Auto-Update: 2024-06-01T04:00:37.505560+00:00

This commit is contained in:
cad-safe-bot 2024-06-01 04:03:29 +00:00
parent 0ba1613af0
commit 552b3b7d4a
4 changed files with 133 additions and 41 deletions

View File

@ -0,0 +1,51 @@
{
"id": "CVE-2024-2933",
"sourceIdentifier": "security@wordfence.com",
"published": "2024-06-01T02:15:47.727",
"lastModified": "2024-06-01T02:15:47.727",
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "The Page Builder Gutenberg Blocks \u2013 CoBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Social Profiles widget in all versions up to, and including, 3.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "security@wordfence.com",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "CHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "NONE",
"baseScore": 6.4,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 3.1,
"impactScore": 2.7
}
]
},
"references": [
{
"url": "https://plugins.trac.wordpress.org/browser/coblocks/tags/3.1.7/src/blocks/social-profiles/index.php#L28",
"source": "security@wordfence.com"
},
{
"url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3095285%40coblocks&new=3095285%40coblocks&sfp_email=&sfph_mail=",
"source": "security@wordfence.com"
},
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/020d14f8-e8e2-4da2-9a4b-4d15cb0994c8?source=cve",
"source": "security@wordfence.com"
}
]
}

View File

@ -0,0 +1,55 @@
{
"id": "CVE-2024-4711",
"sourceIdentifier": "security@wordfence.com",
"published": "2024-06-01T03:15:08.413",
"lastModified": "2024-06-01T03:15:08.413",
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "The WordPress Infinite Scroll \u2013 Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ajax_load_more shortcode in versions up to, and including, 7.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "security@wordfence.com",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "CHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "NONE",
"baseScore": 6.4,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 3.1,
"impactScore": 2.7
}
]
},
"references": [
{
"url": "https://plugins.trac.wordpress.org/browser/ajax-load-more/trunk/build/frontend/ajax-load-more.js",
"source": "security@wordfence.com"
},
{
"url": "https://plugins.trac.wordpress.org/browser/ajax-load-more/trunk/core/classes/class-alm-shortcode.php#L1191",
"source": "security@wordfence.com"
},
{
"url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3095200%40ajax-load-more&new=3095200%40ajax-load-more&sfp_email=&sfph_mail=#file3",
"source": "security@wordfence.com"
},
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e86c080d-202c-4c41-b9cc-c35249aabba5?source=cve",
"source": "security@wordfence.com"
}
]
}

