From 2d09cc2b16bfca216cf7d476abef6af813c56bc9 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 30 Aug 2024 18:31:56 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-343v-9ccv-7535.json | 2 +- .../GHSA-ccwc-jrj7-h4v6.json | 2 +- .../GHSA-mw3w-f2gc-g47m.json | 2 +- .../GHSA-qqfg-j9g4-4mfh.json | 2 +- .../GHSA-fm46-q589-f96x.json | 2 +- .../GHSA-3v7c-xw2c-76j5.json | 11 ++-- .../GHSA-4r7h-hv98-vx5w.json | 6 +- .../GHSA-4xqj-427q-hf6q.json | 1 + .../GHSA-5827-p7qc-6vf6.json | 11 ++-- .../GHSA-5c96-24qg-f876.json | 9 ++- .../GHSA-5hj8-xgx5-p37f.json | 9 ++- .../GHSA-5q6v-fp9h-6rjg.json | 3 +- .../GHSA-6hmg-mqf6-m38g.json | 11 ++-- .../GHSA-76vg-grjj-w595.json | 3 +- .../GHSA-83h2-mm3x-cpw4.json | 11 ++-- .../GHSA-87xp-v6jc-jprf.json | 2 +- .../GHSA-8q5q-cjjx-r967.json | 58 +++++++++++++++++++ .../GHSA-8v2g-m5cr-4r79.json | 11 ++-- .../GHSA-94ch-6cfh-xxgc.json | 46 +++++++++++++++ .../GHSA-cxc7-qrmh-3wx5.json | 11 ++-- .../GHSA-fcrv-q4xw-6crp.json | 38 ++++++++++++ .../GHSA-g5wr-xh7j-3w9v.json | 11 ++-- .../GHSA-j665-mqhh-jvh2.json | 58 +++++++++++++++++++ .../GHSA-jfp9-mpfm-8qc7.json | 1 + .../GHSA-mh7j-x4vr-3mg3.json | 35 +++++++++++ .../GHSA-mm9r-w8fm-6592.json | 46 +++++++++++++++ .../GHSA-p64m-r26f-95x6.json | 9 ++- .../GHSA-px2q-62h5-wq69.json | 31 ++++++++++ .../GHSA-q2fm-rxrg-hgpw.json | 58 +++++++++++++++++++ .../GHSA-q2mq-qmgr-3266.json | 11 ++-- .../GHSA-q777-ff33-4xgr.json | 6 +- .../GHSA-v323-q9x3-gg6h.json | 38 ++++++++++++ .../GHSA-v587-qwh9-6xx3.json | 1 + .../GHSA-v65h-92x8-q66f.json | 58 +++++++++++++++++++ .../GHSA-vf33-j375-2hrc.json | 31 ++++++++++ .../GHSA-w4qw-whg8-4fjc.json | 11 ++-- .../GHSA-w7cc-q8x4-3xx9.json | 11 ++-- .../GHSA-w9pm-7cxw-vw6j.json | 1 + .../GHSA-wm63-qmcq-5w39.json | 3 +- .../GHSA-wv98-rm53-823r.json | 11 ++-- .../GHSA-x36v-pwx4-c656.json | 31 ++++++++++ .../GHSA-x37r-vj3m-8vc5.json | 11 ++-- .../GHSA-x6xm-9hw6-q7gc.json | 6 +- .../GHSA-xpwg-9vrv-hq2j.json | 9 ++- 44 files changed, 669 insertions(+), 70 deletions(-) create mode 100644 advisories/unreviewed/2024/08/GHSA-8q5q-cjjx-r967/GHSA-8q5q-cjjx-r967.json create mode 100644 advisories/unreviewed/2024/08/GHSA-94ch-6cfh-xxgc/GHSA-94ch-6cfh-xxgc.json create mode 100644 advisories/unreviewed/2024/08/GHSA-fcrv-q4xw-6crp/GHSA-fcrv-q4xw-6crp.json create mode 100644 advisories/unreviewed/2024/08/GHSA-j665-mqhh-jvh2/GHSA-j665-mqhh-jvh2.json create mode 100644 advisories/unreviewed/2024/08/GHSA-mh7j-x4vr-3mg3/GHSA-mh7j-x4vr-3mg3.json create mode 100644 advisories/unreviewed/2024/08/GHSA-mm9r-w8fm-6592/GHSA-mm9r-w8fm-6592.json create mode 100644 advisories/unreviewed/2024/08/GHSA-px2q-62h5-wq69/GHSA-px2q-62h5-wq69.json create mode 100644 advisories/unreviewed/2024/08/GHSA-q2fm-rxrg-hgpw/GHSA-q2fm-rxrg-hgpw.json create mode 100644 advisories/unreviewed/2024/08/GHSA-v323-q9x3-gg6h/GHSA-v323-q9x3-gg6h.json create mode 100644 advisories/unreviewed/2024/08/GHSA-v65h-92x8-q66f/GHSA-v65h-92x8-q66f.json create mode 100644 advisories/unreviewed/2024/08/GHSA-vf33-j375-2hrc/GHSA-vf33-j375-2hrc.json create mode 100644 advisories/unreviewed/2024/08/GHSA-x36v-pwx4-c656/GHSA-x36v-pwx4-c656.json diff --git a/advisories/unreviewed/2024/01/GHSA-343v-9ccv-7535/GHSA-343v-9ccv-7535.json b/advisories/unreviewed/2024/01/GHSA-343v-9ccv-7535/GHSA-343v-9ccv-7535.json index f15f404382f..3e10221d470 100644 --- a/advisories/unreviewed/2024/01/GHSA-343v-9ccv-7535/GHSA-343v-9ccv-7535.json +++ b/advisories/unreviewed/2024/01/GHSA-343v-9ccv-7535/GHSA-343v-9ccv-7535.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-ccwc-jrj7-h4v6/GHSA-ccwc-jrj7-h4v6.json b/advisories/unreviewed/2024/01/GHSA-ccwc-jrj7-h4v6/GHSA-ccwc-jrj7-h4v6.json index 193f6112fd4..7119bc78a9d 100644 --- a/advisories/unreviewed/2024/01/GHSA-ccwc-jrj7-h4v6/GHSA-ccwc-jrj7-h4v6.json +++ b/advisories/unreviewed/2024/01/GHSA-ccwc-jrj7-h4v6/GHSA-ccwc-jrj7-h4v6.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-mw3w-f2gc-g47m/GHSA-mw3w-f2gc-g47m.json b/advisories/unreviewed/2024/06/GHSA-mw3w-f2gc-g47m/GHSA-mw3w-f2gc-g47m.json index fc562d685c1..bf8571969d2 100644 --- a/advisories/unreviewed/2024/06/GHSA-mw3w-f2gc-g47m/GHSA-mw3w-f2gc-g47m.json +++ b/advisories/unreviewed/2024/06/GHSA-mw3w-f2gc-g47m/GHSA-mw3w-f2gc-g47m.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-qqfg-j9g4-4mfh/GHSA-qqfg-j9g4-4mfh.json b/advisories/unreviewed/2024/06/GHSA-qqfg-j9g4-4mfh/GHSA-qqfg-j9g4-4mfh.json index 7121c667b38..b1e0d1c780b 100644 --- a/advisories/unreviewed/2024/06/GHSA-qqfg-j9g4-4mfh/GHSA-qqfg-j9g4-4mfh.json +++ b/advisories/unreviewed/2024/06/GHSA-qqfg-j9g4-4mfh/GHSA-qqfg-j9g4-4mfh.