From 35121c46483e9a6af7212bb1b132c783da1d66f2 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 23 Aug 2024 18:34:27 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-833m-43m7-9vxh.json | 11 +++-- .../GHSA-2mm4-vwp4-8j4f.json | 11 +++-- .../GHSA-2pvh-rqjq-h9px.json | 11 +++-- .../GHSA-6fj5-m574-p4w9.json | 9 ++-- .../GHSA-72vv-7jqj-qv3q.json | 6 ++- .../GHSA-8xgj-w267-6p92.json | 11 +++-- .../GHSA-frpv-8jj9-m3cv.json | 11 +++-- .../GHSA-g5jv-2gj9-v424.json | 6 ++- .../GHSA-g8hw-gxg5-v62g.json | 11 +++-- .../GHSA-h339-65jr-4wwh.json | 6 ++- .../GHSA-mq4v-mwpp-gcfh.json | 6 ++- .../GHSA-p7rm-v5xq-5pr9.json | 6 ++- .../GHSA-prhw-q7f9-j4w8.json | 6 ++- .../GHSA-rgjh-vj92-73c9.json | 6 ++- .../GHSA-6mp9-hrx8-6ffg.json | 9 ++-- .../GHSA-8482-wc7m-w3q5.json | 11 +++-- .../GHSA-cg5c-5558-3qmm.json | 9 ++-- .../GHSA-235v-2948-prr3.json | 38 +++++++++++++++ .../GHSA-36gx-rqg5-2fh6.json | 42 +++++++++++++++++ .../GHSA-3rj4-hw95-8jqg.json | 38 +++++++++++++++ .../GHSA-3xww-gg44-m2qc.json | 35 ++++++++++++++ .../GHSA-42mv-3h37-wfh9.json | 46 +++++++++++++++++++ .../GHSA-44mp-qrwc-xm4x.json | 35 ++++++++++++++ .../GHSA-4g6m-wpfm-pfxv.json | 11 +++-- .../GHSA-4w56-w59g-jg9w.json | 38 +++++++++++++++ .../GHSA-4wrj-qhhf-3c55.json | 2 +- .../GHSA-4ww8-fprq-cq34.json | 3 +- .../GHSA-5236-grq3-77jq.json | 38 +++++++++++++++ .../GHSA-58cw-gjp7-8mm7.json | 39 ++++++++++++++++ .../GHSA-5pvf-fc2q-jq4q.json | 11 +++-- .../GHSA-64gw-gxfq-f34c.json | 1 + .../GHSA-65h6-4ccg-v5j8.json | 42 +++++++++++++++++ .../GHSA-662c-cj8q-qc4g.json | 1 + .../GHSA-6fcq-8rv2-rc2j.json | 39 ++++++++++++++++ .../GHSA-6v83-ppjw-wp84.json | 35 ++++++++++++++ .../GHSA-723q-4x66-vrf2.json | 39 ++++++++++++++++ .../GHSA-7c8c-x5xp-8wgj.json | 3 +- .../GHSA-7v24-gjqv-fwg7.json | 4 +- .../GHSA-8chj-vfwh-89pj.json | 9 ++-- .../GHSA-982x-jhrm-q8mj.json | 2 +- .../GHSA-9j5g-j2hj-xfpc.json | 1 + .../GHSA-9x8h-2288-5g98.json | 1 + .../GHSA-c23f-2mjw-h676.json | 38 +++++++++++++++ .../GHSA-c6vp-jjgv-38wj.json | 2 +- .../GHSA-c866-phfm-vxw2.json | 42 +++++++++++++++++ .../GHSA-c96v-5mr3-4xxf.json | 38 +++++++++++++++ .../GHSA-ccvv-v4jq-v9x2.json | 38 +++++++++++++++ .../GHSA-cxrj-5q7c-cmrm.json | 38 +++++++++++++++ .../GHSA-f56c-x89x-xgxh.json | 9 +++- .../GHSA-f8x5-fv5x-fcq5.json | 11 +++-- .../GHSA-fcf2-47c2-px5h.json | 11 +++-- .../GHSA-ffmr-5xqw-mpjg.json | 38 +++++++++++++++ .../GHSA-fg8g-qmfg-pf88.json | 38 +++++++++++++++ .../GHSA-g3jm-x33w-9q5w.json | 35 ++++++++++++++ .../GHSA-gp95-49cg-49jc.json | 11 +++-- .../GHSA-h363-vrwv-gpwf.json | 38 +++++++++++++++ .../GHSA-hch6-3cq4-hjhm.json | 9 +++- .../GHSA-hrf9-rm95-fpf3.json | 2 +- .../GHSA-j3cx-fj78-gw65.json | 11 +++-- .../GHSA-j7cx-qx73-9wxc.json | 5 +- .../GHSA-j7f9-7qqh-2rxf.json | 9 +++- .../GHSA-j99w-m756-f646.json | 38 +++++++++++++++ .../GHSA-jj85-4qm9-xvwg.json | 39 ++++++++++++++++ .../GHSA-m3fh-qqv6-hgxx.json | 2 +- .../GHSA-m59m-755q-5h2m.json | 11 +++-- .../GHSA-m99q-r6r6-wxx3.json | 1 + .../GHSA-p4hm-hcqj-m7g5.json | 38 +++++++++++++++ .../GHSA-pr8m-g3mq-j9w6.json | 38 +++++++++++++++ .../GHSA-q8cw-c873-9xh2.json | 38 +++++++++++++++ .../GHSA-q98g-hxg3-268c.json | 6 ++- .../GHSA-qgvg-8hq5-mx9m.json | 38 +++++++++++++++ .../GHSA-r6rr-3664-gq2w.json | 39 ++++++++++++++++ .../GHSA-r7m6-x679-p3mh.json | 38 +++++++++++++++ .../GHSA-r936-6588-v9v4.json | 39 ++++++++++++++++ .../GHSA-v6x2-q2r8-qg76.json | 11 +++-- .../GHSA-vcg9-h624-c2c9.json | 38 +++++++++++++++ .../GHSA-vcw3-hwj8-8j82.json | 39 ++++++++++++++++ .../GHSA-vq36-rf43-jmh7.json | 39 ++++++++++++++++ .../GHSA-w57x-f5pm-84r5.json | 3 +- .../GHSA-w96m-rw5m-pf44.json | 6 ++- .../GHSA-wpjv-3phj-f64x.json | 11 +++-- .../GHSA-wqgx-27v7-cr9h.json | 39 ++++++++++++++++ .../GHSA-wwmm-864r-f54x.json | 6 ++- 83 files changed, 1575 insertions(+), 104 deletions(-) create mode 100644 advisories/unreviewed/2024/08/GHSA-235v-2948-prr3/GHSA-235v-2948-prr3.json create mode 100644 advisories/unreviewed/2024/08/GHSA-36gx-rqg5-2fh6/GHSA-36gx-rqg5-2fh6.json create mode 100644 advisories/unreviewed/2024/08/GHSA-3rj4-hw95-8jqg/GHSA-3rj4-hw95-8jqg.json create mode 100644 advisories/unreviewed/2024/08/GHSA-3xww-gg44-m2qc/GHSA-3xww-gg44-m2qc.json create mode 100644 advisories/unreviewed/2024/08/GHSA-42mv-3h37-wfh9/GHSA-42mv-3h37-wfh9.json create mode 100644 advisories/unreviewed/2024/08/GHSA-44mp-qrwc-xm4x/GHSA-44mp-qrwc-xm4x.json create mode 100644 advisories/unreviewed/2024/08/GHSA-4w56-w59g-jg9w/GHSA-4w56-w59g-jg9w.json create mode 100644 advisories/unreviewed/2024/08/GHSA-5236-grq3-77jq/GHSA-5236-grq3-77jq.json create mode 100644 advisories/unreviewed/2024/08/GHSA-58cw-gjp7-8mm7/GHSA-58cw-gjp7-8mm7.json create mode 100644 advisories/unreviewed/2024/08/GHSA-65h6-4ccg-v5j8/GHSA-65h6-4ccg-v5j8.json create mode 100644 advisories/unreviewed/2024/08/GHSA-6fcq-8rv2-rc2j/GHSA-6fcq-8rv2-rc2j.json create mode 100644 advisories/unreviewed/2024/08/GHSA-6v83-ppjw-wp84/GHSA-6v83-ppjw-wp84.json create mode 100644 advisories/unreviewed/2024/08/GHSA-723q-4x66-vrf2/GHSA-723q-4x66-vrf2.json create mode 100644 advisories/unreviewed/2024/08/GHSA-c23f-2mjw-h676/GHSA-c23f-2mjw-h676.json create mode 100644 advisories/unreviewed/2024/08/GHSA-c866-phfm-vxw2/GHSA-c866-phfm-vxw2.json create mode 100644 advisories/unreviewed/2024/08/GHSA-c96v-5mr3-4xxf/GHSA-c96v-5mr3-4xxf.json create mode 100644 advisories/unreviewed/2024/08/GHSA-ccvv-v4jq-v9x2/GHSA-ccvv-v4jq-v9x2.json create mode 100644 advisories/unreviewed/2024/08/GHSA-cxrj-5q7c-cmrm/GHSA-cxrj-5q7c-cmrm.json create mode 100644 advisories/unreviewed/2024/08/GHSA-ffmr-5xqw-mpjg/GHSA-ffmr-5xqw-mpjg.json create mode 100644 advisories/unreviewed/2024/08/GHSA-fg8g-qmfg-pf88/GHSA-fg8g-qmfg-pf88.json create mode 100644 advisories/unreviewed/2024/08/GHSA-g3jm-x33w-9q5w/GHSA-g3jm-x33w-9q5w.json create mode 100644 advisories/unreviewed/2024/08/GHSA-h363-vrwv-gpwf/GHSA-h363-vrwv-gpwf.json create mode 100644 advisories/unreviewed/2024/08/GHSA-j99w-m756-f646/GHSA-j99w-m756-f646.json create mode 100644 advisories/unreviewed/2024/08/GHSA-jj85-4qm9-xvwg/GHSA-jj85-4qm9-xvwg.json create mode 100644 advisories/unreviewed/2024/08/GHSA-p4hm-hcqj-m7g5/GHSA-p4hm-hcqj-m7g5.json create mode 100644 advisories/unreviewed/2024/08/GHSA-pr8m-g3mq-j9w6/GHSA-pr8m-g3mq-j9w6.json create mode 100644 advisories/unreviewed/2024/08/GHSA-q8cw-c873-9xh2/GHSA-q8cw-c873-9xh2.json create mode 100644 advisories/unreviewed/2024/08/GHSA-qgvg-8hq5-mx9m/GHSA-qgvg-8hq5-mx9m.json create mode 100644 advisories/unreviewed/2024/08/GHSA-r6rr-3664-gq2w/GHSA-r6rr-3664-gq2w.json create mode 100644 advisories/unreviewed/2024/08/GHSA-r7m6-x679-p3mh/GHSA-r7m6-x679-p3mh.json create mode 100644 advisories/unreviewed/2024/08/GHSA-r936-6588-v9v4/GHSA-r936-6588-v9v4.json create mode 100644 advisories/unreviewed/2024/08/GHSA-vcg9-h624-c2c9/GHSA-vcg9-h624-c2c9.json create mode 100644 advisories/unreviewed/2024/08/GHSA-vcw3-hwj8-8j82/GHSA-vcw3-hwj8-8j82.json create mode 100644 advisories/unreviewed/2024/08/GHSA-vq36-rf43-jmh7/GHSA-vq36-rf43-jmh7.json create mode 100644 advisories/unreviewed/2024/08/GHSA-wqgx-27v7-cr9h/GHSA-wqgx-27v7-cr9h.json diff --git a/advisories/unreviewed/2024/03/GHSA-833m-43m7-9vxh/GHSA-833m-43m7-9vxh.json b/advisories/unreviewed/2024/03/GHSA-833m-43m7-9vxh/GHSA-833m-43m7-9vxh.json index f86b85265a6..5111c8940b6 100644 --- a/advisories/unreviewed/2024/03/GHSA-833m-43m7-9vxh/GHSA-833m-43m7-9vxh.json +++ b/advisories/unreviewed/2024/03/GHSA-833m-43m7-9vxh/GHSA-833m-43m7-9vxh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-833m-43m7-9vxh", - "modified": "2024-03-02T00:31:31Z", + "modified": "2024-08-23T18:32:56Z", "published": "2024-03-02T00:31:31Z", "aliases": [ "CVE-2024-1869" ], "details": "Certain HP DesignJet print products are potentially vulnerable to information disclosure related to accessing memory out-of-bounds when using the general-purpose gateway (GGW) over port 9220.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-01T22:15:47Z" diff --git a/advisories/unreviewed/2024/05/GHSA-2mm4-vwp4-8j4f/GHSA-2mm4-vwp4-8j4f.json b/advisories/unreviewed/2024/05/GHSA-2mm4-vwp4-8j4f/GHSA-2mm4-vwp4-8j4f.json index 35857f13203..b8b84dd5cd8 100644 --- a/advisories/unreviewed/2024/05/GHSA-2mm4-vwp4-8j4f/GHSA-2mm4-vwp4-8j4f.json +++ b/advisories/unreviewed/2024/05/GHSA-2mm4-vwp4-8j4f/GHSA-2mm4-vwp4-8j4f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2mm4-vwp4-8j4f", - "modified": "2024-05-14T15:32:55Z", + "modified": "2024-08-23T18:32:56Z", "published": "2024-05-14T15:32:55Z", "aliases": [ "CVE-2024-31771" ], "details": "Insecure Permission vulnerability in TotalAV v.6.0.740 allows a local attacker to escalate privileges via a crafted file", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-266" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:25:42Z" diff --git a/advisories/unreviewed/2024/06/GHSA-2pvh-rqjq-h9px/GHSA-2pvh-rqjq-h9px.json b/advisories/unreviewed/2024/06/GHSA-2pvh-rqjq-h9px/GHSA-2pvh-rqjq-h9px.json index b4b03e0394f..d92960d9d29 100644 --- a/advisories/unreviewed/2024/06/GHSA-2pvh-rqjq-h9px/GHSA-2pvh-rqjq-h9px.json +++ b/advisories/unreviewed/2024/06/GHSA-2pvh-rqjq-h9px/GHSA-2pvh-rqjq-h9px.