diff --git a/advisories/unreviewed/2023/11/GHSA-2wh3-v786-vq3m/GHSA-2wh3-v786-vq3m.json b/advisories/unreviewed/2023/11/GHSA-2wh3-v786-vq3m/GHSA-2wh3-v786-vq3m.json index 177adf2e7fa..d8470bd2a20 100644 --- a/advisories/unreviewed/2023/11/GHSA-2wh3-v786-vq3m/GHSA-2wh3-v786-vq3m.json +++ b/advisories/unreviewed/2023/11/GHSA-2wh3-v786-vq3m/GHSA-2wh3-v786-vq3m.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-122", "CWE-787" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2023/11/GHSA-47fh-x67f-4gjx/GHSA-47fh-x67f-4gjx.json b/advisories/unreviewed/2023/11/GHSA-47fh-x67f-4gjx/GHSA-47fh-x67f-4gjx.json index 57ef691fb05..50cedbd7c56 100644 --- a/advisories/unreviewed/2023/11/GHSA-47fh-x67f-4gjx/GHSA-47fh-x67f-4gjx.json +++ b/advisories/unreviewed/2023/11/GHSA-47fh-x67f-4gjx/GHSA-47fh-x67f-4gjx.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-778" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-g4cc-jjqp-vp8c/GHSA-g4cc-jjqp-vp8c.json b/advisories/unreviewed/2023/11/GHSA-g4cc-jjqp-vp8c/GHSA-g4cc-jjqp-vp8c.json index e8a3c33b01c..63358a14213 100644 --- a/advisories/unreviewed/2023/11/GHSA-g4cc-jjqp-vp8c/GHSA-g4cc-jjqp-vp8c.json +++ b/advisories/unreviewed/2023/11/GHSA-g4cc-jjqp-vp8c/GHSA-g4cc-jjqp-vp8c.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-qhmg-pv98-3cg7/GHSA-qhmg-pv98-3cg7.json b/advisories/unreviewed/2023/11/GHSA-qhmg-pv98-3cg7/GHSA-qhmg-pv98-3cg7.json index ce0876aef32..409671081ae 100644 --- a/advisories/unreviewed/2023/11/GHSA-qhmg-pv98-3cg7/GHSA-qhmg-pv98-3cg7.json +++ b/advisories/unreviewed/2023/11/GHSA-qhmg-pv98-3cg7/GHSA-qhmg-pv98-3cg7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qhmg-pv98-3cg7", - "modified": "2023-11-06T15:30:32Z", + "modified": "2024-09-05T15:33:30Z", "published": "2023-11-06T15:30:32Z", "aliases": [ "CVE-2023-45163" diff --git a/advisories/unreviewed/2023/11/GHSA-v246-p8m5-h759/GHSA-v246-p8m5-h759.json b/advisories/unreviewed/2023/11/GHSA-v246-p8m5-h759/GHSA-v246-p8m5-h759.json index a77921fa546..c363d446448 100644 --- a/advisories/unreviewed/2023/11/GHSA-v246-p8m5-h759/GHSA-v246-p8m5-h759.json +++ b/advisories/unreviewed/2023/11/GHSA-v246-p8m5-h759/GHSA-v246-p8m5-h759.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-121", "CWE-787" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2023/11/GHSA-x5qc-9crp-x6hr/GHSA-x5qc-9crp-x6hr.json b/advisories/unreviewed/2023/11/GHSA-x5qc-9crp-x6hr/GHSA-x5qc-9crp-x6hr.json index 632a6ae35fc..9cad2e041ae 100644 --- a/advisories/unreviewed/2023/11/GHSA-x5qc-9crp-x6hr/GHSA-x5qc-9crp-x6hr.json +++ b/advisories/unreviewed/2023/11/GHSA-x5qc-9crp-x6hr/GHSA-x5qc-9crp-x6hr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x5qc-9crp-x6hr", - "modified": "2023-11-06T15:30:32Z", + "modified": "2024-09-05T15:33:30Z", "published": "2023-11-06T15:30:32Z", "aliases": [ "CVE-2023-45161" diff --git a/advisories/unreviewed/2024/02/GHSA-2qrq-mpmg-w3v6/GHSA-2qrq-mpmg-w3v6.json b/advisories/unreviewed/2024/02/GHSA-2qrq-mpmg-w3v6/GHSA-2qrq-mpmg-w3v6.json index 78967a2753d..42301189cfd 100644 --- a/advisories/unreviewed/2024/02/GHSA-2qrq-mpmg-w3v6/GHSA-2qrq-mpmg-w3v6.json +++ b/advisories/unreviewed/2024/02/GHSA-2qrq-mpmg-w3v6/GHSA-2qrq-mpmg-w3v6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2qrq-mpmg-w3v6", - "modified": "2024-02-08T21:30:38Z", + "modified": "2024-09-05T15:33:32Z", "published": "2024-02-08T21:30:38Z", "aliases": [ "CVE-2024-24494" ], "details": "Cross Site Scripting vulnerability in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via the day, exercise, pray, read_book, vitamins, laundry, alcohol and meat parameters in the add-tracker.php and update-tracker.php components.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-08T21:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-3f8r-x482-8qpg/GHSA-3f8r-x482-8qpg.json b/advisories/unreviewed/2024/02/GHSA-3f8r-x482-8qpg/GHSA-3f8r-x482-8qpg.json index 36e57c19393..fc5da713865 100644 --- a/advisories/unreviewed/2024/02/GHSA-3f8r-x482-8qpg/GHSA-3f8r-x482-8qpg.json +++ b/advisories/unreviewed/2024/02/GHSA-3f8r-x482-8qpg/GHSA-3f8r-x482-8qpg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3f8r-x482-8qpg", - "modified": "2024-02-10T00:31:59Z", + "modified": "2024-09-05T15:33:32Z", "published": "2024-02-10T00:31:59Z", "aliases": [ "CVE-2023-45718" @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-384" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-68p8-j476-8w35/GHSA-68p8-j476-8w35.json b/advisories/unreviewed/2024/02/GHSA-68p8-j476-8w35/GHSA-68p8-j476-8w35.json index 58219190b3c..b6f8bd4ad1a 100644 --- a/advisories/unreviewed/2024/02/GHSA-68p8-j476-8w35/GHSA-68p8-j476-8w35.json +++ b/advisories/unreviewed/2024/02/GHSA-68p8-j476-8w35/GHSA-68p8-j476-8w35.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-68p8-j476-8w35", - "modified": "2024-02-11T06:30:27Z", + "modified": "2024-09-05T15:33:33Z", "published": "2024-02-11T06:30:27Z", "aliases": [ "CVE-2024-25722" ], "details": "qanything_kernel/connector/database/mysql/mysql_client.py in qanything.ai QAnything before 1.2.0 allows SQL Injection.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-11T05:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-g7f3-4crr-9hfj/GHSA-g7f3-4crr-9hfj.json b/advisories/unreviewed/2024/02/GHSA-g7f3-4crr-9hfj/GHSA-g7f3-4crr-9hfj.json index 73cd597d436..ce63013552b 100644 --- a/advisories/unreviewed/2024/02/GHSA-g7f3-4crr-9hfj/GHSA-g7f3-4crr-9hfj.json +++ b/advisories/unreviewed/2024/02/GHSA-g7f3-4crr-9hfj/GHSA-g7f3-4crr-9hfj.json @@ -56,7 +56,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-r2g2-g732-97cw/GHSA-r2g2-g732-97cw.json b/advisories/unreviewed/2024/02/GHSA-r2g2-g732-97cw/GHSA-r2g2-g732-97cw.json index 5ec3ea13097..c874ef12979 100644 --- a/advisories/unreviewed/2024/02/GHSA-r2g2-g732-97cw/GHSA-r2g2-g732-97cw.json +++ b/advisories/unreviewed/2024/02/GHSA-r2g2-g732-97cw/GHSA-r2g2-g732-97cw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r2g2-g732-97cw", - "modified": "2024-02-08T09:30:41Z", + "modified": "2024-09-05T15:33:32Z", "published": "2024-02-08T09:30:41Z", "aliases": [ "CVE-2024-24034" ], "details": "Setor Informatica S.I.L version 3.0 is vulnerable to Open Redirect via the hprinter parameter, allows remote attackers to execute arbitrary code.