diff --git a/advisories/github-reviewed/2024/04/GHSA-79vv-vp32-gpp7/GHSA-79vv-vp32-gpp7.json b/advisories/github-reviewed/2024/04/GHSA-79vv-vp32-gpp7/GHSA-79vv-vp32-gpp7.json index e3625697881..dd6d18c47d5 100644 --- a/advisories/github-reviewed/2024/04/GHSA-79vv-vp32-gpp7/GHSA-79vv-vp32-gpp7.json +++ b/advisories/github-reviewed/2024/04/GHSA-79vv-vp32-gpp7/GHSA-79vv-vp32-gpp7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-79vv-vp32-gpp7", - "modified": "2024-05-02T14:49:13Z", + "modified": "2024-07-05T18:34:13Z", "published": "2024-04-12T09:33:40Z", "aliases": [ "CVE-2024-27309" @@ -52,6 +52,10 @@ "type": "WEB", "url": "https://lists.apache.org/thread/6536rmzyg076lzzdw2xdktvnz163mjpy" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240705-0002" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/04/12/3" diff --git a/advisories/github-reviewed/2024/05/GHSA-2xp3-57p7-qf4v/GHSA-2xp3-57p7-qf4v.json b/advisories/github-reviewed/2024/05/GHSA-2xp3-57p7-qf4v/GHSA-2xp3-57p7-qf4v.json index a1de3438a36..47efe77a75d 100644 --- a/advisories/github-reviewed/2024/05/GHSA-2xp3-57p7-qf4v/GHSA-2xp3-57p7-qf4v.json +++ b/advisories/github-reviewed/2024/05/GHSA-2xp3-57p7-qf4v/GHSA-2xp3-57p7-qf4v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2xp3-57p7-qf4v", - "modified": "2024-05-02T19:35:35Z", + "modified": "2024-07-05T18:34:13Z", "published": "2024-05-01T17:05:53Z", "aliases": [ "CVE-2024-32962" @@ -68,6 +68,10 @@ "type": "WEB", "url": "https://github.com/node-saml/xml-crypto/discussions/399" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240705-0003" + }, { "type": "WEB", "url": "https://www.w3.org/TR/2008/REC-xmldsig-core-20080610/#sec-CoreValidation" diff --git a/advisories/unreviewed/2024/03/GHSA-q63v-rwfp-q5p2/GHSA-q63v-rwfp-q5p2.json b/advisories/unreviewed/2024/03/GHSA-q63v-rwfp-q5p2/GHSA-q63v-rwfp-q5p2.json index fbe5ff145a2..21ad87f2c47 100644 --- a/advisories/unreviewed/2024/03/GHSA-q63v-rwfp-q5p2/GHSA-q63v-rwfp-q5p2.json +++ b/advisories/unreviewed/2024/03/GHSA-q63v-rwfp-q5p2/GHSA-q63v-rwfp-q5p2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q63v-rwfp-q5p2", - "modified": "2024-07-03T18:33:40Z", + "modified": "2024-07-05T18:34:12Z", "published": "2024-03-07T12:30:26Z", "aliases": [ "CVE-2024-1931" @@ -37,6 +37,10 @@ "type": "WEB", "url": "https://lists.freebsd.org/archives/freebsd-security/2024-July/000283.html" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240705-0006" + }, { "type": "WEB", "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2024-1931.txt" diff --git a/advisories/unreviewed/2024/03/GHSA-wvcr-5p3p-5934/GHSA-wvcr-5p3p-5934.json b/advisories/unreviewed/2024/03/GHSA-wvcr-5p3p-5934/GHSA-wvcr-5p3p-5934.json index 205547f804d..7e470714b96 100644 --- a/advisories/unreviewed/2024/03/GHSA-wvcr-5p3p-5934/GHSA-wvcr-5p3p-5934.json +++ b/advisories/unreviewed/2024/03/GHSA-wvcr-5p3p-5934/GHSA-wvcr-5p3p-5934.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wvcr-5p3p-5934", - "modified": "2024-03-24T12:30:39Z", + "modified": "2024-07-05T18:34:12Z", "published": "2024-03-24T12:30:39Z", "aliases": [ "CVE-2020-36825" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/05/GHSA-2w87-6hh6-mqrj/GHSA-2w87-6hh6-mqrj.json b/advisories/unreviewed/2024/05/GHSA-2w87-6hh6-mqrj/GHSA-2w87-6hh6-mqrj.json index 0140914a89b..94d5b9522cd 100644 --- a/advisories/unreviewed/2024/05/GHSA-2w87-6hh6-mqrj/GHSA-2w87-6hh6-mqrj.json +++ b/advisories/unreviewed/2024/05/GHSA-2w87-6hh6-mqrj/GHSA-2w87-6hh6-mqrj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2w87-6hh6-mqrj", - "modified": "2024-07-03T18:39:51Z", + "modified": "2024-07-05T18:34:13Z", "published": "2024-05-07T21:31:47Z", "aliases": [ "CVE-2024-4030" @@ -76,6 +76,10 @@ { "type": "WEB", "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/PRGS5OR3N3PNPT4BMV2VAGN5GMUI5636" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240705-0005" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/06/GHSA-vfg9-hgrq-rjhq/GHSA-vfg9-hgrq-rjhq.json b/advisories/unreviewed/2024/06/GHSA-vfg9-hgrq-rjhq/GHSA-vfg9-hgrq-rjhq.json index b150537ed13..fef146daafa 100644 --- a/advisories/unreviewed/2024/06/GHSA-vfg9-hgrq-rjhq/GHSA-vfg9-hgrq-rjhq.json +++ b/advisories/unreviewed/2024/06/GHSA-vfg9-hgrq-rjhq/GHSA-vfg9-hgrq-rjhq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vfg9-hgrq-rjhq", - "modified": "2024-06-10T18:31:09Z", + "modified": "2024-07-05T18:34:13Z", "published": "2024-06-10T18:31:09Z", "aliases": [ "CVE-2024-37051" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37051" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240705-0004" + }, { "type": "WEB", "url": "https://www.jetbrains.com/privacy-security/issues-fixed" diff --git a/advisories/unreviewed/2024/07/GHSA-2m2r-m3j2-rcph/GHSA-2m2r-m3j2-rcph.json