"source_name": "cve",
"external_id": "CVE-2024-45422"
}
]
}
]
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
{
"type": "bundle",
"id": "bundle--152b1ebc-730c-434e-8d5d-2dae8d8a1425",
"objects": [
{
"type": "vulnerability",
"spec_version": "2.1",
"id": "vulnerability--04d61f1f-8dcc-447c-a340-f6c5952df6ac",
"created_by_ref": "identity--8ce3f695-d5a4-4dc8-9e93-a65af453a31a",
"created": "2024-11-20T00:21:30.147765Z",
"modified": "2024-11-20T00:21:30.147765Z",
"name": "CVE-2024-53084",
"description": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/imagination: Break an object reference loop\n\nWhen remaining resources are being cleaned up on driver close,\noutstanding VM mappings may result in resources being leaked, due\nto an object reference loop, as shown below, with each object (or\nset of objects) referencing the object below it:\n\n PVR GEM Object\n GPU scheduler \"finished\" fence\n GPU scheduler “scheduled” fence\n PVR driver “done” fence\n PVR Context\n PVR VM Context\n PVR VM Mappings\n PVR GEM Object\n\nThe reference that the PVR VM Context has on the VM mappings is a\nsoft one, in the sense that the freeing of outstanding VM mappings\nis done as part of VM context destruction; no reference counts are\ninvolved, as is the case for all the other references in the loop.\n\nTo break the reference loop during cleanup, free the outstanding\nVM mappings before destroying the PVR Context associated with the\nVM context.",
"external_references": [
{
"source_name": "cve",
"external_id": "CVE-2024-53084"
}
]
}
]
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
{
"type": "bundle",
"id": "bundle--9d072cef-eedd-42ed-aa6d-841b5a53beca",
"objects": [
{
"type": "vulnerability",
"spec_version": "2.1",
"id": "vulnerability--052845b8-0432-4930-87d2-150af0c63562",
"created_by_ref": "identity--8ce3f695-d5a4-4dc8-9e93-a65af453a31a",
"created": "2024-11-20T00:21:28.865521Z",
"modified": "2024-11-20T00:21:28.865521Z",
"name": "CVE-2024-51654",
"description": "Cross-Site Request Forgery (CSRF) vulnerability in APK.Support APK Downloader allows Stored XSS.This issue affects APK Downloader: from n/a through 1.0.0.",
"external_references": [
{
"source_name": "cve",
"external_id": "CVE-2024-51654"
}
]
}
]
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
{
"type": "bundle",
"id": "bundle--9aeb6328-43af-473b-b645-52caae55258d",
"objects": [
{
"type": "vulnerability",
"spec_version": "2.1",
"id": "vulnerability--05305ef0-d2ae-41d2-a9bb-dbddc12d3e21",
"created_by_ref": "identity--8ce3f695-d5a4-4dc8-9e93-a65af453a31a",
"created": "2024-11-20T00:21:43.189645Z",
"modified": "2024-11-20T00:21:43.189645Z",
"name": "CVE-2018-9338",
"description": "In ResStringPool::setTo of ResourceTypes.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
"external_references": [
{
"source_name": "cve",
"external_id": "CVE-2018-9338"
}
]
}
]
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
{
"type": "bundle",
"id": "bundle--7fff6038-4fb8-45de-a4f6-b3b075666b52",
"objects": [
{
"type": "vulnerability",
"spec_version": "2.1",
"id": "vulnerability--05751025-51bc-4c42-ab0f-b1334a828159",
"created_by_ref": "identity--8ce3f695-d5a4-4dc8-9e93-a65af453a31a",
"created": "2024-11-20T00:21:29.868382Z",
"modified": "2024-11-20T00:21:29.868382Z",
"name": "CVE-2024-11198",
"description": "The GD Rating System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘extra_class’ parameter in all versions up to, and including, 3.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
"external_references": [
{
"source_name": "cve",
"external_id": "CVE-2024-11198"
}
