diff --git a/advisories/unreviewed/2024/04/GHSA-94qf-5xc2-5vrq/GHSA-94qf-5xc2-5vrq.json b/advisories/unreviewed/2024/04/GHSA-94qf-5xc2-5vrq/GHSA-94qf-5xc2-5vrq.json index 5ea170345a8..2482216fbce 100644 --- a/advisories/unreviewed/2024/04/GHSA-94qf-5xc2-5vrq/GHSA-94qf-5xc2-5vrq.json +++ b/advisories/unreviewed/2024/04/GHSA-94qf-5xc2-5vrq/GHSA-94qf-5xc2-5vrq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-94qf-5xc2-5vrq", - "modified": "2024-04-12T15:37:21Z", + "modified": "2024-07-05T15:32:05Z", "published": "2024-04-12T15:37:21Z", "aliases": [ "CVE-2024-3707" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3707" }, + { + "type": "WEB", + "url": "https://opengnsys.es/web/parche-de-seguridad-cve-2024-370x" + }, { "type": "WEB", "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-opengnsys" diff --git a/advisories/unreviewed/2024/04/GHSA-g949-gmj8-65gh/GHSA-g949-gmj8-65gh.json b/advisories/unreviewed/2024/04/GHSA-g949-gmj8-65gh/GHSA-g949-gmj8-65gh.json index 15d7aeb0277..95baa43c2e4 100644 --- a/advisories/unreviewed/2024/04/GHSA-g949-gmj8-65gh/GHSA-g949-gmj8-65gh.json +++ b/advisories/unreviewed/2024/04/GHSA-g949-gmj8-65gh/GHSA-g949-gmj8-65gh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g949-gmj8-65gh", - "modified": "2024-04-12T15:37:21Z", + "modified": "2024-07-05T15:32:05Z", "published": "2024-04-12T15:37:21Z", "aliases": [ "CVE-2024-3706" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3706" }, + { + "type": "WEB", + "url": "https://opengnsys.es/web/parche-de-seguridad-cve-2024-370x" + }, { "type": "WEB", "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-opengnsys" diff --git a/advisories/unreviewed/2024/04/GHSA-pjv5-66g3-7gqx/GHSA-pjv5-66g3-7gqx.json b/advisories/unreviewed/2024/04/GHSA-pjv5-66g3-7gqx/GHSA-pjv5-66g3-7gqx.json index c49ea174c87..28f2b97d13c 100644 --- a/advisories/unreviewed/2024/04/GHSA-pjv5-66g3-7gqx/GHSA-pjv5-66g3-7gqx.json +++ b/advisories/unreviewed/2024/04/GHSA-pjv5-66g3-7gqx/GHSA-pjv5-66g3-7gqx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pjv5-66g3-7gqx", - "modified": "2024-04-12T15:37:21Z", + "modified": "2024-07-05T15:32:05Z", "published": "2024-04-12T15:37:21Z", "aliases": [ "CVE-2024-3705" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3705" }, + { + "type": "WEB", + "url": "https://opengnsys.es/web/parche-de-seguridad-cve-2024-370x" + }, { "type": "WEB", "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-opengnsys" diff --git a/advisories/unreviewed/2024/04/GHSA-rpjc-8hv7-4jhp/GHSA-rpjc-8hv7-4jhp.json b/advisories/unreviewed/2024/04/GHSA-rpjc-8hv7-4jhp/GHSA-rpjc-8hv7-4jhp.json index 25a6ad45d7d..074b8ae92d8 100644 --- a/advisories/unreviewed/2024/04/GHSA-rpjc-8hv7-4jhp/GHSA-rpjc-8hv7-4jhp.json +++ b/advisories/unreviewed/2024/04/GHSA-rpjc-8hv7-4jhp/GHSA-rpjc-8hv7-4jhp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rpjc-8hv7-4jhp", - "modified": "2024-04-12T15:37:21Z", + "modified": "2024-07-05T15:32:05Z", "published": "2024-04-12T15:37:21Z", "aliases": [ "CVE-2024-3704" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3704" }, + { + "type": "WEB", + "url": "https://opengnsys.es/web/parche-de-seguridad-cve-2024-370x" + }, { "type": "WEB", "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-opengnsys" diff --git a/advisories/unreviewed/2024/06/GHSA-3qj5-4m44-45xw/GHSA-3qj5-4m44-45xw.json b/advisories/unreviewed/2024/06/GHSA-3qj5-4m44-45xw/GHSA-3qj5-4m44-45xw.json index 9095acddcf5..403b37ff902 100644 --- a/advisories/unreviewed/2024/06/GHSA-3qj5-4m44-45xw/GHSA-3qj5-4m44-45xw.json +++ b/advisories/unreviewed/2024/06/GHSA-3qj5-4m44-45xw/GHSA-3qj5-4m44-45xw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3qj5-4m44-45xw", - "modified": "2024-06-18T06:30:40Z", + "modified": "2024-07-05T15:32:05Z", "published": "2024-06-18T06:30:40Z", "aliases": [ "CVE-2024-5860" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-5h34-8wx8-3j39/GHSA-5h34-8wx8-3j39.json b/advisories/unreviewed/2024/06/GHSA-5h34-8wx8-3j39/GHSA-5h34-8wx8-3j39.json index 5b660263f3d..0f78e8db7e9 100644 --- a/advisories/unreviewed/2024/06/GHSA-5h34-8wx8-3j39/GHSA-5h34-8wx8-3j39.json +++ b/advisories/unreviewed/2024/06/GHSA-5h34-8wx8-3j39/GHSA-5h34-8wx8-3j39.