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-fm46-q589-f96x/GHSA-fm46-q589-f96x.json b/advisories/unreviewed/2024/07/GHSA-fm46-q589-f96x/GHSA-fm46-q589-f96x.json index d3818e1a5f6..c1d653b36a2 100644 --- a/advisories/unreviewed/2024/07/GHSA-fm46-q589-f96x/GHSA-fm46-q589-f96x.json +++ b/advisories/unreviewed/2024/07/GHSA-fm46-q589-f96x/GHSA-fm46-q589-f96x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fm46-q589-f96x", - "modified": "2024-07-20T09:30:36Z", + "modified": "2024-08-30T18:30:36Z", "published": "2024-07-20T09:30:36Z", "aliases": [ "CVE-2024-37955" diff --git a/advisories/unreviewed/2024/08/GHSA-3v7c-xw2c-76j5/GHSA-3v7c-xw2c-76j5.json b/advisories/unreviewed/2024/08/GHSA-3v7c-xw2c-76j5/GHSA-3v7c-xw2c-76j5.json index 42c74d9c42d..0db272905a1 100644 --- a/advisories/unreviewed/2024/08/GHSA-3v7c-xw2c-76j5/GHSA-3v7c-xw2c-76j5.json +++ b/advisories/unreviewed/2024/08/GHSA-3v7c-xw2c-76j5/GHSA-3v7c-xw2c-76j5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3v7c-xw2c-76j5", - "modified": "2024-08-05T06:30:36Z", + "modified": "2024-08-30T18:30:37Z", "published": "2024-08-05T06:30:36Z", "aliases": [ "CVE-2024-39838" ], "details": "ZWX-2000CSW2-HN firmware versions prior to Ver.0.3.15 uses hard-coded credentials, which may allow a network-adjacent attacker with an administrative privilege to alter the configuration of the device.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-798" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-05T05:15:39Z" diff --git a/advisories/unreviewed/2024/08/GHSA-4r7h-hv98-vx5w/GHSA-4r7h-hv98-vx5w.json b/advisories/unreviewed/2024/08/GHSA-4r7h-hv98-vx5w/GHSA-4r7h-hv98-vx5w.json index acf9b21cfdf..07db8db4504 100644 --- a/advisories/unreviewed/2024/08/GHSA-4r7h-hv98-vx5w/GHSA-4r7h-hv98-vx5w.json +++ b/advisories/unreviewed/2024/08/GHSA-4r7h-hv98-vx5w/GHSA-4r7h-hv98-vx5w.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4r7h-hv98-vx5w", - "modified": "2024-08-05T06:30:37Z", + "modified": "2024-08-30T18:30:37Z", "published": "2024-08-05T06:30:37Z", "aliases": [ "CVE-2024-6117" ], "details": "A Unrestricted upload of file with dangerous type vulnerability in meeting management function in Hamastar MeetingHub Paperless Meetings 2021 allows remote authenticated users to perform arbitrary system commands via a crafted ASP file.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/08/GHSA-4xqj-427q-hf6q/GHSA-4xqj-427q-hf6q.json b/advisories/unreviewed/2024/08/GHSA-4xqj-427q-hf6q/GHSA-4xqj-427q-hf6q.json index ad51d77ed1f..5b6ebec4cd0 100644 --- a/advisories/unreviewed/2024/08/GHSA-4xqj-427q-hf6q/GHSA-4xqj-427q-hf6q.json +++ b/advisories/unreviewed/2024/08/GHSA-4xqj-427q-hf6q/GHSA-4xqj-427q-hf6q.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-787", "CWE-825" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/08/GHSA-5827-p7qc-6vf6/GHSA-5827-p7qc-6vf6.json b/advisories/unreviewed/2024/08/GHSA-5827-p7qc-6vf6/GHSA-5827-p7qc-6vf6.json index 38845c534c3..7c8007a7aca 100644 --- a/advisories/unreviewed/2024/08/GHSA-5827-p7qc-6vf6/GHSA-5827-p7qc-6vf6.json +++ b/advisories/unreviewed/2024/08/GHSA-5827-p7qc-6vf6/GHSA-5827-p7qc-6vf6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5827-p7qc-6vf6", - "modified": "2024-08-29T21:31:03Z", + "modified": "2024-08-30T18:30:39Z", "published": "2024-08-29T21:31:03Z", "aliases": [ "CVE-2024-41364" ], "details": "RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\\trackEdit.php", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-29T20:15:09Z" diff --git a/advisories/unreviewed/2024/08/GHSA-5c96-24qg-f876/GHSA-5c96-24qg-f876.json b/advisories/unreviewed/2024/08/GHSA-5c96-24qg-f876/GHSA-5c96-24qg-f876.json index d5f6ca7053e..f2ceaf672f1 100644 --- a/advisories/unreviewed/2024/08/GHSA-5c96-24qg-f876/GHSA-5c96-24qg-f876.json +++ b/advisories/unreviewed/2024/08/GHSA-5c96-24qg-f876/GHSA-5c96-24qg-f876.