diff --git a/advisories/unreviewed/2023/09/GHSA-3r84-hhrv-2935/GHSA-3r84-hhrv-2935.json b/advisories/unreviewed/2023/09/GHSA-3r84-hhrv-2935/GHSA-3r84-hhrv-2935.json index 949ee1d832a..24e6e42f4b4 100644 --- a/advisories/unreviewed/2023/09/GHSA-3r84-hhrv-2935/GHSA-3r84-hhrv-2935.json +++ b/advisories/unreviewed/2023/09/GHSA-3r84-hhrv-2935/GHSA-3r84-hhrv-2935.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-48cj-hmgx-8f7h/GHSA-48cj-hmgx-8f7h.json b/advisories/unreviewed/2023/09/GHSA-48cj-hmgx-8f7h/GHSA-48cj-hmgx-8f7h.json index 4118ca64977..d3e04959790 100644 --- a/advisories/unreviewed/2023/09/GHSA-48cj-hmgx-8f7h/GHSA-48cj-hmgx-8f7h.json +++ b/advisories/unreviewed/2023/09/GHSA-48cj-hmgx-8f7h/GHSA-48cj-hmgx-8f7h.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-5ph3-mr96-8v94/GHSA-5ph3-mr96-8v94.json b/advisories/unreviewed/2023/09/GHSA-5ph3-mr96-8v94/GHSA-5ph3-mr96-8v94.json index 2e0483ef706..499a552db0f 100644 --- a/advisories/unreviewed/2023/09/GHSA-5ph3-mr96-8v94/GHSA-5ph3-mr96-8v94.json +++ b/advisories/unreviewed/2023/09/GHSA-5ph3-mr96-8v94/GHSA-5ph3-mr96-8v94.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-8758-wxjc-xqrh/GHSA-8758-wxjc-xqrh.json b/advisories/unreviewed/2023/09/GHSA-8758-wxjc-xqrh/GHSA-8758-wxjc-xqrh.json index 70571b52120..d5c38c78949 100644 --- a/advisories/unreviewed/2023/09/GHSA-8758-wxjc-xqrh/GHSA-8758-wxjc-xqrh.json +++ b/advisories/unreviewed/2023/09/GHSA-8758-wxjc-xqrh/GHSA-8758-wxjc-xqrh.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-8x9q-p82f-q5gx/GHSA-8x9q-p82f-q5gx.json b/advisories/unreviewed/2023/09/GHSA-8x9q-p82f-q5gx/GHSA-8x9q-p82f-q5gx.json index 6bd4595e9a8..20d3c730182 100644 --- a/advisories/unreviewed/2023/09/GHSA-8x9q-p82f-q5gx/GHSA-8x9q-p82f-q5gx.json +++ b/advisories/unreviewed/2023/09/GHSA-8x9q-p82f-q5gx/GHSA-8x9q-p82f-q5gx.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-c2rp-g99g-j6gv/GHSA-c2rp-g99g-j6gv.json b/advisories/unreviewed/2023/09/GHSA-c2rp-g99g-j6gv/GHSA-c2rp-g99g-j6gv.json index 8dc4a240d48..e73a1994c56 100644 --- a/advisories/unreviewed/2023/09/GHSA-c2rp-g99g-j6gv/GHSA-c2rp-g99g-j6gv.json +++ b/advisories/unreviewed/2023/09/GHSA-c2rp-g99g-j6gv/GHSA-c2rp-g99g-j6gv.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-682" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-p95j-356c-hgx2/GHSA-p95j-356c-hgx2.json b/advisories/unreviewed/2023/09/GHSA-p95j-356c-hgx2/GHSA-p95j-356c-hgx2.json index 034c950e1bf..c06529ba990 100644 --- a/advisories/unreviewed/2023/09/GHSA-p95j-356c-hgx2/GHSA-p95j-356c-hgx2.json +++ b/advisories/unreviewed/2023/09/GHSA-p95j-356c-hgx2/GHSA-p95j-356c-hgx2.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-r97g-mv85-crqf/GHSA-r97g-mv85-crqf.json b/advisories/unreviewed/2023/09/GHSA-r97g-mv85-crqf/GHSA-r97g-mv85-crqf.json index cf1e68531e5..375a45a7e0b 100644 --- a/advisories/unreviewed/2023/09/GHSA-r97g-mv85-crqf/GHSA-r97g-mv85-crqf.json +++ b/advisories/unreviewed/2023/09/GHSA-r97g-mv85-crqf/GHSA-r97g-mv85-crqf.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-xpgj-rhc7-55qx/GHSA-xpgj-rhc7-55qx.json b/advisories/unreviewed/2023/09/GHSA-xpgj-rhc7-55qx/GHSA-xpgj-rhc7-55qx.json index 76e7bd12ffa..158f62ccda5 100644 --- a/advisories/unreviewed/2023/09/GHSA-xpgj-rhc7-55qx/GHSA-xpgj-rhc7-55qx.json +++ b/advisories/unreviewed/2023/09/GHSA-xpgj-rhc7-55qx/GHSA-xpgj-rhc7-55qx.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-279c-3782-hjv5/GHSA-279c-3782-hjv5.json b/advisories/unreviewed/2024/09/GHSA-279c-3782-hjv5/GHSA-279c-3782-hjv5.json new file mode 100644 index 00000000000..eb8fe90c892 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-279c-3782-hjv5/GHSA-279c-3782-hjv5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-279c-3782-hjv5", + "modified": "2024-09-26T18:31:44Z", + "published": "2024-09-26T18:31:44Z", + "aliases": [ + "CVE-2024-9166" + ], + "details": "The device enables an unauthorized attacker to execute system commands with elevated privileges. This exploit is facilitated through the use of the 'getcommand' query within the application, allowing the attacker to gain root access.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9166" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-03" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-26T17:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-36pg-hxf8-378v/GHSA-36pg-hxf8-378v.json b/advisories/unreviewed/2024/09/GHSA-36pg-hxf8-378v/GHSA-36pg-hxf8-378v.json index 5497b764f30..9fc5877233d 100644 --- a/advisories/unreviewed/2024/09/GHSA-36pg-hxf8-378v/GHSA-36pg-hxf8-378v.json +++ b/advisories/unreviewed/2024/09/GHSA-36pg-hxf8-378v/GHSA-36pg-hxf8-378v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-36pg-hxf8-378v", - "modified": "2024-09-06T15:32:59Z", + "modified": "2024-09-26T18:31:43Z", "published": "2024-09-06T15:32:59Z", "aliases": [ "CVE-2024-7599" diff --git a/advisories/unreviewed/2024/09/GHSA-36xj-gx8g-m5fr/GHSA-36xj-gx8g-m5fr.json b/advisories/unreviewed/2024/09/GHSA-36xj-gx8g-m5fr/GHSA-36xj-gx8g-m5fr.json new file mode 100644 index 00000000000..c0bbcdcb241 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-36xj-gx8g-m5fr/GHSA-36xj-gx8g-m5fr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-36xj-gx8g-m5fr", + "modified": "2024-09-26T18:31:45Z", + "published": "2024-09-26T18:31:45Z", + "aliases": [ + "CVE-2024-47130" + ], + "details": "The goTenna Pro series allows unauthenticated attackers to remotely update the local public keys used for P2P and Group messages.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47130" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-04" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-26T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-3f32-jc9w-78m7/GHSA-3f32-jc9w-78m7.json b/advisories/unreviewed/2024/09/GHSA-3f32-jc9w-78m7/GHSA-3f32-jc9w-78m7.json new file mode 100644 index 00000000000..626565e9d5f --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-3f32-jc9w-78m7/GHSA-3f32-jc9w-78m7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3f32-jc9w-78m7", + "modified": "2024-09-26T18:31:45Z", + "published": "2024-09-26T18:31:45Z", + "aliases": [ + "CVE-2024-47123" + ], + "details": "The goTenna Pro series use AES CTR mode for short, encrypted messages without any additional integrity checking mechanisms. This leaves messages malleable to any attacker that can access the message.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47123" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-04" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-353" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-26T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-3hjm-w3jh-pc36/GHSA-3hjm-w3jh-pc36.json b/advisories/unreviewed/2024/09/GHSA-3hjm-w3jh-pc36/GHSA-3hjm-w3jh-pc36.json new file mode 100644 index 00000000000..1302648d16f --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-3hjm-w3jh-pc36/GHSA-3hjm-w3jh-pc36.