diff --git a/advisories/github-reviewed/2024/05/GHSA-6wvf-f2vw-3425/GHSA-6wvf-f2vw-3425.json b/advisories/github-reviewed/2024/05/GHSA-6wvf-f2vw-3425/GHSA-6wvf-f2vw-3425.json index 0a00ee2cf3e..abd1ced493c 100644 --- a/advisories/github-reviewed/2024/05/GHSA-6wvf-f2vw-3425/GHSA-6wvf-f2vw-3425.json +++ b/advisories/github-reviewed/2024/05/GHSA-6wvf-f2vw-3425/GHSA-6wvf-f2vw-3425.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6wvf-f2vw-3425", - "modified": "2024-06-27T18:31:30Z", + "modified": "2024-07-03T18:41:22Z", "published": "2024-05-14T18:30:52Z", "aliases": [ "CVE-2024-3727" @@ -142,6 +142,10 @@ "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-3727" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:4159" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:0045" diff --git a/advisories/unreviewed/2024/05/GHSA-22fx-rv4f-228x/GHSA-22fx-rv4f-228x.json b/advisories/unreviewed/2024/05/GHSA-22fx-rv4f-228x/GHSA-22fx-rv4f-228x.json index e567cc24be1..63dda2ebbfe 100644 --- a/advisories/unreviewed/2024/05/GHSA-22fx-rv4f-228x/GHSA-22fx-rv4f-228x.json +++ b/advisories/unreviewed/2024/05/GHSA-22fx-rv4f-228x/GHSA-22fx-rv4f-228x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-22fx-rv4f-228x", - "modified": "2024-05-15T15:30:33Z", + "modified": "2024-07-03T18:41:57Z", "published": "2024-05-15T15:30:33Z", "aliases": [ "CVE-2024-34954" ], "details": "Code-projects Budget Management 1.0 is vulnerable to Cross Site Scripting (XSS) via the budget parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-15T15:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-22hh-9pxh-mm6v/GHSA-22hh-9pxh-mm6v.json b/advisories/unreviewed/2024/05/GHSA-22hh-9pxh-mm6v/GHSA-22hh-9pxh-mm6v.json index 44be44a4c2f..51313fcbf4c 100644 --- a/advisories/unreviewed/2024/05/GHSA-22hh-9pxh-mm6v/GHSA-22hh-9pxh-mm6v.json +++ b/advisories/unreviewed/2024/05/GHSA-22hh-9pxh-mm6v/GHSA-22hh-9pxh-mm6v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-22hh-9pxh-mm6v", - "modified": "2024-05-14T18:30:46Z", + "modified": "2024-07-03T18:40:37Z", "published": "2024-05-14T18:30:46Z", "aliases": [ "CVE-2024-32619" ], "details": "HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T_copy_reopen in H5T.c, resulting in the corruption of the instruction pointer.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:36:47Z" diff --git a/advisories/unreviewed/2024/05/GHSA-2738-rgv4-92wj/GHSA-2738-rgv4-92wj.json b/advisories/unreviewed/2024/05/GHSA-2738-rgv4-92wj/GHSA-2738-rgv4-92wj.json index fbbbcb52337..a930d46eac6 100644 --- a/advisories/unreviewed/2024/05/GHSA-2738-rgv4-92wj/GHSA-2738-rgv4-92wj.json +++ b/advisories/unreviewed/2024/05/GHSA-2738-rgv4-92wj/GHSA-2738-rgv4-92wj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2738-rgv4-92wj", - "modified": "2024-05-14T18:30:49Z", + "modified": "2024-07-03T18:41:01Z", "published": "2024-05-14T18:30:49Z", "aliases": [ "CVE-2024-34220" ], "details": "Sourcecodester Human Resource Management System 1.0 is vulnerable to SQL Injection via the 'leave' parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:38:35Z" diff --git a/advisories/unreviewed/2024/05/GHSA-28fv-xp4g-pphf/GHSA-28fv-xp4g-pphf.json b/advisories/unreviewed/2024/05/GHSA-28fv-xp4g-pphf/GHSA-28fv-xp4g-pphf.json index d5bc5fec484..d103a1b062e 100644 --- a/advisories/unreviewed/2024/05/GHSA-28fv-xp4g-pphf/GHSA-28fv-xp4g-pphf.json +++ b/advisories/unreviewed/2024/05/GHSA-28fv-xp4g-pphf/GHSA-28fv-xp4g-pphf.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-2g58-2x39-qh45/GHSA-2g58-2x39-qh45.json b/advisories/unreviewed/2024/05/GHSA-2g58-2x39-qh45/GHSA-2g58-2x39-qh45.json index 9411bebd4ab..be8a4ca7e81 100644 --- a/advisories/unreviewed/2024/05/GHSA-2g58-2x39-qh45/GHSA-2g58-2x39-qh45.json +++ b/advisories/unreviewed/2024/05/GHSA-2g58-2x39-qh45/GHSA-2g58-2x39-qh45.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2g58-2x39-qh45", - "modified": "2024-05-14T18:31:01Z", + "modified": "2024-07-03T18:41:33Z", "published": "2024-05-14T18:31:01Z", "aliases": [ "CVE-2024-34256" ], "details": "OFCMS V1.1.2 is vulnerable to SQL Injection via the new table function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T16:17:23Z" diff --git a/advisories/unreviewed/2024/05/GHSA-2pww-4jgc-f998/GHSA-2pww-4jgc-f998.json b/advisories/unreviewed/2024/05/GHSA-2pww-4jgc-f998/GHSA-2pww-4jgc-f998.json index 4cf98ca6959..11359a11d59 100644 --- a/advisories/unreviewed/2024/05/GHSA-2pww-4jgc-f998/GHSA-2pww-4jgc-f998.json +++ b/advisories/unreviewed/2024/05/GHSA-2pww-4jgc-f998/GHSA-2pww-4jgc-f998.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2pww-4jgc-f998", - "modified": "2024-05-15T15:30:33Z", + "modified": "2024-07-03T18:41:55Z", "published": "2024-05-15T15:30:33Z", "aliases": [ "CVE-2024-25078" ], "details": "A memory corruption vulnerability in StorageSecurityCommandDxe in Insyde InsydeH2O before kernel 5.2: IB19130163 in 05.29.07, kernel 5.3: IB19130163 in 05.38.07, kernel 5.4: IB19130163 in 05.46.07, kernel 5.5: IB19130163 in 05.54.07, and kernel 5.6: IB19130163 in 05.61.07 could lead to escalating privileges in SMM.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:L" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-822" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-15T14:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-38hg-hvc8-v572/GHSA-38hg-hvc8-v572.json b/advisories/unreviewed/2024/05/GHSA-38hg-hvc8-v572/GHSA-38hg-hvc8-v572.json index b75e2dd1d3d..751534494e6 100644 --- a/advisories/unreviewed/2024/05/GHSA-38hg-hvc8-v572/GHSA-38hg-hvc8-v572.json +++ b/advisories/unreviewed/2024/05/GHSA-38hg-hvc8-v572/GHSA-38hg-hvc8-v572.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-38hg-hvc8-v572", - "modified": "2024-05-14T18:30:51Z", + "modified": "2024-07-03T18:41:07Z", "published": "2024-05-14T18:30:51Z", "aliases": [ "CVE-2024-34943" ], "details": "Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at ip/goform/NatStaticSetting.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:39:38Z" diff --git a/advisories/unreviewed/2024/05/GHSA-38mm-6p5m-rh38/GHSA-38mm-6p5m-rh38.json b/advisories/unreviewed/2024/05/GHSA-38mm-6p5m-rh38/GHSA-38mm-6p5m-rh38.json index e23209b45e3..4f880dc280b 100644 --- a/advisories/unreviewed/2024/05/GHSA-38mm-6p5m-rh38/GHSA-38mm-6p5m-rh38.json +++ b/advisories/unreviewed/2024/05/GHSA-38mm-6p5m-rh38/GHSA-38mm-6p5m-rh38.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-38mm-6p5m-rh38", - "modified": "2024-05-14T18:31:05Z", + "modified": "2024-07-03T18:41:41Z", "published": "2024-05-14T18:31:05Z", "aliases": [ "CVE-2024-4776" ], "details": "A file dialog shown while in full-screen mode could have resulted in the window remaining disabled. This vulnerability affects Firefox < 126.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T18:15:16Z" diff --git a/advisories/unreviewed/2024/05/GHSA-3m6r-3gw2-h96x/GHSA-3m6r-3gw2-h96x.json b/advisories/unreviewed/2024/05/GHSA-3m6r-3gw2-h96x/GHSA-3m6r-3gw2-h96x.json index f9534de5351..7b1e2b594cc 100644 --- a/advisories/unreviewed/2024/05/GHSA-3m6r-3gw2-h96x/GHSA-3m6r-3gw2-h96x.json +++ b/advisories/unreviewed/2024/05/GHSA-3m6r-3gw2-h96x/GHSA-3m6r-3gw2-h96x.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-922" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-49hv-2hp8-w863/GHSA-49hv-2hp8-w863.json b/advisories/unreviewed/2024/05/GHSA-49hv-2hp8-w863/GHSA-49hv-2hp8-w863.json index 4820efaeb61..6be6673967a 100644 --- a/advisories/unreviewed/2024/05/GHSA-49hv-2hp8-w863/GHSA-49hv-2hp8-w863.json +++ b/advisories/unreviewed/2024/05/GHSA-49hv-2hp8-w863/GHSA-49hv-2hp8-w863.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-49hv-2hp8-w863", - "modified": "2024-05-14T18:30:46Z", + "modified": "2024-07-03T18:40:38Z", "published": "2024-05-14T18:30:46Z", "aliases": [ "CVE-2024-32620" ], "details": "HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5F_addr_decode_len in H5Fint.c, resulting in the corruption of the instruction pointer.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:36:47Z" diff --git a/advisories/unreviewed/2024/05/GHSA-4jqg-874r-phg3/GHSA-4jqg-874r-phg3.json b/advisories/unreviewed/2024/05/GHSA-4jqg-874r-phg3/GHSA-4jqg-874r-phg3.json index d355fe29317..07ac68f8db5 100644 --- a/advisories/unreviewed/2024/05/GHSA-4jqg-874r-phg3/GHSA-4jqg-874r-phg3.json +++ b/advisories/unreviewed/2024/05/GHSA-4jqg-874r-phg3/GHSA-4jqg-874r-phg3.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-4vrv-4wc3-4q25/GHSA-4vrv-4wc3-4q25.json b/advisories/unreviewed/2024/05/GHSA-4vrv-4wc3-4q25/GHSA-4vrv-4wc3-4q25.json index 6ed18559dbf..d9339b4c4be 100644 --- a/advisories/unreviewed/2024/05/GHSA-4vrv-4wc3-4q25/GHSA-4vrv-4wc3-4q25.json +++ b/advisories/unreviewed/2024/05/GHSA-4vrv-4wc3-4q25/GHSA-4vrv-4wc3-4q25.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4vrv-4wc3-4q25", - "modified": "2024-05-14T18:30:49Z", + "modified": "2024-07-03T18:41:02Z", "published": "2024-05-14T18:30:49Z", "aliases": [ "CVE-2024-34221" ], "details": "Sourcecodester Human Resource Management System 1.0 is vulnerable to Insecure Permissions resulting in privilege escalation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:38:36Z" diff --git a/advisories/unreviewed/2024/05/GHSA-4x9h-9pcf-jf7h/GHSA-4x9h-9pcf-jf7h.json b/advisories/unreviewed/2024/05/GHSA-4x9h-9pcf-jf7h/GHSA-4x9h-9pcf-jf7h.json index 28cc11f144e..8a8d7e07ac8 100644 --- a/advisories/unreviewed/2024/05/GHSA-4x9h-9pcf-jf7h/GHSA-4x9h-9pcf-jf7h.json +++ b/advisories/unreviewed/2024/05/GHSA-4x9h-9pcf-jf7h/GHSA-4x9h-9pcf-jf7h.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-119" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-53j6-rqp4-4h6m/GHSA-53j6-rqp4-4h6m.json b/advisories/unreviewed/2024/05/GHSA-53j6-rqp4-4h6m/GHSA-53j6-rqp4-4h6m.json index aad6bc55012..e6e2e6de157 100644 --- a/advisories/unreviewed/2024/05/GHSA-53j6-rqp4-4h6m/GHSA-53j6-rqp4-4h6m.json +++ b/advisories/unreviewed/2024/05/GHSA-53j6-rqp4-4h6m/GHSA-53j6-rqp4-4h6m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-53j6-rqp4-4h6m", - "modified": "2024-05-15T06:30:44Z", + "modified": "2024-07-03T18:41:55Z", "published": "2024-05-15T06:30:44Z", "aliases": [ "CVE-2024-3407" ], "details": "The WP Prayer WordPress plugin through 2.0.9 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-15T06:15:11Z" diff --git a/advisories/unreviewed/2024/05/GHSA-54pq-5528-hp79/GHSA-54pq-5528-hp79.json b/advisories/unreviewed/2024/05/GHSA-54pq-5528-hp79/GHSA-54pq-5528-hp79.json index 109f48b3f94..c3fdb792b66 100644 --- a/advisories/unreviewed/2024/05/GHSA-54pq-5528-hp79/GHSA-54pq-5528-hp79.json +++ b/advisories/unreviewed/2024/05/GHSA-54pq-5528-hp79/GHSA-54pq-5528-hp79.