From 37e28da5310b63b87e99736b89891842af03fd99 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 3 Jul 2024 18:40:52 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-2252-jwp3-qxfh/GHSA-2252-jwp3-qxfh.json | 2 +- .../GHSA-26cg-rw99-22rc/GHSA-26cg-rw99-22rc.json | 11 +++++++---- .../GHSA-2769-9cr9-9w7h/GHSA-2769-9cr9-9w7h.json | 11 +++++++---- .../GHSA-2cf3-8v44-39fh/GHSA-2cf3-8v44-39fh.json | 2 +- .../GHSA-2f36-cx3x-62vx/GHSA-2f36-cx3x-62vx.json | 9 ++++++--- .../GHSA-2jv5-xv66-fhx8/GHSA-2jv5-xv66-fhx8.json | 11 +++++++---- .../GHSA-2r4f-jfx8-mhm3/GHSA-2r4f-jfx8-mhm3.json | 1 + .../GHSA-2r9m-fc3w-cxph/GHSA-2r9m-fc3w-cxph.json | 11 +++++++---- .../GHSA-2w87-6hh6-mqrj/GHSA-2w87-6hh6-mqrj.json | 9 ++++++--- .../GHSA-2w94-phv7-xjw4/GHSA-2w94-phv7-xjw4.json | 11 +++++++---- .../GHSA-32r2-xfqh-9qx6/GHSA-32r2-xfqh-9qx6.json | 11 +++++++---- .../GHSA-339j-p2wf-p72r/GHSA-339j-p2wf-p72r.json | 11 +++++++---- .../GHSA-33r5-hf6m-mc27/GHSA-33r5-hf6m-mc27.json | 11 +++++++---- .../GHSA-377p-g8gr-5wpg/GHSA-377p-g8gr-5wpg.json | 11 +++++++---- .../GHSA-37jj-p98x-q9ff/GHSA-37jj-p98x-q9ff.json | 11 +++++++---- .../GHSA-3849-33qq-vw2c/GHSA-3849-33qq-vw2c.json | 11 +++++++---- .../GHSA-38f9-jc9v-rgw6/GHSA-38f9-jc9v-rgw6.json | 11 +++++++---- .../GHSA-39cp-8qfj-8cjm/GHSA-39cp-8qfj-8cjm.json | 11 +++++++---- .../GHSA-39jg-cp5w-9278/GHSA-39jg-cp5w-9278.json | 11 +++++++---- .../GHSA-3f3h-87pc-27hg/GHSA-3f3h-87pc-27hg.json | 11 +++++++---- .../GHSA-3g5p-5p6j-r9qp/GHSA-3g5p-5p6j-r9qp.json | 11 +++++++---- .../GHSA-3jxg-9cjf-4f5f/GHSA-3jxg-9cjf-4f5f.json | 11 +++++++---- .../GHSA-3m3m-q3hw-6qq6/GHSA-3m3m-q3hw-6qq6.json | 9 ++++++--- .../GHSA-3q9v-78jg-p832/GHSA-3q9v-78jg-p832.json | 11 +++++++---- .../GHSA-3vcv-qvpj-9v53/GHSA-3vcv-qvpj-9v53.json | 11 +++++++---- .../GHSA-3vp4-9c6g-mcq2/GHSA-3vp4-9c6g-mcq2.json | 11 +++++++---- .../GHSA-3wvq-9p67-m439/GHSA-3wvq-9p67-m439.json | 11 +++++++---- .../GHSA-446j-5276-666q/GHSA-446j-5276-666q.json | 11 +++++++---- .../GHSA-4996-x4q8-5x37/GHSA-4996-x4q8-5x37.json | 9 ++++++--- .../GHSA-4f92-w438-f484/GHSA-4f92-w438-f484.json | 9 ++++++--- .../GHSA-4g7f-972r-hmcv/GHSA-4g7f-972r-hmcv.json | 11 +++++++---- .../GHSA-4g9w-6f9w-cjc7/GHSA-4g9w-6f9w-cjc7.json | 9 ++++++--- .../GHSA-4jjj-r6hx-hx6f/GHSA-4jjj-r6hx-hx6f.json | 11 +++++++---- .../GHSA-4rfv-qq74-7p4v/GHSA-4rfv-qq74-7p4v.json | 11 +++++++---- .../GHSA-4rmp-jjj9-cfm4/GHSA-4rmp-jjj9-cfm4.json | 11 +++++++---- .../GHSA-52cx-m9j4-rq34/GHSA-52cx-m9j4-rq34.json | 11 +++++++---- .../GHSA-52mx-4f7f-jvvm/GHSA-52mx-4f7f-jvvm.json | 11 +++++++---- .../GHSA-56hg-r682-945v/GHSA-56hg-r682-945v.json | 9 ++++++--- .../GHSA-59j5-r3pj-3q9p/GHSA-59j5-r3pj-3q9p.json | 11 +++++++---- .../GHSA-5fq7-4mxc-535h/GHSA-5fq7-4mxc-535h.json | 9 ++++++--- .../GHSA-5h2f-vwh5-pc3g/GHSA-5h2f-vwh5-pc3g.json | 2 +- .../GHSA-5j82-6875-gc5h/GHSA-5j82-6875-gc5h.json | 11 +++++++---- .../GHSA-5jpw-vjgv-8mfx/GHSA-5jpw-vjgv-8mfx.json | 11 +++++++---- .../GHSA-5pwc-cvx7-34mp/GHSA-5pwc-cvx7-34mp.json | 11 +++++++---- .../GHSA-5q3j-866r-jjww/GHSA-5q3j-866r-jjww.json | 11 +++++++---- .../GHSA-5q6f-3g3m-rjw9/GHSA-5q6f-3g3m-rjw9.json | 11 +++++++---- .../GHSA-5rmw-4x72-xqxv/GHSA-5rmw-4x72-xqxv.json | 2 +- .../GHSA-5vjq-2rf8-q4wj/GHSA-5vjq-2rf8-q4wj.json | 11 +++++++---- .../GHSA-5wvm-hc4p-r45f/GHSA-5wvm-hc4p-r45f.json | 2 +- .../GHSA-5x44-874c-9rmj/GHSA-5x44-874c-9rmj.json | 11 +++++++---- .../GHSA-6577-mq92-mvr2/GHSA-6577-mq92-mvr2.json | 9 ++++++--- .../GHSA-682x-vcqv-v7v6/GHSA-682x-vcqv-v7v6.json | 2 +- .../GHSA-6gwg-w9p5-2c42/GHSA-6gwg-w9p5-2c42.json | 11 +++++++---- .../GHSA-6h69-r77q-c662/GHSA-6h69-r77q-c662.json | 11 +++++++---- .../GHSA-6hcr-8cp5-58wj/GHSA-6hcr-8cp5-58wj.json | 11 +++++++---- .../GHSA-6jj6-4cwr-qpr2/GHSA-6jj6-4cwr-qpr2.json | 11 +++++++---- .../GHSA-6m2f-g987-jc22/GHSA-6m2f-g987-jc22.json | 11 +++++++---- .../GHSA-72vc-f76g-4qq4/GHSA-72vc-f76g-4qq4.json | 2 +- .../GHSA-77q6-5h9c-2c36/GHSA-77q6-5h9c-2c36.json | 11 +++++++---- .../GHSA-79fj-qcrm-4368/GHSA-79fj-qcrm-4368.json | 9 ++++++--- .../GHSA-7c6h-5h65-pq5v/GHSA-7c6h-5h65-pq5v.json | 11 +++++++---- .../GHSA-7fwm-5rwh-hfg5/GHSA-7fwm-5rwh-hfg5.json | 11 +++++++---- .../GHSA-7gx3-fr27-7gx9/GHSA-7gx3-fr27-7gx9.json | 11 +++++++---- .../GHSA-7h9q-j3hq-cpc4/GHSA-7h9q-j3hq-cpc4.json | 11 +++++++---- .../GHSA-7jgq-6qw7-j88f/GHSA-7jgq-6qw7-j88f.json | 11 +++++++---- .../GHSA-7m4r-mvj2-xjpx/GHSA-7m4r-mvj2-xjpx.json | 11 +++++++---- .../GHSA-7pjp-mg36-54v4/GHSA-7pjp-mg36-54v4.json | 11 +++++++---- .../GHSA-7rp2-vcrx-9h2r/GHSA-7rp2-vcrx-9h2r.json | 11 +++++++---- .../GHSA-7rp4-4g4h-9gwv/GHSA-7rp4-4g4h-9gwv.json | 11 +++++++---- .../GHSA-7vvx-296g-vp4g/GHSA-7vvx-296g-vp4g.json | 11 +++++++---- .../GHSA-7wfw-7p9h-4j2c/GHSA-7wfw-7p9h-4j2c.json | 11 +++++++---- .../GHSA-8422-7263-3xg6/GHSA-8422-7263-3xg6.json | 9 ++++++--- .../GHSA-87hc-xjjc-rvw9/GHSA-87hc-xjjc-rvw9.json | 11 +++++++---- .../GHSA-8g74-32fg-5ghc/GHSA-8g74-32fg-5ghc.json | 9 ++++++--- .../GHSA-8jf6-v4rh-2g3w/GHSA-8jf6-v4rh-2g3w.json | 11 +++++++---- .../GHSA-8q98-72mq-w92m/GHSA-8q98-72mq-w92m.json | 9 ++++++--- .../GHSA-8w79-35vx-63xh/GHSA-8w79-35vx-63xh.json | 11 +++++++---- .../GHSA-96fg-696f-w9g3/GHSA-96fg-696f-w9g3.json | 11 +++++++---- .../GHSA-96wf-rc2w-4922/GHSA-96wf-rc2w-4922.json | 11 +++++++---- .../GHSA-972x-xwpx-cr2c/GHSA-972x-xwpx-cr2c.json | 2 +- .../GHSA-9cw5-fjxh-j5fv/GHSA-9cw5-fjxh-j5fv.json | 2 +- .../GHSA-9f8j-537f-m943/GHSA-9f8j-537f-m943.json | 11 +++++++---- .../GHSA-9fp6-rmrc-c2jw/GHSA-9fp6-rmrc-c2jw.json | 11 +++++++---- .../GHSA-9frm-76c2-fq2w/GHSA-9frm-76c2-fq2w.json | 11 +++++++---- .../GHSA-9g7g-rfw9-5xff/GHSA-9g7g-rfw9-5xff.json | 11 +++++++---- .../GHSA-9g7x-rcc4-g9h9/GHSA-9g7x-rcc4-g9h9.json | 15 +++++++++++---- .../GHSA-9rqf-45x9-xp9f/GHSA-9rqf-45x9-xp9f.json | 11 +++++++---- .../GHSA-9w3g-mqc5-c9p4/GHSA-9w3g-mqc5-c9p4.json | 11 +++++++---- .../GHSA-9w5v-j38r-rr4m/GHSA-9w5v-j38r-rr4m.json | 11 +++++++---- .../GHSA-c37g-646h-qgp8/GHSA-c37g-646h-qgp8.json | 11 +++++++---- .../GHSA-c3jw-865v-8wx2/GHSA-c3jw-865v-8wx2.json | 11 +++++++---- .../GHSA-c49x-w662-272g/GHSA-c49x-w662-272g.json | 11 +++++++---- .../GHSA-c6h3-4727-9w7w/GHSA-c6h3-4727-9w7w.json | 11 +++++++---- .../GHSA-c9f8-5x26-4646/GHSA-c9f8-5x26-4646.json | 11 +++++++---- .../GHSA-cc7f-xj8f-c4mm/GHSA-cc7f-xj8f-c4mm.json | 2 +- .../GHSA-cf3q-2prj-j668/GHSA-cf3q-2prj-j668.json | 11 +++++++---- .../GHSA-ch8g-2w9c-j286/GHSA-ch8g-2w9c-j286.json | 11 +++++++---- .../GHSA-cm5q-2h7w-xfc7/GHSA-cm5q-2h7w-xfc7.json | 11 +++++++---- .../GHSA-cqfx-xvr4-7hr2/GHSA-cqfx-xvr4-7hr2.json | 11 +++++++---- .../GHSA-crpf-8hgm-99cp/GHSA-crpf-8hgm-99cp.json | 11 +++++++---- .../GHSA-cv5j-h4rr-jj29/GHSA-cv5j-h4rr-jj29.json | 11 +++++++---- .../GHSA-cxv9-jpfc-6237/GHSA-cxv9-jpfc-6237.json | 11 +++++++---- .../GHSA-f4cf-2w52-c853/GHSA-f4cf-2w52-c853.json | 9 ++++++--- .../GHSA-f4pv-q5f7-2h55/GHSA-f4pv-q5f7-2h55.json | 9 ++++++--- .../GHSA-fhf8-hvgj-q5vh/GHSA-fhf8-hvgj-q5vh.json | 9 ++++++--- .../GHSA-fj57-wwj6-8p79/GHSA-fj57-wwj6-8p79.json | 11 +++++++---- .../GHSA-fqv7-fhq2-929v/GHSA-fqv7-fhq2-929v.json | 11 +++++++---- .../GHSA-fv57-985w-x39v/GHSA-fv57-985w-x39v.json | 11 +++++++---- .../GHSA-fvwh-2fv9-m663/GHSA-fvwh-2fv9-m663.json | 11 +++++++---- .../GHSA-fxfv-f99m-vfjq/GHSA-fxfv-f99m-vfjq.json | 11 +++++++---- .../GHSA-g4jh-vmj9-2xmw/GHSA-g4jh-vmj9-2xmw.json | 2 +- .../GHSA-g8rr-54r4-95mg/GHSA-g8rr-54r4-95mg.json | 11 +++++++---- .../GHSA-g9rq-ppxc-pmj6/GHSA-g9rq-ppxc-pmj6.json | 11 +++++++---- .../GHSA-g9vx-vfc5-9mgj/GHSA-g9vx-vfc5-9mgj.json | 11 +++++++---- .../GHSA-gfv2-v87j-2hqj/GHSA-gfv2-v87j-2hqj.json | 11 +++++++---- .../GHSA-gpc9-w434-fvwx/GHSA-gpc9-w434-fvwx.json | 11 +++++++---- .../GHSA-gr6h-g3pg-9ggp/GHSA-gr6h-g3pg-9ggp.json | 11 +++++++---- .../GHSA-gr7j-q4q6-rxcf/GHSA-gr7j-q4q6-rxcf.json | 11 +++++++---- .../GHSA-gwp7-78vh-mpmm/GHSA-gwp7-78vh-mpmm.json | 11 +++++++---- .../GHSA-gwqx-m7rc-2c9p/GHSA-gwqx-m7rc-2c9p.json | 9 ++++++--- .../GHSA-gx23-3rqm-g2xc/GHSA-gx23-3rqm-g2xc.json | 11 +++++++---- .../GHSA-h2jp-gf2g-f6fc/GHSA-h2jp-gf2g-f6fc.json | 11 +++++++---- .../GHSA-h3xp-fgm5-94vx/GHSA-h3xp-fgm5-94vx.json | 11 +++++++---- .../GHSA-h455-phph-2r6j/GHSA-h455-phph-2r6j.json | 11 +++++++---- .../GHSA-h6w6-gghp-c4hr/GHSA-h6w6-gghp-c4hr.json | 2 +- .../GHSA-h83h-p79w-q64j/GHSA-h83h-p79w-q64j.json | 11 +++++++---- .../GHSA-hpg3-whph-cvcf/GHSA-hpg3-whph-cvcf.json | 11 +++++++---- .../GHSA-hrr2-23m9-vwg9/GHSA-hrr2-23m9-vwg9.json | 11 +++++++---- .../GHSA-hv8p-cqc6-r6pm/GHSA-hv8p-cqc6-r6pm.json | 11 +++++++---- .../GHSA-hw9f-66ch-w6pg/GHSA-hw9f-66ch-w6pg.json | 11 +++++++---- .../GHSA-hwpw-xpj3-c397/GHSA-hwpw-xpj3-c397.json | 11 +++++++---- .../GHSA-hx86-84jq-2v5p/GHSA-hx86-84jq-2v5p.json | 11 +++++++---- .../GHSA-j3mh-hgxq-fp6h/GHSA-j3mh-hgxq-fp6h.json | 9 ++++++--- .../GHSA-j7qq-x7xm-2hpv/GHSA-j7qq-x7xm-2hpv.json | 11 +++++++---- .../GHSA-jhpp-3jgc-qfwp/GHSA-jhpp-3jgc-qfwp.json | 11 +++++++---- .../GHSA-jvfj-c7wv-mq45/GHSA-jvfj-c7wv-mq45.json | 2 +- .../GHSA-jw4v-xfx4-pv7q/GHSA-jw4v-xfx4-pv7q.json | 11 +++++++---- .../GHSA-jw9c-3jfh-2qq2/GHSA-jw9c-3jfh-2qq2.json | 11 +++++++---- .../GHSA-m6xf-rg25-42wc/GHSA-m6xf-rg25-42wc.json | 11 +++++++---- .../GHSA-m854-6wh4-fmg2/GHSA-m854-6wh4-fmg2.json | 11 +++++++---- .../GHSA-mg24-mpj4-j47p/GHSA-mg24-mpj4-j47p.json | 11 +++++++---- .../GHSA-mgmj-jff7-4w5p/GHSA-mgmj-jff7-4w5p.json | 9 ++++++--- .../GHSA-mjm2-m2m4-7qj6/GHSA-mjm2-m2m4-7qj6.json | 11 +++++++---- .../GHSA-mq9p-qw76-q6h7/GHSA-mq9p-qw76-q6h7.json | 11 +++++++---- .../GHSA-mqrq-8fm6-x78m/GHSA-mqrq-8fm6-x78m.json | 15 +++++++++++---- .../GHSA-mwc7-2pw4-jqc9/GHSA-mwc7-2pw4-jqc9.json | 11 +++++++---- .../GHSA-mx84-33q7-299w/GHSA-mx84-33q7-299w.json | 9 ++++++--- .../GHSA-p4xc-x8pv-x8j5/GHSA-p4xc-x8pv-x8j5.json | 11 +++++++---- .../GHSA-p9rm-gwg4-7qmf/GHSA-p9rm-gwg4-7qmf.json | 11 +++++++---- .../GHSA-pc9f-29p9-88xf/GHSA-pc9f-29p9-88xf.json | 11 +++++++---- .../GHSA-pcv6-8pf7-r5hc/GHSA-pcv6-8pf7-r5hc.json | 11 +++++++---- .../GHSA-pfqw-6jm8-f3j8/GHSA-pfqw-6jm8-f3j8.json | 11 +++++++---- .../GHSA-pg8p-96cv-v9cj/GHSA-pg8p-96cv-v9cj.json | 11 +++++++---- .../GHSA-pg9r-hpv4-c9cq/GHSA-pg9r-hpv4-c9cq.json | 11 +++++++---- .../GHSA-pjfh-ccg3-6463/GHSA-pjfh-ccg3-6463.json | 9 ++++++--- .../GHSA-pm48-m4w3-255f/GHSA-pm48-m4w3-255f.json | 11 +++++++---- .../GHSA-pm5j-x234-pqf6/GHSA-pm5j-x234-pqf6.json | 11 +++++++---- .../GHSA-prqw-x27x-86h2/GHSA-prqw-x27x-86h2.json | 2 +- .../GHSA-pvcr-2c24-m94c/GHSA-pvcr-2c24-m94c.json | 11 +++++++---- .../GHSA-q2g7-qm59-84wp/GHSA-q2g7-qm59-84wp.json | 11 +++++++---- .../GHSA-q2hw-c235-rp9r/GHSA-q2hw-c235-rp9r.json | 11 +++++++---- .../GHSA-q2mm-7g26-cqpf/GHSA-q2mm-7g26-cqpf.json | 11 +++++++---- .../GHSA-q3rg-6598-285v/GHSA-q3rg-6598-285v.json | 11 +++++++---- .../GHSA-q4jw-jxm3-52jh/GHSA-q4jw-jxm3-52jh.json | 11 +++++++---- .../GHSA-qwgv-36mc-mpx9/GHSA-qwgv-36mc-mpx9.json | 9 ++++++--- .../GHSA-qwqc-jjwg-53mj/GHSA-qwqc-jjwg-53mj.json | 11 +++++++---- .../GHSA-qxcf-7fw9-mhjf/GHSA-qxcf-7fw9-mhjf.json | 11 +++++++---- .../GHSA-qxxc-w5wg-5w4v/GHSA-qxxc-w5wg-5w4v.json | 11 +++++++---- .../GHSA-r4j8-j63p-24j8/GHSA-r4j8-j63p-24j8.json | 11 +++++++---- .../GHSA-r8mx-gcwg-x6f7/GHSA-r8mx-gcwg-x6f7.json | 9 ++++++--- .../GHSA-rc9x-h469-w6gc/GHSA-rc9x-h469-w6gc.json | 9 ++++++--- .../GHSA-rcf6-gj9x-5p73/GHSA-rcf6-gj9x-5p73.json | 11 +++++++---- .../GHSA-rf5h-29fq-hr47/GHSA-rf5h-29fq-hr47.json | 11 +++++++---- .../GHSA-rgf9-4hxh-9736/GHSA-rgf9-4hxh-9736.json | 11 +++++++---- .../GHSA-rhq7-7m7h-w8m7/GHSA-rhq7-7m7h-w8m7.json | 2 +- .../GHSA-v4vq-27w6-p28p/GHSA-v4vq-27w6-p28p.json | 11 +++++++---- .../GHSA-v7jc-fx5p-2j4v/GHSA-v7jc-fx5p-2j4v.json | 11 +++++++---- .../GHSA-v7x8-wrhv-8rh2/GHSA-v7x8-wrhv-8rh2.json | 11 +++++++---- .../GHSA-v8fc-7564-v98v/GHSA-v8fc-7564-v98v.json | 11 +++++++---- .../GHSA-vf5w-x6g7-5c7q/GHSA-vf5w-x6g7-5c7q.json | 11 +++++++---- .../GHSA-vgjf-wg4r-wfgj/GHSA-vgjf-wg4r-wfgj.json | 11 +++++++---- .../GHSA-vpfw-2qg8-p8w4/GHSA-vpfw-2qg8-p8w4.json | 11 +++++++---- .../GHSA-vpvx-qcvr-cpv4/GHSA-vpvx-qcvr-cpv4.json | 15 +++++++++++---- .../GHSA-vq69-6gcm-2ff7/GHSA-vq69-6gcm-2ff7.json | 9 ++++++--- .../GHSA-vxmv-r24r-j66w/GHSA-vxmv-r24r-j66w.json | 11 +++++++---- .../GHSA-w2v7-qw4p-jjp9/GHSA-w2v7-qw4p-jjp9.json | 2 +- .../GHSA-w342-h5p8-hw97/GHSA-w342-h5p8-hw97.json | 11 +++++++---- .../GHSA-w96c-mpgg-prqv/GHSA-w96c-mpgg-prqv.json | 15 +++++++++++---- .../GHSA-wcjc-qwhg-vfmr/GHSA-wcjc-qwhg-vfmr.json | 11 +++++++---- .../GHSA-whmp-p89r-qv54/GHSA-whmp-p89r-qv54.json | 11 +++++++---- .../GHSA-wm6p-93j5-rx57/GHSA-wm6p-93j5-rx57.json | 11 +++++++---- .../GHSA-wmq9-769v-mqmc/GHSA-wmq9-769v-mqmc.json | 11 +++++++---- .../GHSA-wrgh-mmr6-2rm6/GHSA-wrgh-mmr6-2rm6.json | 11 +++++++---- .../GHSA-wwgc-f5xv-4vvc/GHSA-wwgc-f5xv-4vvc.json | 11 +++++++---- .../GHSA-wwjm-ww5x-84hm/GHSA-wwjm-ww5x-84hm.json | 11 +++++++---- .../GHSA-wxc5-mwv4-h4hh/GHSA-wxc5-mwv4-h4hh.json | 11 +++++++---- .../GHSA-x363-pjcf-82m7/GHSA-x363-pjcf-82m7.json | 11 +++++++---- .../GHSA-x7hx-9w3p-f5r3/GHSA-x7hx-9w3p-f5r3.json | 11 +++++++---- .../GHSA-x7p4-m95h-xjv4/GHSA-x7p4-m95h-xjv4.json | 2 +- .../GHSA-xpq8-mc3r-r862/GHSA-xpq8-mc3r-r862.json | 11 +++++++---- .../GHSA-xv27-hp74-6hr9/GHSA-xv27-hp74-6hr9.json | 11 +++++++---- .../GHSA-xw4h-q7jg-jqg8/GHSA-xw4h-q7jg-jqg8.json | 11 +++++++---- .../GHSA-xw97-mfvw-wc3w/GHSA-xw97-mfvw-wc3w.json | 11 +++++++---- .../GHSA-xxmf-fmx4-hxq3/GHSA-xxmf-fmx4-hxq3.json | 11 +++++++---- 204 files changed, 1311 insertions(+), 736 deletions(-) diff --git a/advisories/unreviewed/2024/05/GHSA-2252-jwp3-qxfh/GHSA-2252-jwp3-qxfh.json b/advisories/unreviewed/2024/05/GHSA-2252-jwp3-qxfh/GHSA-2252-jwp3-qxfh.json index aa86a158b06..3fe94dbfb84 100644 --- a/advisories/unreviewed/2024/05/GHSA-2252-jwp3-qxfh/GHSA-2252-jwp3-qxfh.json +++ b/advisories/unreviewed/2024/05/GHSA-2252-jwp3-qxfh/GHSA-2252-jwp3-qxfh.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-26cg-rw99-22rc/GHSA-26cg-rw99-22rc.json b/advisories/unreviewed/2024/05/GHSA-26cg-rw99-22rc/GHSA-26cg-rw99-22rc.json index da8fdd38e78..beb943efd0d 100644 --- a/advisories/unreviewed/2024/05/GHSA-26cg-rw99-22rc/GHSA-26cg-rw99-22rc.json +++ b/advisories/unreviewed/2024/05/GHSA-26cg-rw99-22rc/GHSA-26cg-rw99-22rc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-26cg-rw99-22rc", - "modified": "2024-05-01T21:30:34Z", + "modified": "2024-07-03T18:38:20Z", "published": "2024-05-01T21:30:34Z", "aliases": [ "CVE-2023-23019" ], "details": "Cross site scripting (XSS) vulnerability in file main.php in sourcecodester oretnom23 Blog Site 1.0 via the name and email parameters to function user_add.\\", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-01T19:15:20Z" diff --git a/advisories/unreviewed/2024/05/GHSA-2769-9cr9-9w7h/GHSA-2769-9cr9-9w7h.json b/advisories/unreviewed/2024/05/GHSA-2769-9cr9-9w7h/GHSA-2769-9cr9-9w7h.json index 90a7c0ebde2..3a652ebe609 100644 --- a/advisories/unreviewed/2024/05/GHSA-2769-9cr9-9w7h/GHSA-2769-9cr9-9w7h.json +++ b/advisories/unreviewed/2024/05/GHSA-2769-9cr9-9w7h/GHSA-2769-9cr9-9w7h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2769-9cr9-9w7h", - "modified": "2024-05-07T18:30:34Z", + "modified": "2024-07-03T18:39:35Z", "published": "2024-05-07T18:30:34Z", "aliases": [ "CVE-2024-33155" ], "details": "J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the getDeptList() function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T17:15:09Z" diff --git a/advisories/unreviewed/2024/05/GHSA-2cf3-8v44-39fh/GHSA-2cf3-8v44-39fh.json b/advisories/unreviewed/2024/05/GHSA-2cf3-8v44-39fh/GHSA-2cf3-8v44-39fh.json index 268bdee3657..f38d7d77777 100644 --- a/advisories/unreviewed/2024/05/GHSA-2cf3-8v44-39fh/GHSA-2cf3-8v44-39fh.json +++ b/advisories/unreviewed/2024/05/GHSA-2cf3-8v44-39fh/GHSA-2cf3-8v44-39fh.