b/advisories/unreviewed/2024/07/GHSA-2m2r-m3j2-rcph/GHSA-2m2r-m3j2-rcph.json index a94d33ed083..24e19ed740b 100644 --- a/advisories/unreviewed/2024/07/GHSA-2m2r-m3j2-rcph/GHSA-2m2r-m3j2-rcph.json +++ b/advisories/unreviewed/2024/07/GHSA-2m2r-m3j2-rcph/GHSA-2m2r-m3j2-rcph.json @@ -60,7 +60,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-2v2c-wv9c-g6cm/GHSA-2v2c-wv9c-g6cm.json b/advisories/unreviewed/2024/07/GHSA-2v2c-wv9c-g6cm/GHSA-2v2c-wv9c-g6cm.json new file mode 100644 index 00000000000..de0e4a36afb --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-2v2c-wv9c-g6cm/GHSA-2v2c-wv9c-g6cm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2v2c-wv9c-g6cm", + "modified": "2024-07-05T18:34:17Z", + "published": "2024-07-05T18:34:17Z", + "aliases": [ + "CVE-2024-37769" + ], + "details": "Insecure permissions in 14Finger v1.1 allow attackers to escalate privileges from normal user to Administrator via a crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37769" + }, + { + "type": "WEB", + "url": "https://github.com/b1ackc4t/14Finger/issues/12" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-05T16:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-2wx3-jm7x-4xg5/GHSA-2wx3-jm7x-4xg5.json b/advisories/unreviewed/2024/07/GHSA-2wx3-jm7x-4xg5/GHSA-2wx3-jm7x-4xg5.json index 2878d12efa9..e2f84c2ea98 100644 --- a/advisories/unreviewed/2024/07/GHSA-2wx3-jm7x-4xg5/GHSA-2wx3-jm7x-4xg5.json +++ b/advisories/unreviewed/2024/07/GHSA-2wx3-jm7x-4xg5/GHSA-2wx3-jm7x-4xg5.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-494v-93jg-xf9g/GHSA-494v-93jg-xf9g.json b/advisories/unreviewed/2024/07/GHSA-494v-93jg-xf9g/GHSA-494v-93jg-xf9g.json index 97f84b16cab..f73f26f12b3 100644 --- a/advisories/unreviewed/2024/07/GHSA-494v-93jg-xf9g/GHSA-494v-93jg-xf9g.json +++ b/advisories/unreviewed/2024/07/GHSA-494v-93jg-xf9g/GHSA-494v-93jg-xf9g.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-287" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-4gq9-jp3j-mwwg/GHSA-4gq9-jp3j-mwwg.json b/advisories/unreviewed/2024/07/GHSA-4gq9-jp3j-mwwg/GHSA-4gq9-jp3j-mwwg.json index 645d74b2171..178d0035188 100644 --- a/advisories/unreviewed/2024/07/GHSA-4gq9-jp3j-mwwg/GHSA-4gq9-jp3j-mwwg.json +++ b/advisories/unreviewed/2024/07/GHSA-4gq9-jp3j-mwwg/GHSA-4gq9-jp3j-mwwg.json @@ -40,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-4pp4-hqhr-q59r/GHSA-4pp4-hqhr-q59r.json b/advisories/unreviewed/2024/07/GHSA-4pp4-hqhr-q59r/GHSA-4pp4-hqhr-q59r.json index 56d9243c282..a8684bab108 100644 --- a/advisories/unreviewed/2024/07/GHSA-4pp4-hqhr-q59r/GHSA-4pp4-hqhr-q59r.json +++ b/advisories/unreviewed/2024/07/GHSA-4pp4-hqhr-q59r/GHSA-4pp4-hqhr-q59r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4pp4-hqhr-q59r", - "modified": "2024-07-02T21:32:15Z", + "modified": "2024-07-05T18:34:16Z", "published": "2024-07-02T21:32:15Z", "aliases": [ "CVE-2024-25088" ], "details": "Improper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges and execute arbitrary code.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-02T16:15:04Z" diff --git a/advisories/unreviewed/2024/07/GHSA-54wv-c7pf-j4j8/GHSA-54wv-c7pf-j4j8.json b/advisories/unreviewed/2024/07/GHSA-54wv-c7pf-j4j8/GHSA-54wv-c7pf-j4j8.json new file mode 100644 index 00000000000..98445c4ed55 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-54wv-c7pf-j4j8/GHSA-54wv-c7pf-j4j8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-54wv-c7pf-j4j8", + "modified": "2024-07-05T18:34:18Z", + "published": "2024-07-05T18:34:18Z", + "aliases": [ + "CVE-2024-27716" + ], + "details": "Cross Site Scripting vulnerability in Eskooly Web Product v.3.0 and before allows a remote attacker to execute arbitrary code via the message sending and user input fields.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27716" + }, + { + "type": "WEB", + "url": "https://blog.be-hacktive.com/eskooly-cve/cve-2024-27716-cross-site-scripting-xss-in-eskooly-web-product-less-than-v3.0" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-05T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-5cg2-wmx6-ccqv/GHSA-5cg2-wmx6-ccqv.json b/advisories/unreviewed/2024/07/GHSA-5cg2-wmx6-ccqv/GHSA-5cg2-wmx6-ccqv.json index 44cc03c47e1..cd345458dcd 100644 --- a/advisories/unreviewed/2024/07/GHSA-5cg2-wmx6-ccqv/GHSA-5cg2-wmx6-ccqv.json +++ b/advisories/unreviewed/2024/07/GHSA-5cg2-wmx6-ccqv/GHSA-5cg2-wmx6-ccqv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5cg2-wmx6-ccqv", - "modified": "2024-07-03T18:48:08Z", + "modified": "2024-07-05T18:34:16Z", "published": "2024-07-03T18:48:08Z", "aliases": [ "CVE-2024-36257" diff --git a/advisories/unreviewed/2024/07/GHSA-5qj7-735j-qhqj/GHSA-5qj7-735j-qhqj.json b/advisories/unreviewed/2024/07/GHSA-5qj7-735j-qhqj/GHSA-5qj7-735j-qhqj.json new file mode 100644 index 00000000000..5b517541f39 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-5qj7-735j-qhqj/GHSA-5qj7-735j-qhqj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5qj7-735j-qhqj", + "modified": "2024-07-05T18:34:17Z", + "published": "2024-07-05T18:34:17Z", + "aliases": [ + "CVE-2024-29318" + ], + "details": "Volmarg Personal Management System 1.4.64 is vulnerable to stored cross site scripting (XSS) via upload of a SVG file with embedded javascript code.