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3hjm-w3jh-pc36", + "modified": "2024-09-26T18:31:44Z", + "published": "2024-09-26T18:31:44Z", + "aliases": [ + "CVE-2024-37125" + ], + "details": "Dell SmartFabric OS10 Software, versions 10.5.6.x, 10.5.5.x, 10.5.4.x,10.5.3.x, contains an Uncontrolled Resource Consumption vulnerability. A remote unauthenticated host could potentially exploit this vulnerability leading to a denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37125" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000228976/dsa-2024-274-security-update-for-dell-networking-os10-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-26T17:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-4v4q-xr4r-hm4m/GHSA-4v4q-xr4r-hm4m.json b/advisories/unreviewed/2024/09/GHSA-4v4q-xr4r-hm4m/GHSA-4v4q-xr4r-hm4m.json new file mode 100644 index 00000000000..03cceb6a7ab --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-4v4q-xr4r-hm4m/GHSA-4v4q-xr4r-hm4m.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4v4q-xr4r-hm4m", + "modified": "2024-09-26T18:31:45Z", + "published": "2024-09-26T18:31:44Z", + "aliases": [ + "CVE-2024-41931" + ], + "details": "The goTenna Pro ATAK Plugin broadcast key name is always sent unencrypted and could reveal the location of operation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41931" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-05" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-201" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-26T18:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-5257-g4x8-28qj/GHSA-5257-g4x8-28qj.json b/advisories/unreviewed/2024/09/GHSA-5257-g4x8-28qj/GHSA-5257-g4x8-28qj.json new file mode 100644 index 00000000000..0c47471b2d6 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-5257-g4x8-28qj/GHSA-5257-g4x8-28qj.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5257-g4x8-28qj", + "modified": "2024-09-26T18:31:45Z", + "published": "2024-09-26T18:31:45Z", + "aliases": [ + "CVE-2024-45374" + ], + "details": "In the goTenna Pro ATAK Plugin application, the encryption keys are \nstored along with a static IV on the device. This allows for complete \ndecryption of keys stored on the device. This allows an attacker to \ndecrypt all encrypted broadcast communications based on broadcast keys \nstored on the device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45374" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-05" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-521" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-26T18:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-5f2j-f39j-26m7/GHSA-5f2j-f39j-26m7.json b/advisories/unreviewed/2024/09/GHSA-5f2j-f39j-26m7/GHSA-5f2j-f39j-26m7.json new file mode 100644 index 00000000000..abed819a042 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-5f2j-f39j-26m7/GHSA-5f2j-f39j-26m7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5f2j-f39j-26m7", + "modified": "2024-09-26T18:31:45Z", + "published": "2024-09-26T18:31:45Z", + "aliases": [ + "CVE-2024-39577" + ], + "details": "Dell SmartFabric OS10 Software, versions 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability leading to code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39577" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000228976/dsa-2024-274-security-update-for-dell-networking-os10-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-26T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-5mqf-9q34-g8c2/GHSA-5mqf-9q34-g8c2.json b/advisories/unreviewed/2024/09/GHSA-5mqf-9q34-g8c2/GHSA-5mqf-9q34-g8c2.json index 202fe77afc8..318342b5764 100644 --- a/advisories/unreviewed/2024/09/GHSA-5mqf-9q34-g8c2/GHSA-5mqf-9q34-g8c2.json +++ b/advisories/unreviewed/2024/09/GHSA-5mqf-9q34-g8c2/GHSA-5mqf-9q34-g8c2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5mqf-9q34-g8c2", - "modified": "2024-09-25T18:31:20Z", + "modified": "2024-09-26T18:31:43Z", "published": "2024-09-25T18:31:20Z", "aliases": [ "CVE-2024-44825" ], "details": "Directory Traversal vulnerability in Centro de Tecnologia da Informaco Renato Archer InVesalius3 v3.1.99995 allows attackers to write arbitrary files unto the system via a crafted .inv3 file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-25T16:15:10Z" diff --git a/advisories/unreviewed/2024/09/GHSA-6hw6-g568-pg8m/GHSA-6hw6-g568-pg8m.json b/advisories/unreviewed/2024/09/GHSA-6hw6-g568-pg8m/GHSA-6hw6-g568-pg8m.json index 15c93df7b7a..357b016992d 100644 --- a/advisories/unreviewed/2024/09/GHSA-6hw6-g568-pg8m/GHSA-6hw6-g568-pg8m.json +++ b/advisories/unreviewed/2024/09/GHSA-6hw6-g568-pg8m/GHSA-6hw6-g568-pg8m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6hw6-g568-pg8m", - "modified": "2024-09-26T15:30:43Z", + "modified": "2024-09-26T18:31:44Z", "published": "2024-09-26T15:30:43Z", "aliases": [ "CVE-2024-46328" ], "details": "VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain hardcoded credentials for several different privileged accounts, including root.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-259" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-26T14:15:09Z" diff --git a/advisories/unreviewed/2024/09/GHSA-7vrc-hc62-3f49/GHSA-7vrc-hc62-3f49.json b/advisories/unreviewed/2024/09/GHSA-7vrc-hc62-3f49/GHSA-7vrc-hc62-3f49.json new file mode 100644 index 00000000000..70e38ade820 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-7vrc-hc62-3f49/GHSA-7vrc-hc62-3f49.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7vrc-hc62-3f49", + "modified": "2024-09-26T18:31:45Z", + "published": "2024-09-26T18:31:45Z", + "aliases": [ + "CVE-2024-47126" + ], + "details": "The goTenna Pro series does not use SecureRandom when generating its cryptographic keys. The random function in use is not suitable for cryptographic use.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47126" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-04" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-338" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-26T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-7w3c-jwh7-4486/GHSA-7w3c-jwh7-4486.json b/advisories/unreviewed/2024/09/GHSA-7w3c-jwh7-4486/GHSA-7w3c-jwh7-4486.json new file mode 100644 index 00000000000..308471149ef --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-7w3c-jwh7-4486/GHSA-7w3c-jwh7-4486.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7w3c-jwh7-4486", + "modified": "2024-09-26T18:31:45Z", + "published": "2024-09-26T18:31:45Z", + "aliases": [ + "CVE-2024-45989" + ], + "details": "Monica AI Assistant desktop application v2.3.0 is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor. A prompt injection allows an attacker to modify chatbot answer with an unloaded image that exfiltrates the user's sensitive chat data of the current session to a malicious third-party or attacker-controlled server.