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-2f36-cx3x-62vx/GHSA-2f36-cx3x-62vx.json b/advisories/unreviewed/2024/05/GHSA-2f36-cx3x-62vx/GHSA-2f36-cx3x-62vx.json index 00d6f541139..56509b87f59 100644 --- a/advisories/unreviewed/2024/05/GHSA-2f36-cx3x-62vx/GHSA-2f36-cx3x-62vx.json +++ b/advisories/unreviewed/2024/05/GHSA-2f36-cx3x-62vx/GHSA-2f36-cx3x-62vx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2f36-cx3x-62vx", - "modified": "2024-05-07T21:31:47Z", + "modified": "2024-07-03T18:39:50Z", "published": "2024-05-07T21:31:47Z", "aliases": [ "CVE-2024-23710" ], "details": "In assertPackageWithSharedUserIdIsPrivileged of InstallPackageHelper.java, there is a possible execution of arbitrary app code as a privileged app due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T21:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-2jv5-xv66-fhx8/GHSA-2jv5-xv66-fhx8.json b/advisories/unreviewed/2024/05/GHSA-2jv5-xv66-fhx8/GHSA-2jv5-xv66-fhx8.json index 03045370726..55f951f2fb0 100644 --- a/advisories/unreviewed/2024/05/GHSA-2jv5-xv66-fhx8/GHSA-2jv5-xv66-fhx8.json +++ b/advisories/unreviewed/2024/05/GHSA-2jv5-xv66-fhx8/GHSA-2jv5-xv66-fhx8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2jv5-xv66-fhx8", - "modified": "2024-05-03T18:30:37Z", + "modified": "2024-07-03T18:38:48Z", "published": "2024-05-03T18:30:37Z", "aliases": [ "CVE-2024-33791" ], "details": "A cross-site scripting (XSS) vulnerability in netis-systems MEX605 v2.00.06 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the getTimeZone function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-03T17:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-2r4f-jfx8-mhm3/GHSA-2r4f-jfx8-mhm3.json b/advisories/unreviewed/2024/05/GHSA-2r4f-jfx8-mhm3/GHSA-2r4f-jfx8-mhm3.json index 0c122b6f2d8..c1527452051 100644 --- a/advisories/unreviewed/2024/05/GHSA-2r4f-jfx8-mhm3/GHSA-2r4f-jfx8-mhm3.json +++ b/advisories/unreviewed/2024/05/GHSA-2r4f-jfx8-mhm3/GHSA-2r4f-jfx8-mhm3.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-120", "CWE-306" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/05/GHSA-2r9m-fc3w-cxph/GHSA-2r9m-fc3w-cxph.json b/advisories/unreviewed/2024/05/GHSA-2r9m-fc3w-cxph/GHSA-2r9m-fc3w-cxph.json index e57cbf0e9ca..5841a759ecc 100644 --- a/advisories/unreviewed/2024/05/GHSA-2r9m-fc3w-cxph/GHSA-2r9m-fc3w-cxph.json +++ b/advisories/unreviewed/2024/05/GHSA-2r9m-fc3w-cxph/GHSA-2r9m-fc3w-cxph.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2r9m-fc3w-cxph", - "modified": "2024-05-14T15:32:54Z", + "modified": "2024-07-03T18:40:25Z", "published": "2024-05-14T15:32:54Z", "aliases": [ "CVE-2024-29161" ], "details": "HDF5 through 1.14.3 contains a heap buffer overflow in H5A__attr_release_table, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:15:32Z" diff --git a/advisories/unreviewed/2024/05/GHSA-2w87-6hh6-mqrj/GHSA-2w87-6hh6-mqrj.json b/advisories/unreviewed/2024/05/GHSA-2w87-6hh6-mqrj/GHSA-2w87-6hh6-mqrj.json index d74071804a7..0140914a89b 100644 --- a/advisories/unreviewed/2024/05/GHSA-2w87-6hh6-mqrj/GHSA-2w87-6hh6-mqrj.json +++ b/advisories/unreviewed/2024/05/GHSA-2w87-6hh6-mqrj/GHSA-2w87-6hh6-mqrj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2w87-6hh6-mqrj", - "modified": "2024-06-13T21:30:36Z", + "modified": "2024-07-03T18:39:51Z", "published": "2024-05-07T21:31:47Z", "aliases": [ "CVE-2024-4030" ], "details": "On Windows a directory returned by tempfile.mkdtemp() would not always have permissions set to restrict reading and writing to the temporary directory by other users, instead usually inheriting the correct permissions from the default location. Alternate configurations or users without a profile directory may not have the intended permissions.\n\nIf you’re not using Windows or haven’t changed the temporary directory location then you aren’t affected by this vulnerability. On other platforms the returned directory is consistently readable and writable only by the current user.\n\nThis issue was caused by Python not supporting Unix permissions on Windows. The fix adds support for Unix “700” for the mkdir function on Windows which is used by mkdtemp() to ensure the newly created directory has the proper permissions.\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -79,7 +82,7 @@ "cwe_ids": [ "CWE-276" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T21:15:09Z" diff --git a/advisories/unreviewed/2024/05/GHSA-2w94-phv7-xjw4/GHSA-2w94-phv7-xjw4.json b/advisories/unreviewed/2024/05/GHSA-2w94-phv7-xjw4/GHSA-2w94-phv7-xjw4.json index d3a533f541f..eca220d39b1 100644 --- a/advisories/unreviewed/2024/05/GHSA-2w94-phv7-xjw4/GHSA-2w94-phv7-xjw4.json +++ b/advisories/unreviewed/2024/05/GHSA-2w94-phv7-xjw4/GHSA-2w94-phv7-xjw4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2w94-phv7-xjw4", - "modified": "2024-05-06T18:30:34Z", + "modified": "2024-07-03T18:39:09Z", "published": "2024-05-06T18:30:34Z", "aliases": [ "CVE-2024-26312" ], "details": "Archer Platform 6 before 2024.03 contains a sensitive information disclosure vulnerability. An authenticated attacker could potentially obtain access to sensitive information via a popup warning message.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-06T16:15:13Z" diff --git a/advisories/unreviewed/2024/05/GHSA-32r2-xfqh-9qx6/GHSA-32r2-xfqh-9qx6.json b/advisories/unreviewed/2024/05/GHSA-32r2-xfqh-9qx6/GHSA-32r2-xfqh-9qx6.json index 218b5924002..bf05ffed14a 100644 --- a/advisories/unreviewed/2024/05/GHSA-32r2-xfqh-9qx6/GHSA-32r2-xfqh-9qx6.json +++ b/advisories/unreviewed/2024/05/GHSA-32r2-xfqh-9qx6/GHSA-32r2-xfqh-9qx6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-32r2-xfqh-9qx6", - "modified": "2024-05-14T18:30:44Z", + "modified": "2024-07-03T18:40:07Z", "published": "2024-05-14T18:30:44Z", "aliases": [ "CVE-2022-32508" ], "details": "An issue was discovered on certain Nuki Home Solutions devices. By sending a malformed HTTP verb, it is possible to force a reboot of the device. This affects Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T10:43:41Z" diff --git a/advisories/unreviewed/2024/05/GHSA-339j-p2wf-p72r/GHSA-339j-p2wf-p72r.json b/advisories/unreviewed/2024/05/GHSA-339j-p2wf-p72r/GHSA-339j-p2wf-p72r.json index dc2da21f9df..c778f48ade2 100644 --- a/advisories/unreviewed/2024/05/GHSA-339j-p2wf-p72r/GHSA-339j-p2wf-p72r.json +++ b/advisories/unreviewed/2024/05/GHSA-339j-p2wf-p72r/GHSA-339j-p2wf-p72r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-339j-p2wf-p72r", - "modified": "2024-05-08T15:30:42Z", + "modified": "2024-07-03T18:39:57Z", "published": "2024-05-08T15:30:42Z", "aliases": [ "CVE-2024-25525" ], "details": "RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the filename parameter at /WorkFlow/OfficeFileDownload.aspx.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-08T15:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-33r5-hf6m-mc27/GHSA-33r5-hf6m-mc27.json b/advisories/unreviewed/2024/05/GHSA-33r5-hf6m-mc27/GHSA-33r5-hf6m-mc27.json index 3bd097ee366..4dacefc628e 100644 --- a/advisories/unreviewed/2024/05/GHSA-33r5-hf6m-mc27/GHSA-33r5-hf6m-mc27.json +++ b/advisories/unreviewed/2024/05/GHSA-33r5-hf6m-mc27/GHSA-33r5-hf6m-mc27.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-33r5-hf6m-mc27", - "modified": "2024-05-06T15:30:39Z", + "modified": "2024-07-03T18:39:08Z", "published": "2024-05-06T15:30:39Z", "aliases": [ "CVE-2024-33294" ], "details": "An issue in Library System using PHP/MySQli with Source Code V1.0 allows a remote attacker to execute arbitrary code via the _FAILE variable in the student_edit_photo.php component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-06T15:15:23Z" diff --git a/advisories/unreviewed/2024/05/GHSA-377p-g8gr-5wpg/GHSA-377p-g8gr-5wpg.json b/advisories/unreviewed/2024/05/GHSA-377p-g8gr-5wpg/GHSA-377p-g8gr-5wpg.json index 5945c2f5f13..5fd02bc608b 100644 --- a/advisories/unreviewed/2024/05/GHSA-377p-g8gr-5wpg/GHSA-377p-g8gr-5wpg.json +++ b/advisories/unreviewed/2024/05/GHSA-377p-g8gr-5wpg/GHSA-377p-g8gr-5wpg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-377p-g8gr-5wpg", - "modified": "2024-05-03T18:30:37Z", + "modified": "2024-07-03T18:38:47Z", "published": "2024-05-03T18:30:37Z", "aliases": [ "CVE-2024-31636" ], "details": "An issue in LIEF v.0.14.1 allows a local attacker to obtain sensitive information via the name parameter of the machd_reader.c component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-457" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-03T17:15:07Z" diff --git a/advisories/unreviewed/2024/05/GHSA-37jj-p98x-q9ff/GHSA-37jj-p98x-q9ff.json b/advisories/unreviewed/2024/05/GHSA-37jj-p98x-q9ff/GHSA-37jj-p98x-q9ff.json index 4b34ce398a6..a9f6dfed003 100644 --- a/advisories/unreviewed/2024/05/GHSA-37jj-p98x-q9ff/GHSA-37jj-p98x-q9ff.json +++ b/advisories/unreviewed/2024/05/GHSA-37jj-p98x-q9ff/GHSA-37jj-p98x-q9ff.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-37jj-p98x-q9ff", - "modified": "2024-05-07T21:31:46Z", + "modified": "2024-07-03T18:39:46Z", "published": "2024-05-07T21:31:46Z", "aliases": [ "CVE-2024-23705" ], "details": "In multiple locations, there is a possible failure to persist or enforce user restrictions due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T21:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-3849-33qq-vw2c/GHSA-3849-33qq-vw2c.json b/advisories/unreviewed/2024/05/GHSA-3849-33qq-vw2c/GHSA-3849-33qq-vw2c.json index 200ce9906d3..bc5cc17712c 100644 --- a/advisories/unreviewed/2024/05/GHSA-3849-33qq-vw2c/GHSA-3849-33qq-vw2c.json +++ b/advisories/unreviewed/2024/05/GHSA-3849-33qq-vw2c/GHSA-3849-33qq-vw2c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3849-33qq-vw2c", - "modified": "2024-05-01T21:30:38Z", + "modified": "2024-07-03T18:38:30Z", "published": "2024-05-01T21:30:38Z", "aliases": [ "CVE-2024-33423" ], "details": "Cross-Site Scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Logout parameter under the Language section.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-80" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-01T20:15:12Z" diff --git a/advisories/unreviewed/2024/05/GHSA-38f9-jc9v-rgw6/GHSA-38f9-jc9v-rgw6.json b/advisories/unreviewed/2024/05/GHSA-38f9-jc9v-rgw6/GHSA-38f9-jc9v-rgw6.json index 13efcf98b50..f1d1c1a7726 100644 --- a/advisories/unreviewed/2024/05/GHSA-38f9-jc9v-rgw6/GHSA-38f9-jc9v-rgw6.json +++ b/advisories/unreviewed/2024/05/GHSA-38f9-jc9v-rgw6/GHSA-38f9-jc9v-rgw6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-38f9-jc9v-rgw6", - "modified": "2024-05-02T18:30:51Z", + "modified": "2024-07-03T18:38:44Z", "published": "2024-05-02T18:30:51Z", "aliases": [ "CVE-2024-32359" ], "details": "An RBAC authorization risk in Carina v0.13.0 and earlier allows local attackers to execute arbitrary code through designed commands to obtain the secrets of the entire cluster and further take over the cluster.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-285" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-02T16:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-39cp-8qfj-8cjm/GHSA-39cp-8qfj-8cjm.json b/advisories/unreviewed/2024/05/GHSA-39cp-8qfj-8cjm/GHSA-39cp-8qfj-8cjm.json index a71e45fe781..28232e54080 100644 --- a/advisories/unreviewed/2024/05/GHSA-39cp-8qfj-8cjm/GHSA-39cp-8qfj-8cjm.json +++ b/advisories/unreviewed/2024/05/GHSA-39cp-8qfj-8cjm/GHSA-39cp-8qfj-8cjm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-39cp-8qfj-8cjm", - "modified": "2024-05-01T21:30:38Z", + "modified": "2024-07-03T18:38:27Z", "published": "2024-05-01T21:30:38Z", "aliases": [ "CVE-2024-33431" ], "details": "An issue in phiola/src/afilter/conv.c:115 of phiola v2.0-rc22 allows a remote attacker to cause a denial of service via a crafted .wav file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-670" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-01T19:15:27Z" diff --git a/advisories/unreviewed/2024/05/GHSA-39jg-cp5w-9278/GHSA-39jg-cp5w-9278.json b/advisories/unreviewed/2024/05/GHSA-39jg-cp5w-9278/GHSA-39jg-cp5w-9278.json index 08f26aee6f5..3858a2b8645 100644 --- a/advisories/unreviewed/2024/05/GHSA-39jg-cp5w-9278/GHSA-39jg-cp5w-9278.json +++ b/advisories/unreviewed/2024/05/GHSA-39jg-cp5w-9278/GHSA-39jg-cp5w-9278.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-39jg-cp5w-9278", - "modified": "2024-05-08T15:30:42Z", + "modified": "2024-07-03T18:39:57Z", "published": "2024-05-08T15:30:42Z", "aliases": [ "CVE-2024-25524" ], "details": "RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the sys_file_storage_id parameter at /WorkPlan/WorkPlanAttachDownLoad.aspx.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-08T15:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-3f3h-87pc-27hg/GHSA-3f3h-87pc-27hg.json b/advisories/unreviewed/2024/05/GHSA-3f3h-87pc-27hg/GHSA-3f3h-87pc-27hg.json index dba5f5a6916..b121511e127 100644 --- a/advisories/unreviewed/2024/05/GHSA-3f3h-87pc-27hg/GHSA-3f3h-87pc-27hg.json +++ b/advisories/unreviewed/2024/05/GHSA-3f3h-87pc-27hg/GHSA-3f3h-87pc-27hg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3f3h-87pc-27hg", - "modified": "2024-05-07T21:31:45Z", + "modified": "2024-07-03T18:39:40Z", "published": "2024-05-07T21:31:44Z", "aliases": [ "CVE-2024-25509" ], "details": "RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the sys_file_storage_id parameter at /WorkFlow/wf_file_download.aspx.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T19:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-3g5p-5p6j-r9qp/GHSA-3g5p-5p6j-r9qp.json b/advisories/unreviewed/2024/05/GHSA-3g5p-5p6j-r9qp/GHSA-3g5p-5p6j-r9qp.json index 53ca169015b..5570209277d 100644 --- a/advisories/unreviewed/2024/05/GHSA-3g5p-5p6j-r9qp/GHSA-3g5p-5p6j-r9qp.json +++ b/advisories/unreviewed/2024/05/GHSA-3g5p-5p6j-r9qp/GHSA-3g5p-5p6j-r9qp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3g5p-5p6j-r9qp", - "modified": "2024-05-07T21:31:47Z", + "modified": "2024-07-03T18:39:47Z", "published": "2024-05-07T21:31:46Z", "aliases": [ "CVE-2024-23706" ], "details": "In multiple locations, there is a possible bypass of health data permissions due to an improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T21:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-3jxg-9cjf-4f5f/GHSA-3jxg-9cjf-4f5f.json b/advisories/unreviewed/2024/05/GHSA-3jxg-9cjf-4f5f/GHSA-3jxg-9cjf-4f5f.json index 86d346cdc76..da92d24cb2a 100644 --- a/advisories/unreviewed/2024/05/GHSA-3jxg-9cjf-4f5f/GHSA-3jxg-9cjf-4f5f.json +++ b/advisories/unreviewed/2024/05/GHSA-3jxg-9cjf-4f5f/GHSA-3jxg-9cjf-4f5f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3jxg-9cjf-4f5f", - "modified": "2024-05-14T18:30:44Z", + "modified": "2024-07-03T18:40:03Z", "published": "2024-05-14T18:30:44Z", "aliases": [ "CVE-2022-32502" ], "details": "An issue was discovered on certain Nuki Home Solutions devices. There is a buffer overflow over the encrypted token parsing logic in the HTTP service that allows remote code execution. This affects Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T10:43:40Z" diff --git a/advisories/unreviewed/2024/05/GHSA-3m3m-q3hw-6qq6/GHSA-3m3m-q3hw-6qq6.json b/advisories/unreviewed/2024/05/GHSA-3m3m-q3hw-6qq6/GHSA-3m3m-q3hw-6qq6.json index 9a11eb317bf..2772167e8af 100644 --- a/advisories/unreviewed/2024/05/GHSA-3m3m-q3hw-6qq6/GHSA-3m3m-q3hw-6qq6.json +++ b/advisories/unreviewed/2024/05/GHSA-3m3m-q3hw-6qq6/GHSA-3m3m-q3hw-6qq6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3m3m-q3hw-6qq6", - "modified": "2024-06-10T18:30:58Z", + "modified": "2024-07-03T18:40:10Z", "published": "2024-05-14T15:32:53Z", "aliases": [ "CVE-2024-27793" ], "details": "The issue was addressed with improved checks. This issue is fixed in iTunes 12.13.2 for Windows. Parsing a file may lead to an unexpected app termination or arbitrary code execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:13:02Z" diff --git a/advisories/unreviewed/2024/05/GHSA-3q9v-78jg-p832/GHSA-3q9v-78jg-p832.json b/advisories/unreviewed/2024/05/GHSA-3q9v-78jg-p832/GHSA-3q9v-78jg-p832.json index dc508ebd209..61dec1f0c3c 100644 --- a/advisories/unreviewed/2024/05/GHSA-3q9v-78jg-p832/GHSA-3q9v-78jg-p832.json +++ b/advisories/unreviewed/2024/05/GHSA-3q9v-78jg-p832/GHSA-3q9v-78jg-p832.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3q9v-78jg-p832", - "modified": "2024-05-01T21:30:37Z", + "modified": "2024-07-03T18:38:25Z", "published": "2024-05-01T21:30:37Z", "aliases": [ "CVE-2024-26504" ], "details": "An issue in Wifire Hotspot v.4.5.3 allows a local attacker to execute arbitrary code via a crafted payload to the dst parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-601" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-01T19:15:22Z" diff --git a/advisories/unreviewed/2024/05/GHSA-3vcv-qvpj-9v53/GHSA-3vcv-qvpj-9v53.json b/advisories/unreviewed/2024/05/GHSA-3vcv-qvpj-9v53/GHSA-3vcv-qvpj-9v53.json index 3aa63ef0b26..9a9b75aa46e 100644 --- a/advisories/unreviewed/2024/05/GHSA-3vcv-qvpj-9v53/GHSA-3vcv-qvpj-9v53.json +++ b/advisories/unreviewed/2024/05/GHSA-3vcv-qvpj-9v53/GHSA-3vcv-qvpj-9v53.