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5c96-24qg-f876", - "modified": "2024-08-27T15:32:43Z", + "modified": "2024-08-30T18:30:37Z", "published": "2024-08-23T15:30:34Z", "aliases": [ "CVE-2024-38869" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38869" }, + { + "type": "WEB", + "url": "https://www.manageengine.com/products/desktop-central/security-updates-config-access.html" + }, { "type": "WEB", "url": "https://www.manageengine.com/products/service-desk/CVE-2024-41150.html" @@ -28,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-79" + "CWE-79", + "CWE-863" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-5hj8-xgx5-p37f/GHSA-5hj8-xgx5-p37f.json b/advisories/unreviewed/2024/08/GHSA-5hj8-xgx5-p37f/GHSA-5hj8-xgx5-p37f.json index 04be4cf4be6..8a070fc85f1 100644 --- a/advisories/unreviewed/2024/08/GHSA-5hj8-xgx5-p37f/GHSA-5hj8-xgx5-p37f.json +++ b/advisories/unreviewed/2024/08/GHSA-5hj8-xgx5-p37f/GHSA-5hj8-xgx5-p37f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5hj8-xgx5-p37f", - "modified": "2024-08-05T12:31:15Z", + "modified": "2024-08-30T18:30:37Z", "published": "2024-08-05T12:31:15Z", "aliases": [ "CVE-2024-36448" ], "details": "** UNSUPPORTED WHEN ASSIGNED ** Server-Side Request Forgery (SSRF) vulnerability in Apache IoTDB Workbench.\n\nThis issue affects Apache IoTDB Workbench: from 0.13.0.\n\nAs this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.\n\nNOTE: This vulnerability only affects products that are no longer supported by the maintainer.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-918" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-05T10:15:32Z" diff --git a/advisories/unreviewed/2024/08/GHSA-5q6v-fp9h-6rjg/GHSA-5q6v-fp9h-6rjg.json b/advisories/unreviewed/2024/08/GHSA-5q6v-fp9h-6rjg/GHSA-5q6v-fp9h-6rjg.json index 3749bfa3e6b..66ddd7817c3 100644 --- a/advisories/unreviewed/2024/08/GHSA-5q6v-fp9h-6rjg/GHSA-5q6v-fp9h-6rjg.json +++ b/advisories/unreviewed/2024/08/GHSA-5q6v-fp9h-6rjg/GHSA-5q6v-fp9h-6rjg.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-6hmg-mqf6-m38g/GHSA-6hmg-mqf6-m38g.json b/advisories/unreviewed/2024/08/GHSA-6hmg-mqf6-m38g/GHSA-6hmg-mqf6-m38g.json index d1e0118d40f..cf429437853 100644 --- a/advisories/unreviewed/2024/08/GHSA-6hmg-mqf6-m38g/GHSA-6hmg-mqf6-m38g.json +++ b/advisories/unreviewed/2024/08/GHSA-6hmg-mqf6-m38g/GHSA-6hmg-mqf6-m38g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6hmg-mqf6-m38g", - "modified": "2024-08-29T21:31:03Z", + "modified": "2024-08-30T18:30:39Z", "published": "2024-08-29T21:31:03Z", "aliases": [ "CVE-2024-41361" ], "details": "RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\\manageFilesFolders.php", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-29T20:15:08Z" diff --git a/advisories/unreviewed/2024/08/GHSA-76vg-grjj-w595/GHSA-76vg-grjj-w595.json b/advisories/unreviewed/2024/08/GHSA-76vg-grjj-w595/GHSA-76vg-grjj-w595.json index 739f89ac425..40655b3ff82 100644 --- a/advisories/unreviewed/2024/08/GHSA-76vg-grjj-w595/GHSA-76vg-grjj-w595.json +++ b/advisories/unreviewed/2024/08/GHSA-76vg-grjj-w595/GHSA-76vg-grjj-w595.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-83h2-mm3x-cpw4/GHSA-83h2-mm3x-cpw4.json b/advisories/unreviewed/2024/08/GHSA-83h2-mm3x-cpw4/GHSA-83h2-mm3x-cpw4.json index ec5688df8b5..d2e27037f6a 100644 --- a/advisories/unreviewed/2024/08/GHSA-83h2-mm3x-cpw4/GHSA-83h2-mm3x-cpw4.json +++ b/advisories/unreviewed/2024/08/GHSA-83h2-mm3x-cpw4/GHSA-83h2-mm3x-cpw4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-83h2-mm3x-cpw4", - "modified": "2024-08-29T21:31:04Z", + "modified": "2024-08-30T18:30:40Z", "published": "2024-08-29T21:31:04Z", "aliases": [ "CVE-2024-41371" ], "details": "Organizr v1.90 is vulnerable to Cross Site Scripting (XSS) via api.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-29T20:15:09Z" diff --git a/advisories/unreviewed/2024/08/GHSA-87xp-v6jc-jprf/GHSA-87xp-v6jc-jprf.json b/advisories/unreviewed/2024/08/GHSA-87xp-v6jc-jprf/GHSA-87xp-v6jc-jprf.json index 603291dafc1..840e4fd3e75 100644 --- a/advisories/unreviewed/2024/08/GHSA-87xp-v6jc-jprf/GHSA-87xp-v6jc-jprf.json +++ b/advisories/unreviewed/2024/08/GHSA-87xp-v6jc-jprf/GHSA-87xp-v6jc-jprf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-87xp-v6jc-jprf", - "modified": "2024-08-29T18:31:35Z", + "modified": "2024-08-30T18:30:39Z", "published": "2024-08-29T18:31:35Z", "aliases": [ "CVE-2024-43953" diff --git a/advisories/unreviewed/2024/08/GHSA-8q5q-cjjx-r967/GHSA-8q5q-cjjx-r967.json b/advisories/unreviewed/2024/08/GHSA-8q5q-cjjx-r967/GHSA-8q5q-cjjx-r967.json new file mode 100644 index 00000000000..7e77ff42607 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-8q5q-cjjx-r967/GHSA-8q5q-cjjx-r967.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8q5q-cjjx-r967", + "modified": "2024-08-30T18:30:40Z", + "published": "2024-08-30T18:30:40Z", + "aliases": [ + "CVE-2024-8344" + ], + "details": "A vulnerability has been found in Campcodes Supplier Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/edit_area.