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45989" + }, + { + "type": "WEB", + "url": "https://github.com/soursec/CVEs/tree/main/CVE-2024-45989" + }, + { + "type": "WEB", + "url": "https://monica.im/desktop" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-26T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-8vp8-g29r-fxpf/GHSA-8vp8-g29r-fxpf.json b/advisories/unreviewed/2024/09/GHSA-8vp8-g29r-fxpf/GHSA-8vp8-g29r-fxpf.json index 25c6587faae..0bbee482107 100644 --- a/advisories/unreviewed/2024/09/GHSA-8vp8-g29r-fxpf/GHSA-8vp8-g29r-fxpf.json +++ b/advisories/unreviewed/2024/09/GHSA-8vp8-g29r-fxpf/GHSA-8vp8-g29r-fxpf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8vp8-g29r-fxpf", - "modified": "2024-09-25T03:30:36Z", + "modified": "2024-09-26T18:31:43Z", "published": "2024-09-25T03:30:36Z", "aliases": [ "CVE-2024-47048" ], "details": "Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier allows stored XSS in the description and release notes of the marketplace and private apps.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-25T01:15:44Z" diff --git a/advisories/unreviewed/2024/09/GHSA-9362-9gf3-j66g/GHSA-9362-9gf3-j66g.json b/advisories/unreviewed/2024/09/GHSA-9362-9gf3-j66g/GHSA-9362-9gf3-j66g.json new file mode 100644 index 00000000000..8d6d4cc2ad4 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-9362-9gf3-j66g/GHSA-9362-9gf3-j66g.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9362-9gf3-j66g", + "modified": "2024-09-26T18:31:44Z", + "published": "2024-09-26T18:31:44Z", + "aliases": [ + "CVE-2024-45982" + ], + "details": "A host header injection vulnerability in scheduleR v0.0.18 allows attackers to obtain the password reset token via user interaction with a crafted password reset link. This allows attackers to arbitrarily reset other users' passwords and compromise their accounts.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45982" + }, + { + "type": "WEB", + "url": "https://github.com/soursec/CVEs/tree/main/CVE-2024-45982" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-26T17:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-94pj-f953-73h5/GHSA-94pj-f953-73h5.json b/advisories/unreviewed/2024/09/GHSA-94pj-f953-73h5/GHSA-94pj-f953-73h5.json index b77707ca16a..c04cd3ec847 100644 --- a/advisories/unreviewed/2024/09/GHSA-94pj-f953-73h5/GHSA-94pj-f953-73h5.json +++ b/advisories/unreviewed/2024/09/GHSA-94pj-f953-73h5/GHSA-94pj-f953-73h5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-94pj-f953-73h5", - "modified": "2024-09-06T15:32:59Z", + "modified": "2024-09-26T18:31:43Z", "published": "2024-09-06T15:32:59Z", "aliases": [ "CVE-2024-7611" diff --git a/advisories/unreviewed/2024/09/GHSA-99f7-m726-289j/GHSA-99f7-m726-289j.json b/advisories/unreviewed/2024/09/GHSA-99f7-m726-289j/GHSA-99f7-m726-289j.json index 6699f91a62b..637cd09d583 100644 --- a/advisories/unreviewed/2024/09/GHSA-99f7-m726-289j/GHSA-99f7-m726-289j.json +++ b/advisories/unreviewed/2024/09/GHSA-99f7-m726-289j/GHSA-99f7-m726-289j.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-295" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-9gxg-3rjh-xv63/GHSA-9gxg-3rjh-xv63.json b/advisories/unreviewed/2024/09/GHSA-9gxg-3rjh-xv63/GHSA-9gxg-3rjh-xv63.json new file mode 100644 index 00000000000..e0fd6eaf93a --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-9gxg-3rjh-xv63/GHSA-9gxg-3rjh-xv63.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9gxg-3rjh-xv63", + "modified": "2024-09-26T18:31:44Z", + "published": "2024-09-26T18:31:44Z", + "aliases": [ + "CVE-2024-7259" + ], + "details": "A flaw was found in oVirt. A user with administrator privileges, including users with the ReadOnlyAdmin permission, may be able to use browser developer tools to view Provider passwords in cleartext.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7259" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-7259" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2314229" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-312" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-26T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-9vgq-8h3w-xj2r/GHSA-9vgq-8h3w-xj2r.json b/advisories/unreviewed/2024/09/GHSA-9vgq-8h3w-xj2r/GHSA-9vgq-8h3w-xj2r.json new file mode 100644 index 00000000000..2e0338f7934 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-9vgq-8h3w-xj2r/GHSA-9vgq-8h3w-xj2r.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9vgq-8h3w-xj2r", + "modified": "2024-09-26T18:31:44Z", + "published": "2024-09-26T18:31:44Z", + "aliases": [ + "CVE-2024-45983" + ], + "details": "A Cross-Site Request Forgery (CSRF) vulnerability exists in kishan0725's Hospital Management System version 6.3.5. The vulnerability allows an attacker to craft a malicious HTML form that submits a request to delete a doctor record. By enticing an authenticated admin user to visit the specially crafted web page, the attacker can leverage the victim's browser to make unauthorized requests to the vulnerable endpoint, effectively allowing the attacker to perform actions on behalf of the admin without their consent.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45983" + }, + { + "type": "WEB", + "url": "https://github.com/soursec/CVEs/tree/main/CVE-2024-45983" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-26T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-c2c6-68mw-462f/GHSA-c2c6-68mw-462f.json b/advisories/unreviewed/2024/09/GHSA-c2c6-68mw-462f/GHSA-c2c6-68mw-462f.json index 8ced1766c6c..d69c8b1f045 100644 --- a/advisories/unreviewed/2024/09/GHSA-c2c6-68mw-462f/GHSA-c2c6-68mw-462f.json +++ b/advisories/unreviewed/2024/09/GHSA-c2c6-68mw-462f/GHSA-c2c6-68mw-462f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c2c6-68mw-462f", - "modified": "2024-09-25T03:30:36Z", + "modified": "2024-09-26T18:31:43Z", "published": "2024-09-25T03:30:36Z", "aliases": [ "CVE-2024-46934" ], "details": "Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to DOM-based Cross-site Scripting (XSS). Attackers may be able to abuse the UpdateOTRAck method to forge a message that contains an XSS payload.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-25T01:15:44Z" diff --git a/advisories/unreviewed/2024/09/GHSA-chqx-36rm-rf8h/GHSA-chqx-36rm-rf8h.json b/advisories/unreviewed/2024/09/GHSA-chqx-36rm-rf8h/GHSA-chqx-36rm-rf8h.json index 3689becbf2a..67056b64a8b 100644 --- a/advisories/unreviewed/2024/09/GHSA-chqx-36rm-rf8h/GHSA-chqx-36rm-rf8h.json +++ b/advisories/unreviewed/2024/09/GHSA-chqx-36rm-rf8h/GHSA-chqx-36rm-rf8h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-chqx-36rm-rf8h", - "modified": "2024-09-25T18:31:21Z", + "modified": "2024-09-26T18:31:44Z", "published": "2024-09-25T18:31:21Z", "aliases": [ "CVE-2024-8975" @@ -21,10 +21,18 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8975" }, + { + "type": "WEB", + "url": "https://github.com/grafana/alloy/releases/tag/v1.3.4" + }, { "type": "WEB", "url": "https://github.com/grafana/alloy/releases/tag/v1.4.0" }, + { + "type": "WEB", + "url": "https://github.com/grafana/alloy/releases/tag/v1.4.1" + }, { "type": "WEB", "url": "https://grafana.com/blog/2024/09/25/grafana-alloy-and-grafana-agent-flow-security-release-high-severity-fix-for-cve-2024-8975-and-cve-2024-8996" diff --git a/advisories/unreviewed/2024/09/GHSA-cwjv-mxfr-rrv9/GHSA-cwjv-mxfr-rrv9.json b/advisories/unreviewed/2024/09/GHSA-cwjv-mxfr-rrv9/GHSA-cwjv-mxfr-rrv9.json new file mode 100644 index 00000000000..49c0389fadd --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-cwjv-mxfr-rrv9/GHSA-cwjv-mxfr-rrv9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cwjv-mxfr-rrv9", + "modified": "2024-09-26T18:31:44Z", + "published": "2024-09-26T18:31:44Z", + "aliases": [ + "CVE-2024-45981" + ], + "details": "A host header injection vulnerability in BookReviewLibrary 1.0 allows attackers to obtain the password reset token via user interaction with a crafted password reset link.