diff --git a/advisories/unreviewed/2024/07/GHSA-44mp-wrcj-wjx3/GHSA-44mp-wrcj-wjx3.json b/advisories/unreviewed/2024/07/GHSA-44mp-wrcj-wjx3/GHSA-44mp-wrcj-wjx3.json index e1592c7ccfc..a1b20cdac8d 100644 --- a/advisories/unreviewed/2024/07/GHSA-44mp-wrcj-wjx3/GHSA-44mp-wrcj-wjx3.json +++ b/advisories/unreviewed/2024/07/GHSA-44mp-wrcj-wjx3/GHSA-44mp-wrcj-wjx3.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-116", "CWE-644" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/07/GHSA-56wj-jfhp-fq9f/GHSA-56wj-jfhp-fq9f.json b/advisories/unreviewed/2024/07/GHSA-56wj-jfhp-fq9f/GHSA-56wj-jfhp-fq9f.json index 0fd16ac829f..e8f08193f2a 100644 --- a/advisories/unreviewed/2024/07/GHSA-56wj-jfhp-fq9f/GHSA-56wj-jfhp-fq9f.json +++ b/advisories/unreviewed/2024/07/GHSA-56wj-jfhp-fq9f/GHSA-56wj-jfhp-fq9f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-56wj-jfhp-fq9f", - "modified": "2024-07-31T21:32:38Z", + "modified": "2024-08-13T15:31:33Z", "published": "2024-07-31T21:32:38Z", "aliases": [ "CVE-2019-6198" diff --git a/advisories/unreviewed/2024/07/GHSA-86w3-pw2m-73fq/GHSA-86w3-pw2m-73fq.json b/advisories/unreviewed/2024/07/GHSA-86w3-pw2m-73fq/GHSA-86w3-pw2m-73fq.json index af2808adc91..1f937763172 100644 --- a/advisories/unreviewed/2024/07/GHSA-86w3-pw2m-73fq/GHSA-86w3-pw2m-73fq.json +++ b/advisories/unreviewed/2024/07/GHSA-86w3-pw2m-73fq/GHSA-86w3-pw2m-73fq.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-1004" + "CWE-1004", + "CWE-732" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-qjh8-9wf4-5229/GHSA-qjh8-9wf4-5229.json b/advisories/unreviewed/2024/07/GHSA-qjh8-9wf4-5229/GHSA-qjh8-9wf4-5229.json index 240d4b6d7a9..8689b50e5ba 100644 --- a/advisories/unreviewed/2024/07/GHSA-qjh8-9wf4-5229/GHSA-qjh8-9wf4-5229.json +++ b/advisories/unreviewed/2024/07/GHSA-qjh8-9wf4-5229/GHSA-qjh8-9wf4-5229.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-77" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-whww-hhj9-9f35/GHSA-whww-hhj9-9f35.json b/advisories/unreviewed/2024/07/GHSA-whww-hhj9-9f35/GHSA-whww-hhj9-9f35.json index 6facc787147..76e812758e0 100644 --- a/advisories/unreviewed/2024/07/GHSA-whww-hhj9-9f35/GHSA-whww-hhj9-9f35.json +++ b/advisories/unreviewed/2024/07/GHSA-whww-hhj9-9f35/GHSA-whww-hhj9-9f35.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-23v8-j48f-jm74/GHSA-23v8-j48f-jm74.json b/advisories/unreviewed/2024/08/GHSA-23v8-j48f-jm74/GHSA-23v8-j48f-jm74.json index 8ac969496d9..a6e5e7c811e 100644 --- a/advisories/unreviewed/2024/08/GHSA-23v8-j48f-jm74/GHSA-23v8-j48f-jm74.json +++ b/advisories/unreviewed/2024/08/GHSA-23v8-j48f-jm74/GHSA-23v8-j48f-jm74.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-23v8-j48f-jm74", - "modified": "2024-08-12T15:30:48Z", + "modified": "2024-08-13T15:31:33Z", "published": "2024-08-12T15:30:48Z", "aliases": [ "CVE-2023-50809" ], "details": "In certain Sonos products before S1 Release 11.12 and S2 release 15.9, the mt_7615.ko wireless driver does not properly validate an information element during negotiation of a WPA2 four-way handshake. This lack of validation leads to a stack buffer overflow. This can result in remote code execution within the kernel. This affects Amp, Arc, Arc SL, Beam, Beam Gen 2, Beam SL, and Five.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-12T13:38:11Z" diff --git a/advisories/unreviewed/2024/08/GHSA-2mcp-f38w-p5gf/GHSA-2mcp-f38w-p5gf.json b/advisories/unreviewed/2024/08/GHSA-2mcp-f38w-p5gf/GHSA-2mcp-f38w-p5gf.json index 725d639c1df..c831a82d845 100644 --- a/advisories/unreviewed/2024/08/GHSA-2mcp-f38w-p5gf/GHSA-2mcp-f38w-p5gf.json +++ b/advisories/unreviewed/2024/08/GHSA-2mcp-f38w-p5gf/GHSA-2mcp-f38w-p5gf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2mcp-f38w-p5gf", - "modified": "2024-08-12T15:30:51Z", + "modified": "2024-08-13T15:31:34Z", "published": "2024-08-12T15:30:51Z", "aliases": [ "CVE-2024-6760" ], "details": "A logic bug in the code which disables kernel tracing for setuid programs meant that tracing was not disabled when it should have, allowing unprivileged users to trace and inspect the behavior of setuid programs.