From 10d86e38e71a2aa1bc7d0ee8d853b56d8f81bf57 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 26 Jun 2024 21:33:39 +0000 Subject: [PATCH] Publish Advisories GHSA-2jvx-3h5f-w2j7 GHSA-7f2q-q825-57p8 GHSA-3r8p-3x67-72v8 GHSA-23wq-qm4c-6497 GHSA-2g4v-8vvw-r8m9 GHSA-34x7-h5wm-79jf GHSA-43wj-hwhg-9h4m GHSA-4cqv-cv9m-26q8 GHSA-5rj5-w87x-2r8m GHSA-8mgc-gvxr-fgch GHSA-8wv3-qwhx-w2cj GHSA-952j-g655-5gm9 GHSA-cvph-c7fw-4mjc GHSA-grq4-g85p-x45c GHSA-pcgg-6f95-wg8g GHSA-qr63-7f35-4m2w GHSA-v3rc-5q86-wwq8 GHSA-w54f-vq4c-7637 GHSA-xggx-88w4-2942 --- .../GHSA-2jvx-3h5f-w2j7.json | 6 ++- .../GHSA-7f2q-q825-57p8.json | 2 +- .../GHSA-3r8p-3x67-72v8.json | 2 +- .../GHSA-23wq-qm4c-6497.json | 35 ++++++++++++++ .../GHSA-2g4v-8vvw-r8m9.json | 35 ++++++++++++++ .../GHSA-34x7-h5wm-79jf.json | 35 ++++++++++++++ .../GHSA-43wj-hwhg-9h4m.json | 38 +++++++++++++++ .../GHSA-4cqv-cv9m-26q8.json | 35 ++++++++++++++ .../GHSA-5rj5-w87x-2r8m.json | 46 +++++++++++++++++++ .../GHSA-8mgc-gvxr-fgch.json | 35 ++++++++++++++ .../GHSA-8wv3-qwhx-w2cj.json | 35 ++++++++++++++ .../GHSA-952j-g655-5gm9.json | 35 ++++++++++++++ .../GHSA-cvph-c7fw-4mjc.json | 39 ++++++++++++++++ .../GHSA-grq4-g85p-x45c.json | 35 ++++++++++++++ .../GHSA-pcgg-6f95-wg8g.json | 35 ++++++++++++++ .../GHSA-qr63-7f35-4m2w.json | 35 ++++++++++++++ .../GHSA-v3rc-5q86-wwq8.json | 35 ++++++++++++++ .../GHSA-w54f-vq4c-7637.json | 39 ++++++++++++++++ .../GHSA-xggx-88w4-2942.json | 35 ++++++++++++++ 19 files changed, 589 insertions(+), 3 deletions(-) create mode 100644 advisories/unreviewed/2024/06/GHSA-23wq-qm4c-6497/GHSA-23wq-qm4c-6497.json create mode 100644 advisories/unreviewed/2024/06/GHSA-2g4v-8vvw-r8m9/GHSA-2g4v-8vvw-r8m9.json create mode 100644 advisories/unreviewed/2024/06/GHSA-34x7-h5wm-79jf/GHSA-34x7-h5wm-79jf.json create mode 100644 advisories/unreviewed/2024/06/GHSA-43wj-hwhg-9h4m/GHSA-43wj-hwhg-9h4m.json create mode 100644 advisories/unreviewed/2024/06/GHSA-4cqv-cv9m-26q8/GHSA-4cqv-cv9m-26q8.json create mode 100644 advisories/unreviewed/2024/06/GHSA-5rj5-w87x-2r8m/GHSA-5rj5-w87x-2r8m.json create mode 100644 advisories/unreviewed/2024/06/GHSA-8mgc-gvxr-fgch/GHSA-8mgc-gvxr-fgch.json create mode 100644 advisories/unreviewed/2024/06/GHSA-8wv3-qwhx-w2cj/GHSA-8wv3-qwhx-w2cj.json create mode 100644 advisories/unreviewed/2024/06/GHSA-952j-g655-5gm9/GHSA-952j-g655-5gm9.json create mode 100644 advisories/unreviewed/2024/06/GHSA-cvph-c7fw-4mjc/GHSA-cvph-c7fw-4mjc.json create mode 100644 advisories/unreviewed/2024/06/GHSA-grq4-g85p-x45c/GHSA-grq4-g85p-x45c.json create mode 100644 advisories/unreviewed/2024/06/GHSA-pcgg-6f95-wg8g/GHSA-pcgg-6f95-wg8g.json create mode 100644 advisories/unreviewed/2024/06/GHSA-qr63-7f35-4m2w/GHSA-qr63-7f35-4m2w.json create mode 100644 advisories/unreviewed/2024/06/GHSA-v3rc-5q86-wwq8/GHSA-v3rc-5q86-wwq8.json create mode 100644 advisories/unreviewed/2024/06/GHSA-w54f-vq4c-7637/GHSA-w54f-vq4c-7637.json create mode 100644 advisories/unreviewed/2024/06/GHSA-xggx-88w4-2942/GHSA-xggx-88w4-2942.json diff --git a/advisories/unreviewed/2023/11/GHSA-2jvx-3h5f-w2j7/GHSA-2jvx-3h5f-w2j7.json b/advisories/unreviewed/2023/11/GHSA-2jvx-3h5f-w2j7/GHSA-2jvx-3h5f-w2j7.json index ba9da29a501..9c865a63828 100644 --- a/advisories/unreviewed/2023/11/GHSA-2jvx-3h5f-w2j7/GHSA-2jvx-3h5f-w2j7.json +++ b/advisories/unreviewed/2023/11/GHSA-2jvx-3h5f-w2j7/GHSA-2jvx-3h5f-w2j7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2jvx-3h5f-w2j7", - "modified": "2023-11-15T21:35:08Z", + "modified": "2024-06-26T21:32:15Z", "published": "2023-11-15T21:35:08Z", "aliases": [ "CVE-2023-6105" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6105" }, + { + "type": "WEB", + "url": "https://www.manageengine.com/security/advisory/CVE/CVE-2023-6105.html" + }, { "type": "WEB", "url": "https://www.tenable.com/security/research/tra-2023-35" diff --git a/advisories/unreviewed/2023/11/GHSA-7f2q-q825-57p8/GHSA-7f2q-q825-57p8.json b/advisories/unreviewed/2023/11/GHSA-7f2q-q825-57p8/GHSA-7f2q-q825-57p8.json