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3vcv-qvpj-9v53", - "modified": "2024-05-02T15:30:34Z", + "modified": "2024-07-03T18:38:37Z", "published": "2024-05-02T15:30:34Z", "aliases": [ "CVE-2024-33302" ], "details": "SourceCodester Product Show Room 1.0 and before is vulnerable to Cross Site Scripting (XSS) via \"Middle Name\" under Add Users.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-02T14:15:09Z" diff --git a/advisories/unreviewed/2024/05/GHSA-3vp4-9c6g-mcq2/GHSA-3vp4-9c6g-mcq2.json b/advisories/unreviewed/2024/05/GHSA-3vp4-9c6g-mcq2/GHSA-3vp4-9c6g-mcq2.json index ce5eef8b952..b8e6e0972b3 100644 --- a/advisories/unreviewed/2024/05/GHSA-3vp4-9c6g-mcq2/GHSA-3vp4-9c6g-mcq2.json +++ b/advisories/unreviewed/2024/05/GHSA-3vp4-9c6g-mcq2/GHSA-3vp4-9c6g-mcq2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3vp4-9c6g-mcq2", - "modified": "2024-05-08T06:30:48Z", + "modified": "2024-07-03T18:39:51Z", "published": "2024-05-08T06:30:48Z", "aliases": [ "CVE-2024-32674" ], "details": "Heateor Social Login WordPress prior to 1.1.32 contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-08T04:15:09Z" diff --git a/advisories/unreviewed/2024/05/GHSA-3wvq-9p67-m439/GHSA-3wvq-9p67-m439.json b/advisories/unreviewed/2024/05/GHSA-3wvq-9p67-m439/GHSA-3wvq-9p67-m439.json index 3c20848ee21..6e452c83c46 100644 --- a/advisories/unreviewed/2024/05/GHSA-3wvq-9p67-m439/GHSA-3wvq-9p67-m439.json +++ b/advisories/unreviewed/2024/05/GHSA-3wvq-9p67-m439/GHSA-3wvq-9p67-m439.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3wvq-9p67-m439", - "modified": "2024-05-07T15:30:40Z", + "modified": "2024-07-03T18:39:25Z", "published": "2024-05-07T15:30:40Z", "aliases": [ "CVE-2024-33120" ], "details": "Roothub v2.5 was discovered to contain an arbitrary file upload vulnerability via the customPath parameter in the upload() function. This vulnerability allows attackers to execute arbitrary code via a crafted JSP file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T15:15:09Z" diff --git a/advisories/unreviewed/2024/05/GHSA-446j-5276-666q/GHSA-446j-5276-666q.json b/advisories/unreviewed/2024/05/GHSA-446j-5276-666q/GHSA-446j-5276-666q.json index f439a8599f1..02225562fbc 100644 --- a/advisories/unreviewed/2024/05/GHSA-446j-5276-666q/GHSA-446j-5276-666q.json +++ b/advisories/unreviewed/2024/05/GHSA-446j-5276-666q/GHSA-446j-5276-666q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-446j-5276-666q", - "modified": "2024-05-03T15:30:55Z", + "modified": "2024-07-03T18:38:47Z", "published": "2024-05-03T15:30:55Z", "aliases": [ "CVE-2024-29417" ], "details": "Insecure Permissions vulnerability in e-trust Horacius 1.0, 1.1, and 1.2 allows a local attacker to escalate privileges via the password reset function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-277" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-03T15:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-4996-x4q8-5x37/GHSA-4996-x4q8-5x37.json b/advisories/unreviewed/2024/05/GHSA-4996-x4q8-5x37/GHSA-4996-x4q8-5x37.json index 79926283552..21ff714b409 100644 --- a/advisories/unreviewed/2024/05/GHSA-4996-x4q8-5x37/GHSA-4996-x4q8-5x37.json +++ b/advisories/unreviewed/2024/05/GHSA-4996-x4q8-5x37/GHSA-4996-x4q8-5x37.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4996-x4q8-5x37", - "modified": "2024-05-07T18:30:34Z", + "modified": "2024-07-03T18:39:36Z", "published": "2024-05-07T18:30:34Z", "aliases": [ "CVE-2023-42757" ], "details": "Process Explorer before 17.04 allows attackers to make it functionally unavailable (a denial of service for analysis) by renaming an executable file to a new extensionless 255-character name and launching it with NtCreateUserProcess. This can occur through an issue in wcscat_s error handling.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T18:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-4f92-w438-f484/GHSA-4f92-w438-f484.json b/advisories/unreviewed/2024/05/GHSA-4f92-w438-f484/GHSA-4f92-w438-f484.json index b597d88e6db..9906613ede6 100644 --- a/advisories/unreviewed/2024/05/GHSA-4f92-w438-f484/GHSA-4f92-w438-f484.json +++ b/advisories/unreviewed/2024/05/GHSA-4f92-w438-f484/GHSA-4f92-w438-f484.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4f92-w438-f484", - "modified": "2024-05-02T12:30:40Z", + "modified": "2024-07-03T18:38:36Z", "published": "2024-05-02T12:30:40Z", "aliases": [ "CVE-2024-3955" ], "details": "URL GET parameter \"logtime\" utilized within the \"downloadlog\" function from \"cbpi/http_endpoints/http_system.py\" is subsequently passed to the \"os.system\" function in \"cbpi/controller/system_controller.py\" without prior validation allowing to execute arbitrary code.This issue affects CraftBeerPi 4: from 4.0.0.58 (commit 563fae9) before 4.4.1.a1 (commit 57572c7).\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-02T10:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-4g7f-972r-hmcv/GHSA-4g7f-972r-hmcv.json b/advisories/unreviewed/2024/05/GHSA-4g7f-972r-hmcv/GHSA-4g7f-972r-hmcv.json index 5a7a0672c92..1e5e2427efc 100644 --- a/advisories/unreviewed/2024/05/GHSA-4g7f-972r-hmcv/GHSA-4g7f-972r-hmcv.json +++ b/advisories/unreviewed/2024/05/GHSA-4g7f-972r-hmcv/GHSA-4g7f-972r-hmcv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4g7f-972r-hmcv", - "modified": "2024-05-07T18:30:33Z", + "modified": "2024-07-03T18:39:32Z", "published": "2024-05-07T18:30:33Z", "aliases": [ "CVE-2024-29149" ], "details": "An issue was discovered in Alcatel-Lucent ALE NOE deskphones through 86x8_NOE-R300.1.40.12.4180 and SIP deskphones through 86x8_SIP-R200.1.01.10.728. Because of a time-of-check time-of-use vulnerability, an authenticated attacker is able to replace the verified firmware image with malicious firmware during the update process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-367" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T17:15:07Z" diff --git a/advisories/unreviewed/2024/05/GHSA-4g9w-6f9w-cjc7/GHSA-4g9w-6f9w-cjc7.json b/advisories/unreviewed/2024/05/GHSA-4g9w-6f9w-cjc7/GHSA-4g9w-6f9w-cjc7.json index 34d03af1d31..eee7a509a05 100644 --- a/advisories/unreviewed/2024/05/GHSA-4g9w-6f9w-cjc7/GHSA-4g9w-6f9w-cjc7.json +++ b/advisories/unreviewed/2024/05/GHSA-4g9w-6f9w-cjc7/GHSA-4g9w-6f9w-cjc7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4g9w-6f9w-cjc7", - "modified": "2024-05-07T15:30:38Z", + "modified": "2024-07-03T18:39:20Z", "published": "2024-05-07T15:30:38Z", "aliases": [ "CVE-2024-33782" ], "details": "MP-SPDZ v0.3.8 was discovered to contain a stack overflow via the function OTExtensionWithMatrix::extend in /OT/OTExtensionWithMatrix.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted message.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T14:15:10Z" diff --git a/advisories/unreviewed/2024/05/GHSA-4jjj-r6hx-hx6f/GHSA-4jjj-r6hx-hx6f.json b/advisories/unreviewed/2024/05/GHSA-4jjj-r6hx-hx6f/GHSA-4jjj-r6hx-hx6f.json index 01d09dfa694..6680ce29311 100644 --- a/advisories/unreviewed/2024/05/GHSA-4jjj-r6hx-hx6f/GHSA-4jjj-r6hx-hx6f.json +++ b/advisories/unreviewed/2024/05/GHSA-4jjj-r6hx-hx6f/GHSA-4jjj-r6hx-hx6f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4jjj-r6hx-hx6f", - "modified": "2024-05-06T21:30:38Z", + "modified": "2024-07-03T18:39:19Z", "published": "2024-05-06T21:30:38Z", "aliases": [ "CVE-2024-34534" ], "details": "A SQL injection vulnerability in Cybrosys Techno Solutions Text Commander module (aka text_commander) 16.0 through 16.0.1 allows a remote attacker to gain privileges via the data parameter to models/ir_model.py:IrModel::chech_model.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-06T21:15:48Z" diff --git a/advisories/unreviewed/2024/05/GHSA-4rfv-qq74-7p4v/GHSA-4rfv-qq74-7p4v.json b/advisories/unreviewed/2024/05/GHSA-4rfv-qq74-7p4v/GHSA-4rfv-qq74-7p4v.json index eebf87c25f5..e28429eb83f 100644 --- a/advisories/unreviewed/2024/05/GHSA-4rfv-qq74-7p4v/GHSA-4rfv-qq74-7p4v.json +++ b/advisories/unreviewed/2024/05/GHSA-4rfv-qq74-7p4v/GHSA-4rfv-qq74-7p4v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4rfv-qq74-7p4v", - "modified": "2024-05-07T15:30:39Z", + "modified": "2024-07-03T18:39:22Z", "published": "2024-05-07T15:30:39Z", "aliases": [ "CVE-2024-32369" ], "details": "SQL Injection vulnerability in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a remote attacker to obtain sensitive information via a crafted payload to the start and limit parameter in the mliWhiteList.php component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T15:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-4rmp-jjj9-cfm4/GHSA-4rmp-jjj9-cfm4.json b/advisories/unreviewed/2024/05/GHSA-4rmp-jjj9-cfm4/GHSA-4rmp-jjj9-cfm4.json index eac010de7e4..d4386756586 100644 --- a/advisories/unreviewed/2024/05/GHSA-4rmp-jjj9-cfm4/GHSA-4rmp-jjj9-cfm4.json +++ b/advisories/unreviewed/2024/05/GHSA-4rmp-jjj9-cfm4/GHSA-4rmp-jjj9-cfm4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4rmp-jjj9-cfm4", - "modified": "2024-06-22T03:31:08Z", + "modified": "2024-07-03T18:40:15Z", "published": "2024-05-14T15:32:53Z", "aliases": [ "CVE-2024-27834" ], "details": "The issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, tvOS 17.5, Safari 17.5, watchOS 10.5, macOS Sonoma 14.5. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -73,9 +76,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-277" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:13:06Z" diff --git a/advisories/unreviewed/2024/05/GHSA-52cx-m9j4-rq34/GHSA-52cx-m9j4-rq34.json b/advisories/unreviewed/2024/05/GHSA-52cx-m9j4-rq34/GHSA-52cx-m9j4-rq34.json index 47e4d845c9b..dc4cb342b43 100644 --- a/advisories/unreviewed/2024/05/GHSA-52cx-m9j4-rq34/GHSA-52cx-m9j4-rq34.json +++ b/advisories/unreviewed/2024/05/GHSA-52cx-m9j4-rq34/GHSA-52cx-m9j4-rq34.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-52cx-m9j4-rq34", - "modified": "2024-05-07T18:30:33Z", + "modified": "2024-07-03T18:39:31Z", "published": "2024-05-07T18:30:33Z", "aliases": [ "CVE-2024-33857" ], "details": "An issue was discovered in Logpoint before 7.4.0. Due to a lack of input validation on URLs in threat intelligence, an attacker with low-level access to the system can trigger Server Side Request Forgery.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-918" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T16:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-52mx-4f7f-jvvm/GHSA-52mx-4f7f-jvvm.json b/advisories/unreviewed/2024/05/GHSA-52mx-4f7f-jvvm/GHSA-52mx-4f7f-jvvm.json index 6e5e17edfb5..015ad7daecb 100644 --- a/advisories/unreviewed/2024/05/GHSA-52mx-4f7f-jvvm/GHSA-52mx-4f7f-jvvm.json +++ b/advisories/unreviewed/2024/05/GHSA-52mx-4f7f-jvvm/GHSA-52mx-4f7f-jvvm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-52mx-4f7f-jvvm", - "modified": "2024-06-11T09:30:59Z", + "modified": "2024-07-03T18:40:16Z", "published": "2024-05-14T15:32:53Z", "aliases": [ "CVE-2024-27847" ], "details": "This issue was addressed with improved checks This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. An app may be able to bypass Privacy preferences.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -57,9 +60,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-277" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:13:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-56hg-r682-945v/GHSA-56hg-r682-945v.json b/advisories/unreviewed/2024/05/GHSA-56hg-r682-945v/GHSA-56hg-r682-945v.json index affe896b3f7..e5d7d0e20d4 100644 --- a/advisories/unreviewed/2024/05/GHSA-56hg-r682-945v/GHSA-56hg-r682-945v.json +++ b/advisories/unreviewed/2024/05/GHSA-56hg-r682-945v/GHSA-56hg-r682-945v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-56hg-r682-945v", - "modified": "2024-05-14T15:32:54Z", + "modified": "2024-07-03T18:40:27Z", "published": "2024-05-14T15:32:54Z", "aliases": [ "CVE-2024-2257" ], "details": "This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to improper implementation of password policies. An attacker with physical access could exploit this by creating password that do not adhere to the defined security standards/policy on the vulnerable system.\n\nSuccessful exploitation of this vulnerability could allow the attacker to expose the router to potential security threats.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-20" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:18:35Z" diff --git a/advisories/unreviewed/2024/05/GHSA-59j5-r3pj-3q9p/GHSA-59j5-r3pj-3q9p.json b/advisories/unreviewed/2024/05/GHSA-59j5-r3pj-3q9p/GHSA-59j5-r3pj-3q9p.json index 2207dcc2bcb..a5b06cb2bba 100644 --- a/advisories/unreviewed/2024/05/GHSA-59j5-r3pj-3q9p/GHSA-59j5-r3pj-3q9p.json +++ b/advisories/unreviewed/2024/05/GHSA-59j5-r3pj-3q9p/GHSA-59j5-r3pj-3q9p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-59j5-r3pj-3q9p", - "modified": "2024-05-07T21:31:46Z", + "modified": "2024-07-03T18:39:46Z", "published": "2024-05-07T21:31:46Z", "aliases": [ "CVE-2024-0042" ], "details": "In TBD of TBD, there is a possible confusion of OEM and DRM certificates due to improperly used crypto. This could lead to local bypass of DRM content protection with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-843" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T21:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-5fq7-4mxc-535h/GHSA-5fq7-4mxc-535h.json b/advisories/unreviewed/2024/05/GHSA-5fq7-4mxc-535h/GHSA-5fq7-4mxc-535h.json index 4ae0891beb6..919be9b5a13 100644 --- a/advisories/unreviewed/2024/05/GHSA-5fq7-4mxc-535h/GHSA-5fq7-4mxc-535h.json +++ b/advisories/unreviewed/2024/05/GHSA-5fq7-4mxc-535h/GHSA-5fq7-4mxc-535h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5fq7-4mxc-535h", - "modified": "2024-06-10T18:30:58Z", + "modified": "2024-07-03T18:39:57Z", "published": "2024-05-08T18:30:48Z", "aliases": [ "CVE-2024-24787" ], "details": "On Darwin, building a Go module which contains CGO can trigger arbitrary code execution when using the Apple version of ld, due to usage of the -lto_library flag in a \"#cgo LDFLAGS\" directive.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-08T16:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-5h2f-vwh5-pc3g/GHSA-5h2f-vwh5-pc3g.json b/advisories/unreviewed/2024/05/GHSA-5h2f-vwh5-pc3g/GHSA-5h2f-vwh5-pc3g.json index e5c3c46c633..f529ac86187 100644 --- a/advisories/unreviewed/2024/05/GHSA-5h2f-vwh5-pc3g/GHSA-5h2f-vwh5-pc3g.json +++ b/advisories/unreviewed/2024/05/GHSA-5h2f-vwh5-pc3g/GHSA-5h2f-vwh5-pc3g.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-502" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-5j82-6875-gc5h/GHSA-5j82-6875-gc5h.json b/advisories/unreviewed/2024/05/GHSA-5j82-6875-gc5h/GHSA-5j82-6875-gc5h.json index 3c8356fdac5..2e83b6bd9f4 100644 --- a/advisories/unreviewed/2024/05/GHSA-5j82-6875-gc5h/GHSA-5j82-6875-gc5h.json +++ b/advisories/unreviewed/2024/05/GHSA-5j82-6875-gc5h/GHSA-5j82-6875-gc5h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5j82-6875-gc5h", - "modified": "2024-05-08T18:30:49Z", + "modified": "2024-07-03T18:40:01Z", "published": "2024-05-08T18:30:49Z", "aliases": [ "CVE-2024-25532" ], "details": "RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the bt_id parameter at /include/get_dict.aspx.