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2pvh-rqjq-h9px", - "modified": "2024-06-12T18:30:40Z", + "modified": "2024-08-23T18:32:57Z", "published": "2024-06-12T18:30:40Z", "aliases": [ "CVE-2024-36761" ], "details": "naga v0.14.0 was discovered to contain a stack overflow via the component /wgsl/parse/mod.rs.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-12T16:15:11Z" diff --git a/advisories/unreviewed/2024/06/GHSA-6fj5-m574-p4w9/GHSA-6fj5-m574-p4w9.json b/advisories/unreviewed/2024/06/GHSA-6fj5-m574-p4w9/GHSA-6fj5-m574-p4w9.json index 11720172ec8..b2af449e93b 100644 --- a/advisories/unreviewed/2024/06/GHSA-6fj5-m574-p4w9/GHSA-6fj5-m574-p4w9.json +++ b/advisories/unreviewed/2024/06/GHSA-6fj5-m574-p4w9/GHSA-6fj5-m574-p4w9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6fj5-m574-p4w9", - "modified": "2024-06-11T15:31:14Z", + "modified": "2024-08-23T18:32:57Z", "published": "2024-06-11T15:31:14Z", "aliases": [ "CVE-2024-5697" ], "details": "A website was able to detect when a user took a screenshot of a page using the built-in Screenshot functionality in Firefox. This vulnerability affects Firefox < 127.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-11T13:15:51Z" diff --git a/advisories/unreviewed/2024/06/GHSA-72vv-7jqj-qv3q/GHSA-72vv-7jqj-qv3q.json b/advisories/unreviewed/2024/06/GHSA-72vv-7jqj-qv3q/GHSA-72vv-7jqj-qv3q.json index bed20fc3384..19d14db6369 100644 --- a/advisories/unreviewed/2024/06/GHSA-72vv-7jqj-qv3q/GHSA-72vv-7jqj-qv3q.json +++ b/advisories/unreviewed/2024/06/GHSA-72vv-7jqj-qv3q/GHSA-72vv-7jqj-qv3q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-72vv-7jqj-qv3q", - "modified": "2024-06-18T15:30:35Z", + "modified": "2024-08-23T18:32:57Z", "published": "2024-06-18T15:30:35Z", "aliases": [ "CVE-2024-6114" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-8xgj-w267-6p92/GHSA-8xgj-w267-6p92.json b/advisories/unreviewed/2024/06/GHSA-8xgj-w267-6p92/GHSA-8xgj-w267-6p92.json index fb6b8b141fe..675fbb63300 100644 --- a/advisories/unreviewed/2024/06/GHSA-8xgj-w267-6p92/GHSA-8xgj-w267-6p92.json +++ b/advisories/unreviewed/2024/06/GHSA-8xgj-w267-6p92/GHSA-8xgj-w267-6p92.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8xgj-w267-6p92", - "modified": "2024-06-27T21:32:08Z", + "modified": "2024-08-23T18:32:58Z", "published": "2024-06-27T21:32:08Z", "aliases": [ "CVE-2024-39207" ], "details": "lua-shmem v1.0-1 was discovered to contain a buffer overflow via the shmem_write function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-27T20:15:22Z" diff --git a/advisories/unreviewed/2024/06/GHSA-frpv-8jj9-m3cv/GHSA-frpv-8jj9-m3cv.json b/advisories/unreviewed/2024/06/GHSA-frpv-8jj9-m3cv/GHSA-frpv-8jj9-m3cv.json index f75a9550058..b5f2ccc3932 100644 --- a/advisories/unreviewed/2024/06/GHSA-frpv-8jj9-m3cv/GHSA-frpv-8jj9-m3cv.json +++ b/advisories/unreviewed/2024/06/GHSA-frpv-8jj9-m3cv/GHSA-frpv-8jj9-m3cv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-frpv-8jj9-m3cv", - "modified": "2024-06-11T15:31:14Z", + "modified": "2024-08-23T18:32:57Z", "published": "2024-06-11T15:31:14Z", "aliases": [ "CVE-2024-5698" ], "details": "By manipulating the fullscreen feature while opening a data-list, an attacker could have overlaid a text box over the address bar. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 127.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1021" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-11T13:15:51Z" diff --git a/advisories/unreviewed/2024/06/GHSA-g5jv-2gj9-v424/GHSA-g5jv-2gj9-v424.json b/advisories/unreviewed/2024/06/GHSA-g5jv-2gj9-v424/GHSA-g5jv-2gj9-v424.json index 0dae7eb6663..8fd96593d16 100644 --- a/advisories/unreviewed/2024/06/GHSA-g5jv-2gj9-v424/GHSA-g5jv-2gj9-v424.json +++ b/advisories/unreviewed/2024/06/GHSA-g5jv-2gj9-v424/GHSA-g5jv-2gj9-v424.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g5jv-2gj9-v424", - "modified": "2024-06-12T18:30:41Z", + "modified": "2024-08-23T18:32:57Z", "published": "2024-06-12T18:30:41Z", "aliases": [ "CVE-2024-5898" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-g8hw-gxg5-v62g/GHSA-g8hw-gxg5-v62g.json b/advisories/unreviewed/2024/06/GHSA-g8hw-gxg5-v62g/GHSA-g8hw-gxg5-v62g.json index a77757a0349..fe8002e9130 100644 --- a/advisories/unreviewed/2024/06/GHSA-g8hw-gxg5-v62g/GHSA-g8hw-gxg5-v62g.json +++ b/advisories/unreviewed/2024/06/GHSA-g8hw-gxg5-v62g/GHSA-g8hw-gxg5-v62g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g8hw-gxg5-v62g", - "modified": "2024-06-13T18:31:58Z", + "modified": "2024-08-23T18:32:57Z", "published": "2024-06-13T18:31:58Z", "aliases": [ "CVE-2024-35325" ], "details": "A vulnerability was found in libyaml up to 0.2.5. Affected by this issue is the function yaml_event_delete of the file /src/libyaml/src/api.c. The manipulation leads to a double-free.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-415" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-13T17:15:50Z" diff --git a/advisories/unreviewed/2024/06/GHSA-h339-65jr-4wwh/GHSA-h339-65jr-4wwh.json b/advisories/unreviewed/2024/06/GHSA-h339-65jr-4wwh/GHSA-h339-65jr-4wwh.json index 400d50299dc..d8a698957c9 100644 --- a/advisories/unreviewed/2024/06/GHSA-h339-65jr-4wwh/GHSA-h339-65jr-4wwh.json +++ b/advisories/unreviewed/2024/06/GHSA-h339-65jr-4wwh/GHSA-h339-65jr-4wwh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h339-65jr-4wwh", - "modified": "2024-06-12T18:30:41Z", + "modified": "2024-08-23T18:32:57Z", "published": "2024-06-12T18:30:41Z", "aliases": [ "CVE-2024-5896" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-mq4v-mwpp-gcfh/GHSA-mq4v-mwpp-gcfh.json b/advisories/unreviewed/2024/06/GHSA-mq4v-mwpp-gcfh/GHSA-mq4v-mwpp-gcfh.json index c86d5f8d529..cb3c82dc353 100644 --- a/advisories/unreviewed/2024/06/GHSA-mq4v-mwpp-gcfh/GHSA-mq4v-mwpp-gcfh.json +++ b/advisories/unreviewed/2024/06/GHSA-mq4v-mwpp-gcfh/GHSA-mq4v-mwpp-gcfh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mq4v-mwpp-gcfh", - "modified": "2024-06-25T18:31:22Z", + "modified": "2024-08-23T18:32:57Z", "published": "2024-06-25T18:31:22Z", "aliases": [ "CVE-2024-6308" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-p7rm-v5xq-5pr9/GHSA-p7rm-v5xq-5pr9.json b/advisories/unreviewed/2024/06/GHSA-p7rm-v5xq-5pr9/GHSA-p7rm-v5xq-5pr9.json index b23ed474db3..0ad62ae32bd 100644 --- a/advisories/unreviewed/2024/06/GHSA-p7rm-v5xq-5pr9/GHSA-p7rm-v5xq-5pr9.json +++ b/advisories/unreviewed/2024/06/GHSA-p7rm-v5xq-5pr9/GHSA-p7rm-v5xq-5pr9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p7rm-v5xq-5pr9", - "modified": "2024-06-21T03:30:33Z", + "modified": "2024-08-23T18:32:57Z", "published": "2024-06-21T03:30:33Z", "aliases": [ "CVE-2024-6218" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-prhw-q7f9-j4w8/GHSA-prhw-q7f9-j4w8.json b/advisories/unreviewed/2024/06/GHSA-prhw-q7f9-j4w8/GHSA-prhw-q7f9-j4w8.json index d42a15555da..1913b2c7a03 100644 --- a/advisories/unreviewed/2024/06/GHSA-prhw-q7f9-j4w8/GHSA-prhw-q7f9-j4w8.json +++ b/advisories/unreviewed/2024/06/GHSA-prhw-q7f9-j4w8/GHSA-prhw-q7f9-j4w8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-prhw-q7f9-j4w8", - "modified": "2024-06-12T18:30:41Z", + "modified": "2024-08-23T18:32:57Z", "published": "2024-06-12T18:30:41Z", "aliases": [ "CVE-2024-5897" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-rgjh-vj92-73c9/GHSA-rgjh-vj92-73c9.json b/advisories/unreviewed/2024/06/GHSA-rgjh-vj92-73c9/GHSA-rgjh-vj92-73c9.json index 635d02e436a..68c2ee8cf18 100644 --- a/advisories/unreviewed/2024/06/GHSA-rgjh-vj92-73c9/GHSA-rgjh-vj92-73c9.json +++ b/advisories/unreviewed/2024/06/GHSA-rgjh-vj92-73c9/GHSA-rgjh-vj92-73c9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rgjh-vj92-73c9", - "modified": "2024-06-18T12:30:42Z", + "modified": "2024-08-23T18:32:57Z", "published": "2024-06-18T12:30:42Z", "aliases": [ "CVE-2024-6109" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/07/GHSA-6mp9-hrx8-6ffg/GHSA-6mp9-hrx8-6ffg.json b/advisories/unreviewed/2024/07/GHSA-6mp9-hrx8-6ffg/GHSA-6mp9-hrx8-6ffg.json index 48a5a64bcee..ce049386d23 100644 --- a/advisories/unreviewed/2024/07/GHSA-6mp9-hrx8-6ffg/GHSA-6mp9-hrx8-6ffg.json +++ b/advisories/unreviewed/2024/07/GHSA-6mp9-hrx8-6ffg/GHSA-6mp9-hrx8-6ffg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6mp9-hrx8-6ffg", - "modified": "2024-07-30T03:30:52Z", + "modified": "2024-08-23T18:32:58Z", "published": "2024-07-30T00:34:27Z", "aliases": [ "CVE-2024-40789" ], "details": "An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, Safari 17.6, iOS 17.6 and iPadOS 17.6, watchOS 10.6, tvOS 17.6, visionOS 1.3, macOS Sonoma 14.6. Processing maliciously crafted web content may lead to an unexpected process crash.