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-54pq-5528-hp79", - "modified": "2024-05-14T18:31:02Z", + "modified": "2024-07-03T18:41:34Z", "published": "2024-05-14T18:31:02Z", "aliases": [ "CVE-2024-3579" ], "details": "Open-source project Online Shopping System Advanced is vulnerable to Reflected Cross-Site Scripting (XSS). An attacker might trick somebody into using a crafted URL, which will cause a script to be run in user's browser. \n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T16:17:32Z" diff --git a/advisories/unreviewed/2024/05/GHSA-55qw-5fwm-j996/GHSA-55qw-5fwm-j996.json b/advisories/unreviewed/2024/05/GHSA-55qw-5fwm-j996/GHSA-55qw-5fwm-j996.json index 0547712c2d9..42c9f1a6fcc 100644 --- a/advisories/unreviewed/2024/05/GHSA-55qw-5fwm-j996/GHSA-55qw-5fwm-j996.json +++ b/advisories/unreviewed/2024/05/GHSA-55qw-5fwm-j996/GHSA-55qw-5fwm-j996.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-55qw-5fwm-j996", - "modified": "2024-05-14T18:30:49Z", + "modified": "2024-07-03T18:40:57Z", "published": "2024-05-14T18:30:49Z", "aliases": [ "CVE-2024-34210" ], "details": "TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the CloudACMunualUpdate function via the FileName parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:38:34Z" diff --git a/advisories/unreviewed/2024/05/GHSA-574f-9862-pvrw/GHSA-574f-9862-pvrw.json b/advisories/unreviewed/2024/05/GHSA-574f-9862-pvrw/GHSA-574f-9862-pvrw.json index 41d98a61bcc..c0999d25497 100644 --- a/advisories/unreviewed/2024/05/GHSA-574f-9862-pvrw/GHSA-574f-9862-pvrw.json +++ b/advisories/unreviewed/2024/05/GHSA-574f-9862-pvrw/GHSA-574f-9862-pvrw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-574f-9862-pvrw", - "modified": "2024-05-14T18:30:48Z", + "modified": "2024-07-03T18:40:47Z", "published": "2024-05-14T18:30:48Z", "aliases": [ "CVE-2024-33873" ], "details": "HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5D__scatter_mem in H5Dscatgath.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:38:09Z" diff --git a/advisories/unreviewed/2024/05/GHSA-57h3-6mh3-cjrr/GHSA-57h3-6mh3-cjrr.json b/advisories/unreviewed/2024/05/GHSA-57h3-6mh3-cjrr/GHSA-57h3-6mh3-cjrr.json index 74037d934ca..84d3c30ab71 100644 --- a/advisories/unreviewed/2024/05/GHSA-57h3-6mh3-cjrr/GHSA-57h3-6mh3-cjrr.json +++ b/advisories/unreviewed/2024/05/GHSA-57h3-6mh3-cjrr/GHSA-57h3-6mh3-cjrr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-57h3-6mh3-cjrr", - "modified": "2024-05-15T18:30:34Z", + "modified": "2024-07-03T18:41:59Z", "published": "2024-05-15T18:30:34Z", "aliases": [ "CVE-2024-27593" ], "details": "A stored cross-site scripting (XSS) vulnerability in the Filter function of Eramba Version 3.22.3 Community Edition allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the filter name field. This vulnerability has been fixed in version 3.23.0.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-15T17:15:10Z" diff --git a/advisories/unreviewed/2024/05/GHSA-5cx3-xfw2-wh7v/GHSA-5cx3-xfw2-wh7v.json b/advisories/unreviewed/2024/05/GHSA-5cx3-xfw2-wh7v/GHSA-5cx3-xfw2-wh7v.json index 82aa8650b02..cbc3707901e 100644 --- a/advisories/unreviewed/2024/05/GHSA-5cx3-xfw2-wh7v/GHSA-5cx3-xfw2-wh7v.json +++ b/advisories/unreviewed/2024/05/GHSA-5cx3-xfw2-wh7v/GHSA-5cx3-xfw2-wh7v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5cx3-xfw2-wh7v", - "modified": "2024-05-14T18:30:51Z", + "modified": "2024-07-03T18:41:08Z", "published": "2024-05-14T18:30:51Z", "aliases": [ "CVE-2024-34945" ], "details": "Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the PPW parameter at ip/goform/WizardHandle.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:39:38Z" diff --git a/advisories/unreviewed/2024/05/GHSA-5p37-9q3q-vh68/GHSA-5p37-9q3q-vh68.json b/advisories/unreviewed/2024/05/GHSA-5p37-9q3q-vh68/GHSA-5p37-9q3q-vh68.json index ad2e356b6b6..89d124235c6 100644 --- a/advisories/unreviewed/2024/05/GHSA-5p37-9q3q-vh68/GHSA-5p37-9q3q-vh68.json +++ b/advisories/unreviewed/2024/05/GHSA-5p37-9q3q-vh68/GHSA-5p37-9q3q-vh68.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5p37-9q3q-vh68", - "modified": "2024-05-14T18:31:01Z", + "modified": "2024-07-03T18:41:31Z", "published": "2024-05-14T18:31:01Z", "aliases": [ "CVE-2024-33864" ], "details": "An issue was discovered in linqi before 1.4.0.1 on Windows. There is SSRF via Document template generation; i.e., via remote images in process creation, file inclusion, and PDF document generation via malicious JavaScript.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-918" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T16:17:22Z" diff --git a/advisories/unreviewed/2024/05/GHSA-5pm7-95xh-g4vm/GHSA-5pm7-95xh-g4vm.json b/advisories/unreviewed/2024/05/GHSA-5pm7-95xh-g4vm/GHSA-5pm7-95xh-g4vm.json index 35bf8043cef..246ed934395 100644 --- a/advisories/unreviewed/2024/05/GHSA-5pm7-95xh-g4vm/GHSA-5pm7-95xh-g4vm.json +++ b/advisories/unreviewed/2024/05/GHSA-5pm7-95xh-g4vm/GHSA-5pm7-95xh-g4vm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5pm7-95xh-g4vm", - "modified": "2024-05-14T18:30:50Z", + "modified": "2024-07-03T18:41:06Z", "published": "2024-05-14T18:30:49Z", "aliases": [ "CVE-2024-34338" ], "details": "A Blind command injection vulnerability in Tenda O3V2 V1.0.0.12 and earlier allows remote attackers to execute operating system commands via dest parameter in /goform/getTraceroute", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:38:39Z" diff --git a/advisories/unreviewed/2024/05/GHSA-5rfc-xc58-54q3/GHSA-5rfc-xc58-54q3.json b/advisories/unreviewed/2024/05/GHSA-5rfc-xc58-54q3/GHSA-5rfc-xc58-54q3.json index 49a1ddbedda..aaa20be7289 100644 --- a/advisories/unreviewed/2024/05/GHSA-5rfc-xc58-54q3/GHSA-5rfc-xc58-54q3.json +++ b/advisories/unreviewed/2024/05/GHSA-5rfc-xc58-54q3/GHSA-5rfc-xc58-54q3.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-67p4-w92f-qx68/GHSA-67p4-w92f-qx68.json b/advisories/unreviewed/2024/05/GHSA-67p4-w92f-qx68/GHSA-67p4-w92f-qx68.json index a2fdd6c0e59..ae1fb672548 100644 --- a/advisories/unreviewed/2024/05/GHSA-67p4-w92f-qx68/GHSA-67p4-w92f-qx68.json +++ b/advisories/unreviewed/2024/05/GHSA-67p4-w92f-qx68/GHSA-67p4-w92f-qx68.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-67p4-w92f-qx68", - "modified": "2024-05-14T18:30:47Z", + "modified": "2024-07-03T18:40:40Z", "published": "2024-05-14T18:30:47Z", "aliases": [ "CVE-2024-32735" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-306" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-68c9-wp52-fpg7/GHSA-68c9-wp52-fpg7.json b/advisories/unreviewed/2024/05/GHSA-68c9-wp52-fpg7/GHSA-68c9-wp52-fpg7.json index 5d98d4401bc..dc7f8671727 100644 --- a/advisories/unreviewed/2024/05/GHSA-68c9-wp52-fpg7/GHSA-68c9-wp52-fpg7.json +++ b/advisories/unreviewed/2024/05/GHSA-68c9-wp52-fpg7/GHSA-68c9-wp52-fpg7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-68c9-wp52-fpg7", - "modified": "2024-05-14T18:31:05Z", + "modified": "2024-07-03T18:41:40Z", "published": "2024-05-14T18:31:05Z", "aliases": [ "CVE-2024-4775" ], "details": "An iterator stop condition was missing when handling WASM code in the built-in profiler, potentially leading to invalid memory access and undefined behavior. *Note:* This issue only affects the application when the profiler is running. This vulnerability affects Firefox < 126.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-431" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T18:15:15Z" diff --git a/advisories/unreviewed/2024/05/GHSA-69w4-p3c2-pwc7/GHSA-69w4-p3c2-pwc7.json b/advisories/unreviewed/2024/05/GHSA-69w4-p3c2-pwc7/GHSA-69w4-p3c2-pwc7.json index 5fff2e3935b..34a7788bcd2 100644 --- a/advisories/unreviewed/2024/05/GHSA-69w4-p3c2-pwc7/GHSA-69w4-p3c2-pwc7.json +++ b/advisories/unreviewed/2024/05/GHSA-69w4-p3c2-pwc7/GHSA-69w4-p3c2-pwc7.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1220", "CWE-284" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/05/GHSA-6gcq-x87m-9q8h/GHSA-6gcq-x87m-9q8h.json b/advisories/unreviewed/2024/05/GHSA-6gcq-x87m-9q8h/GHSA-6gcq-x87m-9q8h.json index ef8976fd89b..78669d67453 100644 --- a/advisories/unreviewed/2024/05/GHSA-6gcq-x87m-9q8h/GHSA-6gcq-x87m-9q8h.json +++ b/advisories/unreviewed/2024/05/GHSA-6gcq-x87m-9q8h/GHSA-6gcq-x87m-9q8h.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-6jgg-5f89-cp73/GHSA-6jgg-5f89-cp73.json b/advisories/unreviewed/2024/05/GHSA-6jgg-5f89-cp73/GHSA-6jgg-5f89-cp73.json index 09f0142fce8..5d716106310 100644 --- a/advisories/unreviewed/2024/05/GHSA-6jgg-5f89-cp73/GHSA-6jgg-5f89-cp73.json +++ b/advisories/unreviewed/2024/05/GHSA-6jgg-5f89-cp73/GHSA-6jgg-5f89-cp73.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6jgg-5f89-cp73", - "modified": "2024-05-14T18:30:49Z", + "modified": "2024-07-03T18:41:02Z", "published": "2024-05-14T18:30:49Z", "aliases": [ "CVE-2024-34222" ], "details": "Sourcecodester Human Resource Management System 1.0 is vulnerable to SQL Injection via the searccountry parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:38:36Z" diff --git a/advisories/unreviewed/2024/05/GHSA-6px8-gfpp-6wpc/GHSA-6px8-gfpp-6wpc.json b/advisories/unreviewed/2024/05/GHSA-6px8-gfpp-6wpc/GHSA-6px8-gfpp-6wpc.json index bd64ebf6df6..234f99097f1 100644 --- a/advisories/unreviewed/2024/05/GHSA-6px8-gfpp-6wpc/GHSA-6px8-gfpp-6wpc.json +++ b/advisories/unreviewed/2024/05/GHSA-6px8-gfpp-6wpc/GHSA-6px8-gfpp-6wpc.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-119" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-76hv-682v-6fpm/GHSA-76hv-682v-6fpm.json b/advisories/unreviewed/2024/05/GHSA-76hv-682v-6fpm/GHSA-76hv-682v-6fpm.json index 0a7c38fbe34..69c975e59db 100644 --- a/advisories/unreviewed/2024/05/GHSA-76hv-682v-6fpm/GHSA-76hv-682v-6fpm.json +++ b/advisories/unreviewed/2024/05/GHSA-76hv-682v-6fpm/GHSA-76hv-682v-6fpm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-76hv-682v-6fpm", - "modified": "2024-05-14T18:30:47Z", + "modified": "2024-07-03T18:40:40Z", "published": "2024-05-14T18:30:47Z", "aliases": [ "CVE-2024-32737" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-7gr6-pqw7-p68c/GHSA-7gr6-pqw7-p68c.json b/advisories/unreviewed/2024/05/GHSA-7gr6-pqw7-p68c/GHSA-7gr6-pqw7-p68c.json index 684d2d35e78..f78e24a1dd2 100644 --- a/advisories/unreviewed/2024/05/GHSA-7gr6-pqw7-p68c/GHSA-7gr6-pqw7-p68c.json +++ b/advisories/unreviewed/2024/05/GHSA-7gr6-pqw7-p68c/GHSA-7gr6-pqw7-p68c.