diff --git a/advisories/unreviewed/2024/06/GHSA-22f8-6qq6-p38x/GHSA-22f8-6qq6-p38x.json b/advisories/unreviewed/2024/06/GHSA-22f8-6qq6-p38x/GHSA-22f8-6qq6-p38x.json index 2e5f591d8e1..a24d9d31e93 100644 --- a/advisories/unreviewed/2024/06/GHSA-22f8-6qq6-p38x/GHSA-22f8-6qq6-p38x.json +++ b/advisories/unreviewed/2024/06/GHSA-22f8-6qq6-p38x/GHSA-22f8-6qq6-p38x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-22f8-6qq6-p38x", - "modified": "2024-06-22T00:30:56Z", + "modified": "2024-07-03T18:46:20Z", "published": "2024-06-22T00:30:56Z", "aliases": [ "CVE-2014-5470" ], "details": "Actual Analyzer through 2014-08-29 allows code execution via shell metacharacters because untrusted input is used for part of the input data passed to an eval operation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-21T22:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-252v-9w3r-w4vm/GHSA-252v-9w3r-w4vm.json b/advisories/unreviewed/2024/06/GHSA-252v-9w3r-w4vm/GHSA-252v-9w3r-w4vm.json index 492a60f6d6c..10e5cd518b7 100644 --- a/advisories/unreviewed/2024/06/GHSA-252v-9w3r-w4vm/GHSA-252v-9w3r-w4vm.json +++ b/advisories/unreviewed/2024/06/GHSA-252v-9w3r-w4vm/GHSA-252v-9w3r-w4vm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-252v-9w3r-w4vm", - "modified": "2024-06-25T06:30:39Z", + "modified": "2024-07-03T18:46:56Z", "published": "2024-06-25T06:30:39Z", "aliases": [ "CVE-2024-4757" ], "details": "The Logo Manager For Enamad WordPress plugin through 0.7.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-25T06:15:11Z" diff --git a/advisories/unreviewed/2024/06/GHSA-2g4v-8vvw-r8m9/GHSA-2g4v-8vvw-r8m9.json b/advisories/unreviewed/2024/06/GHSA-2g4v-8vvw-r8m9/GHSA-2g4v-8vvw-r8m9.json index 07627784dfc..15765117b63 100644 --- a/advisories/unreviewed/2024/06/GHSA-2g4v-8vvw-r8m9/GHSA-2g4v-8vvw-r8m9.json +++ b/advisories/unreviewed/2024/06/GHSA-2g4v-8vvw-r8m9/GHSA-2g4v-8vvw-r8m9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2g4v-8vvw-r8m9", - "modified": "2024-06-26T21:32:18Z", + "modified": "2024-07-03T18:47:04Z", "published": "2024-06-26T21:32:18Z", "aliases": [ "CVE-2024-39243" ], "details": "An issue discovered in skycaiji 2.8 allows attackers to run arbitrary code via crafted POST request to /index.php?s=/admin/develop/editor_save.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-75" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-26T20:15:16Z" diff --git a/advisories/unreviewed/2024/06/GHSA-2vx6-mxq6-c2rw/GHSA-2vx6-mxq6-c2rw.json b/advisories/unreviewed/2024/06/GHSA-2vx6-mxq6-c2rw/GHSA-2vx6-mxq6-c2rw.json index 28bb82191e1..5e42aa3a0d5 100644 --- a/advisories/unreviewed/2024/06/GHSA-2vx6-mxq6-c2rw/GHSA-2vx6-mxq6-c2rw.json +++ b/advisories/unreviewed/2024/06/GHSA-2vx6-mxq6-c2rw/GHSA-2vx6-mxq6-c2rw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2vx6-mxq6-c2rw", - "modified": "2024-06-21T12:31:20Z", + "modified": "2024-07-03T18:46:19Z", "published": "2024-06-21T12:31:20Z", "aliases": [ "CVE-2024-38623" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: Use variable length array instead of fixed size\n\nShould fix smatch warning:\n\tntfs_set_label() error: __builtin_memcpy() 'uni->name' too small (20 vs 256)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-129" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-21T11:15:11Z" diff --git a/advisories/unreviewed/2024/06/GHSA-34x7-h5wm-79jf/GHSA-34x7-h5wm-79jf.json b/advisories/unreviewed/2024/06/GHSA-34x7-h5wm-79jf/GHSA-34x7-h5wm-79jf.json index 9e429639b84..988e6797e62 100644 --- a/advisories/unreviewed/2024/06/GHSA-34x7-h5wm-79jf/GHSA-34x7-h5wm-79jf.json +++ b/advisories/unreviewed/2024/06/GHSA-34x7-h5wm-79jf/GHSA-34x7-h5wm-79jf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-34x7-h5wm-79jf", - "modified": "2024-06-26T21:32:16Z", + "modified": "2024-07-03T18:47:02Z", "published": "2024-06-26T21:32:16Z", "aliases": [ "CVE-2024-33327" ], "details": "A cross-site scripting (XSS) vulnerability in the component UrlAccessibilityEvaluation.jsp of Lumisxp v15.0.x to v16.1.x allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the contentHtml parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-26T19:15:13Z" diff --git a/advisories/unreviewed/2024/06/GHSA-354c-38ff-3cw6/GHSA-354c-38ff-3cw6.json b/advisories/unreviewed/2024/06/GHSA-354c-38ff-3cw6/GHSA-354c-38ff-3cw6.json index bcb09d580c6..33d2d846d8c 100644 --- a/advisories/unreviewed/2024/06/GHSA-354c-38ff-3cw6/GHSA-354c-38ff-3cw6.json +++ b/advisories/unreviewed/2024/06/GHSA-354c-38ff-3cw6/GHSA-354c-38ff-3cw6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-354c-38ff-3cw6", - "modified": "2024-06-25T03:31:07Z", + "modified": "2024-07-03T18:46:48Z", "published": "2024-06-25T03:31:07Z", "aliases": [ "CVE-2024-37002" ], "details": "A maliciously crafted MODEL file, when parsed in ASMkern229A.dllthrough Autodesk applications, can be used to uninitialized variables. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-457" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-25T03:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-372p-q8pm-xrrr/GHSA-372p-q8pm-xrrr.json b/advisories/unreviewed/2024/06/GHSA-372p-q8pm-xrrr/GHSA-372p-q8pm-xrrr.json index 16c10645576..59d15996a17 100644 --- a/advisories/unreviewed/2024/06/GHSA-372p-q8pm-xrrr/GHSA-372p-q8pm-xrrr.json +++ b/advisories/unreviewed/2024/06/GHSA-372p-q8pm-xrrr/GHSA-372p-q8pm-xrrr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-372p-q8pm-xrrr", - "modified": "2024-06-24T21:33:21Z", + "modified": "2024-07-03T18:46:35Z", "published": "2024-06-24T21:33:21Z", "aliases": [ "CVE-2024-38897" ], "details": "WAVLINK WN551K1'live_check.shtml enables attackers to obtain sensitive router information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-202" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-24T21:15:26Z" diff --git a/advisories/unreviewed/2024/06/GHSA-37hm-8cwf-jp7f/GHSA-37hm-8cwf-jp7f.json b/advisories/unreviewed/2024/06/GHSA-37hm-8cwf-jp7f/GHSA-37hm-8cwf-jp7f.json index 3b835ce8e28..da547b35339 100644 --- a/advisories/unreviewed/2024/06/GHSA-37hm-8cwf-jp7f/GHSA-37hm-8cwf-jp7f.json +++ b/advisories/unreviewed/2024/06/GHSA-37hm-8cwf-jp7f/GHSA-37hm-8cwf-jp7f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-37hm-8cwf-jp7f", - "modified": "2024-06-25T03:31:07Z", + "modified": "2024-07-03T18:46:47Z", "published": "2024-06-25T03:31:07Z", "aliases": [ "CVE-2024-37001" ], "details": "[A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk applications, can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-122" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-25T03:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-3fjc-pjgm-cw7f/GHSA-3fjc-pjgm-cw7f.json b/advisories/unreviewed/2024/06/GHSA-3fjc-pjgm-cw7f/GHSA-3fjc-pjgm-cw7f.json index 16e8f05ab19..42006e597fa 100644 --- a/advisories/unreviewed/2024/06/GHSA-3fjc-pjgm-cw7f/GHSA-3fjc-pjgm-cw7f.json +++ b/advisories/unreviewed/2024/06/GHSA-3fjc-pjgm-cw7f/GHSA-3fjc-pjgm-cw7f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3fjc-pjgm-cw7f", - "modified": "2024-06-24T21:33:21Z", + "modified": "2024-07-03T18:46:33Z", "published": "2024-06-24T21:33:21Z", "aliases": [ "CVE-2024-37678" ], "details": "Cross Site Scripting vulnerability in Hangzhou Meisoft Information Technology Co., Ltd. Finesoft v.8.0 and before allows a remote attacker to execute arbitrary code via a crafted script.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-24T20:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-3w26-g558-6q3x/GHSA-3w26-g558-6q3x.json b/advisories/unreviewed/2024/06/GHSA-3w26-g558-6q3x/GHSA-3w26-g558-6q3x.json index 441a986d21d..08d8b9dad2b 100644 --- a/advisories/unreviewed/2024/06/GHSA-3w26-g558-6q3x/GHSA-3w26-g558-6q3x.json +++ b/advisories/unreviewed/2024/06/GHSA-3w26-g558-6q3x/GHSA-3w26-g558-6q3x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3w26-g558-6q3x", - "modified": "2024-06-27T06:32:47Z", + "modified": "2024-07-03T18:47:04Z", "published": "2024-06-27T06:32:47Z", "aliases": [ "CVE-2024-4704" ], "details": "The Contact Form 7 WordPress plugin before 5.9.5 has an open redirect that allows an attacker to utilize a false URL and redirect to the URL of their choosing.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-601" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-27T06:15:14Z" diff --git a/advisories/unreviewed/2024/06/GHSA-3x3g-7ggq-rm95/GHSA-3x3g-7ggq-rm95.json b/advisories/unreviewed/2024/06/GHSA-3x3g-7ggq-rm95/GHSA-3x3g-7ggq-rm95.json index 1014ced9ca8..1562302bdb8 100644 --- a/advisories/unreviewed/2024/06/GHSA-3x3g-7ggq-rm95/GHSA-3x3g-7ggq-rm95.json +++ b/advisories/unreviewed/2024/06/GHSA-3x3g-7ggq-rm95/GHSA-3x3g-7ggq-rm95.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3x3g-7ggq-rm95", - "modified": "2024-06-25T03:31:07Z", + "modified": "2024-07-03T18:46:47Z", "published": "2024-06-25T03:31:07Z", "aliases": [ "CVE-2024-23144" ], "details": "A maliciously crafted CATPART file, when parsed in CC5Dll.dll and ASMBASE228A.dll through Autodesk applications, can force an Out-of-Bound Write. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-25T02:15:11Z" diff --git a/advisories/unreviewed/2024/06/GHSA-3x55-2c2w-5c9f/GHSA-3x55-2c2w-5c9f.json b/advisories/unreviewed/2024/06/GHSA-3x55-2c2w-5c9f/GHSA-3x55-2c2w-5c9f.json index fe4b6189003..ae9eaba1e10 100644 --- a/advisories/unreviewed/2024/06/GHSA-3x55-2c2w-5c9f/GHSA-3x55-2c2w-5c9f.json +++ b/advisories/unreviewed/2024/06/GHSA-3x55-2c2w-5c9f/GHSA-3x55-2c2w-5c9f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3x55-2c2w-5c9f", - "modified": "2024-06-24T21:33:21Z", + "modified": "2024-07-03T18:46:35Z", "published": "2024-06-24T21:33:21Z", "aliases": [ "CVE-2024-38892" ], "details": "An issue in Wavlink WN551K1 allows a remote attacker to obtain sensitive information via the ExportAllSettings.sh component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-202" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-24T21:15:26Z" diff --git a/advisories/unreviewed/2024/06/GHSA-489p-q5cq-r62h/GHSA-489p-q5cq-r62h.json b/advisories/unreviewed/2024/06/GHSA-489p-q5cq-r62h/GHSA-489p-q5cq-r62h.json index a3e1054d001..8dab23524ab 100644 --- a/advisories/unreviewed/2024/06/GHSA-489p-q5cq-r62h/GHSA-489p-q5cq-r62h.json +++ b/advisories/unreviewed/2024/06/GHSA-489p-q5cq-r62h/GHSA-489p-q5cq-r62h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-489p-q5cq-r62h", - "modified": "2024-06-25T06:30:39Z", + "modified": "2024-07-03T18:46:52Z", "published": "2024-06-25T06:30:39Z", "aliases": [ "CVE-2024-23158" ], "details": "A maliciously crafted IGES file, when parsed in ASMImport229A.dll through Autodesk applications, can be used to cause a use-after-free vulnerability. A malicious actor can leverage this vulnerability to cause a crash or execute arbitrary code in the context of the current process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-25T04:15:14Z" diff --git a/advisories/unreviewed/2024/06/GHSA-4cqv-cv9m-26q8/GHSA-4cqv-cv9m-26q8.json b/advisories/unreviewed/2024/06/GHSA-4cqv-cv9m-26q8/GHSA-4cqv-cv9m-26q8.json index d4ffc70e7f0..0280556cab2 100644 --- a/advisories/unreviewed/2024/06/GHSA-4cqv-cv9m-26q8/GHSA-4cqv-cv9m-26q8.json +++ b/advisories/unreviewed/2024/06/GHSA-4cqv-cv9m-26q8/GHSA-4cqv-cv9m-26q8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4cqv-cv9m-26q8", - "modified": "2024-06-26T21:32:18Z", + "modified": "2024-07-03T18:47:04Z", "published": "2024-06-26T21:32:18Z", "aliases": [ "CVE-2024-23766" ], "details": "An issue was discovered on HMS Anybus X-Gateway AB7832-F 3 devices. The gateway exposes a web interface on port 80. An unauthenticated GET request to a specific URL triggers the reboot of the Anybus gateway (or at least most of its modules). An attacker can use this feature to carry out a denial of service attack by continuously sending GET requests to that URL.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-598" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-26T21:15:12Z" diff --git a/advisories/unreviewed/2024/06/GHSA-4fc7-mvrr-wv2c/GHSA-4fc7-mvrr-wv2c.json b/advisories/unreviewed/2024/06/GHSA-4fc7-mvrr-wv2c/GHSA-4fc7-mvrr-wv2c.json index bc9be0a6142..59fe67733a7 100644 --- a/advisories/unreviewed/2024/06/GHSA-4fc7-mvrr-wv2c/GHSA-4fc7-mvrr-wv2c.json +++ b/advisories/unreviewed/2024/06/GHSA-4fc7-mvrr-wv2c/GHSA-4fc7-mvrr-wv2c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4fc7-mvrr-wv2c", - "modified": "2024-06-29T06:31:39Z", + "modified": "2024-07-03T18:47:04Z", "published": "2024-06-27T12:30:48Z", "aliases": [ "CVE-2024-5535" ], "details": "Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an\nempty supported client protocols buffer may cause a crash or memory contents to\nbe sent to the peer.\n\nImpact summary: A buffer overread can have a range of potential consequences\nsuch as unexpected application beahviour or a crash. In particular this issue\ncould result in up to 255 bytes of arbitrary private data from memory being sent\nto the peer leading to a loss of confidentiality. However, only applications\nthat directly call the SSL_select_next_proto function with a 0 length list of\nsupported client protocols are affected by this issue. This would normally never\nbe a valid scenario and is typically not under attacker control but may occur by\naccident in the case of a configuration or programming error in the calling\napplication.\n\nThe OpenSSL API function SSL_select_next_proto is typically used by TLS\napplications that support ALPN (Application Layer Protocol Negotiation) or NPN\n(Next Protocol Negotiation). NPN is older, was never standardised and\nis deprecated in favour of ALPN. We believe that ALPN is significantly more\nwidely deployed than NPN. The SSL_select_next_proto function accepts a list of\nprotocols from the server and a list of protocols from the client and returns\nthe first protocol that appears in the server list that also appears in the\nclient list. In the case of no overlap between the two lists it returns the\nfirst item in the client list. In either case it will signal whether an overlap\nbetween the two lists was found. In the case where SSL_select_next_proto is\ncalled with a zero length client list it fails to notice this condition and\nreturns the memory immediately following the client list pointer (and reports\nthat there was no overlap in the lists).\n\nThis function is typically called from a server side application callback for\nALPN or a client side application callback for NPN. In the case of ALPN the list\nof protocols supplied by the client is guaranteed by libssl to never be zero in\nlength. The list of server protocols comes from the application and should never\nnormally be expected to be of zero length. In this case if the\nSSL_select_next_proto function has been called as expected (with the list\nsupplied by the client passed in the client/client_len parameters), then the\napplication will not be vulnerable to this issue. If the application has\naccidentally been configured with a zero length server list, and has\naccidentally passed that zero length server list in the client/client_len\nparameters, and has additionally failed to correctly handle a \"no overlap\"\nresponse (which would normally result in a handshake failure in ALPN) then it\nwill be vulnerable to this problem.\n\nIn the case of NPN, the protocol permits the client to opportunistically select\na protocol when there is no overlap. OpenSSL returns the first client protocol\nin the no overlap case in support of this. The list of client protocols comes\nfrom the application and should never normally be expected to be of zero length.\nHowever if the SSL_select_next_proto function is accidentally called with a\nclient_len of 0 then an invalid memory pointer will be returned instead. If the\napplication uses this output as the opportunistic protocol then the loss of\nconfidentiality will occur.\n\nThis issue has been assessed as Low severity because applications are most\nlikely to be vulnerable if they are using NPN instead of ALPN - but NPN is not\nwidely used. It also requires an application configuration or programming error.\nFinally, this issue would not typically be under attacker control making active\nexploitation unlikely.\n\nThe FIPS modules in 3.3, 3.2, 3.1 and 3.0 are not affected by this issue.\n\nDue to the low severity of this issue we are not issuing new releases of\nOpenSSL at this time. The fix will be included in the next releases when they\nbecome available.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -59,7 +62,7 @@ "cwe_ids": [ "CWE-200" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-27T11:15:24Z" diff --git a/advisories/unreviewed/2024/06/GHSA-4hgg-qgc6-rv76/GHSA-4hgg-qgc6-rv76.json b/advisories/unreviewed/2024/06/GHSA-4hgg-qgc6-rv76/GHSA-4hgg-qgc6-rv76.json index 0778f241035..c296eeb6692 100644 --- a/advisories/unreviewed/2024/06/GHSA-4hgg-qgc6-rv76/GHSA-4hgg-qgc6-rv76.json +++ b/advisories/unreviewed/2024/06/GHSA-4hgg-qgc6-rv76/GHSA-4hgg-qgc6-rv76.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4hgg-qgc6-rv76", - "modified": "2024-06-25T06:30:39Z", + "modified": "2024-07-03T18:46:50Z", "published": "2024-06-25T06:30:39Z", "aliases": [ "CVE-2024-23154" ], "details": "A maliciously crafted SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-122" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-25T04:15:13Z" diff --git a/advisories/unreviewed/2024/06/GHSA-4m8x-4m59-3q64/GHSA-4m8x-4m59-3q64.json b/advisories/unreviewed/2024/06/GHSA-4m8x-4m59-3q64/GHSA-4m8x-4m59-3q64.json index da518084aa4..8fb65d14b24 100644 --- a/advisories/unreviewed/2024/06/GHSA-4m8x-4m59-3q64/GHSA-4m8x-4m59-3q64.json +++ b/advisories/unreviewed/2024/06/GHSA-4m8x-4m59-3q64/GHSA-4m8x-4m59-3q64.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4m8x-4m59-3q64", - "modified": "2024-06-25T21:31:17Z", + "modified": "2024-07-03T18:46:57Z", "published": "2024-06-25T21:31:17Z", "aliases": [ "CVE-2024-21741" ], "details": "GigaDevice GD32E103C8T6 devices have Incorrect Access Control.