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-601" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-08T09:15:46Z" diff --git a/advisories/unreviewed/2024/02/GHSA-r57p-gw8h-38xj/GHSA-r57p-gw8h-38xj.json b/advisories/unreviewed/2024/02/GHSA-r57p-gw8h-38xj/GHSA-r57p-gw8h-38xj.json index b019997cdd5..aa9825ad568 100644 --- a/advisories/unreviewed/2024/02/GHSA-r57p-gw8h-38xj/GHSA-r57p-gw8h-38xj.json +++ b/advisories/unreviewed/2024/02/GHSA-r57p-gw8h-38xj/GHSA-r57p-gw8h-38xj.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-78", "CWE-94" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2024/02/GHSA-vpg2-32g8-56wf/GHSA-vpg2-32g8-56wf.json b/advisories/unreviewed/2024/02/GHSA-vpg2-32g8-56wf/GHSA-vpg2-32g8-56wf.json index ffb62ec9e48..f82b7011525 100644 --- a/advisories/unreviewed/2024/02/GHSA-vpg2-32g8-56wf/GHSA-vpg2-32g8-56wf.json +++ b/advisories/unreviewed/2024/02/GHSA-vpg2-32g8-56wf/GHSA-vpg2-32g8-56wf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vpg2-32g8-56wf", - "modified": "2024-02-12T00:30:22Z", + "modified": "2024-09-05T15:33:33Z", "published": "2024-02-12T00:30:22Z", "aliases": [ "CVE-2024-25728" ], "details": "ExpressVPN before 12.73.0 on Windows, when split tunneling is used, sends DNS requests according to the Windows configuration (e.g., sends them to DNS servers operated by the user's ISP instead of to the ExpressVPN DNS servers), which may allow remote attackers to obtain sensitive information about websites visited by VPN users.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-11T22:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-xf6f-94pc-55vc/GHSA-xf6f-94pc-55vc.json b/advisories/unreviewed/2024/02/GHSA-xf6f-94pc-55vc/GHSA-xf6f-94pc-55vc.json index 67b613c245e..940daf90bb7 100644 --- a/advisories/unreviewed/2024/02/GHSA-xf6f-94pc-55vc/GHSA-xf6f-94pc-55vc.json +++ b/advisories/unreviewed/2024/02/GHSA-xf6f-94pc-55vc/GHSA-xf6f-94pc-55vc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xf6f-94pc-55vc", - "modified": "2024-02-08T06:30:24Z", + "modified": "2024-09-05T15:33:32Z", "published": "2024-02-08T06:30:24Z", "aliases": [ "CVE-2024-24216" ], "details": "Zentao v18.0 to v18.10 was discovered to contain a remote code execution (RCE) vulnerability via the checkConnection method of /app/zentao/module/repo/model.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-08T06:15:51Z" diff --git a/advisories/unreviewed/2024/08/GHSA-w8pg-hrp7-6jch/GHSA-w8pg-hrp7-6jch.json b/advisories/unreviewed/2024/08/GHSA-w8pg-hrp7-6jch/GHSA-w8pg-hrp7-6jch.json index 7ab39b64c20..ffe44b00ad1 100644 --- a/advisories/unreviewed/2024/08/GHSA-w8pg-hrp7-6jch/GHSA-w8pg-hrp7-6jch.json +++ b/advisories/unreviewed/2024/08/GHSA-w8pg-hrp7-6jch/GHSA-w8pg-hrp7-6jch.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w8pg-hrp7-6jch", - "modified": "2024-08-05T15:30:51Z", + "modified": "2024-09-05T15:33:33Z", "published": "2024-08-05T06:30:37Z", "aliases": [ "CVE-2024-6498" ], "details": "The Chatbot for WordPress by Collect.chat ⚡️ WordPress plugin before 2.4.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-05T06:16:41Z" diff --git a/advisories/unreviewed/2024/08/GHSA-wfr9-cxf9-hqxv/GHSA-wfr9-cxf9-hqxv.json b/advisories/unreviewed/2024/08/GHSA-wfr9-cxf9-hqxv/GHSA-wfr9-cxf9-hqxv.json index 985b67e0358..7834c6c7632 100644 --- a/advisories/unreviewed/2024/08/GHSA-wfr9-cxf9-hqxv/GHSA-wfr9-cxf9-hqxv.json +++ b/advisories/unreviewed/2024/08/GHSA-wfr9-cxf9-hqxv/GHSA-wfr9-cxf9-hqxv.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-2jjj-25f5-6pvh/GHSA-2jjj-25f5-6pvh.json b/advisories/unreviewed/2024/09/GHSA-2jjj-25f5-6pvh/GHSA-2jjj-25f5-6pvh.json index 961f9dfd4a9..365210b43b5 100644 --- a/advisories/unreviewed/2024/09/GHSA-2jjj-25f5-6pvh/GHSA-2jjj-25f5-6pvh.json +++ b/advisories/unreviewed/2024/09/GHSA-2jjj-25f5-6pvh/GHSA-2jjj-25f5-6pvh.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-435p-f446-gxf4/GHSA-435p-f446-gxf4.json b/advisories/unreviewed/2024/09/GHSA-435p-f446-gxf4/GHSA-435p-f446-gxf4.json index 80393ba13f6..68f6eadc29f 100644 --- a/advisories/unreviewed/2024/09/GHSA-435p-f446-gxf4/GHSA-435p-f446-gxf4.json +++ b/advisories/unreviewed/2024/09/GHSA-435p-f446-gxf4/GHSA-435p-f446-gxf4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-435p-f446-gxf4", - "modified": "2024-09-04T21:30:32Z", + "modified": "2024-09-05T15:33:35Z", "published": "2024-09-04T21:30:32Z", "aliases": [ "CVE-2024-44995" diff --git a/advisories/unreviewed/2024/09/GHSA-459r-6xm8-3p72/GHSA-459r-6xm8-3p72.json b/advisories/unreviewed/2024/09/GHSA-459r-6xm8-3p72/GHSA-459r-6xm8-3p72.json new file mode 100644 index 00000000000..fd7f6db19fb --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-459r-6xm8-3p72/GHSA-459r-6xm8-3p72.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-459r-6xm8-3p72", + "modified": "2024-09-05T15:33:37Z", + "published": "2024-09-05T15:33:37Z", + "aliases": [ + "CVE-2024-44587" + ], + "details": "itsourcecode Alton Management System 1.0 is vulnerable to SQL Injection in /noncombo_save.php via the \"menu\" parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44587" + }, + { + "type": "WEB", + "url": "https://github.com/Lejeremiah/excavation/blob/main/cms-sql1.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-05T14:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-5hv9-vfr9-4mh3/GHSA-5hv9-vfr9-4mh3.json b/advisories/unreviewed/2024/09/GHSA-5hv9-vfr9-4mh3/GHSA-5hv9-vfr9-4mh3.json index 5696272531b..f3981397e20 100644 --- a/advisories/unreviewed/2024/09/GHSA-5hv9-vfr9-4mh3/GHSA-5hv9-vfr9-4mh3.json +++ b/advisories/unreviewed/2024/09/GHSA-5hv9-vfr9-4mh3/GHSA-5hv9-vfr9-4mh3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5hv9-vfr9-4mh3", - "modified": "2024-09-05T06:31:34Z", + "modified": "2024-09-05T15:33:35Z", "published": "2024-09-05T06:31:34Z", "aliases": [ "CVE-2024-45288" ], "details": "A missing null-termination character in the last element of an nvlist array string can lead to writing outside the allocated buffer.