diff --git a/advisories/github-reviewed/2022/05/GHSA-hcjf-rp5h-g5h3/GHSA-hcjf-rp5h-g5h3.json b/advisories/github-reviewed/2022/05/GHSA-hcjf-rp5h-g5h3/GHSA-hcjf-rp5h-g5h3.json index 73db7b7809c..18c5e5388c2 100644 --- a/advisories/github-reviewed/2022/05/GHSA-hcjf-rp5h-g5h3/GHSA-hcjf-rp5h-g5h3.json +++ b/advisories/github-reviewed/2022/05/GHSA-hcjf-rp5h-g5h3/GHSA-hcjf-rp5h-g5h3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hcjf-rp5h-g5h3", - "modified": "2024-04-22T21:10:55Z", + "modified": "2024-10-23T18:32:07Z", "published": "2022-05-24T17:48:21Z", "aliases": [ "CVE-2021-31607" @@ -43,10 +43,6 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-31607" }, - { - "type": "ADVISORY", - "url": "https://github.com/advisories/GHSA-hcjf-rp5h-g5h3" - }, { "type": "WEB", "url": "https://github.com/pypa/advisory-database/tree/main/vulns/salt/PYSEC-2021-56.yaml" diff --git a/advisories/github-reviewed/2022/12/GHSA-r9hx-vwmv-q579/GHSA-r9hx-vwmv-q579.json b/advisories/github-reviewed/2022/12/GHSA-r9hx-vwmv-q579/GHSA-r9hx-vwmv-q579.json index f74f6b08097..f3a6ff64313 100644 --- a/advisories/github-reviewed/2022/12/GHSA-r9hx-vwmv-q579/GHSA-r9hx-vwmv-q579.json +++ b/advisories/github-reviewed/2022/12/GHSA-r9hx-vwmv-q579/GHSA-r9hx-vwmv-q579.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r9hx-vwmv-q579", - "modified": "2024-06-24T21:24:10Z", + "modified": "2024-10-23T18:33:02Z", "published": "2022-12-23T00:30:23Z", "aliases": [ "CVE-2022-40897" @@ -48,6 +48,10 @@ "type": "WEB", "url": "https://github.com/pypa/setuptools/commit/43a9c9bfa6aa626ec2a22540bea28d2ca77964be" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/setuptools/PYSEC-2022-43012.yaml" + }, { "type": "WEB", "url": "https://github.com/pypa/setuptools" diff --git a/advisories/unreviewed/2023/07/GHSA-6m39-ww2w-wpfg/GHSA-6m39-ww2w-wpfg.json b/advisories/unreviewed/2023/07/GHSA-6m39-ww2w-wpfg/GHSA-6m39-ww2w-wpfg.json index a8db9482fd7..ef30bf43fcc 100644 --- a/advisories/unreviewed/2023/07/GHSA-6m39-ww2w-wpfg/GHSA-6m39-ww2w-wpfg.json +++ b/advisories/unreviewed/2023/07/GHSA-6m39-ww2w-wpfg/GHSA-6m39-ww2w-wpfg.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-h2fx-27f9-5cr5/GHSA-h2fx-27f9-5cr5.json b/advisories/unreviewed/2023/07/GHSA-h2fx-27f9-5cr5/GHSA-h2fx-27f9-5cr5.json index 57ec06a9cb7..a88e1c73cee 100644 --- a/advisories/unreviewed/2023/07/GHSA-h2fx-27f9-5cr5/GHSA-h2fx-27f9-5cr5.json +++ b/advisories/unreviewed/2023/07/GHSA-h2fx-27f9-5cr5/GHSA-h2fx-27f9-5cr5.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-116", "CWE-20" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/07/GHSA-p3x3-92wj-v2j2/GHSA-p3x3-92wj-v2j2.json b/advisories/unreviewed/2023/07/GHSA-p3x3-92wj-v2j2/GHSA-p3x3-92wj-v2j2.json index 50508159777..f9fd5317a7a 100644 --- a/advisories/unreviewed/2023/07/GHSA-p3x3-92wj-v2j2/GHSA-p3x3-92wj-v2j2.json +++ b/advisories/unreviewed/2023/07/GHSA-p3x3-92wj-v2j2/GHSA-p3x3-92wj-v2j2.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-3wxf-8h2q-7rqj/GHSA-3wxf-8h2q-7rqj.json b/advisories/unreviewed/2024/01/GHSA-3wxf-8h2q-7rqj/GHSA-3wxf-8h2q-7rqj.json index ef11530046f..3a3c710990a 100644 --- a/advisories/unreviewed/2024/01/GHSA-3wxf-8h2q-7rqj/GHSA-3wxf-8h2q-7rqj.json +++ b/advisories/unreviewed/2024/01/GHSA-3wxf-8h2q-7rqj/GHSA-3wxf-8h2q-7rqj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3wxf-8h2q-7rqj", - "modified": "2024-01-19T21:30:34Z", + "modified": "2024-10-23T18:33:06Z", "published": "2024-01-16T09:30:19Z", "aliases": [ "CVE-2023-52098" @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-116", "CWE-400" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/01/GHSA-j977-qqwc-8rmm/GHSA-j977-qqwc-8rmm.json b/advisories/unreviewed/2024/01/GHSA-j977-qqwc-8rmm/GHSA-j977-qqwc-8rmm.json