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8344" + }, + { + "type": "WEB", + "url": "https://github.com/yooo0oo0/cve_report/blob/main/supplier-management-system/SQLi-2.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.276223" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.276223" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.400185" + }, + { + "type": "WEB", + "url": "https://www.campcodes.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-30T17:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-8v2g-m5cr-4r79/GHSA-8v2g-m5cr-4r79.json b/advisories/unreviewed/2024/08/GHSA-8v2g-m5cr-4r79/GHSA-8v2g-m5cr-4r79.json index 64495bbee4d..ae2f09e24f2 100644 --- a/advisories/unreviewed/2024/08/GHSA-8v2g-m5cr-4r79/GHSA-8v2g-m5cr-4r79.json +++ b/advisories/unreviewed/2024/08/GHSA-8v2g-m5cr-4r79/GHSA-8v2g-m5cr-4r79.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8v2g-m5cr-4r79", - "modified": "2024-08-29T21:31:03Z", + "modified": "2024-08-30T18:30:39Z", "published": "2024-08-29T21:31:03Z", "aliases": [ "CVE-2024-41366" ], "details": "RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\\userScripts.php", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-29T20:15:09Z" diff --git a/advisories/unreviewed/2024/08/GHSA-94ch-6cfh-xxgc/GHSA-94ch-6cfh-xxgc.json b/advisories/unreviewed/2024/08/GHSA-94ch-6cfh-xxgc/GHSA-94ch-6cfh-xxgc.json new file mode 100644 index 00000000000..0ed7e3dc73e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-94ch-6cfh-xxgc/GHSA-94ch-6cfh-xxgc.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-94ch-6cfh-xxgc", + "modified": "2024-08-30T18:30:40Z", + "published": "2024-08-30T18:30:40Z", + "aliases": [ + "CVE-2024-8235" + ], + "details": "A flaw was found in libvirt. A refactor of the code fetching the list of interfaces for multiple APIs introduced a corner case on platforms where allocating 0 bytes of memory results in a NULL pointer. This corner case would lead to a NULL-pointer dereference and subsequent crash of virtinterfaced. This issue could allow clients connecting to the read-only socket to crash the virtinterfaced daemon.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8235" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-8235" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2308680" + }, + { + "type": "WEB", + "url": "https://lists.libvirt.org/archives/list/devel@lists.libvirt.org/thread/X6WOVCL6QF3FQRFIIXL736RFZVSUWLWJ" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-30T17:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-cxc7-qrmh-3wx5/GHSA-cxc7-qrmh-3wx5.json b/advisories/unreviewed/2024/08/GHSA-cxc7-qrmh-3wx5/GHSA-cxc7-qrmh-3wx5.json index b478893f7be..2799641cbae 100644 --- a/advisories/unreviewed/2024/08/GHSA-cxc7-qrmh-3wx5/GHSA-cxc7-qrmh-3wx5.json +++ b/advisories/unreviewed/2024/08/GHSA-cxc7-qrmh-3wx5/GHSA-cxc7-qrmh-3wx5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cxc7-qrmh-3wx5", - "modified": "2024-08-22T21:31:29Z", + "modified": "2024-08-30T18:30:37Z", "published": "2024-08-05T12:31:15Z", "aliases": [ "CVE-2024-40096" ], "details": "The com.cascadialabs.who (aka Who - Caller ID, Spam Block) application 15.0 for Android places sensitive information in the system log.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-532" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-05T10:15:33Z" diff --git a/advisories/unreviewed/2024/08/GHSA-fcrv-q4xw-6crp/GHSA-fcrv-q4xw-6crp.json b/advisories/unreviewed/2024/08/GHSA-fcrv-q4xw-6crp/GHSA-fcrv-q4xw-6crp.json new file mode 100644 index 00000000000..1c0ba69996f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-fcrv-q4xw-6crp/GHSA-fcrv-q4xw-6crp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fcrv-q4xw-6crp", + "modified": "2024-08-30T18:30:40Z", + "published": "2024-08-30T18:30:40Z", + "aliases": [ + "CVE-2024-38868" + ], + "details": "Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability while isolating the devices.This issue affects Endpoint Central: before 11.3.2406.08 and before 11.3.2400.15", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38868" + }, + { + "type": "WEB", + "url": "https://www.manageengine.com/products/desktop-central/security-updates-ngav.