\n\nThe bug may be used by an unprivileged user to read the contents of files to which they would not otherwise have access, such as the local password database.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-12T13:38:40Z" diff --git a/advisories/unreviewed/2024/08/GHSA-2qw7-j9xq-5qjq/GHSA-2qw7-j9xq-5qjq.json b/advisories/unreviewed/2024/08/GHSA-2qw7-j9xq-5qjq/GHSA-2qw7-j9xq-5qjq.json index 865212ae74c..703e153fc83 100644 --- a/advisories/unreviewed/2024/08/GHSA-2qw7-j9xq-5qjq/GHSA-2qw7-j9xq-5qjq.json +++ b/advisories/unreviewed/2024/08/GHSA-2qw7-j9xq-5qjq/GHSA-2qw7-j9xq-5qjq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2qw7-j9xq-5qjq", - "modified": "2024-08-12T18:30:48Z", + "modified": "2024-08-13T15:31:34Z", "published": "2024-08-12T18:30:48Z", "aliases": [ "CVE-2024-42623" ], "details": "FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/delete/1", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-12T17:15:17Z" diff --git a/advisories/unreviewed/2024/08/GHSA-3h5p-hx2f-x27c/GHSA-3h5p-hx2f-x27c.json b/advisories/unreviewed/2024/08/GHSA-3h5p-hx2f-x27c/GHSA-3h5p-hx2f-x27c.json new file mode 100644 index 00000000000..2011d232e0e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-3h5p-hx2f-x27c/GHSA-3h5p-hx2f-x27c.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3h5p-hx2f-x27c", + "modified": "2024-08-13T15:31:32Z", + "published": "2024-08-13T15:31:32Z", + "aliases": [ + "CVE-2024-23787" + ], + "details": "Path traversal vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to obtain an arbitrary file in the affected product.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23787" + }, + { + "type": "WEB", + "url": "https://jp.sharp/support/taiyo/info/JVNVU94591337_en.pdf" + }, + { + "type": "WEB", + "url": "https://jp.sharp/support/taiyo/info/JVNVU94591337_jp.pdf" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/vu/JVNVU94591337" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-46r4-hcf2-8pmx/GHSA-46r4-hcf2-8pmx.json b/advisories/unreviewed/2024/08/GHSA-46r4-hcf2-8pmx/GHSA-46r4-hcf2-8pmx.json index 32acfc79bb3..8c2d75ce957 100644 --- a/advisories/unreviewed/2024/08/GHSA-46r4-hcf2-8pmx/GHSA-46r4-hcf2-8pmx.json +++ b/advisories/unreviewed/2024/08/GHSA-46r4-hcf2-8pmx/GHSA-46r4-hcf2-8pmx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-46r4-hcf2-8pmx", - "modified": "2024-08-06T15:30:54Z", + "modified": "2024-08-13T15:31:33Z", "published": "2024-08-06T15:30:54Z", "aliases": [ "CVE-2024-41913" ], "details": "A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware flaw does not properly sanitize User input.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-06T14:16:04Z" diff --git a/advisories/unreviewed/2024/08/GHSA-4wrj-qhhf-3c55/GHSA-4wrj-qhhf-3c55.json b/advisories/unreviewed/2024/08/GHSA-4wrj-qhhf-3c55/GHSA-4wrj-qhhf-3c55.json new file mode 100644 index 00000000000..61e3bf424df --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-4wrj-qhhf-3c55/GHSA-4wrj-qhhf-3c55.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4wrj-qhhf-3c55", + "modified": "2024-08-13T15:31:35Z", + "published": "2024-08-13T15:31:35Z", + "aliases": [ + "CVE-2024-41623" + ], + "details": "An issue in D3D Security D3D IP Camera (D8801) v.V9.1.17.1.4-20180428 allows a local attacker to execute arbitrary code via a crafted payload", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41623" + }, + { + "type": "WEB", + "url": "https://github.com/Anonymous120386/Anonymous" + }, + { + "type": "WEB", + "url": "http://d3d.