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -83,7 +86,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T23:15:12Z" diff --git a/advisories/unreviewed/2024/07/GHSA-8482-wc7m-w3q5/GHSA-8482-wc7m-w3q5.json b/advisories/unreviewed/2024/07/GHSA-8482-wc7m-w3q5/GHSA-8482-wc7m-w3q5.json index fd65168d2aa..3f0bd601158 100644 --- a/advisories/unreviewed/2024/07/GHSA-8482-wc7m-w3q5/GHSA-8482-wc7m-w3q5.json +++ b/advisories/unreviewed/2024/07/GHSA-8482-wc7m-w3q5/GHSA-8482-wc7m-w3q5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8482-wc7m-w3q5", - "modified": "2024-07-30T18:32:07Z", + "modified": "2024-08-23T18:32:58Z", "published": "2024-07-30T18:32:07Z", "aliases": [ "CVE-2024-41304" ], "details": "An arbitrary file upload vulnerability in the uploadFileAction() function of WonderCMS v3.4.3 allows attackers to execute arbitrary code via a crafted SVG file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-30T18:15:05Z" diff --git a/advisories/unreviewed/2024/07/GHSA-cg5c-5558-3qmm/GHSA-cg5c-5558-3qmm.json b/advisories/unreviewed/2024/07/GHSA-cg5c-5558-3qmm/GHSA-cg5c-5558-3qmm.json index dc460b15bc2..e03ed3c94f8 100644 --- a/advisories/unreviewed/2024/07/GHSA-cg5c-5558-3qmm/GHSA-cg5c-5558-3qmm.json +++ b/advisories/unreviewed/2024/07/GHSA-cg5c-5558-3qmm/GHSA-cg5c-5558-3qmm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cg5c-5558-3qmm", - "modified": "2024-07-30T03:30:52Z", + "modified": "2024-08-23T18:32:58Z", "published": "2024-07-30T00:34:27Z", "aliases": [ "CVE-2024-40793" ], "details": "This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, macOS Ventura 13.6.8, macOS Monterey 12.7.6, iOS 17.6 and iPadOS 17.6, watchOS 10.6, macOS Sonoma 14.6. An app may be able to access user-sensitive data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -71,7 +74,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T23:15:12Z" diff --git a/advisories/unreviewed/2024/08/GHSA-235v-2948-prr3/GHSA-235v-2948-prr3.json b/advisories/unreviewed/2024/08/GHSA-235v-2948-prr3/GHSA-235v-2948-prr3.json new file mode 100644 index 00000000000..050d72d86ca --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-235v-2948-prr3/GHSA-235v-2948-prr3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-235v-2948-prr3", + "modified": "2024-08-23T18:33:02Z", + "published": "2024-08-23T18:33:02Z", + "aliases": [ + "CVE-2024-41846" + ], + "details": "Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41846" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-28.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-36gx-rqg5-2fh6/GHSA-36gx-rqg5-2fh6.json b/advisories/unreviewed/2024/08/GHSA-36gx-rqg5-2fh6/GHSA-36gx-rqg5-2fh6.json new file mode 100644 index 00000000000..44f8c448297 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-36gx-rqg5-2fh6/GHSA-36gx-rqg5-2fh6.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-36gx-rqg5-2fh6", + "modified": "2024-08-23T18:33:02Z", + "published": "2024-08-23T18:33:02Z", + "aliases": [ + "CVE-2024-33852" + ], + "details": "A SQL Injection vulnerability exists in the Downtime component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33852" + }, + { + "type": "WEB", + "url": "https://github.com/centreon/centreon/releases" + }, + { + "type": "WEB", + "url": "https://thewatch.centreon.com/latest-security-bulletins-64/security-bulletin-for-centreon-web-3744" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T17:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-3rj4-hw95-8jqg/GHSA-3rj4-hw95-8jqg.json b/advisories/unreviewed/2024/08/GHSA-3rj4-hw95-8jqg/GHSA-3rj4-hw95-8jqg.json new file mode 100644 index 00000000000..726161f8aba --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-3rj4-hw95-8jqg/GHSA-3rj4-hw95-8jqg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3rj4-hw95-8jqg", + "modified": "2024-08-23T18:33:03Z", + "published": "2024-08-23T18:33:03Z", + "aliases": [ + "CVE-2024-41878" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. This vulnerability could allow an attacker to inject and execute arbitrary JavaScript code within the context of the user's browser session. Exploitation of this issue requires user interaction, such as convincing a victim to click on a malicious link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41878" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-05.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-3xww-gg44-m2qc/GHSA-3xww-gg44-m2qc.json b/advisories/unreviewed/2024/08/GHSA-3xww-gg44-m2qc/GHSA-3xww-gg44-m2qc.json new file mode 100644 index 00000000000..208eb3cef36 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-3xww-gg44-m2qc/GHSA-3xww-gg44-m2qc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3xww-gg44-m2qc", + "modified": "2024-08-23T18:33:01Z", + "published": "2024-08-23T18:33:01Z", + "aliases": [ + "CVE-2024-42756" + ], + "details": "An issue in Netgear DGN1000WW v.1.1.00.45 allows a remote attacker to execute arbitrary code via the Diagnostics page", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42756" + }, + { + "type": "WEB", + "url": "https://www.netgear.com/about/security" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T16:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-42mv-3h37-wfh9/GHSA-42mv-3h37-wfh9.json b/advisories/unreviewed/2024/08/GHSA-42mv-3h37-wfh9/GHSA-42mv-3h37-wfh9.json new file mode 100644 index 00000000000..fe7e18756ce --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-42mv-3h37-wfh9/GHSA-42mv-3h37-wfh9.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-42mv-3h37-wfh9", + "modified": "2024-08-23T18:33:03Z", + "published": "2024-08-23T18:33:03Z", + "aliases": [ + "CVE-2024-7954" + ], + "details": "The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can execute arbitrary PHP as the SPIP user by sending a crafted HTTP request.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7954" + }, + { + "type": "WEB", + "url": "https://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-3-0-alpha2-SPIP-4-2-13-SPIP-4.html" + }, + { + "type": "WEB", + "url": "https://thinkloveshare.com/hacking/spip_preauth_rce_2024_part_1_the_feather" + }, + { + "type": "WEB", + "url": "https://vulncheck.com/advisories/spip-porte-plume" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T18:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-44mp-qrwc-xm4x/GHSA-44mp-qrwc-xm4x.json b/advisories/unreviewed/2024/08/GHSA-44mp-qrwc-xm4x/GHSA-44mp-qrwc-xm4x.json new file mode 100644 index 00000000000..90535f99bdd --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-44mp-qrwc-xm4x/GHSA-44mp-qrwc-xm4x.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-44mp-qrwc-xm4x", + "modified": "2024-08-23T18:33:03Z", + "published": "2024-08-23T18:33:03Z", + "aliases": [ + "CVE-2024-42852" + ], + "details": "Cross Site Scripting vulnerability in AcuToWeb server v.10.5.0.7577C8b allows a remote attacker to execute arbitrary code via the index.php component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42852" + }, + { + "type": "WEB", + "url": "https://github.com/Hebing123/cve/issues/64" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T18:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-4g6m-wpfm-pfxv/GHSA-4g6m-wpfm-pfxv.json b/advisories/unreviewed/2024/08/GHSA-4g6m-wpfm-pfxv/GHSA-4g6m-wpfm-pfxv.json index 242fb34d1ce..2cb0749b765 100644 --- a/advisories/unreviewed/2024/08/GHSA-4g6m-wpfm-pfxv/GHSA-4g6m-wpfm-pfxv.json +++ b/advisories/unreviewed/2024/08/GHSA-4g6m-wpfm-pfxv/GHSA-4g6m-wpfm-pfxv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4g6m-wpfm-pfxv", - "modified": "2024-08-01T03:30:46Z", + "modified": "2024-08-23T18:32:58Z", "published": "2024-08-01T03:30:46Z", "aliases": [ "CVE-2024-40883" ], "details": "Cross-site request forgery vulnerability exists in ELECOM wireless LAN routers. Viewing a malicious page while logging in to the affected product with an administrative privilege, the user may be directed to perform unintended operations such as changing the login ID, login password, etc.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-01T02:15:02Z" diff --git a/advisories/unreviewed/2024/08/GHSA-4w56-w59g-jg9w/GHSA-4w56-w59g-jg9w.json b/advisories/unreviewed/2024/08/GHSA-4w56-w59g-jg9w/GHSA-4w56-w59g-jg9w.json new file mode 100644 index 00000000000..b91912f21e5 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-4w56-w59g-jg9w/GHSA-4w56-w59g-jg9w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4w56-w59g-jg9w", + "modified": "2024-08-23T18:33:03Z", + "published": "2024-08-23T18:33:03Z", + "aliases": [ + "CVE-2024-41877" + ], + "details": "Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41877" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-05.