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-170" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-05T04:15:07Z" diff --git a/advisories/unreviewed/2024/09/GHSA-7hvr-66jc-2p7f/GHSA-7hvr-66jc-2p7f.json b/advisories/unreviewed/2024/09/GHSA-7hvr-66jc-2p7f/GHSA-7hvr-66jc-2p7f.json index 1cdbc92939e..5992f6d9d64 100644 --- a/advisories/unreviewed/2024/09/GHSA-7hvr-66jc-2p7f/GHSA-7hvr-66jc-2p7f.json +++ b/advisories/unreviewed/2024/09/GHSA-7hvr-66jc-2p7f/GHSA-7hvr-66jc-2p7f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7hvr-66jc-2p7f", - "modified": "2024-09-04T09:30:45Z", + "modified": "2024-09-05T15:33:34Z", "published": "2024-09-04T09:30:45Z", "aliases": [ "CVE-2024-8104" diff --git a/advisories/unreviewed/2024/09/GHSA-7xv3-rpxg-r28m/GHSA-7xv3-rpxg-r28m.json b/advisories/unreviewed/2024/09/GHSA-7xv3-rpxg-r28m/GHSA-7xv3-rpxg-r28m.json new file mode 100644 index 00000000000..7f3a1b7d1b0 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-7xv3-rpxg-r28m/GHSA-7xv3-rpxg-r28m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7xv3-rpxg-r28m", + "modified": "2024-09-05T15:33:36Z", + "published": "2024-09-05T15:33:36Z", + "aliases": [ + "CVE-2024-8466" + ], + "details": "SQL injection vulnerability, by which an attacker could send a specially designed query through CATEGORY parameter in /jobportal/admin/category/controller.php, and retrieve all the information stored in it.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8466" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-job-portal" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-05T13:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-94j5-29m8-f8jq/GHSA-94j5-29m8-f8jq.json b/advisories/unreviewed/2024/09/GHSA-94j5-29m8-f8jq/GHSA-94j5-29m8-f8jq.json index cad4068f84f..3746f57a7bb 100644 --- a/advisories/unreviewed/2024/09/GHSA-94j5-29m8-f8jq/GHSA-94j5-29m8-f8jq.json +++ b/advisories/unreviewed/2024/09/GHSA-94j5-29m8-f8jq/GHSA-94j5-29m8-f8jq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-94j5-29m8-f8jq", - "modified": "2024-09-05T06:31:34Z", + "modified": "2024-09-05T15:33:35Z", "published": "2024-09-05T06:31:34Z", "aliases": [ "CVE-2024-32668" ], "details": "An insufficient boundary validation in the USB code could lead to an out-of-bounds write on the heap, with data controlled by the caller.\n\nA malicious, privileged software running in a guest VM can exploit the vulnerability to achieve code execution on the host in the bhyve userspace process, which typically runs as root. Note that bhyve runs in a Capsicum sandbox, so malicious code is constrained by the capabilities available to the bhyve process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-193" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-05T05:15:13Z" diff --git a/advisories/unreviewed/2024/09/GHSA-97xc-8xj3-86xm/GHSA-97xc-8xj3-86xm.json b/advisories/unreviewed/2024/09/GHSA-97xc-8xj3-86xm/GHSA-97xc-8xj3-86xm.json new file mode 100644 index 00000000000..bd6b10c041c --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-97xc-8xj3-86xm/GHSA-97xc-8xj3-86xm.json @@ -0,0 +1,62 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-97xc-8xj3-86xm", + "modified": "2024-09-05T15:33:35Z", + "published": "2024-09-05T15:33:35Z", + "aliases": [ + "CVE-2024-8461" + ], + "details": "A vulnerability, which was classified as problematic, was found in D-Link DNS-320 2.02b01. This affects an unknown part of the file /cgi-bin/discovery.cgi of the component Web Management Interface. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. Vendor was contacted early and confirmed that the product is end-of-life. It should be retired and replaced.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8461" + }, + { + "type": "WEB", + "url": "https://github.com/leetsun/IoT-Vuls/tree/main/Dlink-dns320/4" + }, + { + "type": "WEB", + "url": "https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10383" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.276627" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.276627" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.401300" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-05T13:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-99ph-h865-m6x2/GHSA-99ph-h865-m6x2.json b/advisories/unreviewed/2024/09/GHSA-99ph-h865-m6x2/GHSA-99ph-h865-m6x2.json index c443b664ce3..9251dfeae05 100644 --- a/advisories/unreviewed/2024/09/GHSA-99ph-h865-m6x2/GHSA-99ph-h865-m6x2.json +++ b/advisories/unreviewed/2024/09/GHSA-99ph-h865-m6x2/GHSA-99ph-h865-m6x2.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-99ph-h865-m6x2", - "modified": "2024-09-04T15:30:36Z", + "modified": "2024-09-05T15:33:34Z", "published": "2024-09-04T15:30:36Z", "aliases": [ "CVE-2024-7077" ], "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Semtek Informatics Software Consulting Inc. Semtek Sempos allows Reflected XSS.This issue affects Semtek Sempos: through 31072024.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/09/GHSA-9q6m-vr5h-rqq5/GHSA-9q6m-vr5h-rqq5.json b/advisories/unreviewed/2024/09/GHSA-9q6m-vr5h-rqq5/GHSA-9q6m-vr5h-rqq5.json new file mode 100644 index 00000000000..f06a6fcb26f --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-9q6m-vr5h-rqq5/GHSA-9q6m-vr5h-rqq5.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9q6m-vr5h-rqq5", + "modified": "2024-09-05T15:33:37Z", + "published": "2024-09-05T15:33:37Z", + "aliases": [ + "CVE-2024-8445" + ], + "details": "The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios. In certain product versions, an authenticated user may cause a server crash while modifying `userPassword` using malformed input.