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5h34-8wx8-3j39", - "modified": "2024-06-18T03:34:27Z", + "modified": "2024-07-05T15:32:05Z", "published": "2024-06-18T03:34:27Z", "aliases": [ "CVE-2024-1634" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-953j-hfcf-57cx/GHSA-953j-hfcf-57cx.json b/advisories/unreviewed/2024/06/GHSA-953j-hfcf-57cx/GHSA-953j-hfcf-57cx.json index deb3903ba2f..1401f63f6ad 100644 --- a/advisories/unreviewed/2024/06/GHSA-953j-hfcf-57cx/GHSA-953j-hfcf-57cx.json +++ b/advisories/unreviewed/2024/06/GHSA-953j-hfcf-57cx/GHSA-953j-hfcf-57cx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-953j-hfcf-57cx", - "modified": "2024-06-18T03:34:27Z", + "modified": "2024-07-05T15:32:05Z", "published": "2024-06-18T03:34:27Z", "aliases": [ "CVE-2024-4375" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-c89w-5mx2-xmrq/GHSA-c89w-5mx2-xmrq.json b/advisories/unreviewed/2024/06/GHSA-c89w-5mx2-xmrq/GHSA-c89w-5mx2-xmrq.json index 33167273a80..640a86c495e 100644 --- a/advisories/unreviewed/2024/06/GHSA-c89w-5mx2-xmrq/GHSA-c89w-5mx2-xmrq.json +++ b/advisories/unreviewed/2024/06/GHSA-c89w-5mx2-xmrq/GHSA-c89w-5mx2-xmrq.json @@ -40,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1236" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-p4vw-qxhv-9g7j/GHSA-p4vw-qxhv-9g7j.json b/advisories/unreviewed/2024/06/GHSA-p4vw-qxhv-9g7j/GHSA-p4vw-qxhv-9g7j.json index 57094ff8d5b..e2b89025f2b 100644 --- a/advisories/unreviewed/2024/06/GHSA-p4vw-qxhv-9g7j/GHSA-p4vw-qxhv-9g7j.json +++ b/advisories/unreviewed/2024/06/GHSA-p4vw-qxhv-9g7j/GHSA-p4vw-qxhv-9g7j.json @@ -44,7 +44,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-qrw5-2xvc-ff3x/GHSA-qrw5-2xvc-ff3x.json b/advisories/unreviewed/2024/06/GHSA-qrw5-2xvc-ff3x/GHSA-qrw5-2xvc-ff3x.json index 7acefdc5565..24c1dcc2736 100644 --- a/advisories/unreviewed/2024/06/GHSA-qrw5-2xvc-ff3x/GHSA-qrw5-2xvc-ff3x.json +++ b/advisories/unreviewed/2024/06/GHSA-qrw5-2xvc-ff3x/GHSA-qrw5-2xvc-ff3x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qrw5-2xvc-ff3x", - "modified": "2024-06-18T06:30:44Z", + "modified": "2024-07-05T15:32:05Z", "published": "2024-06-18T06:30:44Z", "aliases": [ "CVE-2024-4094" ], "details": "The Simple Share Buttons Adder WordPress plugin before 8.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-18T06:15:12Z" diff --git a/advisories/unreviewed/2024/06/GHSA-v437-gvmx-8wm3/GHSA-v437-gvmx-8wm3.json b/advisories/unreviewed/2024/06/GHSA-v437-gvmx-8wm3/GHSA-v437-gvmx-8wm3.json index ccc9ac11332..067057331cc 100644 --- a/advisories/unreviewed/2024/06/GHSA-v437-gvmx-8wm3/GHSA-v437-gvmx-8wm3.json +++ b/advisories/unreviewed/2024/06/GHSA-v437-gvmx-8wm3/GHSA-v437-gvmx-8wm3.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-w3hx-hrcp-gr58/GHSA-w3hx-hrcp-gr58.json b/advisories/unreviewed/2024/06/GHSA-w3hx-hrcp-gr58/GHSA-w3hx-hrcp-gr58.json index c7eb9b19c61..2964fbece6a 100644 --- a/advisories/unreviewed/2024/06/GHSA-w3hx-hrcp-gr58/GHSA-w3hx-hrcp-gr58.json +++ b/advisories/unreviewed/2024/06/GHSA-w3hx-hrcp-gr58/GHSA-w3hx-hrcp-gr58.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w3hx-hrcp-gr58", - "modified": "2024-06-18T06:30:44Z", + "modified": "2024-07-05T15:32:05Z", "published": "2024-06-18T06:30:44Z", "aliases": [ "CVE-2024-3276" ], "details": "The Lightbox & Modal Popup WordPress Plugin WordPress plugin before 2.7.28, foobox-image-lightbox-premium WordPress plugin before 2.7.28 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-18T06:15:12Z" diff --git a/advisories/unreviewed/2024/07/GHSA-2frf-jr2g-pjp7/GHSA-2frf-jr2g-pjp7.json b/advisories/unreviewed/2024/07/GHSA-2frf-jr2g-pjp7/GHSA-2frf-jr2g-pjp7.json