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-62mf-rw5r-h5jq/GHSA-62mf-rw5r-h5jq.json b/advisories/unreviewed/2024/08/GHSA-62mf-rw5r-h5jq/GHSA-62mf-rw5r-h5jq.json index 4231add1371..4351adaa3fc 100644 --- a/advisories/unreviewed/2024/08/GHSA-62mf-rw5r-h5jq/GHSA-62mf-rw5r-h5jq.json +++ b/advisories/unreviewed/2024/08/GHSA-62mf-rw5r-h5jq/GHSA-62mf-rw5r-h5jq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-62mf-rw5r-h5jq", - "modified": "2024-08-12T18:30:48Z", + "modified": "2024-08-13T15:31:34Z", "published": "2024-08-12T18:30:48Z", "aliases": [ "CVE-2024-42632" ], "details": "FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/page/add.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-12T16:15:17Z" diff --git a/advisories/unreviewed/2024/08/GHSA-644m-h87w-v6x9/GHSA-644m-h87w-v6x9.json b/advisories/unreviewed/2024/08/GHSA-644m-h87w-v6x9/GHSA-644m-h87w-v6x9.json index b5e2bba2374..a430d7ab625 100644 --- a/advisories/unreviewed/2024/08/GHSA-644m-h87w-v6x9/GHSA-644m-h87w-v6x9.json +++ b/advisories/unreviewed/2024/08/GHSA-644m-h87w-v6x9/GHSA-644m-h87w-v6x9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-644m-h87w-v6x9", - "modified": "2024-08-12T18:30:48Z", + "modified": "2024-08-13T15:31:34Z", "published": "2024-08-12T18:30:48Z", "aliases": [ "CVE-2024-42630" ], "details": "FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/create_file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-12T16:15:17Z" diff --git a/advisories/unreviewed/2024/08/GHSA-6q4q-jp73-89cq/GHSA-6q4q-jp73-89cq.json b/advisories/unreviewed/2024/08/GHSA-6q4q-jp73-89cq/GHSA-6q4q-jp73-89cq.json index 0c60e4cc7d5..41cb4626406 100644 --- a/advisories/unreviewed/2024/08/GHSA-6q4q-jp73-89cq/GHSA-6q4q-jp73-89cq.json +++ b/advisories/unreviewed/2024/08/GHSA-6q4q-jp73-89cq/GHSA-6q4q-jp73-89cq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6q4q-jp73-89cq", - "modified": "2024-08-12T18:30:48Z", + "modified": "2024-08-13T15:31:34Z", "published": "2024-08-12T18:30:48Z", "aliases": [ "CVE-2024-42545" ], "details": "TOTOLINK A3700R v9.1.2u.5822_B20200513 has a buffer overflow vulnerability in the ssid parameter in setWizardCfg function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-12T18:15:12Z" diff --git a/advisories/unreviewed/2024/08/GHSA-766h-vjvr-5rg4/GHSA-766h-vjvr-5rg4.json b/advisories/unreviewed/2024/08/GHSA-766h-vjvr-5rg4/GHSA-766h-vjvr-5rg4.json new file mode 100644 index 00000000000..13505f9f45b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-766h-vjvr-5rg4/GHSA-766h-vjvr-5rg4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-766h-vjvr-5rg4", + "modified": "2024-08-13T15:31:35Z", + "published": "2024-08-13T15:31:35Z", + "aliases": [ + "CVE-2024-5849" + ], + "details": "An unauthenticated remote attacker may use a reflected XSS vulnerability to obtain information from a user or reboot the affected device once.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5849" + }, + { + "type": "WEB", + "url": "https://cert.vde.com/en/advisories/VDE-2024-033" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T13:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7q2g-j3r8-hgwh/GHSA-7q2g-j3r8-hgwh.json b/advisories/unreviewed/2024/08/GHSA-7q2g-j3r8-hgwh/GHSA-7q2g-j3r8-hgwh.json index 71a35abedff..861bc08834a 100644 --- a/advisories/unreviewed/2024/08/GHSA-7q2g-j3r8-hgwh/GHSA-7q2g-j3r8-hgwh.json +++ b/advisories/unreviewed/2024/08/GHSA-7q2g-j3r8-hgwh/GHSA-7q2g-j3r8-hgwh.json @@ -48,7 +48,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-7xp8-p4r3-6rv8/GHSA-7xp8-p4r3-6rv8.json b/advisories/unreviewed/2024/08/GHSA-7xp8-p4r3-6rv8/GHSA-7xp8-p4r3-6rv8.json index 2ee5488fd70..5afbd01c0b8 100644 --- a/advisories/unreviewed/2024/08/GHSA-7xp8-p4r3-6rv8/GHSA-7xp8-p4r3-6rv8.json +++ b/advisories/unreviewed/2024/08/GHSA-7xp8-p4r3-6rv8/GHSA-7xp8-p4r3-6rv8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7xp8-p4r3-6rv8", - "modified": "2024-08-06T15:30:54Z", + "modified": "2024-08-13T15:31:33Z", "published": "2024-08-06T15:30:54Z", "aliases": [ "CVE-2024-41911" ], "details": "A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The flaw does not properly neutralize input during a web page generation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-06T14:16:04Z" diff --git a/advisories/unreviewed/2024/08/GHSA-82fp-rv69-j7ww/GHSA-82fp-rv69-j7ww.json b/advisories/unreviewed/2024/08/GHSA-82fp-rv69-j7ww/GHSA-82fp-rv69-j7ww.json index db886dc94c5..117e915b8cc 100644 --- a/advisories/unreviewed/2024/08/GHSA-82fp-rv69-j7ww/GHSA-82fp-rv69-j7ww.json +++ b/advisories/unreviewed/2024/08/GHSA-82fp-rv69-j7ww/GHSA-82fp-rv69-j7ww.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-82fp-rv69-j7ww", - "modified": "2024-08-12T18:30:48Z", + "modified": "2024-08-13T15:31:34Z", "published": "2024-08-12T18:30:48Z", "aliases": [ "CVE-2024-42543" ], "details": "TOTOLINK A3700R v9.1.2u.5822_B20200513 has a buffer overflow vulnerability in the http_host parameter in the loginauth function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-12T18:15:12Z" diff --git a/advisories/unreviewed/2024/08/GHSA-83cp-ppjr-7w6j/GHSA-83cp-ppjr-7w6j.json b/advisories/unreviewed/2024/08/GHSA-83cp-ppjr-7w6j/GHSA-83cp-ppjr-7w6j.json new file mode 100644 index 00000000000..3d83d564254 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-83cp-ppjr-7w6j/GHSA-83cp-ppjr-7w6j.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-83cp-ppjr-7w6j", + "modified": "2024-08-13T15:31:36Z", + "published": "2024-08-13T15:31:36Z", + "aliases": [ + "CVE-2024-42738" + ], + "details": "In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setDmzCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42738" + }, + { + "type": "WEB", + "url": "https://github.com/HouseFuzz/reports/blob/main/totolink/x5000r/setDmzCfg/setDmzCfg.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T14:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-86mq-3mw2-pcch/GHSA-86mq-3mw2-pcch.json b/advisories/unreviewed/2024/08/GHSA-86mq-3mw2-pcch/GHSA-86mq-3mw2-pcch.json index 80d19f0bdb7..d0b31f8e7d1 100644 --- a/advisories/unreviewed/2024/08/GHSA-86mq-3mw2-pcch/GHSA-86mq-3mw2-pcch.json +++ b/advisories/unreviewed/2024/08/GHSA-86mq-3mw2-pcch/GHSA-86mq-3mw2-pcch.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-86mq-3mw2-pcch", - "modified": "2024-08-12T18:30:48Z", + "modified": "2024-08-13T15:31:34Z", "published": "2024-08-12T18:30:48Z", "aliases": [ "CVE-2024-42631" ], "details": "FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/edit/1.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-12T16:15:17Z" diff --git a/advisories/unreviewed/2024/08/GHSA-9vqm-2gvw-hvf5/GHSA-9vqm-2gvw-hvf5.json b/advisories/unreviewed/2024/08/GHSA-9vqm-2gvw-hvf5/GHSA-9vqm-2gvw-hvf5.json index 5514d243848..b28497d14d1 100644 --- a/advisories/unreviewed/2024/08/GHSA-9vqm-2gvw-hvf5/GHSA-9vqm-2gvw-hvf5.json +++ b/advisories/unreviewed/2024/08/GHSA-9vqm-2gvw-hvf5/GHSA-9vqm-2gvw-hvf5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9vqm-2gvw-hvf5", - "modified": "2024-08-12T18:30:48Z", + "modified": "2024-08-13T15:31:34Z", "published": "2024-08-12T18:30:48Z", "aliases": [ "CVE-2024-42626" ], "details": "FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/snippet/add.