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45981" + }, + { + "type": "WEB", + "url": "https://github.com/soursec/CVEs/tree/main/CVE-2024-45981" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-26T17:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-f6qm-w5rg-95gh/GHSA-f6qm-w5rg-95gh.json b/advisories/unreviewed/2024/09/GHSA-f6qm-w5rg-95gh/GHSA-f6qm-w5rg-95gh.json new file mode 100644 index 00000000000..5c4cd11f1cb --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-f6qm-w5rg-95gh/GHSA-f6qm-w5rg-95gh.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f6qm-w5rg-95gh", + "modified": "2024-09-26T18:31:44Z", + "published": "2024-09-26T18:31:44Z", + "aliases": [ + "CVE-2024-45979" + ], + "details": "A host header injection vulnerability in Lines Police CAD 1.0 allows attackers to obtain the password reset token via user interaction with a crafted password reset link. This allows attackers to arbitrarily reset other users' passwords and compromise their accounts.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45979" + }, + { + "type": "WEB", + "url": "https://github.com/soursec/CVEs/tree/main/CVE-2024-45979" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-26T17:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-fg6p-6vjg-95r5/GHSA-fg6p-6vjg-95r5.json b/advisories/unreviewed/2024/09/GHSA-fg6p-6vjg-95r5/GHSA-fg6p-6vjg-95r5.json new file mode 100644 index 00000000000..2025a3db34e --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-fg6p-6vjg-95r5/GHSA-fg6p-6vjg-95r5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fg6p-6vjg-95r5", + "modified": "2024-09-26T18:31:45Z", + "published": "2024-09-26T18:31:45Z", + "aliases": [ + "CVE-2024-47127" + ], + "details": "In the goTenna Pro there is a vulnerability that makes it possible to inject any custom message with any GID and Callsign using a software defined radio in existing gotenna mesh networks. This vulnerability can be exploited if the device is being used in a unencrypted environment or if the cryptography has already been compromised.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47127" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-04" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1390" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-26T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-g75p-qvp4-j95j/GHSA-g75p-qvp4-j95j.json b/advisories/unreviewed/2024/09/GHSA-g75p-qvp4-j95j/GHSA-g75p-qvp4-j95j.json new file mode 100644 index 00000000000..193f9aa6df1 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-g75p-qvp4-j95j/GHSA-g75p-qvp4-j95j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g75p-qvp4-j95j", + "modified": "2024-09-26T18:31:44Z", + "published": "2024-09-26T18:31:44Z", + "aliases": [ + "CVE-2024-43191" + ], + "details": "IBM ManageIQ could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted yaml file request.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43191" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7170411" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-26T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-g8xq-w7g6-jc3v/GHSA-g8xq-w7g6-jc3v.json b/advisories/unreviewed/2024/09/GHSA-g8xq-w7g6-jc3v/GHSA-g8xq-w7g6-jc3v.json new file mode 100644 index 00000000000..50ee396538b --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-g8xq-w7g6-jc3v/GHSA-g8xq-w7g6-jc3v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g8xq-w7g6-jc3v", + "modified": "2024-09-26T18:31:45Z", + "published": "2024-09-26T18:31:45Z", + "aliases": [ + "CVE-2024-47128" + ], + "details": "The goTenna Pro broadcast key name is always sent unencrypted and could reveal the location of operation.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47128" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-04" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-201" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-26T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-g922-hx36-gr43/GHSA-g922-hx36-gr43.json b/advisories/unreviewed/2024/09/GHSA-g922-hx36-gr43/GHSA-g922-hx36-gr43.json new file mode 100644 index 00000000000..3bc15339967 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-g922-hx36-gr43/GHSA-g922-hx36-gr43.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g922-hx36-gr43", + "modified": "2024-09-26T18:31:45Z", + "published": "2024-09-26T18:31:45Z", + "aliases": [ + "CVE-2024-45984" + ], + "details": "A Cross Site Scripting (XSS) vulnerability in add_donor.php of Blood Bank And Donation Management System 1.0 allows an attacker to inject malicious scripts that will be executed when the Donor List is viewed.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45984" + }, + { + "type": "WEB", + "url": "https://github.com/soursec/CVEs/tree/main/CVE-2024-45984" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-26T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-gvfm-hc65-h2hv/GHSA-gvfm-hc65-h2hv.json b/advisories/unreviewed/2024/09/GHSA-gvfm-hc65-h2hv/GHSA-gvfm-hc65-h2hv.json new file mode 100644 index 00000000000..5b7a0c9ccbe --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-gvfm-hc65-h2hv/GHSA-gvfm-hc65-h2hv.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gvfm-hc65-h2hv", + "modified": "2024-09-26T18:31:44Z", + "published": "2024-09-26T18:31:44Z", + "aliases": [ + "CVE-2024-46627" + ], + "details": "Incorrect access control in BECN DATAGERRY v2.2 allows attackers to execute arbitrary commands via crafted web requests.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46627" + }, + { + "type": "WEB", + "url": "https://daly.wtf/cve-2024-46627-incorrect-access-control-in-becn-datagerry-v2-2-allows-attackers-to-execute-arbitrary-commands-via-crafted-web-requests" + }, + { + "type": "WEB", + "url": "https://datagerry.com" + }, + { + "type": "WEB", + "url": "https://github.com/DATAGerry" + }, + { + "type": "WEB", + "url": "https://github.com/d4lyw/CVE-2024-46627" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-26T17:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-gwp5-2fcr-m24v/GHSA-gwp5-2fcr-m24v.json b/advisories/unreviewed/2024/09/GHSA-gwp5-2fcr-m24v/GHSA-gwp5-2fcr-m24v.json new file mode 100644 index 00000000000..1f6fb29af9f --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-gwp5-2fcr-m24v/GHSA-gwp5-2fcr-m24v.