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-463" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-7pxj-w55v-hwp4/GHSA-7pxj-w55v-hwp4.json b/advisories/unreviewed/2024/05/GHSA-7pxj-w55v-hwp4/GHSA-7pxj-w55v-hwp4.json index 5c46b680897..b0b24dcbf23 100644 --- a/advisories/unreviewed/2024/05/GHSA-7pxj-w55v-hwp4/GHSA-7pxj-w55v-hwp4.json +++ b/advisories/unreviewed/2024/05/GHSA-7pxj-w55v-hwp4/GHSA-7pxj-w55v-hwp4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7pxj-w55v-hwp4", - "modified": "2024-05-15T15:30:33Z", + "modified": "2024-07-03T18:41:56Z", "published": "2024-05-15T15:30:33Z", "aliases": [ "CVE-2024-25079" ], "details": "A memory corruption vulnerability in HddPassword in Insyde InsydeH2O kernel 5.2 before 05.29.09, kernel 5.3 before 05.38.09, kernel 5.4 before 05.46.09, kernel 5.5 before 05.54.09, and kernel 5.6 before 05.61.09 could lead to escalating privileges in SMM.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:L" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-822" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-15T15:15:07Z" diff --git a/advisories/unreviewed/2024/05/GHSA-7q29-7r79-pg2f/GHSA-7q29-7r79-pg2f.json b/advisories/unreviewed/2024/05/GHSA-7q29-7r79-pg2f/GHSA-7q29-7r79-pg2f.json index cd9154e0325..962a808b7ad 100644 --- a/advisories/unreviewed/2024/05/GHSA-7q29-7r79-pg2f/GHSA-7q29-7r79-pg2f.json +++ b/advisories/unreviewed/2024/05/GHSA-7q29-7r79-pg2f/GHSA-7q29-7r79-pg2f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7q29-7r79-pg2f", - "modified": "2024-05-14T18:30:49Z", + "modified": "2024-07-03T18:40:52Z", "published": "2024-05-14T18:30:49Z", "aliases": [ "CVE-2024-34200" ], "details": "TOTOLINK CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setIpQosRules function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:38:33Z" diff --git a/advisories/unreviewed/2024/05/GHSA-88hc-cq92-6755/GHSA-88hc-cq92-6755.json b/advisories/unreviewed/2024/05/GHSA-88hc-cq92-6755/GHSA-88hc-cq92-6755.json index 2ed45f8005c..d95f244bea0 100644 --- a/advisories/unreviewed/2024/05/GHSA-88hc-cq92-6755/GHSA-88hc-cq92-6755.json +++ b/advisories/unreviewed/2024/05/GHSA-88hc-cq92-6755/GHSA-88hc-cq92-6755.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-88hc-cq92-6755", - "modified": "2024-05-14T18:31:00Z", + "modified": "2024-07-03T18:41:23Z", "published": "2024-05-14T18:31:00Z", "aliases": [ "CVE-2024-32352" ], "details": "TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the \"ipsecL2tpEnable\" parameter in the \"cstecgi.cgi\" binary.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T16:17:03Z" diff --git a/advisories/unreviewed/2024/05/GHSA-8hpc-6883-68x9/GHSA-8hpc-6883-68x9.json b/advisories/unreviewed/2024/05/GHSA-8hpc-6883-68x9/GHSA-8hpc-6883-68x9.json index 5798b820f85..6da3b1390e5 100644 --- a/advisories/unreviewed/2024/05/GHSA-8hpc-6883-68x9/GHSA-8hpc-6883-68x9.json +++ b/advisories/unreviewed/2024/05/GHSA-8hpc-6883-68x9/GHSA-8hpc-6883-68x9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8hpc-6883-68x9", - "modified": "2024-05-14T18:30:46Z", + "modified": "2024-07-03T18:40:29Z", "published": "2024-05-14T18:30:46Z", "aliases": [ "CVE-2024-32612" ], "details": "HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5HL__fl_deserialize in H5HLcache.c, resulting in the corruption of the instruction pointer, a different vulnerability than CVE-2024-32613.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:36:46Z" diff --git a/advisories/unreviewed/2024/05/GHSA-8rh4-8m27-rjwj/GHSA-8rh4-8m27-rjwj.json b/advisories/unreviewed/2024/05/GHSA-8rh4-8m27-rjwj/GHSA-8rh4-8m27-rjwj.json index 3c4c4a3adbc..30a1675609b 100644 --- a/advisories/unreviewed/2024/05/GHSA-8rh4-8m27-rjwj/GHSA-8rh4-8m27-rjwj.json +++ b/advisories/unreviewed/2024/05/GHSA-8rh4-8m27-rjwj/GHSA-8rh4-8m27-rjwj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8rh4-8m27-rjwj", - "modified": "2024-05-14T18:31:00Z", + "modified": "2024-07-03T18:41:23Z", "published": "2024-05-14T18:31:00Z", "aliases": [ "CVE-2024-32349" ], "details": "TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the \"mtu\" parameters in the \"cstecgi.cgi\" binary.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T16:17:02Z" diff --git a/advisories/unreviewed/2024/05/GHSA-9335-6645-8v9q/GHSA-9335-6645-8v9q.json b/advisories/unreviewed/2024/05/GHSA-9335-6645-8v9q/GHSA-9335-6645-8v9q.json index 58070156d5a..a23e26cb029 100644 --- a/advisories/unreviewed/2024/05/GHSA-9335-6645-8v9q/GHSA-9335-6645-8v9q.json +++ b/advisories/unreviewed/2024/05/GHSA-9335-6645-8v9q/GHSA-9335-6645-8v9q.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-120" + "CWE-120", + "CWE-121" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-94jp-p24v-f62j/GHSA-94jp-p24v-f62j.json b/advisories/unreviewed/2024/05/GHSA-94jp-p24v-f62j/GHSA-94jp-p24v-f62j.json index 4241c3e43f4..0aba006c909 100644 --- a/advisories/unreviewed/2024/05/GHSA-94jp-p24v-f62j/GHSA-94jp-p24v-f62j.json +++ b/advisories/unreviewed/2024/05/GHSA-94jp-p24v-f62j/GHSA-94jp-p24v-f62j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-94jp-p24v-f62j", - "modified": "2024-05-14T18:30:51Z", + "modified": "2024-07-03T18:41:12Z", "published": "2024-05-14T18:30:51Z", "aliases": [ "CVE-2024-35050" ], "details": "An issue in SurveyKing v1.3.1 allows attackers to escalate privileges via re-using the session ID of a user that was deleted by an Admin.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-613" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:39:39Z" diff --git a/advisories/unreviewed/2024/05/GHSA-9656-q4mh-5w45/GHSA-9656-q4mh-5w45.json b/advisories/unreviewed/2024/05/GHSA-9656-q4mh-5w45/GHSA-9656-q4mh-5w45.json index dcffe6cf0fb..d76c6e9a81b 100644 --- a/advisories/unreviewed/2024/05/GHSA-9656-q4mh-5w45/GHSA-9656-q4mh-5w45.json +++ b/advisories/unreviewed/2024/05/GHSA-9656-q4mh-5w45/GHSA-9656-q4mh-5w45.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9656-q4mh-5w45", - "modified": "2024-05-14T18:30:49Z", + "modified": "2024-07-03T18:40:55Z", "published": "2024-05-14T18:30:49Z", "aliases": [ "CVE-2024-34203" ], "details": "TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setLanguageCfg function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:38:33Z" diff --git a/advisories/unreviewed/2024/05/GHSA-9f68-fj3x-pjr4/GHSA-9f68-fj3x-pjr4.json b/advisories/unreviewed/2024/05/GHSA-9f68-fj3x-pjr4/GHSA-9f68-fj3x-pjr4.json index e668c34d715..17ca0a1a40c 100644 --- a/advisories/unreviewed/2024/05/GHSA-9f68-fj3x-pjr4/GHSA-9f68-fj3x-pjr4.json +++ b/advisories/unreviewed/2024/05/GHSA-9f68-fj3x-pjr4/GHSA-9f68-fj3x-pjr4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9f68-fj3x-pjr4", - "modified": "2024-05-14T18:30:51Z", + "modified": "2024-07-03T18:41:06Z", "published": "2024-05-14T18:30:51Z", "aliases": [ "CVE-2024-34921" ], "details": "TOTOLINK X5000R v9.1.0cu.2350_B20230313 was discovered to contain a command injection via the disconnectVPN function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:39:37Z" diff --git a/advisories/unreviewed/2024/05/GHSA-9fxj-374w-r2wg/GHSA-9fxj-374w-r2wg.json b/advisories/unreviewed/2024/05/GHSA-9fxj-374w-r2wg/GHSA-9fxj-374w-r2wg.json index 42ac884b3b2..83cf92a223c 100644 --- a/advisories/unreviewed/2024/05/GHSA-9fxj-374w-r2wg/GHSA-9fxj-374w-r2wg.json +++ b/advisories/unreviewed/2024/05/GHSA-9fxj-374w-r2wg/GHSA-9fxj-374w-r2wg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9fxj-374w-r2wg", - "modified": "2024-05-14T18:31:05Z", + "modified": "2024-07-03T18:41:35Z", "published": "2024-05-14T18:31:05Z", "aliases": [ "CVE-2024-33485" ], "details": "SQL Injection vulnerability in CASAP Automated Enrollment System using PHP/MySQLi with Source Code V1.0 allows a remote attacker to obtain sensitive information via a crafted payload to the login.php component", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T18:15:11Z" diff --git a/advisories/unreviewed/2024/05/GHSA-c3rm-r6pr-rg5j/GHSA-c3rm-r6pr-rg5j.json b/advisories/unreviewed/2024/05/GHSA-c3rm-r6pr-rg5j/GHSA-c3rm-r6pr-rg5j.json index 168f5bd910e..5ed2e635db7 100644 --- a/advisories/unreviewed/2024/05/GHSA-c3rm-r6pr-rg5j/GHSA-c3rm-r6pr-rg5j.json +++ b/advisories/unreviewed/2024/05/GHSA-c3rm-r6pr-rg5j/GHSA-c3rm-r6pr-rg5j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c3rm-r6pr-rg5j", - "modified": "2024-05-14T18:31:02Z", + "modified": "2024-07-03T18:41:33Z", "published": "2024-05-14T18:31:02Z", "aliases": [ "CVE-2024-34950" ], "details": "D-Link DIR-822+ v1.0.5 was discovered to contain a stack-based buffer overflow vulnerability in the SetNetworkTomographySettings function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T16:17:30Z" diff --git a/advisories/unreviewed/2024/05/GHSA-c3xc-5f5r-x95w/GHSA-c3xc-5f5r-x95w.json b/advisories/unreviewed/2024/05/GHSA-c3xc-5f5r-x95w/GHSA-c3xc-5f5r-x95w.json index e3f07d1fe0a..c7960b4ba79 100644 --- a/advisories/unreviewed/2024/05/GHSA-c3xc-5f5r-x95w/GHSA-c3xc-5f5r-x95w.json +++ b/advisories/unreviewed/2024/05/GHSA-c3xc-5f5r-x95w/GHSA-c3xc-5f5r-x95w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c3xc-5f5r-x95w", - "modified": "2024-05-14T18:30:46Z", + "modified": "2024-07-03T18:40:37Z", "published": "2024-05-14T18:30:46Z", "aliases": [ "CVE-2024-32616" ], "details": "HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5O__dtype_encode_helper in H5Odtype.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:36:46Z" diff --git a/advisories/unreviewed/2024/05/GHSA-c4p6-9xvf-x54w/GHSA-c4p6-9xvf-x54w.json b/advisories/unreviewed/2024/05/GHSA-c4p6-9xvf-x54w/GHSA-c4p6-9xvf-x54w.json index d227f4f23f1..3e8c82ee70e 100644 --- a/advisories/unreviewed/2024/05/GHSA-c4p6-9xvf-x54w/GHSA-c4p6-9xvf-x54w.json +++ b/advisories/unreviewed/2024/05/GHSA-c4p6-9xvf-x54w/GHSA-c4p6-9xvf-x54w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c4p6-9xvf-x54w", - "modified": "2024-05-14T18:30:49Z", + "modified": "2024-07-03T18:40:55Z", "published": "2024-05-14T18:30:49Z", "aliases": [ "CVE-2024-34206" ], "details": "TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the setWebWlanIdx function via the webWlanIdx parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:38:34Z" diff --git a/advisories/unreviewed/2024/05/GHSA-c738-rr4c-jj27/GHSA-c738-rr4c-jj27.json b/advisories/unreviewed/2024/05/GHSA-c738-rr4c-jj27/GHSA-c738-rr4c-jj27.json index 7e0fc509583..6f754e5c9ea 100644 --- a/advisories/unreviewed/2024/05/GHSA-c738-rr4c-jj27/GHSA-c738-rr4c-jj27.json +++ b/advisories/unreviewed/2024/05/GHSA-c738-rr4c-jj27/GHSA-c738-rr4c-jj27.