index 1e7f04af42b..61884743e13 100644 --- a/advisories/unreviewed/2023/11/GHSA-7f2q-q825-57p8/GHSA-7f2q-q825-57p8.json +++ b/advisories/unreviewed/2023/11/GHSA-7f2q-q825-57p8/GHSA-7f2q-q825-57p8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7f2q-q825-57p8", - "modified": "2023-11-22T00:30:21Z", + "modified": "2024-06-26T21:32:15Z", "published": "2023-11-22T00:30:21Z", "aliases": [ "CVE-2023-49103" diff --git a/advisories/unreviewed/2023/12/GHSA-3r8p-3x67-72v8/GHSA-3r8p-3x67-72v8.json b/advisories/unreviewed/2023/12/GHSA-3r8p-3x67-72v8/GHSA-3r8p-3x67-72v8.json index 7fd7d933f52..1bc24d2d47b 100644 --- a/advisories/unreviewed/2023/12/GHSA-3r8p-3x67-72v8/GHSA-3r8p-3x67-72v8.json +++ b/advisories/unreviewed/2023/12/GHSA-3r8p-3x67-72v8/GHSA-3r8p-3x67-72v8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3r8p-3x67-72v8", - "modified": "2023-12-05T18:30:23Z", + "modified": "2024-06-26T21:32:16Z", "published": "2023-12-05T18:30:23Z", "aliases": [ "CVE-2023-6448" diff --git a/advisories/unreviewed/2024/06/GHSA-23wq-qm4c-6497/GHSA-23wq-qm4c-6497.json b/advisories/unreviewed/2024/06/GHSA-23wq-qm4c-6497/GHSA-23wq-qm4c-6497.json new file mode 100644 index 00000000000..6686de8cb39 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-23wq-qm4c-6497/GHSA-23wq-qm4c-6497.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-23wq-qm4c-6497", + "modified": "2024-06-26T21:32:18Z", + "published": "2024-06-26T21:32:18Z", + "aliases": [ + "CVE-2024-39242" + ], + "details": "A cross-site scripting (XSS) vulnerability in skycaiji v2.8 allows attackers to execute arbitrary web scripts or HTML via a crafted payload using eval(String.fromCharCode()).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39242" + }, + { + "type": "WEB", + "url": "https://fushuling.com/index.php/2024/06/13/test2" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-26T20:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-2g4v-8vvw-r8m9/GHSA-2g4v-8vvw-r8m9.json b/advisories/unreviewed/2024/06/GHSA-2g4v-8vvw-r8m9/GHSA-2g4v-8vvw-r8m9.json new file mode 100644 index 00000000000..07627784dfc --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-2g4v-8vvw-r8m9/GHSA-2g4v-8vvw-r8m9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2g4v-8vvw-r8m9", + "modified": "2024-06-26T21:32:18Z", + "published": "2024-06-26T21:32:18Z", + "aliases": [ + "CVE-2024-39243" + ], + "details": "An issue discovered in skycaiji 2.8 allows attackers to run arbitrary code via crafted POST request to /index.php?s=/admin/develop/editor_save.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39243" + }, + { + "type": "WEB", + "url": "https://fushuling.com/index.php/2024/06/11/test" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-26T20:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-34x7-h5wm-79jf/GHSA-34x7-h5wm-79jf.json b/advisories/unreviewed/2024/06/GHSA-34x7-h5wm-79jf/GHSA-34x7-h5wm-79jf.json new file mode 100644 index 00000000000..9e429639b84 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-34x7-h5wm-79jf/GHSA-34x7-h5wm-79jf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-34x7-h5wm-79jf", + "modified": "2024-06-26T21:32:16Z", + "published": "2024-06-26T21:32:16Z", + "aliases": [ + "CVE-2024-33327" + ], + "details": "A cross-site scripting (XSS) vulnerability in the component UrlAccessibilityEvaluation.jsp of Lumisxp v15.0.x to v16.1.x allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the contentHtml parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33327" + }, + { + "type": "WEB", + "url": "https://gist.github.com/rodnt/c53d4c95bb6966f0a2cf381ae5089c79" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-26T19:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-43wj-hwhg-9h4m/GHSA-43wj-hwhg-9h4m.json b/advisories/unreviewed/2024/06/GHSA-43wj-hwhg-9h4m/GHSA-43wj-hwhg-9h4m.json new file mode 100644 index 00000000000..a22f7db797c --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-43wj-hwhg-9h4m/GHSA-43wj-hwhg-9h4m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-43wj-hwhg-9h4m", + "modified": "2024-06-26T21:32:18Z", + "published": "2024-06-26T21:32:18Z", + "aliases": [ + "CVE-2024-1839" + ], + "details": "Intrado 911 Emergency Gateway login form is vulnerable to an unauthenticated blind time-based SQL injection, which may allow an unauthenticated remote attacker to execute malicious code, exfiltrate data, or manipulate the database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1839" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-163-04" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-26T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-4cqv-cv9m-26q8/GHSA-4cqv-cv9m-26q8.json b/advisories/unreviewed/2024/06/GHSA-4cqv-cv9m-26q8/GHSA-4cqv-cv9m-26q8.json new file mode 100644 index 00000000000..d4ffc70e7f0 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-4cqv-cv9m-26q8/GHSA-4cqv-cv9m-26q8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4cqv-cv9m-26q8", + "modified": "2024-06-26T21:32:18Z", + "published": "2024-06-26T21:32:18Z", + "aliases": [ + "CVE-2024-23766" + ], + "details": "An issue was discovered on HMS Anybus X-Gateway AB7832-F 3 devices. The gateway exposes a web interface on port 80. An unauthenticated GET request to a specific URL triggers the reboot of the Anybus gateway (or at least most of its modules). An attacker can use this feature to carry out a denial of service attack by continuously sending GET requests to that URL.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23766" + }, + { + "type": "WEB", + "url": "https://sensepost.com/blog/2024/targeting-an-industrial-protocol-gateway" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-26T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-5rj5-w87x-2r8m/GHSA-5rj5-w87x-2r8m.json b/advisories/unreviewed/2024/06/GHSA-5rj5-w87x-2r8m/GHSA-5rj5-w87x-2r8m.json new file mode 100644 index 00000000000..9774b07c738 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-5rj5-w87x-2r8m/GHSA-5rj5-w87x-2r8m.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5rj5-w87x-2r8m", + "modified": "2024-06-26T21:32:19Z", + "published": "2024-06-26T21:32:19Z", + "aliases": [ + "CVE-2024-6355" + ], + "details": "A vulnerability was found in Genexis Tilgin Fiber Home Gateway HG1522 CSx000-01_09_01_12. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /status/product_info/. The manipulation of the argument product_info leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-269755. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6355" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.269755" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.269755" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.359289" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-26T21:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-8mgc-gvxr-fgch/GHSA-8mgc-gvxr-fgch.json b/advisories/unreviewed/2024/06/GHSA-8mgc-gvxr-fgch/GHSA-8mgc-gvxr-fgch.json new file mode 100644 index 00000000000..7901eacac45 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-8mgc-gvxr-fgch/GHSA-8mgc-gvxr-fgch.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8mgc-gvxr-fgch", + "modified": "2024-06-26T21:32:16Z", + "published": "2024-06-26T21:32:16Z", + "aliases": [ + "CVE-2024-33328" + ], + "details": "A cross-site scripting (XSS) vulnerability in the component main.jsp of Lumisxp v15.0.x to v16.1.x allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the pageId parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33328" + }, + { + "type": "WEB", + "url": "https://gist.github.com/rodnt/cf2946b0f6136cd03ee4737aa72ae95b" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-26T19:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-8wv3-qwhx-w2cj/GHSA-8wv3-qwhx-w2cj.json b/advisories/unreviewed/2024/06/GHSA-8wv3-qwhx-w2cj/GHSA-8wv3-qwhx-w2cj.json new file mode 100644 index 00000000000..cdd42755a42 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-8wv3-qwhx-w2cj/GHSA-8wv3-qwhx-w2cj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8wv3-qwhx-w2cj", + "modified": "2024-06-26T21:32:18Z", + "published": "2024-06-26T21:32:18Z", + "aliases": [ + "CVE-2024-23765" + ], + "details": "An issue was discovered on HMS Anybus X-Gateway AB7832-F 3 devices. The gateway exposes an unidentified service on port 7412 on the network. All the network services of the gateway become unresponsive after sending 85 requests to this port. The content and length of the frame does not matter. The device needs to be restarted to resume operations.