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-12T17:15:18Z" diff --git a/advisories/unreviewed/2024/08/GHSA-cf5j-4329-c5cr/GHSA-cf5j-4329-c5cr.json b/advisories/unreviewed/2024/08/GHSA-cf5j-4329-c5cr/GHSA-cf5j-4329-c5cr.json index 0ec942f2a4f..90f60818b8a 100644 --- a/advisories/unreviewed/2024/08/GHSA-cf5j-4329-c5cr/GHSA-cf5j-4329-c5cr.json +++ b/advisories/unreviewed/2024/08/GHSA-cf5j-4329-c5cr/GHSA-cf5j-4329-c5cr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cf5j-4329-c5cr", - "modified": "2024-08-12T15:30:50Z", + "modified": "2024-08-13T15:31:33Z", "published": "2024-08-12T15:30:50Z", "aliases": [ "CVE-2024-41482" ], "details": "Typora before 1.9.3 Markdown editor has a cross-site scripting (XSS) vulnerability via the MathJax component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-12T13:38:31Z" diff --git a/advisories/unreviewed/2024/08/GHSA-cmqh-7j5w-frxf/GHSA-cmqh-7j5w-frxf.json b/advisories/unreviewed/2024/08/GHSA-cmqh-7j5w-frxf/GHSA-cmqh-7j5w-frxf.json index 2b69e796b96..22dfcb22e47 100644 --- a/advisories/unreviewed/2024/08/GHSA-cmqh-7j5w-frxf/GHSA-cmqh-7j5w-frxf.json +++ b/advisories/unreviewed/2024/08/GHSA-cmqh-7j5w-frxf/GHSA-cmqh-7j5w-frxf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cmqh-7j5w-frxf", - "modified": "2024-08-12T15:30:50Z", + "modified": "2024-08-13T15:31:33Z", "published": "2024-08-12T15:30:50Z", "aliases": [ "CVE-2024-41481" ], "details": "Typora before 1.9.3 Markdown editor has a cross-site scripting (XSS) vulnerability via the Mermaid component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-12T13:38:30Z" diff --git a/advisories/unreviewed/2024/08/GHSA-f478-vv2x-5qvv/GHSA-f478-vv2x-5qvv.json b/advisories/unreviewed/2024/08/GHSA-f478-vv2x-5qvv/GHSA-f478-vv2x-5qvv.json new file mode 100644 index 00000000000..6139778d66f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-f478-vv2x-5qvv/GHSA-f478-vv2x-5qvv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f478-vv2x-5qvv", + "modified": "2024-08-13T15:31:35Z", + "published": "2024-08-13T15:31:35Z", + "aliases": [ + "CVE-2024-38501" + ], + "details": "An unauthenticated remote attacker may use a HTML injection vulnerability with limited length to inject malicious HTML code and gain low-privileged access on the affected device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38501" + }, + { + "type": "WEB", + "url": "https://cert.vde.com/en/advisories/VDE-2024-033" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T13:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-ghv2-6cx6-8wrg/GHSA-ghv2-6cx6-8wrg.json b/advisories/unreviewed/2024/08/GHSA-ghv2-6cx6-8wrg/GHSA-ghv2-6cx6-8wrg.json index 2e88d7bd477..0ba160996ee 100644 --- a/advisories/unreviewed/2024/08/GHSA-ghv2-6cx6-8wrg/GHSA-ghv2-6cx6-8wrg.json +++ b/advisories/unreviewed/2024/08/GHSA-ghv2-6cx6-8wrg/GHSA-ghv2-6cx6-8wrg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ghv2-6cx6-8wrg", - "modified": "2024-08-12T18:30:48Z", + "modified": "2024-08-13T15:31:34Z", "published": "2024-08-12T18:30:48Z", "aliases": [ "CVE-2024-42627" ], "details": "FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/snippet/delete/3.