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-25T21:15:57Z" diff --git a/advisories/unreviewed/2024/06/GHSA-4pj4-pm6x-xf9x/GHSA-4pj4-pm6x-xf9x.json b/advisories/unreviewed/2024/06/GHSA-4pj4-pm6x-xf9x/GHSA-4pj4-pm6x-xf9x.json index c51237506a6..4be4eaab277 100644 --- a/advisories/unreviewed/2024/06/GHSA-4pj4-pm6x-xf9x/GHSA-4pj4-pm6x-xf9x.json +++ b/advisories/unreviewed/2024/06/GHSA-4pj4-pm6x-xf9x/GHSA-4pj4-pm6x-xf9x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4pj4-pm6x-xf9x", - "modified": "2024-06-25T00:34:46Z", + "modified": "2024-07-03T18:46:40Z", "published": "2024-06-25T00:34:46Z", "aliases": [ "CVE-2023-50029" ], "details": "PHP Injection vulnerability in the module \"M4 PDF Extensions\" (m4pdf) up to version 3.3.2 from PrestaAddons for PrestaShop allows attackers to run arbitrary code via the M4PDF::saveTemplate() method.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-24T23:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-4w8c-j9fj-jw7x/GHSA-4w8c-j9fj-jw7x.json b/advisories/unreviewed/2024/06/GHSA-4w8c-j9fj-jw7x/GHSA-4w8c-j9fj-jw7x.json index 791a9d60902..a1eef8a5ec8 100644 --- a/advisories/unreviewed/2024/06/GHSA-4w8c-j9fj-jw7x/GHSA-4w8c-j9fj-jw7x.json +++ b/advisories/unreviewed/2024/06/GHSA-4w8c-j9fj-jw7x/GHSA-4w8c-j9fj-jw7x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4w8c-j9fj-jw7x", - "modified": "2024-06-25T03:31:07Z", + "modified": "2024-07-03T18:46:47Z", "published": "2024-06-25T03:31:07Z", "aliases": [ "CVE-2024-23143" ], "details": "A maliciously crafted 3DM, MODEL and X_B file, when parsed in ASMkern229A.dll and ASMBASE229A.dll through Autodesk applications, can force an Out-of-Bound Read and/or Out-of-Bound Write. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-25T02:15:11Z" diff --git a/advisories/unreviewed/2024/06/GHSA-549r-m25h-hvpx/GHSA-549r-m25h-hvpx.json b/advisories/unreviewed/2024/06/GHSA-549r-m25h-hvpx/GHSA-549r-m25h-hvpx.json index cf2bef2f4a7..0bd9a3db45c 100644 --- a/advisories/unreviewed/2024/06/GHSA-549r-m25h-hvpx/GHSA-549r-m25h-hvpx.json +++ b/advisories/unreviewed/2024/06/GHSA-549r-m25h-hvpx/GHSA-549r-m25h-hvpx.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-568c-mgmg-28q2/GHSA-568c-mgmg-28q2.json b/advisories/unreviewed/2024/06/GHSA-568c-mgmg-28q2/GHSA-568c-mgmg-28q2.json index 41f39503b7f..df1d0300138 100644 --- a/advisories/unreviewed/2024/06/GHSA-568c-mgmg-28q2/GHSA-568c-mgmg-28q2.json +++ b/advisories/unreviewed/2024/06/GHSA-568c-mgmg-28q2/GHSA-568c-mgmg-28q2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-568c-mgmg-28q2", - "modified": "2024-06-25T03:31:07Z", + "modified": "2024-07-03T18:46:47Z", "published": "2024-06-25T03:31:07Z", "aliases": [ "CVE-2024-23146" ], "details": "A maliciously crafted X_B and X_T file, when parsed in pskernel.DLL through Autodesk applications, can force an Out-of-Bound Write. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-25T03:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-5vq6-44f5-4pc9/GHSA-5vq6-44f5-4pc9.json b/advisories/unreviewed/2024/06/GHSA-5vq6-44f5-4pc9/GHSA-5vq6-44f5-4pc9.json index 9527689496f..6877284ab9f 100644 --- a/advisories/unreviewed/2024/06/GHSA-5vq6-44f5-4pc9/GHSA-5vq6-44f5-4pc9.json +++ b/advisories/unreviewed/2024/06/GHSA-5vq6-44f5-4pc9/GHSA-5vq6-44f5-4pc9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5vq6-44f5-4pc9", - "modified": "2024-06-25T00:34:46Z", + "modified": "2024-07-03T18:46:37Z", "published": "2024-06-25T00:34:46Z", "aliases": [ "CVE-2024-34991" ], "details": "In the module \"Axepta\" (axepta) before 1.3.4 from Quadra Informatique for PrestaShop, a guest can download partial credit card information (expiry date) / postal address / email / etc. without restriction due to a lack of permissions control.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-24T22:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-64v6-hr9r-33mx/GHSA-64v6-hr9r-33mx.json b/advisories/unreviewed/2024/06/GHSA-64v6-hr9r-33mx/GHSA-64v6-hr9r-33mx.json index 4ecb93388c0..b6f58367285 100644 --- a/advisories/unreviewed/2024/06/GHSA-64v6-hr9r-33mx/GHSA-64v6-hr9r-33mx.json +++ b/advisories/unreviewed/2024/06/GHSA-64v6-hr9r-33mx/GHSA-64v6-hr9r-33mx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-64v6-hr9r-33mx", - "modified": "2024-06-26T06:30:29Z", + "modified": "2024-07-03T18:46:59Z", "published": "2024-06-26T06:30:29Z", "aliases": [ "CVE-2024-34581" ], "details": "The W3C XML Signature Syntax and Processing (XMLDsig) specification, starting with 1.0, was originally published with a \"RetrievalMethod is a URI ... that may be used to obtain key and/or certificate information\" statement and no accompanying information about SSRF risks, and this may have contributed to vulnerable implementations such as those discussed in CVE-2023-36661 and CVE-2024-21893. NOTE: this was mitigated in 1.1 and 2.0 via a directly referenced Best Practices document that calls on implementers to be wary of SSRF.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-918" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-26T05:15:51Z" diff --git a/advisories/unreviewed/2024/06/GHSA-65j5-22x9-vjjf/GHSA-65j5-22x9-vjjf.json b/advisories/unreviewed/2024/06/GHSA-65j5-22x9-vjjf/GHSA-65j5-22x9-vjjf.json index 5da1e5597c8..3de9a0d2070 100644 --- a/advisories/unreviewed/2024/06/GHSA-65j5-22x9-vjjf/GHSA-65j5-22x9-vjjf.json +++ b/advisories/unreviewed/2024/06/GHSA-65j5-22x9-vjjf/GHSA-65j5-22x9-vjjf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-65j5-22x9-vjjf", - "modified": "2024-06-27T15:30:45Z", + "modified": "2024-07-03T18:47:08Z", "published": "2024-06-27T15:30:45Z", "aliases": [ "CVE-2024-39157" ], "details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ipRecord_deal.php?mudi=del&dataType=&dataID=1.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-27T14:15:16Z" diff --git a/advisories/unreviewed/2024/06/GHSA-679m-qrhj-wgh2/GHSA-679m-qrhj-wgh2.json b/advisories/unreviewed/2024/06/GHSA-679m-qrhj-wgh2/GHSA-679m-qrhj-wgh2.json index 290fd9f2216..6761365fa17 100644 --- a/advisories/unreviewed/2024/06/GHSA-679m-qrhj-wgh2/GHSA-679m-qrhj-wgh2.json +++ b/advisories/unreviewed/2024/06/GHSA-679m-qrhj-wgh2/GHSA-679m-qrhj-wgh2.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-426" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-67g5-2gq2-r5h9/GHSA-67g5-2gq2-r5h9.json b/advisories/unreviewed/2024/06/GHSA-67g5-2gq2-r5h9/GHSA-67g5-2gq2-r5h9.json index 2a5529376d6..e6f13bad4e1 100644 --- a/advisories/unreviewed/2024/06/GHSA-67g5-2gq2-r5h9/GHSA-67g5-2gq2-r5h9.json +++ b/advisories/unreviewed/2024/06/GHSA-67g5-2gq2-r5h9/GHSA-67g5-2gq2-r5h9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-67g5-2gq2-r5h9", - "modified": "2024-06-24T15:31:44Z", + "modified": "2024-07-03T18:46:25Z", "published": "2024-06-24T15:31:44Z", "aliases": [ "CVE-2024-33278" ], "details": "Buffer Overflow vulnerability in ASUS router RT-AX88U with firmware versions v3.0.0.4.388_24198 allows a remote attacker to execute arbitrary code via the connection_state_machine due to improper length validation for the cookie field.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-24T14:15:11Z" diff --git a/advisories/unreviewed/2024/06/GHSA-68wq-r58h-5q45/GHSA-68wq-r58h-5q45.json b/advisories/unreviewed/2024/06/GHSA-68wq-r58h-5q45/GHSA-68wq-r58h-5q45.json index 75d59bf0672..6ec830301f4 100644 --- a/advisories/unreviewed/2024/06/GHSA-68wq-r58h-5q45/GHSA-68wq-r58h-5q45.json +++ b/advisories/unreviewed/2024/06/GHSA-68wq-r58h-5q45/GHSA-68wq-r58h-5q45.json @@ -1,14 +1,21 @@ { "schema_version": "1.4.0", "id": "GHSA-68wq-r58h-5q45", - "modified": "2024-06-28T00:33:31Z", + "modified": "2024-07-03T18:47:15Z", "published": "2024-06-28T00:33:31Z", "aliases": [ "CVE-2024-4395" ], "details": "The XPC service within the audit functionality of Jamf Compliance Editor before version 1.3.1 on macOS can lead to local privilege escalation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:U/V:D/RE:M/U:Green" + } ], "affected": [ @@ -37,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-27T22:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-6www-xm5g-97xc/GHSA-6www-xm5g-97xc.json b/advisories/unreviewed/2024/06/GHSA-6www-xm5g-97xc/GHSA-6www-xm5g-97xc.json index fded48c6a12..b1b4d419a9c 100644 --- a/advisories/unreviewed/2024/06/GHSA-6www-xm5g-97xc/GHSA-6www-xm5g-97xc.json +++ b/advisories/unreviewed/2024/06/GHSA-6www-xm5g-97xc/GHSA-6www-xm5g-97xc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6www-xm5g-97xc", - "modified": "2024-06-22T00:30:57Z", + "modified": "2024-07-03T18:46:21Z", "published": "2024-06-22T00:30:57Z", "aliases": [ "CVE-2024-34989" ], "details": "In the module RSI PDF/HTML catalog evolution (prestapdf) <= 7.0.0 from RSI for PrestaShop, a guest can perform SQL injection via `PrestaPDFProductListModuleFrontController::queryDb().'", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-21T22:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-6xv6-j448-ffr5/GHSA-6xv6-j448-ffr5.json b/advisories/unreviewed/2024/06/GHSA-6xv6-j448-ffr5/GHSA-6xv6-j448-ffr5.json index 38253329f50..4e7061c70a5 100644 --- a/advisories/unreviewed/2024/06/GHSA-6xv6-j448-ffr5/GHSA-6xv6-j448-ffr5.json +++ b/advisories/unreviewed/2024/06/GHSA-6xv6-j448-ffr5/GHSA-6xv6-j448-ffr5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6xv6-j448-ffr5", - "modified": "2024-06-25T03:31:07Z", + "modified": "2024-07-03T18:46:47Z", "published": "2024-06-25T03:31:07Z", "aliases": [ "CVE-2024-23142" ], "details": "A maliciously crafted CATPART, STP, and MODEL file, when parsed in atf_dwg_consumer.dll, rose_x64_vc15.dll and libodxdll through Autodesk applications, can cause a use-after-free vulnerability. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-25T02:15:11Z" diff --git a/advisories/unreviewed/2024/06/GHSA-78rj-c2qq-g3pc/GHSA-78rj-c2qq-g3pc.json b/advisories/unreviewed/2024/06/GHSA-78rj-c2qq-g3pc/GHSA-78rj-c2qq-g3pc.json index b5d49286ebb..70ead51b652 100644 --- a/advisories/unreviewed/2024/06/GHSA-78rj-c2qq-g3pc/GHSA-78rj-c2qq-g3pc.json +++ b/advisories/unreviewed/2024/06/GHSA-78rj-c2qq-g3pc/GHSA-78rj-c2qq-g3pc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-78rj-c2qq-g3pc", - "modified": "2024-06-25T06:30:38Z", + "modified": "2024-07-03T18:46:48Z", "published": "2024-06-25T06:30:38Z", "aliases": [ "CVE-2024-23150" ], "details": "A maliciously crafted PRT file, when parsed in odxug_dll.dll through Autodesk applications, can force an Out-of-Bounds Write. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-25T04:15:11Z" diff --git a/advisories/unreviewed/2024/06/GHSA-7967-r4q5-m6jj/GHSA-7967-r4q5-m6jj.json b/advisories/unreviewed/2024/06/GHSA-7967-r4q5-m6jj/GHSA-7967-r4q5-m6jj.json index c5c28e570fa..89f42169908 100644 --- a/advisories/unreviewed/2024/06/GHSA-7967-r4q5-m6jj/GHSA-7967-r4q5-m6jj.json +++ b/advisories/unreviewed/2024/06/GHSA-7967-r4q5-m6jj/GHSA-7967-r4q5-m6jj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7967-r4q5-m6jj", - "modified": "2024-06-25T06:30:39Z", + "modified": "2024-07-03T18:46:52Z", "published": "2024-06-25T06:30:39Z", "aliases": [ "CVE-2024-23157" ], "details": "A maliciously crafted SLDASM or SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-119" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-25T04:15:13Z" diff --git a/advisories/unreviewed/2024/06/GHSA-7gh6-h622-qxjx/GHSA-7gh6-h622-qxjx.json b/advisories/unreviewed/2024/06/GHSA-7gh6-h622-qxjx/GHSA-7gh6-h622-qxjx.json index a8b602fd500..a10d05f8b31 100644 --- a/advisories/unreviewed/2024/06/GHSA-7gh6-h622-qxjx/GHSA-7gh6-h622-qxjx.json +++ b/advisories/unreviewed/2024/06/GHSA-7gh6-h622-qxjx/GHSA-7gh6-h622-qxjx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7gh6-h622-qxjx", - "modified": "2024-06-24T21:33:21Z", + "modified": "2024-07-03T18:46:33Z", "published": "2024-06-24T21:33:21Z", "aliases": [ "CVE-2024-37759" ], "details": "DataGear v5.0.0 and earlier was discovered to contain a SpEL (Spring Expression Language) expression injection vulnerability via the Data Viewing interface.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-74" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-24T21:15:25Z" diff --git a/advisories/unreviewed/2024/06/GHSA-7p6q-hqg2-6cpg/GHSA-7p6q-hqg2-6cpg.json b/advisories/unreviewed/2024/06/GHSA-7p6q-hqg2-6cpg/GHSA-7p6q-hqg2-6cpg.json index 6dc5e053e32..aa7ca7a0c93 100644 --- a/advisories/unreviewed/2024/06/GHSA-7p6q-hqg2-6cpg/GHSA-7p6q-hqg2-6cpg.json +++ b/advisories/unreviewed/2024/06/GHSA-7p6q-hqg2-6cpg/GHSA-7p6q-hqg2-6cpg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7p6q-hqg2-6cpg", - "modified": "2024-06-25T06:30:38Z", + "modified": "2024-07-03T18:46:24Z", "published": "2024-06-24T09:30:53Z", "aliases": [ "CVE-2024-36497" ], "details": "The decrypted configuration file contains the password in cleartext \nwhich is used to configure WINSelect. It can be used to remove the \nexisting restrictions and disable WINSelect entirely.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-312" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-24T09:15:09Z" diff --git a/advisories/unreviewed/2024/06/GHSA-7w58-2c67-8xhv/GHSA-7w58-2c67-8xhv.json b/advisories/unreviewed/2024/06/GHSA-7w58-2c67-8xhv/GHSA-7w58-2c67-8xhv.json index a896ec740f9..a67c87a9c5e 100644 --- a/advisories/unreviewed/2024/06/GHSA-7w58-2c67-8xhv/GHSA-7w58-2c67-8xhv.json +++ b/advisories/unreviewed/2024/06/GHSA-7w58-2c67-8xhv/GHSA-7w58-2c67-8xhv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7w58-2c67-8xhv", - "modified": "2024-06-25T03:31:07Z", + "modified": "2024-07-03T18:46:47Z", "published": "2024-06-25T03:31:07Z", "aliases": [ "CVE-2024-23148" ], "details": "A maliciously crafted CATPRODUCT file, when parsed in CC5Dll.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-119" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-25T03:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-857q-8r99-c659/GHSA-857q-8r99-c659.json b/advisories/unreviewed/2024/06/GHSA-857q-8r99-c659/GHSA-857q-8r99-c659.json index dfcb2691db4..6b650086632 100644 --- a/advisories/unreviewed/2024/06/GHSA-857q-8r99-c659/GHSA-857q-8r99-c659.json +++ b/advisories/unreviewed/2024/06/GHSA-857q-8r99-c659/GHSA-857q-8r99-c659.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-857q-8r99-c659", - "modified": "2024-06-24T21:33:21Z", + "modified": "2024-07-03T18:46:36Z", "published": "2024-06-24T21:33:21Z", "aliases": [ "CVE-2024-38902" ], "details": "H3C Magic R230 V100R002 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-259" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-24T21:15:26Z" diff --git a/advisories/unreviewed/2024/06/GHSA-8925-jp4p-j7g9/GHSA-8925-jp4p-j7g9.json b/advisories/unreviewed/2024/06/GHSA-8925-jp4p-j7g9/GHSA-8925-jp4p-j7g9.json index 0f8d8642f9e..34510aea15a 100644 --- a/advisories/unreviewed/2024/06/GHSA-8925-jp4p-j7g9/GHSA-8925-jp4p-j7g9.json +++ b/advisories/unreviewed/2024/06/GHSA-8925-jp4p-j7g9/GHSA-8925-jp4p-j7g9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8925-jp4p-j7g9", - "modified": "2024-06-24T06:30:55Z", + "modified": "2024-07-03T18:46:23Z", "published": "2024-06-24T06:30:55Z", "aliases": [ "CVE-2024-4899" ], "details": "The SEOPress WordPress plugin before 7.8 does not sanitise and escape some of its Post settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-24T06:15:11Z" diff --git a/advisories/unreviewed/2024/06/GHSA-8gvf-f484-h344/GHSA-8gvf-f484-h344.json b/advisories/unreviewed/2024/06/GHSA-8gvf-f484-h344/GHSA-8gvf-f484-h344.json index db87cb2928b..23c1d963343 100644 --- a/advisories/unreviewed/2024/06/GHSA-8gvf-f484-h344/GHSA-8gvf-f484-h344.json +++ b/advisories/unreviewed/2024/06/GHSA-8gvf-f484-h344/GHSA-8gvf-f484-h344.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8gvf-f484-h344", - "modified": "2024-06-22T00:30:56Z", + "modified": "2024-07-03T18:46:21Z", "published": "2024-06-22T00:30:56Z", "aliases": [ "CVE-2022-42974" ], "details": "In Kostal PIKO 1.5-1 MP plus HMI OEM p 1.0.1, the web application for the Solar Panel is vulnerable to a Stored Cross-Site Scripting (XSS) attack on /file.bootloader.upload.html. The application fails to sanitize the parameter filename, in a POST request to /file.bootloader.upload.html for a system update, thus allowing one to inject HTML and/or JavaScript on the page that will then be processed and stored by the application. Any subsequent requests to pages that retrieve the malicious content will automatically exploit the vulnerability on the victim's browser. This also happens because the tag is loaded in the function innerHTML in the page HTML.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-21T22:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-8pgm-8mwr-cm87/GHSA-8pgm-8mwr-cm87.json b/advisories/unreviewed/2024/06/GHSA-8pgm-8mwr-cm87/GHSA-8pgm-8mwr-cm87.json index 324a6c248f0..353d9b9d496 100644 --- a/advisories/unreviewed/2024/06/GHSA-8pgm-8mwr-cm87/GHSA-8pgm-8mwr-cm87.json +++ b/advisories/unreviewed/2024/06/GHSA-8pgm-8mwr-cm87/GHSA-8pgm-8mwr-cm87.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8pgm-8mwr-cm87", - "modified": "2024-06-26T00:31:43Z", + "modified": "2024-07-03T18:46:58Z", "published": "2024-06-26T00:31:43Z", "aliases": [ "CVE-2024-30931" ], "details": "Stored Cross Site Scripting vulnerability in Emby Media Server Emby Media Server 4.8.3.0 allows a remote attacker to escalate privileges via the notifications.html component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-25T22:15:30Z" diff --git a/advisories/unreviewed/2024/06/GHSA-8xjv-mwp7-g69v/GHSA-8xjv-mwp7-g69v.json b/advisories/unreviewed/2024/06/GHSA-8xjv-mwp7-g69v/GHSA-8xjv-mwp7-g69v.json index 98d10f63a84..8d39d0a4c6e 100644 --- a/advisories/unreviewed/2024/06/GHSA-8xjv-mwp7-g69v/GHSA-8xjv-mwp7-g69v.json +++ b/advisories/unreviewed/2024/06/GHSA-8xjv-mwp7-g69v/GHSA-8xjv-mwp7-g69v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8xjv-mwp7-g69v", - "modified": "2024-06-24T21:33:21Z", + "modified": "2024-07-03T18:46:34Z", "published": "2024-06-24T21:33:21Z", "aliases": [ "CVE-2024-38894" ], "details": "WAVLINK WN551K1 found a command injection vulnerability through the IP parameter of /cgi-bin/touchlist_sync.cgi.