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-4wrj-qhhf-3c55/GHSA-4wrj-qhhf-3c55.json b/advisories/unreviewed/2024/08/GHSA-4wrj-qhhf-3c55/GHSA-4wrj-qhhf-3c55.json index 96bd3b360b5..907f919aadc 100644 --- a/advisories/unreviewed/2024/08/GHSA-4wrj-qhhf-3c55/GHSA-4wrj-qhhf-3c55.json +++ b/advisories/unreviewed/2024/08/GHSA-4wrj-qhhf-3c55/GHSA-4wrj-qhhf-3c55.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-4ww8-fprq-cq34/GHSA-4ww8-fprq-cq34.json b/advisories/unreviewed/2024/08/GHSA-4ww8-fprq-cq34/GHSA-4ww8-fprq-cq34.json index 05e2c4dddfa..3323a5b171b 100644 --- a/advisories/unreviewed/2024/08/GHSA-4ww8-fprq-cq34/GHSA-4ww8-fprq-cq34.json +++ b/advisories/unreviewed/2024/08/GHSA-4ww8-fprq-cq34/GHSA-4ww8-fprq-cq34.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-312" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-5236-grq3-77jq/GHSA-5236-grq3-77jq.json b/advisories/unreviewed/2024/08/GHSA-5236-grq3-77jq/GHSA-5236-grq3-77jq.json new file mode 100644 index 00000000000..8c4c2bc569f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-5236-grq3-77jq/GHSA-5236-grq3-77jq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5236-grq3-77jq", + "modified": "2024-08-23T18:33:03Z", + "published": "2024-08-23T18:33:03Z", + "aliases": [ + "CVE-2024-41848" + ], + "details": "Adobe Experience Manager versions 6.5.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41848" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-28.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-58cw-gjp7-8mm7/GHSA-58cw-gjp7-8mm7.json b/advisories/unreviewed/2024/08/GHSA-58cw-gjp7-8mm7/GHSA-58cw-gjp7-8mm7.json new file mode 100644 index 00000000000..a8a0070a005 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-58cw-gjp7-8mm7/GHSA-58cw-gjp7-8mm7.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-58cw-gjp7-8mm7", + "modified": "2024-08-23T18:33:02Z", + "published": "2024-08-23T18:33:02Z", + "aliases": [ + "CVE-2024-39841" + ], + "details": "A SQL Injection vulnerability exists in the service configuration functionality in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39841" + }, + { + "type": "WEB", + "url": "https://github.com/centreon/centreon/releases" + }, + { + "type": "WEB", + "url": "https://thewatch.centreon.com/latest-security-bulletins-64/security-bulletin-for-centreon-web-3744" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T17:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-5pvf-fc2q-jq4q/GHSA-5pvf-fc2q-jq4q.json b/advisories/unreviewed/2024/08/GHSA-5pvf-fc2q-jq4q/GHSA-5pvf-fc2q-jq4q.json index 974642cc345..451d7241400 100644 --- a/advisories/unreviewed/2024/08/GHSA-5pvf-fc2q-jq4q/GHSA-5pvf-fc2q-jq4q.json +++ b/advisories/unreviewed/2024/08/GHSA-5pvf-fc2q-jq4q/GHSA-5pvf-fc2q-jq4q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5pvf-fc2q-jq4q", - "modified": "2024-08-22T21:31:29Z", + "modified": "2024-08-23T18:33:00Z", "published": "2024-08-22T21:31:29Z", "aliases": [ "CVE-2024-42763" ], "details": "A Reflected Cross Site Scripting (XSS) vulnerability was found in the \"/schedule.php\" page of the Kashipara Bus Ticket Reservation System v1.0, which allows remote attackers to execute arbitrary code via the \"bookingdate\" parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-22T21:15:17Z" diff --git a/advisories/unreviewed/2024/08/GHSA-64gw-gxfq-f34c/GHSA-64gw-gxfq-f34c.json b/advisories/unreviewed/2024/08/GHSA-64gw-gxfq-f34c/GHSA-64gw-gxfq-f34c.json index 64e850616af..0181fff3d11 100644 --- a/advisories/unreviewed/2024/08/GHSA-64gw-gxfq-f34c/GHSA-64gw-gxfq-f34c.json +++ b/advisories/unreviewed/2024/08/GHSA-64gw-gxfq-f34c/GHSA-64gw-gxfq-f34c.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-121" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/08/GHSA-65h6-4ccg-v5j8/GHSA-65h6-4ccg-v5j8.json b/advisories/unreviewed/2024/08/GHSA-65h6-4ccg-v5j8/GHSA-65h6-4ccg-v5j8.json new file mode 100644 index 00000000000..20baaf67559 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-65h6-4ccg-v5j8/GHSA-65h6-4ccg-v5j8.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-65h6-4ccg-v5j8", + "modified": "2024-08-23T18:33:02Z", + "published": "2024-08-23T18:33:02Z", + "aliases": [ + "CVE-2024-33853" + ], + "details": "A SQL Injection vulnerability exists in the Timeperiod component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33853" + }, + { + "type": "WEB", + "url": "https://github.com/centreon/centreon/releases" + }, + { + "type": "WEB", + "url": "https://thewatch.centreon.com/latest-security-bulletins-64/security-bulletin-for-centreon-web-3744" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T17:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-662c-cj8q-qc4g/GHSA-662c-cj8q-qc4g.json b/advisories/unreviewed/2024/08/GHSA-662c-cj8q-qc4g/GHSA-662c-cj8q-qc4g.json index e46611048b3..ff79525caa2 100644 --- a/advisories/unreviewed/2024/08/GHSA-662c-cj8q-qc4g/GHSA-662c-cj8q-qc4g.json +++ b/advisories/unreviewed/2024/08/GHSA-662c-cj8q-qc4g/GHSA-662c-cj8q-qc4g.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-287", "CWE-305" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/08/GHSA-6fcq-8rv2-rc2j/GHSA-6fcq-8rv2-rc2j.json b/advisories/unreviewed/2024/08/GHSA-6fcq-8rv2-rc2j/GHSA-6fcq-8rv2-rc2j.json new file mode 100644 index 00000000000..be2938f9b8c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6fcq-8rv2-rc2j/GHSA-6fcq-8rv2-rc2j.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6fcq-8rv2-rc2j", + "modified": "2024-08-23T18:33:02Z", + "published": "2024-08-23T18:33:02Z", + "aliases": [ + "CVE-2024-32501" + ], + "details": "A SQL Injection vulnerability exists in the updateServiceHost functionality in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32501" + }, + { + "type": "WEB", + "url": "https://centreon.com" + }, + { + "type": "WEB", + "url": "https://thewatch.centreon.com/latest-security-bulletins-64/security-bulletin-for-centreon-web-3744" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T17:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-6v83-ppjw-wp84/GHSA-6v83-ppjw-wp84.json b/advisories/unreviewed/2024/08/GHSA-6v83-ppjw-wp84/GHSA-6v83-ppjw-wp84.json new file mode 100644 index 00000000000..3fbf8961bef --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6v83-ppjw-wp84/GHSA-6v83-ppjw-wp84.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6v83-ppjw-wp84", + "modified": "2024-08-23T18:33:01Z", + "published": "2024-08-23T18:33:01Z", + "aliases": [ + "CVE-2024-42636" + ], + "details": "DedeCMS V5.7.115 has a command execution vulnerability via file_manage_view.php?fmdo=newfile&activepath.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42636" + }, + { + "type": "WEB", + "url": "https://github.com/iami233/cve/issues/1" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T16:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-723q-4x66-vrf2/GHSA-723q-4x66-vrf2.json b/advisories/unreviewed/2024/08/GHSA-723q-4x66-vrf2/GHSA-723q-4x66-vrf2.json new file mode 100644 index 00000000000..0ab80220bc5 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-723q-4x66-vrf2/GHSA-723q-4x66-vrf2.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-723q-4x66-vrf2", + "modified": "2024-08-23T18:33:02Z", + "published": "2024-08-23T18:33:02Z", + "aliases": [ + "CVE-2024-44381" + ], + "details": "D-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in jhttpd msp_info_htm function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44381" + }, + { + "type": "WEB", + "url": "https://github.com/GroundCTL2MajorTom/pocs/blob/main/dlink_DI8004W.md" + }, + { + "type": "WEB", + "url": "https://www.dlink.com/en/security-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7c8c-x5xp-8wgj/GHSA-7c8c-x5xp-8wgj.json b/advisories/unreviewed/2024/08/GHSA-7c8c-x5xp-8wgj/GHSA-7c8c-x5xp-8wgj.json index 8efb05a0e70..ae2311a0b45 100644 --- a/advisories/unreviewed/2024/08/GHSA-7c8c-x5xp-8wgj/GHSA-7c8c-x5xp-8wgj.json +++ b/advisories/unreviewed/2024/08/GHSA-7c8c-x5xp-8wgj/GHSA-7c8c-x5xp-8wgj.