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c738-rr4c-jj27", - "modified": "2024-05-14T18:31:00Z", + "modified": "2024-07-03T18:41:24Z", "published": "2024-05-14T18:31:00Z", "aliases": [ "CVE-2024-32355" ], "details": "TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'password' parameter in the setSSServer function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T16:17:03Z" diff --git a/advisories/unreviewed/2024/05/GHSA-c76f-4g6w-3ff9/GHSA-c76f-4g6w-3ff9.json b/advisories/unreviewed/2024/05/GHSA-c76f-4g6w-3ff9/GHSA-c76f-4g6w-3ff9.json index ef77c646e2b..014bb632f66 100644 --- a/advisories/unreviewed/2024/05/GHSA-c76f-4g6w-3ff9/GHSA-c76f-4g6w-3ff9.json +++ b/advisories/unreviewed/2024/05/GHSA-c76f-4g6w-3ff9/GHSA-c76f-4g6w-3ff9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c76f-4g6w-3ff9", - "modified": "2024-05-15T15:30:33Z", + "modified": "2024-07-03T18:41:57Z", "published": "2024-05-15T15:30:33Z", "aliases": [ "CVE-2024-27353" ], "details": "A memory corruption vulnerability in SdHost and SdMmcDevice in Insyde InsydeH2O kernel 5.2 before 05.29.09, kernel 5.3 before 05.38.09, kernel 5.4 before 05.46.09, kernel 5.5 before 05.54.09, and kernel 5.6 before 05.61.09 could lead to escalating privileges in SMM.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:L" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-822" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-15T15:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-cgrv-qh7r-p7q6/GHSA-cgrv-qh7r-p7q6.json b/advisories/unreviewed/2024/05/GHSA-cgrv-qh7r-p7q6/GHSA-cgrv-qh7r-p7q6.json index 30a9db4c050..c3b38b4fe7e 100644 --- a/advisories/unreviewed/2024/05/GHSA-cgrv-qh7r-p7q6/GHSA-cgrv-qh7r-p7q6.json +++ b/advisories/unreviewed/2024/05/GHSA-cgrv-qh7r-p7q6/GHSA-cgrv-qh7r-p7q6.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-20" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/05/GHSA-chh9-c5qm-7x5j/GHSA-chh9-c5qm-7x5j.json b/advisories/unreviewed/2024/05/GHSA-chh9-c5qm-7x5j/GHSA-chh9-c5qm-7x5j.json index cc9dde19e6f..a62b421865c 100644 --- a/advisories/unreviewed/2024/05/GHSA-chh9-c5qm-7x5j/GHSA-chh9-c5qm-7x5j.json +++ b/advisories/unreviewed/2024/05/GHSA-chh9-c5qm-7x5j/GHSA-chh9-c5qm-7x5j.json @@ -25,7 +25,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-cpx5-6mwc-hxp6/GHSA-cpx5-6mwc-hxp6.json b/advisories/unreviewed/2024/05/GHSA-cpx5-6mwc-hxp6/GHSA-cpx5-6mwc-hxp6.json index 67ff9bea808..7320923292a 100644 --- a/advisories/unreviewed/2024/05/GHSA-cpx5-6mwc-hxp6/GHSA-cpx5-6mwc-hxp6.json +++ b/advisories/unreviewed/2024/05/GHSA-cpx5-6mwc-hxp6/GHSA-cpx5-6mwc-hxp6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cpx5-6mwc-hxp6", - "modified": "2024-05-14T18:30:46Z", + "modified": "2024-07-03T18:40:34Z", "published": "2024-05-14T18:30:46Z", "aliases": [ "CVE-2024-32615" ], "details": "HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5Z__nbit_decompress_one_byte in H5Znbit.c, caused by the earlier use of an initialized pointer.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:36:46Z" diff --git a/advisories/unreviewed/2024/05/GHSA-crf4-j4g9-p5f8/GHSA-crf4-j4g9-p5f8.json b/advisories/unreviewed/2024/05/GHSA-crf4-j4g9-p5f8/GHSA-crf4-j4g9-p5f8.json index 8fc31c9d0af..78ca2458c62 100644 --- a/advisories/unreviewed/2024/05/GHSA-crf4-j4g9-p5f8/GHSA-crf4-j4g9-p5f8.json +++ b/advisories/unreviewed/2024/05/GHSA-crf4-j4g9-p5f8/GHSA-crf4-j4g9-p5f8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-crf4-j4g9-p5f8", - "modified": "2024-05-14T18:30:51Z", + "modified": "2024-07-03T18:41:11Z", "published": "2024-05-14T18:30:51Z", "aliases": [ "CVE-2024-35048" ], "details": "An issue in SurveyKing v1.3.1 allows attackers to execute a session replay attack after a user changes their password.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-613" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:39:38Z" diff --git a/advisories/unreviewed/2024/05/GHSA-f7gp-8jp4-wwj5/GHSA-f7gp-8jp4-wwj5.json b/advisories/unreviewed/2024/05/GHSA-f7gp-8jp4-wwj5/GHSA-f7gp-8jp4-wwj5.json index e6c18fe0f8f..ba8314aff61 100644 --- a/advisories/unreviewed/2024/05/GHSA-f7gp-8jp4-wwj5/GHSA-f7gp-8jp4-wwj5.json +++ b/advisories/unreviewed/2024/05/GHSA-f7gp-8jp4-wwj5/GHSA-f7gp-8jp4-wwj5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f7gp-8jp4-wwj5", - "modified": "2024-05-14T18:30:51Z", + "modified": "2024-07-03T18:41:08Z", "published": "2024-05-14T18:30:51Z", "aliases": [ "CVE-2024-34946" ], "details": "Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at ip/goform/DhcpListClient.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:39:38Z" diff --git a/advisories/unreviewed/2024/05/GHSA-f9xr-555m-75cp/GHSA-f9xr-555m-75cp.json b/advisories/unreviewed/2024/05/GHSA-f9xr-555m-75cp/GHSA-f9xr-555m-75cp.json index 33ce4f45a20..dad0620f136 100644 --- a/advisories/unreviewed/2024/05/GHSA-f9xr-555m-75cp/GHSA-f9xr-555m-75cp.json +++ b/advisories/unreviewed/2024/05/GHSA-f9xr-555m-75cp/GHSA-f9xr-555m-75cp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f9xr-555m-75cp", - "modified": "2024-05-14T18:30:46Z", + "modified": "2024-07-03T18:40:38Z", "published": "2024-05-14T18:30:46Z", "aliases": [ "CVE-2024-32623" ], "details": "HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5VM_array_fill in H5VM.c (called from H5S_select_elements in H5Spoint.c).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:36:47Z" diff --git a/advisories/unreviewed/2024/05/GHSA-fffc-4hjp-2r9v/GHSA-fffc-4hjp-2r9v.json b/advisories/unreviewed/2024/05/GHSA-fffc-4hjp-2r9v/GHSA-fffc-4hjp-2r9v.json index 42044c3e8ac..0d981d037ae 100644 --- a/advisories/unreviewed/2024/05/GHSA-fffc-4hjp-2r9v/GHSA-fffc-4hjp-2r9v.json +++ b/advisories/unreviewed/2024/05/GHSA-fffc-4hjp-2r9v/GHSA-fffc-4hjp-2r9v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fffc-4hjp-2r9v", - "modified": "2024-06-10T18:31:01Z", + "modified": "2024-07-03T18:41:35Z", "published": "2024-05-14T18:31:05Z", "aliases": [ "CVE-2024-4767" ], "details": "If the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB files were not properly deleted when the window was closed. This preference is disabled by default in Firefox. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T18:15:13Z" diff --git a/advisories/unreviewed/2024/05/GHSA-fv84-h83r-2rc5/GHSA-fv84-h83r-2rc5.json b/advisories/unreviewed/2024/05/GHSA-fv84-h83r-2rc5/GHSA-fv84-h83r-2rc5.json index d840c0885ac..d6e01a41187 100644 --- a/advisories/unreviewed/2024/05/GHSA-fv84-h83r-2rc5/GHSA-fv84-h83r-2rc5.json +++ b/advisories/unreviewed/2024/05/GHSA-fv84-h83r-2rc5/GHSA-fv84-h83r-2rc5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fv84-h83r-2rc5", - "modified": "2024-05-14T18:30:59Z", + "modified": "2024-07-03T18:41:23Z", "published": "2024-05-14T18:30:59Z", "aliases": [ "CVE-2024-22269" @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-fvfx-gv98-q344/GHSA-fvfx-gv98-q344.json b/advisories/unreviewed/2024/05/GHSA-fvfx-gv98-q344/GHSA-fvfx-gv98-q344.json index 9012b798487..008135944a7 100644 --- a/advisories/unreviewed/2024/05/GHSA-fvfx-gv98-q344/GHSA-fvfx-gv98-q344.json +++ b/advisories/unreviewed/2024/05/GHSA-fvfx-gv98-q344/GHSA-fvfx-gv98-q344.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-703", "CWE-754" ], "severity": "LOW", diff --git a/advisories/unreviewed/2024/05/GHSA-fvhg-7469-pq78/GHSA-fvhg-7469-pq78.json b/advisories/unreviewed/2024/05/GHSA-fvhg-7469-pq78/GHSA-fvhg-7469-pq78.json index c33d6341b5e..df3b75c83a5 100644 --- a/advisories/unreviewed/2024/05/GHSA-fvhg-7469-pq78/GHSA-fvhg-7469-pq78.json +++ b/advisories/unreviewed/2024/05/GHSA-fvhg-7469-pq78/GHSA-fvhg-7469-pq78.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-g86v-m7q4-wf42/GHSA-g86v-m7q4-wf42.json b/advisories/unreviewed/2024/05/GHSA-g86v-m7q4-wf42/GHSA-g86v-m7q4-wf42.json index f29e5d54b5c..604eb09687c 100644 --- a/advisories/unreviewed/2024/05/GHSA-g86v-m7q4-wf42/GHSA-g86v-m7q4-wf42.json +++ b/advisories/unreviewed/2024/05/GHSA-g86v-m7q4-wf42/GHSA-g86v-m7q4-wf42.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g86v-m7q4-wf42", - "modified": "2024-05-14T18:30:58Z", + "modified": "2024-07-03T18:41:23Z", "published": "2024-05-14T18:30:58Z", "aliases": [ "CVE-2024-1598" @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-g9gj-v6cc-49m8/GHSA-g9gj-v6cc-49m8.json b/advisories/unreviewed/2024/05/GHSA-g9gj-v6cc-49m8/GHSA-g9gj-v6cc-49m8.json index 51aa253fe60..2ea7e4ee04a 100644 --- a/advisories/unreviewed/2024/05/GHSA-g9gj-v6cc-49m8/GHSA-g9gj-v6cc-49m8.json +++ b/advisories/unreviewed/2024/05/GHSA-g9gj-v6cc-49m8/GHSA-g9gj-v6cc-49m8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g9gj-v6cc-49m8", - "modified": "2024-05-16T15:31:37Z", + "modified": "2024-07-03T18:42:06Z", "published": "2024-05-16T15:31:37Z", "aliases": [ "CVE-2024-34582" ], "details": "Sunhillo SureLine through 8.10.0 on RICI 5000 devices allows cgi/usrPasswd.cgi userid_change XSS within the Forgot Password feature.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-16T15:15:47Z" diff --git a/advisories/unreviewed/2024/05/GHSA-gc43-cvgg-xjpv/GHSA-gc43-cvgg-xjpv.json b/advisories/unreviewed/2024/05/GHSA-gc43-cvgg-xjpv/GHSA-gc43-cvgg-xjpv.json index 7c5c50ce7c6..5b94ac02e8a 100644 --- a/advisories/unreviewed/2024/05/GHSA-gc43-cvgg-xjpv/GHSA-gc43-cvgg-xjpv.json +++ b/advisories/unreviewed/2024/05/GHSA-gc43-cvgg-xjpv/GHSA-gc43-cvgg-xjpv.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-269", "CWE-668" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/05/GHSA-gh8g-37ff-mvrg/GHSA-gh8g-37ff-mvrg.json b/advisories/unreviewed/2024/05/GHSA-gh8g-37ff-mvrg/GHSA-gh8g-37ff-mvrg.json index faff211309c..2fb9ce8630e 100644 --- a/advisories/unreviewed/2024/05/GHSA-gh8g-37ff-mvrg/GHSA-gh8g-37ff-mvrg.json +++ b/advisories/unreviewed/2024/05/GHSA-gh8g-37ff-mvrg/GHSA-gh8g-37ff-mvrg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gh8g-37ff-mvrg", - "modified": "2024-05-14T18:30:49Z", + "modified": "2024-07-03T18:41:00Z", "published": "2024-05-14T18:30:49Z", "aliases": [ "CVE-2024-34213" ], "details": "TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the SetPortForwardRules function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:38:35Z" diff --git a/advisories/unreviewed/2024/05/GHSA-gmmc-jv6q-8crf/GHSA-gmmc-jv6q-8crf.json b/advisories/unreviewed/2024/05/GHSA-gmmc-jv6q-8crf/GHSA-gmmc-jv6q-8crf.json index 6b487d86aac..cfeb341b19f 100644 --- a/advisories/unreviewed/2024/05/GHSA-gmmc-jv6q-8crf/GHSA-gmmc-jv6q-8crf.json +++ b/advisories/unreviewed/2024/05/GHSA-gmmc-jv6q-8crf/GHSA-gmmc-jv6q-8crf.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-grq5-cg54-wp35/GHSA-grq5-cg54-wp35.json b/advisories/unreviewed/2024/05/GHSA-grq5-cg54-wp35/GHSA-grq5-cg54-wp35.json index 6ce543d89f1..ebeaabd3181 100644 --- a/advisories/unreviewed/2024/05/GHSA-grq5-cg54-wp35/GHSA-grq5-cg54-wp35.json +++ b/advisories/unreviewed/2024/05/GHSA-grq5-cg54-wp35/GHSA-grq5-cg54-wp35.