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-08T17:15:07Z" diff --git a/advisories/unreviewed/2024/05/GHSA-5jpw-vjgv-8mfx/GHSA-5jpw-vjgv-8mfx.json b/advisories/unreviewed/2024/05/GHSA-5jpw-vjgv-8mfx/GHSA-5jpw-vjgv-8mfx.json index 78d9593ccb2..8bcd0008951 100644 --- a/advisories/unreviewed/2024/05/GHSA-5jpw-vjgv-8mfx/GHSA-5jpw-vjgv-8mfx.json +++ b/advisories/unreviewed/2024/05/GHSA-5jpw-vjgv-8mfx/GHSA-5jpw-vjgv-8mfx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5jpw-vjgv-8mfx", - "modified": "2024-05-08T18:30:49Z", + "modified": "2024-07-03T18:39:57Z", "published": "2024-05-08T18:30:49Z", "aliases": [ "CVE-2024-31961" ], "details": "A SQL injection vulnerability in unit.php in Sonic Shopfloor.guide before 3.1.3 allows remote attackers to execute arbitrary SQL commands via the level2 parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-08T16:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-5pwc-cvx7-34mp/GHSA-5pwc-cvx7-34mp.json b/advisories/unreviewed/2024/05/GHSA-5pwc-cvx7-34mp/GHSA-5pwc-cvx7-34mp.json index 42a93548f90..417e977f167 100644 --- a/advisories/unreviewed/2024/05/GHSA-5pwc-cvx7-34mp/GHSA-5pwc-cvx7-34mp.json +++ b/advisories/unreviewed/2024/05/GHSA-5pwc-cvx7-34mp/GHSA-5pwc-cvx7-34mp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5pwc-cvx7-34mp", - "modified": "2024-05-14T15:32:54Z", + "modified": "2024-07-03T18:40:26Z", "published": "2024-05-14T15:32:54Z", "aliases": [ "CVE-2024-29162" ], "details": "HDF5 through 1.13.3 and/or 1.14.2 contains a stack buffer overflow in H5HG_read, resulting in denial of service or potential code execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:15:32Z" diff --git a/advisories/unreviewed/2024/05/GHSA-5q3j-866r-jjww/GHSA-5q3j-866r-jjww.json b/advisories/unreviewed/2024/05/GHSA-5q3j-866r-jjww/GHSA-5q3j-866r-jjww.json index 8677464caa4..522e0a2f1bc 100644 --- a/advisories/unreviewed/2024/05/GHSA-5q3j-866r-jjww/GHSA-5q3j-866r-jjww.json +++ b/advisories/unreviewed/2024/05/GHSA-5q3j-866r-jjww/GHSA-5q3j-866r-jjww.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5q3j-866r-jjww", - "modified": "2024-05-02T18:30:51Z", + "modified": "2024-07-03T18:38:42Z", "published": "2024-05-02T18:30:51Z", "aliases": [ "CVE-2024-31966" ], "details": "A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones, including 6970 Conference Unit, through 6.3 SP3 HF4 allows an authenticated attacker with administrative privilege to conduct an argument injection attack due to insufficient parameter sanitization. A successful exploit could allow an attacker to access sensitive information, modify the system configuration, or execute arbitrary commands.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-88" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-02T16:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-5q6f-3g3m-rjw9/GHSA-5q6f-3g3m-rjw9.json b/advisories/unreviewed/2024/05/GHSA-5q6f-3g3m-rjw9/GHSA-5q6f-3g3m-rjw9.json index 54097b0721e..eb4711257ca 100644 --- a/advisories/unreviewed/2024/05/GHSA-5q6f-3g3m-rjw9/GHSA-5q6f-3g3m-rjw9.json +++ b/advisories/unreviewed/2024/05/GHSA-5q6f-3g3m-rjw9/GHSA-5q6f-3g3m-rjw9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5q6f-3g3m-rjw9", - "modified": "2024-05-05T00:30:30Z", + "modified": "2024-07-03T18:38:55Z", "published": "2024-05-05T00:30:30Z", "aliases": [ "CVE-2024-34475" ], "details": "Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: gmm_state_authentication in amf/gmm-sm.c for != OGS_ERROR.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-617" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-05T00:15:07Z" diff --git a/advisories/unreviewed/2024/05/GHSA-5rmw-4x72-xqxv/GHSA-5rmw-4x72-xqxv.json b/advisories/unreviewed/2024/05/GHSA-5rmw-4x72-xqxv/GHSA-5rmw-4x72-xqxv.json index 268b508e8ee..69531b3c02c 100644 --- a/advisories/unreviewed/2024/05/GHSA-5rmw-4x72-xqxv/GHSA-5rmw-4x72-xqxv.json +++ b/advisories/unreviewed/2024/05/GHSA-5rmw-4x72-xqxv/GHSA-5rmw-4x72-xqxv.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-5vjq-2rf8-q4wj/GHSA-5vjq-2rf8-q4wj.json b/advisories/unreviewed/2024/05/GHSA-5vjq-2rf8-q4wj/GHSA-5vjq-2rf8-q4wj.json index 6dcc9545815..3d93dea511d 100644 --- a/advisories/unreviewed/2024/05/GHSA-5vjq-2rf8-q4wj/GHSA-5vjq-2rf8-q4wj.json +++ b/advisories/unreviewed/2024/05/GHSA-5vjq-2rf8-q4wj/GHSA-5vjq-2rf8-q4wj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5vjq-2rf8-q4wj", - "modified": "2024-05-03T18:30:37Z", + "modified": "2024-07-03T18:38:50Z", "published": "2024-05-03T18:30:37Z", "aliases": [ "CVE-2024-33793" ], "details": "A cross-site scripting (XSS) vulnerability in netis-systems MEX605 v2.00.06 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the ping test page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-03T17:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-5wvm-hc4p-r45f/GHSA-5wvm-hc4p-r45f.json b/advisories/unreviewed/2024/05/GHSA-5wvm-hc4p-r45f/GHSA-5wvm-hc4p-r45f.json index f6c033fa42d..80894919579 100644 --- a/advisories/unreviewed/2024/05/GHSA-5wvm-hc4p-r45f/GHSA-5wvm-hc4p-r45f.json +++ b/advisories/unreviewed/2024/05/GHSA-5wvm-hc4p-r45f/GHSA-5wvm-hc4p-r45f.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-538" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-5x44-874c-9rmj/GHSA-5x44-874c-9rmj.json b/advisories/unreviewed/2024/05/GHSA-5x44-874c-9rmj/GHSA-5x44-874c-9rmj.json index e86a1c7dbe9..7a0e29702aa 100644 --- a/advisories/unreviewed/2024/05/GHSA-5x44-874c-9rmj/GHSA-5x44-874c-9rmj.json +++ b/advisories/unreviewed/2024/05/GHSA-5x44-874c-9rmj/GHSA-5x44-874c-9rmj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5x44-874c-9rmj", - "modified": "2024-05-06T15:30:39Z", + "modified": "2024-07-03T18:39:08Z", "published": "2024-05-06T15:30:39Z", "aliases": [ "CVE-2024-33110" ], "details": "D-Link DIR-845L router v1.01KRb03 and before is vulnerable to Permission Bypass via the getcfg.php component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-287" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-06T15:15:23Z" diff --git a/advisories/unreviewed/2024/05/GHSA-6577-mq92-mvr2/GHSA-6577-mq92-mvr2.json b/advisories/unreviewed/2024/05/GHSA-6577-mq92-mvr2/GHSA-6577-mq92-mvr2.json index f4f4b28c46d..9946b233ce4 100644 --- a/advisories/unreviewed/2024/05/GHSA-6577-mq92-mvr2/GHSA-6577-mq92-mvr2.json +++ b/advisories/unreviewed/2024/05/GHSA-6577-mq92-mvr2/GHSA-6577-mq92-mvr2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6577-mq92-mvr2", - "modified": "2024-05-07T18:30:34Z", + "modified": "2024-07-03T18:39:36Z", "published": "2024-05-07T18:30:34Z", "aliases": [ "CVE-2024-33164" ], "details": "J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the authUserList() function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T17:15:09Z" diff --git a/advisories/unreviewed/2024/05/GHSA-682x-vcqv-v7v6/GHSA-682x-vcqv-v7v6.json b/advisories/unreviewed/2024/05/GHSA-682x-vcqv-v7v6/GHSA-682x-vcqv-v7v6.json index 1ab09bd2215..f078dec973a 100644 --- a/advisories/unreviewed/2024/05/GHSA-682x-vcqv-v7v6/GHSA-682x-vcqv-v7v6.json +++ b/advisories/unreviewed/2024/05/GHSA-682x-vcqv-v7v6/GHSA-682x-vcqv-v7v6.json @@ -44,7 +44,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-80" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-6gwg-w9p5-2c42/GHSA-6gwg-w9p5-2c42.json b/advisories/unreviewed/2024/05/GHSA-6gwg-w9p5-2c42/GHSA-6gwg-w9p5-2c42.json index 3ad1aa1d1ab..640004fdbca 100644 --- a/advisories/unreviewed/2024/05/GHSA-6gwg-w9p5-2c42/GHSA-6gwg-w9p5-2c42.json +++ b/advisories/unreviewed/2024/05/GHSA-6gwg-w9p5-2c42/GHSA-6gwg-w9p5-2c42.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6gwg-w9p5-2c42", - "modified": "2024-05-14T15:32:50Z", + "modified": "2024-07-03T18:40:08Z", "published": "2024-05-14T15:32:50Z", "aliases": [ "CVE-2023-42955" ], "details": "Claris International has successfully resolved an issue of potentially exposing password information to front-end websites when signed in to the Admin Console with an administrator role. This issue has been fixed in FileMaker Server 20.3.1 by eliminating the send of Admin Role passwords in the Node.js socket.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-257" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T13:46:21Z" diff --git a/advisories/unreviewed/2024/05/GHSA-6h69-r77q-c662/GHSA-6h69-r77q-c662.json b/advisories/unreviewed/2024/05/GHSA-6h69-r77q-c662/GHSA-6h69-r77q-c662.json index 216c8722056..a907ac78385 100644 --- a/advisories/unreviewed/2024/05/GHSA-6h69-r77q-c662/GHSA-6h69-r77q-c662.json +++ b/advisories/unreviewed/2024/05/GHSA-6h69-r77q-c662/GHSA-6h69-r77q-c662.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6h69-r77q-c662", - "modified": "2024-05-06T21:30:38Z", + "modified": "2024-07-03T18:39:18Z", "published": "2024-05-06T21:30:38Z", "aliases": [ "CVE-2024-34532" ], "details": "A SQL injection vulnerability in Yvan Dotet PostgreSQL Query Deluxe module (aka query_deluxe) 17.x before 17.0.0.4 allows a remote attacker to gain privileges via the query parameter to models/querydeluxe.py:QueryDeluxe::get_result_from_query.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-06T21:15:48Z" diff --git a/advisories/unreviewed/2024/05/GHSA-6hcr-8cp5-58wj/GHSA-6hcr-8cp5-58wj.json b/advisories/unreviewed/2024/05/GHSA-6hcr-8cp5-58wj/GHSA-6hcr-8cp5-58wj.json index 039a6d1fe5e..31fe7e840c7 100644 --- a/advisories/unreviewed/2024/05/GHSA-6hcr-8cp5-58wj/GHSA-6hcr-8cp5-58wj.json +++ b/advisories/unreviewed/2024/05/GHSA-6hcr-8cp5-58wj/GHSA-6hcr-8cp5-58wj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6hcr-8cp5-58wj", - "modified": "2024-05-06T18:30:36Z", + "modified": "2024-07-03T18:39:14Z", "published": "2024-05-06T18:30:36Z", "aliases": [ "CVE-2024-33407" ], "details": "SQL injection vulnerability in /model/delete_record.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the id parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-06T18:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-6jj6-4cwr-qpr2/GHSA-6jj6-4cwr-qpr2.json b/advisories/unreviewed/2024/05/GHSA-6jj6-4cwr-qpr2/GHSA-6jj6-4cwr-qpr2.json index 5dd29bcd1a0..8f613db2011 100644 --- a/advisories/unreviewed/2024/05/GHSA-6jj6-4cwr-qpr2/GHSA-6jj6-4cwr-qpr2.json +++ b/advisories/unreviewed/2024/05/GHSA-6jj6-4cwr-qpr2/GHSA-6jj6-4cwr-qpr2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6jj6-4cwr-qpr2", - "modified": "2024-05-07T18:30:33Z", + "modified": "2024-07-03T18:39:34Z", "published": "2024-05-07T18:30:33Z", "aliases": [ "CVE-2024-29150" ], "details": "An issue was discovered in Alcatel-Lucent ALE NOE deskphones through 86x8_NOE-R300.1.40.12.4180 and SIP deskphones through 86x8_SIP-R200.1.01.10.728. Because of improper privilege management, an authenticated attacker is able to create symlinks to sensitive and protected data in locations that are used for debugging files. Given that the process of gathering debug logs is carried out with root privileges, any file referenced in the symlink is consequently written to the debug archive, thereby granting accessibility to the attacker.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T17:15:07Z" diff --git a/advisories/unreviewed/2024/05/GHSA-6m2f-g987-jc22/GHSA-6m2f-g987-jc22.json b/advisories/unreviewed/2024/05/GHSA-6m2f-g987-jc22/GHSA-6m2f-g987-jc22.json index abe27222d30..4fb6362986b 100644 --- a/advisories/unreviewed/2024/05/GHSA-6m2f-g987-jc22/GHSA-6m2f-g987-jc22.json +++ b/advisories/unreviewed/2024/05/GHSA-6m2f-g987-jc22/GHSA-6m2f-g987-jc22.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6m2f-g987-jc22", - "modified": "2024-05-04T21:30:33Z", + "modified": "2024-07-03T18:38:52Z", "published": "2024-05-04T21:30:33Z", "aliases": [ "CVE-2024-34462" ], "details": "Alinto SOGo through 5.10.0 allows XSS during attachment preview.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-04T19:15:46Z" diff --git a/advisories/unreviewed/2024/05/GHSA-72vc-f76g-4qq4/GHSA-72vc-f76g-4qq4.json b/advisories/unreviewed/2024/05/GHSA-72vc-f76g-4qq4/GHSA-72vc-f76g-4qq4.json index 2104b89b5b4..8481851a896 100644 --- a/advisories/unreviewed/2024/05/GHSA-72vc-f76g-4qq4/GHSA-72vc-f76g-4qq4.json +++ b/advisories/unreviewed/2024/05/GHSA-72vc-f76g-4qq4/GHSA-72vc-f76g-4qq4.json @@ -25,7 +25,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-77q6-5h9c-2c36/GHSA-77q6-5h9c-2c36.json b/advisories/unreviewed/2024/05/GHSA-77q6-5h9c-2c36/GHSA-77q6-5h9c-2c36.json index 5ae984dfbcf..3c6e20fd114 100644 --- a/advisories/unreviewed/2024/05/GHSA-77q6-5h9c-2c36/GHSA-77q6-5h9c-2c36.json +++ b/advisories/unreviewed/2024/05/GHSA-77q6-5h9c-2c36/GHSA-77q6-5h9c-2c36.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-77q6-5h9c-2c36", - "modified": "2024-05-01T21:30:38Z", + "modified": "2024-07-03T18:38:26Z", "published": "2024-05-01T21:30:38Z", "aliases": [ "CVE-2024-33430" ], "details": "An issue in phiola/src/afilter/pcm_convert.h:513 of phiola v2.0-rc22 allows a remote attacker to execute arbitrary code via the a crafted .wav file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-482" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-01T19:15:27Z" diff --git a/advisories/unreviewed/2024/05/GHSA-79fj-qcrm-4368/GHSA-79fj-qcrm-4368.json b/advisories/unreviewed/2024/05/GHSA-79fj-qcrm-4368/GHSA-79fj-qcrm-4368.json index 4acb81e8be5..d7b1d9d6c69 100644 --- a/advisories/unreviewed/2024/05/GHSA-79fj-qcrm-4368/GHSA-79fj-qcrm-4368.json +++ b/advisories/unreviewed/2024/05/GHSA-79fj-qcrm-4368/GHSA-79fj-qcrm-4368.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-79fj-qcrm-4368", - "modified": "2024-05-03T15:30:54Z", + "modified": "2024-07-03T18:38:46Z", "published": "2024-05-03T15:30:54Z", "aliases": [ "CVE-2024-1395" ], "details": "Use After Free vulnerability in Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations. If the system’s memory is carefully prepared by the user, then this in turn could give them access to already freed memory.\nThis issue affects Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r47p0.\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-03T14:15:10Z" diff --git a/advisories/unreviewed/2024/05/GHSA-7c6h-5h65-pq5v/GHSA-7c6h-5h65-pq5v.json b/advisories/unreviewed/2024/05/GHSA-7c6h-5h65-pq5v/GHSA-7c6h-5h65-pq5v.json index bc0a69571dd..feddcd4ae9e 100644 --- a/advisories/unreviewed/2024/05/GHSA-7c6h-5h65-pq5v/GHSA-7c6h-5h65-pq5v.json +++ b/advisories/unreviewed/2024/05/GHSA-7c6h-5h65-pq5v/GHSA-7c6h-5h65-pq5v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7c6h-5h65-pq5v", - "modified": "2024-05-06T15:30:38Z", + "modified": "2024-07-03T18:39:02Z", "published": "2024-05-06T15:30:38Z", "aliases": [ "CVE-2024-33829" ], "details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/readDeal.php?mudi=updateWebCache.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-06T13:15:49Z" diff --git a/advisories/unreviewed/2024/05/GHSA-7fwm-5rwh-hfg5/GHSA-7fwm-5rwh-hfg5.json b/advisories/unreviewed/2024/05/GHSA-7fwm-5rwh-hfg5/GHSA-7fwm-5rwh-hfg5.json index 8ec0494feb8..be3dd818bd6 100644 --- a/advisories/unreviewed/2024/05/GHSA-7fwm-5rwh-hfg5/GHSA-7fwm-5rwh-hfg5.json +++ b/advisories/unreviewed/2024/05/GHSA-7fwm-5rwh-hfg5/GHSA-7fwm-5rwh-hfg5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7fwm-5rwh-hfg5", - "modified": "2024-06-10T18:30:57Z", + "modified": "2024-07-03T18:39:45Z", "published": "2024-05-07T21:31:45Z", "aliases": [ "CVE-2024-4559" ], "details": "Heap buffer overflow in WebAudio in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T19:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-7gx3-fr27-7gx9/GHSA-7gx3-fr27-7gx9.json b/advisories/unreviewed/2024/05/GHSA-7gx3-fr27-7gx9/GHSA-7gx3-fr27-7gx9.json index b7c38205200..44b5b34843b 100644 --- a/advisories/unreviewed/2024/05/GHSA-7gx3-fr27-7gx9/GHSA-7gx3-fr27-7gx9.json +++ b/advisories/unreviewed/2024/05/GHSA-7gx3-fr27-7gx9/GHSA-7gx3-fr27-7gx9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7gx3-fr27-7gx9", - "modified": "2024-05-01T21:30:38Z", + "modified": "2024-07-03T18:38:30Z", "published": "2024-05-01T21:30:38Z", "aliases": [ "CVE-2023-46295" ], "details": "An issue was discovered in Teledyne FLIR M300 2.00-19. Unauthenticated remote code execution can occur in the web server. An attacker can exploit this by sending a POST request to the vulnerable PHP page. An attacker can elevate to root permissions with Sudo.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-918" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-01T20:15:12Z" diff --git a/advisories/unreviewed/2024/05/GHSA-7h9q-j3hq-cpc4/GHSA-7h9q-j3hq-cpc4.json b/advisories/unreviewed/2024/05/GHSA-7h9q-j3hq-cpc4/GHSA-7h9q-j3hq-cpc4.json index 8d33cd344f3..65f3bfd3ec3 100644 --- a/advisories/unreviewed/2024/05/GHSA-7h9q-j3hq-cpc4/GHSA-7h9q-j3hq-cpc4.json +++ b/advisories/unreviewed/2024/05/GHSA-7h9q-j3hq-cpc4/GHSA-7h9q-j3hq-cpc4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7h9q-j3hq-cpc4", - "modified": "2024-05-08T15:30:42Z", + "modified": "2024-07-03T18:39:56Z", "published": "2024-05-08T15:30:42Z", "aliases": [ "CVE-2024-25521" ], "details": "RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the txt_keyword parameter at get_company.aspx.