index 65ee481f329..c34b07ae0bd 100644 --- a/advisories/unreviewed/2024/07/GHSA-2frf-jr2g-pjp7/GHSA-2frf-jr2g-pjp7.json +++ b/advisories/unreviewed/2024/07/GHSA-2frf-jr2g-pjp7/GHSA-2frf-jr2g-pjp7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2frf-jr2g-pjp7", - "modified": "2024-07-02T03:31:34Z", + "modified": "2024-07-05T15:32:05Z", "published": "2024-07-02T03:31:34Z", "aliases": [ "CVE-2024-5938" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-2x8c-95vh-gfv4/GHSA-2x8c-95vh-gfv4.json b/advisories/unreviewed/2024/07/GHSA-2x8c-95vh-gfv4/GHSA-2x8c-95vh-gfv4.json index 6d3f505a07c..1672775bfb6 100644 --- a/advisories/unreviewed/2024/07/GHSA-2x8c-95vh-gfv4/GHSA-2x8c-95vh-gfv4.json +++ b/advisories/unreviewed/2024/07/GHSA-2x8c-95vh-gfv4/GHSA-2x8c-95vh-gfv4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2x8c-95vh-gfv4", - "modified": "2024-07-04T12:34:39Z", + "modified": "2024-07-05T15:32:06Z", "published": "2024-07-01T15:32:33Z", "aliases": [ "CVE-2024-6387" @@ -37,29 +37,13 @@ "type": "WEB", "url": "https://github.com/PowerShell/Win32-OpenSSH/issues/2249" }, - { - "type": "WEB", - "url": "https://github.com/AlmaLinux/updates/issues/629" - }, { "type": "WEB", "url": "https://github.com/Azure/AKS/issues/4379" }, { "type": "WEB", - "url": "https://news.ycombinator.com/item?id=40843778" - }, - { - "type": "WEB", - "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0010" - }, - { - "type": "WEB", - "url": "https://security-tracker.debian.org/tracker/CVE-2024-6387" - }, - { - "type": "WEB", - "url": "https://security.netapp.com/advisory/ntap-20240701-0001" + "url": "https://github.com/AlmaLinux/updates/issues/629" }, { "type": "WEB", @@ -73,6 +57,10 @@ "type": "WEB", "url": "https://ubuntu.com/security/notices/USN-6859-1" }, + { + "type": "WEB", + "url": "https://sig-security.rocky.page/issues/CVE-2024-6387" + }, { "type": "WEB", "url": "https://www.freebsd.org/security/advisories/FreeBSD-SA-24:04.openssh.asc" @@ -89,10 +77,26 @@ "type": "WEB", "url": "https://www.suse.com/security/cve/CVE-2024-6387.html" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240701-0001" + }, + { + "type": "WEB", + "url": "https://security-tracker.debian.org/tracker/CVE-2024-6387" + }, + { + "type": "WEB", + "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0010" + }, { "type": "WEB", "url": "https://www.theregister.com/2024/07/01/regresshion_openssh" }, + { + "type": "WEB", + "url": "https://news.ycombinator.com/item?id=40843778" + }, { "type": "WEB", "url": "https://lists.mindrot.org/pipermail/openssh-unix-dev/2024-July/041431.html" @@ -188,6 +192,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-362", "CWE-364" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/07/GHSA-3qx7-ff8p-6j2r/GHSA-3qx7-ff8p-6j2r.json b/advisories/unreviewed/2024/07/GHSA-3qx7-ff8p-6j2r/GHSA-3qx7-ff8p-6j2r.json new file mode 100644 index 00000000000..0cdadb5943f --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-3qx7-ff8p-6j2r/GHSA-3qx7-ff8p-6j2r.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3qx7-ff8p-6j2r", + "modified": "2024-07-05T15:32:06Z", + "published": "2024-07-05T15:32:06Z", + "aliases": [ + "CVE-2024-6505" + ], + "details": "A flaw was found in the virtio-net device in QEMU. When enabling the RSS feature on the virtio-net network card, the indirections_table data within RSS becomes controllable. Setting excessively large values may cause an index out-of-bounds issue, potentially resulting in heap overflow access. This flaw allows a privileged user in the guest to crash the QEMU process on the host.