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-288" + "CWE-288", + "CWE-306" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-7v24-gjqv-fwg7/GHSA-7v24-gjqv-fwg7.json b/advisories/unreviewed/2024/08/GHSA-7v24-gjqv-fwg7/GHSA-7v24-gjqv-fwg7.json index e43edccf663..e9541685023 100644 --- a/advisories/unreviewed/2024/08/GHSA-7v24-gjqv-fwg7/GHSA-7v24-gjqv-fwg7.json +++ b/advisories/unreviewed/2024/08/GHSA-7v24-gjqv-fwg7/GHSA-7v24-gjqv-fwg7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7v24-gjqv-fwg7", - "modified": "2024-08-22T21:31:29Z", + "modified": "2024-08-23T18:33:00Z", "published": "2024-08-22T21:31:29Z", "aliases": [ "CVE-2024-39717" @@ -40,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-8chj-vfwh-89pj/GHSA-8chj-vfwh-89pj.json b/advisories/unreviewed/2024/08/GHSA-8chj-vfwh-89pj/GHSA-8chj-vfwh-89pj.json index 9bdcaaaf6cc..6b0e9e7a39b 100644 --- a/advisories/unreviewed/2024/08/GHSA-8chj-vfwh-89pj/GHSA-8chj-vfwh-89pj.json +++ b/advisories/unreviewed/2024/08/GHSA-8chj-vfwh-89pj/GHSA-8chj-vfwh-89pj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8chj-vfwh-89pj", - "modified": "2024-08-23T06:30:44Z", + "modified": "2024-08-23T18:33:00Z", "published": "2024-08-23T06:30:44Z", "aliases": [ "CVE-2024-3282" ], "details": "The WP Table Builder WordPress plugin through 1.5.0 does not sanitise and escape some of its Table data, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-23T06:15:03Z" diff --git a/advisories/unreviewed/2024/08/GHSA-982x-jhrm-q8mj/GHSA-982x-jhrm-q8mj.json b/advisories/unreviewed/2024/08/GHSA-982x-jhrm-q8mj/GHSA-982x-jhrm-q8mj.json index b6ff1c33b88..1ba422de40f 100644 --- a/advisories/unreviewed/2024/08/GHSA-982x-jhrm-q8mj/GHSA-982x-jhrm-q8mj.json +++ b/advisories/unreviewed/2024/08/GHSA-982x-jhrm-q8mj/GHSA-982x-jhrm-q8mj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-982x-jhrm-q8mj", - "modified": "2024-08-21T15:30:53Z", + "modified": "2024-08-23T18:32:59Z", "published": "2024-08-21T15:30:53Z", "aliases": [ "CVE-2020-11846" diff --git a/advisories/unreviewed/2024/08/GHSA-9j5g-j2hj-xfpc/GHSA-9j5g-j2hj-xfpc.json b/advisories/unreviewed/2024/08/GHSA-9j5g-j2hj-xfpc/GHSA-9j5g-j2hj-xfpc.json index e3bd593647c..cab58b21310 100644 --- a/advisories/unreviewed/2024/08/GHSA-9j5g-j2hj-xfpc/GHSA-9j5g-j2hj-xfpc.json +++ b/advisories/unreviewed/2024/08/GHSA-9j5g-j2hj-xfpc/GHSA-9j5g-j2hj-xfpc.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-829", "CWE-98" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/08/GHSA-9x8h-2288-5g98/GHSA-9x8h-2288-5g98.json b/advisories/unreviewed/2024/08/GHSA-9x8h-2288-5g98/GHSA-9x8h-2288-5g98.json index 568a959f720..35427f958ad 100644 --- a/advisories/unreviewed/2024/08/GHSA-9x8h-2288-5g98/GHSA-9x8h-2288-5g98.json +++ b/advisories/unreviewed/2024/08/GHSA-9x8h-2288-5g98/GHSA-9x8h-2288-5g98.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1333", "CWE-400" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/08/GHSA-c23f-2mjw-h676/GHSA-c23f-2mjw-h676.json b/advisories/unreviewed/2024/08/GHSA-c23f-2mjw-h676/GHSA-c23f-2mjw-h676.json new file mode 100644 index 00000000000..9b1078a77b1 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-c23f-2mjw-h676/GHSA-c23f-2mjw-h676.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c23f-2mjw-h676", + "modified": "2024-08-23T18:33:03Z", + "published": "2024-08-23T18:33:03Z", + "aliases": [ + "CVE-2024-44387" + ], + "details": "Tenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the functino formWrlExtraGet.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44387" + }, + { + "type": "WEB", + "url": "https://github.com/GroundCTL2MajorTom/pocs/blob/main/tenda_FH1206_buffer_overflow1.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-c6vp-jjgv-38wj/GHSA-c6vp-jjgv-38wj.json b/advisories/unreviewed/2024/08/GHSA-c6vp-jjgv-38wj/GHSA-c6vp-jjgv-38wj.json index 616a7ca1e0d..574d3a08d18 100644 --- a/advisories/unreviewed/2024/08/GHSA-c6vp-jjgv-38wj/GHSA-c6vp-jjgv-38wj.json +++ b/advisories/unreviewed/2024/08/GHSA-c6vp-jjgv-38wj/GHSA-c6vp-jjgv-38wj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c6vp-jjgv-38wj", - "modified": "2024-08-22T09:30:32Z", + "modified": "2024-08-23T18:33:00Z", "published": "2024-08-22T09:30:32Z", "aliases": [ "CVE-2024-39836" diff --git a/advisories/unreviewed/2024/08/GHSA-c866-phfm-vxw2/GHSA-c866-phfm-vxw2.json b/advisories/unreviewed/2024/08/GHSA-c866-phfm-vxw2/GHSA-c866-phfm-vxw2.json new file mode 100644 index 00000000000..bd5e9ab8fe0 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-c866-phfm-vxw2/GHSA-c866-phfm-vxw2.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c866-phfm-vxw2", + "modified": "2024-08-23T18:33:01Z", + "published": "2024-08-23T18:33:01Z", + "aliases": [ + "CVE-2024-43031" + ], + "details": "autMan v2.9.6 was discovered to contain an access control issue.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43031" + }, + { + "type": "WEB", + "url": "https://github.com/hdbjlizhe/fanli" + }, + { + "type": "WEB", + "url": "http://autman.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T16:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-c96v-5mr3-4xxf/GHSA-c96v-5mr3-4xxf.json b/advisories/unreviewed/2024/08/GHSA-c96v-5mr3-4xxf/GHSA-c96v-5mr3-4xxf.json new file mode 100644 index 00000000000..1bc18a1b0b5 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-c96v-5mr3-4xxf/GHSA-c96v-5mr3-4xxf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c96v-5mr3-4xxf", + "modified": "2024-08-23T18:33:03Z", + "published": "2024-08-23T18:33:03Z", + "aliases": [ + "CVE-2024-7427" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Network Node Manager i (NNMi) could allow Cross-Site Scripting (XSS).This issue affects Network Node Manager i (NNMi): 2022.11, 2023.05, 23.4, 24.2.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:A/V:C/RE:L/U:Red" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7427" + }, + { + "type": "WEB", + "url": "https://portal.microfocus.com/s/article/KM000033018?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-ccvv-v4jq-v9x2/GHSA-ccvv-v4jq-v9x2.json b/advisories/unreviewed/2024/08/GHSA-ccvv-v4jq-v9x2/GHSA-ccvv-v4jq-v9x2.json new file mode 100644 index 00000000000..aa3ba8b357c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-ccvv-v4jq-v9x2/GHSA-ccvv-v4jq-v9x2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ccvv-v4jq-v9x2", + "modified": "2024-08-23T18:33:02Z", + "published": "2024-08-23T18:33:02Z", + "aliases": [ + "CVE-2024-41845" + ], + "details": "Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41845" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-28.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T17:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-cxrj-5q7c-cmrm/GHSA-cxrj-5q7c-cmrm.json b/advisories/unreviewed/2024/08/GHSA-cxrj-5q7c-cmrm/GHSA-cxrj-5q7c-cmrm.json new file mode 100644 index 00000000000..51ddabba307 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-cxrj-5q7c-cmrm/GHSA-cxrj-5q7c-cmrm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cxrj-5q7c-cmrm", + "modified": "2024-08-23T18:33:02Z", + "published": "2024-08-23T18:33:02Z", + "aliases": [ + "CVE-2024-41843" + ], + "details": "Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41843" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-28.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T17:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-f56c-x89x-xgxh/GHSA-f56c-x89x-xgxh.json b/advisories/unreviewed/2024/08/GHSA-f56c-x89x-xgxh/GHSA-f56c-x89x-xgxh.json index c0d1be0c9f4..04f457a8973 100644 --- a/advisories/unreviewed/2024/08/GHSA-f56c-x89x-xgxh/GHSA-f56c-x89x-xgxh.json +++ b/advisories/unreviewed/2024/08/GHSA-f56c-x89x-xgxh/GHSA-f56c-x89x-xgxh.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f56c-x89x-xgxh", - "modified": "2024-08-12T15:30:49Z", + "modified": "2024-08-23T18:32:59Z", "published": "2024-08-12T15:30:48Z", "aliases": [ "CVE-2024-21880" ], "details": "Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability via the url parameter of an authenticated enpoint in Enphase IQ Gateway (formerly known as Enphase) allows OS Command Injection.This issue affects Envoy: 4.x <= 7.x", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:I/V:C/RE:H/U:X" @@ -36,7 +40,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-f8x5-fv5x-fcq5/GHSA-f8x5-fv5x-fcq5.json b/advisories/unreviewed/2024/08/GHSA-f8x5-fv5x-fcq5/GHSA-f8x5-fv5x-fcq5.json index 4535aeff3cb..e38cd741128 100644 --- a/advisories/unreviewed/2024/08/GHSA-f8x5-fv5x-fcq5/GHSA-f8x5-fv5x-fcq5.json +++ b/advisories/unreviewed/2024/08/GHSA-f8x5-fv5x-fcq5/GHSA-f8x5-fv5x-fcq5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f8x5-fv5x-fcq5", - "modified": "2024-08-23T15:30:34Z", + "modified": "2024-08-23T18:33:01Z", "published": "2024-08-23T15:30:34Z", "aliases": [ "CVE-2024-42764" ], "details": "Kashipara Bus Ticket Reservation System v1.0 is vulnerable to Cross Site Request Forgery (CSRF) via /deleteTicket.