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-08T15:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-7jgq-6qw7-j88f/GHSA-7jgq-6qw7-j88f.json b/advisories/unreviewed/2024/05/GHSA-7jgq-6qw7-j88f/GHSA-7jgq-6qw7-j88f.json index 32182fe0225..f0cc7ac3678 100644 --- a/advisories/unreviewed/2024/05/GHSA-7jgq-6qw7-j88f/GHSA-7jgq-6qw7-j88f.json +++ b/advisories/unreviewed/2024/05/GHSA-7jgq-6qw7-j88f/GHSA-7jgq-6qw7-j88f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7jgq-6qw7-j88f", - "modified": "2024-05-14T18:30:44Z", + "modified": "2024-07-03T18:40:03Z", "published": "2024-05-14T18:30:44Z", "aliases": [ "CVE-2022-32503" ], "details": "An issue was discovered on certain Nuki Home Solutions devices. An attacker with physical access to this JTAG port may be able to connect to the device and bypass both hardware and software security protections. This affects Nuki Keypad before 1.9.2 and Nuki Fob before 1.8.1.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-288" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T10:43:41Z" diff --git a/advisories/unreviewed/2024/05/GHSA-7m4r-mvj2-xjpx/GHSA-7m4r-mvj2-xjpx.json b/advisories/unreviewed/2024/05/GHSA-7m4r-mvj2-xjpx/GHSA-7m4r-mvj2-xjpx.json index 67fc5c25af3..cc1aef9a14a 100644 --- a/advisories/unreviewed/2024/05/GHSA-7m4r-mvj2-xjpx/GHSA-7m4r-mvj2-xjpx.json +++ b/advisories/unreviewed/2024/05/GHSA-7m4r-mvj2-xjpx/GHSA-7m4r-mvj2-xjpx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7m4r-mvj2-xjpx", - "modified": "2024-05-03T18:30:38Z", + "modified": "2024-07-03T18:38:50Z", "published": "2024-05-03T18:30:38Z", "aliases": [ "CVE-2024-34453" ], "details": "TwoNav 2.1.13 contains an SSRF vulnerability via the url paramater to index.php?c=api&method=read_data&type=connectivity_test (which reaches /system/api.php).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-918" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-03T18:15:10Z" diff --git a/advisories/unreviewed/2024/05/GHSA-7pjp-mg36-54v4/GHSA-7pjp-mg36-54v4.json b/advisories/unreviewed/2024/05/GHSA-7pjp-mg36-54v4/GHSA-7pjp-mg36-54v4.json index 61c345474af..2878288f060 100644 --- a/advisories/unreviewed/2024/05/GHSA-7pjp-mg36-54v4/GHSA-7pjp-mg36-54v4.json +++ b/advisories/unreviewed/2024/05/GHSA-7pjp-mg36-54v4/GHSA-7pjp-mg36-54v4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7pjp-mg36-54v4", - "modified": "2024-05-06T15:30:35Z", + "modified": "2024-07-03T18:39:01Z", "published": "2024-05-06T15:30:35Z", "aliases": [ "CVE-2024-33788" ], "details": "Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the PinCode parameter at /API/info form endpoint.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-06T13:15:49Z" diff --git a/advisories/unreviewed/2024/05/GHSA-7rp2-vcrx-9h2r/GHSA-7rp2-vcrx-9h2r.json b/advisories/unreviewed/2024/05/GHSA-7rp2-vcrx-9h2r/GHSA-7rp2-vcrx-9h2r.json index 83b040dc508..3c465d57a73 100644 --- a/advisories/unreviewed/2024/05/GHSA-7rp2-vcrx-9h2r/GHSA-7rp2-vcrx-9h2r.json +++ b/advisories/unreviewed/2024/05/GHSA-7rp2-vcrx-9h2r/GHSA-7rp2-vcrx-9h2r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7rp2-vcrx-9h2r", - "modified": "2024-05-07T18:30:34Z", + "modified": "2024-07-03T18:39:36Z", "published": "2024-05-07T18:30:34Z", "aliases": [ "CVE-2024-33161" ], "details": "J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the unallocatedList() function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T17:15:09Z" diff --git a/advisories/unreviewed/2024/05/GHSA-7rp4-4g4h-9gwv/GHSA-7rp4-4g4h-9gwv.json b/advisories/unreviewed/2024/05/GHSA-7rp4-4g4h-9gwv/GHSA-7rp4-4g4h-9gwv.json index 982d77fd6b9..f5771757484 100644 --- a/advisories/unreviewed/2024/05/GHSA-7rp4-4g4h-9gwv/GHSA-7rp4-4g4h-9gwv.json +++ b/advisories/unreviewed/2024/05/GHSA-7rp4-4g4h-9gwv/GHSA-7rp4-4g4h-9gwv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7rp4-4g4h-9gwv", - "modified": "2024-05-07T21:31:45Z", + "modified": "2024-07-03T18:39:41Z", "published": "2024-05-07T21:31:45Z", "aliases": [ "CVE-2024-25510" ], "details": "RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /AddressBook/address_public_show.aspx.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T19:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-7vvx-296g-vp4g/GHSA-7vvx-296g-vp4g.json b/advisories/unreviewed/2024/05/GHSA-7vvx-296g-vp4g/GHSA-7vvx-296g-vp4g.json index b44a3dceeb0..01d9717de3c 100644 --- a/advisories/unreviewed/2024/05/GHSA-7vvx-296g-vp4g/GHSA-7vvx-296g-vp4g.json +++ b/advisories/unreviewed/2024/05/GHSA-7vvx-296g-vp4g/GHSA-7vvx-296g-vp4g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7vvx-296g-vp4g", - "modified": "2024-05-06T00:30:49Z", + "modified": "2024-07-03T18:38:57Z", "published": "2024-05-06T00:30:49Z", "aliases": [ "CVE-2024-34519" ], "details": "Avantra Server 24.x before 24.0.7 and 24.1.x before 24.1.1 mishandles the security of dashboards, aka XAN-5367. If a user can create a dashboard with an auto-login user, data disclosure may occur. Access control can be bypassed when there is a shared dashboard, and its auto-login user has privileges that a dashboard visitor should not have.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-289" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-05T22:15:07Z" diff --git a/advisories/unreviewed/2024/05/GHSA-7wfw-7p9h-4j2c/GHSA-7wfw-7p9h-4j2c.json b/advisories/unreviewed/2024/05/GHSA-7wfw-7p9h-4j2c/GHSA-7wfw-7p9h-4j2c.json index 6ae2b8904a8..8f303568932 100644 --- a/advisories/unreviewed/2024/05/GHSA-7wfw-7p9h-4j2c/GHSA-7wfw-7p9h-4j2c.json +++ b/advisories/unreviewed/2024/05/GHSA-7wfw-7p9h-4j2c/GHSA-7wfw-7p9h-4j2c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7wfw-7p9h-4j2c", - "modified": "2024-05-06T18:30:35Z", + "modified": "2024-07-03T18:39:12Z", "published": "2024-05-06T18:30:35Z", "aliases": [ "CVE-2024-34250" ], "details": "A heap buffer overflow vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cause at least a denial of service via the \"wasm_loader_check_br\" function in core/iwasm/interpreter/wasm_loader.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-06T16:15:14Z" diff --git a/advisories/unreviewed/2024/05/GHSA-8422-7263-3xg6/GHSA-8422-7263-3xg6.json b/advisories/unreviewed/2024/05/GHSA-8422-7263-3xg6/GHSA-8422-7263-3xg6.json index b1b54276188..7a38443f793 100644 --- a/advisories/unreviewed/2024/05/GHSA-8422-7263-3xg6/GHSA-8422-7263-3xg6.json +++ b/advisories/unreviewed/2024/05/GHSA-8422-7263-3xg6/GHSA-8422-7263-3xg6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8422-7263-3xg6", - "modified": "2024-05-06T03:30:47Z", + "modified": "2024-07-03T18:38:58Z", "published": "2024-05-06T03:30:47Z", "aliases": [ "CVE-2024-20021" ], "details": "In atf spm, there is a possible way to remap physical memory to virtual memory due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08584568; Issue ID: MSV-1249.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-269" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-06T03:15:09Z" diff --git a/advisories/unreviewed/2024/05/GHSA-87hc-xjjc-rvw9/GHSA-87hc-xjjc-rvw9.json b/advisories/unreviewed/2024/05/GHSA-87hc-xjjc-rvw9/GHSA-87hc-xjjc-rvw9.json index 3fa2e4cf7cb..ec49b2e1e78 100644 --- a/advisories/unreviewed/2024/05/GHSA-87hc-xjjc-rvw9/GHSA-87hc-xjjc-rvw9.json +++ b/advisories/unreviewed/2024/05/GHSA-87hc-xjjc-rvw9/GHSA-87hc-xjjc-rvw9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-87hc-xjjc-rvw9", - "modified": "2024-05-02T18:30:50Z", + "modified": "2024-07-03T18:38:40Z", "published": "2024-05-02T18:30:50Z", "aliases": [ "CVE-2024-31963" ], "details": "A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones, including 6970 Conference Unit, through 6.3 SP3 HF4 allows an authenticated attacker to conduct a buffer overflow attack due to insufficient bounds checking and input sanitization. A successful exploit could allow an attacker to cause a denial of service.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-02T16:15:07Z" diff --git a/advisories/unreviewed/2024/05/GHSA-8g74-32fg-5ghc/GHSA-8g74-32fg-5ghc.json b/advisories/unreviewed/2024/05/GHSA-8g74-32fg-5ghc/GHSA-8g74-32fg-5ghc.json index d715cdec4db..36dd4e338a7 100644 --- a/advisories/unreviewed/2024/05/GHSA-8g74-32fg-5ghc/GHSA-8g74-32fg-5ghc.json +++ b/advisories/unreviewed/2024/05/GHSA-8g74-32fg-5ghc/GHSA-8g74-32fg-5ghc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8g74-32fg-5ghc", - "modified": "2024-05-02T15:30:32Z", + "modified": "2024-07-03T18:38:35Z", "published": "2024-05-02T12:30:40Z", "aliases": [ "CVE-2024-32638" ], "details": "Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Apache APISIX when using `forward-auth` plugin.This issue affects Apache APISIX: from 3.8.0, 3.9.0.\n\nUsers are recommended to upgrade to version 3.8.1, 3.9.1 or higher, which fixes the issue.\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-444" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-02T10:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-8jf6-v4rh-2g3w/GHSA-8jf6-v4rh-2g3w.json b/advisories/unreviewed/2024/05/GHSA-8jf6-v4rh-2g3w/GHSA-8jf6-v4rh-2g3w.json index 6dae89621ce..83c9301cc1f 100644 --- a/advisories/unreviewed/2024/05/GHSA-8jf6-v4rh-2g3w/GHSA-8jf6-v4rh-2g3w.json +++ b/advisories/unreviewed/2024/05/GHSA-8jf6-v4rh-2g3w/GHSA-8jf6-v4rh-2g3w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8jf6-v4rh-2g3w", - "modified": "2024-05-07T15:30:38Z", + "modified": "2024-07-03T18:39:21Z", "published": "2024-05-07T15:30:38Z", "aliases": [ "CVE-2024-33783" ], "details": "MP-SPDZ v0.3.8 was discovered to contain a segmentation violation via the function osuCrypto::SilentMultiPprfReceiver::expand in /Tools/SilentPprf.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted message.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T14:15:10Z" diff --git a/advisories/unreviewed/2024/05/GHSA-8q98-72mq-w92m/GHSA-8q98-72mq-w92m.json b/advisories/unreviewed/2024/05/GHSA-8q98-72mq-w92m/GHSA-8q98-72mq-w92m.json index 6cd69065475..6fba0bdbb6f 100644 --- a/advisories/unreviewed/2024/05/GHSA-8q98-72mq-w92m/GHSA-8q98-72mq-w92m.json +++ b/advisories/unreviewed/2024/05/GHSA-8q98-72mq-w92m/GHSA-8q98-72mq-w92m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8q98-72mq-w92m", - "modified": "2024-05-06T06:30:45Z", + "modified": "2024-07-03T18:39:00Z", "published": "2024-05-06T06:30:45Z", "aliases": [ "CVE-2024-3756" ], "details": "The MF Gig Calendar WordPress plugin through 1.2.1 does not have CSRF checks in some places, which could allow attackers to make logged in Contributors and above delete arbitrary events via a CSRF attack", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-06T06:15:07Z" diff --git a/advisories/unreviewed/2024/05/GHSA-8w79-35vx-63xh/GHSA-8w79-35vx-63xh.json b/advisories/unreviewed/2024/05/GHSA-8w79-35vx-63xh/GHSA-8w79-35vx-63xh.json index 25a9465bd2a..cc9b046dc6e 100644 --- a/advisories/unreviewed/2024/05/GHSA-8w79-35vx-63xh/GHSA-8w79-35vx-63xh.json +++ b/advisories/unreviewed/2024/05/GHSA-8w79-35vx-63xh/GHSA-8w79-35vx-63xh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8w79-35vx-63xh", - "modified": "2024-05-08T18:30:49Z", + "modified": "2024-07-03T18:40:02Z", "published": "2024-05-08T18:30:49Z", "aliases": [ "CVE-2024-25533" ], "details": "Error messages in RuvarOA v6.01 and v12.01 were discovered to leak the physical path of the website (/WorkFlow/OfficeFileUpdate.aspx). This vulnerability can allow attackers to write files to the server or execute arbitrary commands via crafted SQL statements.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-08T17:15:07Z" diff --git a/advisories/unreviewed/2024/05/GHSA-96fg-696f-w9g3/GHSA-96fg-696f-w9g3.json b/advisories/unreviewed/2024/05/GHSA-96fg-696f-w9g3/GHSA-96fg-696f-w9g3.json index f25a832459c..f84e84df6ad 100644 --- a/advisories/unreviewed/2024/05/GHSA-96fg-696f-w9g3/GHSA-96fg-696f-w9g3.json +++ b/advisories/unreviewed/2024/05/GHSA-96fg-696f-w9g3/GHSA-96fg-696f-w9g3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-96fg-696f-w9g3", - "modified": "2024-05-08T15:30:42Z", + "modified": "2024-07-03T18:39:56Z", "published": "2024-05-08T15:30:42Z", "aliases": [ "CVE-2024-25520" ], "details": "RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /SysManage/sys_blogtemplate_new.aspx.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-08T15:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-96wf-rc2w-4922/GHSA-96wf-rc2w-4922.json b/advisories/unreviewed/2024/05/GHSA-96wf-rc2w-4922/GHSA-96wf-rc2w-4922.json index 5e928299d30..844224de4ae 100644 --- a/advisories/unreviewed/2024/05/GHSA-96wf-rc2w-4922/GHSA-96wf-rc2w-4922.json +++ b/advisories/unreviewed/2024/05/GHSA-96wf-rc2w-4922/GHSA-96wf-rc2w-4922.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-96wf-rc2w-4922", - "modified": "2024-05-06T15:30:40Z", + "modified": "2024-07-03T18:39:09Z", "published": "2024-05-06T15:30:40Z", "aliases": [ "CVE-2024-34472" ], "details": "An issue was discovered in HSC Mailinspector 5.2.17-3 through v.5.2.18. An authenticated blind SQL injection vulnerability exists in the mliRealtimeEmails.php file. The ordemGrid parameter in a POST request to /mailinspector/mliRealtimeEmails.php does not properly sanitize input, allowing an authenticated attacker to execute arbitrary SQL commands, leading to the potential disclosure of the entire application database.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-06T15:15:24Z" diff --git a/advisories/unreviewed/2024/05/GHSA-972x-xwpx-cr2c/GHSA-972x-xwpx-cr2c.json b/advisories/unreviewed/2024/05/GHSA-972x-xwpx-cr2c/GHSA-972x-xwpx-cr2c.json index 29540c2ee37..1ff64d5c7c0 100644 --- a/advisories/unreviewed/2024/05/GHSA-972x-xwpx-cr2c/GHSA-972x-xwpx-cr2c.json +++ b/advisories/unreviewed/2024/05/GHSA-972x-xwpx-cr2c/GHSA-972x-xwpx-cr2c.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-521" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-9cw5-fjxh-j5fv/GHSA-9cw5-fjxh-j5fv.json b/advisories/unreviewed/2024/05/GHSA-9cw5-fjxh-j5fv/GHSA-9cw5-fjxh-j5fv.json index bd8f5457558..9f00d017548 100644 --- a/advisories/unreviewed/2024/05/GHSA-9cw5-fjxh-j5fv/GHSA-9cw5-fjxh-j5fv.json +++ b/advisories/unreviewed/2024/05/GHSA-9cw5-fjxh-j5fv/GHSA-9cw5-fjxh-j5fv.json @@ -25,7 +25,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-9f8j-537f-m943/GHSA-9f8j-537f-m943.json b/advisories/unreviewed/2024/05/GHSA-9f8j-537f-m943/GHSA-9f8j-537f-m943.json index bf1eeb33767..23e1281feca 100644 --- a/advisories/unreviewed/2024/05/GHSA-9f8j-537f-m943/GHSA-9f8j-537f-m943.json +++ b/advisories/unreviewed/2024/05/GHSA-9f8j-537f-m943/GHSA-9f8j-537f-m943.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9f8j-537f-m943", - "modified": "2024-05-07T18:30:34Z", + "modified": "2024-07-03T18:39:35Z", "published": "2024-05-07T18:30:34Z", "aliases": [ "CVE-2024-33153" ], "details": "J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the commentList() function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T17:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-9fp6-rmrc-c2jw/GHSA-9fp6-rmrc-c2jw.json b/advisories/unreviewed/2024/05/GHSA-9fp6-rmrc-c2jw/GHSA-9fp6-rmrc-c2jw.json index a4bdc7a5bb6..5d1a0e3a8b6 100644 --- a/advisories/unreviewed/2024/05/GHSA-9fp6-rmrc-c2jw/GHSA-9fp6-rmrc-c2jw.json +++ b/advisories/unreviewed/2024/05/GHSA-9fp6-rmrc-c2jw/GHSA-9fp6-rmrc-c2jw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9fp6-rmrc-c2jw", - "modified": "2024-05-01T21:30:37Z", + "modified": "2024-07-03T18:38:24Z", "published": "2024-05-01T21:30:37Z", "aliases": [ "CVE-2024-24313" ], "details": "An issue in Vaales Technologies V_QRS v.2024-01-17 allows a remote attacker to obtain sensitive information via the Models/FormModel.php and QRModel.php component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-01T19:15:22Z" diff --git a/advisories/unreviewed/2024/05/GHSA-9frm-76c2-fq2w/GHSA-9frm-76c2-fq2w.json b/advisories/unreviewed/2024/05/GHSA-9frm-76c2-fq2w/GHSA-9frm-76c2-fq2w.json index ff5a564c044..58a7db2b0b2 100644 --- a/advisories/unreviewed/2024/05/GHSA-9frm-76c2-fq2w/GHSA-9frm-76c2-fq2w.json +++ b/advisories/unreviewed/2024/05/GHSA-9frm-76c2-fq2w/GHSA-9frm-76c2-fq2w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9frm-76c2-fq2w", - "modified": "2024-06-10T18:30:59Z", + "modified": "2024-07-03T18:40:11Z", "published": "2024-05-14T15:32:53Z", "aliases": [ "CVE-2024-27822" ], "details": "A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sonoma 14.5. An app may be able to gain root privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-277" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:13:05Z" diff --git a/advisories/unreviewed/2024/05/GHSA-9g7g-rfw9-5xff/GHSA-9g7g-rfw9-5xff.json b/advisories/unreviewed/2024/05/GHSA-9g7g-rfw9-5xff/GHSA-9g7g-rfw9-5xff.json index aff7ab9dbcf..144002ac5d7 100644 --- a/advisories/unreviewed/2024/05/GHSA-9g7g-rfw9-5xff/GHSA-9g7g-rfw9-5xff.json +++ b/advisories/unreviewed/2024/05/GHSA-9g7g-rfw9-5xff/GHSA-9g7g-rfw9-5xff.