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8445" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-8445" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2310110" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-05T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-c52g-pq8x-mvmm/GHSA-c52g-pq8x-mvmm.json b/advisories/unreviewed/2024/09/GHSA-c52g-pq8x-mvmm/GHSA-c52g-pq8x-mvmm.json index 77384c71461..fb74bd6303f 100644 --- a/advisories/unreviewed/2024/09/GHSA-c52g-pq8x-mvmm/GHSA-c52g-pq8x-mvmm.json +++ b/advisories/unreviewed/2024/09/GHSA-c52g-pq8x-mvmm/GHSA-c52g-pq8x-mvmm.json @@ -40,6 +40,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-24" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/09/GHSA-cf94-f85j-g689/GHSA-cf94-f85j-g689.json b/advisories/unreviewed/2024/09/GHSA-cf94-f85j-g689/GHSA-cf94-f85j-g689.json new file mode 100644 index 00000000000..54502f4473b --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-cf94-f85j-g689/GHSA-cf94-f85j-g689.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cf94-f85j-g689", + "modified": "2024-09-05T15:33:36Z", + "published": "2024-09-05T15:33:36Z", + "aliases": [ + "CVE-2024-8471" + ], + "details": "Cross-Site Scripting (XSS) vulnerability, whereby user-controlled input is not sufficiently encrypted. Exploitation of this vulnerability could allow an attacker to retrieve the session details of an authenticated user through JOBID and USERNAME parameters in /jobportal/process.php.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8471" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-job-portal" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-05T13:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-cq42-4xp3-5247/GHSA-cq42-4xp3-5247.json b/advisories/unreviewed/2024/09/GHSA-cq42-4xp3-5247/GHSA-cq42-4xp3-5247.json new file mode 100644 index 00000000000..4d1e177f415 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-cq42-4xp3-5247/GHSA-cq42-4xp3-5247.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cq42-4xp3-5247", + "modified": "2024-09-05T15:33:37Z", + "published": "2024-09-05T15:33:37Z", + "aliases": [ + "CVE-2024-45173" + ], + "details": "An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper privilege management concerning sudo privileges, C-MOR is vulnerable to a privilege escalation attack. The Linux user www-data running the C-MOR web interface can execute some OS commands as root via Sudo without having to enter the root password. These commands, for example, include cp, chown, and chmod, which enable an attacker to modify the system's sudoers file in order to execute all commands with root privileges. Thus, it is possible to escalate the limited privileges of the user www-data to root privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45173" + }, + { + "type": "WEB", + "url": "https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-027.txt" + }, + { + "type": "WEB", + "url": "https://www.syss.de/pentest-blog/mehrere-sicherheitsschwachstellen-in-videoueberwachungssoftware-c-mor-syss-2024-020-bis-030" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-05T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-f2h5-3j7q-vp2p/GHSA-f2h5-3j7q-vp2p.json b/advisories/unreviewed/2024/09/GHSA-f2h5-3j7q-vp2p/GHSA-f2h5-3j7q-vp2p.json index 909f9afb04d..bdeafaa06f2 100644 --- a/advisories/unreviewed/2024/09/GHSA-f2h5-3j7q-vp2p/GHSA-f2h5-3j7q-vp2p.json +++ b/advisories/unreviewed/2024/09/GHSA-f2h5-3j7q-vp2p/GHSA-f2h5-3j7q-vp2p.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f2h5-3j7q-vp2p", - "modified": "2024-09-03T15:30:46Z", + "modified": "2024-09-05T15:33:34Z", "published": "2024-09-03T15:30:46Z", "aliases": [ "CVE-2024-4259" ], "details": "Improper Privilege Management vulnerability in SAMPA? Holding AKOS allows Collect Data as Provided by Users.This issue affects AKOS: through 20240902. \n\nNOTE: The vendor was contacted early about this disclosure but did not respond in any way.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/09/GHSA-f7xr-hxhp-pp5m/GHSA-f7xr-hxhp-pp5m.json b/advisories/unreviewed/2024/09/GHSA-f7xr-hxhp-pp5m/GHSA-f7xr-hxhp-pp5m.json new file mode 100644 index 00000000000..3a4cb89a735 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-f7xr-hxhp-pp5m/GHSA-f7xr-hxhp-pp5m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f7xr-hxhp-pp5m", + "modified": "2024-09-05T15:33:35Z", + "published": "2024-09-05T15:33:35Z", + "aliases": [ + "CVE-2024-8464" + ], + "details": "SQL injection vulnerability, by which an attacker could send a specially designed query through JOBREGID parameter in /jobportal/admin/applicants/controller.php, and retrieve all the information stored in it.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8464" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-job-portal" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-05T13:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-fgc8-q46c-35v5/GHSA-fgc8-q46c-35v5.json b/advisories/unreviewed/2024/09/GHSA-fgc8-q46c-35v5/GHSA-fgc8-q46c-35v5.json index 08ee79eaec6..d672528ed36 100644 --- a/advisories/unreviewed/2024/09/GHSA-fgc8-q46c-35v5/GHSA-fgc8-q46c-35v5.json +++ b/advisories/unreviewed/2024/09/GHSA-fgc8-q46c-35v5/GHSA-fgc8-q46c-35v5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fgc8-q46c-35v5", - "modified": "2024-09-03T15:30:46Z", + "modified": "2024-09-05T15:33:34Z", "published": "2024-09-03T15:30:46Z", "aliases": [ "CVE-2024-7654" diff --git a/advisories/unreviewed/2024/09/GHSA-g68r-c5p5-f438/GHSA-g68r-c5p5-f438.json b/advisories/unreviewed/2024/09/GHSA-g68r-c5p5-f438/GHSA-g68r-c5p5-f438.json index 3a0a0cc907d..9abbb960c74 100644 --- a/advisories/unreviewed/2024/09/GHSA-g68r-c5p5-f438/GHSA-g68r-c5p5-f438.json +++ b/advisories/unreviewed/2024/09/GHSA-g68r-c5p5-f438/GHSA-g68r-c5p5-f438.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g68r-c5p5-f438", - "modified": "2024-09-02T06:30:47Z", + "modified": "2024-09-05T15:33:34Z", "published": "2024-09-02T06:30:47Z", "aliases": [ "CVE-2024-20085" ], "details": "In power, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08944204; Issue ID: MSV-1560.