diff --git a/advisories/github-reviewed/2024/03/GHSA-5jpm-x58v-624v/GHSA-5jpm-x58v-624v.json b/advisories/github-reviewed/2024/03/GHSA-5jpm-x58v-624v/GHSA-5jpm-x58v-624v.json index 8ef637ad92e..5e125ec4a15 100644 --- a/advisories/github-reviewed/2024/03/GHSA-5jpm-x58v-624v/GHSA-5jpm-x58v-624v.json +++ b/advisories/github-reviewed/2024/03/GHSA-5jpm-x58v-624v/GHSA-5jpm-x58v-624v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5jpm-x58v-624v", - "modified": "2024-03-25T22:31:40Z", + "modified": "2024-06-22T00:30:55Z", "published": "2024-03-25T19:40:50Z", "aliases": [ "CVE-2024-29025" @@ -59,6 +59,10 @@ { "type": "WEB", "url": "https://github.com/vietj/netty/tree/post-request-decoder" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00015.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/06/GHSA-22f8-6qq6-p38x/GHSA-22f8-6qq6-p38x.json b/advisories/unreviewed/2024/06/GHSA-22f8-6qq6-p38x/GHSA-22f8-6qq6-p38x.json new file mode 100644 index 00000000000..2e5f591d8e1 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-22f8-6qq6-p38x/GHSA-22f8-6qq6-p38x.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-22f8-6qq6-p38x", + "modified": "2024-06-22T00:30:56Z", + "published": "2024-06-22T00:30:56Z", + "aliases": [ + "CVE-2014-5470" + ], + "details": "Actual Analyzer through 2014-08-29 allows code execution via shell metacharacters because untrusted input is used for part of the input data passed to an eval operation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2014-5470" + }, + { + "type": "WEB", + "url": "https://vulmon.com/exploitdetails?qidtp=exploitdb&qid=35549" + }, + { + "type": "WEB", + "url": "https://www.exploit-db.com/exploits/35549" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-21T22:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-26x4-2jjv-hq3q/GHSA-26x4-2jjv-hq3q.json b/advisories/unreviewed/2024/06/GHSA-26x4-2jjv-hq3q/GHSA-26x4-2jjv-hq3q.json new file mode 100644 index 00000000000..9d2373a029e --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-26x4-2jjv-hq3q/GHSA-26x4-2jjv-hq3q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-26x4-2jjv-hq3q", + "modified": "2024-06-22T00:30:57Z", + "published": "2024-06-22T00:30:57Z", + "aliases": [ + "CVE-2024-37654" + ], + "details": "An issue in BAS-IP AV-01D, AV-01MD, AV-01MFD, AV-01ED, AV-01KD, AV-01BD, AV-01KBD, AV-02D, AV-02IDE, AV-02IDR, AV-02IPD, AV-02FDE, AV-02FDR, AV-03D, AV-03BD, AV-04AFD, AV-04ASD, AV-04FD, AV-04SD, AV-05FD, AV-05SD, AA-07BD, AA-07BDI, BA-04BD, BA-04MD, BA-08BD, BA-08MD, BA-12BD, BA-12MD, CR-02BD before 3.9.2 allows a remote attacker to obtain sensitive information via a crafted HTTP GET request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37654" + }, + { + "type": "WEB", + "url": "https://github.com/DrieVlad/BAS-IP-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-21T22:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-4jh7-m9q3-3qw9/GHSA-4jh7-m9q3-3qw9.json b/advisories/unreviewed/2024/06/GHSA-4jh7-m9q3-3qw9/GHSA-4jh7-m9q3-3qw9.json new file mode 100644 index 00000000000..1998429c4b4 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-4jh7-m9q3-3qw9/GHSA-4jh7-m9q3-3qw9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4jh7-m9q3-3qw9", + "modified": "2024-06-22T00:30:56Z", + "published": "2024-06-22T00:30:56Z", + "aliases": [ + "CVE-2024-34452" + ], + "details": "CMSimple_XH 1.7.6 allows XSS by uploading a crafted SVG document.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34452" + }, + { + "type": "WEB", + "url": "https://github.com/surajhacx/CVE-2024-34452" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-21T22:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-5rg9-mjfx-pqq5/GHSA-5rg9-mjfx-pqq5.json b/advisories/unreviewed/2024/06/GHSA-5rg9-mjfx-pqq5/GHSA-5rg9-mjfx-pqq5.json new file mode 100644 index 00000000000..b1c89a29193 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-5rg9-mjfx-pqq5/GHSA-5rg9-mjfx-pqq5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5rg9-mjfx-pqq5", + "modified": "2024-06-22T00:30:57Z", + "published": "2024-06-22T00:30:57Z", + "aliases": [ + "CVE-2024-37694" + ], + "details": "ArcGIS Enterprise Server 10.8.0 allows a remote attacker to obtain sensitive information because /arcgis/rest/services does not require authentication.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37694" + }, + { + "type": "WEB", + "url": "https://github.com/NSSCYCTFER/SRC-CVE" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-21T22:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-6www-xm5g-97xc/GHSA-6www-xm5g-97xc.json b/advisories/unreviewed/2024/06/GHSA-6www-xm5g-97xc/GHSA-6www-xm5g-97xc.json new file mode 100644 index 00000000000..fded48c6a12 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-6www-xm5g-97xc/GHSA-6www-xm5g-97xc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6www-xm5g-97xc", + "modified": "2024-06-22T00:30:57Z", + "published": "2024-06-22T00:30:57Z", + "aliases": [ + "CVE-2024-34989" + ], + "details": "In the module RSI PDF/HTML catalog evolution (prestapdf) <= 7.0.0 from RSI for PrestaShop, a guest can perform SQL injection via `PrestaPDFProductListModuleFrontController::queryDb().'", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34989" + }, + { + "type": "WEB", + "url": "https://security.friendsofpresta.org/modules/2024/06/20/prestapdf.