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9g7g-rfw9-5xff", - "modified": "2024-05-07T15:30:37Z", + "modified": "2024-07-03T18:39:19Z", "published": "2024-05-07T15:30:37Z", "aliases": [ "CVE-2024-33781" ], "details": "MP-SPDZ v0.3.8 was discovered to contain a stack overflow via the function octetStream::get_bytes in /Tools/octetStream.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted message.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T14:15:10Z" diff --git a/advisories/unreviewed/2024/05/GHSA-9g7x-rcc4-g9h9/GHSA-9g7x-rcc4-g9h9.json b/advisories/unreviewed/2024/05/GHSA-9g7x-rcc4-g9h9/GHSA-9g7x-rcc4-g9h9.json index fa7ae7ccec2..9293c5cfffe 100644 --- a/advisories/unreviewed/2024/05/GHSA-9g7x-rcc4-g9h9/GHSA-9g7x-rcc4-g9h9.json +++ b/advisories/unreviewed/2024/05/GHSA-9g7x-rcc4-g9h9/GHSA-9g7x-rcc4-g9h9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9g7x-rcc4-g9h9", - "modified": "2024-05-06T18:30:36Z", + "modified": "2024-07-03T18:39:15Z", "published": "2024-05-06T18:30:36Z", "aliases": [ "CVE-2024-33411" ], "details": "A SQL injection vulnerability in /model/get_admin_profile.php in Campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the my_index parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -21,13 +24,17 @@ { "type": "WEB", "url": "https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2010.pdf" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%208.pdf" } ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-06T18:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-9rqf-45x9-xp9f/GHSA-9rqf-45x9-xp9f.json b/advisories/unreviewed/2024/05/GHSA-9rqf-45x9-xp9f/GHSA-9rqf-45x9-xp9f.json index fcfe23aba41..7124869654e 100644 --- a/advisories/unreviewed/2024/05/GHSA-9rqf-45x9-xp9f/GHSA-9rqf-45x9-xp9f.json +++ b/advisories/unreviewed/2024/05/GHSA-9rqf-45x9-xp9f/GHSA-9rqf-45x9-xp9f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9rqf-45x9-xp9f", - "modified": "2024-05-14T15:32:54Z", + "modified": "2024-07-03T18:40:23Z", "published": "2024-05-14T15:32:54Z", "aliases": [ "CVE-2024-29160" ], "details": "HDF5 through 1.14.3 contains a heap buffer overflow in H5HG__cache_heap_deserialize, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:15:32Z" diff --git a/advisories/unreviewed/2024/05/GHSA-9w3g-mqc5-c9p4/GHSA-9w3g-mqc5-c9p4.json b/advisories/unreviewed/2024/05/GHSA-9w3g-mqc5-c9p4/GHSA-9w3g-mqc5-c9p4.json index f0c3d0d0370..acefd3f83f0 100644 --- a/advisories/unreviewed/2024/05/GHSA-9w3g-mqc5-c9p4/GHSA-9w3g-mqc5-c9p4.json +++ b/advisories/unreviewed/2024/05/GHSA-9w3g-mqc5-c9p4/GHSA-9w3g-mqc5-c9p4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9w3g-mqc5-c9p4", - "modified": "2024-05-06T15:30:38Z", + "modified": "2024-07-03T18:39:02Z", "published": "2024-05-06T15:30:38Z", "aliases": [ "CVE-2024-33752" ], "details": "An arbitrary file upload vulnerability exists in emlog pro 2.3.0 and pro 2.3.2 at admin/views/plugin.php that could be exploited by a remote attacker to submit a special request to upload a malicious file to execute arbitrary code.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-06T14:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-9w5v-j38r-rr4m/GHSA-9w5v-j38r-rr4m.json b/advisories/unreviewed/2024/05/GHSA-9w5v-j38r-rr4m/GHSA-9w5v-j38r-rr4m.json index fb528e89a7f..39a910b6e56 100644 --- a/advisories/unreviewed/2024/05/GHSA-9w5v-j38r-rr4m/GHSA-9w5v-j38r-rr4m.json +++ b/advisories/unreviewed/2024/05/GHSA-9w5v-j38r-rr4m/GHSA-9w5v-j38r-rr4m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9w5v-j38r-rr4m", - "modified": "2024-05-01T21:30:37Z", + "modified": "2024-07-03T18:38:25Z", "published": "2024-05-01T21:30:37Z", "aliases": [ "CVE-2024-33300" ], "details": "Typora v1.0.0 through v1.7 version (below) Markdown editor has a cross-site scripting (XSS) vulnerability, which allows attackers to execute arbitrary code by uploading Markdown files.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-01T19:15:26Z" diff --git a/advisories/unreviewed/2024/05/GHSA-c37g-646h-qgp8/GHSA-c37g-646h-qgp8.json b/advisories/unreviewed/2024/05/GHSA-c37g-646h-qgp8/GHSA-c37g-646h-qgp8.json index d865abe335c..d71f81c606a 100644 --- a/advisories/unreviewed/2024/05/GHSA-c37g-646h-qgp8/GHSA-c37g-646h-qgp8.json +++ b/advisories/unreviewed/2024/05/GHSA-c37g-646h-qgp8/GHSA-c37g-646h-qgp8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c37g-646h-qgp8", - "modified": "2024-05-06T15:30:38Z", + "modified": "2024-07-03T18:39:02Z", "published": "2024-05-06T15:30:38Z", "aliases": [ "CVE-2024-33830" ], "details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/readDeal.php?mudi=clearWebCache.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-06T13:15:49Z" diff --git a/advisories/unreviewed/2024/05/GHSA-c3jw-865v-8wx2/GHSA-c3jw-865v-8wx2.json b/advisories/unreviewed/2024/05/GHSA-c3jw-865v-8wx2/GHSA-c3jw-865v-8wx2.json index c8b04b29aea..691cc7646a0 100644 --- a/advisories/unreviewed/2024/05/GHSA-c3jw-865v-8wx2/GHSA-c3jw-865v-8wx2.json +++ b/advisories/unreviewed/2024/05/GHSA-c3jw-865v-8wx2/GHSA-c3jw-865v-8wx2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c3jw-865v-8wx2", - "modified": "2024-05-02T18:30:51Z", + "modified": "2024-07-03T18:38:42Z", "published": "2024-05-02T18:30:51Z", "aliases": [ "CVE-2024-31967" ], "details": "A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones, including 6970 Conference Unit, through 6.3 SP3 HF4 allows an unauthenticated attacker to conduct an unauthorized access attack due to improper access control. A successful exploit could allow an attacker to gain unauthorized access to user information or the system configuration.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-02T16:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-c49x-w662-272g/GHSA-c49x-w662-272g.json b/advisories/unreviewed/2024/05/GHSA-c49x-w662-272g/GHSA-c49x-w662-272g.json index 7b73b57b750..ebead6cf25d 100644 --- a/advisories/unreviewed/2024/05/GHSA-c49x-w662-272g/GHSA-c49x-w662-272g.json +++ b/advisories/unreviewed/2024/05/GHSA-c49x-w662-272g/GHSA-c49x-w662-272g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c49x-w662-272g", - "modified": "2024-05-07T21:31:45Z", + "modified": "2024-07-03T18:39:41Z", "published": "2024-05-07T21:31:45Z", "aliases": [ "CVE-2024-25514" ], "details": "RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the template_id parameter at /SysManage/wf_template_child_field_list.aspx.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T19:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-c6h3-4727-9w7w/GHSA-c6h3-4727-9w7w.json b/advisories/unreviewed/2024/05/GHSA-c6h3-4727-9w7w/GHSA-c6h3-4727-9w7w.json index c4a8a0f5d26..b188d8134bb 100644 --- a/advisories/unreviewed/2024/05/GHSA-c6h3-4727-9w7w/GHSA-c6h3-4727-9w7w.json +++ b/advisories/unreviewed/2024/05/GHSA-c6h3-4727-9w7w/GHSA-c6h3-4727-9w7w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c6h3-4727-9w7w", - "modified": "2024-06-10T18:30:57Z", + "modified": "2024-07-03T18:38:46Z", "published": "2024-05-03T03:30:47Z", "aliases": [ "CVE-2024-34403" ], "details": "An issue was discovered in uriparser through 0.9.7. ComposeQueryMallocExMm in UriQuery.c has an integer overflow via a long string.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-190" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-03T01:15:48Z" diff --git a/advisories/unreviewed/2024/05/GHSA-c9f8-5x26-4646/GHSA-c9f8-5x26-4646.json b/advisories/unreviewed/2024/05/GHSA-c9f8-5x26-4646/GHSA-c9f8-5x26-4646.json index 18cbce1599c..c28067eee1a 100644 --- a/advisories/unreviewed/2024/05/GHSA-c9f8-5x26-4646/GHSA-c9f8-5x26-4646.json +++ b/advisories/unreviewed/2024/05/GHSA-c9f8-5x26-4646/GHSA-c9f8-5x26-4646.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c9f8-5x26-4646", - "modified": "2024-05-07T18:30:34Z", + "modified": "2024-07-03T18:39:35Z", "published": "2024-05-07T18:30:34Z", "aliases": [ "CVE-2024-33149" ], "details": "J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the myProcessList function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T17:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-cc7f-xj8f-c4mm/GHSA-cc7f-xj8f-c4mm.json b/advisories/unreviewed/2024/05/GHSA-cc7f-xj8f-c4mm/GHSA-cc7f-xj8f-c4mm.json index 0e3e6dab412..0cb6b2446f2 100644 --- a/advisories/unreviewed/2024/05/GHSA-cc7f-xj8f-c4mm/GHSA-cc7f-xj8f-c4mm.json +++ b/advisories/unreviewed/2024/05/GHSA-cc7f-xj8f-c4mm/GHSA-cc7f-xj8f-c4mm.json @@ -25,7 +25,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-259" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-cf3q-2prj-j668/GHSA-cf3q-2prj-j668.json b/advisories/unreviewed/2024/05/GHSA-cf3q-2prj-j668/GHSA-cf3q-2prj-j668.json index f1f7e484fa0..686934c4838 100644 --- a/advisories/unreviewed/2024/05/GHSA-cf3q-2prj-j668/GHSA-cf3q-2prj-j668.json +++ b/advisories/unreviewed/2024/05/GHSA-cf3q-2prj-j668/GHSA-cf3q-2prj-j668.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cf3q-2prj-j668", - "modified": "2024-05-01T18:30:42Z", + "modified": "2024-07-03T18:38:19Z", "published": "2024-05-01T18:30:42Z", "aliases": [ "CVE-2024-33442" ], "details": "An issue in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the add_post.php component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-01T18:15:24Z" diff --git a/advisories/unreviewed/2024/05/GHSA-ch8g-2w9c-j286/GHSA-ch8g-2w9c-j286.json b/advisories/unreviewed/2024/05/GHSA-ch8g-2w9c-j286/GHSA-ch8g-2w9c-j286.json index c9a91b547d6..558b890e470 100644 --- a/advisories/unreviewed/2024/05/GHSA-ch8g-2w9c-j286/GHSA-ch8g-2w9c-j286.json +++ b/advisories/unreviewed/2024/05/GHSA-ch8g-2w9c-j286/GHSA-ch8g-2w9c-j286.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ch8g-2w9c-j286", - "modified": "2024-05-03T06:30:35Z", + "modified": "2024-07-03T18:38:46Z", "published": "2024-05-03T06:30:35Z", "aliases": [ "CVE-2024-34408" ], "details": "Tencent libpag through 4.3.51 has an integer overflow in DecodeStream::checkEndOfFile() in codec/utils/DecodeStream.cpp via a crafted PAG (Portable Animated Graphics) file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-03T06:15:13Z" diff --git a/advisories/unreviewed/2024/05/GHSA-cm5q-2h7w-xfc7/GHSA-cm5q-2h7w-xfc7.json b/advisories/unreviewed/2024/05/GHSA-cm5q-2h7w-xfc7/GHSA-cm5q-2h7w-xfc7.json index 8badd91a182..122511df4c5 100644 --- a/advisories/unreviewed/2024/05/GHSA-cm5q-2h7w-xfc7/GHSA-cm5q-2h7w-xfc7.json +++ b/advisories/unreviewed/2024/05/GHSA-cm5q-2h7w-xfc7/GHSA-cm5q-2h7w-xfc7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cm5q-2h7w-xfc7", - "modified": "2024-06-10T18:30:59Z", + "modified": "2024-07-03T18:40:15Z", "published": "2024-05-14T15:32:53Z", "aliases": [ "CVE-2024-27829" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.5. Processing a file may lead to unexpected app termination or arbitrary code execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-788" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:13:06Z" diff --git a/advisories/unreviewed/2024/05/GHSA-cqfx-xvr4-7hr2/GHSA-cqfx-xvr4-7hr2.json b/advisories/unreviewed/2024/05/GHSA-cqfx-xvr4-7hr2/GHSA-cqfx-xvr4-7hr2.json index 00a32b01a80..949a592b312 100644 --- a/advisories/unreviewed/2024/05/GHSA-cqfx-xvr4-7hr2/GHSA-cqfx-xvr4-7hr2.json +++ b/advisories/unreviewed/2024/05/GHSA-cqfx-xvr4-7hr2/GHSA-cqfx-xvr4-7hr2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cqfx-xvr4-7hr2", - "modified": "2024-05-07T18:30:34Z", + "modified": "2024-07-03T18:39:37Z", "published": "2024-05-07T18:30:34Z", "aliases": [ "CVE-2024-25512" ], "details": "RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the attach_id parameter at /Bulletin/AttachDownLoad.aspx.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T18:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-crpf-8hgm-99cp/GHSA-crpf-8hgm-99cp.json b/advisories/unreviewed/2024/05/GHSA-crpf-8hgm-99cp/GHSA-crpf-8hgm-99cp.json index 88982843766..8a93c6874d1 100644 --- a/advisories/unreviewed/2024/05/GHSA-crpf-8hgm-99cp/GHSA-crpf-8hgm-99cp.json +++ b/advisories/unreviewed/2024/05/GHSA-crpf-8hgm-99cp/GHSA-crpf-8hgm-99cp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-crpf-8hgm-99cp", - "modified": "2024-05-08T18:30:49Z", + "modified": "2024-07-03T18:40:02Z", "published": "2024-05-08T18:30:49Z", "aliases": [ "CVE-2024-34244" ], "details": "libmodbus v3.1.10 is vulnerable to Buffer Overflow via the modbus_write_bits function. This issue can be triggered when the function is fed with specially crafted input, which leads to out-of-bounds read and can potentially cause a crash or other unintended behaviors.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-08T17:15:07Z" diff --git a/advisories/unreviewed/2024/05/GHSA-cv5j-h4rr-jj29/GHSA-cv5j-h4rr-jj29.json b/advisories/unreviewed/2024/05/GHSA-cv5j-h4rr-jj29/GHSA-cv5j-h4rr-jj29.json index e8bea01c467..b34f7c65288 100644 --- a/advisories/unreviewed/2024/05/GHSA-cv5j-h4rr-jj29/GHSA-cv5j-h4rr-jj29.json +++ b/advisories/unreviewed/2024/05/GHSA-cv5j-h4rr-jj29/GHSA-cv5j-h4rr-jj29.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cv5j-h4rr-jj29", - "modified": "2024-05-07T21:31:47Z", + "modified": "2024-07-03T18:39:51Z", "published": "2024-05-07T21:31:47Z", "aliases": [ "CVE-2024-23713" ], "details": "In migrateNotificationFilter of NotificationManagerService.java, there is a possible failure to persist notifications settings due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T21:15:09Z" diff --git a/advisories/unreviewed/2024/05/GHSA-cxv9-jpfc-6237/GHSA-cxv9-jpfc-6237.json b/advisories/unreviewed/2024/05/GHSA-cxv9-jpfc-6237/GHSA-cxv9-jpfc-6237.json index 79240a8a27c..5afc86efbf6 100644 --- a/advisories/unreviewed/2024/05/GHSA-cxv9-jpfc-6237/GHSA-cxv9-jpfc-6237.json +++ b/advisories/unreviewed/2024/05/GHSA-cxv9-jpfc-6237/GHSA-cxv9-jpfc-6237.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cxv9-jpfc-6237", - "modified": "2024-05-08T18:30:49Z", + "modified": "2024-07-03T18:39:57Z", "published": "2024-05-08T18:30:49Z", "aliases": [ "CVE-2024-25531" ], "details": "RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the PageID parameter at /WebUtility/SearchCondiction.aspx.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-08T16:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-f4cf-2w52-c853/GHSA-f4cf-2w52-c853.json b/advisories/unreviewed/2024/05/GHSA-f4cf-2w52-c853/GHSA-f4cf-2w52-c853.json index 1666306cb96..172283f4859 100644 --- a/advisories/unreviewed/2024/05/GHSA-f4cf-2w52-c853/GHSA-f4cf-2w52-c853.json +++ b/advisories/unreviewed/2024/05/GHSA-f4cf-2w52-c853/GHSA-f4cf-2w52-c853.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f4cf-2w52-c853", - "modified": "2024-06-30T15:30:42Z", + "modified": "2024-07-03T18:39:17Z", "published": "2024-05-06T21:30:38Z", "aliases": [ "CVE-2024-33601" ], "details": "nscd: netgroup cache may terminate daemon on memory allocation failure\n\nThe Name Service Cache Daemon's (nscd) netgroup cache uses xmalloc or\nxrealloc and these functions may terminate the process due to a memory\nallocation failure resulting in a denial of service to the clients. The\nflaw was introduced in glibc 2.15 when the cache was added to nscd.\n\nThis vulnerability is only present in the nscd binary.\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-617" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-06T20:15:11Z" diff --git a/advisories/unreviewed/2024/05/GHSA-f4pv-q5f7-2h55/GHSA-f4pv-q5f7-2h55.json b/advisories/unreviewed/2024/05/GHSA-f4pv-q5f7-2h55/GHSA-f4pv-q5f7-2h55.json index ed12e4558b0..e1349811b83 100644 --- a/advisories/unreviewed/2024/05/GHSA-f4pv-q5f7-2h55/GHSA-f4pv-q5f7-2h55.json +++ b/advisories/unreviewed/2024/05/GHSA-f4pv-q5f7-2h55/GHSA-f4pv-q5f7-2h55.