Auto-Update: 2024-11-30T07:00:41.265303+00:00

This commit is contained in:
cad-safe-bot 2024-11-30 07:03:52 +00:00
parent e61c0eca32
commit 3b38d769f1
4 changed files with 80 additions and 11 deletions

View File

@ -0,0 +1,64 @@
{
"id": "CVE-2024-11252",
"sourceIdentifier": "security@wordfence.com",
"published": "2024-11-30T06:15:17.580",
"lastModified": "2024-11-30T06:15:17.580",
"vulnStatus": "Received",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The Social Sharing Plugin \u2013 Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the heateor_mastodon_share parameter in all versions up to, and including, 3.3.69 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "security@wordfence.com",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "REQUIRED",
"scope": "CHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 2.8,
"impactScore": 2.7
}
]
},
"weaknesses": [
{
"source": "security@wordfence.com",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"references": [
{
"url": "https://plugins.trac.wordpress.org/browser/sassy-social-share/tags/3.3.69/public/class-sassy-social-share-public.php#L1478",
"source": "security@wordfence.com"
},
{
"url": "https://plugins.trac.wordpress.org/browser/sassy-social-share/tags/3.3.69/public/class-sassy-social-share-public.php#L1481",
"source": "security@wordfence.com"
},
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/3d065c2a-da7d-469a-b57d-f2fd5b760ff4?source=cve",
"source": "security@wordfence.com"
}
]
}

View File

@ -2,7 +2,7 @@
"id": "CVE-2024-27398", "id": "CVE-2024-27398",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"published": "2024-05-14T15:12:28.623", "published": "2024-05-14T15:12:28.623",
"lastModified": "2024-11-29T08:15:04.900", "lastModified": "2024-11-30T05:15:05.320",
"vulnStatus": "Awaiting Analysis", "vulnStatus": "Awaiting Analysis",
"cveTags": [], "cveTags": [],
"descriptions": [ "descriptions": [
@ -53,6 +53,10 @@
"url": "http://www.openwall.com/lists/oss-security/2024/11/29/1", "url": "http://www.openwall.com/lists/oss-security/2024/11/29/1",
"source": "af854a3a-2127-422b-91ae-364da2661108" "source": "af854a3a-2127-422b-91ae-364da2661108"
}, },
{
"url": "http://www.openwall.com/lists/oss-security/2024/11/30/1",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{ {
"url": "https://git.kernel.org/stable/c/012363cb1bec5f33a7b94629ab2c1086f30280f2", "url": "https://git.kernel.org/stable/c/012363cb1bec5f33a7b94629ab2c1086f30280f2",
"source": "af854a3a-2127-422b-91ae-364da2661108" "source": "af854a3a-2127-422b-91ae-364da2661108"

View File

@ -13,13 +13,13 @@ Repository synchronizes with the NVD every 2 hours.
### Last Repository Update ### Last Repository Update
```plain ```plain
2024-11-30T05:00:49.623857+00:00 2024-11-30T07:00:41.265303+00:00
``` ```
### Most recent CVE Modification Timestamp synchronized with NVD ### Most recent CVE Modification Timestamp synchronized with NVD
```plain ```plain
2024-11-30T03:15:14.030000+00:00 2024-11-30T06:15:17.580000+00:00
``` ```
### Last Data Feed Release ### Last Data Feed Release
@ -33,21 +33,21 @@ Download and Changelog: [Click](https://github.com/fkie-cad/nvd-json-data-feeds/
### Total Number of included CVEs ### Total Number of included CVEs
```plain ```plain
271711 271712
``` ```
### CVEs added in the last Commit ### CVEs added in the last Commit
Recently added CVEs: `2` Recently added CVEs: `1`
- [CVE-2024-43702](CVE-2024/CVE-2024-437xx/CVE-2024-43702.json) (`2024-11-30T03:15:13.903`) - [CVE-2024-11252](CVE-2024/CVE-2024-112xx/CVE-2024-11252.json) (`2024-11-30T06:15:17.580`)
- [CVE-2024-43703](CVE-2024/CVE-2024-437xx/CVE-2024-43703.json) (`2024-11-30T03:15:14.030`)
### CVEs modified in the last Commit ### CVEs modified in the last Commit
Recently modified CVEs: `0` Recently modified CVEs: `1`
- [CVE-2024-27398](CVE-2024/CVE-2024-273xx/CVE-2024-27398.json) (`2024-11-30T05:15:05.320`)
## Download and Usage ## Download and Usage