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-grq5-cg54-wp35", - "modified": "2024-05-14T18:30:50Z", + "modified": "2024-07-03T18:41:05Z", "published": "2024-05-14T18:30:49Z", "aliases": [ "CVE-2024-34308" ], "details": "TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the password parameter in the function urldecode.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:38:38Z" diff --git a/advisories/unreviewed/2024/05/GHSA-h256-c797-73hf/GHSA-h256-c797-73hf.json b/advisories/unreviewed/2024/05/GHSA-h256-c797-73hf/GHSA-h256-c797-73hf.json index e525169a57b..753182c2f35 100644 --- a/advisories/unreviewed/2024/05/GHSA-h256-c797-73hf/GHSA-h256-c797-73hf.json +++ b/advisories/unreviewed/2024/05/GHSA-h256-c797-73hf/GHSA-h256-c797-73hf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h256-c797-73hf", - "modified": "2024-05-14T18:31:01Z", + "modified": "2024-07-03T18:41:28Z", "published": "2024-05-14T18:31:01Z", "aliases": [ "CVE-2024-33863" ], "details": "An issue was discovered in linqi before 1.4.0.1 on Windows. There is /api/Cdn/GetFile local file inclusion.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-98" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T16:17:22Z" diff --git a/advisories/unreviewed/2024/05/GHSA-h2pj-pf6w-85p2/GHSA-h2pj-pf6w-85p2.json b/advisories/unreviewed/2024/05/GHSA-h2pj-pf6w-85p2/GHSA-h2pj-pf6w-85p2.json index 105d167f246..e42b7ffab3d 100644 --- a/advisories/unreviewed/2024/05/GHSA-h2pj-pf6w-85p2/GHSA-h2pj-pf6w-85p2.json +++ b/advisories/unreviewed/2024/05/GHSA-h2pj-pf6w-85p2/GHSA-h2pj-pf6w-85p2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h2pj-pf6w-85p2", - "modified": "2024-06-10T18:31:02Z", + "modified": "2024-07-03T18:42:04Z", "published": "2024-05-15T21:31:26Z", "aliases": [ "CVE-2024-4950" ], "details": "Inappropriate implementation in Downloads in Google Chrome prior to 125.0.6422.60 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-15T21:15:09Z" diff --git a/advisories/unreviewed/2024/05/GHSA-h554-f2fg-8fw5/GHSA-h554-f2fg-8fw5.json b/advisories/unreviewed/2024/05/GHSA-h554-f2fg-8fw5/GHSA-h554-f2fg-8fw5.json index 5e255baf5f8..3ea091c7a47 100644 --- a/advisories/unreviewed/2024/05/GHSA-h554-f2fg-8fw5/GHSA-h554-f2fg-8fw5.json +++ b/advisories/unreviewed/2024/05/GHSA-h554-f2fg-8fw5/GHSA-h554-f2fg-8fw5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h554-f2fg-8fw5", - "modified": "2024-05-15T15:30:33Z", + "modified": "2024-07-03T18:41:58Z", "published": "2024-05-15T15:30:33Z", "aliases": [ "CVE-2024-34955" ], "details": "Code-projects Budget Management 1.0 is vulnerable to SQL Injection via the delete parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-15T15:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-hx7q-82h5-f6mc/GHSA-hx7q-82h5-f6mc.json b/advisories/unreviewed/2024/05/GHSA-hx7q-82h5-f6mc/GHSA-hx7q-82h5-f6mc.json index 76c8242d2f9..0acd1d20e25 100644 --- a/advisories/unreviewed/2024/05/GHSA-hx7q-82h5-f6mc/GHSA-hx7q-82h5-f6mc.json +++ b/advisories/unreviewed/2024/05/GHSA-hx7q-82h5-f6mc/GHSA-hx7q-82h5-f6mc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hx7q-82h5-f6mc", - "modified": "2024-05-15T03:30:44Z", + "modified": "2024-07-03T18:41:55Z", "published": "2024-05-15T03:30:44Z", "aliases": [ "CVE-2024-35109" ], "details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /homePro_deal.php?mudi=add&nohrefStr=close.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-15T02:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-hxrp-wx99-35hh/GHSA-hxrp-wx99-35hh.json b/advisories/unreviewed/2024/05/GHSA-hxrp-wx99-35hh/GHSA-hxrp-wx99-35hh.json index ecfe7eb7a13..c84ba012e0b 100644 --- a/advisories/unreviewed/2024/05/GHSA-hxrp-wx99-35hh/GHSA-hxrp-wx99-35hh.json +++ b/advisories/unreviewed/2024/05/GHSA-hxrp-wx99-35hh/GHSA-hxrp-wx99-35hh.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-269", "CWE-427" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/05/GHSA-hxxh-fvrv-f5f5/GHSA-hxxh-fvrv-f5f5.json b/advisories/unreviewed/2024/05/GHSA-hxxh-fvrv-f5f5/GHSA-hxxh-fvrv-f5f5.json index 840d6dfc11f..329cd3e3059 100644 --- a/advisories/unreviewed/2024/05/GHSA-hxxh-fvrv-f5f5/GHSA-hxxh-fvrv-f5f5.json +++ b/advisories/unreviewed/2024/05/GHSA-hxxh-fvrv-f5f5/GHSA-hxxh-fvrv-f5f5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hxxh-fvrv-f5f5", - "modified": "2024-05-14T18:30:49Z", + "modified": "2024-07-03T18:40:53Z", "published": "2024-05-14T18:30:49Z", "aliases": [ "CVE-2024-34202" ], "details": "TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setMacFilterRules function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:38:33Z" diff --git a/advisories/unreviewed/2024/05/GHSA-j7cc-68q3-4fm7/GHSA-j7cc-68q3-4fm7.json b/advisories/unreviewed/2024/05/GHSA-j7cc-68q3-4fm7/GHSA-j7cc-68q3-4fm7.json index 534fa5f33d1..5be9c25107a 100644 --- a/advisories/unreviewed/2024/05/GHSA-j7cc-68q3-4fm7/GHSA-j7cc-68q3-4fm7.json +++ b/advisories/unreviewed/2024/05/GHSA-j7cc-68q3-4fm7/GHSA-j7cc-68q3-4fm7.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-665" + "CWE-665", + "CWE-707" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-j7v6-qmgv-768h/GHSA-j7v6-qmgv-768h.json b/advisories/unreviewed/2024/05/GHSA-j7v6-qmgv-768h/GHSA-j7v6-qmgv-768h.json index b53ff62d381..9e335d21aec 100644 --- a/advisories/unreviewed/2024/05/GHSA-j7v6-qmgv-768h/GHSA-j7v6-qmgv-768h.json +++ b/advisories/unreviewed/2024/05/GHSA-j7v6-qmgv-768h/GHSA-j7v6-qmgv-768h.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-jf76-3x62-8fgf/GHSA-jf76-3x62-8fgf.json b/advisories/unreviewed/2024/05/GHSA-jf76-3x62-8fgf/GHSA-jf76-3x62-8fgf.json index 3f9e416328f..5d452ecad31 100644 --- a/advisories/unreviewed/2024/05/GHSA-jf76-3x62-8fgf/GHSA-jf76-3x62-8fgf.json +++ b/advisories/unreviewed/2024/05/GHSA-jf76-3x62-8fgf/GHSA-jf76-3x62-8fgf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jf76-3x62-8fgf", - "modified": "2024-05-14T18:30:48Z", + "modified": "2024-07-03T18:40:42Z", "published": "2024-05-14T18:30:48Z", "aliases": [ "CVE-2024-33772" ], "details": "A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via formTcpipSetup allows remote authenticated users to trigger a denial of service (DoS) through the parameter \"curTime.\"", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:38:05Z" diff --git a/advisories/unreviewed/2024/05/GHSA-jqcw-w3rj-6rhg/GHSA-jqcw-w3rj-6rhg.json b/advisories/unreviewed/2024/05/GHSA-jqcw-w3rj-6rhg/GHSA-jqcw-w3rj-6rhg.json index 819e24fc5cf..5a0d01ffa9d 100644 --- a/advisories/unreviewed/2024/05/GHSA-jqcw-w3rj-6rhg/GHSA-jqcw-w3rj-6rhg.json +++ b/advisories/unreviewed/2024/05/GHSA-jqcw-w3rj-6rhg/GHSA-jqcw-w3rj-6rhg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jqcw-w3rj-6rhg", - "modified": "2024-05-15T03:30:43Z", + "modified": "2024-07-03T18:41:55Z", "published": "2024-05-15T03:30:43Z", "aliases": [ "CVE-2024-35108" ], "details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/homePro_deal.php?mudi=del&dataType=&dataTypeCN.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-15T02:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-jr2r-57f7-7qgq/GHSA-jr2r-57f7-7qgq.json b/advisories/unreviewed/2024/05/GHSA-jr2r-57f7-7qgq/GHSA-jr2r-57f7-7qgq.json index 2f37189ad31..26b021317f0 100644 --- a/advisories/unreviewed/2024/05/GHSA-jr2r-57f7-7qgq/GHSA-jr2r-57f7-7qgq.json +++ b/advisories/unreviewed/2024/05/GHSA-jr2r-57f7-7qgq/GHSA-jr2r-57f7-7qgq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jr2r-57f7-7qgq", - "modified": "2024-05-14T18:30:46Z", + "modified": "2024-07-03T18:40:33Z", "published": "2024-05-14T18:30:46Z", "aliases": [ "CVE-2024-32614" ], "details": "HDF5 Library through 1.14.3 has a SEGV in H5VM_memcpyvv in H5VM.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:36:46Z" diff --git a/advisories/unreviewed/2024/05/GHSA-mqpq-887p-5xgm/GHSA-mqpq-887p-5xgm.json b/advisories/unreviewed/2024/05/GHSA-mqpq-887p-5xgm/GHSA-mqpq-887p-5xgm.json index 1e65f6c089c..4f4fd14ac4f 100644 --- a/advisories/unreviewed/2024/05/GHSA-mqpq-887p-5xgm/GHSA-mqpq-887p-5xgm.json +++ b/advisories/unreviewed/2024/05/GHSA-mqpq-887p-5xgm/GHSA-mqpq-887p-5xgm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mqpq-887p-5xgm", - "modified": "2024-05-14T18:30:51Z", + "modified": "2024-07-03T18:41:12Z", "published": "2024-05-14T18:30:51Z", "aliases": [ "CVE-2024-35049" ], "details": "SurveyKing v1.3.1 was discovered to keep users' sessions active after logout. Related to an incomplete fix for CVE-2022-25590.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-613" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:39:39Z" diff --git a/advisories/unreviewed/2024/05/GHSA-mxgq-2jwv-2cc8/GHSA-mxgq-2jwv-2cc8.json b/advisories/unreviewed/2024/05/GHSA-mxgq-2jwv-2cc8/GHSA-mxgq-2jwv-2cc8.json index b975c750395..bd2a15b1c24 100644 --- a/advisories/unreviewed/2024/05/GHSA-mxgq-2jwv-2cc8/GHSA-mxgq-2jwv-2cc8.json +++ b/advisories/unreviewed/2024/05/GHSA-mxgq-2jwv-2cc8/GHSA-mxgq-2jwv-2cc8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mxgq-2jwv-2cc8", - "modified": "2024-05-14T18:30:49Z", + "modified": "2024-07-03T18:41:01Z", "published": "2024-05-14T18:30:49Z", "aliases": [ "CVE-2024-34218" ], "details": "TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the NTPSyncWithHost function via the hostTime parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:38:35Z" diff --git a/advisories/unreviewed/2024/05/GHSA-p2hw-rvhj-wg9r/GHSA-p2hw-rvhj-wg9r.json b/advisories/unreviewed/2024/05/GHSA-p2hw-rvhj-wg9r/GHSA-p2hw-rvhj-wg9r.json index 813861fccec..2deec5098ce 100644 --- a/advisories/unreviewed/2024/05/GHSA-p2hw-rvhj-wg9r/GHSA-p2hw-rvhj-wg9r.json +++ b/advisories/unreviewed/2024/05/GHSA-p2hw-rvhj-wg9r/GHSA-p2hw-rvhj-wg9r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p2hw-rvhj-wg9r", - "modified": "2024-05-14T18:30:49Z", + "modified": "2024-07-03T18:41:00Z", "published": "2024-05-14T18:30:49Z", "aliases": [ "CVE-2024-34215" ], "details": "TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setUrlFilterRules function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:38:35Z" diff --git a/advisories/unreviewed/2024/05/GHSA-p55r-fqh8-ccwq/GHSA-p55r-fqh8-ccwq.json b/advisories/unreviewed/2024/05/GHSA-p55r-fqh8-ccwq/GHSA-p55r-fqh8-ccwq.json index 0eaf4b29ec5..683686a861a 100644 --- a/advisories/unreviewed/2024/05/GHSA-p55r-fqh8-ccwq/GHSA-p55r-fqh8-ccwq.json +++ b/advisories/unreviewed/2024/05/GHSA-p55r-fqh8-ccwq/GHSA-p55r-fqh8-ccwq.json @@ -1,14 +1,21 @@ { "schema_version": "1.4.0", "id": "GHSA-p55r-fqh8-ccwq", - "modified": "2024-06-05T15:30:38Z", + "modified": "2024-07-03T18:41:22Z", "published": "2024-05-14T18:30:54Z", "aliases": [ "CVE-2024-4232" ], "details": "This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to presence of root terminal access on a serial interface without proper access control. An attacker with physical access could exploit this by identifying UART pins and accessing the root shell on the vulnerable system.