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f4pv-q5f7-2h55", - "modified": "2024-06-30T15:30:42Z", + "modified": "2024-07-03T18:39:18Z", "published": "2024-05-06T21:30:38Z", "aliases": [ "CVE-2024-33602" ], "details": "nscd: netgroup cache assumes NSS callback uses in-buffer strings\n\nThe Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory\nwhen the NSS callback does not store all strings in the provided buffer.\nThe flaw was introduced in glibc 2.15 when the cache was added to nscd.\n\nThis vulnerability is only present in the nscd binary.\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-466" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-06T20:15:11Z" diff --git a/advisories/unreviewed/2024/05/GHSA-fhf8-hvgj-q5vh/GHSA-fhf8-hvgj-q5vh.json b/advisories/unreviewed/2024/05/GHSA-fhf8-hvgj-q5vh/GHSA-fhf8-hvgj-q5vh.json index 5820695d736..bcd11ad4013 100644 --- a/advisories/unreviewed/2024/05/GHSA-fhf8-hvgj-q5vh/GHSA-fhf8-hvgj-q5vh.json +++ b/advisories/unreviewed/2024/05/GHSA-fhf8-hvgj-q5vh/GHSA-fhf8-hvgj-q5vh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fhf8-hvgj-q5vh", - "modified": "2024-05-07T21:31:46Z", + "modified": "2024-07-03T18:39:46Z", "published": "2024-05-07T21:31:46Z", "aliases": [ "CVE-2024-0043" ], "details": "In multiple locations, there is a possible notification listener grant to an app running in the work profile due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T21:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-fj57-wwj6-8p79/GHSA-fj57-wwj6-8p79.json b/advisories/unreviewed/2024/05/GHSA-fj57-wwj6-8p79/GHSA-fj57-wwj6-8p79.json index 2c0f67df562..9a02f750ead 100644 --- a/advisories/unreviewed/2024/05/GHSA-fj57-wwj6-8p79/GHSA-fj57-wwj6-8p79.json +++ b/advisories/unreviewed/2024/05/GHSA-fj57-wwj6-8p79/GHSA-fj57-wwj6-8p79.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fj57-wwj6-8p79", - "modified": "2024-05-03T18:30:37Z", + "modified": "2024-07-03T18:38:47Z", "published": "2024-05-03T18:30:37Z", "aliases": [ "CVE-2024-33789" ], "details": "Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the ipurl parameter at /API/info form endpoint.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-03T17:15:07Z" diff --git a/advisories/unreviewed/2024/05/GHSA-fqv7-fhq2-929v/GHSA-fqv7-fhq2-929v.json b/advisories/unreviewed/2024/05/GHSA-fqv7-fhq2-929v/GHSA-fqv7-fhq2-929v.json index 2ab4c2f151f..45f21f31a11 100644 --- a/advisories/unreviewed/2024/05/GHSA-fqv7-fhq2-929v/GHSA-fqv7-fhq2-929v.json +++ b/advisories/unreviewed/2024/05/GHSA-fqv7-fhq2-929v/GHSA-fqv7-fhq2-929v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fqv7-fhq2-929v", - "modified": "2024-05-01T21:30:37Z", + "modified": "2024-07-03T18:38:21Z", "published": "2024-05-01T21:30:37Z", "aliases": [ "CVE-2023-26793" ], "details": "libmodbus v3.1.10 has a heap-based buffer overflow vulnerability in read_io_status function in src/modbus.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-01T19:15:21Z" diff --git a/advisories/unreviewed/2024/05/GHSA-fv57-985w-x39v/GHSA-fv57-985w-x39v.json b/advisories/unreviewed/2024/05/GHSA-fv57-985w-x39v/GHSA-fv57-985w-x39v.json index 02cf5b915e5..4d155be3f81 100644 --- a/advisories/unreviewed/2024/05/GHSA-fv57-985w-x39v/GHSA-fv57-985w-x39v.json +++ b/advisories/unreviewed/2024/05/GHSA-fv57-985w-x39v/GHSA-fv57-985w-x39v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fv57-985w-x39v", - "modified": "2024-05-06T15:30:40Z", + "modified": "2024-07-03T18:39:09Z", "published": "2024-05-06T15:30:40Z", "aliases": [ "CVE-2024-34470" ], "details": "An issue was discovered in HSC Mailinspector 5.2.17-3 through v.5.2.18. An Unauthenticated Path Traversal vulnerability exists in the /public/loader.php file. The path parameter does not properly filter whether the file and directory passed are part of the webroot, allowing an attacker to read arbitrary files on the server.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-29" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-06T15:15:24Z" diff --git a/advisories/unreviewed/2024/05/GHSA-fvwh-2fv9-m663/GHSA-fvwh-2fv9-m663.json b/advisories/unreviewed/2024/05/GHSA-fvwh-2fv9-m663/GHSA-fvwh-2fv9-m663.json index 38359faf875..f4e10ef2d65 100644 --- a/advisories/unreviewed/2024/05/GHSA-fvwh-2fv9-m663/GHSA-fvwh-2fv9-m663.json +++ b/advisories/unreviewed/2024/05/GHSA-fvwh-2fv9-m663/GHSA-fvwh-2fv9-m663.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fvwh-2fv9-m663", - "modified": "2024-05-07T18:30:33Z", + "modified": "2024-07-03T18:39:30Z", "published": "2024-05-07T18:30:32Z", "aliases": [ "CVE-2024-33144" ], "details": "J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the findApplyedTasksPage function in BpmTaskMapper.xml.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T16:15:07Z" diff --git a/advisories/unreviewed/2024/05/GHSA-fxfv-f99m-vfjq/GHSA-fxfv-f99m-vfjq.json b/advisories/unreviewed/2024/05/GHSA-fxfv-f99m-vfjq/GHSA-fxfv-f99m-vfjq.json index ee814776194..5ee76ab7db2 100644 --- a/advisories/unreviewed/2024/05/GHSA-fxfv-f99m-vfjq/GHSA-fxfv-f99m-vfjq.json +++ b/advisories/unreviewed/2024/05/GHSA-fxfv-f99m-vfjq/GHSA-fxfv-f99m-vfjq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fxfv-f99m-vfjq", - "modified": "2024-05-08T15:30:42Z", + "modified": "2024-07-03T18:39:56Z", "published": "2024-05-08T15:30:42Z", "aliases": [ "CVE-2024-25522" ], "details": "RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the office_missive_id parameter at /WorkFlow/wf_work_form_save.aspx.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-08T15:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-g4jh-vmj9-2xmw/GHSA-g4jh-vmj9-2xmw.json b/advisories/unreviewed/2024/05/GHSA-g4jh-vmj9-2xmw/GHSA-g4jh-vmj9-2xmw.json index 60299ce8889..09ba8fc78e7 100644 --- a/advisories/unreviewed/2024/05/GHSA-g4jh-vmj9-2xmw/GHSA-g4jh-vmj9-2xmw.json +++ b/advisories/unreviewed/2024/05/GHSA-g4jh-vmj9-2xmw/GHSA-g4jh-vmj9-2xmw.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-287" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-g8rr-54r4-95mg/GHSA-g8rr-54r4-95mg.json b/advisories/unreviewed/2024/05/GHSA-g8rr-54r4-95mg/GHSA-g8rr-54r4-95mg.json index fb75d85726a..f2a20b2bb0d 100644 --- a/advisories/unreviewed/2024/05/GHSA-g8rr-54r4-95mg/GHSA-g8rr-54r4-95mg.json +++ b/advisories/unreviewed/2024/05/GHSA-g8rr-54r4-95mg/GHSA-g8rr-54r4-95mg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g8rr-54r4-95mg", - "modified": "2024-05-08T15:30:39Z", + "modified": "2024-07-03T18:39:52Z", "published": "2024-05-08T15:30:39Z", "aliases": [ "CVE-2024-34255" ], "details": "jizhicms v2.5.1 contains a Cross-Site Scripting(XSS) vulnerability in the message function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-08T13:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-g9rq-ppxc-pmj6/GHSA-g9rq-ppxc-pmj6.json b/advisories/unreviewed/2024/05/GHSA-g9rq-ppxc-pmj6/GHSA-g9rq-ppxc-pmj6.json index bee59f512da..9d02ccb3307 100644 --- a/advisories/unreviewed/2024/05/GHSA-g9rq-ppxc-pmj6/GHSA-g9rq-ppxc-pmj6.json +++ b/advisories/unreviewed/2024/05/GHSA-g9rq-ppxc-pmj6/GHSA-g9rq-ppxc-pmj6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g9rq-ppxc-pmj6", - "modified": "2024-05-06T00:30:52Z", + "modified": "2024-07-03T18:38:58Z", "published": "2024-05-06T00:30:52Z", "aliases": [ "CVE-2024-34524" ], "details": "In XLANG OpenAgents through fe73ac4, the allowed_file protection mechanism can be bypassed by using an incorrect file extension for the nature of the file content.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-288" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-06T00:15:10Z" diff --git a/advisories/unreviewed/2024/05/GHSA-g9vx-vfc5-9mgj/GHSA-g9vx-vfc5-9mgj.json b/advisories/unreviewed/2024/05/GHSA-g9vx-vfc5-9mgj/GHSA-g9vx-vfc5-9mgj.json index 996169ecdc0..c85435a41f5 100644 --- a/advisories/unreviewed/2024/05/GHSA-g9vx-vfc5-9mgj/GHSA-g9vx-vfc5-9mgj.json +++ b/advisories/unreviewed/2024/05/GHSA-g9vx-vfc5-9mgj/GHSA-g9vx-vfc5-9mgj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g9vx-vfc5-9mgj", - "modified": "2024-05-14T18:30:44Z", + "modified": "2024-07-03T18:40:02Z", "published": "2024-05-14T18:30:44Z", "aliases": [ "CVE-2020-18305" ], "details": "Extreme Networks EXOS before v.22.7 and before v.30.2 was discovered to contain an issue in its Web GUI which fails to restrict URL access, allowing attackers to access sensitive information or escalate privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-287" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T06:36:01Z" diff --git a/advisories/unreviewed/2024/05/GHSA-gfv2-v87j-2hqj/GHSA-gfv2-v87j-2hqj.json b/advisories/unreviewed/2024/05/GHSA-gfv2-v87j-2hqj/GHSA-gfv2-v87j-2hqj.json index 44fffee6023..7d3c7cf429a 100644 --- a/advisories/unreviewed/2024/05/GHSA-gfv2-v87j-2hqj/GHSA-gfv2-v87j-2hqj.json +++ b/advisories/unreviewed/2024/05/GHSA-gfv2-v87j-2hqj/GHSA-gfv2-v87j-2hqj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gfv2-v87j-2hqj", - "modified": "2024-05-06T18:30:36Z", + "modified": "2024-07-03T18:39:12Z", "published": "2024-05-06T18:30:36Z", "aliases": [ "CVE-2024-33404" ], "details": "A SQL injection vulnerability in /model/add_student_first_payment.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the index parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-06T18:15:07Z" diff --git a/advisories/unreviewed/2024/05/GHSA-gpc9-w434-fvwx/GHSA-gpc9-w434-fvwx.json b/advisories/unreviewed/2024/05/GHSA-gpc9-w434-fvwx/GHSA-gpc9-w434-fvwx.json index e1286ff2337..d69fa644e34 100644 --- a/advisories/unreviewed/2024/05/GHSA-gpc9-w434-fvwx/GHSA-gpc9-w434-fvwx.json +++ b/advisories/unreviewed/2024/05/GHSA-gpc9-w434-fvwx/GHSA-gpc9-w434-fvwx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gpc9-w434-fvwx", - "modified": "2024-05-05T03:30:47Z", + "modified": "2024-07-03T18:38:56Z", "published": "2024-05-05T03:30:47Z", "aliases": [ "CVE-2024-34490" ], "details": "In Maxima through 5.47.0 before 51704c, the plotting facilities make use of predictable names under /tmp. Thus, the contents may be controlled by a local attacker who can create files in advance with these names. This affects, for example, plot2d.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-377" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-05T03:15:07Z" diff --git a/advisories/unreviewed/2024/05/GHSA-gr6h-g3pg-9ggp/GHSA-gr6h-g3pg-9ggp.json b/advisories/unreviewed/2024/05/GHSA-gr6h-g3pg-9ggp/GHSA-gr6h-g3pg-9ggp.json index 555c8fd8a3f..e6d2912689f 100644 --- a/advisories/unreviewed/2024/05/GHSA-gr6h-g3pg-9ggp/GHSA-gr6h-g3pg-9ggp.json +++ b/advisories/unreviewed/2024/05/GHSA-gr6h-g3pg-9ggp/GHSA-gr6h-g3pg-9ggp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gr6h-g3pg-9ggp", - "modified": "2024-05-08T18:30:49Z", + "modified": "2024-07-03T18:39:57Z", "published": "2024-05-08T18:30:49Z", "aliases": [ "CVE-2024-25530" ], "details": "RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the PageID parameter at /WebUtility/get_find_condiction.aspx.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-08T16:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-gr7j-q4q6-rxcf/GHSA-gr7j-q4q6-rxcf.json b/advisories/unreviewed/2024/05/GHSA-gr7j-q4q6-rxcf/GHSA-gr7j-q4q6-rxcf.json index d8017d10416..d93c4ed7422 100644 --- a/advisories/unreviewed/2024/05/GHSA-gr7j-q4q6-rxcf/GHSA-gr7j-q4q6-rxcf.json +++ b/advisories/unreviewed/2024/05/GHSA-gr7j-q4q6-rxcf/GHSA-gr7j-q4q6-rxcf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gr7j-q4q6-rxcf", - "modified": "2024-05-19T06:31:55Z", + "modified": "2024-07-03T18:40:09Z", "published": "2024-05-14T15:32:52Z", "aliases": [ "CVE-2024-22774" ], "details": "An issue in Panoramic Corporation Digital Imaging Software v.9.1.2.7600 allows a local attacker to escalate privileges via the ccsservice.exe component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T14:58:21Z" diff --git a/advisories/unreviewed/2024/05/GHSA-gwp7-78vh-mpmm/GHSA-gwp7-78vh-mpmm.json b/advisories/unreviewed/2024/05/GHSA-gwp7-78vh-mpmm/GHSA-gwp7-78vh-mpmm.json index 9c20fc3255c..cc888b8042c 100644 --- a/advisories/unreviewed/2024/05/GHSA-gwp7-78vh-mpmm/GHSA-gwp7-78vh-mpmm.json +++ b/advisories/unreviewed/2024/05/GHSA-gwp7-78vh-mpmm/GHSA-gwp7-78vh-mpmm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gwp7-78vh-mpmm", - "modified": "2024-06-10T18:30:57Z", + "modified": "2024-07-03T18:38:57Z", "published": "2024-05-05T21:30:31Z", "aliases": [ "CVE-2024-34507" ], "details": "An issue was discovered in includes/CommentFormatter/CommentParser.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1. XSS can occur because of mishandling of the 0x1b character, as demonstrated by Special:RecentChanges#%1b0000000.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-80" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-05T19:15:07Z" diff --git a/advisories/unreviewed/2024/05/GHSA-gwqx-m7rc-2c9p/GHSA-gwqx-m7rc-2c9p.json b/advisories/unreviewed/2024/05/GHSA-gwqx-m7rc-2c9p/GHSA-gwqx-m7rc-2c9p.json index 03b7eb97548..bdb9a96a4a1 100644 --- a/advisories/unreviewed/2024/05/GHSA-gwqx-m7rc-2c9p/GHSA-gwqx-m7rc-2c9p.json +++ b/advisories/unreviewed/2024/05/GHSA-gwqx-m7rc-2c9p/GHSA-gwqx-m7rc-2c9p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gwqx-m7rc-2c9p", - "modified": "2024-05-02T06:30:32Z", + "modified": "2024-07-03T18:38:35Z", "published": "2024-05-02T06:30:32Z", "aliases": [ "CVE-2024-3481" ], "details": "The Counter Box WordPress plugin before 1.2.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such deleting counters via CSRF attacks", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:H/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-02T06:15:51Z" diff --git a/advisories/unreviewed/2024/05/GHSA-gx23-3rqm-g2xc/GHSA-gx23-3rqm-g2xc.json b/advisories/unreviewed/2024/05/GHSA-gx23-3rqm-g2xc/GHSA-gx23-3rqm-g2xc.json index b819a27a60a..21ef0f9734c 100644 --- a/advisories/unreviewed/2024/05/GHSA-gx23-3rqm-g2xc/GHSA-gx23-3rqm-g2xc.json +++ b/advisories/unreviewed/2024/05/GHSA-gx23-3rqm-g2xc/GHSA-gx23-3rqm-g2xc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gx23-3rqm-g2xc", - "modified": "2024-05-07T18:30:34Z", + "modified": "2024-07-03T18:39:36Z", "published": "2024-05-07T18:30:34Z", "aliases": [ "CVE-2024-33860" ], "details": "An issue was discovered in Logpoint before 7.4.0. It allows Local File Inclusion (LFI) when an arbitrary File Path is used within the File System Collector. The content of the file specified can be viewed in the incoming logs.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-73" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T17:15:09Z" diff --git a/advisories/unreviewed/2024/05/GHSA-h2jp-gf2g-f6fc/GHSA-h2jp-gf2g-f6fc.json b/advisories/unreviewed/2024/05/GHSA-h2jp-gf2g-f6fc/GHSA-h2jp-gf2g-f6fc.json index 71d515b756c..04b1d4e1704 100644 --- a/advisories/unreviewed/2024/05/GHSA-h2jp-gf2g-f6fc/GHSA-h2jp-gf2g-f6fc.json +++ b/advisories/unreviewed/2024/05/GHSA-h2jp-gf2g-f6fc/GHSA-h2jp-gf2g-f6fc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h2jp-gf2g-f6fc", - "modified": "2024-05-14T15:32:54Z", + "modified": "2024-07-03T18:40:28Z", "published": "2024-05-14T15:32:54Z", "aliases": [ "CVE-2024-2749" ], "details": "The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8's access control mechanism fails to properly restrict access to its settings, permitting any users that can access a menu to manipulate requests and perform unauthorized actions such as editing, renaming or deleting (categories for example) despite initial settings prohibiting such access. This vulnerability resembles broken access control, enabling unauthorized users to modify critical VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8 configurations.