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23765" + }, + { + "type": "WEB", + "url": "https://sensepost.com/blog/2024/targeting-an-industrial-protocol-gateway" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-26T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-952j-g655-5gm9/GHSA-952j-g655-5gm9.json b/advisories/unreviewed/2024/06/GHSA-952j-g655-5gm9/GHSA-952j-g655-5gm9.json new file mode 100644 index 00000000000..eca53eb46e3 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-952j-g655-5gm9/GHSA-952j-g655-5gm9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-952j-g655-5gm9", + "modified": "2024-06-26T21:32:17Z", + "published": "2024-06-26T21:32:17Z", + "aliases": [ + "CVE-2024-39241" + ], + "details": "Cross Site Scripting (XSS) vulnerability in skycaiji 2.8 allows attackers to run arbitrary code via /admin/tool/preview.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39241" + }, + { + "type": "WEB", + "url": "https://fushuling.com/index.php/2024/06/19/test3" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-26T20:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-cvph-c7fw-4mjc/GHSA-cvph-c7fw-4mjc.json b/advisories/unreviewed/2024/06/GHSA-cvph-c7fw-4mjc/GHSA-cvph-c7fw-4mjc.json new file mode 100644 index 00000000000..cc2ac7e80d1 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-cvph-c7fw-4mjc/GHSA-cvph-c7fw-4mjc.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cvph-c7fw-4mjc", + "modified": "2024-06-26T21:32:17Z", + "published": "2024-06-26T21:32:17Z", + "aliases": [ + "CVE-2024-38950" + ], + "details": "Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to __interceptor_memcpy function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38950" + }, + { + "type": "WEB", + "url": "https://github.com/strukturag/libde265/issues/460" + }, + { + "type": "WEB", + "url": "https://github.com/zhangteng0526/CVE-information/blob/main/CVE-2024-38950" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-26T20:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-grq4-g85p-x45c/GHSA-grq4-g85p-x45c.json b/advisories/unreviewed/2024/06/GHSA-grq4-g85p-x45c/GHSA-grq4-g85p-x45c.json new file mode 100644 index 00000000000..5594765b148 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-grq4-g85p-x45c/GHSA-grq4-g85p-x45c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-grq4-g85p-x45c", + "modified": "2024-06-26T21:32:18Z", + "published": "2024-06-26T21:32:18Z", + "aliases": [ + "CVE-2024-36829" + ], + "details": "Incorrect access control in Teldat M1 v11.00.05.50.01 allows attackers to obtain sensitive information via a crafted query string.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36829" + }, + { + "type": "WEB", + "url": "https://gist.github.com/MILPDS/96843ccf7369ec1da643b7d6e22d428d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-26T21:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-pcgg-6f95-wg8g/GHSA-pcgg-6f95-wg8g.json b/advisories/unreviewed/2024/06/GHSA-pcgg-6f95-wg8g/GHSA-pcgg-6f95-wg8g.json new file mode 100644 index 00000000000..94bdf997727 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-pcgg-6f95-wg8g/GHSA-pcgg-6f95-wg8g.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pcgg-6f95-wg8g", + "modified": "2024-06-26T21:32:18Z", + "published": "2024-06-26T21:32:18Z", + "aliases": [ + "CVE-2024-23767" + ], + "details": "An issue was discovered on HMS Anybus X-Gateway AB7832-F firmware version 3. The HICP protocol allows unauthenticated changes to a device's network configurations.