View File

@ -243542,6 +243542,7 @@ CVE-2024-11248,0,0,4b443be48ce8c0ac739bd8e1e543cf49244a70dde1362a8604cecd8601bec
CVE-2024-1125,0,0,f1d015036f4cdda32f03ba210c93a8838e991a1e1d168cce1bd81d56428097c5,2024-03-11T01:32:39.697000 CVE-2024-1125,0,0,f1d015036f4cdda32f03ba210c93a8838e991a1e1d168cce1bd81d56428097c5,2024-03-11T01:32:39.697000
CVE-2024-11250,0,0,b4820e7b4c32719c1293f43a37edd055a8fc217b09b6b40bc790c864314ccbee,2024-11-18T17:11:56.587000 CVE-2024-11250,0,0,b4820e7b4c32719c1293f43a37edd055a8fc217b09b6b40bc790c864314ccbee,2024-11-18T17:11:56.587000
CVE-2024-11251,0,0,9ac244f132ebb74fe7dc564429d4c9f6a76eead3d9d81e83ddd43f46265382d0,2024-11-18T17:11:56.587000 CVE-2024-11251,0,0,9ac244f132ebb74fe7dc564429d4c9f6a76eead3d9d81e83ddd43f46265382d0,2024-11-18T17:11:56.587000
CVE-2024-11252,1,1,fb6dd864d369bcaaa178c38411440a597d4952ec3ac8a3258e6be67833d6e094,2024-11-30T06:15:17.580000
CVE-2024-11256,0,0,29e00e0ee4d12938f6e2912644ef71a80cda2431b2f5fea5964a69693712d8d3,2024-11-19T21:49:04.790000 CVE-2024-11256,0,0,29e00e0ee4d12938f6e2912644ef71a80cda2431b2f5fea5964a69693712d8d3,2024-11-19T21:49:04.790000
CVE-2024-11257,0,0,585c01a54f1385c2a001e222fb74644a8874e08d56dfcf6a642daa13e730e553,2024-11-19T21:24:40.443000 CVE-2024-11257,0,0,585c01a54f1385c2a001e222fb74644a8874e08d56dfcf6a642daa13e730e553,2024-11-19T21:24:40.443000
CVE-2024-11258,0,0,4c929a765c19f3d13acbcc084dd9b1be8b2bf3ca4132bc34b1e32fe14a03df6a,2024-11-19T21:24:27.473000 CVE-2024-11258,0,0,4c929a765c19f3d13acbcc084dd9b1be8b2bf3ca4132bc34b1e32fe14a03df6a,2024-11-19T21:24:27.473000
@ -250355,7 +250356,7 @@ CVE-2024-27394,0,0,08a27f4278e90895db869570c2ad1394d2b1b7ce2eebd13c81985e703b3d5
CVE-2024-27395,0,0,0717a5340b130d9ad6c83d02a6a375ee46786932fc1ca7bcae52c4e65548e91e,2024-11-05T10:16:29.630000 CVE-2024-27395,0,0,0717a5340b130d9ad6c83d02a6a375ee46786932fc1ca7bcae52c4e65548e91e,2024-11-05T10:16:29.630000
CVE-2024-27396,0,0,f99b3ed9649441d52beedad6717e389342b6bd13026bafae1f070293d6b326f9,2024-11-05T10:16:29.910000 CVE-2024-27396,0,0,f99b3ed9649441d52beedad6717e389342b6bd13026bafae1f070293d6b326f9,2024-11-05T10:16:29.910000
CVE-2024-27397,0,0,a0f40ad4c2f891849c489ae4b9841685ad4e227c084159373a42e20fef210207,2024-08-19T05:15:06.293000 CVE-2024-27397,0,0,a0f40ad4c2f891849c489ae4b9841685ad4e227c084159373a42e20fef210207,2024-08-19T05:15:06.293000
CVE-2024-27398,0,0,80716e7d91e1962ddaa63002f6f890b898c12f1dd035426105b4bdc13b61e672,2024-11-29T08:15:04.900000 CVE-2024-27398,0,1,a5dd55c90df6f8e9d6058842983c03968400530681520b33ec05d53e74e91f57,2024-11-30T05:15:05.320000