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29318" + }, + { + "type": "WEB", + "url": "https://github.com/b-hermes/vulnerability-research/tree/main/CVE-2024-29318" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-05T16:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-6cj7-cwrr-q8fr/GHSA-6cj7-cwrr-q8fr.json b/advisories/unreviewed/2024/07/GHSA-6cj7-cwrr-q8fr/GHSA-6cj7-cwrr-q8fr.json index 587088c0d2e..7c5fb25f082 100644 --- a/advisories/unreviewed/2024/07/GHSA-6cj7-cwrr-q8fr/GHSA-6cj7-cwrr-q8fr.json +++ b/advisories/unreviewed/2024/07/GHSA-6cj7-cwrr-q8fr/GHSA-6cj7-cwrr-q8fr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6cj7-cwrr-q8fr", - "modified": "2024-07-02T21:32:14Z", + "modified": "2024-07-05T18:34:14Z", "published": "2024-07-02T21:32:14Z", "aliases": [ "CVE-2023-51776" ], "details": "Improper privilege management in Jungo WinDriver before 12.1.0 allows local attackers to escalate privileges and execute arbitrary code.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-02T15:15:10Z" diff --git a/advisories/unreviewed/2024/07/GHSA-6jcx-jf58-7hch/GHSA-6jcx-jf58-7hch.json b/advisories/unreviewed/2024/07/GHSA-6jcx-jf58-7hch/GHSA-6jcx-jf58-7hch.json index f3bae422be9..51fd5df6a25 100644 --- a/advisories/unreviewed/2024/07/GHSA-6jcx-jf58-7hch/GHSA-6jcx-jf58-7hch.json +++ b/advisories/unreviewed/2024/07/GHSA-6jcx-jf58-7hch/GHSA-6jcx-jf58-7hch.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6jcx-jf58-7hch", - "modified": "2024-07-02T21:32:14Z", + "modified": "2024-07-05T18:34:14Z", "published": "2024-07-02T21:32:14Z", "aliases": [ "CVE-2023-51778" ], "details": "Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.1.0 allows local attackers to cause a Windows blue screen error and Denial of Service (DoS).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-02T15:15:10Z" diff --git a/advisories/unreviewed/2024/07/GHSA-76jf-55hx-4969/GHSA-76jf-55hx-4969.json b/advisories/unreviewed/2024/07/GHSA-76jf-55hx-4969/GHSA-76jf-55hx-4969.json index 5d7f4579571..a9a200ac5ee 100644 --- a/advisories/unreviewed/2024/07/GHSA-76jf-55hx-4969/GHSA-76jf-55hx-4969.json +++ b/advisories/unreviewed/2024/07/GHSA-76jf-55hx-4969/GHSA-76jf-55hx-4969.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-76jf-55hx-4969", - "modified": "2024-07-03T18:48:09Z", + "modified": "2024-07-05T18:34:16Z", "published": "2024-07-03T18:48:09Z", "aliases": [ "CVE-2024-39361" diff --git a/advisories/unreviewed/2024/07/GHSA-927f-2f7r-vg99/GHSA-927f-2f7r-vg99.json b/advisories/unreviewed/2024/07/GHSA-927f-2f7r-vg99/GHSA-927f-2f7r-vg99.json new file mode 100644 index 00000000000..4ad6bd62324 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-927f-2f7r-vg99/GHSA-927f-2f7r-vg99.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-927f-2f7r-vg99", + "modified": "2024-07-05T18:34:18Z", + "published": "2024-07-05T18:34:17Z", + "aliases": [ + "CVE-2024-39210" + ], + "details": "Best House Rental Management System v1.0 was discovered to contain an arbitrary file read vulnerability via the Page parameter at index.php. This vulnerability allows attackers to read arbitrary PHP files and access other sensitive information within the application.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39210" + }, + { + "type": "WEB", + "url": "https://github.com/KRookieSec/CVE-2024-39210" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-05T16:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-98p3-57xf-2q44/GHSA-98p3-57xf-2q44.json b/advisories/unreviewed/2024/07/GHSA-98p3-57xf-2q44/GHSA-98p3-57xf-2q44.json index 376c1f2ef2f..d40fd7ac114 100644 --- a/advisories/unreviewed/2024/07/GHSA-98p3-57xf-2q44/GHSA-98p3-57xf-2q44.json +++ b/advisories/unreviewed/2024/07/GHSA-98p3-57xf-2q44/GHSA-98p3-57xf-2q44.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-98p3-57xf-2q44", - "modified": "2024-07-02T21:32:15Z", + "modified": "2024-07-05T18:34:16Z", "published": "2024-07-02T21:32:15Z", "aliases": [ "CVE-2024-25086" ], "details": "Improper privilege management in Jungo WinDriver before 12.2.0 allows local attackers to escalate privileges and execute arbitrary code.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-02T16:15:04Z" diff --git a/advisories/unreviewed/2024/07/GHSA-9gf4-mq65-qx36/GHSA-9gf4-mq65-qx36.json b/advisories/unreviewed/2024/07/GHSA-9gf4-mq65-qx36/GHSA-9gf4-mq65-qx36.json index 16539c4e268..0bc424bcf0c 100644 --- a/advisories/unreviewed/2024/07/GHSA-9gf4-mq65-qx36/GHSA-9gf4-mq65-qx36.json +++ b/advisories/unreviewed/2024/07/GHSA-9gf4-mq65-qx36/GHSA-9gf4-mq65-qx36.