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-24T21:15:26Z" diff --git a/advisories/unreviewed/2024/06/GHSA-95jf-85v4-5p6v/GHSA-95jf-85v4-5p6v.json b/advisories/unreviewed/2024/06/GHSA-95jf-85v4-5p6v/GHSA-95jf-85v4-5p6v.json index d7a3e5af53e..fc83b297b73 100644 --- a/advisories/unreviewed/2024/06/GHSA-95jf-85v4-5p6v/GHSA-95jf-85v4-5p6v.json +++ b/advisories/unreviewed/2024/06/GHSA-95jf-85v4-5p6v/GHSA-95jf-85v4-5p6v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-95jf-85v4-5p6v", - "modified": "2024-06-22T00:30:57Z", + "modified": "2024-07-03T18:46:22Z", "published": "2024-06-22T00:30:57Z", "aliases": [ "CVE-2024-36532" ], "details": "Insecure permissions in kruise v1.6.2 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-281" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-21T22:15:11Z" diff --git a/advisories/unreviewed/2024/06/GHSA-9f8f-453p-rg87/GHSA-9f8f-453p-rg87.json b/advisories/unreviewed/2024/06/GHSA-9f8f-453p-rg87/GHSA-9f8f-453p-rg87.json index 7e42dac8d38..71eec06e879 100644 --- a/advisories/unreviewed/2024/06/GHSA-9f8f-453p-rg87/GHSA-9f8f-453p-rg87.json +++ b/advisories/unreviewed/2024/06/GHSA-9f8f-453p-rg87/GHSA-9f8f-453p-rg87.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9f8f-453p-rg87", - "modified": "2024-06-27T03:30:56Z", + "modified": "2024-07-03T18:46:39Z", "published": "2024-06-25T00:34:46Z", "aliases": [ "CVE-2024-6293" ], "details": "Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-24T22:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-9gqj-qmq3-h3hc/GHSA-9gqj-qmq3-h3hc.json b/advisories/unreviewed/2024/06/GHSA-9gqj-qmq3-h3hc/GHSA-9gqj-qmq3-h3hc.json index 0fa47f3c31e..b1722617e57 100644 --- a/advisories/unreviewed/2024/06/GHSA-9gqj-qmq3-h3hc/GHSA-9gqj-qmq3-h3hc.json +++ b/advisories/unreviewed/2024/06/GHSA-9gqj-qmq3-h3hc/GHSA-9gqj-qmq3-h3hc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9gqj-qmq3-h3hc", - "modified": "2024-06-25T06:30:39Z", + "modified": "2024-07-03T18:46:52Z", "published": "2024-06-25T06:30:39Z", "aliases": [ "CVE-2024-37003" ], "details": "A maliciously crafted DWG and SLDPRT file, when parsed in opennurbs.dll and ODXSW_DLL.dll through Autodesk applications, can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-121" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-25T04:15:15Z" diff --git a/advisories/unreviewed/2024/06/GHSA-c2f6-2qgv-549c/GHSA-c2f6-2qgv-549c.json b/advisories/unreviewed/2024/06/GHSA-c2f6-2qgv-549c/GHSA-c2f6-2qgv-549c.json index 1a90074cbc1..f044681da24 100644 --- a/advisories/unreviewed/2024/06/GHSA-c2f6-2qgv-549c/GHSA-c2f6-2qgv-549c.json +++ b/advisories/unreviewed/2024/06/GHSA-c2f6-2qgv-549c/GHSA-c2f6-2qgv-549c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c2f6-2qgv-549c", - "modified": "2024-06-26T06:30:29Z", + "modified": "2024-07-03T18:46:59Z", "published": "2024-06-26T06:30:29Z", "aliases": [ "CVE-2024-4959" ], "details": "The Frontend Checklist WordPress plugin through 2.3.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-26T06:15:16Z" diff --git a/advisories/unreviewed/2024/06/GHSA-c5vh-fhpc-wg5w/GHSA-c5vh-fhpc-wg5w.json b/advisories/unreviewed/2024/06/GHSA-c5vh-fhpc-wg5w/GHSA-c5vh-fhpc-wg5w.json index fc984eb1626..c22e3f673b3 100644 --- a/advisories/unreviewed/2024/06/GHSA-c5vh-fhpc-wg5w/GHSA-c5vh-fhpc-wg5w.json +++ b/advisories/unreviewed/2024/06/GHSA-c5vh-fhpc-wg5w/GHSA-c5vh-fhpc-wg5w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c5vh-fhpc-wg5w", - "modified": "2024-06-27T15:30:45Z", + "modified": "2024-07-03T18:47:06Z", "published": "2024-06-27T15:30:45Z", "aliases": [ "CVE-2024-39156" ], "details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/keyWord_deal.php?mudi=add.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-27T14:15:16Z" diff --git a/advisories/unreviewed/2024/06/GHSA-c8f7-vvrw-73c7/GHSA-c8f7-vvrw-73c7.json b/advisories/unreviewed/2024/06/GHSA-c8f7-vvrw-73c7/GHSA-c8f7-vvrw-73c7.json index 8e50ddaa23e..bfd7d09b22b 100644 --- a/advisories/unreviewed/2024/06/GHSA-c8f7-vvrw-73c7/GHSA-c8f7-vvrw-73c7.json +++ b/advisories/unreviewed/2024/06/GHSA-c8f7-vvrw-73c7/GHSA-c8f7-vvrw-73c7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c8f7-vvrw-73c7", - "modified": "2024-06-22T00:30:56Z", + "modified": "2024-07-03T18:46:19Z", "published": "2024-06-22T00:30:56Z", "aliases": [ "CVE-2012-6664" ], "details": "Multiple directory traversal vulnerabilities in the TFTP Server in Distinct Intranet Servers 3.10 and earlier allow remote attackers to read or write arbitrary files via a .. (dot dot) in the (1) get or (2) put commands.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-21T22:15:09Z" diff --git a/advisories/unreviewed/2024/06/GHSA-c94h-cmw2-96cv/GHSA-c94h-cmw2-96cv.json b/advisories/unreviewed/2024/06/GHSA-c94h-cmw2-96cv/GHSA-c94h-cmw2-96cv.json index eebba73c938..2ba71792181 100644 --- a/advisories/unreviewed/2024/06/GHSA-c94h-cmw2-96cv/GHSA-c94h-cmw2-96cv.json +++ b/advisories/unreviewed/2024/06/GHSA-c94h-cmw2-96cv/GHSA-c94h-cmw2-96cv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c94h-cmw2-96cv", - "modified": "2024-06-25T15:31:09Z", + "modified": "2024-07-03T18:46:57Z", "published": "2024-06-25T15:31:09Z", "aliases": [ "CVE-2024-39462" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nclk: bcm: dvp: Assign ->num before accessing ->hws\n\nCommit f316cdff8d67 (\"clk: Annotate struct clk_hw_onecell_data with\n__counted_by\") annotated the hws member of 'struct clk_hw_onecell_data'\nwith __counted_by, which informs the bounds sanitizer about the number\nof elements in hws, so that it can warn when hws is accessed out of\nbounds. As noted in that change, the __counted_by member must be\ninitialized with the number of elements before the first array access\nhappens, otherwise there will be a warning from each access prior to the\ninitialization because the number of elements is zero. This occurs in\nclk_dvp_probe() due to ->num being assigned after ->hws has been\naccessed:\n\n UBSAN: array-index-out-of-bounds in drivers/clk/bcm/clk-bcm2711-dvp.c:59:2\n index 0 is out of range for type 'struct clk_hw *[] __counted_by(num)' (aka 'struct clk_hw *[]')\n\nMove the ->num initialization to before the first access of ->hws, which\nclears up the warning.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-25T15:15:14Z" diff --git a/advisories/unreviewed/2024/06/GHSA-cqrv-6jr2-m8qj/GHSA-cqrv-6jr2-m8qj.json b/advisories/unreviewed/2024/06/GHSA-cqrv-6jr2-m8qj/GHSA-cqrv-6jr2-m8qj.json index ea6a3f2427a..240b4f8c49d 100644 --- a/advisories/unreviewed/2024/06/GHSA-cqrv-6jr2-m8qj/GHSA-cqrv-6jr2-m8qj.json +++ b/advisories/unreviewed/2024/06/GHSA-cqrv-6jr2-m8qj/GHSA-cqrv-6jr2-m8qj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cqrv-6jr2-m8qj", - "modified": "2024-06-25T06:30:39Z", + "modified": "2024-07-03T18:46:50Z", "published": "2024-06-25T06:30:39Z", "aliases": [ "CVE-2024-23153" ], "details": "A maliciously crafted MODEL file, when parsed in libodx.dll through Autodesk applications, can force an Out-of-Bounds Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-25T04:15:12Z" diff --git a/advisories/unreviewed/2024/06/GHSA-ffcq-3472-r63j/GHSA-ffcq-3472-r63j.json b/advisories/unreviewed/2024/06/GHSA-ffcq-3472-r63j/GHSA-ffcq-3472-r63j.json index b1b58335341..e649af52557 100644 --- a/advisories/unreviewed/2024/06/GHSA-ffcq-3472-r63j/GHSA-ffcq-3472-r63j.json +++ b/advisories/unreviewed/2024/06/GHSA-ffcq-3472-r63j/GHSA-ffcq-3472-r63j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ffcq-3472-r63j", - "modified": "2024-06-25T03:31:07Z", + "modified": "2024-07-03T18:46:47Z", "published": "2024-06-25T03:31:07Z", "aliases": [ "CVE-2024-23141" ], "details": "A maliciously crafted MODEL file, when parsed in libodxdll through Autodesk applications, can cause a double free. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-415" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-25T02:15:11Z" diff --git a/advisories/unreviewed/2024/06/GHSA-fg6c-4jx9-vvgm/GHSA-fg6c-4jx9-vvgm.json b/advisories/unreviewed/2024/06/GHSA-fg6c-4jx9-vvgm/GHSA-fg6c-4jx9-vvgm.json index eff926273f5..be2303357d9 100644 --- a/advisories/unreviewed/2024/06/GHSA-fg6c-4jx9-vvgm/GHSA-fg6c-4jx9-vvgm.json +++ b/advisories/unreviewed/2024/06/GHSA-fg6c-4jx9-vvgm/GHSA-fg6c-4jx9-vvgm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fg6c-4jx9-vvgm", - "modified": "2024-06-25T06:30:39Z", + "modified": "2024-07-03T18:46:56Z", "published": "2024-06-25T06:30:39Z", "aliases": [ "CVE-2024-37007" ], "details": "A maliciously crafted X_B and X_T file, when parsed in pskernel.DLL through Autodesk applications, can cause a use-after-free vulnerability. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-25T04:15:16Z" diff --git a/advisories/unreviewed/2024/06/GHSA-fh98-wqgq-wr3p/GHSA-fh98-wqgq-wr3p.json b/advisories/unreviewed/2024/06/GHSA-fh98-wqgq-wr3p/GHSA-fh98-wqgq-wr3p.json index 50736b2cc1b..9a603fc2ead 100644 --- a/advisories/unreviewed/2024/06/GHSA-fh98-wqgq-wr3p/GHSA-fh98-wqgq-wr3p.json +++ b/advisories/unreviewed/2024/06/GHSA-fh98-wqgq-wr3p/GHSA-fh98-wqgq-wr3p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fh98-wqgq-wr3p", - "modified": "2024-06-24T21:33:21Z", + "modified": "2024-07-03T18:46:33Z", "published": "2024-06-24T21:33:21Z", "aliases": [ "CVE-2024-34313" ], "details": "An issue in VPL Jail System up to v4.0.2 allows attackers to execute a directory traversal via a crafted request to a public endpoint.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-24T20:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-fwjp-fr8h-pc84/GHSA-fwjp-fr8h-pc84.json b/advisories/unreviewed/2024/06/GHSA-fwjp-fr8h-pc84/GHSA-fwjp-fr8h-pc84.json index 5e72a09739d..eaa26b725a5 100644 --- a/advisories/unreviewed/2024/06/GHSA-fwjp-fr8h-pc84/GHSA-fwjp-fr8h-pc84.json +++ b/advisories/unreviewed/2024/06/GHSA-fwjp-fr8h-pc84/GHSA-fwjp-fr8h-pc84.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fwjp-fr8h-pc84", - "modified": "2024-06-25T00:34:47Z", + "modified": "2024-07-03T18:46:45Z", "published": "2024-06-25T00:34:47Z", "aliases": [ "CVE-2024-36681" ], "details": "SQL Injection vulnerability in the module \"Isotope\" (pk_isotope) <=1.7.3 from Promokit.eu for PrestaShop allows attackers to obtain sensitive information and cause other impacts via `pk_isotope::saveData` and `pk_isotope::removeData` methods.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-24T23:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-g463-8wv2-fc9f/GHSA-g463-8wv2-fc9f.json b/advisories/unreviewed/2024/06/GHSA-g463-8wv2-fc9f/GHSA-g463-8wv2-fc9f.json index 88f116ca774..f547025e175 100644 --- a/advisories/unreviewed/2024/06/GHSA-g463-8wv2-fc9f/GHSA-g463-8wv2-fc9f.json +++ b/advisories/unreviewed/2024/06/GHSA-g463-8wv2-fc9f/GHSA-g463-8wv2-fc9f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g463-8wv2-fc9f", - "modified": "2024-06-27T21:32:09Z", + "modified": "2024-07-03T18:47:11Z", "published": "2024-06-27T21:32:09Z", "aliases": [ "CVE-2024-36075" ], "details": "Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnerability in the application configuration component of the Endpoint Protector and Unify agent which allows a remote, unauthenticated attacker to manipulate the configuration of either their own or another client endpoint resulting in the bypass of certain configuration options. Manipulation of the application configuration can result in local policy bypass and in some scenarios remote code execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-27T21:15:15Z" diff --git a/advisories/unreviewed/2024/06/GHSA-g67v-gq6f-p8x3/GHSA-g67v-gq6f-p8x3.json b/advisories/unreviewed/2024/06/GHSA-g67v-gq6f-p8x3/GHSA-g67v-gq6f-p8x3.json index 3983a0a0257..a2dc35a0312 100644 --- a/advisories/unreviewed/2024/06/GHSA-g67v-gq6f-p8x3/GHSA-g67v-gq6f-p8x3.json +++ b/advisories/unreviewed/2024/06/GHSA-g67v-gq6f-p8x3/GHSA-g67v-gq6f-p8x3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g67v-gq6f-p8x3", - "modified": "2024-06-24T21:33:21Z", + "modified": "2024-07-03T18:46:35Z", "published": "2024-06-24T21:33:21Z", "aliases": [ "CVE-2024-38895" ], "details": "WAVLINK WN551K1'live_mfg.shtml enables attackers to obtain sensitive router information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-202" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-24T21:15:26Z" diff --git a/advisories/unreviewed/2024/06/GHSA-g9gg-xprq-97gc/GHSA-g9gg-xprq-97gc.json b/advisories/unreviewed/2024/06/GHSA-g9gg-xprq-97gc/GHSA-g9gg-xprq-97gc.json index 65d7cbe1074..5c34615ba33 100644 --- a/advisories/unreviewed/2024/06/GHSA-g9gg-xprq-97gc/GHSA-g9gg-xprq-97gc.json +++ b/advisories/unreviewed/2024/06/GHSA-g9gg-xprq-97gc/GHSA-g9gg-xprq-97gc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g9gg-xprq-97gc", - "modified": "2024-06-27T21:32:09Z", + "modified": "2024-07-03T18:47:14Z", "published": "2024-06-27T21:32:09Z", "aliases": [ "CVE-2024-39134" ], "details": "A Stack Buffer Overflow vulnerability in zziplibv 0.13.77 allows attackers to cause a denial of service via the __zzip_fetch_disk_trailer() function at /zzip/zip.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-27T21:15:15Z" diff --git a/advisories/unreviewed/2024/06/GHSA-gp6m-m3pw-7m24/GHSA-gp6m-m3pw-7m24.json b/advisories/unreviewed/2024/06/GHSA-gp6m-m3pw-7m24/GHSA-gp6m-m3pw-7m24.json index 88c81b11f01..b8f73cf0dff 100644 --- a/advisories/unreviewed/2024/06/GHSA-gp6m-m3pw-7m24/GHSA-gp6m-m3pw-7m24.json +++ b/advisories/unreviewed/2024/06/GHSA-gp6m-m3pw-7m24/GHSA-gp6m-m3pw-7m24.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gp6m-m3pw-7m24", - "modified": "2024-06-25T00:34:47Z", + "modified": "2024-07-03T18:46:45Z", "published": "2024-06-25T00:34:47Z", "aliases": [ "CVE-2024-34992" ], "details": "SQL Injection vulnerability in the module \"Help Desk - Customer Support Management System\" (helpdesk) up to version 2.4.0 from FME Modules for PrestaShop allows attackers to obtain sensitive information and cause other impacts via 'Tickets::getsearchedtickets()'", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-24T23:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-gw84-qf63-55gw/GHSA-gw84-qf63-55gw.json b/advisories/unreviewed/2024/06/GHSA-gw84-qf63-55gw/GHSA-gw84-qf63-55gw.json index 0eda1187307..020ed257b6c 100644 --- a/advisories/unreviewed/2024/06/GHSA-gw84-qf63-55gw/GHSA-gw84-qf63-55gw.json +++ b/advisories/unreviewed/2024/06/GHSA-gw84-qf63-55gw/GHSA-gw84-qf63-55gw.json @@ -25,7 +25,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1262" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-gwgm-rvh4-63c2/GHSA-gwgm-rvh4-63c2.json b/advisories/unreviewed/2024/06/GHSA-gwgm-rvh4-63c2/GHSA-gwgm-rvh4-63c2.json index 462f0dad1f4..8bd44e1c1b0 100644 --- a/advisories/unreviewed/2024/06/GHSA-gwgm-rvh4-63c2/GHSA-gwgm-rvh4-63c2.json +++ b/advisories/unreviewed/2024/06/GHSA-gwgm-rvh4-63c2/GHSA-gwgm-rvh4-63c2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gwgm-rvh4-63c2", - "modified": "2024-06-25T03:31:07Z", + "modified": "2024-07-03T18:46:47Z", "published": "2024-06-25T03:31:07Z", "aliases": [ "CVE-2024-23147" ], "details": "A maliciously crafted CATPART, X_B and STEP, when parsed in ASMKERN228A.dll and ASMKERN229A.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-119" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-25T03:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-h257-p73p-qx36/GHSA-h257-p73p-qx36.json b/advisories/unreviewed/2024/06/GHSA-h257-p73p-qx36/GHSA-h257-p73p-qx36.json index ae479112adc..da023015ffc 100644 --- a/advisories/unreviewed/2024/06/GHSA-h257-p73p-qx36/GHSA-h257-p73p-qx36.json +++ b/advisories/unreviewed/2024/06/GHSA-h257-p73p-qx36/GHSA-h257-p73p-qx36.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h257-p73p-qx36", - "modified": "2024-06-25T06:30:39Z", + "modified": "2024-07-03T18:46:55Z", "published": "2024-06-25T06:30:39Z", "aliases": [ "CVE-2024-37005" ], "details": "A maliciously crafted X_B and X_T file, when parsed in pskernel.DLL through Autodesk applications, can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-25T04:15:15Z" diff --git a/advisories/unreviewed/2024/06/GHSA-hfgv-wmc3-7jwm/GHSA-hfgv-wmc3-7jwm.json b/advisories/unreviewed/2024/06/GHSA-hfgv-wmc3-7jwm/GHSA-hfgv-wmc3-7jwm.json index 0af5931ba86..e7561b31b0b 100644 --- a/advisories/unreviewed/2024/06/GHSA-hfgv-wmc3-7jwm/GHSA-hfgv-wmc3-7jwm.json +++ b/advisories/unreviewed/2024/06/GHSA-hfgv-wmc3-7jwm/GHSA-hfgv-wmc3-7jwm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hfgv-wmc3-7jwm", - "modified": "2024-06-26T06:30:30Z", + "modified": "2024-07-03T18:46:59Z", "published": "2024-06-26T06:30:30Z", "aliases": [ "CVE-2024-5473" ], "details": "The Simple Photoswipe WordPress plugin through 0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-26T06:15:17Z" diff --git a/advisories/unreviewed/2024/06/GHSA-hp3p-7892-f222/GHSA-hp3p-7892-f222.json b/advisories/unreviewed/2024/06/GHSA-hp3p-7892-f222/GHSA-hp3p-7892-f222.json index 37f5a204990..406f5c94354 100644 --- a/advisories/unreviewed/2024/06/GHSA-hp3p-7892-f222/GHSA-hp3p-7892-f222.json +++ b/advisories/unreviewed/2024/06/GHSA-hp3p-7892-f222/GHSA-hp3p-7892-f222.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hp3p-7892-f222", - "modified": "2024-06-29T09:30:56Z", + "modified": "2024-07-03T18:46:22Z", "published": "2024-06-24T00:34:02Z", "aliases": [ "CVE-2024-39331" ], "details": "In Emacs before 29.4, org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe function, such as shell-command-to-string. This affects Org Mode before 9.7.5.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -57,9 +60,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-23T22:15:09Z" diff --git a/advisories/unreviewed/2024/06/GHSA-j2gg-6w32-gqc2/GHSA-j2gg-6w32-gqc2.json b/advisories/unreviewed/2024/06/GHSA-j2gg-6w32-gqc2/GHSA-j2gg-6w32-gqc2.json index 31692f4657f..d575e49ce23 100644 --- a/advisories/unreviewed/2024/06/GHSA-j2gg-6w32-gqc2/GHSA-j2gg-6w32-gqc2.json +++ b/advisories/unreviewed/2024/06/GHSA-j2gg-6w32-gqc2/GHSA-j2gg-6w32-gqc2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j2gg-6w32-gqc2", - "modified": "2024-06-27T21:32:08Z", + "modified": "2024-07-03T18:47:11Z", "published": "2024-06-27T21:32:08Z", "aliases": [ "CVE-2024-39208" ], "details": "luci-app-lucky v2.8.3 was discovered to contain hardcoded credentials.