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gwp5-2fcr-m24v", + "modified": "2024-09-26T18:31:45Z", + "published": "2024-09-26T18:31:45Z", + "aliases": [ + "CVE-2024-45985" + ], + "details": "A Cross Site Scripting (XSS) vulnerability in update_contact.php of Blood Bank and Donation Management System v1.0 allows an attacker to inject malicious scripts via the name parameter of the update_contact.php", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45985" + }, + { + "type": "WEB", + "url": "https://github.com/soursec/CVEs/tree/main/CVE-2024-45985" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-26T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-h66g-2x3f-vgpp/GHSA-h66g-2x3f-vgpp.json b/advisories/unreviewed/2024/09/GHSA-h66g-2x3f-vgpp/GHSA-h66g-2x3f-vgpp.json index cd3ee83fb77..0089096450e 100644 --- a/advisories/unreviewed/2024/09/GHSA-h66g-2x3f-vgpp/GHSA-h66g-2x3f-vgpp.json +++ b/advisories/unreviewed/2024/09/GHSA-h66g-2x3f-vgpp/GHSA-h66g-2x3f-vgpp.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h66g-2x3f-vgpp", - "modified": "2024-09-18T15:30:53Z", + "modified": "2024-09-26T18:31:43Z", "published": "2024-09-18T15:30:53Z", "aliases": [ "CVE-2024-5958" ], "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eliz Software Panel allows Command Line Execution through SQL Injection.This issue affects Panel: before v2.3.24.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/09/GHSA-hjw2-8p34-88rj/GHSA-hjw2-8p34-88rj.json b/advisories/unreviewed/2024/09/GHSA-hjw2-8p34-88rj/GHSA-hjw2-8p34-88rj.json index 6efcf14186d..90971a429df 100644 --- a/advisories/unreviewed/2024/09/GHSA-hjw2-8p34-88rj/GHSA-hjw2-8p34-88rj.json +++ b/advisories/unreviewed/2024/09/GHSA-hjw2-8p34-88rj/GHSA-hjw2-8p34-88rj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hjw2-8p34-88rj", - "modified": "2024-09-26T09:31:41Z", + "modified": "2024-09-26T18:31:43Z", "published": "2024-09-26T06:30:48Z", "aliases": [ "CVE-2024-47045" ], "details": "User interface (UI) misrepresentation of critical information issue exists in multiple Home GateWay/Hikari Denwa routers provided by NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION. If this vulnerability is exploited, an attacker who identified WAN-side IPv6 address may access the product's Device Setting page via WAN-side. Note that, affects products are also provided by NIPPON TELEGRAPH AND TELEPHONE WEST CORPORATION, but the vulnerability only affects products subscribed and used in NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION areas.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -56,7 +59,7 @@ "CWE-268", "CWE-451" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-26T04:15:07Z" diff --git a/advisories/unreviewed/2024/09/GHSA-hwxp-6qf7-q3rc/GHSA-hwxp-6qf7-q3rc.json b/advisories/unreviewed/2024/09/GHSA-hwxp-6qf7-q3rc/GHSA-hwxp-6qf7-q3rc.json index c1011b13829..82db6ba7e07 100644 --- a/advisories/unreviewed/2024/09/GHSA-hwxp-6qf7-q3rc/GHSA-hwxp-6qf7-q3rc.json +++ b/advisories/unreviewed/2024/09/GHSA-hwxp-6qf7-q3rc/GHSA-hwxp-6qf7-q3rc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hwxp-6qf7-q3rc", - "modified": "2024-09-25T18:31:21Z", + "modified": "2024-09-26T18:31:43Z", "published": "2024-09-25T18:31:21Z", "aliases": [ "CVE-2024-46489" ], "details": "A remote command execution (RCE) vulnerability in promptr v6.0.7 allows attackers to execute arbitrary commands via a crafted URL.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-25T18:15:05Z" diff --git a/advisories/unreviewed/2024/09/GHSA-j6pg-h597-gcx9/GHSA-j6pg-h597-gcx9.json b/advisories/unreviewed/2024/09/GHSA-j6pg-h597-gcx9/GHSA-j6pg-h597-gcx9.json new file mode 100644 index 00000000000..9e5c55d26af --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-j6pg-h597-gcx9/GHSA-j6pg-h597-gcx9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6pg-h597-gcx9", + "modified": "2024-09-26T18:31:44Z", + "published": "2024-09-26T18:31:44Z", + "aliases": [ + "CVE-2024-45980" + ], + "details": "A host header injection vulnerability in MEANStore 1.0 allows attackers to obtain the password reset token via user interaction with a crafted password reset link. This allows attackers to arbitrarily reset other users' passwords and compromise their accounts.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45980" + }, + { + "type": "WEB", + "url": "https://github.com/soursec/CVEs/tree/main/CVE-2024-45980" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-26T17:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-j9vg-w22p-v5v2/GHSA-j9vg-w22p-v5v2.json b/advisories/unreviewed/2024/09/GHSA-j9vg-w22p-v5v2/GHSA-j9vg-w22p-v5v2.json new file mode 100644 index 00000000000..fd5b6fbb9a0 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-j9vg-w22p-v5v2/GHSA-j9vg-w22p-v5v2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j9vg-w22p-v5v2", + "modified": "2024-09-26T18:31:45Z", + "published": "2024-09-26T18:31:45Z", + "aliases": [ + "CVE-2024-47122" + ], + "details": "In the goTenna Pro application, the encryption keys are stored along with a static IV on the device. This allows for complete decryption of keys stored on the device. This allows an attacker to decrypt all encrypted communications that include P2P, Group, and broadcast messages that use these keys.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47122" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-04" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-922" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-26T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-jcqp-84r8-2q6f/GHSA-jcqp-84r8-2q6f.json b/advisories/unreviewed/2024/09/GHSA-jcqp-84r8-2q6f/GHSA-jcqp-84r8-2q6f.json index b03e9f26e72..321ab8c2029 100644 --- a/advisories/unreviewed/2024/09/GHSA-jcqp-84r8-2q6f/GHSA-jcqp-84r8-2q6f.json +++ b/advisories/unreviewed/2024/09/GHSA-jcqp-84r8-2q6f/GHSA-jcqp-84r8-2q6f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jcqp-84r8-2q6f", - "modified": "2024-09-26T15:30:43Z", + "modified": "2024-09-26T18:31:44Z", "published": "2024-09-26T15:30:43Z", "aliases": [ "CVE-2024-46327" ], "details": "An issue in the Http_handle object of VONETS VAP11G-300 v3.3.23.6.9 allows attackers to access sensitive files via a directory traversal.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-26T14:15:09Z" diff --git a/advisories/unreviewed/2024/09/GHSA-jg3f-p7fw-74wx/GHSA-jg3f-p7fw-74wx.json b/advisories/unreviewed/2024/09/GHSA-jg3f-p7fw-74wx/GHSA-jg3f-p7fw-74wx.json new file mode 100644 index 00000000000..0491f76b370 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-jg3f-p7fw-74wx/GHSA-jg3f-p7fw-74wx.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jg3f-p7fw-74wx", + "modified": "2024-09-26T18:31:45Z", + "published": "2024-09-26T18:31:45Z", + "aliases": [ + "CVE-2024-45838" + ], + "details": "The goTenna Pro ATAK Plugin does not encrypt the callsigns of its users.\n These callsigns reveal information about the users and can also be \nleveraged for other vulnerabilities.