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6505" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-6505" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2295760" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-05T14:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-4m48-vrcx-46f2/GHSA-4m48-vrcx-46f2.json b/advisories/unreviewed/2024/07/GHSA-4m48-vrcx-46f2/GHSA-4m48-vrcx-46f2.json new file mode 100644 index 00000000000..f744b7ec944 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-4m48-vrcx-46f2/GHSA-4m48-vrcx-46f2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4m48-vrcx-46f2", + "modified": "2024-07-05T15:32:06Z", + "published": "2024-07-05T15:32:06Z", + "aliases": [ + "CVE-2024-39028" + ], + "details": "An issue was discovered in SeaCMS <=12.9 which allows remote attackers to execute arbitrary code via admin_ping.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39028" + }, + { + "type": "WEB", + "url": "https://github.com/pysnow1/vul_discovery/blob/main/SeaCMS/SeaCMS%20v12.9%20admin_ping.php%20RCE.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-05T14:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-5fc5-2cqx-72pm/GHSA-5fc5-2cqx-72pm.json b/advisories/unreviewed/2024/07/GHSA-5fc5-2cqx-72pm/GHSA-5fc5-2cqx-72pm.json new file mode 100644 index 00000000000..fa1e92d45e4 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-5fc5-2cqx-72pm/GHSA-5fc5-2cqx-72pm.json @@ -0,0 +1,62 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5fc5-2cqx-72pm", + "modified": "2024-07-05T15:32:06Z", + "published": "2024-07-05T15:32:06Z", + "aliases": [ + "CVE-2024-6526" + ], + "details": "A vulnerability classified as problematic has been found in CodeIgniter Ecommerce-CodeIgniter-Bootstrap up to 1998845073cf433bc6c250b0354461fbd84d0e03. This affects an unknown part. The manipulation of the argument search_title/catName/sub/name/categorie leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of the patch is 1b3da45308bb6c3f55247d0e99620b600bd85277. It is recommended to apply a patch to fix this issue. The identifier VDB-270369 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6526" + }, + { + "type": "WEB", + "url": "https://github.com/kirilkirkov/Ecommerce-CodeIgniter-Bootstrap/issues/263" + }, + { + "type": "WEB", + "url": "https://github.com/kirilkirkov/Ecommerce-CodeIgniter-Bootstrap/issues/263#issuecomment-2199387443" + }, + { + "type": "WEB", + "url": "https://github.com/kirilkirkov/Ecommerce-CodeIgniter-Bootstrap/commit/1b3da45308bb6c3f55247d0e99620b600bd85277" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.270369" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.270369" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.368472" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-05T14:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-7g4v-8cvx-gp5q/GHSA-7g4v-8cvx-gp5q.json b/advisories/unreviewed/2024/07/GHSA-7g4v-8cvx-gp5q/GHSA-7g4v-8cvx-gp5q.json new file mode 100644 index 00000000000..26530dfb526 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-7g4v-8cvx-gp5q/GHSA-7g4v-8cvx-gp5q.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7g4v-8cvx-gp5q", + "modified": "2024-07-05T15:32:06Z", + "published": "2024-07-05T15:32:06Z", + "aliases": [ + "CVE-2024-38346" + ], + "details": "The CloudStack cluster service runs on unauthenticated port (default 9090) that can be misused to run arbitrary commands on targeted hypervisors and CloudStack management server hosts. Some of these commands were found to have command injection vulnerabilities that can result in arbitrary code execution via agents on the hosts that may run as a privileged user. An attacker that can reach the cluster service on the unauthenticated port (default 9090), can exploit this to perform remote code execution on CloudStack managed hosts and result in complete compromise of the confidentiality, integrity, and availability of CloudStack managed infrastructure.\n\nUsers are recommended to restrict the network access to the cluster service port (default 9090) on a CloudStack management server host to only its peer CloudStack management server hosts. Users are recommended to upgrade to version 4.18.2.1, 4.19.0.2 or later, which addresses this issue.