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-12T17:15:18Z" diff --git a/advisories/unreviewed/2024/08/GHSA-gvrf-4h52-xwxp/GHSA-gvrf-4h52-xwxp.json b/advisories/unreviewed/2024/08/GHSA-gvrf-4h52-xwxp/GHSA-gvrf-4h52-xwxp.json new file mode 100644 index 00000000000..109ac481723 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-gvrf-4h52-xwxp/GHSA-gvrf-4h52-xwxp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gvrf-4h52-xwxp", + "modified": "2024-08-13T15:31:36Z", + "published": "2024-08-13T15:31:36Z", + "aliases": [ + "CVE-2024-6384" + ], + "details": "\"Hot\" backup files may be downloaded by underprivileged users, if they are capable of acquiring a unique backup identifier. This issue affects MongoDB Enterprise Server v6.0 versions prior to 6.0.16, MongoDB Enterprise Server v7.0 versions prior to 7.0.11 and MongoDB Enterprise Server v7.3 versions prior to 7.3.3", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6384" + }, + { + "type": "WEB", + "url": "https://jira.mongodb.org/browse/SERVER-93516" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-hjw6-cjgv-379x/GHSA-hjw6-cjgv-379x.json b/advisories/unreviewed/2024/08/GHSA-hjw6-cjgv-379x/GHSA-hjw6-cjgv-379x.json index 65a0764bfb6..bd9e0419e6a 100644 --- a/advisories/unreviewed/2024/08/GHSA-hjw6-cjgv-379x/GHSA-hjw6-cjgv-379x.json +++ b/advisories/unreviewed/2024/08/GHSA-hjw6-cjgv-379x/GHSA-hjw6-cjgv-379x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hjw6-cjgv-379x", - "modified": "2024-08-06T15:30:54Z", + "modified": "2024-08-13T15:31:33Z", "published": "2024-08-06T15:30:54Z", "aliases": [ "CVE-2024-41910" ], "details": "A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware contained multiple XXS vulnerabilities in the version of JavaScript used.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-06T14:16:04Z" diff --git a/advisories/unreviewed/2024/08/GHSA-j85v-mpgg-r272/GHSA-j85v-mpgg-r272.json b/advisories/unreviewed/2024/08/GHSA-j85v-mpgg-r272/GHSA-j85v-mpgg-r272.json new file mode 100644 index 00000000000..cc81c5f1d81 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-j85v-mpgg-r272/GHSA-j85v-mpgg-r272.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j85v-mpgg-r272", + "modified": "2024-08-13T15:31:35Z", + "published": "2024-08-13T15:31:35Z", + "aliases": [ + "CVE-2024-42736" + ], + "details": "In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in addBlacklist. Authenticated Attackers can send malicious packet to execute arbitrary commands.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42736" + }, + { + "type": "WEB", + "url": "https://github.com/HouseFuzz/reports/blob/main/totolink/x5000r/addBlacklist/addBlacklist.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T14:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-jcvv-37v4-9r3f/GHSA-jcvv-37v4-9r3f.json b/advisories/unreviewed/2024/08/GHSA-jcvv-37v4-9r3f/GHSA-jcvv-37v4-9r3f.json new file mode 100644 index 00000000000..353816d5407 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-jcvv-37v4-9r3f/GHSA-jcvv-37v4-9r3f.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jcvv-37v4-9r3f", + "modified": "2024-08-13T15:31:36Z", + "published": "2024-08-13T15:31:36Z", + "aliases": [ + "CVE-2024-42740" + ], + "details": "In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setLedCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42740" + }, + { + "type": "WEB", + "url": "https://github.com/HouseFuzz/reports/blob/main/totolink/x5000r/setLedCfg/setLedCfg.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T14:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-m373-6rxj-pvqw/GHSA-m373-6rxj-pvqw.json b/advisories/unreviewed/2024/08/GHSA-m373-6rxj-pvqw/GHSA-m373-6rxj-pvqw.json index 9e750347dea..9c47fa178b7 100644 --- a/advisories/unreviewed/2024/08/GHSA-m373-6rxj-pvqw/GHSA-m373-6rxj-pvqw.json +++ b/advisories/unreviewed/2024/08/GHSA-m373-6rxj-pvqw/GHSA-m373-6rxj-pvqw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m373-6rxj-pvqw", - "modified": "2024-08-12T15:30:54Z", + "modified": "2024-08-13T15:31:34Z", "published": "2024-08-12T15:30:54Z", "aliases": [ "CVE-2024-42520" ], "details": "TOTOLINK A3002R v4.0.0-B20230531.1404 contains a buffer overflow vulnerability in /bin/boa via formParentControl.