CVE-2024-27399,0,0,99d9510b637361dde4a735c6783496f5b872927f33529f36ec6d87018b5bc247,2024-11-05T10:16:30.393000 CVE-2024-27399,0,0,99d9510b637361dde4a735c6783496f5b872927f33529f36ec6d87018b5bc247,2024-11-05T10:16:30.393000
CVE-2024-2740,0,0,7545651108e8514acefb2b72311b601ee7dbdf24da5bdaec2774b5ead308107f,2024-04-11T12:47:44.137000 CVE-2024-2740,0,0,7545651108e8514acefb2b72311b601ee7dbdf24da5bdaec2774b5ead308107f,2024-04-11T12:47:44.137000
CVE-2024-27400,0,0,069e4b8cc0d3bf02e960ba37e8375912ae86e06a0fac9563b07518abcdfda328,2024-11-05T10:16:30.580000 CVE-2024-27400,0,0,069e4b8cc0d3bf02e960ba37e8375912ae86e06a0fac9563b07518abcdfda328,2024-11-05T10:16:30.580000
@ -262164,8 +262165,8 @@ CVE-2024-43699,0,0,78534d33d290678062dddcdfe24e803feecb99e21dbcb3ac97f746608e5c5
CVE-2024-4370,0,0,3c1f5b342c087fc6587c8bc9012541b58d80e50fdee9d14eea44daecdec82901,2024-05-15T16:40:19.330000 CVE-2024-4370,0,0,3c1f5b342c087fc6587c8bc9012541b58d80e50fdee9d14eea44daecdec82901,2024-05-15T16:40:19.330000
CVE-2024-43700,0,0,0a06b833e6fd1b1e874ef27bf2dcddebe6eeed2fb3b70101d743561cb29959e0,2024-10-15T14:35:01.987000 CVE-2024-43700,0,0,0a06b833e6fd1b1e874ef27bf2dcddebe6eeed2fb3b70101d743561cb29959e0,2024-10-15T14:35:01.987000
CVE-2024-43701,0,0,806d05bc9a9c57505164825be7dbf8680f4cf63f26e698ce90f59cb6324208a0,2024-10-15T15:35:16.050000 CVE-2024-43701,0,0,806d05bc9a9c57505164825be7dbf8680f4cf63f26e698ce90f59cb6324208a0,2024-10-15T15:35:16.050000
CVE-2024-43702,1,1,8a2638259ef7d0c0bd5ed169f1bc8777f60d13fe6bd61e7083d6d48b42f35850,2024-11-30T03:15:13.903000 CVE-2024-43702,0,0,8a2638259ef7d0c0bd5ed169f1bc8777f60d13fe6bd61e7083d6d48b42f35850,2024-11-30T03:15:13.903000
CVE-2024-43703,1,1,9541812b1f1e1f53c274c0839d61438b11d7c3f5eb2e292d5cebbf841568c53c,2024-11-30T03:15:14.030000 CVE-2024-43703,0,0,9541812b1f1e1f53c274c0839d61438b11d7c3f5eb2e292d5cebbf841568c53c,2024-11-30T03:15:14.030000
CVE-2024-43704,0,0,68e20ff94c977992fbc81773ba7e2608b5e5a8d64b392bf66e598044f6eb2d60,2024-11-18T17:11:17.393000 CVE-2024-43704,0,0,68e20ff94c977992fbc81773ba7e2608b5e5a8d64b392bf66e598044f6eb2d60,2024-11-18T17:11:17.393000
CVE-2024-4371,0,0,a0b0e0fb8c98057b2328743d7da5c32e9a585001a67e08f1632ceab0df487dfa,2024-07-15T16:42:39.107000 CVE-2024-4371,0,0,a0b0e0fb8c98057b2328743d7da5c32e9a585001a67e08f1632ceab0df487dfa,2024-07-15T16:42:39.107000
CVE-2024-4372,0,0,9ae4f43bf2d0d90214ce2e4715e0031799e31627a4319bb26ad2a73cf60988cf,2024-05-21T12:37:59.687000 CVE-2024-4372,0,0,9ae4f43bf2d0d90214ce2e4715e0031799e31627a4319bb26ad2a73cf60988cf,2024-05-21T12:37:59.687000

Can't render this file because it is too large.