diff --git a/advisories/unreviewed/2024/06/GHSA-5cfq-mh36-cvhr/GHSA-5cfq-mh36-cvhr.json b/advisories/unreviewed/2024/06/GHSA-5cfq-mh36-cvhr/GHSA-5cfq-mh36-cvhr.json index f95eb42c9b5..5a04d35e295 100644 --- a/advisories/unreviewed/2024/06/GHSA-5cfq-mh36-cvhr/GHSA-5cfq-mh36-cvhr.json +++ b/advisories/unreviewed/2024/06/GHSA-5cfq-mh36-cvhr/GHSA-5cfq-mh36-cvhr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5cfq-mh36-cvhr", - "modified": "2024-06-05T06:30:40Z", + "modified": "2024-06-06T15:30:36Z", "published": "2024-06-05T06:30:40Z", "aliases": [ "CVE-2024-2087" @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-8w2q-mh8v-whx2/GHSA-8w2q-mh8v-whx2.json b/advisories/unreviewed/2024/06/GHSA-8w2q-mh8v-whx2/GHSA-8w2q-mh8v-whx2.json index cdcfef5040c..5b81ed3894a 100644 --- a/advisories/unreviewed/2024/06/GHSA-8w2q-mh8v-whx2/GHSA-8w2q-mh8v-whx2.json +++ b/advisories/unreviewed/2024/06/GHSA-8w2q-mh8v-whx2/GHSA-8w2q-mh8v-whx2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8w2q-mh8v-whx2", - "modified": "2024-06-04T15:30:59Z", + "modified": "2024-06-06T15:30:36Z", "published": "2024-06-04T15:30:59Z", "aliases": [ "CVE-2024-36547" ], "details": "idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/vpsClass_deal.php?mudi=add", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-04T15:15:47Z" diff --git a/advisories/unreviewed/2024/06/GHSA-9qpj-gvc6-34rv/GHSA-9qpj-gvc6-34rv.json b/advisories/unreviewed/2024/06/GHSA-9qpj-gvc6-34rv/GHSA-9qpj-gvc6-34rv.json index 5965fe205fd..1d3a2dd0285 100644 --- a/advisories/unreviewed/2024/06/GHSA-9qpj-gvc6-34rv/GHSA-9qpj-gvc6-34rv.json +++ b/advisories/unreviewed/2024/06/GHSA-9qpj-gvc6-34rv/GHSA-9qpj-gvc6-34rv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9qpj-gvc6-34rv", - "modified": "2024-06-04T15:30:59Z", + "modified": "2024-06-06T15:30:36Z", "published": "2024-06-04T15:30:59Z", "aliases": [ "CVE-2024-36548" ], "details": "idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/vpsCompany_deal.php?mudi=del", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-04T15:15:47Z" diff --git a/advisories/unreviewed/2024/06/GHSA-crg8-w24w-qvmq/GHSA-crg8-w24w-qvmq.json b/advisories/unreviewed/2024/06/GHSA-crg8-w24w-qvmq/GHSA-crg8-w24w-qvmq.json new file mode 100644 index 00000000000..a6fdf8845d0 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-crg8-w24w-qvmq/GHSA-crg8-w24w-qvmq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-crg8-w24w-qvmq", + "modified": "2024-06-06T15:30:36Z", + "published": "2024-06-06T15:30:36Z", + "aliases": [ + "CVE-2024-36779" + ], + "details": "Sourcecodester Stock Management System v1.0 is vulnerable to SQL Injection via editCategories.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36779" + }, + { + "type": "WEB", + "url": "https://github.com/CveSecLook/cve/issues/42" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-06T13:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-f2cq-m485-xq43/GHSA-f2cq-m485-xq43.json b/advisories/unreviewed/2024/06/GHSA-f2cq-m485-xq43/GHSA-f2cq-m485-xq43.json new file mode 100644 index 00000000000..5c014a6ce08 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-f2cq-m485-xq43/GHSA-f2cq-m485-xq43.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f2cq-m485-xq43", + "modified": "2024-06-06T15:30:36Z", + "published": "2024-06-06T15:30:36Z", + "aliases": [ + "CVE-2024-5684" + ], + "details": "An attacker with access to the private network (the charger is connected to) or local access to the Ethernet-Interface can exploit a faulty implementation of the JWT-library in order to bypass the password authentication to the web configuration interface and then has full access as the user would have. However, an attacker will not have developer or admin rights. If the implementation of the JWT-library is wrongly configured to accept \"none\"-algorithms, the server will pass insecure JWT. A local, unauthenticated attacker can exploit this vulnerability to bypass the authentication mechanism.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5684" + }, + { + "type": "WEB", + "url": "https://asrg.io/security-advisories/vulnerability-in-id-charger-connect-and-pro-from-volkswagen-group-charging-gmbh-elli-evbox-versions-spr3-2b-spr3-51-and-spr3-52" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-345" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-06T13:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-gh33-mw8r-hv99/GHSA-gh33-mw8r-hv99.json b/advisories/unreviewed/2024/06/GHSA-gh33-mw8r-hv99/GHSA-gh33-mw8r-hv99.json index 7f7c354abea..729d57230ad 100644 --- a/advisories/unreviewed/2024/06/GHSA-gh33-mw8r-hv99/GHSA-gh33-mw8r-hv99.json +++ b/advisories/unreviewed/2024/06/GHSA-gh33-mw8r-hv99/GHSA-gh33-mw8r-hv99.