\n\nSuccessful exploitation of this vulnerability could allow the attacker to access the sensitive information on the targeted system.This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to lack of encryption or hashing in storing of passwords within the router's firmware/ database. An attacker with physical access could exploit this by extracting the firmware and reverse engineer the binary data to access the plaintext passwords on the vulnerable system.\n\nSuccessful exploitation of this vulnerability could allow the attacker to gain unauthorized access to the targeted system.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } ], "affected": [ @@ -27,7 +34,7 @@ "cwe_ids": [ "CWE-256" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:43:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-p76p-6f26-4vgq/GHSA-p76p-6f26-4vgq.json b/advisories/unreviewed/2024/05/GHSA-p76p-6f26-4vgq/GHSA-p76p-6f26-4vgq.json index 06f0a10e1ae..5908e925654 100644 --- a/advisories/unreviewed/2024/05/GHSA-p76p-6f26-4vgq/GHSA-p76p-6f26-4vgq.json +++ b/advisories/unreviewed/2024/05/GHSA-p76p-6f26-4vgq/GHSA-p76p-6f26-4vgq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p76p-6f26-4vgq", - "modified": "2024-06-10T18:31:02Z", + "modified": "2024-07-03T18:42:03Z", "published": "2024-05-15T21:31:26Z", "aliases": [ "CVE-2024-4949" ], "details": "Use after free in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-15T21:15:09Z" diff --git a/advisories/unreviewed/2024/05/GHSA-p98r-qmj8-g8hj/GHSA-p98r-qmj8-g8hj.json b/advisories/unreviewed/2024/05/GHSA-p98r-qmj8-g8hj/GHSA-p98r-qmj8-g8hj.json index d6afeb8fc01..e8ad0cd8c52 100644 --- a/advisories/unreviewed/2024/05/GHSA-p98r-qmj8-g8hj/GHSA-p98r-qmj8-g8hj.json +++ b/advisories/unreviewed/2024/05/GHSA-p98r-qmj8-g8hj/GHSA-p98r-qmj8-g8hj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p98r-qmj8-g8hj", - "modified": "2024-05-14T18:30:51Z", + "modified": "2024-07-03T18:41:11Z", "published": "2024-05-14T18:30:51Z", "aliases": [ "CVE-2024-34974" ], "details": "Tenda AC18 v15.03.05.19 is vulnerable to Buffer Overflow in the formSetPPTPServer function via the endIp parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:39:38Z" diff --git a/advisories/unreviewed/2024/05/GHSA-pg94-fmcp-687m/GHSA-pg94-fmcp-687m.json b/advisories/unreviewed/2024/05/GHSA-pg94-fmcp-687m/GHSA-pg94-fmcp-687m.json index 4dc7c3216b6..599b7db0ff8 100644 --- a/advisories/unreviewed/2024/05/GHSA-pg94-fmcp-687m/GHSA-pg94-fmcp-687m.json +++ b/advisories/unreviewed/2024/05/GHSA-pg94-fmcp-687m/GHSA-pg94-fmcp-687m.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-pgpp-7m6r-q4w2/GHSA-pgpp-7m6r-q4w2.json b/advisories/unreviewed/2024/05/GHSA-pgpp-7m6r-q4w2/GHSA-pgpp-7m6r-q4w2.json index ab0923f5535..dc4eca8fb03 100644 --- a/advisories/unreviewed/2024/05/GHSA-pgpp-7m6r-q4w2/GHSA-pgpp-7m6r-q4w2.json +++ b/advisories/unreviewed/2024/05/GHSA-pgpp-7m6r-q4w2/GHSA-pgpp-7m6r-q4w2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pgpp-7m6r-q4w2", - "modified": "2024-05-15T21:31:26Z", + "modified": "2024-07-03T18:42:01Z", "published": "2024-05-15T21:31:26Z", "aliases": [ "CVE-2024-34909" ], "details": "An arbitrary file upload vulnerability in KYKMS v1.0.1 and below allows attackers to execute arbitrary code via uploading a crafted PDF file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,10 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434", + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-15T20:15:13Z" diff --git a/advisories/unreviewed/2024/05/GHSA-ph38-cmg3-w56j/GHSA-ph38-cmg3-w56j.json b/advisories/unreviewed/2024/05/GHSA-ph38-cmg3-w56j/GHSA-ph38-cmg3-w56j.json index 81855744233..3297e329beb 100644 --- a/advisories/unreviewed/2024/05/GHSA-ph38-cmg3-w56j/GHSA-ph38-cmg3-w56j.json +++ b/advisories/unreviewed/2024/05/GHSA-ph38-cmg3-w56j/GHSA-ph38-cmg3-w56j.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1220", "CWE-284" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/05/GHSA-pjp4-f857-pw2v/GHSA-pjp4-f857-pw2v.json b/advisories/unreviewed/2024/05/GHSA-pjp4-f857-pw2v/GHSA-pjp4-f857-pw2v.json index 095bf815f92..ae309725804 100644 --- a/advisories/unreviewed/2024/05/GHSA-pjp4-f857-pw2v/GHSA-pjp4-f857-pw2v.json +++ b/advisories/unreviewed/2024/05/GHSA-pjp4-f857-pw2v/GHSA-pjp4-f857-pw2v.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-pmhm-2vvm-8rvj/GHSA-pmhm-2vvm-8rvj.json b/advisories/unreviewed/2024/05/GHSA-pmhm-2vvm-8rvj/GHSA-pmhm-2vvm-8rvj.json index 3d4304e3a0d..22ec12b6826 100644 --- a/advisories/unreviewed/2024/05/GHSA-pmhm-2vvm-8rvj/GHSA-pmhm-2vvm-8rvj.json +++ b/advisories/unreviewed/2024/05/GHSA-pmhm-2vvm-8rvj/GHSA-pmhm-2vvm-8rvj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pmhm-2vvm-8rvj", - "modified": "2024-05-14T18:31:01Z", + "modified": "2024-07-03T18:41:32Z", "published": "2024-05-14T18:31:01Z", "aliases": [ "CVE-2024-33867" ], "details": "An issue was discovered in linqi before 1.4.0.1 on Windows. There is a hardcoded password salt.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:L/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-259" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T16:17:22Z" diff --git a/advisories/unreviewed/2024/05/GHSA-pp3p-ch6p-j7fr/GHSA-pp3p-ch6p-j7fr.json b/advisories/unreviewed/2024/05/GHSA-pp3p-ch6p-j7fr/GHSA-pp3p-ch6p-j7fr.json index 030b901ff85..c39afdfdc66 100644 --- a/advisories/unreviewed/2024/05/GHSA-pp3p-ch6p-j7fr/GHSA-pp3p-ch6p-j7fr.json +++ b/advisories/unreviewed/2024/05/GHSA-pp3p-ch6p-j7fr/GHSA-pp3p-ch6p-j7fr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pp3p-ch6p-j7fr", - "modified": "2024-05-14T18:30:45Z", + "modified": "2024-07-03T18:40:29Z", "published": "2024-05-14T18:30:45Z", "aliases": [ "CVE-2024-32605" ], "details": "HDF5 Library through 1.14.3 has a heap-based buffer over-read in H5VM_memcpyvv in H5VM.c (called from H5D__compact_readvv in H5Dcompact.c).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:36:45Z" diff --git a/advisories/unreviewed/2024/05/GHSA-ppc4-w5f5-v2jw/GHSA-ppc4-w5f5-v2jw.json b/advisories/unreviewed/2024/05/GHSA-ppc4-w5f5-v2jw/GHSA-ppc4-w5f5-v2jw.json index dc19aaab512..760b3dd557b 100644 --- a/advisories/unreviewed/2024/05/GHSA-ppc4-w5f5-v2jw/GHSA-ppc4-w5f5-v2jw.json +++ b/advisories/unreviewed/2024/05/GHSA-ppc4-w5f5-v2jw/GHSA-ppc4-w5f5-v2jw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ppc4-w5f5-v2jw", - "modified": "2024-05-14T18:31:00Z", + "modified": "2024-07-03T18:41:23Z", "published": "2024-05-14T18:31:00Z", "aliases": [ "CVE-2024-32353" ], "details": "TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'port' parameter in the setSSServer function at /cgi-bin/cstecgi.cgi.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T16:17:03Z" diff --git a/advisories/unreviewed/2024/05/GHSA-pvm5-6q5c-5jfp/GHSA-pvm5-6q5c-5jfp.json b/advisories/unreviewed/2024/05/GHSA-pvm5-6q5c-5jfp/GHSA-pvm5-6q5c-5jfp.json index 52f8388ca9d..93cc1371c40 100644 --- a/advisories/unreviewed/2024/05/GHSA-pvm5-6q5c-5jfp/GHSA-pvm5-6q5c-5jfp.json +++ b/advisories/unreviewed/2024/05/GHSA-pvm5-6q5c-5jfp/GHSA-pvm5-6q5c-5jfp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pvm5-6q5c-5jfp", - "modified": "2024-05-14T18:30:49Z", + "modified": "2024-07-03T18:40:55Z", "published": "2024-05-14T18:30:49Z", "aliases": [ "CVE-2024-34205" ], "details": "TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the download_firmware function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:38:33Z" diff --git a/advisories/unreviewed/2024/05/GHSA-pwrq-4h7q-j29x/GHSA-pwrq-4h7q-j29x.json b/advisories/unreviewed/2024/05/GHSA-pwrq-4h7q-j29x/GHSA-pwrq-4h7q-j29x.json index 92af068d93a..314a0b57659 100644 --- a/advisories/unreviewed/2024/05/GHSA-pwrq-4h7q-j29x/GHSA-pwrq-4h7q-j29x.json +++ b/advisories/unreviewed/2024/05/GHSA-pwrq-4h7q-j29x/GHSA-pwrq-4h7q-j29x.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-q9xx-vg8w-8qrv/GHSA-q9xx-vg8w-8qrv.json b/advisories/unreviewed/2024/05/GHSA-q9xx-vg8w-8qrv/GHSA-q9xx-vg8w-8qrv.json index 5b38dd602ca..710aa69ddfb 100644 --- a/advisories/unreviewed/2024/05/GHSA-q9xx-vg8w-8qrv/GHSA-q9xx-vg8w-8qrv.json +++ b/advisories/unreviewed/2024/05/GHSA-q9xx-vg8w-8qrv/GHSA-q9xx-vg8w-8qrv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q9xx-vg8w-8qrv", - "modified": "2024-05-14T18:30:48Z", + "modified": "2024-07-03T18:40:48Z", "published": "2024-05-14T18:30:48Z", "aliases": [ "CVE-2024-33877" ], "details": "HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5T__conv_struct_opt in H5Tconv.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:38:10Z" diff --git a/advisories/unreviewed/2024/05/GHSA-qfmw-8q7m-gxm5/GHSA-qfmw-8q7m-gxm5.json b/advisories/unreviewed/2024/05/GHSA-qfmw-8q7m-gxm5/GHSA-qfmw-8q7m-gxm5.json index a86e8aed6cc..310e496ac4e 100644 --- a/advisories/unreviewed/2024/05/GHSA-qfmw-8q7m-gxm5/GHSA-qfmw-8q7m-gxm5.json +++ b/advisories/unreviewed/2024/05/GHSA-qfmw-8q7m-gxm5/GHSA-qfmw-8q7m-gxm5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qfmw-8q7m-gxm5", - "modified": "2024-05-15T06:30:44Z", + "modified": "2024-07-03T18:41:55Z", "published": "2024-05-15T06:30:44Z", "aliases": [ "CVE-2024-3749" ], "details": "The SP Project & Document Manager WordPress plugin through 4.71 lacks proper access controllers and allows a logged in user to view and download files belonging to another user", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-15T06:15:14Z" diff --git a/advisories/unreviewed/2024/05/GHSA-qpjw-29j5-fffr/GHSA-qpjw-29j5-fffr.json b/advisories/unreviewed/2024/05/GHSA-qpjw-29j5-fffr/GHSA-qpjw-29j5-fffr.json index f6d0436da74..bd2d2e2f86b 100644 --- a/advisories/unreviewed/2024/05/GHSA-qpjw-29j5-fffr/GHSA-qpjw-29j5-fffr.json +++ b/advisories/unreviewed/2024/05/GHSA-qpjw-29j5-fffr/GHSA-qpjw-29j5-fffr.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-463" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-qrj2-26jq-rq86/GHSA-qrj2-26jq-rq86.json b/advisories/unreviewed/2024/05/GHSA-qrj2-26jq-rq86/GHSA-qrj2-26jq-rq86.json index 13d0d2f8712..413f6af2653 100644 --- a/advisories/unreviewed/2024/05/GHSA-qrj2-26jq-rq86/GHSA-qrj2-26jq-rq86.json +++ b/advisories/unreviewed/2024/05/GHSA-qrj2-26jq-rq86/GHSA-qrj2-26jq-rq86.