diff --git a/advisories/unreviewed/2024/01/GHSA-4658-4qfx-9295/GHSA-4658-4qfx-9295.json b/advisories/unreviewed/2024/01/GHSA-4658-4qfx-9295/GHSA-4658-4qfx-9295.json index 4bb1dbd8b6a..82a0842b49a 100644 --- a/advisories/unreviewed/2024/01/GHSA-4658-4qfx-9295/GHSA-4658-4qfx-9295.json +++ b/advisories/unreviewed/2024/01/GHSA-4658-4qfx-9295/GHSA-4658-4qfx-9295.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-9h6f-343x-p726/GHSA-9h6f-343x-p726.json b/advisories/unreviewed/2024/01/GHSA-9h6f-343x-p726/GHSA-9h6f-343x-p726.json index ed2c46be5b2..54c4a08b2e8 100644 --- a/advisories/unreviewed/2024/01/GHSA-9h6f-343x-p726/GHSA-9h6f-343x-p726.json +++ b/advisories/unreviewed/2024/01/GHSA-9h6f-343x-p726/GHSA-9h6f-343x-p726.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9h6f-343x-p726", - "modified": "2024-01-19T21:30:35Z", + "modified": "2024-08-30T21:31:39Z", "published": "2024-01-17T00:30:19Z", "aliases": [ "CVE-2023-52042" @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-mj4q-j8hp-mw73/GHSA-mj4q-j8hp-mw73.json b/advisories/unreviewed/2024/01/GHSA-mj4q-j8hp-mw73/GHSA-mj4q-j8hp-mw73.json index 5ba0dd22236..7bdf190f7f2 100644 --- a/advisories/unreviewed/2024/01/GHSA-mj4q-j8hp-mw73/GHSA-mj4q-j8hp-mw73.json +++ b/advisories/unreviewed/2024/01/GHSA-mj4q-j8hp-mw73/GHSA-mj4q-j8hp-mw73.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mj4q-j8hp-mw73", - "modified": "2024-01-23T15:30:57Z", + "modified": "2024-08-30T21:31:39Z", "published": "2024-01-16T18:31:10Z", "aliases": [ "CVE-2023-5558" diff --git a/advisories/unreviewed/2024/01/GHSA-mx5q-46h2-qqfw/GHSA-mx5q-46h2-qqfw.json b/advisories/unreviewed/2024/01/GHSA-mx5q-46h2-qqfw/GHSA-mx5q-46h2-qqfw.json index 740c55de269..8f2aa3944f6 100644 --- a/advisories/unreviewed/2024/01/GHSA-mx5q-46h2-qqfw/GHSA-mx5q-46h2-qqfw.json +++ b/advisories/unreviewed/2024/01/GHSA-mx5q-46h2-qqfw/GHSA-mx5q-46h2-qqfw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mx5q-46h2-qqfw", - "modified": "2024-01-23T18:31:11Z", + "modified": "2024-08-30T21:31:39Z", "published": "2024-01-16T18:31:10Z", "aliases": [ "CVE-2023-7154" diff --git a/advisories/unreviewed/2024/06/GHSA-336q-x7w8-cw7q/GHSA-336q-x7w8-cw7q.json b/advisories/unreviewed/2024/06/GHSA-336q-x7w8-cw7q/GHSA-336q-x7w8-cw7q.json index 5de60474132..b1d5c34760b 100644 --- a/advisories/unreviewed/2024/06/GHSA-336q-x7w8-cw7q/GHSA-336q-x7w8-cw7q.json +++ b/advisories/unreviewed/2024/06/GHSA-336q-x7w8-cw7q/GHSA-336q-x7w8-cw7q.json @@ -44,7 +44,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-4q2x-2wp6-7jhh/GHSA-4q2x-2wp6-7jhh.json b/advisories/unreviewed/2024/06/GHSA-4q2x-2wp6-7jhh/GHSA-4q2x-2wp6-7jhh.json index 8c74386c2b6..57207c706e9 100644 --- a/advisories/unreviewed/2024/06/GHSA-4q2x-2wp6-7jhh/GHSA-4q2x-2wp6-7jhh.json +++ b/advisories/unreviewed/2024/06/GHSA-4q2x-2wp6-7jhh/GHSA-4q2x-2wp6-7jhh.json @@ -44,7 +44,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-m9m5-hfmm-xp78/GHSA-m9m5-hfmm-xp78.json b/advisories/unreviewed/2024/07/GHSA-m9m5-hfmm-xp78/GHSA-m9m5-hfmm-xp78.json index 513addeb11b..b41620954c9 100644 --- a/advisories/unreviewed/2024/07/GHSA-m9m5-hfmm-xp78/GHSA-m9m5-hfmm-xp78.json +++ b/advisories/unreviewed/2024/07/GHSA-m9m5-hfmm-xp78/GHSA-m9m5-hfmm-xp78.