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45838" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-05" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-319" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-26T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-m5gv-m5f9-wgv4/GHSA-m5gv-m5f9-wgv4.json b/advisories/unreviewed/2024/09/GHSA-m5gv-m5f9-wgv4/GHSA-m5gv-m5f9-wgv4.json index dd9059cb183..4e1ceda517c 100644 --- a/advisories/unreviewed/2024/09/GHSA-m5gv-m5f9-wgv4/GHSA-m5gv-m5f9-wgv4.json +++ b/advisories/unreviewed/2024/09/GHSA-m5gv-m5f9-wgv4/GHSA-m5gv-m5f9-wgv4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m5gv-m5f9-wgv4", - "modified": "2024-09-25T18:31:21Z", + "modified": "2024-09-26T18:31:43Z", "published": "2024-09-25T18:31:21Z", "aliases": [ "CVE-2024-8996" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://github.com/grafana/agent/releases/tag/v0.43.2" }, + { + "type": "WEB", + "url": "https://github.com/grafana/agent/releases/tag/v0.43.3" + }, { "type": "WEB", "url": "https://grafana.com/blog/2024/09/25/grafana-alloy-and-grafana-agent-flow-security-release-high-severity-fix-for-cve-2024-8975-and-cve-2024-8996" diff --git a/advisories/unreviewed/2024/09/GHSA-m5pm-m9f5-33q4/GHSA-m5pm-m9f5-33q4.json b/advisories/unreviewed/2024/09/GHSA-m5pm-m9f5-33q4/GHSA-m5pm-m9f5-33q4.json new file mode 100644 index 00000000000..8713e2ef1de --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-m5pm-m9f5-33q4/GHSA-m5pm-m9f5-33q4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m5pm-m9f5-33q4", + "modified": "2024-09-26T18:31:45Z", + "published": "2024-09-26T18:31:45Z", + "aliases": [ + "CVE-2024-45987" + ], + "details": "Projectworld Online Voting System Version 1.0 is vulnerable to Cross Site Request Forgery (CSRF) via voter.php. This vulnerability allows an attacker to craft a malicious link that, when clicked by an authenticated user, automatically submits a vote for a specified party without the user's consent or knowledge. The attack leverages the user's active session to perform the unauthorized action, compromising the integrity of the voting process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45987" + }, + { + "type": "WEB", + "url": "https://github.com/soursec/CVEs/tree/main/CVE-2024-45987" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-26T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-mrhc-m9q7-2fvp/GHSA-mrhc-m9q7-2fvp.json b/advisories/unreviewed/2024/09/GHSA-mrhc-m9q7-2fvp/GHSA-mrhc-m9q7-2fvp.json new file mode 100644 index 00000000000..fc6895ff4df --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-mrhc-m9q7-2fvp/GHSA-mrhc-m9q7-2fvp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mrhc-m9q7-2fvp", + "modified": "2024-09-26T18:31:44Z", + "published": "2024-09-26T18:31:44Z", + "aliases": [ + "CVE-2024-41605" + ], + "details": "An issue in Foxit Software Foxit PDF Reader v.2024.2.2.25170 allows a local attacker to execute arbitrary code via the FoxitPDFReaderUpdater.exe component", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41605" + }, + { + "type": "WEB", + "url": "https://www.foxit.com/support/security-bulletins.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-26T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-mv5r-w7g6-89v6/GHSA-mv5r-w7g6-89v6.json b/advisories/unreviewed/2024/09/GHSA-mv5r-w7g6-89v6/GHSA-mv5r-w7g6-89v6.json index 154eb4f63fd..4fc8f63061a 100644 --- a/advisories/unreviewed/2024/09/GHSA-mv5r-w7g6-89v6/GHSA-mv5r-w7g6-89v6.json +++ b/advisories/unreviewed/2024/09/GHSA-mv5r-w7g6-89v6/GHSA-mv5r-w7g6-89v6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mv5r-w7g6-89v6", - "modified": "2024-09-26T15:30:44Z", + "modified": "2024-09-26T18:31:44Z", "published": "2024-09-26T15:30:44Z", "aliases": [ "CVE-2024-46330" ], "details": "VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain a command injection vulnerability via the iptablesWebsFilterRun object.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-26T14:15:09Z" diff --git a/advisories/unreviewed/2024/09/GHSA-p64c-2wr6-h7wf/GHSA-p64c-2wr6-h7wf.json b/advisories/unreviewed/2024/09/GHSA-p64c-2wr6-h7wf/GHSA-p64c-2wr6-h7wf.json index 3f32b69daf4..d0085acd9ec 100644 --- a/advisories/unreviewed/2024/09/GHSA-p64c-2wr6-h7wf/GHSA-p64c-2wr6-h7wf.json +++ b/advisories/unreviewed/2024/09/GHSA-p64c-2wr6-h7wf/GHSA-p64c-2wr6-h7wf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p64c-2wr6-h7wf", - "modified": "2024-09-07T12:30:44Z", + "modified": "2024-09-26T18:31:43Z", "published": "2024-09-07T12:30:44Z", "aliases": [ "CVE-2024-7112" diff --git a/advisories/unreviewed/2024/09/GHSA-pf8r-hfj4-5hrm/GHSA-pf8r-hfj4-5hrm.json b/advisories/unreviewed/2024/09/GHSA-pf8r-hfj4-5hrm/GHSA-pf8r-hfj4-5hrm.json new file mode 100644 index 00000000000..bb60ceecb8c --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-pf8r-hfj4-5hrm/GHSA-pf8r-hfj4-5hrm.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pf8r-hfj4-5hrm", + "modified": "2024-09-26T18:31:45Z", + "published": "2024-09-26T18:31:45Z", + "aliases": [ + "CVE-2024-43108" + ], + "details": "The goTenna Pro ATAK Plugin use AES CTR mode for short, encrypted \nmessages without any additional integrity checking mechanisms. This \nleaves messages malleable to any attacker that can access the message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43108" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-05" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-353" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-26T18:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-pr27-f9rc-q4vm/GHSA-pr27-f9rc-q4vm.json b/advisories/unreviewed/2024/09/GHSA-pr27-f9rc-q4vm/GHSA-pr27-f9rc-q4vm.json new file mode 100644 index 00000000000..05bed8407d1 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-pr27-f9rc-q4vm/GHSA-pr27-f9rc-q4vm.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pr27-f9rc-q4vm", + "modified": "2024-09-26T18:31:44Z", + "published": "2024-09-26T18:31:44Z", + "aliases": [ + "CVE-2024-8771" + ], + "details": "The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'preview_email_template_design' function in all versions up to, and including, 5.7.34. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive data including the content of private, password protected, pending, and draft posts and pages.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8771" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/email-subscribers/trunk/lite/admin/class-email-subscribers-admin.php#L1754" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3157336" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f9d90717-fd48-493b-9293-32976bf2cada?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-26T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-r7mf-5w8w-4x2h/GHSA-r7mf-5w8w-4x2h.json b/advisories/unreviewed/2024/09/GHSA-r7mf-5w8w-4x2h/GHSA-r7mf-5w8w-4x2h.json index c10bf32ae08..f4c15b79c4e 100644 --- a/advisories/unreviewed/2024/09/GHSA-r7mf-5w8w-4x2h/GHSA-r7mf-5w8w-4x2h.json +++ b/advisories/unreviewed/2024/09/GHSA-r7mf-5w8w-4x2h/GHSA-r7mf-5w8w-4x2h.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r7mf-5w8w-4x2h", - "modified": "2024-09-20T15:30:37Z", + "modified": "2024-09-26T18:31:43Z", "published": "2024-09-19T06:31:36Z", "aliases": [ "CVE-2024-47085" ], "details": "This vulnerability exists in LD DP Back Office due to improper validation of certain parameters “cCdslClicentcode” and “cLdClientCode” in the API endpoint. An authenticated remote attacker could exploit this vulnerability by manipulating parameters in the API request body leading to exposure of sensitive information belonging to other users.