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qrj2-26jq-rq86", - "modified": "2024-05-16T21:31:57Z", + "modified": "2024-07-03T18:41:21Z", "published": "2024-05-14T18:30:52Z", "aliases": [ "CVE-2024-35204" ], "details": "Veritas System Recovery before 23.2_Hotfix has incorrect permissions for the Veritas System Recovery folder, and thus low-privileged users can conduct attacks.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-272" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:39:42Z" diff --git a/advisories/unreviewed/2024/05/GHSA-qvgf-wgjr-g932/GHSA-qvgf-wgjr-g932.json b/advisories/unreviewed/2024/05/GHSA-qvgf-wgjr-g932/GHSA-qvgf-wgjr-g932.json index e9ff3943076..c375f8526d9 100644 --- a/advisories/unreviewed/2024/05/GHSA-qvgf-wgjr-g932/GHSA-qvgf-wgjr-g932.json +++ b/advisories/unreviewed/2024/05/GHSA-qvgf-wgjr-g932/GHSA-qvgf-wgjr-g932.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qvgf-wgjr-g932", - "modified": "2024-05-15T06:30:44Z", + "modified": "2024-07-03T18:41:55Z", "published": "2024-05-15T06:30:44Z", "aliases": [ "CVE-2024-3748" ], "details": "The SP Project & Document Manager WordPress plugin through 4.71 is missing validation in its upload function, allowing a user to manipulate the `user_id` to make it appear that a file was uploaded by another user", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-15T06:15:13Z" diff --git a/advisories/unreviewed/2024/05/GHSA-qxhm-4w63-54c7/GHSA-qxhm-4w63-54c7.json b/advisories/unreviewed/2024/05/GHSA-qxhm-4w63-54c7/GHSA-qxhm-4w63-54c7.json index 72093e2823f..b140b625f9a 100644 --- a/advisories/unreviewed/2024/05/GHSA-qxhm-4w63-54c7/GHSA-qxhm-4w63-54c7.json +++ b/advisories/unreviewed/2024/05/GHSA-qxhm-4w63-54c7/GHSA-qxhm-4w63-54c7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qxhm-4w63-54c7", - "modified": "2024-05-14T18:30:46Z", + "modified": "2024-07-03T18:40:29Z", "published": "2024-05-14T18:30:46Z", "aliases": [ "CVE-2024-32613" ], "details": "HDF5 Library through 1.14.3 contains a heap-based buffer over-read in the function H5HL__fl_deserialize in H5HLcache.c, a different vulnerability than CVE-2024-32612.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:36:46Z" diff --git a/advisories/unreviewed/2024/05/GHSA-r3pj-479m-vpg2/GHSA-r3pj-479m-vpg2.json b/advisories/unreviewed/2024/05/GHSA-r3pj-479m-vpg2/GHSA-r3pj-479m-vpg2.json index d0ca0551fbd..e21b7d36acc 100644 --- a/advisories/unreviewed/2024/05/GHSA-r3pj-479m-vpg2/GHSA-r3pj-479m-vpg2.json +++ b/advisories/unreviewed/2024/05/GHSA-r3pj-479m-vpg2/GHSA-r3pj-479m-vpg2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r3pj-479m-vpg2", - "modified": "2024-05-14T18:30:48Z", + "modified": "2024-07-03T18:40:43Z", "published": "2024-05-14T18:30:48Z", "aliases": [ "CVE-2024-33454" ], "details": "Buffer Overflow vulnerability in esp-idf v.5.1 allows a remote attacker to execute arbitrary code via a crafted script to the Bluetooth stack component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:37:41Z" diff --git a/advisories/unreviewed/2024/05/GHSA-r6wj-xmgr-mg33/GHSA-r6wj-xmgr-mg33.json b/advisories/unreviewed/2024/05/GHSA-r6wj-xmgr-mg33/GHSA-r6wj-xmgr-mg33.json index b17b738f2e8..5bfdfe3c79e 100644 --- a/advisories/unreviewed/2024/05/GHSA-r6wj-xmgr-mg33/GHSA-r6wj-xmgr-mg33.json +++ b/advisories/unreviewed/2024/05/GHSA-r6wj-xmgr-mg33/GHSA-r6wj-xmgr-mg33.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r6wj-xmgr-mg33", - "modified": "2024-05-14T18:31:06Z", + "modified": "2024-07-03T18:41:41Z", "published": "2024-05-14T18:31:06Z", "aliases": [ "CVE-2024-4778" ], "details": "Memory safety bugs present in Firefox 125. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 126.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1260" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T18:15:16Z" diff --git a/advisories/unreviewed/2024/05/GHSA-rqmx-jjch-gmgj/GHSA-rqmx-jjch-gmgj.json b/advisories/unreviewed/2024/05/GHSA-rqmx-jjch-gmgj/GHSA-rqmx-jjch-gmgj.json index 44261b6aac1..4b6111b22b8 100644 --- a/advisories/unreviewed/2024/05/GHSA-rqmx-jjch-gmgj/GHSA-rqmx-jjch-gmgj.json +++ b/advisories/unreviewed/2024/05/GHSA-rqmx-jjch-gmgj/GHSA-rqmx-jjch-gmgj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rqmx-jjch-gmgj", - "modified": "2024-05-14T18:31:05Z", + "modified": "2024-07-03T18:41:35Z", "published": "2024-05-14T18:31:05Z", "aliases": [ "CVE-2024-4764" ], "details": "Multiple WebRTC threads could have claimed a newly connected audio input leading to use-after-free. This vulnerability affects Firefox < 126.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T18:15:12Z" diff --git a/advisories/unreviewed/2024/05/GHSA-rr62-c94h-x6cq/GHSA-rr62-c94h-x6cq.json b/advisories/unreviewed/2024/05/GHSA-rr62-c94h-x6cq/GHSA-rr62-c94h-x6cq.json index 234e7deeb3c..2e377646d7f 100644 --- a/advisories/unreviewed/2024/05/GHSA-rr62-c94h-x6cq/GHSA-rr62-c94h-x6cq.json +++ b/advisories/unreviewed/2024/05/GHSA-rr62-c94h-x6cq/GHSA-rr62-c94h-x6cq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rr62-c94h-x6cq", - "modified": "2024-05-14T18:30:46Z", + "modified": "2024-07-03T18:40:37Z", "published": "2024-05-14T18:30:46Z", "aliases": [ "CVE-2024-32618" ], "details": "HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T__get_native_type in H5Tnative.c, resulting in the corruption of the instruction pointer.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:36:47Z" diff --git a/advisories/unreviewed/2024/05/GHSA-rw6g-5q22-m8p3/GHSA-rw6g-5q22-m8p3.json b/advisories/unreviewed/2024/05/GHSA-rw6g-5q22-m8p3/GHSA-rw6g-5q22-m8p3.json index b12056b9cb1..6f323f87438 100644 --- a/advisories/unreviewed/2024/05/GHSA-rw6g-5q22-m8p3/GHSA-rw6g-5q22-m8p3.json +++ b/advisories/unreviewed/2024/05/GHSA-rw6g-5q22-m8p3/GHSA-rw6g-5q22-m8p3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rw6g-5q22-m8p3", - "modified": "2024-05-14T18:31:00Z", + "modified": "2024-07-03T18:41:23Z", "published": "2024-05-14T18:31:00Z", "aliases": [ "CVE-2024-32354" ], "details": "TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'timeout' parameter in the setSSServer function at /cgi-bin/cstecgi.cgi.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T16:17:03Z" diff --git a/advisories/unreviewed/2024/05/GHSA-rxgq-455j-3wp3/GHSA-rxgq-455j-3wp3.json b/advisories/unreviewed/2024/05/GHSA-rxgq-455j-3wp3/GHSA-rxgq-455j-3wp3.json index 0081601d3e4..7092ad8de90 100644 --- a/advisories/unreviewed/2024/05/GHSA-rxgq-455j-3wp3/GHSA-rxgq-455j-3wp3.json +++ b/advisories/unreviewed/2024/05/GHSA-rxgq-455j-3wp3/GHSA-rxgq-455j-3wp3.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-v2hv-5634-vcq8/GHSA-v2hv-5634-vcq8.json b/advisories/unreviewed/2024/05/GHSA-v2hv-5634-vcq8/GHSA-v2hv-5634-vcq8.json index f4f22d63e6d..e5cba9ae2bc 100644 --- a/advisories/unreviewed/2024/05/GHSA-v2hv-5634-vcq8/GHSA-v2hv-5634-vcq8.json +++ b/advisories/unreviewed/2024/05/GHSA-v2hv-5634-vcq8/GHSA-v2hv-5634-vcq8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v2hv-5634-vcq8", - "modified": "2024-05-14T18:30:47Z", + "modified": "2024-07-03T18:40:41Z", "published": "2024-05-14T18:30:47Z", "aliases": [ "CVE-2024-32738" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-v3xv-2qp3-8qm5/GHSA-v3xv-2qp3-8qm5.json b/advisories/unreviewed/2024/05/GHSA-v3xv-2qp3-8qm5/GHSA-v3xv-2qp3-8qm5.json index 2abe92c37b1..a63b8985783 100644 --- a/advisories/unreviewed/2024/05/GHSA-v3xv-2qp3-8qm5/GHSA-v3xv-2qp3-8qm5.json +++ b/advisories/unreviewed/2024/05/GHSA-v3xv-2qp3-8qm5/GHSA-v3xv-2qp3-8qm5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v3xv-2qp3-8qm5", - "modified": "2024-05-14T18:31:02Z", + "modified": "2024-07-03T18:41:34Z", "published": "2024-05-14T18:31:02Z", "aliases": [ "CVE-2024-35012" ], "details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoType_deal.php?mudi=add&nohrefStr=close.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T16:17:31Z" diff --git a/advisories/unreviewed/2024/05/GHSA-v6x4-xfcg-2vxh/GHSA-v6x4-xfcg-2vxh.json b/advisories/unreviewed/2024/05/GHSA-v6x4-xfcg-2vxh/GHSA-v6x4-xfcg-2vxh.json index a5a0635c491..e2ed722a8fe 100644 --- a/advisories/unreviewed/2024/05/GHSA-v6x4-xfcg-2vxh/GHSA-v6x4-xfcg-2vxh.json +++ b/advisories/unreviewed/2024/05/GHSA-v6x4-xfcg-2vxh/GHSA-v6x4-xfcg-2vxh.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-v7j3-p7jm-f2cp/GHSA-v7j3-p7jm-f2cp.json b/advisories/unreviewed/2024/05/GHSA-v7j3-p7jm-f2cp/GHSA-v7j3-p7jm-f2cp.json index db85a1a4797..73b513f356c 100644 --- a/advisories/unreviewed/2024/05/GHSA-v7j3-p7jm-f2cp/GHSA-v7j3-p7jm-f2cp.json +++ b/advisories/unreviewed/2024/05/GHSA-v7j3-p7jm-f2cp/GHSA-v7j3-p7jm-f2cp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v7j3-p7jm-f2cp", - "modified": "2024-05-16T15:31:39Z", + "modified": "2024-07-03T18:42:06Z", "published": "2024-05-16T15:31:39Z", "aliases": [ "CVE-2024-34958" ], "details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/banner_deal.php?mudi=add", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-16T15:15:48Z" diff --git a/advisories/unreviewed/2024/05/GHSA-v8qg-5mj9-799g/GHSA-v8qg-5mj9-799g.json b/advisories/unreviewed/2024/05/GHSA-v8qg-5mj9-799g/GHSA-v8qg-5mj9-799g.json index d24a91ea61e..766f0af59b8 100644 --- a/advisories/unreviewed/2024/05/GHSA-v8qg-5mj9-799g/GHSA-v8qg-5mj9-799g.json +++ b/advisories/unreviewed/2024/05/GHSA-v8qg-5mj9-799g/GHSA-v8qg-5mj9-799g.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-v9v6-h4rh-wjqh/GHSA-v9v6-h4rh-wjqh.json b/advisories/unreviewed/2024/05/GHSA-v9v6-h4rh-wjqh/GHSA-v9v6-h4rh-wjqh.json index 5639f123dcc..c4418f5dd0f 100644 --- a/advisories/unreviewed/2024/05/GHSA-v9v6-h4rh-wjqh/GHSA-v9v6-h4rh-wjqh.json +++ b/advisories/unreviewed/2024/05/GHSA-v9v6-h4rh-wjqh/GHSA-v9v6-h4rh-wjqh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v9v6-h4rh-wjqh", - "modified": "2024-05-14T18:30:48Z", + "modified": "2024-07-03T18:40:48Z", "published": "2024-05-14T18:30:48Z", "aliases": [ "CVE-2024-33874" ], "details": "HDF5 Library through 1.14.3 has a heap buffer overflow in H5O__mtime_new_encode in H5Omtime.