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-798" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-27T20:15:22Z" diff --git a/advisories/unreviewed/2024/06/GHSA-j4fv-r5w9-h675/GHSA-j4fv-r5w9-h675.json b/advisories/unreviewed/2024/06/GHSA-j4fv-r5w9-h675/GHSA-j4fv-r5w9-h675.json index 73fb8bf69d2..0a43962d7e8 100644 --- a/advisories/unreviewed/2024/06/GHSA-j4fv-r5w9-h675/GHSA-j4fv-r5w9-h675.json +++ b/advisories/unreviewed/2024/06/GHSA-j4fv-r5w9-h675/GHSA-j4fv-r5w9-h675.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j4fv-r5w9-h675", - "modified": "2024-06-26T06:30:29Z", + "modified": "2024-07-03T18:46:58Z", "published": "2024-06-26T06:30:29Z", "aliases": [ "CVE-2024-34580" ], "details": "Apache XML Security for C++ through 2.0.4 implements the XML Signature Syntax and Processing (XMLDsig) specification without protection against an SSRF payload in a KeyInfo element. NOTE: the supplier disputes this CVE Record on the grounds that they are implementing the specification \"correctly\" and are not \"at fault.\"", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-918" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-26T05:15:51Z" diff --git a/advisories/unreviewed/2024/06/GHSA-j67h-vvfp-vgmq/GHSA-j67h-vvfp-vgmq.json b/advisories/unreviewed/2024/06/GHSA-j67h-vvfp-vgmq/GHSA-j67h-vvfp-vgmq.json index 42a685f6cca..84f6becedfd 100644 --- a/advisories/unreviewed/2024/06/GHSA-j67h-vvfp-vgmq/GHSA-j67h-vvfp-vgmq.json +++ b/advisories/unreviewed/2024/06/GHSA-j67h-vvfp-vgmq/GHSA-j67h-vvfp-vgmq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j67h-vvfp-vgmq", - "modified": "2024-06-26T06:30:29Z", + "modified": "2024-07-03T18:46:59Z", "published": "2024-06-26T06:30:29Z", "aliases": [ "CVE-2024-4758" ], "details": "The Muslim Prayer Time BD WordPress plugin through 2.4 does not have CSRF check in place when reseting its settings, which could allow attackers to make a logged in admin reset them via a CSRF attack", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-26T06:15:16Z" diff --git a/advisories/unreviewed/2024/06/GHSA-jm6p-8vc7-99q9/GHSA-jm6p-8vc7-99q9.json b/advisories/unreviewed/2024/06/GHSA-jm6p-8vc7-99q9/GHSA-jm6p-8vc7-99q9.json index 08c60c1ed1c..5b1b131b680 100644 --- a/advisories/unreviewed/2024/06/GHSA-jm6p-8vc7-99q9/GHSA-jm6p-8vc7-99q9.json +++ b/advisories/unreviewed/2024/06/GHSA-jm6p-8vc7-99q9/GHSA-jm6p-8vc7-99q9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jm6p-8vc7-99q9", - "modified": "2024-06-25T06:30:38Z", + "modified": "2024-07-03T18:46:23Z", "published": "2024-06-24T09:30:53Z", "aliases": [ "CVE-2024-36496" ], "details": "The configuration file is encrypted with a static key derived from a \nstatic five-character password which allows an attacker to decrypt this \nfile. The application hashes this five-character password with \nthe outdated and broken MD5 algorithm (no salt) and uses the first five \nbytes as the key for RC4. The configuration file is then encrypted with \nthese parameters.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-798" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-24T09:15:09Z" diff --git a/advisories/unreviewed/2024/06/GHSA-jxj9-c3m8-f8q8/GHSA-jxj9-c3m8-f8q8.json b/advisories/unreviewed/2024/06/GHSA-jxj9-c3m8-f8q8/GHSA-jxj9-c3m8-f8q8.json index c0295905fa6..5f01d2a04b0 100644 --- a/advisories/unreviewed/2024/06/GHSA-jxj9-c3m8-f8q8/GHSA-jxj9-c3m8-f8q8.json +++ b/advisories/unreviewed/2024/06/GHSA-jxj9-c3m8-f8q8/GHSA-jxj9-c3m8-f8q8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jxj9-c3m8-f8q8", - "modified": "2024-06-25T06:30:39Z", + "modified": "2024-07-03T18:46:55Z", "published": "2024-06-25T06:30:39Z", "aliases": [ "CVE-2024-37006" ], "details": "A maliciously crafted CATPRODUCT file, when parsed in CC5Dll.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-119" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-25T04:15:16Z" diff --git a/advisories/unreviewed/2024/06/GHSA-m6hr-8q9f-92q4/GHSA-m6hr-8q9f-92q4.json b/advisories/unreviewed/2024/06/GHSA-m6hr-8q9f-92q4/GHSA-m6hr-8q9f-92q4.json index 80a2058e903..fd0a9431a5e 100644 --- a/advisories/unreviewed/2024/06/GHSA-m6hr-8q9f-92q4/GHSA-m6hr-8q9f-92q4.json +++ b/advisories/unreviewed/2024/06/GHSA-m6hr-8q9f-92q4/GHSA-m6hr-8q9f-92q4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m6hr-8q9f-92q4", - "modified": "2024-06-26T06:30:29Z", + "modified": "2024-07-03T18:46:59Z", "published": "2024-06-26T06:30:29Z", "aliases": [ "CVE-2024-3633" ], "details": "The WebP & SVG Support WordPress plugin through 1.4.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-26T06:15:15Z" diff --git a/advisories/unreviewed/2024/06/GHSA-m848-8f5r-6j4g/GHSA-m848-8f5r-6j4g.json b/advisories/unreviewed/2024/06/GHSA-m848-8f5r-6j4g/GHSA-m848-8f5r-6j4g.json index e481f9b0095..b2262405923 100644 --- a/advisories/unreviewed/2024/06/GHSA-m848-8f5r-6j4g/GHSA-m848-8f5r-6j4g.json +++ b/advisories/unreviewed/2024/06/GHSA-m848-8f5r-6j4g/GHSA-m848-8f5r-6j4g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m848-8f5r-6j4g", - "modified": "2024-06-27T03:30:56Z", + "modified": "2024-07-03T18:46:39Z", "published": "2024-06-25T00:34:46Z", "aliases": [ "CVE-2024-6292" ], "details": "Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-24T22:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-mhg9-7866-m76h/GHSA-mhg9-7866-m76h.json b/advisories/unreviewed/2024/06/GHSA-mhg9-7866-m76h/GHSA-mhg9-7866-m76h.json index d45d8a689ef..8e8b3fc7a6c 100644 --- a/advisories/unreviewed/2024/06/GHSA-mhg9-7866-m76h/GHSA-mhg9-7866-m76h.json +++ b/advisories/unreviewed/2024/06/GHSA-mhg9-7866-m76h/GHSA-mhg9-7866-m76h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mhg9-7866-m76h", - "modified": "2024-06-25T06:30:39Z", + "modified": "2024-07-03T18:46:55Z", "published": "2024-06-25T06:30:39Z", "aliases": [ "CVE-2024-37004" ], "details": "A maliciously crafted SLDPRT file, when parsed in ASMKERN229A.dll through Autodesk applications, can cause a use-after-free vulnerability. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-25T04:15:15Z" diff --git a/advisories/unreviewed/2024/06/GHSA-mv7f-hqh8-jwpv/GHSA-mv7f-hqh8-jwpv.json b/advisories/unreviewed/2024/06/GHSA-mv7f-hqh8-jwpv/GHSA-mv7f-hqh8-jwpv.json index 79a2d636d57..a2e0cea9d42 100644 --- a/advisories/unreviewed/2024/06/GHSA-mv7f-hqh8-jwpv/GHSA-mv7f-hqh8-jwpv.json +++ b/advisories/unreviewed/2024/06/GHSA-mv7f-hqh8-jwpv/GHSA-mv7f-hqh8-jwpv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mv7f-hqh8-jwpv", - "modified": "2024-06-25T03:31:07Z", + "modified": "2024-07-03T18:46:47Z", "published": "2024-06-25T03:31:07Z", "aliases": [ "CVE-2024-23145" ], "details": "A maliciously crafted PRT file, when parsed in opennurbs.dll through Autodesk applications, can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-25T03:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-pmxx-f7h9-2q7w/GHSA-pmxx-f7h9-2q7w.json b/advisories/unreviewed/2024/06/GHSA-pmxx-f7h9-2q7w/GHSA-pmxx-f7h9-2q7w.json index 56a280d3127..c9815e77171 100644 --- a/advisories/unreviewed/2024/06/GHSA-pmxx-f7h9-2q7w/GHSA-pmxx-f7h9-2q7w.json +++ b/advisories/unreviewed/2024/06/GHSA-pmxx-f7h9-2q7w/GHSA-pmxx-f7h9-2q7w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pmxx-f7h9-2q7w", - "modified": "2024-06-27T21:32:08Z", + "modified": "2024-07-03T18:47:10Z", "published": "2024-06-27T21:32:08Z", "aliases": [ "CVE-2024-39133" ], "details": "Heap Buffer Overflow vulnerability in zziplib v0.13.77 allows attackers to cause a denial of service via the __zzip_parse_root_directory() function at /zzip/zip.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-27T20:15:22Z" diff --git a/advisories/unreviewed/2024/06/GHSA-q2gr-59x6-9fh4/GHSA-q2gr-59x6-9fh4.json b/advisories/unreviewed/2024/06/GHSA-q2gr-59x6-9fh4/GHSA-q2gr-59x6-9fh4.json index 1aa175e6dfc..ffd9b90d2fa 100644 --- a/advisories/unreviewed/2024/06/GHSA-q2gr-59x6-9fh4/GHSA-q2gr-59x6-9fh4.json +++ b/advisories/unreviewed/2024/06/GHSA-q2gr-59x6-9fh4/GHSA-q2gr-59x6-9fh4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q2gr-59x6-9fh4", - "modified": "2024-06-25T03:31:07Z", + "modified": "2024-07-03T18:46:45Z", "published": "2024-06-25T03:31:07Z", "aliases": [ "CVE-2024-23140" ], "details": "A maliciously crafted 3DM and MODEL file, when parsed in opennurbs.dll and atf_api.dll through Autodesk applications, can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-25T02:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-q35c-jr5r-prg7/GHSA-q35c-jr5r-prg7.json b/advisories/unreviewed/2024/06/GHSA-q35c-jr5r-prg7/GHSA-q35c-jr5r-prg7.json index 3d2d4e276e6..2ceb3a3c371 100644 --- a/advisories/unreviewed/2024/06/GHSA-q35c-jr5r-prg7/GHSA-q35c-jr5r-prg7.json +++ b/advisories/unreviewed/2024/06/GHSA-q35c-jr5r-prg7/GHSA-q35c-jr5r-prg7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q35c-jr5r-prg7", - "modified": "2024-06-24T15:31:45Z", + "modified": "2024-07-03T18:46:25Z", "published": "2024-06-24T15:31:45Z", "aliases": [ "CVE-2024-38384" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nblk-cgroup: fix list corruption from reorder of WRITE ->lqueued\n\n__blkcg_rstat_flush() can be run anytime, especially when blk_cgroup_bio_start\nis being executed.\n\nIf WRITE of `->lqueued` is re-ordered with READ of 'bisc->lnode.next' in\nthe loop of __blkcg_rstat_flush(), `next_bisc` can be assigned with one\nstat instance being added in blk_cgroup_bio_start(), then the local\nlist in __blkcg_rstat_flush() could be corrupted.\n\nFix the issue by adding one barrier.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-24T14:15:12Z" diff --git a/advisories/unreviewed/2024/06/GHSA-q398-fvpf-fh5x/GHSA-q398-fvpf-fh5x.json b/advisories/unreviewed/2024/06/GHSA-q398-fvpf-fh5x/GHSA-q398-fvpf-fh5x.json index 479c2e867ba..c24b7472a68 100644 --- a/advisories/unreviewed/2024/06/GHSA-q398-fvpf-fh5x/GHSA-q398-fvpf-fh5x.json +++ b/advisories/unreviewed/2024/06/GHSA-q398-fvpf-fh5x/GHSA-q398-fvpf-fh5x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q398-fvpf-fh5x", - "modified": "2024-06-25T21:31:17Z", + "modified": "2024-07-03T18:46:57Z", "published": "2024-06-25T21:31:17Z", "aliases": [ "CVE-2024-37855" ], "details": "An issue in Nepstech Wifi Router xpon (terminal) NTPL-Xpon1GFEVN, hardware verstion 1.0 firmware 2.0.1 allows a remote attacker to execute arbitrary code via the router's Telnet port 2345 without requiring authentication credentials.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-25T21:15:59Z" diff --git a/advisories/unreviewed/2024/06/GHSA-r24r-m7ff-ghq2/GHSA-r24r-m7ff-ghq2.json b/advisories/unreviewed/2024/06/GHSA-r24r-m7ff-ghq2/GHSA-r24r-m7ff-ghq2.json index ddeb61c16a8..be193cf5359 100644 --- a/advisories/unreviewed/2024/06/GHSA-r24r-m7ff-ghq2/GHSA-r24r-m7ff-ghq2.json +++ b/advisories/unreviewed/2024/06/GHSA-r24r-m7ff-ghq2/GHSA-r24r-m7ff-ghq2.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-22" + "CWE-22", + "CWE-400" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-r3r3-mv62-6j33/GHSA-r3r3-mv62-6j33.json b/advisories/unreviewed/2024/06/GHSA-r3r3-mv62-6j33/GHSA-r3r3-mv62-6j33.json index df05c0e97e0..304f4369615 100644 --- a/advisories/unreviewed/2024/06/GHSA-r3r3-mv62-6j33/GHSA-r3r3-mv62-6j33.json +++ b/advisories/unreviewed/2024/06/GHSA-r3r3-mv62-6j33/GHSA-r3r3-mv62-6j33.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r3r3-mv62-6j33", - "modified": "2024-06-24T21:33:21Z", + "modified": "2024-07-03T18:46:35Z", "published": "2024-06-24T21:33:21Z", "aliases": [ "CVE-2024-38896" ], "details": "WAVLINK WN551K1 found a command injection vulnerability through the start_hour parameter of /cgi-bin/nightled.cgi.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-24T21:15:26Z" diff --git a/advisories/unreviewed/2024/06/GHSA-r52c-mh2p-jmpj/GHSA-r52c-mh2p-jmpj.json b/advisories/unreviewed/2024/06/GHSA-r52c-mh2p-jmpj/GHSA-r52c-mh2p-jmpj.json index 784bc4c92f5..3e377c12c30 100644 --- a/advisories/unreviewed/2024/06/GHSA-r52c-mh2p-jmpj/GHSA-r52c-mh2p-jmpj.json +++ b/advisories/unreviewed/2024/06/GHSA-r52c-mh2p-jmpj/GHSA-r52c-mh2p-jmpj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r52c-mh2p-jmpj", - "modified": "2024-06-30T00:31:57Z", + "modified": "2024-07-03T18:47:25Z", "published": "2024-06-30T00:31:57Z", "aliases": [ "CVE-2024-39848" ], "details": "Internet2 Grouper before 5.6 allows authentication bypass when LDAP authentication is used in certain ways. This is related to internet2.middleware.grouper.ws.security.WsGrouperLdapAuthentication and the use of the UyY29r password for the M3vwHr account. This also affects \"Grouper for Web Services\" before 4.13.1.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-29T22:15:02Z" diff --git a/advisories/unreviewed/2024/06/GHSA-r596-778h-jppv/GHSA-r596-778h-jppv.json b/advisories/unreviewed/2024/06/GHSA-r596-778h-jppv/GHSA-r596-778h-jppv.json index ae11e673160..99e4b441831 100644 --- a/advisories/unreviewed/2024/06/GHSA-r596-778h-jppv/GHSA-r596-778h-jppv.json +++ b/advisories/unreviewed/2024/06/GHSA-r596-778h-jppv/GHSA-r596-778h-jppv.json @@ -33,7 +33,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-r5mh-qgc2-26p2/GHSA-r5mh-qgc2-26p2.json b/advisories/unreviewed/2024/06/GHSA-r5mh-qgc2-26p2/GHSA-r5mh-qgc2-26p2.json index 9e74be2d91a..a5ecfd68ee8 100644 --- a/advisories/unreviewed/2024/06/GHSA-r5mh-qgc2-26p2/GHSA-r5mh-qgc2-26p2.json +++ b/advisories/unreviewed/2024/06/GHSA-r5mh-qgc2-26p2/GHSA-r5mh-qgc2-26p2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r5mh-qgc2-26p2", - "modified": "2024-06-27T03:30:56Z", + "modified": "2024-07-03T18:46:36Z", "published": "2024-06-25T00:34:46Z", "aliases": [ "CVE-2024-6290" ], "details": "Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-24T22:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-r6mp-q3jr-f6gv/GHSA-r6mp-q3jr-f6gv.json b/advisories/unreviewed/2024/06/GHSA-r6mp-q3jr-f6gv/GHSA-r6mp-q3jr-f6gv.json index 7345c4cec5d..97fa009c2d9 100644 --- a/advisories/unreviewed/2024/06/GHSA-r6mp-q3jr-f6gv/GHSA-r6mp-q3jr-f6gv.json +++ b/advisories/unreviewed/2024/06/GHSA-r6mp-q3jr-f6gv/GHSA-r6mp-q3jr-f6gv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r6mp-q3jr-f6gv", - "modified": "2024-06-25T00:34:46Z", + "modified": "2024-07-03T18:46:44Z", "published": "2024-06-25T00:34:46Z", "aliases": [ "CVE-2024-34988" ], "details": "SQL injection vulnerability in the module \"Complete for Create a Quote in Frontend + Backend Pro\" (askforaquotemodul) <= 1.0.51 from Buy Addons for PrestaShop allows attackers to view sensitive information and cause other impacts via methods `AskforaquotemodulcustomernewquoteModuleFrontController::run()`, `AskforaquotemoduladdproductnewquoteModuleFrontController::run()`, `AskforaquotemodulCouponcodeModuleFrontController::run()`, `AskforaquotemodulgetshippingcostModuleFrontController::run()`, `AskforaquotemodulgetstateModuleFrontController::run().`", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-24T23:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-r94p-w2wf-q9c9/GHSA-r94p-w2wf-q9c9.json b/advisories/unreviewed/2024/06/GHSA-r94p-w2wf-q9c9/GHSA-r94p-w2wf-q9c9.json index 9a143211733..f673deb8076 100644 --- a/advisories/unreviewed/2024/06/GHSA-r94p-w2wf-q9c9/GHSA-r94p-w2wf-q9c9.json +++ b/advisories/unreviewed/2024/06/GHSA-r94p-w2wf-q9c9/GHSA-r94p-w2wf-q9c9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r94p-w2wf-q9c9", - "modified": "2024-06-25T03:31:07Z", + "modified": "2024-07-03T18:46:47Z", "published": "2024-06-25T03:31:07Z", "aliases": [ "CVE-2024-37000" ], "details": "A maliciously crafted X_B file, when parsed in pskernel.DLL through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-119" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-25T03:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-rg45-hmxp-2hp7/GHSA-rg45-hmxp-2hp7.json b/advisories/unreviewed/2024/06/GHSA-rg45-hmxp-2hp7/GHSA-rg45-hmxp-2hp7.json index ac955a1c09c..d60763b17db 100644 --- a/advisories/unreviewed/2024/06/GHSA-rg45-hmxp-2hp7/GHSA-rg45-hmxp-2hp7.json +++ b/advisories/unreviewed/2024/06/GHSA-rg45-hmxp-2hp7/GHSA-rg45-hmxp-2hp7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rg45-hmxp-2hp7", - "modified": "2024-06-27T21:32:08Z", + "modified": "2024-07-03T18:47:10Z", "published": "2024-06-27T21:32:08Z", "aliases": [ "CVE-2024-39130" ], "details": "A NULL Pointer Dereference discovered in DumpTS v0.1.0-nightly allows attackers to cause a denial of service via the function DumpOneStream() at /src/DumpStream.cpp.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-27T20:15:22Z" diff --git a/advisories/unreviewed/2024/06/GHSA-rpvg-h6p6-42qj/GHSA-rpvg-h6p6-42qj.json b/advisories/unreviewed/2024/06/GHSA-rpvg-h6p6-42qj/GHSA-rpvg-h6p6-42qj.json index f7ef2abf2e7..9e2536c4c15 100644 --- a/advisories/unreviewed/2024/06/GHSA-rpvg-h6p6-42qj/GHSA-rpvg-h6p6-42qj.json +++ b/advisories/unreviewed/2024/06/GHSA-rpvg-h6p6-42qj/GHSA-rpvg-h6p6-42qj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rpvg-h6p6-42qj", - "modified": "2024-06-27T03:30:56Z", + "modified": "2024-07-03T18:46:37Z", "published": "2024-06-25T00:34:46Z", "aliases": [ "CVE-2024-6291" ], "details": "Use after free in Swiftshader in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-24T22:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-rxxp-gpv7-w3c9/GHSA-rxxp-gpv7-w3c9.json b/advisories/unreviewed/2024/06/GHSA-rxxp-gpv7-w3c9/GHSA-rxxp-gpv7-w3c9.json index 83d5a9f18f3..a120112e6dc 100644 --- a/advisories/unreviewed/2024/06/GHSA-rxxp-gpv7-w3c9/GHSA-rxxp-gpv7-w3c9.json +++ b/advisories/unreviewed/2024/06/GHSA-rxxp-gpv7-w3c9/GHSA-rxxp-gpv7-w3c9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rxxp-gpv7-w3c9", - "modified": "2024-06-25T06:30:40Z", + "modified": "2024-07-03T18:46:56Z", "published": "2024-06-25T06:30:39Z", "aliases": [ "CVE-2024-4759" ], "details": "The Mime Types Extended WordPress plugin through 0.11 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-25T06:15:11Z" diff --git a/advisories/unreviewed/2024/06/GHSA-v3rc-5q86-wwq8/GHSA-v3rc-5q86-wwq8.json b/advisories/unreviewed/2024/06/GHSA-v3rc-5q86-wwq8/GHSA-v3rc-5q86-wwq8.json index 5f5a81660f0..56f02eb4469 100644 --- a/advisories/unreviewed/2024/06/GHSA-v3rc-5q86-wwq8/GHSA-v3rc-5q86-wwq8.json +++ b/advisories/unreviewed/2024/06/GHSA-v3rc-5q86-wwq8/GHSA-v3rc-5q86-wwq8.json @@ -25,7 +25,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-798" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-v64w-g6gx-w35j/GHSA-v64w-g6gx-w35j.json b/advisories/unreviewed/2024/06/GHSA-v64w-g6gx-w35j/GHSA-v64w-g6gx-w35j.json index 60c9b42ef7a..3d589f5b95f 100644 --- a/advisories/unreviewed/2024/06/GHSA-v64w-g6gx-w35j/GHSA-v64w-g6gx-w35j.json +++ b/advisories/unreviewed/2024/06/GHSA-v64w-g6gx-w35j/GHSA-v64w-g6gx-w35j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v64w-g6gx-w35j", - "modified": "2024-06-27T18:31:32Z", + "modified": "2024-07-03T18:47:09Z", "published": "2024-06-27T18:31:31Z", "aliases": [ "CVE-2024-39669" ], "details": "In the Console in Soffid IAM before 3.5.39, necessary checks were not applied to some Java objects. A malicious agent could possibly execute arbitrary code in the Sync Server and compromise security.