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m9m5-hfmm-xp78", - "modified": "2024-07-21T09:30:31Z", + "modified": "2024-08-30T21:31:39Z", "published": "2024-07-21T09:30:31Z", "aliases": [ "CVE-2024-37536" diff --git a/advisories/unreviewed/2024/07/GHSA-x64v-pq34-g3cq/GHSA-x64v-pq34-g3cq.json b/advisories/unreviewed/2024/07/GHSA-x64v-pq34-g3cq/GHSA-x64v-pq34-g3cq.json index 57ff2916fe6..6e1e08400ef 100644 --- a/advisories/unreviewed/2024/07/GHSA-x64v-pq34-g3cq/GHSA-x64v-pq34-g3cq.json +++ b/advisories/unreviewed/2024/07/GHSA-x64v-pq34-g3cq/GHSA-x64v-pq34-g3cq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x64v-pq34-g3cq", - "modified": "2024-07-21T09:30:32Z", + "modified": "2024-08-30T21:31:40Z", "published": "2024-07-21T09:30:32Z", "aliases": [ "CVE-2024-38435" diff --git a/advisories/unreviewed/2024/08/GHSA-4h6p-wphh-f8rf/GHSA-4h6p-wphh-f8rf.json b/advisories/unreviewed/2024/08/GHSA-4h6p-wphh-f8rf/GHSA-4h6p-wphh-f8rf.json index 4743da15075..fc3bc194997 100644 --- a/advisories/unreviewed/2024/08/GHSA-4h6p-wphh-f8rf/GHSA-4h6p-wphh-f8rf.json +++ b/advisories/unreviewed/2024/08/GHSA-4h6p-wphh-f8rf/GHSA-4h6p-wphh-f8rf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4h6p-wphh-f8rf", - "modified": "2024-08-02T15:31:19Z", + "modified": "2024-08-30T21:31:40Z", "published": "2024-08-02T15:31:19Z", "aliases": [ "CVE-2024-7029" @@ -25,6 +25,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7029" }, + { + "type": "WEB", + "url": "https://www.akamai.com/blog/security-research/2024-corona-mirai-botnet-infects-zero-day-sirt" + }, { "type": "WEB", "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-214-07" diff --git a/advisories/unreviewed/2024/08/GHSA-4hvh-m426-wv8w/GHSA-4hvh-m426-wv8w.json b/advisories/unreviewed/2024/08/GHSA-4hvh-m426-wv8w/GHSA-4hvh-m426-wv8w.json index 060705b8e3c..97aa9637980 100644 --- a/advisories/unreviewed/2024/08/GHSA-4hvh-m426-wv8w/GHSA-4hvh-m426-wv8w.json +++ b/advisories/unreviewed/2024/08/GHSA-4hvh-m426-wv8w/GHSA-4hvh-m426-wv8w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4hvh-m426-wv8w", - "modified": "2024-08-30T03:30:44Z", + "modified": "2024-08-30T21:31:40Z", "published": "2024-08-30T03:30:44Z", "aliases": [ "CVE-2024-45490" ], "details": "An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-30T03:15:03Z" diff --git a/advisories/unreviewed/2024/08/GHSA-5xg9-v43g-xgcj/GHSA-5xg9-v43g-xgcj.json b/advisories/unreviewed/2024/08/GHSA-5xg9-v43g-xgcj/GHSA-5xg9-v43g-xgcj.json index a9d87a1a2cb..7ab77317acc 100644 --- a/advisories/unreviewed/2024/08/GHSA-5xg9-v43g-xgcj/GHSA-5xg9-v43g-xgcj.json +++ b/advisories/unreviewed/2024/08/GHSA-5xg9-v43g-xgcj/GHSA-5xg9-v43g-xgcj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5xg9-v43g-xgcj", - "modified": "2024-08-26T21:30:34Z", + "modified": "2024-08-30T21:31:40Z", "published": "2024-08-26T21:30:34Z", "aliases": [ "CVE-2024-8105" @@ -22,6 +22,10 @@ "type": "WEB", "url": "https://github.com/binarly-io/Vulnerability-REsearch/blob/main/PKfail/BRLY-2024-005.md" }, + { + "type": "WEB", + "url": "https://kb.cert.org/vuls/id/455367" + }, { "type": "WEB", "url": "https://security.ts.fujitsu.com/ProductSecurity/content/Fujitsu-PSIRT-FJ-ISS-2024-072412-Security-Notice.pdf" @@ -30,6 +34,14 @@ "type": "WEB", "url": "https://uefi.org/specs/UEFI/2.9_A/32_Secure_Boot_and_Driver_Signing.html" }, + { + "type": "WEB", + "url": "https://www.binarly.io/advisories/brly-2024-005" + }, + { + "type": "WEB", + "url": "https://www.gigabyte.com/us/Support/Security/2205" + }, { "type": "WEB", "url": "https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2024-07-25-001.html" diff --git a/advisories/unreviewed/2024/08/GHSA-8pqc-xcjc-j8v3/GHSA-8pqc-xcjc-j8v3.json b/advisories/unreviewed/2024/08/GHSA-8pqc-xcjc-j8v3/GHSA-8pqc-xcjc-j8v3.json index f2c34dafd6b..40ea3dee32f 100644 --- a/advisories/unreviewed/2024/08/GHSA-8pqc-xcjc-j8v3/GHSA-8pqc-xcjc-j8v3.json +++ b/advisories/unreviewed/2024/08/GHSA-8pqc-xcjc-j8v3/GHSA-8pqc-xcjc-j8v3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8pqc-xcjc-j8v3", - "modified": "2024-08-30T06:30:38Z", + "modified": "2024-08-30T21:31:40Z", "published": "2024-08-30T06:30:38Z", "aliases": [ "CVE-2024-3673" ], "details": "The Web Directory Free WordPress plugin before 1.7.3 does not validate a parameter before using it in an include(), which could lead to Local File Inclusion issues.