index d10e35d2ce1..f7e2be0cd89 100644 --- a/advisories/unreviewed/2024/01/GHSA-j977-qqwc-8rmm/GHSA-j977-qqwc-8rmm.json +++ b/advisories/unreviewed/2024/01/GHSA-j977-qqwc-8rmm/GHSA-j977-qqwc-8rmm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j977-qqwc-8rmm", - "modified": "2024-01-23T21:30:20Z", + "modified": "2024-10-23T18:33:06Z", "published": "2024-01-16T18:31:08Z", "aliases": [ "CVE-2021-24566" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-p53v-hm2g-p66x/GHSA-p53v-hm2g-p66x.json b/advisories/unreviewed/2024/01/GHSA-p53v-hm2g-p66x/GHSA-p53v-hm2g-p66x.json index 049f80dcc6a..18bdba93231 100644 --- a/advisories/unreviewed/2024/01/GHSA-p53v-hm2g-p66x/GHSA-p53v-hm2g-p66x.json +++ b/advisories/unreviewed/2024/01/GHSA-p53v-hm2g-p66x/GHSA-p53v-hm2g-p66x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p53v-hm2g-p66x", - "modified": "2024-01-19T21:30:34Z", + "modified": "2024-10-23T18:33:06Z", "published": "2024-01-16T12:30:25Z", "aliases": [ "CVE-2023-52102" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-116" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-6f66-2p45-mpc2/GHSA-6f66-2p45-mpc2.json b/advisories/unreviewed/2024/02/GHSA-6f66-2p45-mpc2/GHSA-6f66-2p45-mpc2.json index 45cc20b186d..7e5fd492a0e 100644 --- a/advisories/unreviewed/2024/02/GHSA-6f66-2p45-mpc2/GHSA-6f66-2p45-mpc2.json +++ b/advisories/unreviewed/2024/02/GHSA-6f66-2p45-mpc2/GHSA-6f66-2p45-mpc2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6f66-2p45-mpc2", - "modified": "2024-02-14T18:30:25Z", + "modified": "2024-10-23T18:33:06Z", "published": "2024-02-14T18:30:25Z", "aliases": [ "CVE-2024-25217" ], "details": "Online Medicine Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /omos/?p=products/view_product.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-14T15:15:09Z" diff --git a/advisories/unreviewed/2024/02/GHSA-8p5m-rr5g-qg99/GHSA-8p5m-rr5g-qg99.json b/advisories/unreviewed/2024/02/GHSA-8p5m-rr5g-qg99/GHSA-8p5m-rr5g-qg99.json index 549b8641133..822be1d113d 100644 --- a/advisories/unreviewed/2024/02/GHSA-8p5m-rr5g-qg99/GHSA-8p5m-rr5g-qg99.json +++ b/advisories/unreviewed/2024/02/GHSA-8p5m-rr5g-qg99/GHSA-8p5m-rr5g-qg99.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8p5m-rr5g-qg99", - "modified": "2024-02-14T18:30:25Z", + "modified": "2024-10-23T18:33:06Z", "published": "2024-02-14T18:30:25Z", "aliases": [ "CVE-2024-25211" ], "details": "Simple Expense Tracker v1.0 was discovered to contain a SQL injection vulnerability via the category parameter at /endpoint/delete_category.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-14T15:15:09Z" diff --git a/advisories/unreviewed/2024/02/GHSA-fw46-3cv3-6c98/GHSA-fw46-3cv3-6c98.json b/advisories/unreviewed/2024/02/GHSA-fw46-3cv3-6c98/GHSA-fw46-3cv3-6c98.json index 8fee3302be1..ca7449be152 100644 --- a/advisories/unreviewed/2024/02/GHSA-fw46-3cv3-6c98/GHSA-fw46-3cv3-6c98.json +++ b/advisories/unreviewed/2024/02/GHSA-fw46-3cv3-6c98/GHSA-fw46-3cv3-6c98.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fw46-3cv3-6c98", - "modified": "2024-02-14T18:30:25Z", + "modified": "2024-10-23T18:33:06Z", "published": "2024-02-14T18:30:25Z", "aliases": [ "CVE-2024-25223" ], "details": "Simple Admin Panel App v1.0 was discovered to contain a SQL injection vulnerability via the orderID parameter at /adminView/viewEachOrder.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-14T15:15:09Z" diff --git a/advisories/unreviewed/2024/02/GHSA-h4x6-mh99-9m5r/GHSA-h4x6-mh99-9m5r.json b/advisories/unreviewed/2024/02/GHSA-h4x6-mh99-9m5r/GHSA-h4x6-mh99-9m5r.json index 29c2a3f332a..e587c3be3dd 100644 --- a/advisories/unreviewed/2024/02/GHSA-h4x6-mh99-9m5r/GHSA-h4x6-mh99-9m5r.json +++ b/advisories/unreviewed/2024/02/GHSA-h4x6-mh99-9m5r/GHSA-h4x6-mh99-9m5r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h4x6-mh99-9m5r", - "modified": "2024-02-14T18:30:24Z", + "modified": "2024-10-23T18:33:06Z", "published": "2024-02-14T18:30:24Z", "aliases": [ "CVE-2024-25209" ], "details": "Barangay Population Monitoring System 1.0 was discovered to contain a SQL injection vulnerability via the resident parameter at /endpoint/delete-resident.