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-27T16:15:12Z" diff --git a/advisories/unreviewed/2024/06/GHSA-vc2p-rvx8-vfx3/GHSA-vc2p-rvx8-vfx3.json b/advisories/unreviewed/2024/06/GHSA-vc2p-rvx8-vfx3/GHSA-vc2p-rvx8-vfx3.json index 98b38a0f9ad..5458083eeb2 100644 --- a/advisories/unreviewed/2024/06/GHSA-vc2p-rvx8-vfx3/GHSA-vc2p-rvx8-vfx3.json +++ b/advisories/unreviewed/2024/06/GHSA-vc2p-rvx8-vfx3/GHSA-vc2p-rvx8-vfx3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vc2p-rvx8-vfx3", - "modified": "2024-06-25T06:30:39Z", + "modified": "2024-07-03T18:46:52Z", "published": "2024-06-25T06:30:39Z", "aliases": [ "CVE-2024-23159" ], "details": "A maliciously crafted STP file, when parsed in stp_aim_x64_vc15d.dll through Autodesk applications, can be used to uninitialized variables. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-457" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-25T04:15:14Z" diff --git a/advisories/unreviewed/2024/06/GHSA-vc52-cgfp-jw27/GHSA-vc52-cgfp-jw27.json b/advisories/unreviewed/2024/06/GHSA-vc52-cgfp-jw27/GHSA-vc52-cgfp-jw27.json index acd9fdce295..5e1098a87ef 100644 --- a/advisories/unreviewed/2024/06/GHSA-vc52-cgfp-jw27/GHSA-vc52-cgfp-jw27.json +++ b/advisories/unreviewed/2024/06/GHSA-vc52-cgfp-jw27/GHSA-vc52-cgfp-jw27.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vc52-cgfp-jw27", - "modified": "2024-06-25T15:31:09Z", + "modified": "2024-07-03T18:46:56Z", "published": "2024-06-25T15:31:08Z", "aliases": [ "CVE-2021-4440" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/xen: Drop USERGS_SYSRET64 paravirt call\n\ncommit afd30525a659ac0ae0904f0cb4a2ca75522c3123 upstream.\n\nUSERGS_SYSRET64 is used to return from a syscall via SYSRET, but\na Xen PV guest will nevertheless use the IRET hypercall, as there\nis no sysret PV hypercall defined.\n\nSo instead of testing all the prerequisites for doing a sysret and\nthen mangling the stack for Xen PV again for doing an iret just use\nthe iret exit from the beginning.\n\nThis can easily be done via an ALTERNATIVE like it is done for the\nsysenter compat case already.\n\nIt should be noted that this drops the optimization in Xen for not\nrestoring a few registers when returning to user mode, but it seems\nas if the saved instructions in the kernel more than compensate for\nthis drop (a kernel build in a Xen PV guest was slightly faster with\nthis patch applied).\n\nWhile at it remove the stale sysret32 remnants.\n\n [ pawan: Brad Spengler and Salvatore Bonaccorso \n\t reported a problem with the 5.10 backport commit edc702b4a820\n\t (\"x86/entry_64: Add VERW just before userspace transition\").\n\n\t When CONFIG_PARAVIRT_XXL=y, CLEAR_CPU_BUFFERS is not executed in\n\t syscall_return_via_sysret path as USERGS_SYSRET64 is runtime\n\t patched to:\n\n\t.cpu_usergs_sysret64 = { 0x0f, 0x01, 0xf8,\n\t\t\t\t 0x48, 0x0f, 0x07 }, // swapgs; sysretq\n\n\t which is missing CLEAR_CPU_BUFFERS. It turns out dropping\n\t USERGS_SYSRET64 simplifies the code, allowing CLEAR_CPU_BUFFERS\n\t to be explicitly added to syscall_return_via_sysret path. Below\n\t is with CONFIG_PARAVIRT_XXL=y and this patch applied:\n\n\t syscall_return_via_sysret:\n\t ...\n\t <+342>: swapgs\n\t <+345>: xchg %ax,%ax\n\t <+347>: verw -0x1a2(%rip) <------\n\t <+354>: sysretq\n ]", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-25T15:15:11Z" diff --git a/advisories/unreviewed/2024/06/GHSA-vcvg-6m26-26vr/GHSA-vcvg-6m26-26vr.json b/advisories/unreviewed/2024/06/GHSA-vcvg-6m26-26vr/GHSA-vcvg-6m26-26vr.json index 19402ee08a8..44e7c4af148 100644 --- a/advisories/unreviewed/2024/06/GHSA-vcvg-6m26-26vr/GHSA-vcvg-6m26-26vr.json +++ b/advisories/unreviewed/2024/06/GHSA-vcvg-6m26-26vr/GHSA-vcvg-6m26-26vr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vcvg-6m26-26vr", - "modified": "2024-06-29T18:31:41Z", + "modified": "2024-07-03T18:47:24Z", "published": "2024-06-29T18:31:41Z", "aliases": [ "CVE-2024-39840" ], "details": "Factorio before 1.1.101 allows a crafted server to execute arbitrary code on clients via a custom map that leverages the ability of certain Lua base module functions to execute bytecode and generate fake objects.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-29T17:15:09Z" diff --git a/advisories/unreviewed/2024/06/GHSA-vhfj-hc4x-wcvp/GHSA-vhfj-hc4x-wcvp.json b/advisories/unreviewed/2024/06/GHSA-vhfj-hc4x-wcvp/GHSA-vhfj-hc4x-wcvp.json index f9051c3b66b..879782ce19d 100644 --- a/advisories/unreviewed/2024/06/GHSA-vhfj-hc4x-wcvp/GHSA-vhfj-hc4x-wcvp.json +++ b/advisories/unreviewed/2024/06/GHSA-vhfj-hc4x-wcvp/GHSA-vhfj-hc4x-wcvp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vhfj-hc4x-wcvp", - "modified": "2024-06-24T21:33:21Z", + "modified": "2024-07-03T18:46:36Z", "published": "2024-06-24T21:33:21Z", "aliases": [ "CVE-2024-38903" ], "details": "H3C Magic R230 V100R002's udpserver opens port 9034, allowing attackers to execute arbitrary commands.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-24T21:15:26Z" diff --git a/advisories/unreviewed/2024/06/GHSA-vqjg-5pqm-q7ph/GHSA-vqjg-5pqm-q7ph.json b/advisories/unreviewed/2024/06/GHSA-vqjg-5pqm-q7ph/GHSA-vqjg-5pqm-q7ph.json index d944b4cf764..bdb0100bab1 100644 --- a/advisories/unreviewed/2024/06/GHSA-vqjg-5pqm-q7ph/GHSA-vqjg-5pqm-q7ph.json +++ b/advisories/unreviewed/2024/06/GHSA-vqjg-5pqm-q7ph/GHSA-vqjg-5pqm-q7ph.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-79" + "CWE-79", + "CWE-80" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-w28f-v4hj-9fxg/GHSA-w28f-v4hj-9fxg.json b/advisories/unreviewed/2024/06/GHSA-w28f-v4hj-9fxg/GHSA-w28f-v4hj-9fxg.json index 114fc152ae3..707e928256a 100644 --- a/advisories/unreviewed/2024/06/GHSA-w28f-v4hj-9fxg/GHSA-w28f-v4hj-9fxg.json +++ b/advisories/unreviewed/2024/06/GHSA-w28f-v4hj-9fxg/GHSA-w28f-v4hj-9fxg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w28f-v4hj-9fxg", - "modified": "2024-06-25T06:30:39Z", + "modified": "2024-07-03T18:46:52Z", "published": "2024-06-25T06:30:39Z", "aliases": [ "CVE-2024-36999" ], "details": "A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk applications, can force an Out-of-Bounds Write. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-25T04:15:15Z" diff --git a/advisories/unreviewed/2024/06/GHSA-wv29-6vvq-vc4h/GHSA-wv29-6vvq-vc4h.json b/advisories/unreviewed/2024/06/GHSA-wv29-6vvq-vc4h/GHSA-wv29-6vvq-vc4h.json index 88dac754753..856f095f937 100644 --- a/advisories/unreviewed/2024/06/GHSA-wv29-6vvq-vc4h/GHSA-wv29-6vvq-vc4h.json +++ b/advisories/unreviewed/2024/06/GHSA-wv29-6vvq-vc4h/GHSA-wv29-6vvq-vc4h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wv29-6vvq-vc4h", - "modified": "2024-06-27T18:31:31Z", + "modified": "2024-07-03T18:47:09Z", "published": "2024-06-27T18:31:31Z", "aliases": [ "CVE-2024-28820" ], "details": "Buffer overflow in the extract_openvpn_cr function in openvpn-cr.c in openvpn-auth-ldap (aka the Three Rings Auth-LDAP plugin for OpenVPN) 2.0.4 allows attackers with a valid LDAP username and who can control the challenge/response password field to pass a string with more than 14 colons into this field and cause a buffer overflow.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-27T16:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-wxj9-7p6q-955h/GHSA-wxj9-7p6q-955h.json b/advisories/unreviewed/2024/06/GHSA-wxj9-7p6q-955h/GHSA-wxj9-7p6q-955h.json index 0da9edb3917..b70dd7d2698 100644 --- a/advisories/unreviewed/2024/06/GHSA-wxj9-7p6q-955h/GHSA-wxj9-7p6q-955h.json +++ b/advisories/unreviewed/2024/06/GHSA-wxj9-7p6q-955h/GHSA-wxj9-7p6q-955h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wxj9-7p6q-955h", - "modified": "2024-06-27T00:31:04Z", + "modified": "2024-07-03T18:47:04Z", "published": "2024-06-27T00:31:04Z", "aliases": [ "CVE-2024-37734" ], "details": "An issue in OpenEMR 7.0.2 allows a remote attacker to escalate privileges viaa crafted POST request using the noteid parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-279" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-26T22:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-x5j4-q642-fm34/GHSA-x5j4-q642-fm34.json b/advisories/unreviewed/2024/06/GHSA-x5j4-q642-fm34/GHSA-x5j4-q642-fm34.json index cc7661051b7..8b7af98177f 100644 --- a/advisories/unreviewed/2024/06/GHSA-x5j4-q642-fm34/GHSA-x5j4-q642-fm34.json +++ b/advisories/unreviewed/2024/06/GHSA-x5j4-q642-fm34/GHSA-x5j4-q642-fm34.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x5j4-q642-fm34", - "modified": "2024-06-27T15:30:45Z", + "modified": "2024-07-03T18:47:05Z", "published": "2024-06-27T15:30:45Z", "aliases": [ "CVE-2024-39153" ], "details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/info_deal.php?mudi=del&dataType=news&dataTypeCN.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-27T14:15:15Z" diff --git a/advisories/unreviewed/2024/06/GHSA-x6j2-4hm4-hxj3/GHSA-x6j2-4hm4-hxj3.json b/advisories/unreviewed/2024/06/GHSA-x6j2-4hm4-hxj3/GHSA-x6j2-4hm4-hxj3.json index 989d60fe690..19e3af6853e 100644 --- a/advisories/unreviewed/2024/06/GHSA-x6j2-4hm4-hxj3/GHSA-x6j2-4hm4-hxj3.json +++ b/advisories/unreviewed/2024/06/GHSA-x6j2-4hm4-hxj3/GHSA-x6j2-4hm4-hxj3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x6j2-4hm4-hxj3", - "modified": "2024-06-25T06:30:39Z", + "modified": "2024-07-03T18:46:51Z", "published": "2024-06-25T06:30:39Z", "aliases": [ "CVE-2024-23156" ], "details": "A maliciously crafted 3DM file, when parsed in opennurbs.dll and ASMkern229A.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-119" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-25T04:15:13Z" diff --git a/advisories/unreviewed/2024/06/GHSA-x7qh-ghv7-7g8x/GHSA-x7qh-ghv7-7g8x.json b/advisories/unreviewed/2024/06/GHSA-x7qh-ghv7-7g8x/GHSA-x7qh-ghv7-7g8x.json index eb7baa2a42a..f0478d2c86b 100644 --- a/advisories/unreviewed/2024/06/GHSA-x7qh-ghv7-7g8x/GHSA-x7qh-ghv7-7g8x.json +++ b/advisories/unreviewed/2024/06/GHSA-x7qh-ghv7-7g8x/GHSA-x7qh-ghv7-7g8x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x7qh-ghv7-7g8x", - "modified": "2024-06-26T06:30:29Z", + "modified": "2024-07-03T18:46:59Z", "published": "2024-06-26T06:30:29Z", "aliases": [ "CVE-2024-4957" ], "details": "The Frontend Checklist WordPress plugin through 2.3.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-26T06:15:16Z" diff --git a/advisories/unreviewed/2024/07/GHSA-26mf-pq9r-c4cw/GHSA-26mf-pq9r-c4cw.json b/advisories/unreviewed/2024/07/GHSA-26mf-pq9r-c4cw/GHSA-26mf-pq9r-c4cw.json new file mode 100644 index 00000000000..122dd62c28a --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-26mf-pq9r-c4cw/GHSA-26mf-pq9r-c4cw.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-26mf-pq9r-c4cw", + "modified": "2024-07-03T18:48:05Z", + "published": "2024-07-03T18:48:05Z", + "aliases": [ + "CVE-2024-6263" + ], + "details": "The WP Lightbox 2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versions up to, and including, 3.0.6.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6263" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-lightbox-2/trunk/wp-lightbox-2.js" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?new=3108386%40wp-lightbox-2&old=3046989%40wp-lightbox-2" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/fe275351-a547-440d-9e8c-c464ed333aa9?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T08:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-2983-rc95-vrc7/GHSA-2983-rc95-vrc7.json b/advisories/unreviewed/2024/07/GHSA-2983-rc95-vrc7/GHSA-2983-rc95-vrc7.json index f0ac946d3e6..cfce885884c 100644 --- a/advisories/unreviewed/2024/07/GHSA-2983-rc95-vrc7/GHSA-2983-rc95-vrc7.json +++ b/advisories/unreviewed/2024/07/GHSA-2983-rc95-vrc7/GHSA-2983-rc95-vrc7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2983-rc95-vrc7", - "modified": "2024-07-01T15:32:04Z", + "modified": "2024-07-03T18:47:29Z", "published": "2024-07-01T15:32:04Z", "aliases": [ "CVE-2024-0153" ], "details": "Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Arm Ltd Valhall GPU Firmware, Arm Ltd Arm 5th Gen GPU Architecture Firmware allows a local non-privileged user to make improper GPU processing operations to access a limited amount outside of buffer bounds. If the operations are carefully prepared, then this in turn could give them access to all system memory. This issue affects Valhall GPU Firmware: from r29p0 through r46p0; Arm 5th Gen GPU Architecture Firmware: from r41p0 through r46p0.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-119" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-01T09:15:06Z" diff --git a/advisories/unreviewed/2024/07/GHSA-2g7h-4jrf-ppfh/GHSA-2g7h-4jrf-ppfh.json b/advisories/unreviewed/2024/07/GHSA-2g7h-4jrf-ppfh/GHSA-2g7h-4jrf-ppfh.json index 6a183963635..7f0b16e50c0 100644 --- a/advisories/unreviewed/2024/07/GHSA-2g7h-4jrf-ppfh/GHSA-2g7h-4jrf-ppfh.json +++ b/advisories/unreviewed/2024/07/GHSA-2g7h-4jrf-ppfh/GHSA-2g7h-4jrf-ppfh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2g7h-4jrf-ppfh", - "modified": "2024-07-02T09:32:05Z", + "modified": "2024-07-03T18:47:47Z", "published": "2024-07-02T09:32:05Z", "aliases": [ "CVE-2024-1427" @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-2gf8-64pg-49p7/GHSA-2gf8-64pg-49p7.json b/advisories/unreviewed/2024/07/GHSA-2gf8-64pg-49p7/GHSA-2gf8-64pg-49p7.json new file mode 100644 index 00000000000..db4c484a143 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-2gf8-64pg-49p7/GHSA-2gf8-64pg-49p7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2gf8-64pg-49p7", + "modified": "2024-07-03T18:48:03Z", + "published": "2024-07-03T18:48:03Z", + "aliases": [ + "CVE-2024-2375" + ], + "details": "The WPQA Builder WordPress plugin before 6.1.1 does not sanitise and escape some of its Slider settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2375" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/3d144e1c-a1f4-4c5a-93e2-4296a96d4ba2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T06:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-2r64-mj4p-q485/GHSA-2r64-mj4p-q485.json b/advisories/unreviewed/2024/07/GHSA-2r64-mj4p-q485/GHSA-2r64-mj4p-q485.json new file mode 100644 index 00000000000..0c479d5dbf9 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-2r64-mj4p-q485/GHSA-2r64-mj4p-q485.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2r64-mj4p-q485", + "modified": "2024-07-03T18:47:20Z", + "published": "2024-07-03T18:47:20Z", + "aliases": [ + "CVE-2024-39704" + ], + "details": "Soft Circle French-Bread Melty Blood: Actress Again: Current Code through 1.07 Rev. 1.4.0 allows a remote attacker to execute arbitrary code on a client's machine via a crafted packet on TCP port 46318.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39704" + }, + { + "type": "WEB", + "url": "https://github.com/MikeIsAStar/Melty-Blood-Actress-Again-Current-Code-Remote-Code-Execution" + }, + { + "type": "WEB", + "url": "https://pastebin.com/agpnQmhu" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-28T13:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-2wcw-rcf9-qm36/GHSA-2wcw-rcf9-qm36.json b/advisories/unreviewed/2024/07/GHSA-2wcw-rcf9-qm36/GHSA-2wcw-rcf9-qm36.json index 4278010f7c4..4129fd70bac 100644 --- a/advisories/unreviewed/2024/07/GHSA-2wcw-rcf9-qm36/GHSA-2wcw-rcf9-qm36.json +++ b/advisories/unreviewed/2024/07/GHSA-2wcw-rcf9-qm36/GHSA-2wcw-rcf9-qm36.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2wcw-rcf9-qm36", - "modified": "2024-07-01T21:31:15Z", + "modified": "2024-07-03T18:47:46Z", "published": "2024-07-01T21:31:15Z", "aliases": [ "CVE-2024-39573" ], "details": "Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to be handled by mod_proxy.\nUsers are recommended to upgrade to version 2.4.60, which fixes this issue.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-20" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-01T19:15:05Z" diff --git a/advisories/unreviewed/2024/07/GHSA-2x8c-95vh-gfv4/GHSA-2x8c-95vh-gfv4.json b/advisories/unreviewed/2024/07/GHSA-2x8c-95vh-gfv4/GHSA-2x8c-95vh-gfv4.json index 761349f9193..d497f24adbf 100644 --- a/advisories/unreviewed/2024/07/GHSA-2x8c-95vh-gfv4/GHSA-2x8c-95vh-gfv4.json +++ b/advisories/unreviewed/2024/07/GHSA-2x8c-95vh-gfv4/GHSA-2x8c-95vh-gfv4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2x8c-95vh-gfv4", - "modified": "2024-07-02T21:32:06Z", + "modified": "2024-07-03T18:47:42Z", "published": "2024-07-01T15:32:33Z", "aliases": [ "CVE-2024-6387" @@ -113,6 +113,10 @@ "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-6387" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:4312" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/07/01/12" @@ -124,6 +128,26 @@ { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/07/02/1" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/07/03/1" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/07/03/2" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/07/03/3" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/07/03/4" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/07/03/5" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-3h7x-5mvc-5r6p/GHSA-3h7x-5mvc-5r6p.json b/advisories/unreviewed/2024/07/GHSA-3h7x-5mvc-5r6p/GHSA-3h7x-5mvc-5r6p.json index f2b802a044e..7b10206e8e2 100644 --- a/advisories/unreviewed/2024/07/GHSA-3h7x-5mvc-5r6p/GHSA-3h7x-5mvc-5r6p.json +++ b/advisories/unreviewed/2024/07/GHSA-3h7x-5mvc-5r6p/GHSA-3h7x-5mvc-5r6p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3h7x-5mvc-5r6p", - "modified": "2024-07-02T21:32:14Z", + "modified": "2024-07-03T18:47:55Z", "published": "2024-07-02T21:32:14Z", "aliases": [ "CVE-2024-39143" ], "details": "A stored cross-site scripting (XSS) vulnerability exists in ResidenceCMS 2.10.1 that allows a low-privilege user to create malicious property content with HTML inside which acts as a stored XSS payload.