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gh33-mw8r-hv99", - "modified": "2024-06-05T06:30:39Z", + "modified": "2024-06-06T15:30:36Z", "published": "2024-06-05T06:30:39Z", "aliases": [ "CVE-2024-1940" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-jfv8-vg3m-73pc/GHSA-jfv8-vg3m-73pc.json b/advisories/unreviewed/2024/06/GHSA-jfv8-vg3m-73pc/GHSA-jfv8-vg3m-73pc.json new file mode 100644 index 00000000000..1ccf27bc06d --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-jfv8-vg3m-73pc/GHSA-jfv8-vg3m-73pc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jfv8-vg3m-73pc", + "modified": "2024-06-06T15:30:36Z", + "published": "2024-06-06T15:30:36Z", + "aliases": [ + "CVE-2024-34832" + ], + "details": "Directory Traversal vulnerability in CubeCart v.6.5.5 and before allows an attacker to execute arbitrary code via a crafted file uploaded to the _g and node parameters.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34832" + }, + { + "type": "WEB", + "url": "https://github.com/julio-cfa/CVE-2024-34832" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-06T15:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-mq9m-c33f-xf29/GHSA-mq9m-c33f-xf29.json b/advisories/unreviewed/2024/06/GHSA-mq9m-c33f-xf29/GHSA-mq9m-c33f-xf29.json index 004adc0f75b..4ee5d3af7e7 100644 --- a/advisories/unreviewed/2024/06/GHSA-mq9m-c33f-xf29/GHSA-mq9m-c33f-xf29.json +++ b/advisories/unreviewed/2024/06/GHSA-mq9m-c33f-xf29/GHSA-mq9m-c33f-xf29.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mq9m-c33f-xf29", - "modified": "2024-06-04T15:30:59Z", + "modified": "2024-06-06T15:30:36Z", "published": "2024-06-04T15:30:59Z", "aliases": [ "CVE-2024-36550" ], "details": "idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/vpsCompany_deal.php?mudi=add&nohrefStr=close", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-04T15:15:47Z" diff --git a/advisories/unreviewed/2024/06/GHSA-mxc5-jmfp-8w6f/GHSA-mxc5-jmfp-8w6f.json b/advisories/unreviewed/2024/06/GHSA-mxc5-jmfp-8w6f/GHSA-mxc5-jmfp-8w6f.json index a82bd2add77..06601602ce6 100644 --- a/advisories/unreviewed/2024/06/GHSA-mxc5-jmfp-8w6f/GHSA-mxc5-jmfp-8w6f.json +++ b/advisories/unreviewed/2024/06/GHSA-mxc5-jmfp-8w6f/GHSA-mxc5-jmfp-8w6f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mxc5-jmfp-8w6f", - "modified": "2024-06-05T06:30:40Z", + "modified": "2024-06-06T15:30:36Z", "published": "2024-06-05T06:30:40Z", "aliases": [ "CVE-2024-3667" @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-w835-4fh5-99v9/GHSA-w835-4fh5-99v9.json b/advisories/unreviewed/2024/06/GHSA-w835-4fh5-99v9/GHSA-w835-4fh5-99v9.json index 0a77aececec..f54dad4a2b9 100644 --- a/advisories/unreviewed/2024/06/GHSA-w835-4fh5-99v9/GHSA-w835-4fh5-99v9.json +++ b/advisories/unreviewed/2024/06/GHSA-w835-4fh5-99v9/GHSA-w835-4fh5-99v9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w835-4fh5-99v9", - "modified": "2024-06-04T15:30:59Z", + "modified": "2024-06-06T15:30:36Z", "published": "2024-06-04T15:30:59Z", "aliases": [ "CVE-2024-36549" ], "details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/vpsCompany_deal.php?mudi=rev&nohrefStr=close", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-04T15:15:47Z" diff --git a/advisories/unreviewed/2024/06/GHSA-w966-799g-fp7v/GHSA-w966-799g-fp7v.json b/advisories/unreviewed/2024/06/GHSA-w966-799g-fp7v/GHSA-w966-799g-fp7v.json new file mode 100644 index 00000000000..7ccf513df5d --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-w966-799g-fp7v/GHSA-w966-799g-fp7v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w966-799g-fp7v", + "modified": "2024-06-06T15:30:36Z", + "published": "2024-06-06T15:30:36Z", + "aliases": [ + "CVE-2024-5675" + ], + "details": "Untrusted data deserialization vulnerability has been found in Mentor - Employee Portal, affecting version 3.83.35. This vulnerability could allow an attacker to execute arbitrary code, by injecting a malicious payload into the “ViewState” field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5675" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/unreliable-data-deserialization-vulnerability-mentor" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-06T13:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-xfjh-8mwq-67xv/GHSA-xfjh-8mwq-67xv.json b/advisories/unreviewed/2024/06/GHSA-xfjh-8mwq-67xv/GHSA-xfjh-8mwq-67xv.json index dc8e28df602..68d3fb099ed 100644 --- a/advisories/unreviewed/2024/06/GHSA-xfjh-8mwq-67xv/GHSA-xfjh-8mwq-67xv.json +++ b/advisories/unreviewed/2024/06/GHSA-xfjh-8mwq-67xv/GHSA-xfjh-8mwq-67xv.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-330" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-xj54-8cp7-f54r/GHSA-xj54-8cp7-f54r.json b/advisories/unreviewed/2024/06/GHSA-xj54-8cp7-f54r/GHSA-xj54-8cp7-f54r.json index fbce8e89242..720b9f2c6b2 100644 --- a/advisories/unreviewed/2024/06/GHSA-xj54-8cp7-f54r/GHSA-xj54-8cp7-f54r.json +++ b/advisories/unreviewed/2024/06/GHSA-xj54-8cp7-f54r/GHSA-xj54-8cp7-f54r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xj54-8cp7-f54r", - "modified": "2024-06-05T06:30:39Z", + "modified": "2024-06-06T15:30:36Z", "published": "2024-06-05T06:30:39Z", "aliases": [ "CVE-2024-1161" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false,