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/09/GHSA-r7rh-frh5-cg5j/GHSA-r7rh-frh5-cg5j.json b/advisories/unreviewed/2024/09/GHSA-r7rh-frh5-cg5j/GHSA-r7rh-frh5-cg5j.json new file mode 100644 index 00000000000..ba16564caf5 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-r7rh-frh5-cg5j/GHSA-r7rh-frh5-cg5j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r7rh-frh5-cg5j", + "modified": "2024-09-26T18:31:45Z", + "published": "2024-09-26T18:31:45Z", + "aliases": [ + "CVE-2024-47124" + ], + "details": "The goTenna pro series does not encrypt the callsigns of its users. These callsigns reveal information about the users and can also be leveraged for other vulnerabilities.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47124" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-04" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-319" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-26T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-r9gf-v8wf-j3wq/GHSA-r9gf-v8wf-j3wq.json b/advisories/unreviewed/2024/09/GHSA-r9gf-v8wf-j3wq/GHSA-r9gf-v8wf-j3wq.json new file mode 100644 index 00000000000..2bcf4cec8ad --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-r9gf-v8wf-j3wq/GHSA-r9gf-v8wf-j3wq.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r9gf-v8wf-j3wq", + "modified": "2024-09-26T18:31:45Z", + "published": "2024-09-26T18:31:45Z", + "aliases": [ + "CVE-2024-41715" + ], + "details": "The goTenna Pro ATAK Plugin has a payload length vulnerability that \nmakes it possible to tell the length of the payload regardless of the \nencryption used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41715" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-05" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-204" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-26T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-rgqq-jvq6-w93r/GHSA-rgqq-jvq6-w93r.json b/advisories/unreviewed/2024/09/GHSA-rgqq-jvq6-w93r/GHSA-rgqq-jvq6-w93r.json new file mode 100644 index 00000000000..bbb2128d743 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-rgqq-jvq6-w93r/GHSA-rgqq-jvq6-w93r.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rgqq-jvq6-w93r", + "modified": "2024-09-26T18:31:45Z", + "published": "2024-09-26T18:31:45Z", + "aliases": [ + "CVE-2024-45723" + ], + "details": "The goTenna Pro ATAK Plugin does not use SecureRandom when generating \nits cryptographic keys. The random function in use is not suitable for \ncryptographic use.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45723" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-05" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-338" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-26T18:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-rhfw-c6gf-ccq3/GHSA-rhfw-c6gf-ccq3.json b/advisories/unreviewed/2024/09/GHSA-rhfw-c6gf-ccq3/GHSA-rhfw-c6gf-ccq3.json new file mode 100644 index 00000000000..cc0754f9243 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-rhfw-c6gf-ccq3/GHSA-rhfw-c6gf-ccq3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rhfw-c6gf-ccq3", + "modified": "2024-09-26T18:31:44Z", + "published": "2024-09-26T18:31:44Z", + "aliases": [ + "CVE-2024-46632" + ], + "details": "Assimp v5.4.3 is vulnerable to Buffer Overflow via the MD5Importer::LoadMD5MeshFile function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46632" + }, + { + "type": "WEB", + "url": "https://github.com/assimp/assimp/issues/5771" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-26T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-rqp2-49p2-7346/GHSA-rqp2-49p2-7346.json b/advisories/unreviewed/2024/09/GHSA-rqp2-49p2-7346/GHSA-rqp2-49p2-7346.json new file mode 100644 index 00000000000..cc3e5ec1715 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-rqp2-49p2-7346/GHSA-rqp2-49p2-7346.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rqp2-49p2-7346", + "modified": "2024-09-26T18:31:45Z", + "published": "2024-09-26T18:31:45Z", + "aliases": [ + "CVE-2024-43694" + ], + "details": "In the goTenna Pro ATAK Plugin application, the encryption keys are \nstored along with a static IV on the device. This allows for complete \ndecryption of keys stored on the device. This allows an attacker to \ndecrypt all encrypted broadcast communications based on broadcast keys \nstored on the device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43694" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-05" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-922" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-26T18:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-v56c-mcwg-jqc2/GHSA-v56c-mcwg-jqc2.json b/advisories/unreviewed/2024/09/GHSA-v56c-mcwg-jqc2/GHSA-v56c-mcwg-jqc2.json index bd22e357319..2a078d4b04c 100644 --- a/advisories/unreviewed/2024/09/GHSA-v56c-mcwg-jqc2/GHSA-v56c-mcwg-jqc2.json +++ b/advisories/unreviewed/2024/09/GHSA-v56c-mcwg-jqc2/GHSA-v56c-mcwg-jqc2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v56c-mcwg-jqc2", - "modified": "2024-09-26T15:30:44Z", + "modified": "2024-09-26T18:31:44Z", "published": "2024-09-26T15:30:44Z", "aliases": [ "CVE-2024-46329" ], "details": "VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain a command injection vulnerability via the SystemCommand object.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-26T14:15:09Z" diff --git a/advisories/unreviewed/2024/09/GHSA-v596-cf8q-xgjv/GHSA-v596-cf8q-xgjv.json b/advisories/unreviewed/2024/09/GHSA-v596-cf8q-xgjv/GHSA-v596-cf8q-xgjv.json index 9c5c60559f9..2a6e4340c09 100644 --- a/advisories/unreviewed/2024/09/GHSA-v596-cf8q-xgjv/GHSA-v596-cf8q-xgjv.json +++ b/advisories/unreviewed/2024/09/GHSA-v596-cf8q-xgjv/GHSA-v596-cf8q-xgjv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v596-cf8q-xgjv", - "modified": "2024-09-07T09:30:32Z", + "modified": "2024-09-26T18:31:43Z", "published": "2024-09-07T09:30:32Z", "aliases": [ "CVE-2024-6849" diff --git a/advisories/unreviewed/2024/09/GHSA-vcw2-g6r2-h5hh/GHSA-vcw2-g6r2-h5hh.json b/advisories/unreviewed/2024/09/GHSA-vcw2-g6r2-h5hh/GHSA-vcw2-g6r2-h5hh.json new file mode 100644 index 00000000000..753d56f111f --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-vcw2-g6r2-h5hh/GHSA-vcw2-g6r2-h5hh.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vcw2-g6r2-h5hh", + "modified": "2024-09-26T18:31:45Z", + "published": "2024-09-26T18:31:45Z", + "aliases": [ + "CVE-2024-43814" + ], + "details": "goTenna Pro ATAK Plugin by default enables frequent unencrypted \nPosition, Location and Information (PLI) transmission. This transmission\n is done without user's knowledge, revealing the exact location \ntransmitted in unencrypted form.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43814" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-05" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-201" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-26T18:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-vfph-fvw4-j4xp/GHSA-vfph-fvw4-j4xp.json b/advisories/unreviewed/2024/09/GHSA-vfph-fvw4-j4xp/GHSA-vfph-fvw4-j4xp.json index ebba8c3bbf9..12198efe277 100644 --- a/advisories/unreviewed/2024/09/GHSA-vfph-fvw4-j4xp/GHSA-vfph-fvw4-j4xp.json +++ b/advisories/unreviewed/2024/09/GHSA-vfph-fvw4-j4xp/GHSA-vfph-fvw4-j4xp.