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:38:09Z" diff --git a/advisories/unreviewed/2024/05/GHSA-vcx5-gghv-x2hh/GHSA-vcx5-gghv-x2hh.json b/advisories/unreviewed/2024/05/GHSA-vcx5-gghv-x2hh/GHSA-vcx5-gghv-x2hh.json index 6e35a56efec..6914b80fc7d 100644 --- a/advisories/unreviewed/2024/05/GHSA-vcx5-gghv-x2hh/GHSA-vcx5-gghv-x2hh.json +++ b/advisories/unreviewed/2024/05/GHSA-vcx5-gghv-x2hh/GHSA-vcx5-gghv-x2hh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vcx5-gghv-x2hh", - "modified": "2024-05-14T18:30:55Z", + "modified": "2024-07-03T18:41:22Z", "published": "2024-05-14T18:30:55Z", "aliases": [ "CVE-2024-4425" ], "details": "The access control in CemiPark software stores integration (e.g. FTP or SIP) credentials in plain-text. An attacker who gained unauthorized access to the device can retrieve clear text passwords used by the system.This issue affects CemiPark software: 4.5, 4.7, 5.03 and potentially others. The vendor refused to provide the specific range of affected products.\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-256" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:43:42Z" diff --git a/advisories/unreviewed/2024/05/GHSA-vgc7-vqc6-2858/GHSA-vgc7-vqc6-2858.json b/advisories/unreviewed/2024/05/GHSA-vgc7-vqc6-2858/GHSA-vgc7-vqc6-2858.json index 4a533c009f6..84f3d48862d 100644 --- a/advisories/unreviewed/2024/05/GHSA-vgc7-vqc6-2858/GHSA-vgc7-vqc6-2858.json +++ b/advisories/unreviewed/2024/05/GHSA-vgc7-vqc6-2858/GHSA-vgc7-vqc6-2858.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vgc7-vqc6-2858", - "modified": "2024-06-10T18:31:01Z", + "modified": "2024-07-03T18:41:36Z", "published": "2024-05-14T18:31:05Z", "aliases": [ "CVE-2024-4769" ], "details": "When importing resources using Web Workers, error messages would distinguish the difference between `application/javascript` responses and non-script responses. This could have been abused to learn information cross-origin. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-351" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T18:15:14Z" diff --git a/advisories/unreviewed/2024/05/GHSA-vgwc-m3fq-wv9x/GHSA-vgwc-m3fq-wv9x.json b/advisories/unreviewed/2024/05/GHSA-vgwc-m3fq-wv9x/GHSA-vgwc-m3fq-wv9x.json index c290c99ec59..2284e3c0dff 100644 --- a/advisories/unreviewed/2024/05/GHSA-vgwc-m3fq-wv9x/GHSA-vgwc-m3fq-wv9x.json +++ b/advisories/unreviewed/2024/05/GHSA-vgwc-m3fq-wv9x/GHSA-vgwc-m3fq-wv9x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vgwc-m3fq-wv9x", - "modified": "2024-05-14T18:30:49Z", + "modified": "2024-07-03T18:40:56Z", "published": "2024-05-14T18:30:49Z", "aliases": [ "CVE-2024-34209" ], "details": "TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setIpPortFilterRules function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:38:34Z" diff --git a/advisories/unreviewed/2024/05/GHSA-vqmm-2jhx-m5fg/GHSA-vqmm-2jhx-m5fg.json b/advisories/unreviewed/2024/05/GHSA-vqmm-2jhx-m5fg/GHSA-vqmm-2jhx-m5fg.json index 249b1dfba5b..3fd2ebaa270 100644 --- a/advisories/unreviewed/2024/05/GHSA-vqmm-2jhx-m5fg/GHSA-vqmm-2jhx-m5fg.json +++ b/advisories/unreviewed/2024/05/GHSA-vqmm-2jhx-m5fg/GHSA-vqmm-2jhx-m5fg.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-w694-6mxx-38mc/GHSA-w694-6mxx-38mc.json b/advisories/unreviewed/2024/05/GHSA-w694-6mxx-38mc/GHSA-w694-6mxx-38mc.json index 7a7655e4024..9d0b000f614 100644 --- a/advisories/unreviewed/2024/05/GHSA-w694-6mxx-38mc/GHSA-w694-6mxx-38mc.json +++ b/advisories/unreviewed/2024/05/GHSA-w694-6mxx-38mc/GHSA-w694-6mxx-38mc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w694-6mxx-38mc", - "modified": "2024-05-14T18:31:05Z", + "modified": "2024-07-03T18:41:37Z", "published": "2024-05-14T18:31:05Z", "aliases": [ "CVE-2024-4771" ], "details": "A memory allocation check was missing which would lead to a use-after-free if the allocation failed. This could have triggered a crash or potentially be leveraged to achieve code execution. This vulnerability affects Firefox < 126.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T18:15:14Z" diff --git a/advisories/unreviewed/2024/05/GHSA-wfm3-g35w-6g75/GHSA-wfm3-g35w-6g75.json b/advisories/unreviewed/2024/05/GHSA-wfm3-g35w-6g75/GHSA-wfm3-g35w-6g75.json index 47cdaebdb24..6424b76e413 100644 --- a/advisories/unreviewed/2024/05/GHSA-wfm3-g35w-6g75/GHSA-wfm3-g35w-6g75.json +++ b/advisories/unreviewed/2024/05/GHSA-wfm3-g35w-6g75/GHSA-wfm3-g35w-6g75.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wfm3-g35w-6g75", - "modified": "2024-05-14T18:30:49Z", + "modified": "2024-07-03T18:41:04Z", "published": "2024-05-14T18:30:49Z", "aliases": [ "CVE-2024-34225" ], "details": "Cross Site Scripting vulnerability in php-lms/admin/?page=system_info in Computer Laboratory Management System using PHP and MySQL 1.0 allow remote attackers to inject arbitrary web script or HTML via the name, shortname parameters.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:38:36Z" diff --git a/advisories/unreviewed/2024/05/GHSA-wr78-jhjx-h77g/GHSA-wr78-jhjx-h77g.json b/advisories/unreviewed/2024/05/GHSA-wr78-jhjx-h77g/GHSA-wr78-jhjx-h77g.json index 5faa6d615b7..c05d250590f 100644 --- a/advisories/unreviewed/2024/05/GHSA-wr78-jhjx-h77g/GHSA-wr78-jhjx-h77g.json +++ b/advisories/unreviewed/2024/05/GHSA-wr78-jhjx-h77g/GHSA-wr78-jhjx-h77g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wr78-jhjx-h77g", - "modified": "2024-05-14T18:30:49Z", + "modified": "2024-07-03T18:40:53Z", "published": "2024-05-14T18:30:49Z", "aliases": [ "CVE-2024-34201" ], "details": "TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the getSaveConfig function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:38:33Z" diff --git a/advisories/unreviewed/2024/05/GHSA-wr86-8vhj-7qx5/GHSA-wr86-8vhj-7qx5.json b/advisories/unreviewed/2024/05/GHSA-wr86-8vhj-7qx5/GHSA-wr86-8vhj-7qx5.json index 9e92e08325f..916002ee821 100644 --- a/advisories/unreviewed/2024/05/GHSA-wr86-8vhj-7qx5/GHSA-wr86-8vhj-7qx5.json +++ b/advisories/unreviewed/2024/05/GHSA-wr86-8vhj-7qx5/GHSA-wr86-8vhj-7qx5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wr86-8vhj-7qx5", - "modified": "2024-05-14T18:30:55Z", + "modified": "2024-07-03T18:41:22Z", "published": "2024-05-14T18:30:55Z", "aliases": [ "CVE-2024-4423" ], "details": "The access control in CemiPark software does not properly validate user-entered data, which allows the authentication bypass. An attacker who has network access to the login panel can log in with administrator rights to the application.This issue affects CemiPark software: 4.5, 4.7, 5.03 and potentially others. The vendor refused to provide the specific range of affected products.\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:43:40Z" diff --git a/advisories/unreviewed/2024/05/GHSA-wx4f-9wf4-26p4/GHSA-wx4f-9wf4-26p4.json b/advisories/unreviewed/2024/05/GHSA-wx4f-9wf4-26p4/GHSA-wx4f-9wf4-26p4.json index 96cdf886c8a..60b336bb0df 100644 --- a/advisories/unreviewed/2024/05/GHSA-wx4f-9wf4-26p4/GHSA-wx4f-9wf4-26p4.json +++ b/advisories/unreviewed/2024/05/GHSA-wx4f-9wf4-26p4/GHSA-wx4f-9wf4-26p4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wx4f-9wf4-26p4", - "modified": "2024-05-14T18:30:49Z", + "modified": "2024-07-03T18:40:48Z", "published": "2024-05-14T18:30:49Z", "aliases": [ "CVE-2024-34199" ], "details": "TinyWeb 1.94 and below allows unauthenticated remote attackers to cause a denial of service (Buffer Overflow) when sending excessively large elements in the request line.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:38:32Z" diff --git a/advisories/unreviewed/2024/05/GHSA-x353-4jwx-m25g/GHSA-x353-4jwx-m25g.json b/advisories/unreviewed/2024/05/GHSA-x353-4jwx-m25g/GHSA-x353-4jwx-m25g.json index 7436af370bd..62c9e33e52b 100644 --- a/advisories/unreviewed/2024/05/GHSA-x353-4jwx-m25g/GHSA-x353-4jwx-m25g.json +++ b/advisories/unreviewed/2024/05/GHSA-x353-4jwx-m25g/GHSA-x353-4jwx-m25g.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-269", "CWE-427" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/05/GHSA-x65p-fjpx-x8qr/GHSA-x65p-fjpx-x8qr.json b/advisories/unreviewed/2024/05/GHSA-x65p-fjpx-x8qr/GHSA-x65p-fjpx-x8qr.json index 4f3de735526..0448bc5e693 100644 --- a/advisories/unreviewed/2024/05/GHSA-x65p-fjpx-x8qr/GHSA-x65p-fjpx-x8qr.json +++ b/advisories/unreviewed/2024/05/GHSA-x65p-fjpx-x8qr/GHSA-x65p-fjpx-x8qr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x65p-fjpx-x8qr", - "modified": "2024-05-14T18:30:49Z", + "modified": "2024-07-03T18:40:59Z", "published": "2024-05-14T18:30:49Z", "aliases": [ "CVE-2024-34212" ], "details": "TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the CloudACMunualUpdate function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:38:35Z" diff --git a/advisories/unreviewed/2024/05/GHSA-xfg4-45f5-2g88/GHSA-xfg4-45f5-2g88.json b/advisories/unreviewed/2024/05/GHSA-xfg4-45f5-2g88/GHSA-xfg4-45f5-2g88.json index f275d4c6cc0..e2572f2182c 100644 --- a/advisories/unreviewed/2024/05/GHSA-xfg4-45f5-2g88/GHSA-xfg4-45f5-2g88.json +++ b/advisories/unreviewed/2024/05/GHSA-xfg4-45f5-2g88/GHSA-xfg4-45f5-2g88.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-77", "CWE-78" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/05/GHSA-xp6h-p4cj-42w8/GHSA-xp6h-p4cj-42w8.json b/advisories/unreviewed/2024/05/GHSA-xp6h-p4cj-42w8/GHSA-xp6h-p4cj-42w8.json index 9c9ac1e58cd..84d57730062 100644 --- a/advisories/unreviewed/2024/05/GHSA-xp6h-p4cj-42w8/GHSA-xp6h-p4cj-42w8.json +++ b/advisories/unreviewed/2024/05/GHSA-xp6h-p4cj-42w8/GHSA-xp6h-p4cj-42w8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xp6h-p4cj-42w8", - "modified": "2024-05-14T18:31:01Z", + "modified": "2024-07-03T18:41:33Z", "published": "2024-05-14T18:31:01Z", "aliases": [ "CVE-2024-33868" ], "details": "An issue was discovered in linqi before 1.4.0.1 on Windows. There is LDAP injection.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T16:17:22Z" diff --git a/advisories/unreviewed/2024/05/GHSA-xvp9-87cv-m4fv/GHSA-xvp9-87cv-m4fv.json b/advisories/unreviewed/2024/05/GHSA-xvp9-87cv-m4fv/GHSA-xvp9-87cv-m4fv.json index e375fe627b5..b1f42925112 100644 --- a/advisories/unreviewed/2024/05/GHSA-xvp9-87cv-m4fv/GHSA-xvp9-87cv-m4fv.json +++ b/advisories/unreviewed/2024/05/GHSA-xvp9-87cv-m4fv/GHSA-xvp9-87cv-m4fv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xvp9-87cv-m4fv", - "modified": "2024-06-10T18:31:02Z", + "modified": "2024-07-03T18:42:01Z", "published": "2024-05-15T21:31:26Z", "aliases": [ "CVE-2024-4948" ], "details": "Use after free in Dawn in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-15T21:15:09Z" diff --git a/advisories/unreviewed/2024/05/GHSA-xxpc-j5ph-gmp8/GHSA-xxpc-j5ph-gmp8.json b/advisories/unreviewed/2024/05/GHSA-xxpc-j5ph-gmp8/GHSA-xxpc-j5ph-gmp8.json index bb1e9854a50..8f7645cff4c 100644 --- a/advisories/unreviewed/2024/05/GHSA-xxpc-j5ph-gmp8/GHSA-xxpc-j5ph-gmp8.json +++ b/advisories/unreviewed/2024/05/GHSA-xxpc-j5ph-gmp8/GHSA-xxpc-j5ph-gmp8.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], "severity": "CRITICAL", "github_reviewed": false,