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-23T15:15:16Z" diff --git a/advisories/unreviewed/2024/08/GHSA-fcf2-47c2-px5h/GHSA-fcf2-47c2-px5h.json b/advisories/unreviewed/2024/08/GHSA-fcf2-47c2-px5h/GHSA-fcf2-47c2-px5h.json index 0e0a9e5cba4..53312bdce8f 100644 --- a/advisories/unreviewed/2024/08/GHSA-fcf2-47c2-px5h/GHSA-fcf2-47c2-px5h.json +++ b/advisories/unreviewed/2024/08/GHSA-fcf2-47c2-px5h/GHSA-fcf2-47c2-px5h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fcf2-47c2-px5h", - "modified": "2024-08-20T15:32:12Z", + "modified": "2024-08-23T18:32:59Z", "published": "2024-08-20T15:32:12Z", "aliases": [ "CVE-2024-42564" ], "details": "ERP commit 44bd04 was discovered to contain a SQL injection vulnerability via the id parameter at /index.php/basedata/inventory/delete?action=delete.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-20T13:15:07Z" diff --git a/advisories/unreviewed/2024/08/GHSA-ffmr-5xqw-mpjg/GHSA-ffmr-5xqw-mpjg.json b/advisories/unreviewed/2024/08/GHSA-ffmr-5xqw-mpjg/GHSA-ffmr-5xqw-mpjg.json new file mode 100644 index 00000000000..5f505631d5e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-ffmr-5xqw-mpjg/GHSA-ffmr-5xqw-mpjg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ffmr-5xqw-mpjg", + "modified": "2024-08-23T18:33:02Z", + "published": "2024-08-23T18:33:02Z", + "aliases": [ + "CVE-2024-41841" + ], + "details": "Adobe Experience Manager versions 6.5.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41841" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-28.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T17:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-fg8g-qmfg-pf88/GHSA-fg8g-qmfg-pf88.json b/advisories/unreviewed/2024/08/GHSA-fg8g-qmfg-pf88/GHSA-fg8g-qmfg-pf88.json new file mode 100644 index 00000000000..1f5df574ef4 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-fg8g-qmfg-pf88/GHSA-fg8g-qmfg-pf88.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fg8g-qmfg-pf88", + "modified": "2024-08-23T18:33:02Z", + "published": "2024-08-23T18:33:02Z", + "aliases": [ + "CVE-2024-41844" + ], + "details": "Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41844" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-28.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T17:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-g3jm-x33w-9q5w/GHSA-g3jm-x33w-9q5w.json b/advisories/unreviewed/2024/08/GHSA-g3jm-x33w-9q5w/GHSA-g3jm-x33w-9q5w.json new file mode 100644 index 00000000000..90658c58af8 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-g3jm-x33w-9q5w/GHSA-g3jm-x33w-9q5w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g3jm-x33w-9q5w", + "modified": "2024-08-23T18:33:02Z", + "published": "2024-08-23T18:33:02Z", + "aliases": [ + "CVE-2024-44386" + ], + "details": "Tenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the function fromSetIpBind.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44386" + }, + { + "type": "WEB", + "url": "https://github.com/GroundCTL2MajorTom/pocs/blob/main/tenda_FH1206_buffer_overflow2.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-gp95-49cg-49jc/GHSA-gp95-49cg-49jc.json b/advisories/unreviewed/2024/08/GHSA-gp95-49cg-49jc/GHSA-gp95-49cg-49jc.json index 7b6fe5cd8f6..956c3f865e8 100644 --- a/advisories/unreviewed/2024/08/GHSA-gp95-49cg-49jc/GHSA-gp95-49cg-49jc.json +++ b/advisories/unreviewed/2024/08/GHSA-gp95-49cg-49jc/GHSA-gp95-49cg-49jc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gp95-49cg-49jc", - "modified": "2024-08-12T15:30:50Z", + "modified": "2024-08-23T18:32:59Z", "published": "2024-08-12T15:30:50Z", "aliases": [ "CVE-2024-40487" ], "details": "A Stored Cross Site Scripting (XSS) vulnerability was found in \"/view_type.php\" of Kashipara Live Membership System v1.0, which allows remote attackers to execute arbitrary code via membershipType parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-12T13:38:29Z" diff --git a/advisories/unreviewed/2024/08/GHSA-h363-vrwv-gpwf/GHSA-h363-vrwv-gpwf.json b/advisories/unreviewed/2024/08/GHSA-h363-vrwv-gpwf/GHSA-h363-vrwv-gpwf.json new file mode 100644 index 00000000000..28f67726406 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-h363-vrwv-gpwf/GHSA-h363-vrwv-gpwf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h363-vrwv-gpwf", + "modified": "2024-08-23T18:33:03Z", + "published": "2024-08-23T18:33:03Z", + "aliases": [ + "CVE-2024-44390" + ], + "details": "Tenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the function formWrlsafeset.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44390" + }, + { + "type": "WEB", + "url": "https://github.com/GroundCTL2MajorTom/pocs/blob/main/tenda_FH1206_buffer_overflow8.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-hch6-3cq4-hjhm/GHSA-hch6-3cq4-hjhm.json b/advisories/unreviewed/2024/08/GHSA-hch6-3cq4-hjhm/GHSA-hch6-3cq4-hjhm.json index 4bb5d13804a..7421afc3fdf 100644 --- a/advisories/unreviewed/2024/08/GHSA-hch6-3cq4-hjhm/GHSA-hch6-3cq4-hjhm.json +++ b/advisories/unreviewed/2024/08/GHSA-hch6-3cq4-hjhm/GHSA-hch6-3cq4-hjhm.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hch6-3cq4-hjhm", - "modified": "2024-08-12T15:30:49Z", + "modified": "2024-08-23T18:32:59Z", "published": "2024-08-12T15:30:48Z", "aliases": [ "CVE-2024-21878" ], "details": "Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Enphase IQ Gateway (formerly known as Envoy) allows OS Command Injection. This vulnerability is present in an internal script.This issue affects Envoy: from 4.x up to and including 8.x and is currently unpatched.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:I/V:C/RE:H/U:X" @@ -36,7 +40,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-hrf9-rm95-fpf3/GHSA-hrf9-rm95-fpf3.json b/advisories/unreviewed/2024/08/GHSA-hrf9-rm95-fpf3/GHSA-hrf9-rm95-fpf3.json index 7750976f45b..4bdc1845031 100644 --- a/advisories/unreviewed/2024/08/GHSA-hrf9-rm95-fpf3/GHSA-hrf9-rm95-fpf3.json +++ b/advisories/unreviewed/2024/08/GHSA-hrf9-rm95-fpf3/GHSA-hrf9-rm95-fpf3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hrf9-rm95-fpf3", - "modified": "2024-08-22T09:30:32Z", + "modified": "2024-08-23T18:33:00Z", "published": "2024-08-22T09:30:32Z", "aliases": [ "CVE-2024-40886" diff --git a/advisories/unreviewed/2024/08/GHSA-j3cx-fj78-gw65/GHSA-j3cx-fj78-gw65.json b/advisories/unreviewed/2024/08/GHSA-j3cx-fj78-gw65/GHSA-j3cx-fj78-gw65.json index d2bd6b113e8..619b458ec8d 100644 --- a/advisories/unreviewed/2024/08/GHSA-j3cx-fj78-gw65/GHSA-j3cx-fj78-gw65.json +++ b/advisories/unreviewed/2024/08/GHSA-j3cx-fj78-gw65/GHSA-j3cx-fj78-gw65.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j3cx-fj78-gw65", - "modified": "2024-08-23T15:30:34Z", + "modified": "2024-08-23T18:33:01Z", "published": "2024-08-23T15:30:34Z", "aliases": [ "CVE-2024-42765" ], "details": "A SQL injection vulnerability in \"/login.php\" of the Kashipara Bus Ticket Reservation System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login via the \"email\" or \"password\" Login page parameters.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-23T15:15:16Z" diff --git a/advisories/unreviewed/2024/08/GHSA-j7cx-qx73-9wxc/GHSA-j7cx-qx73-9wxc.json b/advisories/unreviewed/2024/08/GHSA-j7cx-qx73-9wxc/GHSA-j7cx-qx73-9wxc.json index 04701f6d570..69243e0b33a 100644 --- a/advisories/unreviewed/2024/08/GHSA-j7cx-qx73-9wxc/GHSA-j7cx-qx73-9wxc.json +++ b/advisories/unreviewed/2024/08/GHSA-j7cx-qx73-9wxc/GHSA-j7cx-qx73-9wxc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j7cx-qx73-9wxc", - "modified": "2024-08-21T15:30:53Z", + "modified": "2024-08-23T18:32:59Z", "published": "2024-08-21T15:30:53Z", "aliases": [ "CVE-2020-11850" @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-79" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-j7f9-7qqh-2rxf/GHSA-j7f9-7qqh-2rxf.json b/advisories/unreviewed/2024/08/GHSA-j7f9-7qqh-2rxf/GHSA-j7f9-7qqh-2rxf.json index 8ba1337f22a..727bf67408e 100644 --- a/advisories/unreviewed/2024/08/GHSA-j7f9-7qqh-2rxf/GHSA-j7f9-7qqh-2rxf.json +++ b/advisories/unreviewed/2024/08/GHSA-j7f9-7qqh-2rxf/GHSA-j7f9-7qqh-2rxf.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j7f9-7qqh-2rxf", - "modified": "2024-08-12T15:30:48Z", + "modified": "2024-08-23T18:32:59Z", "published": "2024-08-12T15:30:48Z", "aliases": [ "CVE-2024-21879" ], "details": "Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability through an url parameter of an authenticated enpoint in Enphase IQ Gateway (formerly known as Envoy) allows OS Command Injection.This issue affects Envoy: from 4.x to 8.x and < 8.2.4225.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:I/V:C/RE:H/U:X" @@ -36,7 +40,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-j99w-m756-f646/GHSA-j99w-m756-f646.json b/advisories/unreviewed/2024/08/GHSA-j99w-m756-f646/GHSA-j99w-m756-f646.json new file mode 100644 index 00000000000..24fbca1aec8 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-j99w-m756-f646/GHSA-j99w-m756-f646.