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-30T06:15:05Z" diff --git a/advisories/unreviewed/2024/08/GHSA-9gf5-vfx8-jvxx/GHSA-9gf5-vfx8-jvxx.json b/advisories/unreviewed/2024/08/GHSA-9gf5-vfx8-jvxx/GHSA-9gf5-vfx8-jvxx.json new file mode 100644 index 00000000000..9c9f8555d16 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-9gf5-vfx8-jvxx/GHSA-9gf5-vfx8-jvxx.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9gf5-vfx8-jvxx", + "modified": "2024-08-30T21:31:40Z", + "published": "2024-08-30T21:31:40Z", + "aliases": [ + "CVE-2024-42379" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42379" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-30T20:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-c2jm-97rm-g3c3/GHSA-c2jm-97rm-g3c3.json b/advisories/unreviewed/2024/08/GHSA-c2jm-97rm-g3c3/GHSA-c2jm-97rm-g3c3.json index 3a0441bc002..914ecc1437d 100644 --- a/advisories/unreviewed/2024/08/GHSA-c2jm-97rm-g3c3/GHSA-c2jm-97rm-g3c3.json +++ b/advisories/unreviewed/2024/08/GHSA-c2jm-97rm-g3c3/GHSA-c2jm-97rm-g3c3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c2jm-97rm-g3c3", - "modified": "2024-08-30T03:30:44Z", + "modified": "2024-08-30T21:31:40Z", "published": "2024-08-30T03:30:44Z", "aliases": [ "CVE-2024-45488" ], "details": "One Identity Safeguard for Privileged Passwords before 7.5.2 allows unauthorized access because of an issue related to cookies. This only affects virtual appliance installations (VMware or HyperV). The fixed versions are 7.0.5.1 LTS, 7.4.2, and 7.5.2.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-30T02:15:03Z" diff --git a/advisories/unreviewed/2024/08/GHSA-mh7j-x4vr-3mg3/GHSA-mh7j-x4vr-3mg3.json b/advisories/unreviewed/2024/08/GHSA-mh7j-x4vr-3mg3/GHSA-mh7j-x4vr-3mg3.json index 89cdda7ddc4..6ed943d3ad8 100644 --- a/advisories/unreviewed/2024/08/GHSA-mh7j-x4vr-3mg3/GHSA-mh7j-x4vr-3mg3.json +++ b/advisories/unreviewed/2024/08/GHSA-mh7j-x4vr-3mg3/GHSA-mh7j-x4vr-3mg3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mh7j-x4vr-3mg3", - "modified": "2024-08-30T18:30:40Z", + "modified": "2024-08-30T21:31:40Z", "published": "2024-08-30T18:30:40Z", "aliases": [ "CVE-2024-44918" ], "details": "A cross-site scripting (XSS) vulnerability in the component admin_datarelate.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-30T17:15:15Z" diff --git a/advisories/unreviewed/2024/08/GHSA-pmv2-3483-4jqw/GHSA-pmv2-3483-4jqw.json b/advisories/unreviewed/2024/08/GHSA-pmv2-3483-4jqw/GHSA-pmv2-3483-4jqw.json new file mode 100644 index 00000000000..6ad25f19f8a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-pmv2-3483-4jqw/GHSA-pmv2-3483-4jqw.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pmv2-3483-4jqw", + "modified": "2024-08-30T21:31:40Z", + "published": "2024-08-30T21:31:40Z", + "aliases": [ + "CVE-2024-8346" + ], + "details": "A vulnerability classified as critical has been found in SourceCodester Computer Laboratory Management System 1.0. Affected is the function update_settings_info of the file /classes/SystemSettings.php?f=update_settings. The manipulation of the argument name leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8346" + }, + { + "type": "WEB", + "url": "https://github.com/gaorenyusi/gaorenyusi/blob/main/lms1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.276228" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.276228" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.400343" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-30T21:15:16Z" + } +} \ No newline at end of file