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-30T18:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-g5wr-xh7j-3w9v/GHSA-g5wr-xh7j-3w9v.json b/advisories/unreviewed/2024/08/GHSA-g5wr-xh7j-3w9v/GHSA-g5wr-xh7j-3w9v.json index c1ef296ca6c..f5d386e4ab6 100644 --- a/advisories/unreviewed/2024/08/GHSA-g5wr-xh7j-3w9v/GHSA-g5wr-xh7j-3w9v.json +++ b/advisories/unreviewed/2024/08/GHSA-g5wr-xh7j-3w9v/GHSA-g5wr-xh7j-3w9v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g5wr-xh7j-3w9v", - "modified": "2024-08-02T18:31:10Z", + "modified": "2024-08-30T18:30:37Z", "published": "2024-08-02T18:31:10Z", "aliases": [ "CVE-2024-41519" ], "details": "Feripro <= v2.2.3 is vulnerable to Cross Site Scripting (XSS) via \"/admin/programm//zuordnung/veranstaltungen/\" through the \"school\" input field.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-02T17:16:39Z" diff --git a/advisories/unreviewed/2024/08/GHSA-j665-mqhh-jvh2/GHSA-j665-mqhh-jvh2.json b/advisories/unreviewed/2024/08/GHSA-j665-mqhh-jvh2/GHSA-j665-mqhh-jvh2.json new file mode 100644 index 00000000000..982c1ffc62c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-j665-mqhh-jvh2/GHSA-j665-mqhh-jvh2.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j665-mqhh-jvh2", + "modified": "2024-08-30T18:30:40Z", + "published": "2024-08-30T18:30:40Z", + "aliases": [ + "CVE-2024-8342" + ], + "details": "A vulnerability, which was classified as critical, has been found in SourceCodester Petshop Management System 1.0. This issue affects some unknown processing of the file /controllers/add_client.php. The manipulation of the argument image_profile leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8342" + }, + { + "type": "WEB", + "url": "https://github.com/enjoyworld/webray.com.cn/blob/main/cves/Petshop_Management_System/Petshop_Management_System%20add_client.php%20any%20file%20upload.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.276221" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.276221" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.399662" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-30T16:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-jfp9-mpfm-8qc7/GHSA-jfp9-mpfm-8qc7.json b/advisories/unreviewed/2024/08/GHSA-jfp9-mpfm-8qc7/GHSA-jfp9-mpfm-8qc7.json index e7b19db0a3c..dd40fe2ebd8 100644 --- a/advisories/unreviewed/2024/08/GHSA-jfp9-mpfm-8qc7/GHSA-jfp9-mpfm-8qc7.json +++ b/advisories/unreviewed/2024/08/GHSA-jfp9-mpfm-8qc7/GHSA-jfp9-mpfm-8qc7.json @@ -40,6 +40,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-862", "CWE-939" ], "severity": "LOW", diff --git a/advisories/unreviewed/2024/08/GHSA-mh7j-x4vr-3mg3/GHSA-mh7j-x4vr-3mg3.json b/advisories/unreviewed/2024/08/GHSA-mh7j-x4vr-3mg3/GHSA-mh7j-x4vr-3mg3.json new file mode 100644 index 00000000000..89cdda7ddc4 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-mh7j-x4vr-3mg3/GHSA-mh7j-x4vr-3mg3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mh7j-x4vr-3mg3", + "modified": "2024-08-30T18:30:40Z", + "published": "2024-08-30T18:30:40Z", + "aliases": [ + "CVE-2024-44918" + ], + "details": "A cross-site scripting (XSS) vulnerability in the component admin_datarelate.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44918" + }, + { + "type": "WEB", + "url": "https://github.com/nn0nkey/nn0nkey/blob/main/CVE-2024-44918.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-30T17:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-mm9r-w8fm-6592/GHSA-mm9r-w8fm-6592.json b/advisories/unreviewed/2024/08/GHSA-mm9r-w8fm-6592/GHSA-mm9r-w8fm-6592.json new file mode 100644 index 00000000000..8cb2fb463a2 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-mm9r-w8fm-6592/GHSA-mm9r-w8fm-6592.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mm9r-w8fm-6592", + "modified": "2024-08-30T18:30:40Z", + "published": "2024-08-30T18:30:40Z", + "aliases": [ + "CVE-2024-44916" + ], + "details": "Vulnerability in admin_ip.php in Seacms v13.1, when action=set, allows attackers to control IP parameters that are written to the data/admin/ip.php file and could result in arbitrary command execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44916" + }, + { + "type": "WEB", + "url": "https://github.com/nn0nkey/nn0nkey/blob/main/CVE-2024-44916.md" + }, + { + "type": "WEB", + "url": "https://github.com/seacms-net" + }, + { + "type": "WEB", + "url": "http://seacms.