]
}
]
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
{
"type": "bundle",
"id": "bundle--0e9422ae-bce0-4e4f-b5a1-0b8d8182e88b",
"objects": [
{
"type": "vulnerability",
"spec_version": "2.1",
"id": "vulnerability--0739a77c-64a6-4a83-819c-5cfe48a1cc21",
"created_by_ref": "identity--8ce3f695-d5a4-4dc8-9e93-a65af453a31a",
"created": "2024-11-20T00:21:29.661392Z",
"modified": "2024-11-20T00:21:29.661392Z",
"name": "CVE-2024-50518",
"description": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Common Ninja Pricer Ninja allows Stored XSS.This issue affects Pricer Ninja: from n/a through 2.1.0.",
"external_references": [
{
"source_name": "cve",
"external_id": "CVE-2024-50518"
}
]
}
]
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
{
"type": "bundle",
"id": "bundle--5bfd8912-cd75-4a60-a373-75adc0d339b2",
"objects": [
{
"type": "vulnerability",
"spec_version": "2.1",
"id": "vulnerability--075d24d8-4581-4aa9-88b0-2559d75107de",
"created_by_ref": "identity--8ce3f695-d5a4-4dc8-9e93-a65af453a31a",
"created": "2024-11-20T00:21:29.064339Z",
"modified": "2024-11-20T00:21:29.064339Z",
"name": "CVE-2024-51802",
"description": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bread & Butter IO Inc. Bread & Butter allows DOM-Based XSS.This issue affects Bread & Butter: from n/a through 7.4.857.",
"external_references": [
{
"source_name": "cve",
"external_id": "CVE-2024-51802"
}
]
}
]
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
{
"type": "bundle",
"id": "bundle--5cbc41de-7f2f-46f9-93d4-0499b9f077e3",
"objects": [
{
"type": "vulnerability",
"spec_version": "2.1",
"id": "vulnerability--07b6688b-dad4-45c9-a074-722aa9a87246",
"created_by_ref": "identity--8ce3f695-d5a4-4dc8-9e93-a65af453a31a",
"created": "2024-11-20T00:21:43.251195Z",
"modified": "2024-11-20T00:21:43.251195Z",
"name": "CVE-2018-9456",
"description": "In sdpu_extract_attr_seq of sdp_utils.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.",
"external_references": [
{
"source_name": "cve",
"external_id": "CVE-2018-9456"
}
]
}
]
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
{
"type": "bundle",
"id": "bundle--a5c65944-3dfe-4577-9693-b6b12ee45261",
"objects": [
{
"type": "vulnerability",
"spec_version": "2.1",
"id": "vulnerability--09f39471-1d40-4629-8e30-f78d406e74f2",
"created_by_ref": "identity--8ce3f695-d5a4-4dc8-9e93-a65af453a31a",
"created": "2024-11-20T00:21:29.049957Z",
"modified": "2024-11-20T00:21:29.049957Z",
"name": "CVE-2024-51850",
"description": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bchristopeit WoW Guild Armory Roster allows Stored XSS.This issue affects WoW Guild Armory Roster: from n/a through 0.5.5.",
"external_references": [
{
"source_name": "cve",
"external_id": "CVE-2024-51850"
}
]
}
]
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
{
"type": "bundle",
"id": "bundle--178035b1-2668-4133-b212-24c28d61fc6c",
"objects": [
{
"type": "vulnerability",
"spec_version": "2.1",
"id": "vulnerability--0d307c99-1582-4b57-a219-1d1b9acc4dfd",
"created_by_ref": "identity--8ce3f695-d5a4-4dc8-9e93-a65af453a31a",
"created": "2024-11-20T00:21:43.229553Z",
"modified": "2024-11-20T00:21:43.229553Z",
"name": "CVE-2018-9412",
"description": "In removeUnsynchronization of ID3.cpp there is a possible resource exhaustion due to improper input validation. This could lead to denial of service with no additional execution privileges needed. User interaction is needed for exploitation.",
"external_references": [
{
"source_name": "cve",
"external_id": "CVE-2018-9412"
}
]
}
]
}
Loading

0 comments on commit 3f9fac2

Please sign in to comment.