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j99w-m756-f646", + "modified": "2024-08-23T18:33:02Z", + "published": "2024-08-23T18:33:02Z", + "aliases": [ + "CVE-2024-41842" + ], + "details": "Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41842" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-28.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T17:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-jj85-4qm9-xvwg/GHSA-jj85-4qm9-xvwg.json b/advisories/unreviewed/2024/08/GHSA-jj85-4qm9-xvwg/GHSA-jj85-4qm9-xvwg.json new file mode 100644 index 00000000000..869d1c22544 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-jj85-4qm9-xvwg/GHSA-jj85-4qm9-xvwg.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jj85-4qm9-xvwg", + "modified": "2024-08-23T18:33:01Z", + "published": "2024-08-23T18:33:01Z", + "aliases": [ + "CVE-2024-42523" + ], + "details": "publiccms V4.0.202302.e and before is vulnerable to Any File Upload via publiccms/admin/cmsTemplate/saveMetaData", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42523" + }, + { + "type": "WEB", + "url": "https://gist.github.com/ilikeoyt/3dbbca2679c2551eaaeaea9c83acf1a1" + }, + { + "type": "WEB", + "url": "https://gitee.com/sanluan/PublicCMS/issues/IADVDM" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T16:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-m3fh-qqv6-hgxx/GHSA-m3fh-qqv6-hgxx.json b/advisories/unreviewed/2024/08/GHSA-m3fh-qqv6-hgxx/GHSA-m3fh-qqv6-hgxx.json index 0a0e6f2f303..7b15ec6ab88 100644 --- a/advisories/unreviewed/2024/08/GHSA-m3fh-qqv6-hgxx/GHSA-m3fh-qqv6-hgxx.json +++ b/advisories/unreviewed/2024/08/GHSA-m3fh-qqv6-hgxx/GHSA-m3fh-qqv6-hgxx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m3fh-qqv6-hgxx", - "modified": "2024-08-22T09:30:32Z", + "modified": "2024-08-23T18:33:00Z", "published": "2024-08-22T09:30:32Z", "aliases": [ "CVE-2024-42411" diff --git a/advisories/unreviewed/2024/08/GHSA-m59m-755q-5h2m/GHSA-m59m-755q-5h2m.json b/advisories/unreviewed/2024/08/GHSA-m59m-755q-5h2m/GHSA-m59m-755q-5h2m.json index d03667e0b5a..4826892d696 100644 --- a/advisories/unreviewed/2024/08/GHSA-m59m-755q-5h2m/GHSA-m59m-755q-5h2m.json +++ b/advisories/unreviewed/2024/08/GHSA-m59m-755q-5h2m/GHSA-m59m-755q-5h2m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m59m-755q-5h2m", - "modified": "2024-08-22T21:31:29Z", + "modified": "2024-08-23T18:33:00Z", "published": "2024-08-22T21:31:29Z", "aliases": [ "CVE-2024-42761" ], "details": "A Stored Cross Site Scripting (XSS) vulnerability was found in \"/admin_schedule.php\" in Kashipara Bus Ticket Reservation System v1.0, which allows remote attackers to execute arbitrary code via scheduleDurationPHP parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-22T21:15:17Z" diff --git a/advisories/unreviewed/2024/08/GHSA-m99q-r6r6-wxx3/GHSA-m99q-r6r6-wxx3.json b/advisories/unreviewed/2024/08/GHSA-m99q-r6r6-wxx3/GHSA-m99q-r6r6-wxx3.json index 1ccd7b08798..8589877f24e 100644 --- a/advisories/unreviewed/2024/08/GHSA-m99q-r6r6-wxx3/GHSA-m99q-r6r6-wxx3.json +++ b/advisories/unreviewed/2024/08/GHSA-m99q-r6r6-wxx3/GHSA-m99q-r6r6-wxx3.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1333", "CWE-400" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/08/GHSA-p4hm-hcqj-m7g5/GHSA-p4hm-hcqj-m7g5.json b/advisories/unreviewed/2024/08/GHSA-p4hm-hcqj-m7g5/GHSA-p4hm-hcqj-m7g5.json new file mode 100644 index 00000000000..4ddf0c5703b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-p4hm-hcqj-m7g5/GHSA-p4hm-hcqj-m7g5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p4hm-hcqj-m7g5", + "modified": "2024-08-23T18:33:03Z", + "published": "2024-08-23T18:33:03Z", + "aliases": [ + "CVE-2024-7428" + ], + "details": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in OpenText™ Network Node Manager i (NNMi) allows URL Redirector Abuse.This issue affects Network Node Manager i (NNMi): 2022.11, 2023.05, 23.4, 24.2.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:A/V:C/RE:L/U:Red" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7428" + }, + { + "type": "WEB", + "url": "https://portal.microfocus.com/s/article/KM000033015?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-pr8m-g3mq-j9w6/GHSA-pr8m-g3mq-j9w6.json b/advisories/unreviewed/2024/08/GHSA-pr8m-g3mq-j9w6/GHSA-pr8m-g3mq-j9w6.json new file mode 100644 index 00000000000..b8c384ee6fa --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-pr8m-g3mq-j9w6/GHSA-pr8m-g3mq-j9w6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pr8m-g3mq-j9w6", + "modified": "2024-08-23T18:33:03Z", + "published": "2024-08-23T18:33:02Z", + "aliases": [ + "CVE-2024-41875" + ], + "details": "Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41875" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-28.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-q8cw-c873-9xh2/GHSA-q8cw-c873-9xh2.json b/advisories/unreviewed/2024/08/GHSA-q8cw-c873-9xh2/GHSA-q8cw-c873-9xh2.json new file mode 100644 index 00000000000..91aba3dee98 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-q8cw-c873-9xh2/GHSA-q8cw-c873-9xh2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q8cw-c873-9xh2", + "modified": "2024-08-23T18:33:03Z", + "published": "2024-08-23T18:33:02Z", + "aliases": [ + "CVE-2024-41847" + ], + "details": "Adobe Experience Manager versions 6.5.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41847" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-28.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-q98g-hxg3-268c/GHSA-q98g-hxg3-268c.json b/advisories/unreviewed/2024/08/GHSA-q98g-hxg3-268c/GHSA-q98g-hxg3-268c.json index 33586a7753d..85739f0c25b 100644 --- a/advisories/unreviewed/2024/08/GHSA-q98g-hxg3-268c/GHSA-q98g-hxg3-268c.json +++ b/advisories/unreviewed/2024/08/GHSA-q98g-hxg3-268c/GHSA-q98g-hxg3-268c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q98g-hxg3-268c", - "modified": "2024-08-22T21:31:29Z", + "modified": "2024-08-23T18:33:00Z", "published": "2024-08-22T21:31:29Z", "aliases": [ "CVE-2024-8088" @@ -45,6 +45,10 @@ "type": "WEB", "url": "https://github.com/python/cpython/commit/dcc5182f27c1500006a1ef78e10613bb45788dea" }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/e0264a61119d551658d9445af38323ba94fc16db" + }, { "type": "WEB", "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/GNFCKVI4TCATKQLALJ5SN4L4CSPSMILU" diff --git a/advisories/unreviewed/2024/08/GHSA-qgvg-8hq5-mx9m/GHSA-qgvg-8hq5-mx9m.json b/advisories/unreviewed/2024/08/GHSA-qgvg-8hq5-mx9m/GHSA-qgvg-8hq5-mx9m.json new file mode 100644 index 00000000000..372ed2c402a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-qgvg-8hq5-mx9m/GHSA-qgvg-8hq5-mx9m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qgvg-8hq5-mx9m", + "modified": "2024-08-23T18:33:03Z", + "published": "2024-08-23T18:33:03Z", + "aliases": [ + "CVE-2024-41876" + ], + "details": "Adobe Experience Manager versions 6.5.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41876" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-28.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-r6rr-3664-gq2w/GHSA-r6rr-3664-gq2w.json b/advisories/unreviewed/2024/08/GHSA-r6rr-3664-gq2w/GHSA-r6rr-3664-gq2w.json new file mode 100644 index 00000000000..bb36ad92e1e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-r6rr-3664-gq2w/GHSA-r6rr-3664-gq2w.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r6rr-3664-gq2w", + "modified": "2024-08-23T18:33:02Z", + "published": "2024-08-23T18:33:02Z", + "aliases": [ + "CVE-2024-44382" + ], + "details": "D-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in the jhttpd upgrade_filter_asp function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44382" + }, + { + "type": "WEB", + "url": "https://github.com/GroundCTL2MajorTom/pocs/blob/main/dlink_DI8004W.md" + }, + { + "type": "WEB", + "url": "https://www.dlink.com/en/security-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-r7m6-x679-p3mh/GHSA-r7m6-x679-p3mh.json b/advisories/unreviewed/2024/08/GHSA-r7m6-x679-p3mh/GHSA-r7m6-x679-p3mh.json new file mode 100644 index 00000000000..31db30a618e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-r7m6-x679-p3mh/GHSA-r7m6-x679-p3mh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r7m6-x679-p3mh", + "modified": "2024-08-23T18:33:02Z", + "published": "2024-08-23T18:33:01Z", + "aliases": [ + "CVE-2024-43032" + ], + "details": "autMan v2.9.6 allows attackers to bypass authentication via a crafted web request.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43032" + }, + { + "type": "WEB", + "url": "https://github.com/hdbjlizhe/fanli/releases/tag/2.9.6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T16:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-r936-6588-v9v4/GHSA-r936-6588-v9v4.json b/advisories/unreviewed/2024/08/GHSA-r936-6588-v9v4/GHSA-r936-6588-v9v4.json new file mode 100644 index 00000000000..722ab3d5c27 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-r936-6588-v9v4/GHSA-r936-6588-v9v4.