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-30T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-p64m-r26f-95x6/GHSA-p64m-r26f-95x6.json b/advisories/unreviewed/2024/08/GHSA-p64m-r26f-95x6/GHSA-p64m-r26f-95x6.json index 82ece171057..b7e1b481b41 100644 --- a/advisories/unreviewed/2024/08/GHSA-p64m-r26f-95x6/GHSA-p64m-r26f-95x6.json +++ b/advisories/unreviewed/2024/08/GHSA-p64m-r26f-95x6/GHSA-p64m-r26f-95x6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p64m-r26f-95x6", - "modified": "2024-08-02T18:31:10Z", + "modified": "2024-08-30T18:30:37Z", "published": "2024-08-02T18:31:10Z", "aliases": [ "CVE-2024-41517" ], "details": "An Incorrect Access Control vulnerability in \"/admin/benutzer/institution/rechteverwaltung/uebersicht\" in Feripro <= v2.2.3 allows remote attackers to get a list of all users and their corresponding privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-02T17:16:38Z" diff --git a/advisories/unreviewed/2024/08/GHSA-px2q-62h5-wq69/GHSA-px2q-62h5-wq69.json b/advisories/unreviewed/2024/08/GHSA-px2q-62h5-wq69/GHSA-px2q-62h5-wq69.json new file mode 100644 index 00000000000..70c9f57a5ea --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-px2q-62h5-wq69/GHSA-px2q-62h5-wq69.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-px2q-62h5-wq69", + "modified": "2024-08-30T18:30:40Z", + "published": "2024-08-30T18:30:40Z", + "aliases": [ + "CVE-2024-8064" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8064" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-30T16:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-q2fm-rxrg-hgpw/GHSA-q2fm-rxrg-hgpw.json b/advisories/unreviewed/2024/08/GHSA-q2fm-rxrg-hgpw/GHSA-q2fm-rxrg-hgpw.json new file mode 100644 index 00000000000..e77ab802abe --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-q2fm-rxrg-hgpw/GHSA-q2fm-rxrg-hgpw.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q2fm-rxrg-hgpw", + "modified": "2024-08-30T18:30:40Z", + "published": "2024-08-30T18:30:40Z", + "aliases": [ + "CVE-2024-8345" + ], + "details": "A vulnerability was found in SourceCodester Music Gallery Site 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /classes/Users.php?f=delete. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8345" + }, + { + "type": "WEB", + "url": "https://github.com/GAO-UNO/cve/blob/main/sql3.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.276224" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.276224" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.400192" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-30T17:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-q2mq-qmgr-3266/GHSA-q2mq-qmgr-3266.json b/advisories/unreviewed/2024/08/GHSA-q2mq-qmgr-3266/GHSA-q2mq-qmgr-3266.json index bd77b46d594..925a2c7ef6f 100644 --- a/advisories/unreviewed/2024/08/GHSA-q2mq-qmgr-3266/GHSA-q2mq-qmgr-3266.json +++ b/advisories/unreviewed/2024/08/GHSA-q2mq-qmgr-3266/GHSA-q2mq-qmgr-3266.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q2mq-qmgr-3266", - "modified": "2024-08-05T06:30:37Z", + "modified": "2024-08-30T18:30:37Z", "published": "2024-08-05T06:30:37Z", "aliases": [ "CVE-2024-41720" ], "details": "Incorrect permission assignment for critical resource issue exists in ZWX-2000CSW2-HN firmware versions prior to Ver.0.3.15, which may allow a network-adjacent authenticated attacker to alter the configuration of the device.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-732" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-05T05:15:39Z" diff --git a/advisories/unreviewed/2024/08/GHSA-q777-ff33-4xgr/GHSA-q777-ff33-4xgr.json b/advisories/unreviewed/2024/08/GHSA-q777-ff33-4xgr/GHSA-q777-ff33-4xgr.json index 8183f71bbe8..4bd287d9bb4 100644 --- a/advisories/unreviewed/2024/08/GHSA-q777-ff33-4xgr/GHSA-q777-ff33-4xgr.json +++ b/advisories/unreviewed/2024/08/GHSA-q777-ff33-4xgr/GHSA-q777-ff33-4xgr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q777-ff33-4xgr", - "modified": "2024-08-29T21:31:03Z", + "modified": "2024-08-30T18:30:39Z", "published": "2024-08-29T18:31:35Z", "aliases": [ "CVE-2024-44919" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44919" }, + { + "type": "WEB", + "url": "https://github.com/nn0nkey/nn0nkey/blob/main/CVE-2024-44919.md" + }, { "type": "WEB", "url": "https://github.com/nn0nkey/nn0nkey/blob/main/second.md" diff --git a/advisories/unreviewed/2024/08/GHSA-v323-q9x3-gg6h/GHSA-v323-q9x3-gg6h.json b/advisories/unreviewed/2024/08/GHSA-v323-q9x3-gg6h/GHSA-v323-q9x3-gg6h.json new file mode 100644 index 00000000000..f81a4f55511 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-v323-q9x3-gg6h/GHSA-v323-q9x3-gg6h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v323-q9x3-gg6h", + "modified": "2024-08-30T18:30:40Z", + "published": "2024-08-30T18:30:40Z", + "aliases": [ + "CVE-2024-6204" + ], + "details": "Zohocorp ManageEngine Exchange Reporter Plus versions before 5715 are vulnerable to SQL Injection in the reports module.