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-02T05:15:14Z" diff --git a/advisories/unreviewed/2024/09/GHSA-g6q4-w3j3-jfc4/GHSA-g6q4-w3j3-jfc4.json b/advisories/unreviewed/2024/09/GHSA-g6q4-w3j3-jfc4/GHSA-g6q4-w3j3-jfc4.json new file mode 100644 index 00000000000..b76adef3fa9 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-g6q4-w3j3-jfc4/GHSA-g6q4-w3j3-jfc4.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g6q4-w3j3-jfc4", + "modified": "2024-09-05T15:33:35Z", + "published": "2024-09-05T15:33:35Z", + "aliases": [ + "CVE-2024-8462" + ], + "details": "A vulnerability was found in Windmill 1.380.0. It has been classified as problematic. Affected is an unknown function of the file backend/windmill-api/src/users.rs of the component HTTP Request Handler. The manipulation leads to improper restriction of excessive authentication attempts. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. Upgrading to version 1.390.1 is able to address this issue. The patch is identified as acfe7786152f036f2476f93ab5536571514fa9e3. It is recommended to upgrade the affected component.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8462" + }, + { + "type": "WEB", + "url": "https://github.com/windmill-labs/windmill/commit/acfe7786152f036f2476f93ab5536571514fa9e3" + }, + { + "type": "WEB", + "url": "https://github.com/windmill-labs/windmill/releases/tag/v1.390.1" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.276630" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.276630" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.401826" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-307" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-05T13:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-gggp-8r87-v88f/GHSA-gggp-8r87-v88f.json b/advisories/unreviewed/2024/09/GHSA-gggp-8r87-v88f/GHSA-gggp-8r87-v88f.json index 8a18a29183d..9bf61e4b7fc 100644 --- a/advisories/unreviewed/2024/09/GHSA-gggp-8r87-v88f/GHSA-gggp-8r87-v88f.json +++ b/advisories/unreviewed/2024/09/GHSA-gggp-8r87-v88f/GHSA-gggp-8r87-v88f.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-gq4v-4f65-pcgf/GHSA-gq4v-4f65-pcgf.json b/advisories/unreviewed/2024/09/GHSA-gq4v-4f65-pcgf/GHSA-gq4v-4f65-pcgf.json index 77a0d3ea47d..5c8ce34d603 100644 --- a/advisories/unreviewed/2024/09/GHSA-gq4v-4f65-pcgf/GHSA-gq4v-4f65-pcgf.json +++ b/advisories/unreviewed/2024/09/GHSA-gq4v-4f65-pcgf/GHSA-gq4v-4f65-pcgf.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gq4v-4f65-pcgf", - "modified": "2024-09-04T15:30:36Z", + "modified": "2024-09-05T15:33:34Z", "published": "2024-09-04T15:30:36Z", "aliases": [ "CVE-2024-7078" ], "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Semtek Informatics Software Consulting Inc. Semtek Sempos allows SQL Injection.This issue affects Semtek Sempos: through 31072024.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/09/GHSA-gxvc-8pmw-487p/GHSA-gxvc-8pmw-487p.json b/advisories/unreviewed/2024/09/GHSA-gxvc-8pmw-487p/GHSA-gxvc-8pmw-487p.json index ee3c94e58f2..aa1bc2bd708 100644 --- a/advisories/unreviewed/2024/09/GHSA-gxvc-8pmw-487p/GHSA-gxvc-8pmw-487p.json +++ b/advisories/unreviewed/2024/09/GHSA-gxvc-8pmw-487p/GHSA-gxvc-8pmw-487p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gxvc-8pmw-487p", - "modified": "2024-09-02T06:30:48Z", + "modified": "2024-09-05T15:33:34Z", "published": "2024-09-02T06:30:48Z", "aliases": [ "CVE-2024-20088" ], "details": "In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08932099; Issue ID: MSV-1543.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-02T05:15:15Z" diff --git a/advisories/unreviewed/2024/09/GHSA-h8p6-g323-v7g2/GHSA-h8p6-g323-v7g2.json b/advisories/unreviewed/2024/09/GHSA-h8p6-g323-v7g2/GHSA-h8p6-g323-v7g2.json index 8234f8bca79..e1a8ef00eea 100644 --- a/advisories/unreviewed/2024/09/GHSA-h8p6-g323-v7g2/GHSA-h8p6-g323-v7g2.json +++ b/advisories/unreviewed/2024/09/GHSA-h8p6-g323-v7g2/GHSA-h8p6-g323-v7g2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h8p6-g323-v7g2", - "modified": "2024-09-02T06:30:47Z", + "modified": "2024-09-05T15:33:34Z", "published": "2024-09-02T06:30:47Z", "aliases": [ "CVE-2024-20084" ], "details": "In power, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08944210; Issue ID: MSV-1561.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-02T05:15:14Z" diff --git a/advisories/unreviewed/2024/09/GHSA-hgfp-qxpq-6q7w/GHSA-hgfp-qxpq-6q7w.json b/advisories/unreviewed/2024/09/GHSA-hgfp-qxpq-6q7w/GHSA-hgfp-qxpq-6q7w.json index de39e39bfd7..b55ec280d34 100644 --- a/advisories/unreviewed/2024/09/GHSA-hgfp-qxpq-6q7w/GHSA-hgfp-qxpq-6q7w.json +++ b/advisories/unreviewed/2024/09/GHSA-hgfp-qxpq-6q7w/GHSA-hgfp-qxpq-6q7w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hgfp-qxpq-6q7w", - "modified": "2024-09-05T06:31:35Z", + "modified": "2024-09-05T15:33:35Z", "published": "2024-09-05T06:31:35Z", "aliases": [ "CVE-2024-42416" ], "details": "The ctl_report_supported_opcodes function did not sufficiently validate a field provided by userspace, allowing an arbitrary write to a limited amount of kernel help memory.\n\nMalicious software running in a guest VM that exposes virtio_scsi can exploit the vulnerabilities to achieve code execution on the host in the bhyve userspace process, which typically runs as root. Note that bhyve runs in a Capsicum sandbox, so malicious code is constrained by the capabilities available to the bhyve process. A malicious iSCSI initiator could achieve remote code execution on the iSCSI target host.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-790" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-05T05:15:13Z" diff --git a/advisories/unreviewed/2024/09/GHSA-hjrp-754v-h7fj/GHSA-hjrp-754v-h7fj.json b/advisories/unreviewed/2024/09/GHSA-hjrp-754v-h7fj/GHSA-hjrp-754v-h7fj.json new file mode 100644 index 00000000000..3c78e2b5698 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-hjrp-754v-h7fj/GHSA-hjrp-754v-h7fj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hjrp-754v-h7fj", + "modified": "2024-09-05T15:33:36Z", + "published": "2024-09-05T15:33:36Z", + "aliases": [ + "CVE-2024-8465" + ], + "details": "SQL injection vulnerability, by which an attacker could send a specially designed query through user_id parameter in /jobportal/admin/user/controller.php, and retrieve all the information stored in it.