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-12T15:15:21Z" diff --git a/advisories/unreviewed/2024/08/GHSA-mjh6-rpqh-wmw5/GHSA-mjh6-rpqh-wmw5.json b/advisories/unreviewed/2024/08/GHSA-mjh6-rpqh-wmw5/GHSA-mjh6-rpqh-wmw5.json new file mode 100644 index 00000000000..483a17ecf7e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-mjh6-rpqh-wmw5/GHSA-mjh6-rpqh-wmw5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mjh6-rpqh-wmw5", + "modified": "2024-08-13T15:31:36Z", + "published": "2024-08-13T15:31:36Z", + "aliases": [ + "CVE-2024-42737" + ], + "details": "In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in delBlacklist. Authenticated Attackers can send malicious packet to execute arbitrary commands.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42737" + }, + { + "type": "WEB", + "url": "https://github.com/HouseFuzz/reports/blob/main/totolink/x5000r/delBlacklist/delBlacklist.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T14:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-p734-xg27-8cfq/GHSA-p734-xg27-8cfq.json b/advisories/unreviewed/2024/08/GHSA-p734-xg27-8cfq/GHSA-p734-xg27-8cfq.json index 6b3e667d8d8..b6aa7c8e70f 100644 --- a/advisories/unreviewed/2024/08/GHSA-p734-xg27-8cfq/GHSA-p734-xg27-8cfq.json +++ b/advisories/unreviewed/2024/08/GHSA-p734-xg27-8cfq/GHSA-p734-xg27-8cfq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p734-xg27-8cfq", - "modified": "2024-08-12T15:30:49Z", + "modified": "2024-08-13T15:31:33Z", "published": "2024-08-12T15:30:49Z", "aliases": [ "CVE-2024-38989" ], "details": "izatop bunt v0.29.19 was discovered to contain a prototype pollution via the component /esm/qs.js. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1321" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-12T13:38:24Z" diff --git a/advisories/unreviewed/2024/08/GHSA-r7x8-hv2q-v9r7/GHSA-r7x8-hv2q-v9r7.json b/advisories/unreviewed/2024/08/GHSA-r7x8-hv2q-v9r7/GHSA-r7x8-hv2q-v9r7.json index dc5016a650a..d891620c068 100644 --- a/advisories/unreviewed/2024/08/GHSA-r7x8-hv2q-v9r7/GHSA-r7x8-hv2q-v9r7.json +++ b/advisories/unreviewed/2024/08/GHSA-r7x8-hv2q-v9r7/GHSA-r7x8-hv2q-v9r7.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-476", "CWE-754" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/08/GHSA-r979-6ffq-pvxw/GHSA-r979-6ffq-pvxw.json b/advisories/unreviewed/2024/08/GHSA-r979-6ffq-pvxw/GHSA-r979-6ffq-pvxw.json new file mode 100644 index 00000000000..5518b38a1e0 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-r979-6ffq-pvxw/GHSA-r979-6ffq-pvxw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r979-6ffq-pvxw", + "modified": "2024-08-13T15:31:36Z", + "published": "2024-08-13T15:31:36Z", + "aliases": [ + "CVE-2024-42739" + ], + "details": "In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setAccessDeviceCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42739" + }, + { + "type": "WEB", + "url": "https://github.com/HouseFuzz/reports/blob/main/totolink/x5000r/setAccessDeviceCfg/setAccessDeviceCfg.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T14:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-v4w4-m4h5-jqf4/GHSA-v4w4-m4h5-jqf4.json b/advisories/unreviewed/2024/08/GHSA-v4w4-m4h5-jqf4/GHSA-v4w4-m4h5-jqf4.json new file mode 100644 index 00000000000..ce2f650b90b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-v4w4-m4h5-jqf4/GHSA-v4w4-m4h5-jqf4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v4w4-m4h5-jqf4", + "modified": "2024-08-13T15:31:35Z", + "published": "2024-08-13T15:31:35Z", + "aliases": [ + "CVE-2024-3913" + ], + "details": "An unauthenticated remote attacker can use this vulnerability to change the device configuration due to a file writeable for short time after system startup.