View File

@ -13,13 +13,13 @@ Repository synchronizes with the NVD every 2 hours.
### Last Repository Update
```plain
2024-05-31T22:00:38.346657+00:00
2024-06-01T04:00:37.505560+00:00
```
### Most recent CVE Modification Timestamp synchronized with NVD
```plain
2024-05-31T21:15:09.930000+00:00
2024-06-01T03:15:08.413000+00:00
```
### Last Data Feed Release
@ -27,37 +27,21 @@ Repository synchronizes with the NVD every 2 hours.
Download and Changelog: [Click](https://github.com/fkie-cad/nvd-json-data-feeds/releases/latest)
```plain
2024-05-31T00:00:20.259013+00:00
2024-06-01T00:00:20.271052+00:00
```
### Total Number of included CVEs
```plain
252344
252346
```
### CVEs added in the last Commit
Recently added CVEs: `18`
Recently added CVEs: `2`
- [CVE-2024-33996](CVE-2024/CVE-2024-339xx/CVE-2024-33996.json) (`2024-05-31T20:15:09.647`)
- [CVE-2024-33997](CVE-2024/CVE-2024-339xx/CVE-2024-33997.json) (`2024-05-31T20:15:09.797`)
- [CVE-2024-33998](CVE-2024/CVE-2024-339xx/CVE-2024-33998.json) (`2024-05-31T20:15:09.890`)
- [CVE-2024-33999](CVE-2024/CVE-2024-339xx/CVE-2024-33999.json) (`2024-05-31T20:15:09.987`)
- [CVE-2024-34000](CVE-2024/CVE-2024-340xx/CVE-2024-34000.json) (`2024-05-31T20:15:10.080`)
- [CVE-2024-34001](CVE-2024/CVE-2024-340xx/CVE-2024-34001.json) (`2024-05-31T20:15:10.183`)
- [CVE-2024-34002](CVE-2024/CVE-2024-340xx/CVE-2024-34002.json) (`2024-05-31T21:15:09.130`)
- [CVE-2024-34003](CVE-2024/CVE-2024-340xx/CVE-2024-34003.json) (`2024-05-31T21:15:09.240`)
- [CVE-2024-34004](CVE-2024/CVE-2024-340xx/CVE-2024-34004.json) (`2024-05-31T21:15:09.340`)
- [CVE-2024-34005](CVE-2024/CVE-2024-340xx/CVE-2024-34005.json) (`2024-05-31T21:15:09.440`)
- [CVE-2024-34006](CVE-2024/CVE-2024-340xx/CVE-2024-34006.json) (`2024-05-31T21:15:09.533`)
- [CVE-2024-34007](CVE-2024/CVE-2024-340xx/CVE-2024-34007.json) (`2024-05-31T21:15:09.647`)
- [CVE-2024-34008](CVE-2024/CVE-2024-340xx/CVE-2024-34008.json) (`2024-05-31T21:15:09.743`)
- [CVE-2024-34009](CVE-2024/CVE-2024-340xx/CVE-2024-34009.json) (`2024-05-31T21:15:09.833`)
- [CVE-2024-36843](CVE-2024/CVE-2024-368xx/CVE-2024-36843.json) (`2024-05-31T20:15:10.290`)
- [CVE-2024-36844](CVE-2024/CVE-2024-368xx/CVE-2024-36844.json) (`2024-05-31T20:15:10.380`)
- [CVE-2024-36845](CVE-2024/CVE-2024-368xx/CVE-2024-36845.json) (`2024-05-31T20:15:10.463`)
- [CVE-2024-5138](CVE-2024/CVE-2024-51xx/CVE-2024-5138.json) (`2024-05-31T21:15:09.930`)
- [CVE-2024-2933](CVE-2024/CVE-2024-29xx/CVE-2024-2933.json) (`2024-06-01T02:15:47.727`)
- [CVE-2024-4711](CVE-2024/CVE-2024-47xx/CVE-2024-4711.json) (`2024-06-01T03:15:08.413`)
### CVEs modified in the last Commit