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-287" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-9jxr-3g3h-9m36/GHSA-9jxr-3g3h-9m36.json b/advisories/unreviewed/2024/07/GHSA-9jxr-3g3h-9m36/GHSA-9jxr-3g3h-9m36.json new file mode 100644 index 00000000000..5b5f6fb1beb --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-9jxr-3g3h-9m36/GHSA-9jxr-3g3h-9m36.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9jxr-3g3h-9m36", + "modified": "2024-07-05T18:34:17Z", + "published": "2024-07-05T18:34:17Z", + "aliases": [ + "CVE-2024-23997" + ], + "details": "Lukas Bach yana =<1.0.16 is vulnerable to Cross Site Scripting (XSS) via src/electron-main.ts.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23997" + }, + { + "type": "WEB", + "url": "https://github.com/EQSTLab/PoC/tree/main/2024/LCE/CVE-2024-23997" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-05T16:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-9xcq-99h4-2ffj/GHSA-9xcq-99h4-2ffj.json b/advisories/unreviewed/2024/07/GHSA-9xcq-99h4-2ffj/GHSA-9xcq-99h4-2ffj.json new file mode 100644 index 00000000000..69a6eaf3af7 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-9xcq-99h4-2ffj/GHSA-9xcq-99h4-2ffj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9xcq-99h4-2ffj", + "modified": "2024-07-05T18:34:18Z", + "published": "2024-07-05T18:34:18Z", + "aliases": [ + "CVE-2024-27717" + ], + "details": "Cross Site Request Forgery vulnerability in Eskooly Free Online School Management Software v.3.0 and before allows a remote attacker to escalate privileges via the Token Handling component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27717" + }, + { + "type": "WEB", + "url": "https://blog.be-hacktive.com/eskooly-cve/cve-2024-27717-cross-site-request-forgery-csrf-in-eskooly-web-product-less-than-v3.0" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-05T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-c4xw-jcqw-fwfx/GHSA-c4xw-jcqw-fwfx.json b/advisories/unreviewed/2024/07/GHSA-c4xw-jcqw-fwfx/GHSA-c4xw-jcqw-fwfx.json index b6512ef5fd9..e149632cd45 100644 --- a/advisories/unreviewed/2024/07/GHSA-c4xw-jcqw-fwfx/GHSA-c4xw-jcqw-fwfx.json +++ b/advisories/unreviewed/2024/07/GHSA-c4xw-jcqw-fwfx/GHSA-c4xw-jcqw-fwfx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c4xw-jcqw-fwfx", - "modified": "2024-07-02T21:32:15Z", + "modified": "2024-07-05T18:34:16Z", "published": "2024-07-02T21:32:14Z", "aliases": [ "CVE-2024-25087" ], "details": "Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.7.0 allows local attackers to cause a Windows blue screen error.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-02T16:15:04Z" diff --git a/advisories/unreviewed/2024/07/GHSA-c54q-7px7-pfhr/GHSA-c54q-7px7-pfhr.json b/advisories/unreviewed/2024/07/GHSA-c54q-7px7-pfhr/GHSA-c54q-7px7-pfhr.json index 6ecadddd299..92b6143b3fa 100644 --- a/advisories/unreviewed/2024/07/GHSA-c54q-7px7-pfhr/GHSA-c54q-7px7-pfhr.json +++ b/advisories/unreviewed/2024/07/GHSA-c54q-7px7-pfhr/GHSA-c54q-7px7-pfhr.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-c62q-jr5r-r7x2/GHSA-c62q-jr5r-r7x2.json b/advisories/unreviewed/2024/07/GHSA-c62q-jr5r-r7x2/GHSA-c62q-jr5r-r7x2.json index 2601430d045..af8022b958c 100644 --- a/advisories/unreviewed/2024/07/GHSA-c62q-jr5r-r7x2/GHSA-c62q-jr5r-r7x2.json +++ b/advisories/unreviewed/2024/07/GHSA-c62q-jr5r-r7x2/GHSA-c62q-jr5r-r7x2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c62q-jr5r-r7x2", - "modified": "2024-07-02T21:32:14Z", + "modified": "2024-07-05T18:34:14Z", "published": "2024-07-02T21:32:14Z", "aliases": [ "CVE-2024-22102" ], "details": "Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.6.0 allows local attackers to cause a Windows blue screen error.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-02T15:15:11Z" diff --git a/advisories/unreviewed/2024/07/GHSA-ccvr-35jj-hp58/GHSA-ccvr-35jj-hp58.json b/advisories/unreviewed/2024/07/GHSA-ccvr-35jj-hp58/GHSA-ccvr-35jj-hp58.json index e44c34c5ff0..9a92a1d3e0a 100644 --- a/advisories/unreviewed/2024/07/GHSA-ccvr-35jj-hp58/GHSA-ccvr-35jj-hp58.json +++ b/advisories/unreviewed/2024/07/GHSA-ccvr-35jj-hp58/GHSA-ccvr-35jj-hp58.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ccvr-35jj-hp58", - "modified": "2024-07-02T21:32:15Z", + "modified": "2024-07-05T18:34:16Z", "published": "2024-07-02T21:32:15Z", "aliases": [ "CVE-2024-26314" ], "details": "Improper privilege management in Jungo WinDriver 6.0.0 through 16.1.0 allows local attackers to escalate privileges and execute arbitrary code.