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23767" + }, + { + "type": "WEB", + "url": "https://sensepost.com/blog/2024/targeting-an-industrial-protocol-gateway" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-26T21:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-qr63-7f35-4m2w/GHSA-qr63-7f35-4m2w.json b/advisories/unreviewed/2024/06/GHSA-qr63-7f35-4m2w/GHSA-qr63-7f35-4m2w.json new file mode 100644 index 00000000000..5800ffcbe92 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-qr63-7f35-4m2w/GHSA-qr63-7f35-4m2w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qr63-7f35-4m2w", + "modified": "2024-06-26T21:32:16Z", + "published": "2024-06-26T21:32:16Z", + "aliases": [ + "CVE-2024-33326" + ], + "details": "A cross-site scripting (XSS) vulnerability in the component XsltResultControllerHtml.jsp of Lumisxp v15.0.x to v16.1.x allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the lumPageID parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33326" + }, + { + "type": "WEB", + "url": "https://gist.github.com/rodnt/51ae2897abfff1bdcedccf72edbf3d24" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-26T19:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-v3rc-5q86-wwq8/GHSA-v3rc-5q86-wwq8.json b/advisories/unreviewed/2024/06/GHSA-v3rc-5q86-wwq8/GHSA-v3rc-5q86-wwq8.json new file mode 100644 index 00000000000..5f5a81660f0 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-v3rc-5q86-wwq8/GHSA-v3rc-5q86-wwq8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v3rc-5q86-wwq8", + "modified": "2024-06-26T21:32:16Z", + "published": "2024-06-26T21:32:16Z", + "aliases": [ + "CVE-2024-33329" + ], + "details": "A hardcoded privileged ID within Lumisxp v15.0.x to v16.1.x allows attackers to bypass authentication and access internal pages and other sensitive information.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33329" + }, + { + "type": "WEB", + "url": "https://gist.github.com/rodnt/f6b3a2ac875b8f13656063eefbfd9812" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-26T19:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-w54f-vq4c-7637/GHSA-w54f-vq4c-7637.json b/advisories/unreviewed/2024/06/GHSA-w54f-vq4c-7637/GHSA-w54f-vq4c-7637.json new file mode 100644 index 00000000000..a3c85f8a5ea --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-w54f-vq4c-7637/GHSA-w54f-vq4c-7637.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w54f-vq4c-7637", + "modified": "2024-06-26T21:32:17Z", + "published": "2024-06-26T21:32:17Z", + "aliases": [ + "CVE-2024-38949" + ], + "details": "Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to display444as420 function at sdl.cc", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38949" + }, + { + "type": "WEB", + "url": "https://github.com/strukturag/libde265/issues/460" + }, + { + "type": "WEB", + "url": "https://github.com/zhangteng0526/CVE-information/blob/main/CVE-2024-38949" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-26T20:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-xggx-88w4-2942/GHSA-xggx-88w4-2942.json b/advisories/unreviewed/2024/06/GHSA-xggx-88w4-2942/GHSA-xggx-88w4-2942.json new file mode 100644 index 00000000000..38d699338f5 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-xggx-88w4-2942/GHSA-xggx-88w4-2942.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xggx-88w4-2942", + "modified": "2024-06-26T21:32:16Z", + "published": "2024-06-26T21:32:16Z", + "aliases": [ + "CVE-2023-26877" + ], + "details": "File upload vulnerability found in Softexpert Excellence Suite v.2.1 allows attackers to execute arbitrary code via a .php file upload to the form/efms_exec_html/file_upload_parser.php endpoint.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26877" + }, + { + "type": "WEB", + "url": "https://gist.github.com/rodnt/90ac26fdf891e602f6f090d6aebce32d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-26T20:15:14Z" + } +} \ No newline at end of file