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r936-6588-v9v4", + "modified": "2024-08-23T18:33:03Z", + "published": "2024-08-23T18:33:03Z", + "aliases": [ + "CVE-2024-42918" + ], + "details": "itsourcecode Online Accreditation Management System contains a Cross Site Scripting vulnerability, which allows an attacker to execute arbitrary code via a crafted payload to the SCHOOLNAME, EMAILADDRES, CONTACTNO, COMPANYNAME and COMPANYCONTACTNO parameters in controller.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42918" + }, + { + "type": "WEB", + "url": "https://github.com/n00bS3cLe4rner/CVE-s/blob/main/CVE-2024-42918.md" + }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-v6x2-q2r8-qg76/GHSA-v6x2-q2r8-qg76.json b/advisories/unreviewed/2024/08/GHSA-v6x2-q2r8-qg76/GHSA-v6x2-q2r8-qg76.json index 59f6e8f8c49..a38f278c22b 100644 --- a/advisories/unreviewed/2024/08/GHSA-v6x2-q2r8-qg76/GHSA-v6x2-q2r8-qg76.json +++ b/advisories/unreviewed/2024/08/GHSA-v6x2-q2r8-qg76/GHSA-v6x2-q2r8-qg76.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v6x2-q2r8-qg76", - "modified": "2024-08-12T15:30:48Z", + "modified": "2024-08-23T18:32:59Z", "published": "2024-08-12T15:30:48Z", "aliases": [ "CVE-2023-50810" ], "details": "In certain Sonos products before Sonos S1 Release 11.12 and S2 release 15.9, a vulnerability exists in the U-Boot component of the firmware that allow persistent arbitrary code execution with Linux kernel privileges. A failure to correctly handle the return value of the setenv command can be used to override the kernel command-line parameters and ultimately bypass the Secure Boot implementation. This affects PLAY5 gen 2, PLAYBASE, PLAY:1, One, One SL, and Amp.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-12T13:38:12Z" diff --git a/advisories/unreviewed/2024/08/GHSA-vcg9-h624-c2c9/GHSA-vcg9-h624-c2c9.json b/advisories/unreviewed/2024/08/GHSA-vcg9-h624-c2c9/GHSA-vcg9-h624-c2c9.json new file mode 100644 index 00000000000..3f6274bc9ef --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-vcg9-h624-c2c9/GHSA-vcg9-h624-c2c9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vcg9-h624-c2c9", + "modified": "2024-08-23T18:33:03Z", + "published": "2024-08-23T18:33:03Z", + "aliases": [ + "CVE-2024-41849" + ], + "details": "Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Input Validation vulnerability that could lead to a security feature bypass. An low-privileged attacker could leverage this vulnerability to slightly affect the integrity of the page. Exploitation of this issue requires user interaction and scope is changed.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41849" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-28.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-vcw3-hwj8-8j82/GHSA-vcw3-hwj8-8j82.json b/advisories/unreviewed/2024/08/GHSA-vcw3-hwj8-8j82/GHSA-vcw3-hwj8-8j82.json new file mode 100644 index 00000000000..ff93adc46b9 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-vcw3-hwj8-8j82/GHSA-vcw3-hwj8-8j82.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vcw3-hwj8-8j82", + "modified": "2024-08-23T18:33:02Z", + "published": "2024-08-23T18:33:02Z", + "aliases": [ + "CVE-2024-33854" + ], + "details": "A SQL Injection vulnerability exists in the Graph Template component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33854" + }, + { + "type": "WEB", + "url": "https://github.com/centreon/centreon/releases" + }, + { + "type": "WEB", + "url": "https://thewatch.centreon.com/latest-security-bulletins-64/security-bulletin-for-centreon-web-3744" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T17:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-vq36-rf43-jmh7/GHSA-vq36-rf43-jmh7.json b/advisories/unreviewed/2024/08/GHSA-vq36-rf43-jmh7/GHSA-vq36-rf43-jmh7.json new file mode 100644 index 00000000000..922bc7ef7d5 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-vq36-rf43-jmh7/GHSA-vq36-rf43-jmh7.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vq36-rf43-jmh7", + "modified": "2024-08-23T18:33:03Z", + "published": "2024-08-23T18:33:03Z", + "aliases": [ + "CVE-2024-42992" + ], + "details": "Python Pip Pandas v2.2.2 was discovered to contain an arbitrary file read vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42992" + }, + { + "type": "WEB", + "url": "https://github.com/juwenyi/CVE-2024-42992" + }, + { + "type": "WEB", + "url": "https://pandas.pydata.org" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T18:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-w57x-f5pm-84r5/GHSA-w57x-f5pm-84r5.json b/advisories/unreviewed/2024/08/GHSA-w57x-f5pm-84r5/GHSA-w57x-f5pm-84r5.json index 97b07422367..b903131d0de 100644 --- a/advisories/unreviewed/2024/08/GHSA-w57x-f5pm-84r5/GHSA-w57x-f5pm-84r5.json +++ b/advisories/unreviewed/2024/08/GHSA-w57x-f5pm-84r5/GHSA-w57x-f5pm-84r5.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-w96m-rw5m-pf44/GHSA-w96m-rw5m-pf44.json b/advisories/unreviewed/2024/08/GHSA-w96m-rw5m-pf44/GHSA-w96m-rw5m-pf44.json index e5241337dbc..336348ce77e 100644 --- a/advisories/unreviewed/2024/08/GHSA-w96m-rw5m-pf44/GHSA-w96m-rw5m-pf44.json +++ b/advisories/unreviewed/2024/08/GHSA-w96m-rw5m-pf44/GHSA-w96m-rw5m-pf44.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w96m-rw5m-pf44", - "modified": "2024-08-12T15:30:49Z", + "modified": "2024-08-23T18:32:59Z", "published": "2024-08-12T15:30:48Z", "aliases": [ "CVE-2024-21877" ], "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability through a url parameter in Enphase IQ Gateway (formerly known as Envoy) allows File Manipulation. The endpoint requires authentication.This issue affects Envoy: from 4.x to 8.0 and < 8.2.4225.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:I/V:C/RE:H/U:X" diff --git a/advisories/unreviewed/2024/08/GHSA-wpjv-3phj-f64x/GHSA-wpjv-3phj-f64x.json b/advisories/unreviewed/2024/08/GHSA-wpjv-3phj-f64x/GHSA-wpjv-3phj-f64x.json index e43a303b42e..818155bc377 100644 --- a/advisories/unreviewed/2024/08/GHSA-wpjv-3phj-f64x/GHSA-wpjv-3phj-f64x.json +++ b/advisories/unreviewed/2024/08/GHSA-wpjv-3phj-f64x/GHSA-wpjv-3phj-f64x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wpjv-3phj-f64x", - "modified": "2024-08-02T21:31:34Z", + "modified": "2024-08-23T18:32:59Z", "published": "2024-08-02T21:31:34Z", "aliases": [ "CVE-2024-28298" ], "details": "SQL injection vulnerability in BM SOFT BMPlanning 1.0.0.1 allows authenticated users to execute arbitrary SQL commands via the SEC_IDF, LIE_IDF, PLANF_IDF, CLI_IDF, DOS_IDF, and possibly other parameters to /BMServerR.dll/BMRest.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:L" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-02T19:16:30Z" diff --git a/advisories/unreviewed/2024/08/GHSA-wqgx-27v7-cr9h/GHSA-wqgx-27v7-cr9h.json b/advisories/unreviewed/2024/08/GHSA-wqgx-27v7-cr9h/GHSA-wqgx-27v7-cr9h.json new file mode 100644 index 00000000000..30913bfecfd --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-wqgx-27v7-cr9h/GHSA-wqgx-27v7-cr9h.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wqgx-27v7-cr9h", + "modified": "2024-08-23T18:33:03Z", + "published": "2024-08-23T18:33:03Z", + "aliases": [ + "CVE-2024-42531" + ], + "details": "Ezviz Internet PT Camera CS-CV246 D15655150 allows an unauthenticated host to access its live video stream by crafting a set of RTSP packets with a specific set of URLs that can be used to redirect the camera feed.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42531" + }, + { + "type": "WEB", + "url": "https://github.com/Anonymous120386/Anonymous" + }, + { + "type": "WEB", + "url": "http://ezviz.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-23T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-wwmm-864r-f54x/GHSA-wwmm-864r-f54x.json b/advisories/unreviewed/2024/08/GHSA-wwmm-864r-f54x/GHSA-wwmm-864r-f54x.json index d5e8d96392b..ff53a5e5a23 100644 --- a/advisories/unreviewed/2024/08/GHSA-wwmm-864r-f54x/GHSA-wwmm-864r-f54x.json +++ b/advisories/unreviewed/2024/08/GHSA-wwmm-864r-f54x/GHSA-wwmm-864r-f54x.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wwmm-864r-f54x", - "modified": "2024-08-12T15:30:48Z", + "modified": "2024-08-23T18:32:59Z", "published": "2024-08-12T15:30:48Z", "aliases": [ "CVE-2024-21876" ], "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability via a URL parameter in Enphase IQ Gateway (formerly known as Envoy) allows an unautheticated attacker to access or create arbitratry files.This issue affects Envoy: from 4.x to 8.x and < 8.2.4225.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:X/V:D/RE:H/U:X"