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-21T22:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-8gvf-f484-h344/GHSA-8gvf-f484-h344.json b/advisories/unreviewed/2024/06/GHSA-8gvf-f484-h344/GHSA-8gvf-f484-h344.json new file mode 100644 index 00000000000..db87cb2928b --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-8gvf-f484-h344/GHSA-8gvf-f484-h344.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8gvf-f484-h344", + "modified": "2024-06-22T00:30:56Z", + "published": "2024-06-22T00:30:56Z", + "aliases": [ + "CVE-2022-42974" + ], + "details": "In Kostal PIKO 1.5-1 MP plus HMI OEM p 1.0.1, the web application for the Solar Panel is vulnerable to a Stored Cross-Site Scripting (XSS) attack on /file.bootloader.upload.html. The application fails to sanitize the parameter filename, in a POST request to /file.bootloader.upload.html for a system update, thus allowing one to inject HTML and/or JavaScript on the page that will then be processed and stored by the application. Any subsequent requests to pages that retrieve the malicious content will automatically exploit the vulnerability on the victim's browser. This also happens because the tag is loaded in the function innerHTML in the page HTML.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-42974" + }, + { + "type": "WEB", + "url": "https://medium.com/%40daviddepaulasantos/how-we-got-a-cve-for-a-dom-based-stored-xss-on-a-solar-panel-917b9d7b2545" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-21T22:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-95jf-85v4-5p6v/GHSA-95jf-85v4-5p6v.json b/advisories/unreviewed/2024/06/GHSA-95jf-85v4-5p6v/GHSA-95jf-85v4-5p6v.json new file mode 100644 index 00000000000..d7a3e5af53e --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-95jf-85v4-5p6v/GHSA-95jf-85v4-5p6v.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-95jf-85v4-5p6v", + "modified": "2024-06-22T00:30:57Z", + "published": "2024-06-22T00:30:57Z", + "aliases": [ + "CVE-2024-36532" + ], + "details": "Insecure permissions in kruise v1.6.2 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36532" + }, + { + "type": "WEB", + "url": "https://gist.github.com/HouqiyuA/43488e1d41110a5610146b87b2e88a02" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-21T22:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-c8f7-vvrw-73c7/GHSA-c8f7-vvrw-73c7.json b/advisories/unreviewed/2024/06/GHSA-c8f7-vvrw-73c7/GHSA-c8f7-vvrw-73c7.json new file mode 100644 index 00000000000..8e50ddaa23e --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-c8f7-vvrw-73c7/GHSA-c8f7-vvrw-73c7.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c8f7-vvrw-73c7", + "modified": "2024-06-22T00:30:56Z", + "published": "2024-06-22T00:30:56Z", + "aliases": [ + "CVE-2012-6664" + ], + "details": "Multiple directory traversal vulnerabilities in the TFTP Server in Distinct Intranet Servers 3.10 and earlier allow remote attackers to read or write arbitrary files via a .. (dot dot) in the (1) get or (2) put commands.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2012-6664" + }, + { + "type": "WEB", + "url": "https://www.exploit-db.com/exploits/41714" + }, + { + "type": "WEB", + "url": "https://www.fortiguard.com/encyclopedia/ips/48021" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-21T22:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-gjp6-cpfp-vxjm/GHSA-gjp6-cpfp-vxjm.json b/advisories/unreviewed/2024/06/GHSA-gjp6-cpfp-vxjm/GHSA-gjp6-cpfp-vxjm.json new file mode 100644 index 00000000000..8b68ff28e8a --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-gjp6-cpfp-vxjm/GHSA-gjp6-cpfp-vxjm.json @@ -0,0 +1,70 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gjp6-cpfp-vxjm", + "modified": "2024-06-22T00:30:57Z", + "published": "2024-06-22T00:30:57Z", + "aliases": [ + "CVE-2024-6120" + ], + "details": "The Sparkle Demo Importer plugin for WordPress is vulnerable to unauthorized database reset and demo data import due to a missing capability check on the multiple functions in all versions up to and including 1.4.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete all posts, pages, and uploaded files, as well as download and install a limited set of demo plugins.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6120" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/sparkle-demo-importer/tags/1.4.7/sparkle-demo-importer.php#L446" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/sparkle-demo-importer/tags/1.4.7/sparkle-demo-importer.php#L469" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/sparkle-demo-importer/tags/1.4.7/sparkle-demo-importer.php#L497" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/sparkle-demo-importer/tags/1.4.7/sparkle-demo-importer.php#L519" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/sparkle-demo-importer/tags/1.4.7/sparkle-demo-importer.php#L541" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/sparkle-demo-importer/tags/1.4.7/sparkle-demo-importer.php#L570" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/sparkle-demo-importer/tags/1.4.7/sparkle-demo-importer.php#L595" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/sparkle-demo-importer/tags/1.4.7/sparkle-demo-importer.php#L627" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/8f411d17-5b0d-4a4a-afa8-7efebf6965f2?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-22T00:15:09Z" + } +} \ No newline at end of file