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3913" + }, + { + "type": "WEB", + "url": "https://cert.vde.com/en/advisories/VDE-2024-022" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-552" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T13:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-x43g-g62f-p4cw/GHSA-x43g-g62f-p4cw.json b/advisories/unreviewed/2024/08/GHSA-x43g-g62f-p4cw/GHSA-x43g-g62f-p4cw.json new file mode 100644 index 00000000000..921b7a9ccd2 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-x43g-g62f-p4cw/GHSA-x43g-g62f-p4cw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x43g-g62f-p4cw", + "modified": "2024-08-13T15:31:35Z", + "published": "2024-08-13T15:31:35Z", + "aliases": [ + "CVE-2024-38502" + ], + "details": "An unauthenticated remote attacker may use stored XSS vulnerability to obtain information from a user or reboot the affected device once.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38502" + }, + { + "type": "WEB", + "url": "https://cert.vde.com/en/advisories/VDE-2024-033" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T13:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-xpwm-vrv5-5mgm/GHSA-xpwm-vrv5-5mgm.json b/advisories/unreviewed/2024/08/GHSA-xpwm-vrv5-5mgm/GHSA-xpwm-vrv5-5mgm.json new file mode 100644 index 00000000000..4d98d2423a1 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-xpwm-vrv5-5mgm/GHSA-xpwm-vrv5-5mgm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xpwm-vrv5-5mgm", + "modified": "2024-08-13T15:31:36Z", + "published": "2024-08-13T15:31:36Z", + "aliases": [ + "CVE-2024-6788" + ], + "details": "A remote unauthenticated attacker can use the firmware update feature on the LAN interface of the device to reset the password for the predefined, low-privileged user “user-app” to the default password.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6788" + }, + { + "type": "WEB", + "url": "https://cert.vde.com/en/advisories/VDE-2024-022" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1188" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T14:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-xq9q-5j9m-x6xx/GHSA-xq9q-5j9m-x6xx.json b/advisories/unreviewed/2024/08/GHSA-xq9q-5j9m-x6xx/GHSA-xq9q-5j9m-x6xx.json index d0bb2bb613a..53f5bee2d12 100644 --- a/advisories/unreviewed/2024/08/GHSA-xq9q-5j9m-x6xx/GHSA-xq9q-5j9m-x6xx.json +++ b/advisories/unreviewed/2024/08/GHSA-xq9q-5j9m-x6xx/GHSA-xq9q-5j9m-x6xx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xq9q-5j9m-x6xx", - "modified": "2024-08-12T18:30:48Z", + "modified": "2024-08-13T15:31:34Z", "published": "2024-08-12T18:30:48Z", "aliases": [ "CVE-2024-42624" ], "details": "FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/page/delete/10.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-12T17:15:18Z" diff --git a/advisories/unreviewed/2024/08/GHSA-xw3w-rw7p-r5rj/GHSA-xw3w-rw7p-r5rj.json b/advisories/unreviewed/2024/08/GHSA-xw3w-rw7p-r5rj/GHSA-xw3w-rw7p-r5rj.json index a37247be366..26c49b6c763 100644 --- a/advisories/unreviewed/2024/08/GHSA-xw3w-rw7p-r5rj/GHSA-xw3w-rw7p-r5rj.json +++ b/advisories/unreviewed/2024/08/GHSA-xw3w-rw7p-r5rj/GHSA-xw3w-rw7p-r5rj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xw3w-rw7p-r5rj", - "modified": "2024-08-12T18:30:48Z", + "modified": "2024-08-13T15:31:34Z", "published": "2024-08-12T18:30:48Z", "aliases": [ "CVE-2024-42628" ], "details": "FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/snippet/edit/3.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-12T16:15:16Z"