Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-09-05 15:34:58 +00:00
parent e0dc5ea014
commit 0baa404ce9
61 changed files with 861 additions and 84 deletions
@@ -28,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-122",
"CWE-787"
],
"severity": "CRITICAL",
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-778"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-276"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qhmg-pv98-3cg7",
"modified": "2023-11-06T15:30:32Z",
"modified": "2024-09-05T15:33:30Z",
"published": "2023-11-06T15:30:32Z",
"aliases": [
"CVE-2023-45163"
@@ -28,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-121",
"CWE-787"
],
"severity": "CRITICAL",
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x5qc-9crp-x6hr",
"modified": "2023-11-06T15:30:32Z",
"modified": "2024-09-05T15:33:30Z",
"published": "2023-11-06T15:30:32Z",
"aliases": [
"CVE-2023-45161"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2qrq-mpmg-w3v6",
"modified": "2024-02-08T21:30:38Z",
"modified": "2024-09-05T15:33:32Z",
"published": "2024-02-08T21:30:38Z",
"aliases": [
"CVE-2024-24494"
],
"details": "Cross Site Scripting vulnerability in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via the day, exercise, pray, read_book, vitamins, laundry, alcohol and meat parameters in the add-tracker.php and update-tracker.php components.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-08T21:15:08Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3f8r-x482-8qpg",
"modified": "2024-02-10T00:31:59Z",
"modified": "2024-09-05T15:33:32Z",
"published": "2024-02-10T00:31:59Z",
"aliases": [
"CVE-2023-45718"
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-384"
],
"severity": "LOW",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-68p8-j476-8w35",
"modified": "2024-02-11T06:30:27Z",
"modified": "2024-09-05T15:33:33Z",
"published": "2024-02-11T06:30:27Z",
"aliases": [
"CVE-2024-25722"
],
"details": "qanything_kernel/connector/database/mysql/mysql_client.py in qanything.ai QAnything before 1.2.0 allows SQL Injection.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-11T05:15:08Z"
@@ -56,7 +56,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-121"
"CWE-121",
"CWE-787"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r2g2-g732-97cw",
"modified": "2024-02-08T09:30:41Z",
"modified": "2024-09-05T15:33:32Z",
"published": "2024-02-08T09:30:41Z",
"aliases": [
"CVE-2024-24034"
],
"details": "Setor Informatica S.I.L version 3.0 is vulnerable to Open Redirect via the hprinter parameter, allows remote attackers to execute arbitrary code.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-601"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-08T09:15:46Z"
@@ -28,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-78",
"CWE-94"
],
"severity": "CRITICAL",
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vpg2-32g8-56wf",
"modified": "2024-02-12T00:30:22Z",
"modified": "2024-09-05T15:33:33Z",
"published": "2024-02-12T00:30:22Z",
"aliases": [
"CVE-2024-25728"
],
"details": "ExpressVPN before 12.73.0 on Windows, when split tunneling is used, sends DNS requests according to the Windows configuration (e.g., sends them to DNS servers operated by the user's ISP instead of to the ExpressVPN DNS servers), which may allow remote attackers to obtain sensitive information about websites visited by VPN users.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-11T22:15:08Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xf6f-94pc-55vc",
"modified": "2024-02-08T06:30:24Z",
"modified": "2024-09-05T15:33:32Z",
"published": "2024-02-08T06:30:24Z",
"aliases": [
"CVE-2024-24216"
],
"details": "Zentao v18.0 to v18.10 was discovered to contain a remote code execution (RCE) vulnerability via the checkConnection method of /app/zentao/module/repo/model.php.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-77"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-08T06:15:51Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w8pg-hrp7-6jch",
"modified": "2024-08-05T15:30:51Z",
"modified": "2024-09-05T15:33:33Z",
"published": "2024-08-05T06:30:37Z",
"aliases": [
"CVE-2024-6498"
],
"details": "The Chatbot for WordPress by Collect.chat ⚡️ WordPress plugin before 2.4.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-05T06:16:41Z"
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-435p-f446-gxf4",
"modified": "2024-09-04T21:30:32Z",
"modified": "2024-09-05T15:33:35Z",
"published": "2024-09-04T21:30:32Z",
"aliases": [
"CVE-2024-44995"
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-459r-6xm8-3p72",
"modified": "2024-09-05T15:33:37Z",
"published": "2024-09-05T15:33:37Z",
"aliases": [
"CVE-2024-44587"
],
"details": "itsourcecode Alton Management System 1.0 is vulnerable to SQL Injection in /noncombo_save.php via the \"menu\" parameter.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44587"
},
{
"type": "WEB",
"url": "https://github.com/Lejeremiah/excavation/blob/main/cms-sql1.md"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-05T14:15:10Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5hv9-vfr9-4mh3",
"modified": "2024-09-05T06:31:34Z",
"modified": "2024-09-05T15:33:35Z",
"published": "2024-09-05T06:31:34Z",
"aliases": [
"CVE-2024-45288"
],
"details": "A missing null-termination character in the last element of an nvlist array string can lead to writing outside the allocated buffer.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
"CWE-170"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-05T04:15:07Z"

Some files were not shown because too many files have changed in this diff Show More