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-02T16:15:04Z" diff --git a/advisories/unreviewed/2024/07/GHSA-cpq6-cgjp-6336/GHSA-cpq6-cgjp-6336.json b/advisories/unreviewed/2024/07/GHSA-cpq6-cgjp-6336/GHSA-cpq6-cgjp-6336.json new file mode 100644 index 00000000000..00860263db2 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-cpq6-cgjp-6336/GHSA-cpq6-cgjp-6336.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cpq6-cgjp-6336", + "modified": "2024-07-05T18:34:18Z", + "published": "2024-07-05T18:34:18Z", + "aliases": [ + "CVE-2024-27712" + ], + "details": "An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via the User Account Mangemnt component in the authentication mechanism.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27712" + }, + { + "type": "WEB", + "url": "https://blog.be-hacktive.com/eskooly-cve/eskooly-broken-authentication/cve-2024-27712-user-enumeration-via-account-settings-in-eskooly-web-product-less-than-v3.0" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-05T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-cwgg-8r68-xgqc/GHSA-cwgg-8r68-xgqc.json b/advisories/unreviewed/2024/07/GHSA-cwgg-8r68-xgqc/GHSA-cwgg-8r68-xgqc.json new file mode 100644 index 00000000000..9c1d4b69ee2 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-cwgg-8r68-xgqc/GHSA-cwgg-8r68-xgqc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cwgg-8r68-xgqc", + "modified": "2024-07-05T18:34:18Z", + "published": "2024-07-05T18:34:18Z", + "aliases": [ + "CVE-2024-27710" + ], + "details": "An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via the authentication mechanism.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27710" + }, + { + "type": "WEB", + "url": "https://blog.be-hacktive.com/eskooly-cve/eskooly-broken-authentication/cve-2024-27710-privilege-escalation-via-authentication-mechanism-in-eskooly-web-product-less-than-v3" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-05T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-f33q-f757-3cjh/GHSA-f33q-f757-3cjh.json b/advisories/unreviewed/2024/07/GHSA-f33q-f757-3cjh/GHSA-f33q-f757-3cjh.json new file mode 100644 index 00000000000..8048898bd4c --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-f33q-f757-3cjh/GHSA-f33q-f757-3cjh.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f33q-f757-3cjh", + "modified": "2024-07-05T18:34:17Z", + "published": "2024-07-05T18:34:17Z", + "aliases": [ + "CVE-2024-37768" + ], + "details": "14Finger v1.1 was discovered to contain an arbitrary user deletion vulnerability via the component /api/admin/user?id.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37768" + }, + { + "type": "WEB", + "url": "https://github.com/b1ackc4t/14Finger/issues/12" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-05T16:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-fc2h-j9fj-rh35/GHSA-fc2h-j9fj-rh35.json b/advisories/unreviewed/2024/07/GHSA-fc2h-j9fj-rh35/GHSA-fc2h-j9fj-rh35.json index bca42a9bfde..ddf6e4df713 100644 --- a/advisories/unreviewed/2024/07/GHSA-fc2h-j9fj-rh35/GHSA-fc2h-j9fj-rh35.json +++ b/advisories/unreviewed/2024/07/GHSA-fc2h-j9fj-rh35/GHSA-fc2h-j9fj-rh35.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fc2h-j9fj-rh35", - "modified": "2024-07-03T18:48:11Z", + "modified": "2024-07-05T18:34:17Z", "published": "2024-07-03T18:48:11Z", "aliases": [ "CVE-2024-39807" diff --git a/advisories/unreviewed/2024/07/GHSA-fmjc-52jw-jgcm/GHSA-fmjc-52jw-jgcm.json b/advisories/unreviewed/2024/07/GHSA-fmjc-52jw-jgcm/GHSA-fmjc-52jw-jgcm.json index 91803b5fc27..083e4ba5331 100644 --- a/advisories/unreviewed/2024/07/GHSA-fmjc-52jw-jgcm/GHSA-fmjc-52jw-jgcm.json +++ b/advisories/unreviewed/2024/07/GHSA-fmjc-52jw-jgcm/GHSA-fmjc-52jw-jgcm.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-g9g3-2xqr-578p/GHSA-g9g3-2xqr-578p.json b/advisories/unreviewed/2024/07/GHSA-g9g3-2xqr-578p/GHSA-g9g3-2xqr-578p.json new file mode 100644 index 00000000000..487bfaa3dcf --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-g9g3-2xqr-578p/GHSA-g9g3-2xqr-578p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g9g3-2xqr-578p", + "modified": "2024-07-05T18:34:17Z", + "published": "2024-07-05T18:34:17Z", + "aliases": [ + "CVE-2024-23998" + ], + "details": "goanother Another Redis Desktop Manager =<1.6.1 is vulnerable to Cross Site Scripting (XSS) via src/components/Setting.vue.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23998" + }, + { + "type": "WEB", + "url": "https://github.com/EQSTLab/PoC/tree/main/2024/LCE/CVE-2024-23998" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-05T16:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-gvc5-fjqh-5h22/GHSA-gvc5-fjqh-5h22.json b/advisories/unreviewed/2024/07/GHSA-gvc5-fjqh-5h22/GHSA-gvc5-fjqh-5h22.json new file mode 100644 index 00000000000..dce8a9e9f4e --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-gvc5-fjqh-5h22/GHSA-gvc5-fjqh-5h22.