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-662", "CWE-821" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/09/GHSA-vxwq-vcrr-3qj8/GHSA-vxwq-vcrr-3qj8.json b/advisories/unreviewed/2024/09/GHSA-vxwq-vcrr-3qj8/GHSA-vxwq-vcrr-3qj8.json new file mode 100644 index 00000000000..a842570d85a --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-vxwq-vcrr-3qj8/GHSA-vxwq-vcrr-3qj8.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vxwq-vcrr-3qj8", + "modified": "2024-09-26T18:31:45Z", + "published": "2024-09-26T18:31:45Z", + "aliases": [ + "CVE-2024-9203" + ], + "details": "A vulnerability, which was classified as problematic, has been found in Enpass Password Manager up to 6.9.5 on Windows. This issue affects some unknown processing. The manipulation leads to cleartext storage of sensitive information in memory. An attack has to be approached locally. The complexity of an attack is rather high. The exploitation is known to be difficult. Upgrading to version 6.10.1 is able to address this issue. It is recommended to upgrade the affected component.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9203" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.278561" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.278561" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.411207" + }, + { + "type": "WEB", + "url": "https://www.enpass.io/release-notes/windows-10-desktop" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-316" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-26T17:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-w3gp-gprx-5vj8/GHSA-w3gp-gprx-5vj8.json b/advisories/unreviewed/2024/09/GHSA-w3gp-gprx-5vj8/GHSA-w3gp-gprx-5vj8.json new file mode 100644 index 00000000000..619342987f0 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-w3gp-gprx-5vj8/GHSA-w3gp-gprx-5vj8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w3gp-gprx-5vj8", + "modified": "2024-09-26T18:31:45Z", + "published": "2024-09-26T18:31:45Z", + "aliases": [ + "CVE-2024-47125" + ], + "details": "The goTenna Pro series does not authenticate public keys which allows an unauthenticated attacker to intercept and manipulate messages.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47125" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-04" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-923" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-26T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-wq63-c6fv-j4j6/GHSA-wq63-c6fv-j4j6.json b/advisories/unreviewed/2024/09/GHSA-wq63-c6fv-j4j6/GHSA-wq63-c6fv-j4j6.json new file mode 100644 index 00000000000..c851dc82a06 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-wq63-c6fv-j4j6/GHSA-wq63-c6fv-j4j6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wq63-c6fv-j4j6", + "modified": "2024-09-26T18:31:45Z", + "published": "2024-09-26T18:31:45Z", + "aliases": [ + "CVE-2024-47129" + ], + "details": "The goTenna Pro has a payload length vulnerability that makes it possible to tell the length of the payload regardless of the encryption used.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47129" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-04" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-204" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-26T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-x2m7-9j9x-5v33/GHSA-x2m7-9j9x-5v33.json b/advisories/unreviewed/2024/09/GHSA-x2m7-9j9x-5v33/GHSA-x2m7-9j9x-5v33.json index 4d0f1313174..c52a243a2c4 100644 --- a/advisories/unreviewed/2024/09/GHSA-x2m7-9j9x-5v33/GHSA-x2m7-9j9x-5v33.json +++ b/advisories/unreviewed/2024/09/GHSA-x2m7-9j9x-5v33/GHSA-x2m7-9j9x-5v33.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x2m7-9j9x-5v33", - "modified": "2024-09-07T09:30:32Z", + "modified": "2024-09-26T18:31:43Z", "published": "2024-09-07T09:30:32Z", "aliases": [ "CVE-2024-8538" @@ -36,7 +36,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-22" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-x85h-x3fh-9fpv/GHSA-x85h-x3fh-9fpv.json b/advisories/unreviewed/2024/09/GHSA-x85h-x3fh-9fpv/GHSA-x85h-x3fh-9fpv.json new file mode 100644 index 00000000000..1cee784aff8 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-x85h-x3fh-9fpv/GHSA-x85h-x3fh-9fpv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x85h-x3fh-9fpv", + "modified": "2024-09-26T18:31:44Z", + "published": "2024-09-26T18:31:44Z", + "aliases": [ + "CVE-2024-44860" + ], + "details": "An information disclosure vulnerability in the /Letter/PrintQr/ endpoint of Solvait v24.4.2 allows attackers to access sensitive data via a crafted request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44860" + }, + { + "type": "WEB", + "url": "https://gist.github.com/walhajri/e03974097d1fd4eb698a6a80931bdd45" + }, + { + "type": "WEB", + "url": "https://www.solvait.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-26T17:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-xcqq-5vvm-q9m2/GHSA-xcqq-5vvm-q9m2.json b/advisories/unreviewed/2024/09/GHSA-xcqq-5vvm-q9m2/GHSA-xcqq-5vvm-q9m2.json new file mode 100644 index 00000000000..9f3e075c27c --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-xcqq-5vvm-q9m2/GHSA-xcqq-5vvm-q9m2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xcqq-5vvm-q9m2", + "modified": "2024-09-26T18:31:45Z", + "published": "2024-09-26T18:31:45Z", + "aliases": [ + "CVE-2024-47121" + ], + "details": "The goTenna Pro series uses a weak password for the QR broadcast message. If the QR broadcast message is captured over RF it is possible to decrypt it and use it to decrypt all future and past messages sent via encrypted broadcast.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47121" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-04" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-521" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-26T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-xw45-w4r2-g9c2/GHSA-xw45-w4r2-g9c2.json b/advisories/unreviewed/2024/09/GHSA-xw45-w4r2-g9c2/GHSA-xw45-w4r2-g9c2.json new file mode 100644 index 00000000000..e76e2058bbb --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-xw45-w4r2-g9c2/GHSA-xw45-w4r2-g9c2.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xw45-w4r2-g9c2", + "modified": "2024-09-26T18:31:45Z", + "published": "2024-09-26T18:31:45Z", + "aliases": [ + "CVE-2024-41722" + ], + "details": "In the goTenna Pro ATAK Plugin there is a vulnerability that makes it \npossible to inject any custom message with any GID and Callsign using a \nsoftware defined radio in existing gotenna mesh networks. This \nvulnerability can be exploited if the device is being used in a \nunencrypted environment or if the cryptography has already been \ncompromised.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41722" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-05" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1390" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-26T18:15:06Z" + } +} \ No newline at end of file