View File

@ -247480,6 +247480,7 @@ CVE-2024-2931,0,0,a6d520754016bbdab2d7efa74efc39e3254a7b8cd183192dc94878921c91c9
CVE-2024-29316,0,0,a77a66080b82cffb666cc5dc96a72ca9eacad7eb3c1a78f29a15ae578e7a1db4,2024-03-29T12:45:02.937000
CVE-2024-2932,0,0,a3c1266ff6f47dc95aa30613f077416ccee7f436989a8ec80d1c9241ff3cefc9,2024-05-17T02:38:37.813000
CVE-2024-29320,0,0,321a08ec2af8156a6831bdc4e0f91613cac88682c2798c2c52128b513367591a,2024-04-30T17:52:35.057000
CVE-2024-2933,1,1,a9f810664b426fd297cd6d80897c2d20b389d40ce702149828bd398ef7bb339d,2024-06-01T02:15:47.727000
CVE-2024-29338,0,0,e2411b46399ccf809f7042628f5dc80681cab752a4fc33bfa69d55d7b188c619,2024-03-22T19:02:10.300000
CVE-2024-2934,0,0,3802ca621262b108954a2e7ca078a0b3239a058a100ed0a90d89e0faae5d736e,2024-05-17T02:38:37.907000
CVE-2024-2935,0,0,bec21ac61474c1b8576f1b42d537e6fe78cbe9ea3670df60a6cb2385d6dc491a,2024-05-17T02:38:38.003000
@ -250099,21 +250100,21 @@ CVE-2024-33953,0,0,3b3356729af80b251661673310f8c56f44f10df5bf865f8c660a36c2bb489
CVE-2024-33954,0,0,c503ae766ab5514537a2f4c6d4b14a345a29e519b230f4073c9e782b0bbe69b4,2024-05-14T16:12:23.490000
CVE-2024-33955,0,0,2ca854ebde5acdbe9a0cbc52fdc48933a592e02407281f304c8b2d9d1c5c771f,2024-05-14T16:12:23.490000
CVE-2024-33956,0,0,a3addf39e4aabbdc7e441806152a9a1df58e40ee38caf2a4eb3a2e733fe2d75d,2024-05-14T16:12:23.490000
CVE-2024-33996,1,1,4959daa9527c3eab70f0d5a99ae84bce6b72fe0314e02bb131e992dc561c5aa6,2024-05-31T20:15:09.647000
CVE-2024-33997,1,1,c88cd825130b7b7f6a9aacfb35b22048a51bf8378903f23fb368eeaa98d377b1,2024-05-31T20:15:09.797000
CVE-2024-33998,1,1,fb66089584e94005eddd97aaceb860cf934ec9b3c4a375bf53b58b780e09660a,2024-05-31T20:15:09.890000
CVE-2024-33999,1,1,b54aa16c3843d727680cc15e631a46e0646166505fdc32852941c99b1c86d541,2024-05-31T20:15:09.987000
CVE-2024-33996,0,0,4959daa9527c3eab70f0d5a99ae84bce6b72fe0314e02bb131e992dc561c5aa6,2024-05-31T20:15:09.647000
CVE-2024-33997,0,0,c88cd825130b7b7f6a9aacfb35b22048a51bf8378903f23fb368eeaa98d377b1,2024-05-31T20:15:09.797000
CVE-2024-33998,0,0,fb66089584e94005eddd97aaceb860cf934ec9b3c4a375bf53b58b780e09660a,2024-05-31T20:15:09.890000
CVE-2024-33999,0,0,b54aa16c3843d727680cc15e631a46e0646166505fdc32852941c99b1c86d541,2024-05-31T20:15:09.987000
CVE-2024-3400,0,0,ca612a9a9d0abd8952e404012cd7953d185fcc4b36e6c122ae2aa18b847a21b3,2024-05-29T16:00:24.093000
CVE-2024-34000,1,1,e1e36130628573ca3eb8dd109f9b7ae61a417ca28bec0e437be8c85ed036d010,2024-05-31T20:15:10.080000
CVE-2024-34001,1,1,95e2391357b54410d63fd86db759d10939cabd3526e32bdc01d86ab00e114fc0,2024-05-31T20:15:10.183000
CVE-2024-34002,1,1,1e3e464ffc82f07ff9cbfe3fe1097a108318626368e91cd1603708cd2d1e58e9,2024-05-31T21:15:09.130000
CVE-2024-34003,1,1,0598cd2e484568dfb02f3c47debe9113df4d2b2dffd96e059163b7270297c0c7,2024-05-31T21:15:09.240000