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-02T14:15:13Z" diff --git a/advisories/unreviewed/2024/07/GHSA-459h-qwrj-j9gc/GHSA-459h-qwrj-j9gc.json b/advisories/unreviewed/2024/07/GHSA-459h-qwrj-j9gc/GHSA-459h-qwrj-j9gc.json new file mode 100644 index 00000000000..5fbf54f83c0 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-459h-qwrj-j9gc/GHSA-459h-qwrj-j9gc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-459h-qwrj-j9gc", + "modified": "2024-07-03T18:48:01Z", + "published": "2024-07-03T18:48:01Z", + "aliases": [ + "CVE-2024-2231" + ], + "details": "The allows any authenticated user to join a private group due to a missing authorization check on a function", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2231" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/119d2d93-3b71-4ce9-b385-4e6f57b162cb" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T06:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-4f69-vpc6-qrx2/GHSA-4f69-vpc6-qrx2.json b/advisories/unreviewed/2024/07/GHSA-4f69-vpc6-qrx2/GHSA-4f69-vpc6-qrx2.json new file mode 100644 index 00000000000..5ecaca1f0bf --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-4f69-vpc6-qrx2/GHSA-4f69-vpc6-qrx2.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4f69-vpc6-qrx2", + "modified": "2024-07-03T18:47:18Z", + "published": "2024-07-03T18:47:18Z", + "aliases": [ + "CVE-2024-5735" + ], + "details": "Full Path Disclosure vulnerability in AdmirorFrames Joomla! extension in afHelper.php script allows an unauthorised attacker to retrieve location of web root folder. This issue affects AdmirorFrames: before 5.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:D/RE:L/U:Green" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5735" + }, + { + "type": "WEB", + "url": "https://github.com/vasiljevski/admirorframes/issues/3" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2024/06/CVE-2024-5735" + }, + { + "type": "WEB", + "url": "https://cert.pl/posts/2024/06/CVE-2024-5735" + }, + { + "type": "WEB", + "url": "https://github.com/afine-com/CVE-2024-5735" + }, + { + "type": "WEB", + "url": "https://github.com/sectroyer/CVEs/tree/main/CVE-2024-5735" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-28T12:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-4fr2-p4v7-6hwq/GHSA-4fr2-p4v7-6hwq.json b/advisories/unreviewed/2024/07/GHSA-4fr2-p4v7-6hwq/GHSA-4fr2-p4v7-6hwq.json index 8309de5ff94..f6e380c0136 100644 --- a/advisories/unreviewed/2024/07/GHSA-4fr2-p4v7-6hwq/GHSA-4fr2-p4v7-6hwq.json +++ b/advisories/unreviewed/2024/07/GHSA-4fr2-p4v7-6hwq/GHSA-4fr2-p4v7-6hwq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4fr2-p4v7-6hwq", - "modified": "2024-07-01T21:31:16Z", + "modified": "2024-07-03T18:47:46Z", "published": "2024-07-01T21:31:16Z", "aliases": [ "CVE-2024-32228" ], "details": "FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a SEGV at libavcodec/hevcdec.c:2947:22 in hevc_frame_end.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-01T21:15:03Z" diff --git a/advisories/unreviewed/2024/07/GHSA-5cg2-wmx6-ccqv/GHSA-5cg2-wmx6-ccqv.json b/advisories/unreviewed/2024/07/GHSA-5cg2-wmx6-ccqv/GHSA-5cg2-wmx6-ccqv.json new file mode 100644 index 00000000000..44cc03c47e1 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-5cg2-wmx6-ccqv/GHSA-5cg2-wmx6-ccqv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5cg2-wmx6-ccqv", + "modified": "2024-07-03T18:48:08Z", + "published": "2024-07-03T18:48:08Z", + "aliases": [ + "CVE-2024-36257" + ], + "details": "Mattermost versions 9.5.x <= 9.5.5 and 9.8.0, when using shared channels with multiple remote servers connected, fail to check that the remote server A requesting the server B to update the profile picture of a user is the remote that actually has the user as a local one . This allows a malicious remote A to change the profile images of users that belong to another remote server C that is connected to the server A.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36257" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T09:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-5q6f-fphm-w5qc/GHSA-5q6f-fphm-w5qc.json b/advisories/unreviewed/2024/07/GHSA-5q6f-fphm-w5qc/GHSA-5q6f-fphm-w5qc.json new file mode 100644 index 00000000000..33e1ea1287b --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-5q6f-fphm-w5qc/GHSA-5q6f-fphm-w5qc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5q6f-fphm-w5qc", + "modified": "2024-07-03T18:48:02Z", + "published": "2024-07-03T18:48:02Z", + "aliases": [ + "CVE-2024-2235" + ], + "details": "The Himer WordPress theme before 2.1.1 does not have CSRF checks in some places, which could allow attackers to make users vote on any polls, including those they don't have access to via a CSRF attack", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2235" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/62c8a564-225e-4202-9bb0-03029fa4fd42" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T06:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-5rmp-w29x-xm84/GHSA-5rmp-w29x-xm84.json b/advisories/unreviewed/2024/07/GHSA-5rmp-w29x-xm84/GHSA-5rmp-w29x-xm84.json index 3f99d73f235..e353bd2cf27 100644 --- a/advisories/unreviewed/2024/07/GHSA-5rmp-w29x-xm84/GHSA-5rmp-w29x-xm84.json +++ b/advisories/unreviewed/2024/07/GHSA-5rmp-w29x-xm84/GHSA-5rmp-w29x-xm84.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5rmp-w29x-xm84", - "modified": "2024-07-01T06:31:16Z", + "modified": "2024-07-03T18:47:26Z", "published": "2024-07-01T06:31:16Z", "aliases": [ "CVE-2024-20077" ], "details": "In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01297807; Issue ID: MSV-1482.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-119" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-01T05:15:04Z" diff --git a/advisories/unreviewed/2024/07/GHSA-67h2-79p4-g5r8/GHSA-67h2-79p4-g5r8.json b/advisories/unreviewed/2024/07/GHSA-67h2-79p4-g5r8/GHSA-67h2-79p4-g5r8.json new file mode 100644 index 00000000000..1f33c140457 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-67h2-79p4-g5r8/GHSA-67h2-79p4-g5r8.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-67h2-79p4-g5r8", + "modified": "2024-07-03T18:48:13Z", + "published": "2024-07-03T18:48:13Z", + "aliases": [ + "CVE-2024-6469" + ], + "details": "A vulnerability was found in playSMS 1.4.3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php?app=main&inc=feature_firewall&op=firewall_list of the component Template Handler. The manipulation of the argument IP address with the input {{`id`} leads to injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-270277 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6469" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.270277" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.270277" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.363730" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T11:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-69jw-gxcr-pxhc/GHSA-69jw-gxcr-pxhc.json b/advisories/unreviewed/2024/07/GHSA-69jw-gxcr-pxhc/GHSA-69jw-gxcr-pxhc.json new file mode 100644 index 00000000000..75c66552d28 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-69jw-gxcr-pxhc/GHSA-69jw-gxcr-pxhc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-69jw-gxcr-pxhc", + "modified": "2024-07-03T18:48:02Z", + "published": "2024-07-03T18:48:02Z", + "aliases": [ + "CVE-2024-2234" + ], + "details": "The Himer WordPress theme before 2.1.1 does not sanitise and escape some of its Post settings, which could allow high privilege users such as Contributor to perform Stored Cross-Site Scripting attacks", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2234" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/37018a3f-895f-48f7-b033-c051e2462830" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T06:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-6w4j-5cmh-9j58/GHSA-6w4j-5cmh-9j58.json b/advisories/unreviewed/2024/07/GHSA-6w4j-5cmh-9j58/GHSA-6w4j-5cmh-9j58.json new file mode 100644 index 00000000000..5bf1f3dc31b --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-6w4j-5cmh-9j58/GHSA-6w4j-5cmh-9j58.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6w4j-5cmh-9j58", + "modified": "2024-07-03T18:48:04Z", + "published": "2024-07-03T18:48:04Z", + "aliases": [ + "CVE-2024-38453" + ], + "details": "The Avalara for Salesforce CPQ app before 7.0 for Salesforce allows attackers to read an API key. NOTE: the current version is 11 as of mid-2024.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38453" + }, + { + "type": "WEB", + "url": "https://appexchange.salesforce.com/appxListingDetail?listingId=a0N3A00000FKAoOUAX" + }, + { + "type": "WEB", + "url": "https://deneyed.com/blog/avalara" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T06:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-6x56-7q94-5745/GHSA-6x56-7q94-5745.json b/advisories/unreviewed/2024/07/GHSA-6x56-7q94-5745/GHSA-6x56-7q94-5745.json new file mode 100644 index 00000000000..844744fecca --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-6x56-7q94-5745/GHSA-6x56-7q94-5745.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6x56-7q94-5745", + "modified": "2024-07-03T18:48:16Z", + "published": "2024-07-03T18:48:16Z", + "aliases": [ + "CVE-2024-32937" + ], + "details": "An os command injection vulnerability exists in the CWMP SelfDefinedTimeZone functionality of Grandstream GXP2135 1.0.9.129, 1.0.11.74 and 1.0.11.79. A specially crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of malicious packets to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32937" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-1978" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T14:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-7637-3fm3-m2q3/GHSA-7637-3fm3-m2q3.json b/advisories/unreviewed/2024/07/GHSA-7637-3fm3-m2q3/GHSA-7637-3fm3-m2q3.json new file mode 100644 index 00000000000..2ff00533d03 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-7637-3fm3-m2q3/GHSA-7637-3fm3-m2q3.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7637-3fm3-m2q3", + "modified": "2024-07-03T18:48:16Z", + "published": "2024-07-03T18:48:16Z", + "aliases": [ + "CVE-2024-5672" + ], + "details": "A high privileged remote attacker can execute arbitrary system commands via GET requests due to improper neutralization of special elements used in an OS command.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5672" + }, + { + "type": "WEB", + "url": "https://cert.vde.com/en/advisories/VDE-2024-030" + }, + { + "type": "WEB", + "url": "https://cert.vde.com/en/advisories/VDE-2024-032" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T13:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-76jf-55hx-4969/GHSA-76jf-55hx-4969.json b/advisories/unreviewed/2024/07/GHSA-76jf-55hx-4969/GHSA-76jf-55hx-4969.json new file mode 100644 index 00000000000..5d7f4579571 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-76jf-55hx-4969/GHSA-76jf-55hx-4969.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-76jf-55hx-4969", + "modified": "2024-07-03T18:48:09Z", + "published": "2024-07-03T18:48:09Z", + "aliases": [ + "CVE-2024-39361" + ], + "details": "Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5 fail to prevent users from specifying a RemoteId for their posts which allows an attacker to specify both a remoteId and the post ID, resulting in creating a post with a user-defined post ID. This can cause some broken functionality in the channel or thread with user-defined posts", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39361" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T09:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-796p-jr7h-8vmq/GHSA-796p-jr7h-8vmq.json b/advisories/unreviewed/2024/07/GHSA-796p-jr7h-8vmq/GHSA-796p-jr7h-8vmq.json new file mode 100644 index 00000000000..93afc6fffcf --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-796p-jr7h-8vmq/GHSA-796p-jr7h-8vmq.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-796p-jr7h-8vmq", + "modified": "2024-07-03T18:47:58Z", + "published": "2024-07-03T18:47:58Z", + "aliases": [ + "CVE-2024-39920" + ], + "details": "The TCP protocol in RFC 9293 has a timing side channel that makes it easier for remote attackers to infer the content of one TCP connection from a client system (to any server), when that client system is concurrently obtaining TCP data at a slow rate from an attacker-controlled server, aka the \"SnailLoad\" issue. For example, the attack can begin by measuring RTTs via the TCP segments whose role is to provide an ACK control bit and an Acknowledgment Number.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39920" + }, + { + "type": "WEB", + "url": "https://github.com/IAIK/SnailLoad" + }, + { + "type": "WEB", + "url": "https://news.ycombinator.com/item?id=40809629" + }, + { + "type": "WEB", + "url": "https://twitter.com/tugraz/status/1805272833322299412" + }, + { + "type": "WEB", + "url": "https://www.instagram.com/p/C8wpO1UtExw" + }, + { + "type": "WEB", + "url": "https://www.rfc-editor.org/rfc/rfc9293.txt" + }, + { + "type": "WEB", + "url": "https://www.snailload.com" + }, + { + "type": "WEB", + "url": "https://www.snailload.com/snailload.pdf" + }, + { + "type": "WEB", + "url": "https://www.tugraz.at/en/tu-graz/services/news-stories/tu-graz-news/singleview/article/neue-sicherheitsluecke-erlaubt-ueberwachung-besuchter-websites-und-angesehener-videos" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T04:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-8298-gq74-vj5g/GHSA-8298-gq74-vj5g.json b/advisories/unreviewed/2024/07/GHSA-8298-gq74-vj5g/GHSA-8298-gq74-vj5g.json new file mode 100644 index 00000000000..0419538ff35 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-8298-gq74-vj5g/GHSA-8298-gq74-vj5g.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8298-gq74-vj5g", + "modified": "2024-07-03T18:48:00Z", + "published": "2024-07-03T18:48:00Z", + "aliases": [ + "CVE-2024-4543" + ], + "details": "The Snippet Shortcodes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.1.4. This is due to missing or incorrect nonce validation when adding or editing shortcodes. This makes it possible for unauthenticated attackers to modify shortcodes via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4543" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3110951?contextall=1" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/127b20c4-cd7c-4d04-b32f-bcc26beb2c35?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T05:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-85f9-vc47-9pr8/GHSA-85f9-vc47-9pr8.json b/advisories/unreviewed/2024/07/GHSA-85f9-vc47-9pr8/GHSA-85f9-vc47-9pr8.json index 77fc225d679..02d35ce0809 100644 --- a/advisories/unreviewed/2024/07/GHSA-85f9-vc47-9pr8/GHSA-85f9-vc47-9pr8.json +++ b/advisories/unreviewed/2024/07/GHSA-85f9-vc47-9pr8/GHSA-85f9-vc47-9pr8.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-285" + "CWE-285", + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-8fxq-mgg4-pxg6/GHSA-8fxq-mgg4-pxg6.json b/advisories/unreviewed/2024/07/GHSA-8fxq-mgg4-pxg6/GHSA-8fxq-mgg4-pxg6.json new file mode 100644 index 00000000000..1c5ad24b6be --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-8fxq-mgg4-pxg6/GHSA-8fxq-mgg4-pxg6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8fxq-mgg4-pxg6", + "modified": "2024-07-03T18:48:25Z", + "published": "2024-07-03T18:48:25Z", + "aliases": [ + "CVE-2024-6052" + ], + "details": "Stored XSS in Checkmk before versions 2.3.0p8, 2.2.0p29, 2.1.0p45, and 2.0.0 (EOL) allows users to execute arbitrary scripts by injecting HTML elements", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6052" + }, + { + "type": "WEB", + "url": "https://checkmk.com/werk/17010" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-80" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T15:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-8wxx-35qc-vp6r/GHSA-8wxx-35qc-vp6r.json b/advisories/unreviewed/2024/07/GHSA-8wxx-35qc-vp6r/GHSA-8wxx-35qc-vp6r.json new file mode 100644 index 00000000000..3ed5ee98277 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-8wxx-35qc-vp6r/GHSA-8wxx-35qc-vp6r.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8wxx-35qc-vp6r", + "modified": "2024-07-03T18:48:20Z", + "published": "2024-07-03T18:48:20Z", + "aliases": [ + "CVE-2024-39223" + ], + "details": "An authentication bypass in the SSH service of gost v2.11.5 allows attackers to intercept communications via setting the HostKeyCallback function to ssh.InsecureIgnoreHostKey", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39223" + }, + { + "type": "WEB", + "url": "https://github.com/ginuerzh/gost/issues/1034" + }, + { + "type": "WEB", + "url": "https://gist.github.com/nyxfqq/a7242170b1118e78436a62dee4e09e8a" + }, + { + "type": "WEB", + "url": "https://github.com/ginuerzh/gost/blob/729d0e70005607dc7c69fc1de62fd8fe21f85355/ssh.go#L229" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T15:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-9p46-p224-qhfw/GHSA-9p46-p224-qhfw.json b/advisories/unreviewed/2024/07/GHSA-9p46-p224-qhfw/GHSA-9p46-p224-qhfw.json new file mode 100644 index 00000000000..3994d5b7b23 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-9p46-p224-qhfw/GHSA-9p46-p224-qhfw.