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gvc5-fjqh-5h22", + "modified": "2024-07-05T18:34:18Z", + "published": "2024-07-05T18:34:18Z", + "aliases": [ + "CVE-2024-27713" + ], + "details": "An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via the HTTP Response Header Settings component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27713" + }, + { + "type": "WEB", + "url": "https://blog.be-hacktive.com/eskooly-cve/cve-2024-27713-protection-mechanism-failure-in-eskooly-web-product-less-than-v3.0" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-05T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-gx7h-6gpw-mrqc/GHSA-gx7h-6gpw-mrqc.json b/advisories/unreviewed/2024/07/GHSA-gx7h-6gpw-mrqc/GHSA-gx7h-6gpw-mrqc.json index bc6f2fafc81..e2c16eb2115 100644 --- a/advisories/unreviewed/2024/07/GHSA-gx7h-6gpw-mrqc/GHSA-gx7h-6gpw-mrqc.json +++ b/advisories/unreviewed/2024/07/GHSA-gx7h-6gpw-mrqc/GHSA-gx7h-6gpw-mrqc.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-h747-q33x-7xxp/GHSA-h747-q33x-7xxp.json b/advisories/unreviewed/2024/07/GHSA-h747-q33x-7xxp/GHSA-h747-q33x-7xxp.json new file mode 100644 index 00000000000..62dbfe6b7db --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-h747-q33x-7xxp/GHSA-h747-q33x-7xxp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h747-q33x-7xxp", + "modified": "2024-07-05T18:34:18Z", + "published": "2024-07-05T18:34:18Z", + "aliases": [ + "CVE-2024-39178" + ], + "details": "MyPower vc8100 V100R001C00B030 was discovered to contain an arbitrary file read vulnerability via the component /tcpdump/tcpdump.php?menu_uuid.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39178" + }, + { + "type": "WEB", + "url": "https://github.com/WarmBrew/web_vul/blob/main/Maipu/MyPower%20vc8100/MyPower_vc8100.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-05T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-hx8j-p33g-vmxv/GHSA-hx8j-p33g-vmxv.json b/advisories/unreviewed/2024/07/GHSA-hx8j-p33g-vmxv/GHSA-hx8j-p33g-vmxv.json new file mode 100644 index 00000000000..0a89978227f --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-hx8j-p33g-vmxv/GHSA-hx8j-p33g-vmxv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hx8j-p33g-vmxv", + "modified": "2024-07-05T18:34:17Z", + "published": "2024-07-05T18:34:17Z", + "aliases": [ + "CVE-2024-29319" + ], + "details": "Volmarg Personal Management System 1.4.64 is vulnerable to SSRF (Server Side Request Forgery) via uploading a SVG file. The server can make unintended HTTP and DNS requests to a server that the attacker controls.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29319" + }, + { + "type": "WEB", + "url": "https://github.com/b-hermes/vulnerability-research/tree/main/CVE-2024-29319" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-05T16:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-j9f4-63gf-c7rj/GHSA-j9f4-63gf-c7rj.json b/advisories/unreviewed/2024/07/GHSA-j9f4-63gf-c7rj/GHSA-j9f4-63gf-c7rj.json index 60666a5c1e7..15c781c8259 100644 --- a/advisories/unreviewed/2024/07/GHSA-j9f4-63gf-c7rj/GHSA-j9f4-63gf-c7rj.json +++ b/advisories/unreviewed/2024/07/GHSA-j9f4-63gf-c7rj/GHSA-j9f4-63gf-c7rj.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-m55r-6g9c-6v6w/GHSA-m55r-6g9c-6v6w.json b/advisories/unreviewed/2024/07/GHSA-m55r-6g9c-6v6w/GHSA-m55r-6g9c-6v6w.json index db89f57fdd9..31f889855f8 100644 --- a/advisories/unreviewed/2024/07/GHSA-m55r-6g9c-6v6w/GHSA-m55r-6g9c-6v6w.json +++ b/advisories/unreviewed/2024/07/GHSA-m55r-6g9c-6v6w/GHSA-m55r-6g9c-6v6w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m55r-6g9c-6v6w", - "modified": "2024-07-02T21:32:14Z", + "modified": "2024-07-05T18:34:14Z", "published": "2024-07-02T21:32:14Z", "aliases": [ "CVE-2023-51777" ], "details": "Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.1.0 allows local attackers to cause a Windows blue screen error.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-02T15:15:10Z" diff --git a/advisories/unreviewed/2024/07/GHSA-mg7v-q6g4-qfqr/GHSA-mg7v-q6g4-qfqr.json b/advisories/unreviewed/2024/07/GHSA-mg7v-q6g4-qfqr/GHSA-mg7v-q6g4-qfqr.json index 357cc348e9c..2091553eec0 100644 --- a/advisories/unreviewed/2024/07/GHSA-mg7v-q6g4-qfqr/GHSA-mg7v-q6g4-qfqr.json +++ b/advisories/unreviewed/2024/07/GHSA-mg7v-q6g4-qfqr/GHSA-mg7v-q6g4-qfqr.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-755" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-mhfm-4h29-4r45/GHSA-mhfm-4h29-4r45.json b/advisories/unreviewed/2024/07/GHSA-mhfm-4h29-4r45/GHSA-mhfm-4h29-4r45.json index b826e9872dd..d84223a7bba 100644 --- a/advisories/unreviewed/2024/07/GHSA-mhfm-4h29-4r45/GHSA-mhfm-4h29-4r45.json +++ b/advisories/unreviewed/2024/07/GHSA-mhfm-4h29-4r45/GHSA-mhfm-4h29-4r45.