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6204" + }, + { + "type": "WEB", + "url": "https://www.manageengine.com/products/exchange-reports/advisory/CVE-2024-6204.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-30T17:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-v587-qwh9-6xx3/GHSA-v587-qwh9-6xx3.json b/advisories/unreviewed/2024/08/GHSA-v587-qwh9-6xx3/GHSA-v587-qwh9-6xx3.json index 2421b47c379..898d657db2e 100644 --- a/advisories/unreviewed/2024/08/GHSA-v587-qwh9-6xx3/GHSA-v587-qwh9-6xx3.json +++ b/advisories/unreviewed/2024/08/GHSA-v587-qwh9-6xx3/GHSA-v587-qwh9-6xx3.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-89" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2024/08/GHSA-v65h-92x8-q66f/GHSA-v65h-92x8-q66f.json b/advisories/unreviewed/2024/08/GHSA-v65h-92x8-q66f/GHSA-v65h-92x8-q66f.json new file mode 100644 index 00000000000..6e98f88acd4 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-v65h-92x8-q66f/GHSA-v65h-92x8-q66f.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v65h-92x8-q66f", + "modified": "2024-08-30T18:30:40Z", + "published": "2024-08-30T18:30:40Z", + "aliases": [ + "CVE-2024-8343" + ], + "details": "A vulnerability, which was classified as critical, was found in SourceCodester Sentiment Based Movie Rating System 1.0. Affected is an unknown function of the file /classes/Users.php?f=save_client of the component User Registration Handler. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8343" + }, + { + "type": "WEB", + "url": "https://github.com/gurudattch/CVEs/blob/main/Sourcecodester-SQLi-Sentiment-Based-Moive-Rating.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.276222" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.276222" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.399711" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-30T16:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-vf33-j375-2hrc/GHSA-vf33-j375-2hrc.json b/advisories/unreviewed/2024/08/GHSA-vf33-j375-2hrc/GHSA-vf33-j375-2hrc.json new file mode 100644 index 00000000000..7ea95cb643c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-vf33-j375-2hrc/GHSA-vf33-j375-2hrc.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vf33-j375-2hrc", + "modified": "2024-08-30T18:30:40Z", + "published": "2024-08-30T18:30:40Z", + "aliases": [ + "CVE-2024-7051" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7051" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-30T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-w4qw-whg8-4fjc/GHSA-w4qw-whg8-4fjc.json b/advisories/unreviewed/2024/08/GHSA-w4qw-whg8-4fjc/GHSA-w4qw-whg8-4fjc.json index e0998e0d4ba..183d2995461 100644 --- a/advisories/unreviewed/2024/08/GHSA-w4qw-whg8-4fjc/GHSA-w4qw-whg8-4fjc.json +++ b/advisories/unreviewed/2024/08/GHSA-w4qw-whg8-4fjc/GHSA-w4qw-whg8-4fjc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w4qw-whg8-4fjc", - "modified": "2024-08-30T09:31:17Z", + "modified": "2024-08-30T18:30:40Z", "published": "2024-08-30T09:31:17Z", "aliases": [ "CVE-2024-39300" ], "details": "Missing authentication vulnerability exists in Telnet function of WAB-I1750-PS v1.5.10 and earlier. When Telnet function of the product is enabled, a remote attacker may login to the product without authentication and alter the product's settings.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-306" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-30T07:15:11Z" diff --git a/advisories/unreviewed/2024/08/GHSA-w7cc-q8x4-3xx9/GHSA-w7cc-q8x4-3xx9.json b/advisories/unreviewed/2024/08/GHSA-w7cc-q8x4-3xx9/GHSA-w7cc-q8x4-3xx9.json index e834dfa73b0..37149b88edd 100644 --- a/advisories/unreviewed/2024/08/GHSA-w7cc-q8x4-3xx9/GHSA-w7cc-q8x4-3xx9.json +++ b/advisories/unreviewed/2024/08/GHSA-w7cc-q8x4-3xx9/GHSA-w7cc-q8x4-3xx9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w7cc-q8x4-3xx9", - "modified": "2024-08-29T21:31:04Z", + "modified": "2024-08-30T18:30:40Z", "published": "2024-08-29T21:31:04Z", "aliases": [ "CVE-2024-41369" ], "details": "RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\\inc.setWifi.php", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-29T20:15:09Z" diff --git a/advisories/unreviewed/2024/08/GHSA-w9pm-7cxw-vw6j/GHSA-w9pm-7cxw-vw6j.json b/advisories/unreviewed/2024/08/GHSA-w9pm-7cxw-vw6j/GHSA-w9pm-7cxw-vw6j.json index 8c0d0e5d491..72d961c1b9a 100644 --- a/advisories/unreviewed/2024/08/GHSA-w9pm-7cxw-vw6j/GHSA-w9pm-7cxw-vw6j.json +++ b/advisories/unreviewed/2024/08/GHSA-w9pm-7cxw-vw6j/GHSA-w9pm-7cxw-vw6j.