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9p46-p224-qhfw", + "modified": "2024-07-03T18:48:19Z", + "published": "2024-07-03T18:48:19Z", + "aliases": [ + "CVE-2024-6471" + ], + "details": "A vulnerability classified as critical has been found in SourceCodester Online Tours & Travels Management 1.0. This affects an unknown part of the file sms_setting.php. The manipulation of the argument uname leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-270279.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6471" + }, + { + "type": "WEB", + "url": "https://blog.csdn.net/ENTICE1208/article/details/140141934" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.270279" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.270279" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.367953" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T14:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-c2jm-v3mf-w53g/GHSA-c2jm-v3mf-w53g.json b/advisories/unreviewed/2024/07/GHSA-c2jm-v3mf-w53g/GHSA-c2jm-v3mf-w53g.json index abd92434af9..84d5ed35994 100644 --- a/advisories/unreviewed/2024/07/GHSA-c2jm-v3mf-w53g/GHSA-c2jm-v3mf-w53g.json +++ b/advisories/unreviewed/2024/07/GHSA-c2jm-v3mf-w53g/GHSA-c2jm-v3mf-w53g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c2jm-v3mf-w53g", - "modified": "2024-07-02T09:32:05Z", + "modified": "2024-07-03T18:47:47Z", "published": "2024-07-02T09:32:05Z", "aliases": [ "CVE-2024-4627" ], "details": "The Rank Math SEO WordPress plugin before 1.0.219 does not sanitise and escape some of its settings, which could allow users with access to the General Settings (by default admin, however such access can be given to lower roles via the Role Manager feature of the Rank Math SEO WordPress plugin before 1.0.219) to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-02T06:15:04Z" diff --git a/advisories/unreviewed/2024/07/GHSA-chxv-752j-4vj4/GHSA-chxv-752j-4vj4.json b/advisories/unreviewed/2024/07/GHSA-chxv-752j-4vj4/GHSA-chxv-752j-4vj4.json new file mode 100644 index 00000000000..ab5a191887c --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-chxv-752j-4vj4/GHSA-chxv-752j-4vj4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-chxv-752j-4vj4", + "modified": "2024-07-03T18:48:18Z", + "published": "2024-07-03T18:48:18Z", + "aliases": [ + "CVE-2024-37726" + ], + "details": "Insecure Permissions vulnerability in Micro-Star International Co., Ltd MSI Center v.2.0.36.0 allows a local attacker to escalate privileges via the Export System Info function in MSI.CentralServer.exe", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37726" + }, + { + "type": "WEB", + "url": "https://github.com/carsonchan12345/CVE-2024-37726-MSI-Center-Local-Privilege-Escalation" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T14:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-f238-mg8w-5483/GHSA-f238-mg8w-5483.json b/advisories/unreviewed/2024/07/GHSA-f238-mg8w-5483/GHSA-f238-mg8w-5483.json new file mode 100644 index 00000000000..54c35867071 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-f238-mg8w-5483/GHSA-f238-mg8w-5483.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f238-mg8w-5483", + "modified": "2024-07-03T18:48:13Z", + "published": "2024-07-03T18:48:13Z", + "aliases": [ + "CVE-2024-6426" + ], + "details": "Information exposure vulnerability in MESbook 20221021.03 version, the exploitation of which could allow a local attacker, with user privileges, to access different resources by changing the API value of the application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6426" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-mesbook" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T12:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-f848-67vp-29cf/GHSA-f848-67vp-29cf.json b/advisories/unreviewed/2024/07/GHSA-f848-67vp-29cf/GHSA-f848-67vp-29cf.json index bf27688383c..fedba34fc9d 100644 --- a/advisories/unreviewed/2024/07/GHSA-f848-67vp-29cf/GHSA-f848-67vp-29cf.json +++ b/advisories/unreviewed/2024/07/GHSA-f848-67vp-29cf/GHSA-f848-67vp-29cf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f848-67vp-29cf", - "modified": "2024-07-02T21:32:14Z", + "modified": "2024-07-03T18:47:57Z", "published": "2024-07-02T21:32:14Z", "aliases": [ "CVE-2024-22103" ], "details": "Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.6.0 allows local attackers to cause a Windows blue screen error and Denial of Service (DoS).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-02T15:15:11Z" diff --git a/advisories/unreviewed/2024/07/GHSA-fc2h-j9fj-rh35/GHSA-fc2h-j9fj-rh35.json b/advisories/unreviewed/2024/07/GHSA-fc2h-j9fj-rh35/GHSA-fc2h-j9fj-rh35.json new file mode 100644 index 00000000000..bca42a9bfde --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-fc2h-j9fj-rh35/GHSA-fc2h-j9fj-rh35.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fc2h-j9fj-rh35", + "modified": "2024-07-03T18:48:11Z", + "published": "2024-07-03T18:48:11Z", + "aliases": [ + "CVE-2024-39807" + ], + "details": "Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to properly sanitize the recipients of a webhook event which allows an attacker monitoring webhook events to retrieve the channel IDs of archived or restored channels.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39807" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T09:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-fq2j-8f82-jf62/GHSA-fq2j-8f82-jf62.json b/advisories/unreviewed/2024/07/GHSA-fq2j-8f82-jf62/GHSA-fq2j-8f82-jf62.json new file mode 100644 index 00000000000..ce5a26bcbf5 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-fq2j-8f82-jf62/GHSA-fq2j-8f82-jf62.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fq2j-8f82-jf62", + "modified": "2024-07-03T18:48:05Z", + "published": "2024-07-03T18:48:05Z", + "aliases": [ + "CVE-2024-4482" + ], + "details": "The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Countdown' widget in all versions up to, and including, 5.6.1 due to insufficient input sanitization and output escaping on user supplied 'text_days' attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4482" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/the-plus-addons-for-elementor-page-builder/tags/5.5.1/modules/widgets/tp_countdown.php#L1945" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/the-plus-addons-for-elementor-page-builder/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/25e42bf8-794e-46a5-b7db-f1f8802bba00?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T08:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-g5pm-rq4w-q5jw/GHSA-g5pm-rq4w-q5jw.json b/advisories/unreviewed/2024/07/GHSA-g5pm-rq4w-q5jw/GHSA-g5pm-rq4w-q5jw.json index 5b8612e7307..ce220cc9a7e 100644 --- a/advisories/unreviewed/2024/07/GHSA-g5pm-rq4w-q5jw/GHSA-g5pm-rq4w-q5jw.json +++ b/advisories/unreviewed/2024/07/GHSA-g5pm-rq4w-q5jw/GHSA-g5pm-rq4w-q5jw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g5pm-rq4w-q5jw", - "modified": "2024-07-01T06:31:17Z", + "modified": "2024-07-03T18:47:28Z", "published": "2024-07-01T06:31:17Z", "aliases": [ "CVE-2024-20078" ], "details": "In venc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08737250; Issue ID: MSV-1452.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-843" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-01T05:15:04Z" diff --git a/advisories/unreviewed/2024/07/GHSA-g5qj-pfmg-p3jp/GHSA-g5qj-pfmg-p3jp.json b/advisories/unreviewed/2024/07/GHSA-g5qj-pfmg-p3jp/GHSA-g5qj-pfmg-p3jp.json index d625fac1c7e..99a61e77a90 100644 --- a/advisories/unreviewed/2024/07/GHSA-g5qj-pfmg-p3jp/GHSA-g5qj-pfmg-p3jp.json +++ b/advisories/unreviewed/2024/07/GHSA-g5qj-pfmg-p3jp/GHSA-g5qj-pfmg-p3jp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g5qj-pfmg-p3jp", - "modified": "2024-07-02T21:32:15Z", + "modified": "2024-07-03T18:47:58Z", "published": "2024-07-02T21:32:15Z", "aliases": [ "CVE-2024-39894" @@ -29,6 +29,10 @@ { "type": "WEB", "url": "https://www.openwall.com/lists/oss-security/2024/07/02/1" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/07/03/6" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-g6h4-j28x-38g5/GHSA-g6h4-j28x-38g5.json b/advisories/unreviewed/2024/07/GHSA-g6h4-j28x-38g5/GHSA-g6h4-j28x-38g5.json new file mode 100644 index 00000000000..8b50157f0e6 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-g6h4-j28x-38g5/GHSA-g6h4-j28x-38g5.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g6h4-j28x-38g5", + "modified": "2024-07-03T18:48:26Z", + "published": "2024-07-03T18:48:26Z", + "aliases": [ + "CVE-2024-6126" + ], + "details": "A flaw was found in the cockpit package. This flaw allows an authenticated user to kill any process when enabling the pam_env's user_readenv option, which leads to a denial of service (DoS) attack.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6126" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-6126" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2292897" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T15:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-g7pv-xqg8-329h/GHSA-g7pv-xqg8-329h.json b/advisories/unreviewed/2024/07/GHSA-g7pv-xqg8-329h/GHSA-g7pv-xqg8-329h.json new file mode 100644 index 00000000000..2f7f4e60526 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-g7pv-xqg8-329h/GHSA-g7pv-xqg8-329h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g7pv-xqg8-329h", + "modified": "2024-07-03T18:47:58Z", + "published": "2024-07-03T18:47:58Z", + "aliases": [ + "CVE-2024-32673" + ], + "details": "Improper Validation of Array Index vulnerability in Samsung Open Source Walrus Webassembly runtime engine allows a segmentation fault issue.\n\nThis issue affects Walrus: before 72c7230f32a0b791355bbdfc78669701024b0956.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32673" + }, + { + "type": "WEB", + "url": "https://github.com/Samsung/walrus/pull/241" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-129" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T02:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-g9cc-v23v-rgp5/GHSA-g9cc-v23v-rgp5.json b/advisories/unreviewed/2024/07/GHSA-g9cc-v23v-rgp5/GHSA-g9cc-v23v-rgp5.json index b6b7cdba911..581bf1a9fef 100644 --- a/advisories/unreviewed/2024/07/GHSA-g9cc-v23v-rgp5/GHSA-g9cc-v23v-rgp5.json +++ b/advisories/unreviewed/2024/07/GHSA-g9cc-v23v-rgp5/GHSA-g9cc-v23v-rgp5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g9cc-v23v-rgp5", - "modified": "2024-07-02T21:32:15Z", + "modified": "2024-07-03T18:47:57Z", "published": "2024-07-02T21:32:14Z", "aliases": [ "CVE-2024-22106" ], "details": "Improper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges, execute arbitrary code, or cause a Denial of Service (DoS).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-02T16:15:03Z" diff --git a/advisories/unreviewed/2024/07/GHSA-ghf9-pcm2-m9h8/GHSA-ghf9-pcm2-m9h8.json b/advisories/unreviewed/2024/07/GHSA-ghf9-pcm2-m9h8/GHSA-ghf9-pcm2-m9h8.json index 04277149762..df6fe8f85f9 100644 --- a/advisories/unreviewed/2024/07/GHSA-ghf9-pcm2-m9h8/GHSA-ghf9-pcm2-m9h8.json +++ b/advisories/unreviewed/2024/07/GHSA-ghf9-pcm2-m9h8/GHSA-ghf9-pcm2-m9h8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ghf9-pcm2-m9h8", - "modified": "2024-07-02T00:31:46Z", + "modified": "2024-07-03T18:47:46Z", "published": "2024-07-02T00:31:46Z", "aliases": [ "CVE-2024-37764" ], "details": "MachForm up to version 19 is affected by an authenticated stored cross-site scripting.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-01T22:15:03Z" diff --git a/advisories/unreviewed/2024/07/GHSA-h3q5-gjcc-wrm3/GHSA-h3q5-gjcc-wrm3.json b/advisories/unreviewed/2024/07/GHSA-h3q5-gjcc-wrm3/GHSA-h3q5-gjcc-wrm3.json new file mode 100644 index 00000000000..97e434758bc --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-h3q5-gjcc-wrm3/GHSA-h3q5-gjcc-wrm3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h3q5-gjcc-wrm3", + "modified": "2024-07-03T18:48:03Z", + "published": "2024-07-03T18:48:03Z", + "aliases": [ + "CVE-2024-2376" + ], + "details": "The WPQA Builder WordPress plugin before 6.1.1 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2376" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/bdd2e323-d589-4050-bc27-5edd2507a818" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T06:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-h6cm-9qhf-h7jm/GHSA-h6cm-9qhf-h7jm.json b/advisories/unreviewed/2024/07/GHSA-h6cm-9qhf-h7jm/GHSA-h6cm-9qhf-h7jm.json new file mode 100644 index 00000000000..ec19b2b4de7 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-h6cm-9qhf-h7jm/GHSA-h6cm-9qhf-h7jm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h6cm-9qhf-h7jm", + "modified": "2024-07-03T18:47:17Z", + "published": "2024-07-03T18:47:17Z", + "aliases": [ + "CVE-2024-5727" + ], + "details": "The Widget4Call WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5727" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/5f677863-2f4f-474f-ba48-f490f9d6e71c" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-28T06:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-j6hj-rv6w-c72f/GHSA-j6hj-rv6w-c72f.json b/advisories/unreviewed/2024/07/GHSA-j6hj-rv6w-c72f/GHSA-j6hj-rv6w-c72f.json new file mode 100644 index 00000000000..8c91ea0c3d7 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-j6hj-rv6w-c72f/GHSA-j6hj-rv6w-c72f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6hj-rv6w-c72f", + "modified": "2024-07-03T18:48:00Z", + "published": "2024-07-03T18:48:00Z", + "aliases": [ + "CVE-2024-2040" + ], + "details": "The Himer WordPress theme before 2.1.1 does not have CSRF checks in some places, which could allow attackers to make users join private groups via a CSRF attack", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2040" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/1b97bbf0-c7d1-4e6c-bb80-f9bf45fbfe1e" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T06:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-j9gp-7x9x-fj2q/GHSA-j9gp-7x9x-fj2q.json b/advisories/unreviewed/2024/07/GHSA-j9gp-7x9x-fj2q/GHSA-j9gp-7x9x-fj2q.json index d08384e66f4..24adb878b89 100644 --- a/advisories/unreviewed/2024/07/GHSA-j9gp-7x9x-fj2q/GHSA-j9gp-7x9x-fj2q.json +++ b/advisories/unreviewed/2024/07/GHSA-j9gp-7x9x-fj2q/GHSA-j9gp-7x9x-fj2q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j9gp-7x9x-fj2q", - "modified": "2024-07-01T15:32:25Z", + "modified": "2024-07-03T18:47:39Z", "published": "2024-07-01T15:32:25Z", "aliases": [ "CVE-2024-39016" ], "details": "che3vinci c3/utils-1 1.0.131 was discovered to contain a prototype pollution via the function assign. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1321" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-01T13:15:05Z" diff --git a/advisories/unreviewed/2024/07/GHSA-j9pc-h4qx-72vj/GHSA-j9pc-h4qx-72vj.json b/advisories/unreviewed/2024/07/GHSA-j9pc-h4qx-72vj/GHSA-j9pc-h4qx-72vj.json index cd4506cb06c..3c034f8ea9c 100644 --- a/advisories/unreviewed/2024/07/GHSA-j9pc-h4qx-72vj/GHSA-j9pc-h4qx-72vj.json +++ b/advisories/unreviewed/2024/07/GHSA-j9pc-h4qx-72vj/GHSA-j9pc-h4qx-72vj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j9pc-h4qx-72vj", - "modified": "2024-07-01T15:32:28Z", + "modified": "2024-07-03T18:47:40Z", "published": "2024-07-01T15:32:28Z", "aliases": [ "CVE-2024-39017" ], "details": "agreejs shared v0.0.1 was discovered to contain a prototype pollution via the function mergeInternalComponents. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-01T13:15:05Z" diff --git a/advisories/unreviewed/2024/07/GHSA-jw4h-9877-397h/GHSA-jw4h-9877-397h.json b/advisories/unreviewed/2024/07/GHSA-jw4h-9877-397h/GHSA-jw4h-9877-397h.json new file mode 100644 index 00000000000..8f1757d28f6 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-jw4h-9877-397h/GHSA-jw4h-9877-397h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jw4h-9877-397h", + "modified": "2024-07-03T18:47:18Z", + "published": "2024-07-03T18:47:18Z", + "aliases": [ + "CVE-2024-5730" + ], + "details": "The Pagerank tools WordPress plugin through 1.1.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5730" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/17482b2c-c9ba-480a-8000-879baf835af7" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-28T06:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-jxr4-4prv-mh83/GHSA-jxr4-4prv-mh83.json b/advisories/unreviewed/2024/07/GHSA-jxr4-4prv-mh83/GHSA-jxr4-4prv-mh83.json index ecb8a35c0d5..1320cfbb9a7 100644 --- a/advisories/unreviewed/2024/07/GHSA-jxr4-4prv-mh83/GHSA-jxr4-4prv-mh83.json +++ b/advisories/unreviewed/2024/07/GHSA-jxr4-4prv-mh83/GHSA-jxr4-4prv-mh83.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-jxxp-mqwv-8hqg/GHSA-jxxp-mqwv-8hqg.json b/advisories/unreviewed/2024/07/GHSA-jxxp-mqwv-8hqg/GHSA-jxxp-mqwv-8hqg.json index af6a026eb11..24d06ce1957 100644 --- a/advisories/unreviewed/2024/07/GHSA-jxxp-mqwv-8hqg/GHSA-jxxp-mqwv-8hqg.json +++ b/advisories/unreviewed/2024/07/GHSA-jxxp-mqwv-8hqg/GHSA-jxxp-mqwv-8hqg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jxxp-mqwv-8hqg", - "modified": "2024-07-01T15:32:32Z", + "modified": "2024-07-03T18:47:40Z", "published": "2024-07-01T15:32:32Z", "aliases": [ "CVE-2024-39853" ], "details": "adolph_dudu ratio-swiper 0.0.2 was discovered to contain a prototype pollution via the function parse. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1321" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-01T13:15:06Z" diff --git a/advisories/unreviewed/2024/07/GHSA-m35m-j69m-gvq4/GHSA-m35m-j69m-gvq4.json b/advisories/unreviewed/2024/07/GHSA-m35m-j69m-gvq4/GHSA-m35m-j69m-gvq4.json new file mode 100644 index 00000000000..5a20b48ead1 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-m35m-j69m-gvq4/GHSA-m35m-j69m-gvq4.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m35m-j69m-gvq4", + "modified": "2024-07-03T18:48:16Z", + "published": "2024-07-03T18:48:16Z", + "aliases": [ + "CVE-2024-6470" + ], + "details": "A vulnerability was found in playSMS 1.4.3. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /index.php?app=main&inc=feature_inboxgroup&op=list of the component Template Handler. The manipulation of the argument Receiver Number with the input {{`id`}} leads to injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-270278 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6470" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.270278" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.270278" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.363733" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T13:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-m3r7-wx5j-gx67/GHSA-m3r7-wx5j-gx67.json b/advisories/unreviewed/2024/07/GHSA-m3r7-wx5j-gx67/GHSA-m3r7-wx5j-gx67.json index 5b247f81503..32d3fede728 100644 --- a/advisories/unreviewed/2024/07/GHSA-m3r7-wx5j-gx67/GHSA-m3r7-wx5j-gx67.json +++ b/advisories/unreviewed/2024/07/GHSA-m3r7-wx5j-gx67/GHSA-m3r7-wx5j-gx67.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m3r7-wx5j-gx67", - "modified": "2024-07-01T15:32:18Z", + "modified": "2024-07-03T18:47:30Z", "published": "2024-07-01T15:32:18Z", "aliases": [ "CVE-2024-38998" ], "details": "jrburke requirejs v2.3.6 was discovered to contain a prototype pollution via the function config. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1321" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-01T13:15:05Z" diff --git a/advisories/unreviewed/2024/07/GHSA-mjgw-jfgq-jq67/GHSA-mjgw-jfgq-jq67.json b/advisories/unreviewed/2024/07/GHSA-mjgw-jfgq-jq67/GHSA-mjgw-jfgq-jq67.json index 46350b887a1..b15a30fc406 100644 --- a/advisories/unreviewed/2024/07/GHSA-mjgw-jfgq-jq67/GHSA-mjgw-jfgq-jq67.json +++ b/advisories/unreviewed/2024/07/GHSA-mjgw-jfgq-jq67/GHSA-mjgw-jfgq-jq67.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mjgw-jfgq-jq67", - "modified": "2024-07-02T09:32:05Z", + "modified": "2024-07-03T18:47:48Z", "published": "2024-07-02T09:32:05Z", "aliases": [ "CVE-2024-5606" ], "details": "The Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 is vulnerable does not validate and escape the question_id parameter in the qsm_bulk_delete_question_from_database AJAX action, leading to a SQL injection exploitable by Contributors and above role", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-02T06:15:04Z" diff --git a/advisories/unreviewed/2024/07/GHSA-mrvh-699v-65gr/GHSA-mrvh-699v-65gr.json b/advisories/unreviewed/2024/07/GHSA-mrvh-699v-65gr/GHSA-mrvh-699v-65gr.json index b3390491cc8..8d40fd5394e 100644 --- a/advisories/unreviewed/2024/07/GHSA-mrvh-699v-65gr/GHSA-mrvh-699v-65gr.json +++ b/advisories/unreviewed/2024/07/GHSA-mrvh-699v-65gr/GHSA-mrvh-699v-65gr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mrvh-699v-65gr", - "modified": "2024-07-02T09:32:05Z", + "modified": "2024-07-03T18:47:47Z", "published": "2024-07-02T09:32:05Z", "aliases": [ "CVE-2024-3999" ], "details": "The EazyDocs WordPress plugin before 2.5.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-02T06:15:04Z" diff --git a/advisories/unreviewed/2024/07/GHSA-p5p8-v4qg-3g7c/GHSA-p5p8-v4qg-3g7c.json b/advisories/unreviewed/2024/07/GHSA-p5p8-v4qg-3g7c/GHSA-p5p8-v4qg-3g7c.json index 0659e060723..3f2a519a4ff 100644 --- a/advisories/unreviewed/2024/07/GHSA-p5p8-v4qg-3g7c/GHSA-p5p8-v4qg-3g7c.json +++ b/advisories/unreviewed/2024/07/GHSA-p5p8-v4qg-3g7c/GHSA-p5p8-v4qg-3g7c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p5p8-v4qg-3g7c", - "modified": "2024-07-01T15:32:11Z", + "modified": "2024-07-03T18:47:29Z", "published": "2024-07-01T15:32:11Z", "aliases": [ "CVE-2024-38990" ], "details": "Tada5hi sp-common v0.5.4 was discovered to contain a prototype pollution via the function mergeDeep. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-01T13:15:04Z" diff --git a/advisories/unreviewed/2024/07/GHSA-pp3h-g655-hhfp/GHSA-pp3h-g655-hhfp.json b/advisories/unreviewed/2024/07/GHSA-pp3h-g655-hhfp/GHSA-pp3h-g655-hhfp.json index e8662b7664b..00ea5faf5cd 100644 --- a/advisories/unreviewed/2024/07/GHSA-pp3h-g655-hhfp/GHSA-pp3h-g655-hhfp.json +++ b/advisories/unreviewed/2024/07/GHSA-pp3h-g655-hhfp/GHSA-pp3h-g655-hhfp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pp3h-g655-hhfp", - "modified": "2024-07-01T15:32:20Z", + "modified": "2024-07-03T18:47:35Z", "published": "2024-07-01T15:32:20Z", "aliases": [ "CVE-2024-39003" ], "details": "amoyjs amoy common v1.0.10 was discovered to contain a prototype pollution via the function setValue. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1321" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-01T13:15:05Z" diff --git a/advisories/unreviewed/2024/07/GHSA-pxvx-mm2m-59v4/GHSA-pxvx-mm2m-59v4.json b/advisories/unreviewed/2024/07/GHSA-pxvx-mm2m-59v4/GHSA-pxvx-mm2m-59v4.json new file mode 100644 index 00000000000..095219f6704 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-pxvx-mm2m-59v4/GHSA-pxvx-mm2m-59v4.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pxvx-mm2m-59v4", + "modified": "2024-07-03T18:48:19Z", + "published": "2024-07-03T18:48:19Z", + "aliases": [ + "CVE-2024-39220" + ], + "details": "BAS-IP AV-01D, AV-01MD, AV-01MFD, AV-01ED, AV-01KD, AV-01BD, AV-01KBD, AV-02D, AV-02IDE, AV-02IDR, AV-02IPD, AV-02FDE, AV-02FDR, AV-03D, AV-03BD, AV-04AFD, AV-04ASD, AV-04FD, AV-04SD, AV-05FD, AV-05SD, AA-07BD, AA-07BDI, BA-04BD, BA-04MD, BA-08BD, BA-08MD, BA-12BD, BA-12MD, CR-02BD before firmware v3.9.2 allows authenticated attackers to read SIP account passwords via a crafted GET request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39220" + }, + { + "type": "WEB", + "url": "https://bas-ip.com/bsa-000001" + }, + { + "type": "WEB", + "url": "https://github.com/DrieVlad/BAS-IP-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T15:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-qqg3-wxg7-6j3v/GHSA-qqg3-wxg7-6j3v.json b/advisories/unreviewed/2024/07/GHSA-qqg3-wxg7-6j3v/GHSA-qqg3-wxg7-6j3v.json new file mode 100644 index 00000000000..b67efe0049a --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-qqg3-wxg7-6j3v/GHSA-qqg3-wxg7-6j3v.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qqg3-wxg7-6j3v", + "modified": "2024-07-03T18:48:08Z", + "published": "2024-07-03T18:48:08Z", + "aliases": [ + "CVE-2024-6340" + ], + "details": "The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, and including, 4.10.35 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6340" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/premium-addons-for-elementor/trunk/assets/frontend/js/premium-countdown-timer.js#L113" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/premium-addons-for-elementor/trunk/assets/frontend/js/premium-countdown-timer.js#L31" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3111117" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/premium-addons-for-elementor/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/9ed80507-f3e5-45a8-9498-8cebf97155ff?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T08:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-rvp5-8mrw-f62x/GHSA-rvp5-8mrw-f62x.json b/advisories/unreviewed/2024/07/GHSA-rvp5-8mrw-f62x/GHSA-rvp5-8mrw-f62x.json new file mode 100644 index 00000000000..64127d6f1d3 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-rvp5-8mrw-f62x/GHSA-rvp5-8mrw-f62x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rvp5-8mrw-f62x", + "modified": "2024-07-03T18:48:12Z", + "published": "2024-07-03T18:48:12Z", + "aliases": [ + "CVE-2024-6428" + ], + "details": "Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2, 9.5.x <= 9.5.5 fail to prevent specifying a RemoteId when creating a new user which allows an attacker to specify both a remoteId and the user ID, resulting in creating a user with a user-defined user ID. This can cause some broken functionality in User Management such administrative actions against the user not working.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6428" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-rxwp-vh49-vj6f/GHSA-rxwp-vh49-vj6f.json b/advisories/unreviewed/2024/07/GHSA-rxwp-vh49-vj6f/GHSA-rxwp-vh49-vj6f.json new file mode 100644 index 00000000000..0417efd0d63 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-rxwp-vh49-vj6f/GHSA-rxwp-vh49-vj6f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rxwp-vh49-vj6f", + "modified": "2024-07-03T18:48:02Z", + "published": "2024-07-03T18:48:02Z", + "aliases": [ + "CVE-2024-2233" + ], + "details": "The Himer WordPress theme before 2.1.1 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks. These include declining and accepting group invitations or leaving a group", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2233" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/51d0311a-673b-4538-9427-a48e8c89e38b" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T06:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-v39f-3xwx-xg8f/GHSA-v39f-3xwx-xg8f.json b/advisories/unreviewed/2024/07/GHSA-v39f-3xwx-xg8f/GHSA-v39f-3xwx-xg8f.json new file mode 100644 index 00000000000..cf4f9cfca3a --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-v39f-3xwx-xg8f/GHSA-v39f-3xwx-xg8f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v39f-3xwx-xg8f", + "modified": "2024-07-03T18:48:09Z", + "published": "2024-07-03T18:48:09Z", + "aliases": [ + "CVE-2024-39353" + ], + "details": "Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to sanitize the RemoteClusterFrame payloads before audit logging them which allows a high privileged attacker with access to the audit logs to read message contents.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39353" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T09:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-v6hh-fr8r-f5x6/GHSA-v6hh-fr8r-f5x6.json b/advisories/unreviewed/2024/07/GHSA-v6hh-fr8r-f5x6/GHSA-v6hh-fr8r-f5x6.json index c3c940c02f1..252a83e566d 100644 --- a/advisories/unreviewed/2024/07/GHSA-v6hh-fr8r-f5x6/GHSA-v6hh-fr8r-f5x6.json +++ b/advisories/unreviewed/2024/07/GHSA-v6hh-fr8r-f5x6/GHSA-v6hh-fr8r-f5x6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v6hh-fr8r-f5x6", - "modified": "2024-07-01T15:32:24Z", + "modified": "2024-07-03T18:47:35Z", "published": "2024-07-01T15:32:24Z", "aliases": [ "CVE-2024-39015" ], "details": "cafebazaar hod v0.4.14 was discovered to contain a prototype pollution via the function request. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-01T13:15:05Z" diff --git a/advisories/unreviewed/2024/07/GHSA-vg5j-h7r8-88x8/GHSA-vg5j-h7r8-88x8.json b/advisories/unreviewed/2024/07/GHSA-vg5j-h7r8-88x8/GHSA-vg5j-h7r8-88x8.json index 2dac45045ae..118243f3c24 100644 --- a/advisories/unreviewed/2024/07/GHSA-vg5j-h7r8-88x8/GHSA-vg5j-h7r8-88x8.json +++ b/advisories/unreviewed/2024/07/GHSA-vg5j-h7r8-88x8/GHSA-vg5j-h7r8-88x8.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-203" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-vmvm-jjvw-qwpw/GHSA-vmvm-jjvw-qwpw.json b/advisories/unreviewed/2024/07/GHSA-vmvm-jjvw-qwpw/GHSA-vmvm-jjvw-qwpw.json new file mode 100644 index 00000000000..9cc39e4fb5b --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-vmvm-jjvw-qwpw/GHSA-vmvm-jjvw-qwpw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vmvm-jjvw-qwpw", + "modified": "2024-07-03T18:48:12Z", + "published": "2024-07-03T18:48:12Z", + "aliases": [ + "CVE-2024-39830" + ], + "details": "Mattermost versions 9.8.x <= 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5, when shared channels are enabled, fail to use constant time comparison for remote cluster tokens which allows an attacker to retrieve the remote cluster token via a timing attack during remote cluster token comparison.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39830" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T09:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-w3h5-p6v5-5vjm/GHSA-w3h5-p6v5-5vjm.json b/advisories/unreviewed/2024/07/GHSA-w3h5-p6v5-5vjm/GHSA-w3h5-p6v5-5vjm.json new file mode 100644 index 00000000000..22fd54d0abb --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-w3h5-p6v5-5vjm/GHSA-w3h5-p6v5-5vjm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w3h5-p6v5-5vjm", + "modified": "2024-07-03T18:48:04Z", + "published": "2024-07-03T18:48:04Z", + "aliases": [ + "CVE-2024-37082" + ], + "details": "Security check loophole in HAProxy release (in combination with routing release) in Cloud Foundry prior to v40.17.0 potentially allows bypass of mTLS authentication to applications hosted on Cloud Foundry.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37082" + }, + { + "type": "WEB", + "url": "https://www.cloudfoundry.org/blog/cve-2024-37082-mtls-bypass" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-290" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T06:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-w8hv-qc2j-9q6f/GHSA-w8hv-qc2j-9q6f.json b/advisories/unreviewed/2024/07/GHSA-w8hv-qc2j-9q6f/GHSA-w8hv-qc2j-9q6f.json new file mode 100644 index 00000000000..11db2d18c8c --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-w8hv-qc2j-9q6f/GHSA-w8hv-qc2j-9q6f.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w8hv-qc2j-9q6f", + "modified": "2024-07-03T18:48:26Z", + "published": "2024-07-03T18:48:26Z", + "aliases": [ + "CVE-2024-39248" + ], + "details": "A cross-site scripting (XSS) vulnerability in SimpCMS v0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title field at /admin.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39248" + }, + { + "type": "WEB", + "url": "https://github.com/jasonthename/CVE-2024-39248" + }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com/files/179219" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T17:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-wfv7-jxcv-wwf4/GHSA-wfv7-jxcv-wwf4.json b/advisories/unreviewed/2024/07/GHSA-wfv7-jxcv-wwf4/GHSA-wfv7-jxcv-wwf4.json index 4641967f1e8..248a738ad49 100644 --- a/advisories/unreviewed/2024/07/GHSA-wfv7-jxcv-wwf4/GHSA-wfv7-jxcv-wwf4.json +++ b/advisories/unreviewed/2024/07/GHSA-wfv7-jxcv-wwf4/GHSA-wfv7-jxcv-wwf4.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-wm32-m2h7-232m/GHSA-wm32-m2h7-232m.json b/advisories/unreviewed/2024/07/GHSA-wm32-m2h7-232m/GHSA-wm32-m2h7-232m.json index 87c6eefda3d..a563e215ae4 100644 --- a/advisories/unreviewed/2024/07/GHSA-wm32-m2h7-232m/GHSA-wm32-m2h7-232m.json +++ b/advisories/unreviewed/2024/07/GHSA-wm32-m2h7-232m/GHSA-wm32-m2h7-232m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wm32-m2h7-232m", - "modified": "2024-07-01T15:32:20Z", + "modified": "2024-07-03T18:47:34Z", "published": "2024-07-01T15:32:20Z", "aliases": [ "CVE-2024-39000" ], "details": "adolph_dudu ratio-swiper v0.0.2 was discovered to contain a prototype pollution via the function parse. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1321" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-01T13:15:05Z" diff --git a/advisories/unreviewed/2024/07/GHSA-x82g-5rxp-rxg4/GHSA-x82g-5rxp-rxg4.json b/advisories/unreviewed/2024/07/GHSA-x82g-5rxp-rxg4/GHSA-x82g-5rxp-rxg4.json index 0edbbdc7be3..46853e45390 100644 --- a/advisories/unreviewed/2024/07/GHSA-x82g-5rxp-rxg4/GHSA-x82g-5rxp-rxg4.json +++ b/advisories/unreviewed/2024/07/GHSA-x82g-5rxp-rxg4/GHSA-x82g-5rxp-rxg4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x82g-5rxp-rxg4", - "modified": "2024-07-02T09:32:05Z", + "modified": "2024-07-03T18:47:48Z", "published": "2024-07-02T09:32:05Z", "aliases": [ "CVE-2024-5767" ], "details": "The sitetweet WordPress plugin through 0.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-02T06:15:05Z" diff --git a/advisories/unreviewed/2024/07/GHSA-x8hp-rjr5-68q5/GHSA-x8hp-rjr5-68q5.json b/advisories/unreviewed/2024/07/GHSA-x8hp-rjr5-68q5/GHSA-x8hp-rjr5-68q5.json index 748cf80ce76..07860eb8587 100644 --- a/advisories/unreviewed/2024/07/GHSA-x8hp-rjr5-68q5/GHSA-x8hp-rjr5-68q5.json +++ b/advisories/unreviewed/2024/07/GHSA-x8hp-rjr5-68q5/GHSA-x8hp-rjr5-68q5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x8hp-rjr5-68q5", - "modified": "2024-07-02T09:32:05Z", + "modified": "2024-07-03T18:47:49Z", "published": "2024-07-02T09:32:05Z", "aliases": [ "CVE-2024-6172" @@ -44,7 +44,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-xj6v-rj9r-jrjq/GHSA-xj6v-rj9r-jrjq.json b/advisories/unreviewed/2024/07/GHSA-xj6v-rj9r-jrjq/GHSA-xj6v-rj9r-jrjq.json index b99cf155317..7a8f65ed015 100644 --- a/advisories/unreviewed/2024/07/GHSA-xj6v-rj9r-jrjq/GHSA-xj6v-rj9r-jrjq.json +++ b/advisories/unreviewed/2024/07/GHSA-xj6v-rj9r-jrjq/GHSA-xj6v-rj9r-jrjq.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-xq6f-mgc4-8g5h/GHSA-xq6f-mgc4-8g5h.json b/advisories/unreviewed/2024/07/GHSA-xq6f-mgc4-8g5h/GHSA-xq6f-mgc4-8g5h.json index ba6aae69dd4..a402a5a9213 100644 --- a/advisories/unreviewed/2024/07/GHSA-xq6f-mgc4-8g5h/GHSA-xq6f-mgc4-8g5h.json +++ b/advisories/unreviewed/2024/07/GHSA-xq6f-mgc4-8g5h/GHSA-xq6f-mgc4-8g5h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xq6f-mgc4-8g5h", - "modified": "2024-07-01T06:31:16Z", + "modified": "2024-07-03T18:47:25Z", "published": "2024-07-01T06:31:16Z", "aliases": [ "CVE-2024-20076" ], "details": "In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01297806; Issue ID: MSV-1481.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-119" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-01T05:15:03Z" diff --git a/advisories/unreviewed/2024/07/GHSA-xxqj-x2pv-x5jj/GHSA-xxqj-x2pv-x5jj.json b/advisories/unreviewed/2024/07/GHSA-xxqj-x2pv-x5jj/GHSA-xxqj-x2pv-x5jj.json new file mode 100644 index 00000000000..183b2ae6fe4 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-xxqj-x2pv-x5jj/GHSA-xxqj-x2pv-x5jj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xxqj-x2pv-x5jj", + "modified": "2024-07-03T18:48:14Z", + "published": "2024-07-03T18:48:14Z", + "aliases": [ + "CVE-2024-6427" + ], + "details": "Uncontrolled Resource Consumption vulnerability in MESbook 20221021.03 version. An unauthenticated remote attacker can use the \"message\" parameter to inject a payload with dangerous JavaScript code, causing the application to loop requests on itself, which could lead to resource consumption and disable the application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6427" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-mesbook" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-03T12:15:03Z" + } +} \ No newline at end of file