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38346" + }, + { + "type": "WEB", + "url": "https://cloudstack.apache.org/blog/security-release-advisory-4.19.0.2-4.18.2.1" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/6l51r00csrct61plkyd3qg3fj99215d1" + }, + { + "type": "WEB", + "url": "https://www.shapeblue.com/shapeblue-security-advisory-apache-cloudstack-security-releases-4-18-2-1-and-4-19-0-2" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/07/05/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-05T14:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-f4qq-f5qf-jfp5/GHSA-f4qq-f5qf-jfp5.json b/advisories/unreviewed/2024/07/GHSA-f4qq-f5qf-jfp5/GHSA-f4qq-f5qf-jfp5.json index e509e155047..a22b2de01fe 100644 --- a/advisories/unreviewed/2024/07/GHSA-f4qq-f5qf-jfp5/GHSA-f4qq-f5qf-jfp5.json +++ b/advisories/unreviewed/2024/07/GHSA-f4qq-f5qf-jfp5/GHSA-f4qq-f5qf-jfp5.json @@ -40,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-fmv9-mfm7-498m/GHSA-fmv9-mfm7-498m.json b/advisories/unreviewed/2024/07/GHSA-fmv9-mfm7-498m/GHSA-fmv9-mfm7-498m.json new file mode 100644 index 00000000000..25e81f49342 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-fmv9-mfm7-498m/GHSA-fmv9-mfm7-498m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fmv9-mfm7-498m", + "modified": "2024-07-05T15:32:05Z", + "published": "2024-07-05T15:32:05Z", + "aliases": [ + "CVE-2024-23588" + ], + "details": "HCL Nomad server on Domino fails to properly handle users configured with limited Domino access resulting in a possible denial of service vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23588" + }, + { + "type": "WEB", + "url": "https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0114193" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-05T14:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-qcg7-r5qq-mqmw/GHSA-qcg7-r5qq-mqmw.json b/advisories/unreviewed/2024/07/GHSA-qcg7-r5qq-mqmw/GHSA-qcg7-r5qq-mqmw.json new file mode 100644 index 00000000000..ba2c7433dfc --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-qcg7-r5qq-mqmw/GHSA-qcg7-r5qq-mqmw.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qcg7-r5qq-mqmw", + "modified": "2024-07-05T15:32:06Z", + "published": "2024-07-05T15:32:06Z", + "aliases": [ + "CVE-2024-39864" + ], + "details": "The CloudStack integration API service allows running its unauthenticated API server (usually on port 8096 when configured and enabled via integration.api.port global setting) for internal portal integrations and for testing purposes. By default, the integration API service port is disabled and is considered disabled when integration.api.port is set to 0 or negative. Due to an improper initialisation logic, the integration API service would listen on a random port when its port value is set to 0 (default value). An attacker that can access the CloudStack management network could scan and find the randomised integration API service port and exploit it to perform unauthorised administrative actions and perform remote code execution on CloudStack managed hosts and result in complete compromise of the confidentiality, integrity, and availability of CloudStack managed infrastructure.\n\nUsers are recommended to restrict the network access on the CloudStack management server hosts to only essential ports. Users are recommended to upgrade to version 4.18.2.1, 4.19.0.2 or later, which addresses this issue.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39864" + }, + { + "type": "WEB", + "url": "https://cloudstack.apache.org/blog/security-release-advisory-4.19.0.2-4.18.2.1" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/6l51r00csrct61plkyd3qg3fj99215d1" + }, + { + "type": "WEB", + "url": "https://www.shapeblue.com/shapeblue-security-advisory-apache-cloudstack-security-releases-4-18-2-1-and-4-19-0-2" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/07/05/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-665" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-05T14:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-v6cv-pjf9-9v55/GHSA-v6cv-pjf9-9v55.json b/advisories/unreviewed/2024/07/GHSA-v6cv-pjf9-9v55/GHSA-v6cv-pjf9-9v55.json new file mode 100644 index 00000000000..bb668e2ac5d --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-v6cv-pjf9-9v55/GHSA-v6cv-pjf9-9v55.