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-14T15:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-q5cv-3jwf-5p4q/GHSA-q5cv-3jwf-5p4q.json b/advisories/unreviewed/2024/02/GHSA-q5cv-3jwf-5p4q/GHSA-q5cv-3jwf-5p4q.json index 2051e2b4799..a9968b6d70b 100644 --- a/advisories/unreviewed/2024/02/GHSA-q5cv-3jwf-5p4q/GHSA-q5cv-3jwf-5p4q.json +++ b/advisories/unreviewed/2024/02/GHSA-q5cv-3jwf-5p4q/GHSA-q5cv-3jwf-5p4q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q5cv-3jwf-5p4q", - "modified": "2024-02-14T18:30:24Z", + "modified": "2024-10-23T18:33:06Z", "published": "2024-02-14T18:30:24Z", "aliases": [ "CVE-2024-25210" ], "details": "Simple Expense Tracker v1.0 was discovered to contain a SQL injection vulnerability via the expense parameter at /endpoint/delete_expense.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-14T15:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-w29g-3qfg-crvr/GHSA-w29g-3qfg-crvr.json b/advisories/unreviewed/2024/02/GHSA-w29g-3qfg-crvr/GHSA-w29g-3qfg-crvr.json index 5f2d3614ac8..9a3ce75371a 100644 --- a/advisories/unreviewed/2024/02/GHSA-w29g-3qfg-crvr/GHSA-w29g-3qfg-crvr.json +++ b/advisories/unreviewed/2024/02/GHSA-w29g-3qfg-crvr/GHSA-w29g-3qfg-crvr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w29g-3qfg-crvr", - "modified": "2024-02-14T18:30:25Z", + "modified": "2024-10-23T18:33:06Z", "published": "2024-02-14T18:30:25Z", "aliases": [ "CVE-2024-25224" ], "details": "A cross-site scripting (XSS) vulnerability in Simple Admin Panel App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Size Number parameter under the Add Size function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-14T15:15:09Z" diff --git a/advisories/unreviewed/2024/10/GHSA-cq52-r7vq-58pv/GHSA-cq52-r7vq-58pv.json b/advisories/unreviewed/2024/10/GHSA-cq52-r7vq-58pv/GHSA-cq52-r7vq-58pv.json new file mode 100644 index 00000000000..6d2f2173d37 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-cq52-r7vq-58pv/GHSA-cq52-r7vq-58pv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cq52-r7vq-58pv", + "modified": "2024-10-23T18:33:06Z", + "published": "2024-10-23T18:33:06Z", + "aliases": [ + "CVE-2023-40161" + ], + "details": "Improper access control in some Intel Unite(R) Client software before version 4.2.35041 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40161" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00981.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T14:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-jjm3-4r8v-2j95/GHSA-jjm3-4r8v-2j95.json b/advisories/unreviewed/2024/10/GHSA-jjm3-4r8v-2j95/GHSA-jjm3-4r8v-2j95.json new file mode 100644 index 00000000000..509a801f286 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-jjm3-4r8v-2j95/GHSA-jjm3-4r8v-2j95.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jjm3-4r8v-2j95", + "modified": "2024-10-23T18:33:06Z", + "published": "2024-10-23T18:33:06Z", + "aliases": [ + "CVE-2023-41090" + ], + "details": "Race condition in some Intel(R) MAS software before version 2.3 may allow a privileged user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41090" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00967.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-362", + "CWE-421" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T14:16:05Z" + } +} \ No newline at end of file