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8465" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-job-portal" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-05T13:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-jrv3-q93v-rr48/GHSA-jrv3-q93v-rr48.json b/advisories/unreviewed/2024/09/GHSA-jrv3-q93v-rr48/GHSA-jrv3-q93v-rr48.json index 41414380273..b7dfcd12512 100644 --- a/advisories/unreviewed/2024/09/GHSA-jrv3-q93v-rr48/GHSA-jrv3-q93v-rr48.json +++ b/advisories/unreviewed/2024/09/GHSA-jrv3-q93v-rr48/GHSA-jrv3-q93v-rr48.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jrv3-q93v-rr48", - "modified": "2024-09-04T15:30:35Z", + "modified": "2024-09-05T15:33:34Z", "published": "2024-09-04T15:30:35Z", "aliases": [ "CVE-2024-7076" ], "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Semtek Informatics Software Consulting Inc. Semtek Sempos allows Blind SQL Injection.This issue affects Semtek Sempos: through 31072024.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:L/U:X" diff --git a/advisories/unreviewed/2024/09/GHSA-jw9p-3gc4-84rw/GHSA-jw9p-3gc4-84rw.json b/advisories/unreviewed/2024/09/GHSA-jw9p-3gc4-84rw/GHSA-jw9p-3gc4-84rw.json index b82c46af56b..aa81be9a5bd 100644 --- a/advisories/unreviewed/2024/09/GHSA-jw9p-3gc4-84rw/GHSA-jw9p-3gc4-84rw.json +++ b/advisories/unreviewed/2024/09/GHSA-jw9p-3gc4-84rw/GHSA-jw9p-3gc4-84rw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jw9p-3gc4-84rw", - "modified": "2024-09-03T15:30:46Z", + "modified": "2024-09-05T15:33:34Z", "published": "2024-09-03T15:30:46Z", "aliases": [ "CVE-2024-7346" @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-287", "CWE-297" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/09/GHSA-m4q6-r3hq-hfgq/GHSA-m4q6-r3hq-hfgq.json b/advisories/unreviewed/2024/09/GHSA-m4q6-r3hq-hfgq/GHSA-m4q6-r3hq-hfgq.json new file mode 100644 index 00000000000..92856a3a76d --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-m4q6-r3hq-hfgq/GHSA-m4q6-r3hq-hfgq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m4q6-r3hq-hfgq", + "modified": "2024-09-05T15:33:36Z", + "published": "2024-09-05T15:33:36Z", + "aliases": [ + "CVE-2024-8473" + ], + "details": "Cross-Site Scripting (XSS) vulnerability, whereby user-controlled input is not sufficiently encrypted. Exploitation of this vulnerability could allow an attacker to retrieve the session details of an authenticated user through user_email parameter in /jobportal/admin/login.php.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8473" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-job-portal" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-05T13:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-m553-jg82-m2p2/GHSA-m553-jg82-m2p2.json b/advisories/unreviewed/2024/09/GHSA-m553-jg82-m2p2/GHSA-m553-jg82-m2p2.json index e62c6929716..b9eea12f360 100644 --- a/advisories/unreviewed/2024/09/GHSA-m553-jg82-m2p2/GHSA-m553-jg82-m2p2.json +++ b/advisories/unreviewed/2024/09/GHSA-m553-jg82-m2p2/GHSA-m553-jg82-m2p2.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-mm65-4gm3-h22v/GHSA-mm65-4gm3-h22v.json b/advisories/unreviewed/2024/09/GHSA-mm65-4gm3-h22v/GHSA-mm65-4gm3-h22v.json new file mode 100644 index 00000000000..4b909f5a3e3 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-mm65-4gm3-h22v/GHSA-mm65-4gm3-h22v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mm65-4gm3-h22v", + "modified": "2024-09-05T15:33:36Z", + "published": "2024-09-05T15:33:36Z", + "aliases": [ + "CVE-2024-8468" + ], + "details": "SQL injection vulnerability, by which an attacker could send a specially designed query through search parameter in /jobportal/index.php, and retrieve all the information stored in it.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8468" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-job-portal" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-05T13:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-mrwf-vh6j-2grj/GHSA-mrwf-vh6j-2grj.json b/advisories/unreviewed/2024/09/GHSA-mrwf-vh6j-2grj/GHSA-mrwf-vh6j-2grj.json index 5c23983f1cc..218410bd842 100644 --- a/advisories/unreviewed/2024/09/GHSA-mrwf-vh6j-2grj/GHSA-mrwf-vh6j-2grj.json +++ b/advisories/unreviewed/2024/09/GHSA-mrwf-vh6j-2grj/GHSA-mrwf-vh6j-2grj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mrwf-vh6j-2grj", - "modified": "2024-09-05T06:31:33Z", + "modified": "2024-09-05T15:33:35Z", "published": "2024-09-05T06:31:33Z", "aliases": [ "CVE-2024-45287" ], "details": "A malicious value of size in a structure of packed libnv can cause an integer overflow, leading to the allocation of a smaller buffer than required for the parsed data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-131" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-05T04:15:07Z" diff --git a/advisories/unreviewed/2024/09/GHSA-p6qw-qg3w-mhxx/GHSA-p6qw-qg3w-mhxx.json b/advisories/unreviewed/2024/09/GHSA-p6qw-qg3w-mhxx/GHSA-p6qw-qg3w-mhxx.json index ee5ec2cbdbd..e9109beb39a 100644 --- a/advisories/unreviewed/2024/09/GHSA-p6qw-qg3w-mhxx/GHSA-p6qw-qg3w-mhxx.json +++ b/advisories/unreviewed/2024/09/GHSA-p6qw-qg3w-mhxx/GHSA-p6qw-qg3w-mhxx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p6qw-qg3w-mhxx", - "modified": "2024-09-04T18:30:58Z", + "modified": "2024-09-05T15:33:34Z", "published": "2024-09-04T18:30:58Z", "aliases": [ "CVE-2024-8417" diff --git a/advisories/unreviewed/2024/09/GHSA-p7m8-prjf-m93h/GHSA-p7m8-prjf-m93h.json b/advisories/unreviewed/2024/09/GHSA-p7m8-prjf-m93h/GHSA-p7m8-prjf-m93h.json index 55987b9fa43..dab6b7eb840 100644 --- a/advisories/unreviewed/2024/09/GHSA-p7m8-prjf-m93h/GHSA-p7m8-prjf-m93h.json +++ b/advisories/unreviewed/2024/09/GHSA-p7m8-prjf-m93h/GHSA-p7m8-prjf-m93h.