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-347" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-p36x-j8pc-9vcr/GHSA-p36x-j8pc-9vcr.json b/advisories/unreviewed/2024/07/GHSA-p36x-j8pc-9vcr/GHSA-p36x-j8pc-9vcr.json new file mode 100644 index 00000000000..12b1d68d1d0 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-p36x-j8pc-9vcr/GHSA-p36x-j8pc-9vcr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p36x-j8pc-9vcr", + "modified": "2024-07-05T18:34:18Z", + "published": "2024-07-05T18:34:18Z", + "aliases": [ + "CVE-2024-37767" + ], + "details": "Insecure permissions in the component /api/admin/user of 14Finger v1.1 allows attackers to access all user information via a crafted GET request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37767" + }, + { + "type": "WEB", + "url": "https://github.com/b1ackc4t/14Finger/issues/12" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-05T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-pffg-mp75-j28h/GHSA-pffg-mp75-j28h.json b/advisories/unreviewed/2024/07/GHSA-pffg-mp75-j28h/GHSA-pffg-mp75-j28h.json new file mode 100644 index 00000000000..39c616ee591 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-pffg-mp75-j28h/GHSA-pffg-mp75-j28h.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pffg-mp75-j28h", + "modified": "2024-07-05T18:34:17Z", + "published": "2024-07-05T18:34:17Z", + "aliases": [ + "CVE-2024-27709" + ], + "details": "SQL Injection vulnerability in Eskooly Web Product v.3.0 allows a remote attacker to execute arbitrary code via the searchby parameter of the allstudents.php component and the id parameter of the requestmanager.php component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27709" + }, + { + "type": "WEB", + "url": "https://blog.be-hacktive.com/eskooly-cve/cve-2024-27709-sql-injection-in-eskooly-web-product-v.3.0" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-05T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-pqhg-95v7-rfjf/GHSA-pqhg-95v7-rfjf.json b/advisories/unreviewed/2024/07/GHSA-pqhg-95v7-rfjf/GHSA-pqhg-95v7-rfjf.json new file mode 100644 index 00000000000..27ab94f7fed --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-pqhg-95v7-rfjf/GHSA-pqhg-95v7-rfjf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pqhg-95v7-rfjf", + "modified": "2024-07-05T18:34:18Z", + "published": "2024-07-05T18:34:18Z", + "aliases": [ + "CVE-2024-39174" + ], + "details": "A cross-site scripting (XSS) vulnerability in the Publish Article function of yzmcms v7.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into a published article.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39174" + }, + { + "type": "WEB", + "url": "https://github.com/0x1ang/cvepbulic/issues/1" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-05T18:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-pwxq-7mcj-42pj/GHSA-pwxq-7mcj-42pj.json b/advisories/unreviewed/2024/07/GHSA-pwxq-7mcj-42pj/GHSA-pwxq-7mcj-42pj.json index c4e38491d5c..bc0c9a83672 100644 --- a/advisories/unreviewed/2024/07/GHSA-pwxq-7mcj-42pj/GHSA-pwxq-7mcj-42pj.json +++ b/advisories/unreviewed/2024/07/GHSA-pwxq-7mcj-42pj/GHSA-pwxq-7mcj-42pj.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-287" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-q45p-9x4j-2gjf/GHSA-q45p-9x4j-2gjf.json b/advisories/unreviewed/2024/07/GHSA-q45p-9x4j-2gjf/GHSA-q45p-9x4j-2gjf.json new file mode 100644 index 00000000000..522e64c21b1 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-q45p-9x4j-2gjf/GHSA-q45p-9x4j-2gjf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q45p-9x4j-2gjf", + "modified": "2024-07-05T18:34:18Z", + "published": "2024-07-05T18:34:18Z", + "aliases": [ + "CVE-2024-27715" + ], + "details": "An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via a crafted request to the Password Change mechanism.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27715" + }, + { + "type": "WEB", + "url": "https://blog.be-hacktive.com/eskooly-cve/cve-2024-27715-inadequate-password-update-verification-in-eskooly-web-product-less-than-v3.0" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-05T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-qgq4-8q2v-ggw6/GHSA-qgq4-8q2v-ggw6.json b/advisories/unreviewed/2024/07/GHSA-qgq4-8q2v-ggw6/GHSA-qgq4-8q2v-ggw6.json index 63a3164a9fe..ab81a771a80 100644 --- a/advisories/unreviewed/2024/07/GHSA-qgq4-8q2v-ggw6/GHSA-qgq4-8q2v-ggw6.json +++ b/advisories/unreviewed/2024/07/GHSA-qgq4-8q2v-ggw6/GHSA-qgq4-8q2v-ggw6.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-qp2p-hqhr-hrw4/GHSA-qp2p-hqhr-hrw4.json b/advisories/unreviewed/2024/07/GHSA-qp2p-hqhr-hrw4/GHSA-qp2p-hqhr-hrw4.json index 4de9b29e1c5..dffc2a102ef 100644 --- a/advisories/unreviewed/2024/07/GHSA-qp2p-hqhr-hrw4/GHSA-qp2p-hqhr-hrw4.json +++ b/advisories/unreviewed/2024/07/GHSA-qp2p-hqhr-hrw4/GHSA-qp2p-hqhr-hrw4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qp2p-hqhr-hrw4", - "modified": "2024-07-02T21:32:14Z", + "modified": "2024-07-05T18:34:15Z", "published": "2024-07-02T21:32:14Z", "aliases": [ "CVE-2024-22105" ], "details": "Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.5.1 allows local attackers to cause a Windows blue screen error.