CVE-2024-34004,1,1,fbb80dbfbb086f3ba7cb49bc034e086affb5aa587942e6b7f9a32e2eae291b05,2024-05-31T21:15:09.340000
CVE-2024-34005,1,1,62fc2d8904af4c28f8fb3286f7cbe75d413cbd5b5354e9348bcaeaf74042e8fb,2024-05-31T21:15:09.440000
CVE-2024-34006,1,1,bd02c6e1ed545087d645d0ed794d45df6f9384ca62e25bf334f0e24093ad33f7,2024-05-31T21:15:09.533000
CVE-2024-34007,1,1,de30e92c4c073f115c748d23f749b9f449e3b7909f2482fb58e567407d641af9,2024-05-31T21:15:09.647000
CVE-2024-34008,1,1,fdcf21804eed9e4b9ae003fed0a42f1ce49ecd6f59017e01756d8d13b8d19e04,2024-05-31T21:15:09.743000
CVE-2024-34009,1,1,d153252dbe5664997654e42bc365b211827d395d00e795ad774b03c9036974bd,2024-05-31T21:15:09.833000
CVE-2024-34000,0,0,e1e36130628573ca3eb8dd109f9b7ae61a417ca28bec0e437be8c85ed036d010,2024-05-31T20:15:10.080000
CVE-2024-34001,0,0,95e2391357b54410d63fd86db759d10939cabd3526e32bdc01d86ab00e114fc0,2024-05-31T20:15:10.183000
CVE-2024-34002,0,0,1e3e464ffc82f07ff9cbfe3fe1097a108318626368e91cd1603708cd2d1e58e9,2024-05-31T21:15:09.130000
CVE-2024-34003,0,0,0598cd2e484568dfb02f3c47debe9113df4d2b2dffd96e059163b7270297c0c7,2024-05-31T21:15:09.240000
CVE-2024-34004,0,0,fbb80dbfbb086f3ba7cb49bc034e086affb5aa587942e6b7f9a32e2eae291b05,2024-05-31T21:15:09.340000
CVE-2024-34005,0,0,62fc2d8904af4c28f8fb3286f7cbe75d413cbd5b5354e9348bcaeaf74042e8fb,2024-05-31T21:15:09.440000
CVE-2024-34006,0,0,bd02c6e1ed545087d645d0ed794d45df6f9384ca62e25bf334f0e24093ad33f7,2024-05-31T21:15:09.533000
CVE-2024-34007,0,0,de30e92c4c073f115c748d23f749b9f449e3b7909f2482fb58e567407d641af9,2024-05-31T21:15:09.647000
CVE-2024-34008,0,0,fdcf21804eed9e4b9ae003fed0a42f1ce49ecd6f59017e01756d8d13b8d19e04,2024-05-31T21:15:09.743000
CVE-2024-34009,0,0,d153252dbe5664997654e42bc365b211827d395d00e795ad774b03c9036974bd,2024-05-31T21:15:09.833000
CVE-2024-34010,0,0,c31f2f180475c1f3f2204c1feb2010c5ada948eb1b4d37517c54f97316341f08,2024-04-30T13:11:16.690000
CVE-2024-34011,0,0,4e2e0fb5d64e6e75da5ff3561c6f86ff1f891a3646e890e015512c561d328a58,2024-04-30T13:11:16.690000
CVE-2024-34020,0,0,9d9b11f4db84c3770acd92b1150bad9b802c58de4fce781bba37a89c232e029f,2024-04-30T13:11:16.690000
@ -251168,9 +251169,9 @@ CVE-2024-3680,0,0,b1ed78ba2c31e060c65591b1b4aa0e0cdd627bc790583f352919e473d1394b
CVE-2024-3681,0,0,4cc6e1e77320458af0f4beee59a38c9a663fe20b962b28f234c099bc7c23ab32,2024-05-02T18:00:37.360000
CVE-2024-3682,0,0,a140f5eb71acf183c1e80e0d2f5a14a5c7d8a92c7cf9dd3ea5250a20e3cb490f,2024-04-26T12:58:17.720000
CVE-2024-3684,0,0,e7edf7d6bce31b480b46d692afd4304c988268ba4618e87da8566dc118f2be92,2024-04-19T16:19:49.043000
CVE-2024-36843,1,1,1a54a3bda9d9117dd45ca9cecaeed628da3045145349a07c6e7d1f2d46ab39cd,2024-05-31T20:15:10.290000