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v6cv-pjf9-9v55", + "modified": "2024-07-05T15:32:06Z", + "published": "2024-07-05T15:32:05Z", + "aliases": [ + "CVE-2024-6525" + ], + "details": "** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 up to 20230922. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /log/decodmail.php. The manipulation of the argument file leads to deserialization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-270368. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6525" + }, + { + "type": "WEB", + "url": "https://github.com/flyyue2001/cve/blob/main/D-LINK%20-DAR-7000_rce_%20decodmail.md" + }, + { + "type": "WEB", + "url": "https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10354" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.270368" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.270368" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.368099" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-05T13:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-v7mv-85hf-9fxh/GHSA-v7mv-85hf-9fxh.json b/advisories/unreviewed/2024/07/GHSA-v7mv-85hf-9fxh/GHSA-v7mv-85hf-9fxh.json index abf1546a8c4..b9cbd1a1868 100644 --- a/advisories/unreviewed/2024/07/GHSA-v7mv-85hf-9fxh/GHSA-v7mv-85hf-9fxh.json +++ b/advisories/unreviewed/2024/07/GHSA-v7mv-85hf-9fxh/GHSA-v7mv-85hf-9fxh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v7mv-85hf-9fxh", - "modified": "2024-07-02T09:32:06Z", + "modified": "2024-07-05T15:32:05Z", "published": "2024-07-02T09:32:06Z", "aliases": [ "CVE-2024-3513" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-vqv4-c7v8-752q/GHSA-vqv4-c7v8-752q.json b/advisories/unreviewed/2024/07/GHSA-vqv4-c7v8-752q/GHSA-vqv4-c7v8-752q.json new file mode 100644 index 00000000000..f6f0b016a9e --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-vqv4-c7v8-752q/GHSA-vqv4-c7v8-752q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vqv4-c7v8-752q", + "modified": "2024-07-05T15:32:06Z", + "published": "2024-07-05T15:32:06Z", + "aliases": [ + "CVE-2024-39027" + ], + "details": "SeaCMS v12.9 has an unauthorized SQL injection vulnerability. The vulnerability is caused by the SQL injection through the cid parameter at /js/player/dmplayer/dmku/index.php?ac=edit, which can cause sensitive database information to be leaked.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39027" + }, + { + "type": "WEB", + "url": "https://github.com/seacms-net/CMS/issues/17" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-05T14:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-w5g9-fxf7-88qg/GHSA-w5g9-fxf7-88qg.json b/advisories/unreviewed/2024/07/GHSA-w5g9-fxf7-88qg/GHSA-w5g9-fxf7-88qg.json index 3cdd24de9e7..44ea78f34f1 100644 --- a/advisories/unreviewed/2024/07/GHSA-w5g9-fxf7-88qg/GHSA-w5g9-fxf7-88qg.json +++ b/advisories/unreviewed/2024/07/GHSA-w5g9-fxf7-88qg/GHSA-w5g9-fxf7-88qg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w5g9-fxf7-88qg", - "modified": "2024-07-02T09:32:06Z", + "modified": "2024-07-05T15:32:05Z", "published": "2024-07-02T09:32:06Z", "aliases": [ "CVE-2024-5545" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-wrhh-8xjv-p64h/GHSA-wrhh-8xjv-p64h.json b/advisories/unreviewed/2024/07/GHSA-wrhh-8xjv-p64h/GHSA-wrhh-8xjv-p64h.json index debf7a6f96c..bc260451f9f 100644 --- a/advisories/unreviewed/2024/07/GHSA-wrhh-8xjv-p64h/GHSA-wrhh-8xjv-p64h.json +++ b/advisories/unreviewed/2024/07/GHSA-wrhh-8xjv-p64h/GHSA-wrhh-8xjv-p64h.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false,