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-02T16:15:03Z" diff --git a/advisories/unreviewed/2024/07/GHSA-qwjr-hp4h-rmwf/GHSA-qwjr-hp4h-rmwf.json b/advisories/unreviewed/2024/07/GHSA-qwjr-hp4h-rmwf/GHSA-qwjr-hp4h-rmwf.json new file mode 100644 index 00000000000..ffa6847cd98 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-qwjr-hp4h-rmwf/GHSA-qwjr-hp4h-rmwf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qwjr-hp4h-rmwf", + "modified": "2024-07-05T18:34:18Z", + "published": "2024-07-05T18:34:18Z", + "aliases": [ + "CVE-2024-39150" + ], + "details": "vditor v.3.9.8 and before is vulnerable to Arbitrary file read via a crafted data packet.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39150" + }, + { + "type": "WEB", + "url": "https://b3log.org/vditor" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-05T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-vmvm-jjvw-qwpw/GHSA-vmvm-jjvw-qwpw.json b/advisories/unreviewed/2024/07/GHSA-vmvm-jjvw-qwpw/GHSA-vmvm-jjvw-qwpw.json index 9cc39e4fb5b..aa8242ef6c9 100644 --- a/advisories/unreviewed/2024/07/GHSA-vmvm-jjvw-qwpw/GHSA-vmvm-jjvw-qwpw.json +++ b/advisories/unreviewed/2024/07/GHSA-vmvm-jjvw-qwpw/GHSA-vmvm-jjvw-qwpw.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-203", "CWE-287" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/07/GHSA-w388-4xq6-fqmw/GHSA-w388-4xq6-fqmw.json b/advisories/unreviewed/2024/07/GHSA-w388-4xq6-fqmw/GHSA-w388-4xq6-fqmw.json index ab51a54cdc5..c5f0cc8ae69 100644 --- a/advisories/unreviewed/2024/07/GHSA-w388-4xq6-fqmw/GHSA-w388-4xq6-fqmw.json +++ b/advisories/unreviewed/2024/07/GHSA-w388-4xq6-fqmw/GHSA-w388-4xq6-fqmw.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-w963-c33v-9fmc/GHSA-w963-c33v-9fmc.json b/advisories/unreviewed/2024/07/GHSA-w963-c33v-9fmc/GHSA-w963-c33v-9fmc.json index 74a6fb7a27c..917b3775288 100644 --- a/advisories/unreviewed/2024/07/GHSA-w963-c33v-9fmc/GHSA-w963-c33v-9fmc.json +++ b/advisories/unreviewed/2024/07/GHSA-w963-c33v-9fmc/GHSA-w963-c33v-9fmc.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1333" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-x4p5-hg55-839v/GHSA-x4p5-hg55-839v.json b/advisories/unreviewed/2024/07/GHSA-x4p5-hg55-839v/GHSA-x4p5-hg55-839v.json index 632eaaed533..ad5780346d3 100644 --- a/advisories/unreviewed/2024/07/GHSA-x4p5-hg55-839v/GHSA-x4p5-hg55-839v.json +++ b/advisories/unreviewed/2024/07/GHSA-x4p5-hg55-839v/GHSA-x4p5-hg55-839v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x4p5-hg55-839v", - "modified": "2024-07-02T21:32:14Z", + "modified": "2024-07-05T18:34:15Z", "published": "2024-07-02T21:32:14Z", "aliases": [ "CVE-2024-22104" ], "details": "Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.5.1 allows local attackers to cause a Windows blue screen error and Denial of Service (DoS).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-02T15:15:11Z" diff --git a/advisories/unreviewed/2024/07/GHSA-xqmv-67w6-p3wm/GHSA-xqmv-67w6-p3wm.json b/advisories/unreviewed/2024/07/GHSA-xqmv-67w6-p3wm/GHSA-xqmv-67w6-p3wm.json new file mode 100644 index 00000000000..db203f990d9 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-xqmv-67w6-p3wm/GHSA-xqmv-67w6-p3wm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xqmv-67w6-p3wm", + "modified": "2024-07-05T18:34:18Z", + "published": "2024-07-05T18:34:18Z", + "aliases": [ + "CVE-2024-27711" + ], + "details": "An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via the Sin-up process function in the account settings.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27711" + }, + { + "type": "WEB", + "url": "https://blog.be-hacktive.com/eskooly-cve/eskooly-broken-authentication/cve-2024-27711-user-enumeration-via-sign-up-process-in-eskooly-web-product-less-than-v3.0" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-05T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-xxqj-x2pv-x5jj/GHSA-xxqj-x2pv-x5jj.json b/advisories/unreviewed/2024/07/GHSA-xxqj-x2pv-x5jj/GHSA-xxqj-x2pv-x5jj.json index 183b2ae6fe4..1ffd1c43a3f 100644 --- a/advisories/unreviewed/2024/07/GHSA-xxqj-x2pv-x5jj/GHSA-xxqj-x2pv-x5jj.json +++ b/advisories/unreviewed/2024/07/GHSA-xxqj-x2pv-x5jj/GHSA-xxqj-x2pv-x5jj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xxqj-x2pv-x5jj", - "modified": "2024-07-03T18:48:14Z", + "modified": "2024-07-05T18:34:17Z", "published": "2024-07-03T18:48:14Z", "aliases": [ "CVE-2024-6427" @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-770" ], "severity": "HIGH", "github_reviewed": false,