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p7m8-prjf-m93h", - "modified": "2024-09-03T12:30:33Z", + "modified": "2024-09-05T15:33:34Z", "published": "2024-09-03T12:30:33Z", "aliases": [ "CVE-2024-6473" ], "details": "Yandex Browser for Desktop before 24.7.1.380 has a DLL Hijacking Vulnerability because an untrusted search path is used.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/09/GHSA-phhw-57mq-75j6/GHSA-phhw-57mq-75j6.json b/advisories/unreviewed/2024/09/GHSA-phhw-57mq-75j6/GHSA-phhw-57mq-75j6.json new file mode 100644 index 00000000000..434160debcc --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-phhw-57mq-75j6/GHSA-phhw-57mq-75j6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phhw-57mq-75j6", + "modified": "2024-09-05T15:33:35Z", + "published": "2024-09-05T15:33:35Z", + "aliases": [ + "CVE-2024-8463" + ], + "details": "File upload restriction bypass vulnerability in PHPGurukul Job Portal 1.0, the exploitation of which could allow an authenticated user to execute an RCE via webshell.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8463" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-job-portal" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-05T13:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-pxg7-xwx3-q885/GHSA-pxg7-xwx3-q885.json b/advisories/unreviewed/2024/09/GHSA-pxg7-xwx3-q885/GHSA-pxg7-xwx3-q885.json new file mode 100644 index 00000000000..4771f98f1dd --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-pxg7-xwx3-q885/GHSA-pxg7-xwx3-q885.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pxg7-xwx3-q885", + "modified": "2024-09-05T15:33:36Z", + "published": "2024-09-05T15:33:36Z", + "aliases": [ + "CVE-2024-8470" + ], + "details": "SQL injection vulnerability, by which an attacker could send a specially designed query through CATEGORY parameter in /jobportal/admin/vacancy/controller.php, and retrieve all the information stored in it.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8470" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-job-portal" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-05T13:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-qv39-hg6q-9r5r/GHSA-qv39-hg6q-9r5r.json b/advisories/unreviewed/2024/09/GHSA-qv39-hg6q-9r5r/GHSA-qv39-hg6q-9r5r.json index 150a160dd58..9467f42066b 100644 --- a/advisories/unreviewed/2024/09/GHSA-qv39-hg6q-9r5r/GHSA-qv39-hg6q-9r5r.json +++ b/advisories/unreviewed/2024/09/GHSA-qv39-hg6q-9r5r/GHSA-qv39-hg6q-9r5r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qv39-hg6q-9r5r", - "modified": "2024-09-04T21:30:33Z", + "modified": "2024-09-05T15:33:35Z", "published": "2024-09-04T21:30:33Z", "aliases": [ "CVE-2024-45003" diff --git a/advisories/unreviewed/2024/09/GHSA-r3xx-2cqf-j665/GHSA-r3xx-2cqf-j665.json b/advisories/unreviewed/2024/09/GHSA-r3xx-2cqf-j665/GHSA-r3xx-2cqf-j665.json index 96d0f25ddc9..88eba18949a 100644 --- a/advisories/unreviewed/2024/09/GHSA-r3xx-2cqf-j665/GHSA-r3xx-2cqf-j665.json +++ b/advisories/unreviewed/2024/09/GHSA-r3xx-2cqf-j665/GHSA-r3xx-2cqf-j665.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r3xx-2cqf-j665", - "modified": "2024-09-04T15:30:35Z", + "modified": "2024-09-05T15:33:34Z", "published": "2024-09-04T15:30:35Z", "aliases": [ "CVE-2024-44819" ], "details": "Cross Site Scripting vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information via a crafted script to the pagename parameter of the admin/del.php component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-04T15:15:13Z" diff --git a/advisories/unreviewed/2024/09/GHSA-r58j-7299-f87q/GHSA-r58j-7299-f87q.json b/advisories/unreviewed/2024/09/GHSA-r58j-7299-f87q/GHSA-r58j-7299-f87q.json index 510e21d33f0..1cd0a97b4eb 100644 --- a/advisories/unreviewed/2024/09/GHSA-r58j-7299-f87q/GHSA-r58j-7299-f87q.json +++ b/advisories/unreviewed/2024/09/GHSA-r58j-7299-f87q/GHSA-r58j-7299-f87q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r58j-7299-f87q", - "modified": "2024-09-05T06:31:35Z", + "modified": "2024-09-05T15:33:35Z", "published": "2024-09-05T06:31:35Z", "aliases": [ "CVE-2024-43110" ], "details": "The ctl_request_sense function could expose up to three bytes of the kernel heap to userspace.\n\nMalicious software running in a guest VM that exposes virtio_scsi can exploit the vulnerabilities to achieve code execution on the host in the bhyve userspace process, which typically runs as root. Note that bhyve runs in a Capsicum sandbox, so malicious code is constrained by the capabilities available to the bhyve process. A malicious iSCSI initiator could achieve remote code execution on the iSCSI target host.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-05T05:15:13Z" diff --git a/advisories/unreviewed/2024/09/GHSA-r7pq-7pwm-wmf5/GHSA-r7pq-7pwm-wmf5.json b/advisories/unreviewed/2024/09/GHSA-r7pq-7pwm-wmf5/GHSA-r7pq-7pwm-wmf5.json new file mode 100644 index 00000000000..e918a80542c --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-r7pq-7pwm-wmf5/GHSA-r7pq-7pwm-wmf5.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r7pq-7pwm-wmf5", + "modified": "2024-09-05T15:33:37Z", + "published": "2024-09-05T15:33:37Z", + "aliases": [ + "CVE-2024-45178" + ], + "details": "An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper user input validation, it is possible to download arbitrary files from the C-MOR system via a path traversal attack. It was found out that different functionalities are vulnerable to path traversal attacks, due to insufficient user input validation. For instance, the download functionality for backups provided by the script download-bkf.pml is vulnerable to a path traversal attack via the parameter bkf. This enables an authenticated user to download arbitrary files as Linux user www-data from the C-MOR system. Another path traversal attack is in the script show-movies.pml, which can be exploited via the parameter cam.