CVE-2024-36844,1,1,03b50fa8dadaa43de5a30701030ce5aa53ac888c34ba8a0bda630c036aa57651,2024-05-31T20:15:10.380000
CVE-2024-36845,1,1,44298688a0efafeed94d06d63e0087e35044b38514668b5b77fda18c119d1629,2024-05-31T20:15:10.463000
CVE-2024-36843,0,0,1a54a3bda9d9117dd45ca9cecaeed628da3045145349a07c6e7d1f2d46ab39cd,2024-05-31T20:15:10.290000
CVE-2024-36844,0,0,03b50fa8dadaa43de5a30701030ce5aa53ac888c34ba8a0bda630c036aa57651,2024-05-31T20:15:10.380000
CVE-2024-36845,0,0,44298688a0efafeed94d06d63e0087e35044b38514668b5b77fda18c119d1629,2024-05-31T20:15:10.463000
CVE-2024-3685,0,0,f921a0a401f8b4f7737f6fde068e597ed9cc1b4c23e79252700a3c350a96640b,2024-05-17T02:40:03.840000
CVE-2024-3686,0,0,48e96862a2931368fc7a73a6d531fce8d2b9c3a327baf97d691f2054e9208b18,2024-05-17T02:40:03.933000
CVE-2024-3687,0,0,a3a2ae712cd6c7057b4b6b211557af56d168f80a5b75c666d660903c58451d4c,2024-05-17T02:40:04.027000
@ -251938,6 +251939,7 @@ CVE-2024-4702,0,0,391d02c5718dd442c026ca8f3973c4fe10894f8eeb54175158dc44cd7ef50d
CVE-2024-4706,0,0,a959e13293b1a5966007eb60c79cb973f34e4d1d8bd1c12986cac54d81ac9a3d,2024-05-24T01:15:30.977000
CVE-2024-4709,0,0,c27b22c30c2569acd5c758eb82bd584c5ae09da5862ed28e288bc8b8f592259a,2024-05-20T13:00:34.807000
CVE-2024-4710,0,0,500a7d3af356181a474ebd9523b50fd3ae653f9a07ad01e5b7699589bd4ccc5d,2024-05-21T12:37:59.687000
CVE-2024-4711,1,1,3a11a9a87549fa06b3be5f3ee9634f6d1a64361088dba0c9e99ac1ad3898af7e,2024-06-01T03:15:08.413000
CVE-2024-4712,0,0,f79d5936efdb7279077ea6da35ae307312c55a147f3075b5570853347f8017b9,2024-05-14T16:11:39.510000
CVE-2024-4713,0,0,63c8fe02e071c01e10e60f543cd0776ed83adea75c2d063179e2f75e75c30c3b,2024-05-17T02:40:33.880000
CVE-2024-4714,0,0,4e7ff77f8284c93c8758bb989744763ec5c4cb8551eeb8d726beabface4981b3,2024-05-17T02:40:33.983000
@ -252174,7 +252176,7 @@ CVE-2024-5134,0,0,44ea8effe91da48fa2441b74e001b5effc2d04f097b58592fa0588737465c2
CVE-2024-5135,0,0,a74f6a753fe0dfdbe9ef14fb62e3c1e241b2d21757276b9c7925f9871c2f3420,2024-05-20T13:00:04.957000
CVE-2024-5136,0,0,5cce275ffb1550a3c7261f5e567e7647a017e807bac86076084d9c82ab83e26b,2024-05-20T13:00:04.957000
CVE-2024-5137,0,0,eed8df071842e1a03ca59c05a5655638342140960be3a16fc81a02125200e22f,2024-05-20T13:00:04.957000
CVE-2024-5138,1,1,cea083ed93aa7496cef3355babdc18e6132432c5a45e38535646477d6feeaf03,2024-05-31T21:15:09.930000
CVE-2024-5138,0,0,cea083ed93aa7496cef3355babdc18e6132432c5a45e38535646477d6feeaf03,2024-05-31T21:15:09.930000
CVE-2024-5142,0,0,9a7d794c7ee50b5ecd06d952c402fab37c046b0a6bb4d29e0c6b11e7df538957,2024-05-24T13:03:05.093000
CVE-2024-5143,0,0,85d2302aa16b15f892bf139ed2f510515c9c051290de1dbf060be25f39190615,2024-05-24T01:15:30.977000
CVE-2024-5144,0,0,3682eb32ab74a69dce2a20f55af124165ad49665bd2dae692d6703bd4728c599,2024-05-31T18:15:13.217000

Can't render this file because it is too large.