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-88" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2024/08/GHSA-wm63-qmcq-5w39/GHSA-wm63-qmcq-5w39.json b/advisories/unreviewed/2024/08/GHSA-wm63-qmcq-5w39/GHSA-wm63-qmcq-5w39.json index 77c38a278b1..2bac70d9425 100644 --- a/advisories/unreviewed/2024/08/GHSA-wm63-qmcq-5w39/GHSA-wm63-qmcq-5w39.json +++ b/advisories/unreviewed/2024/08/GHSA-wm63-qmcq-5w39/GHSA-wm63-qmcq-5w39.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-wv98-rm53-823r/GHSA-wv98-rm53-823r.json b/advisories/unreviewed/2024/08/GHSA-wv98-rm53-823r/GHSA-wv98-rm53-823r.json index 6cf86bd5c5a..1af020c3d62 100644 --- a/advisories/unreviewed/2024/08/GHSA-wv98-rm53-823r/GHSA-wv98-rm53-823r.json +++ b/advisories/unreviewed/2024/08/GHSA-wv98-rm53-823r/GHSA-wv98-rm53-823r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wv98-rm53-823r", - "modified": "2024-08-29T21:31:03Z", + "modified": "2024-08-30T18:30:39Z", "published": "2024-08-29T21:31:03Z", "aliases": [ "CVE-2024-41367" ], "details": "RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\\api\\playlist\\appendFileToPlaylist.php", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-29T20:15:09Z" diff --git a/advisories/unreviewed/2024/08/GHSA-x36v-pwx4-c656/GHSA-x36v-pwx4-c656.json b/advisories/unreviewed/2024/08/GHSA-x36v-pwx4-c656/GHSA-x36v-pwx4-c656.json new file mode 100644 index 00000000000..dd76d7a5491 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-x36v-pwx4-c656/GHSA-x36v-pwx4-c656.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x36v-pwx4-c656", + "modified": "2024-08-30T18:30:40Z", + "published": "2024-08-30T18:30:40Z", + "aliases": [ + "CVE-2024-7712" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7712" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-30T16:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-x37r-vj3m-8vc5/GHSA-x37r-vj3m-8vc5.json b/advisories/unreviewed/2024/08/GHSA-x37r-vj3m-8vc5/GHSA-x37r-vj3m-8vc5.json index 5cb0021ec3e..809683e42fb 100644 --- a/advisories/unreviewed/2024/08/GHSA-x37r-vj3m-8vc5/GHSA-x37r-vj3m-8vc5.json +++ b/advisories/unreviewed/2024/08/GHSA-x37r-vj3m-8vc5/GHSA-x37r-vj3m-8vc5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x37r-vj3m-8vc5", - "modified": "2024-08-29T21:31:04Z", + "modified": "2024-08-30T18:30:40Z", "published": "2024-08-29T21:31:04Z", "aliases": [ "CVE-2024-41368" ], "details": "RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\\inc.setWlanIpMail.php", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-29T20:15:09Z" diff --git a/advisories/unreviewed/2024/08/GHSA-x6xm-9hw6-q7gc/GHSA-x6xm-9hw6-q7gc.json b/advisories/unreviewed/2024/08/GHSA-x6xm-9hw6-q7gc/GHSA-x6xm-9hw6-q7gc.json index 933d1b0d317..69e889686e7 100644 --- a/advisories/unreviewed/2024/08/GHSA-x6xm-9hw6-q7gc/GHSA-x6xm-9hw6-q7gc.json +++ b/advisories/unreviewed/2024/08/GHSA-x6xm-9hw6-q7gc/GHSA-x6xm-9hw6-q7gc.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x6xm-9hw6-q7gc", - "modified": "2024-08-29T12:31:05Z", + "modified": "2024-08-30T18:30:38Z", "published": "2024-08-29T12:31:05Z", "aliases": [ "CVE-2024-4428" ], "details": "Improper Privilege Management vulnerability in Menulux Information Technologies Managment Portal allows Collect Data as Provided by Users.This issue affects Managment Portal: through 21.05.2024.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/08/GHSA-xpwg-9vrv-hq2j/GHSA-xpwg-9vrv-hq2j.json b/advisories/unreviewed/2024/08/GHSA-xpwg-9vrv-hq2j/GHSA-xpwg-9vrv-hq2j.json index f79dfb6f7cc..2afca9e7395 100644 --- a/advisories/unreviewed/2024/08/GHSA-xpwg-9vrv-hq2j/GHSA-xpwg-9vrv-hq2j.json +++ b/advisories/unreviewed/2024/08/GHSA-xpwg-9vrv-hq2j/GHSA-xpwg-9vrv-hq2j.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xpwg-9vrv-hq2j", - "modified": "2024-08-05T06:30:37Z", + "modified": "2024-08-30T18:30:37Z", "published": "2024-08-05T06:30:37Z", "aliases": [ "CVE-2024-6118" ], "details": "A Plaintext Storage of a Password vulnerability in ebooknote function in Hamastar MeetingHub Paperless Meetings 2021 allows remote attackers to obtain the other users’ credentials and gain access to the product via an XML file.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" @@ -28,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-256" + "CWE-256", + "CWE-522" ], "severity": "CRITICAL", "github_reviewed": false,