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45178" + }, + { + "type": "WEB", + "url": "https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-025.txt" + }, + { + "type": "WEB", + "url": "https://www.syss.de/pentest-blog/mehrere-sicherheitsschwachstellen-in-videoueberwachungssoftware-c-mor-syss-2024-020-bis-030" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-05T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-r9w6-vj2c-577r/GHSA-r9w6-vj2c-577r.json b/advisories/unreviewed/2024/09/GHSA-r9w6-vj2c-577r/GHSA-r9w6-vj2c-577r.json new file mode 100644 index 00000000000..59efa5508e1 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-r9w6-vj2c-577r/GHSA-r9w6-vj2c-577r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r9w6-vj2c-577r", + "modified": "2024-09-05T15:33:36Z", + "published": "2024-09-05T15:33:36Z", + "aliases": [ + "CVE-2024-8467" + ], + "details": "SQL injection vulnerability, by which an attacker could send a specially designed query through id parameter in /jobportal/admin/category/index.php, and retrieve all the information stored in it.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8467" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-job-portal" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-05T13:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-v72r-7947-x8jx/GHSA-v72r-7947-x8jx.json b/advisories/unreviewed/2024/09/GHSA-v72r-7947-x8jx/GHSA-v72r-7947-x8jx.json index e0e0a15cca6..4881c8a7867 100644 --- a/advisories/unreviewed/2024/09/GHSA-v72r-7947-x8jx/GHSA-v72r-7947-x8jx.json +++ b/advisories/unreviewed/2024/09/GHSA-v72r-7947-x8jx/GHSA-v72r-7947-x8jx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v72r-7947-x8jx", - "modified": "2024-09-05T06:31:35Z", + "modified": "2024-09-05T15:33:35Z", "published": "2024-09-05T06:31:35Z", "aliases": [ "CVE-2024-43102" ], "details": "Concurrent removals of certain anonymous shared memory mappings by using the UMTX_SHM_DESTROY sub-request of UMTX_OP_SHM can lead to decreasing the reference count of the object representing the mapping too many times, causing it to be freed too early.\n\nA malicious code exercizing the UMTX_SHM_DESTROY sub-request in parallel can panic the kernel or enable further Use-After-Free attacks, potentially including code execution or Capsicum sandbox escape.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-05T05:15:13Z" diff --git a/advisories/unreviewed/2024/09/GHSA-vrwg-mgfh-8rc8/GHSA-vrwg-mgfh-8rc8.json b/advisories/unreviewed/2024/09/GHSA-vrwg-mgfh-8rc8/GHSA-vrwg-mgfh-8rc8.json new file mode 100644 index 00000000000..1e120e49e2f --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-vrwg-mgfh-8rc8/GHSA-vrwg-mgfh-8rc8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vrwg-mgfh-8rc8", + "modified": "2024-09-05T15:33:36Z", + "published": "2024-09-05T15:33:36Z", + "aliases": [ + "CVE-2024-8469" + ], + "details": "SQL injection vulnerability, by which an attacker could send a specially designed query through id parameter in /jobportal/admin/employee/index.php, and retrieve all the information stored in it.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8469" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-job-portal" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-05T13:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-vv26-3gxj-65r5/GHSA-vv26-3gxj-65r5.json b/advisories/unreviewed/2024/09/GHSA-vv26-3gxj-65r5/GHSA-vv26-3gxj-65r5.json new file mode 100644 index 00000000000..b12da19cc8c --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-vv26-3gxj-65r5/GHSA-vv26-3gxj-65r5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vv26-3gxj-65r5", + "modified": "2024-09-05T15:33:36Z", + "published": "2024-09-05T15:33:36Z", + "aliases": [ + "CVE-2024-8472" + ], + "details": "Cross-Site Scripting (XSS) vulnerability, whereby user-controlled input is not sufficiently encrypted. Exploitation of this vulnerability could allow an attacker to retrieve the session details of an authenticated user through multiple parameters in /jobportal/index.php.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8472" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-job-portal" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-05T13:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-wv2q-3c9c-q6v7/GHSA-wv2q-3c9c-q6v7.json b/advisories/unreviewed/2024/09/GHSA-wv2q-3c9c-q6v7/GHSA-wv2q-3c9c-q6v7.json index 7d46ee619e4..bf5a4b39a21 100644 --- a/advisories/unreviewed/2024/09/GHSA-wv2q-3c9c-q6v7/GHSA-wv2q-3c9c-q6v7.json +++ b/advisories/unreviewed/2024/09/GHSA-wv2q-3c9c-q6v7/GHSA-wv2q-3c9c-q6v7.json @@ -48,7 +48,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-ww4v-q9h8-2q3m/GHSA-ww4v-q9h8-2q3m.json b/advisories/unreviewed/2024/09/GHSA-ww4v-q9h8-2q3m/GHSA-ww4v-q9h8-2q3m.json index a4193a1b953..317c140c626 100644 --- a/advisories/unreviewed/2024/09/GHSA-ww4v-q9h8-2q3m/GHSA-ww4v-q9h8-2q3m.json +++ b/advisories/unreviewed/2024/09/GHSA-ww4v-q9h8-2q3m/GHSA-ww4v-q9h8-2q3m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ww4v-q9h8-2q3m", - "modified": "2024-09-05T00:31:23Z", + "modified": "2024-09-05T15:33:35Z", "published": "2024-09-05T00:31:23Z", "aliases": [ "CVE-2024-45692" ], "details": "Webmin before 2.202 and Virtualmin before 7.20.2 allow a network traffic loop via spoofed UDP packets on port 10000.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-835" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-04T23:15:12Z" diff --git a/advisories/unreviewed/2024/09/GHSA-x54p-439w-h3mq/GHSA-x54p-439w-h3mq.json b/advisories/unreviewed/2024/09/GHSA-x54p-439w-h3mq/GHSA-x54p-439w-h3mq.json index db148f5fa9b..cfd3302dc56 100644 --- a/advisories/unreviewed/2024/09/GHSA-x54p-439w-h3mq/GHSA-x54p-439w-h3mq.json +++ b/advisories/unreviewed/2024/09/GHSA-x54p-439w-h3mq/GHSA-x54p-439w-h3mq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x54p-439w-h3mq", - "modified": "2024-09-05T06:31:35Z", + "modified": "2024-09-05T15:33:35Z", "published": "2024-09-05T06:31:35Z", "aliases": [ "CVE-2024-6846" ], "details": "The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not validate access on some REST routes, allowing for an unauthenticated user to purge error and chat logs", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-05T06:15:03Z"