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:20:41Z" diff --git a/advisories/unreviewed/2024/05/GHSA-h3xp-fgm5-94vx/GHSA-h3xp-fgm5-94vx.json b/advisories/unreviewed/2024/05/GHSA-h3xp-fgm5-94vx/GHSA-h3xp-fgm5-94vx.json index 93bab67f713..6483e3486bf 100644 --- a/advisories/unreviewed/2024/05/GHSA-h3xp-fgm5-94vx/GHSA-h3xp-fgm5-94vx.json +++ b/advisories/unreviewed/2024/05/GHSA-h3xp-fgm5-94vx/GHSA-h3xp-fgm5-94vx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h3xp-fgm5-94vx", - "modified": "2024-05-07T15:30:39Z", + "modified": "2024-07-03T18:39:22Z", "published": "2024-05-07T15:30:39Z", "aliases": [ "CVE-2024-32370" ], "details": "An issue in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a remote attacker to obtain sensitive information via a crafted payload to the id parameter in the mliSystemUsers.php component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-782" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T15:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-h455-phph-2r6j/GHSA-h455-phph-2r6j.json b/advisories/unreviewed/2024/05/GHSA-h455-phph-2r6j/GHSA-h455-phph-2r6j.json index 0940a124c6e..af4344d3678 100644 --- a/advisories/unreviewed/2024/05/GHSA-h455-phph-2r6j/GHSA-h455-phph-2r6j.json +++ b/advisories/unreviewed/2024/05/GHSA-h455-phph-2r6j/GHSA-h455-phph-2r6j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h455-phph-2r6j", - "modified": "2024-05-07T18:30:33Z", + "modified": "2024-07-03T18:39:31Z", "published": "2024-05-07T18:30:33Z", "aliases": [ "CVE-2024-33856" ], "details": "An issue was discovered in Logpoint before 7.4.0. An attacker can enumerate a valid list of usernames by observing the response time at the Forgot Password endpoint.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-204" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T16:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-h6w6-gghp-c4hr/GHSA-h6w6-gghp-c4hr.json b/advisories/unreviewed/2024/05/GHSA-h6w6-gghp-c4hr/GHSA-h6w6-gghp-c4hr.json index dbeea87c562..b3e5e6b2a2d 100644 --- a/advisories/unreviewed/2024/05/GHSA-h6w6-gghp-c4hr/GHSA-h6w6-gghp-c4hr.json +++ b/advisories/unreviewed/2024/05/GHSA-h6w6-gghp-c4hr/GHSA-h6w6-gghp-c4hr.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-h83h-p79w-q64j/GHSA-h83h-p79w-q64j.json b/advisories/unreviewed/2024/05/GHSA-h83h-p79w-q64j/GHSA-h83h-p79w-q64j.json index 4f0e9890cbf..faedbc7d154 100644 --- a/advisories/unreviewed/2024/05/GHSA-h83h-p79w-q64j/GHSA-h83h-p79w-q64j.json +++ b/advisories/unreviewed/2024/05/GHSA-h83h-p79w-q64j/GHSA-h83h-p79w-q64j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h83h-p79w-q64j", - "modified": "2024-06-11T09:30:58Z", + "modified": "2024-07-03T18:40:11Z", "published": "2024-05-14T15:32:53Z", "aliases": [ "CVE-2024-27810" ], "details": "A path handling issue was addressed with improved validation. This issue is fixed in iOS 17.5 and iPadOS 17.5, tvOS 17.5, watchOS 10.5, macOS Sonoma 14.5. An app may be able to read sensitive location information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -77,9 +80,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-28" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:13:04Z" diff --git a/advisories/unreviewed/2024/05/GHSA-hpg3-whph-cvcf/GHSA-hpg3-whph-cvcf.json b/advisories/unreviewed/2024/05/GHSA-hpg3-whph-cvcf/GHSA-hpg3-whph-cvcf.json index 2be5e284dd2..b876d88caad 100644 --- a/advisories/unreviewed/2024/05/GHSA-hpg3-whph-cvcf/GHSA-hpg3-whph-cvcf.json +++ b/advisories/unreviewed/2024/05/GHSA-hpg3-whph-cvcf/GHSA-hpg3-whph-cvcf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hpg3-whph-cvcf", - "modified": "2024-05-14T15:32:54Z", + "modified": "2024-07-03T18:40:18Z", "published": "2024-05-14T15:32:54Z", "aliases": [ "CVE-2024-29158" ], "details": "HDF5 through 1.14.3 contains a stack buffer overflow in H5FL_arr_malloc, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:15:31Z" diff --git a/advisories/unreviewed/2024/05/GHSA-hrr2-23m9-vwg9/GHSA-hrr2-23m9-vwg9.json b/advisories/unreviewed/2024/05/GHSA-hrr2-23m9-vwg9/GHSA-hrr2-23m9-vwg9.json index e1d150627a8..0d78b67e9b2 100644 --- a/advisories/unreviewed/2024/05/GHSA-hrr2-23m9-vwg9/GHSA-hrr2-23m9-vwg9.json +++ b/advisories/unreviewed/2024/05/GHSA-hrr2-23m9-vwg9/GHSA-hrr2-23m9-vwg9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hrr2-23m9-vwg9", - "modified": "2024-05-06T00:30:52Z", + "modified": "2024-07-03T18:38:58Z", "published": "2024-05-06T00:30:52Z", "aliases": [ "CVE-2024-34525" ], "details": "FileCodeBox 2.0 stores a OneDrive password and AWS key in a cleartext env file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-591" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-06T00:15:10Z" diff --git a/advisories/unreviewed/2024/05/GHSA-hv8p-cqc6-r6pm/GHSA-hv8p-cqc6-r6pm.json b/advisories/unreviewed/2024/05/GHSA-hv8p-cqc6-r6pm/GHSA-hv8p-cqc6-r6pm.json index 23593345196..95b2e9a854e 100644 --- a/advisories/unreviewed/2024/05/GHSA-hv8p-cqc6-r6pm/GHSA-hv8p-cqc6-r6pm.json +++ b/advisories/unreviewed/2024/05/GHSA-hv8p-cqc6-r6pm/GHSA-hv8p-cqc6-r6pm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hv8p-cqc6-r6pm", - "modified": "2024-05-08T15:30:42Z", + "modified": "2024-07-03T18:39:53Z", "published": "2024-05-08T15:30:42Z", "aliases": [ "CVE-2024-25515" ], "details": "RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the sys_file_storage_id parameter at /WorkFlow/wf_work_finish_file_down.aspx.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-08T15:15:07Z" diff --git a/advisories/unreviewed/2024/05/GHSA-hw9f-66ch-w6pg/GHSA-hw9f-66ch-w6pg.json b/advisories/unreviewed/2024/05/GHSA-hw9f-66ch-w6pg/GHSA-hw9f-66ch-w6pg.json index b4b7cad6eaa..803c27b679b 100644 --- a/advisories/unreviewed/2024/05/GHSA-hw9f-66ch-w6pg/GHSA-hw9f-66ch-w6pg.json +++ b/advisories/unreviewed/2024/05/GHSA-hw9f-66ch-w6pg/GHSA-hw9f-66ch-w6pg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hw9f-66ch-w6pg", - "modified": "2024-06-10T18:30:59Z", + "modified": "2024-07-03T18:40:16Z", "published": "2024-05-14T15:32:53Z", "aliases": [ "CVE-2024-27841" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. An app may be able to disclose kernel memory.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:13:07Z" diff --git a/advisories/unreviewed/2024/05/GHSA-hwpw-xpj3-c397/GHSA-hwpw-xpj3-c397.json b/advisories/unreviewed/2024/05/GHSA-hwpw-xpj3-c397/GHSA-hwpw-xpj3-c397.json index c05787d3ac3..403224cad1a 100644 --- a/advisories/unreviewed/2024/05/GHSA-hwpw-xpj3-c397/GHSA-hwpw-xpj3-c397.json +++ b/advisories/unreviewed/2024/05/GHSA-hwpw-xpj3-c397/GHSA-hwpw-xpj3-c397.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hwpw-xpj3-c397", - "modified": "2024-06-10T18:30:57Z", + "modified": "2024-07-03T18:38:45Z", "published": "2024-05-03T03:30:47Z", "aliases": [ "CVE-2024-34402" ], "details": "An issue was discovered in uriparser through 0.9.7. ComposeQueryEngine in UriQuery.c has an integer overflow via long keys or values, with a resultant buffer overflow.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-190" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-03T01:15:48Z" diff --git a/advisories/unreviewed/2024/05/GHSA-hx86-84jq-2v5p/GHSA-hx86-84jq-2v5p.json b/advisories/unreviewed/2024/05/GHSA-hx86-84jq-2v5p/GHSA-hx86-84jq-2v5p.json index 89ac48617ec..ea329b9a948 100644 --- a/advisories/unreviewed/2024/05/GHSA-hx86-84jq-2v5p/GHSA-hx86-84jq-2v5p.json +++ b/advisories/unreviewed/2024/05/GHSA-hx86-84jq-2v5p/GHSA-hx86-84jq-2v5p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hx86-84jq-2v5p", - "modified": "2024-05-01T21:30:37Z", + "modified": "2024-07-03T18:38:25Z", "published": "2024-05-01T21:30:37Z", "aliases": [ "CVE-2024-33304" ], "details": "SourceCodester Product Show Room 1.0 is vulnerable to Cross Site Scripting (XSS) via \"Last Name\" under Add Users.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-01T19:15:26Z" diff --git a/advisories/unreviewed/2024/05/GHSA-j3mh-hgxq-fp6h/GHSA-j3mh-hgxq-fp6h.json b/advisories/unreviewed/2024/05/GHSA-j3mh-hgxq-fp6h/GHSA-j3mh-hgxq-fp6h.json index 2f9b826fd70..298dcb3c556 100644 --- a/advisories/unreviewed/2024/05/GHSA-j3mh-hgxq-fp6h/GHSA-j3mh-hgxq-fp6h.json +++ b/advisories/unreviewed/2024/05/GHSA-j3mh-hgxq-fp6h/GHSA-j3mh-hgxq-fp6h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j3mh-hgxq-fp6h", - "modified": "2024-06-10T18:30:58Z", + "modified": "2024-07-03T18:40:11Z", "published": "2024-05-14T15:32:53Z", "aliases": [ "CVE-2024-27813" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.5. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:13:04Z" diff --git a/advisories/unreviewed/2024/05/GHSA-j7qq-x7xm-2hpv/GHSA-j7qq-x7xm-2hpv.json b/advisories/unreviewed/2024/05/GHSA-j7qq-x7xm-2hpv/GHSA-j7qq-x7xm-2hpv.json index a013fe4aa57..eecdc5d0a4c 100644 --- a/advisories/unreviewed/2024/05/GHSA-j7qq-x7xm-2hpv/GHSA-j7qq-x7xm-2hpv.json +++ b/advisories/unreviewed/2024/05/GHSA-j7qq-x7xm-2hpv/GHSA-j7qq-x7xm-2hpv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j7qq-x7xm-2hpv", - "modified": "2024-05-02T18:30:51Z", + "modified": "2024-07-03T18:38:40Z", "published": "2024-05-02T18:30:51Z", "aliases": [ "CVE-2024-31964" ], "details": "A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones, including 6970 Conference Unit, through 6.3 SP3 HF4 allows an unauthenticated attacker to conduct an authentication bypass attack due to improper authentication control. A successful exploit could allow an attacker to modify system configuration settings and potentially cause a denial of service.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-02T16:15:07Z" diff --git a/advisories/unreviewed/2024/05/GHSA-jhpp-3jgc-qfwp/GHSA-jhpp-3jgc-qfwp.json b/advisories/unreviewed/2024/05/GHSA-jhpp-3jgc-qfwp/GHSA-jhpp-3jgc-qfwp.json index 8570bafcb3d..684767bd145 100644 --- a/advisories/unreviewed/2024/05/GHSA-jhpp-3jgc-qfwp/GHSA-jhpp-3jgc-qfwp.json +++ b/advisories/unreviewed/2024/05/GHSA-jhpp-3jgc-qfwp/GHSA-jhpp-3jgc-qfwp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jhpp-3jgc-qfwp", - "modified": "2024-05-07T21:31:47Z", + "modified": "2024-07-03T18:39:48Z", "published": "2024-05-07T21:31:46Z", "aliases": [ "CVE-2024-23707" ], "details": "In multiple locations, there is a possible permissions bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T21:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-jvfj-c7wv-mq45/GHSA-jvfj-c7wv-mq45.json b/advisories/unreviewed/2024/05/GHSA-jvfj-c7wv-mq45/GHSA-jvfj-c7wv-mq45.json index d279379e7ee..e38214ff934 100644 --- a/advisories/unreviewed/2024/05/GHSA-jvfj-c7wv-mq45/GHSA-jvfj-c7wv-mq45.json +++ b/advisories/unreviewed/2024/05/GHSA-jvfj-c7wv-mq45/GHSA-jvfj-c7wv-mq45.json @@ -25,7 +25,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-jw4v-xfx4-pv7q/GHSA-jw4v-xfx4-pv7q.json b/advisories/unreviewed/2024/05/GHSA-jw4v-xfx4-pv7q/GHSA-jw4v-xfx4-pv7q.json index ff113d76aa7..47a7bd93b91 100644 --- a/advisories/unreviewed/2024/05/GHSA-jw4v-xfx4-pv7q/GHSA-jw4v-xfx4-pv7q.json +++ b/advisories/unreviewed/2024/05/GHSA-jw4v-xfx4-pv7q/GHSA-jw4v-xfx4-pv7q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jw4v-xfx4-pv7q", - "modified": "2024-05-08T15:30:42Z", + "modified": "2024-07-03T18:39:56Z", "published": "2024-05-08T15:30:42Z", "aliases": [ "CVE-2024-25519" ], "details": "RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the idlist parameter at /WorkFlow/wf_work_print.aspx.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-08T15:15:07Z" diff --git a/advisories/unreviewed/2024/05/GHSA-jw9c-3jfh-2qq2/GHSA-jw9c-3jfh-2qq2.json b/advisories/unreviewed/2024/05/GHSA-jw9c-3jfh-2qq2/GHSA-jw9c-3jfh-2qq2.json index f3e6009ae81..475effee9bf 100644 --- a/advisories/unreviewed/2024/05/GHSA-jw9c-3jfh-2qq2/GHSA-jw9c-3jfh-2qq2.json +++ b/advisories/unreviewed/2024/05/GHSA-jw9c-3jfh-2qq2/GHSA-jw9c-3jfh-2qq2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jw9c-3jfh-2qq2", - "modified": "2024-05-06T03:30:47Z", + "modified": "2024-07-03T18:38:59Z", "published": "2024-05-06T03:30:47Z", "aliases": [ "CVE-2024-34538" ], "details": "Mateso PasswordSafe through 8.13.9.26689 has Weak Cryptography.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-338" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-06T03:15:10Z" diff --git a/advisories/unreviewed/2024/05/GHSA-m6xf-rg25-42wc/GHSA-m6xf-rg25-42wc.json b/advisories/unreviewed/2024/05/GHSA-m6xf-rg25-42wc/GHSA-m6xf-rg25-42wc.json index 57fd174654b..ce3dbe33fe6 100644 --- a/advisories/unreviewed/2024/05/GHSA-m6xf-rg25-42wc/GHSA-m6xf-rg25-42wc.json +++ b/advisories/unreviewed/2024/05/GHSA-m6xf-rg25-42wc/GHSA-m6xf-rg25-42wc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m6xf-rg25-42wc", - "modified": "2024-05-07T12:30:50Z", + "modified": "2024-07-03T18:38:50Z", "published": "2024-05-03T21:30:30Z", "aliases": [ "CVE-2024-34455" ], "details": "Buildroot before 0b2967e lacks the sticky bit for the /dev/shm directory.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-03T19:15:07Z" diff --git a/advisories/unreviewed/2024/05/GHSA-m854-6wh4-fmg2/GHSA-m854-6wh4-fmg2.json b/advisories/unreviewed/2024/05/GHSA-m854-6wh4-fmg2/GHSA-m854-6wh4-fmg2.json index 0f49e316922..48fb0e94236 100644 --- a/advisories/unreviewed/2024/05/GHSA-m854-6wh4-fmg2/GHSA-m854-6wh4-fmg2.json +++ b/advisories/unreviewed/2024/05/GHSA-m854-6wh4-fmg2/GHSA-m854-6wh4-fmg2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m854-6wh4-fmg2", - "modified": "2024-05-06T12:30:26Z", + "modified": "2024-07-03T18:39:01Z", "published": "2024-05-06T12:30:26Z", "aliases": [ "CVE-2024-33753" ], "details": "Section Camera V2.5.5.3116-S50-SMA-B20160811 and earlier versions allow the accounts and passwords of administrators and users to be changed without authorization.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-06T12:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-mg24-mpj4-j47p/GHSA-mg24-mpj4-j47p.json b/advisories/unreviewed/2024/05/GHSA-mg24-mpj4-j47p/GHSA-mg24-mpj4-j47p.json index 0ca6fe36edf..e5c51622cf4 100644 --- a/advisories/unreviewed/2024/05/GHSA-mg24-mpj4-j47p/GHSA-mg24-mpj4-j47p.json +++ b/advisories/unreviewed/2024/05/GHSA-mg24-mpj4-j47p/GHSA-mg24-mpj4-j47p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mg24-mpj4-j47p", - "modified": "2024-05-07T21:31:45Z", + "modified": "2024-07-03T18:39:44Z", "published": "2024-05-07T21:31:45Z", "aliases": [ "CVE-2024-34315" ], "details": "CmsEasy v7.7.7.9 was discovered to contain a local file inclusion vunerability via the file_get_contents function in the fckedit_action method of /admin/template_admin.php. This vulnerability allows attackers to read arbitrary files.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T19:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-mgmj-jff7-4w5p/GHSA-mgmj-jff7-4w5p.json b/advisories/unreviewed/2024/05/GHSA-mgmj-jff7-4w5p/GHSA-mgmj-jff7-4w5p.json index bbc516897f7..7cb44f0c4d9 100644 --- a/advisories/unreviewed/2024/05/GHSA-mgmj-jff7-4w5p/GHSA-mgmj-jff7-4w5p.json +++ b/advisories/unreviewed/2024/05/GHSA-mgmj-jff7-4w5p/GHSA-mgmj-jff7-4w5p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mgmj-jff7-4w5p", - "modified": "2024-05-02T06:30:31Z", + "modified": "2024-07-03T18:38:32Z", "published": "2024-05-02T06:30:31Z", "aliases": [ "CVE-2024-2405" ], "details": "The Float menu WordPress plugin before 6.0.1 does not have CSRF check in its bulk actions, which could allow attackers to make logged in admin delete arbitrary menu via a CSRF attack.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-02T06:15:49Z" diff --git a/advisories/unreviewed/2024/05/GHSA-mjm2-m2m4-7qj6/GHSA-mjm2-m2m4-7qj6.json b/advisories/unreviewed/2024/05/GHSA-mjm2-m2m4-7qj6/GHSA-mjm2-m2m4-7qj6.json index 8c768d4be94..09c0ef3600a 100644 --- a/advisories/unreviewed/2024/05/GHSA-mjm2-m2m4-7qj6/GHSA-mjm2-m2m4-7qj6.json +++ b/advisories/unreviewed/2024/05/GHSA-mjm2-m2m4-7qj6/GHSA-mjm2-m2m4-7qj6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mjm2-m2m4-7qj6", - "modified": "2024-05-02T18:30:51Z", + "modified": "2024-07-03T18:38:41Z", "published": "2024-05-02T18:30:51Z", "aliases": [ "CVE-2024-31965" ], "details": "A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones, including 6970 Conference Unit, through 6.3 SP3 HF4 allows an authenticated attacker with administrative privilege to conduct a path traversal attack due to insufficient input validation. A successful exploit could allow an attacker to access sensitive information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-02T16:15:07Z" diff --git a/advisories/unreviewed/2024/05/GHSA-mq9p-qw76-q6h7/GHSA-mq9p-qw76-q6h7.json b/advisories/unreviewed/2024/05/GHSA-mq9p-qw76-q6h7/GHSA-mq9p-qw76-q6h7.json index 743d9a49939..e848d894fa2 100644 --- a/advisories/unreviewed/2024/05/GHSA-mq9p-qw76-q6h7/GHSA-mq9p-qw76-q6h7.json +++ b/advisories/unreviewed/2024/05/GHSA-mq9p-qw76-q6h7/GHSA-mq9p-qw76-q6h7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mq9p-qw76-q6h7", - "modified": "2024-05-06T15:30:39Z", + "modified": "2024-07-03T18:39:09Z", "published": "2024-05-06T15:30:39Z", "aliases": [ "CVE-2024-34249" ], "details": "wasm3 v0.5.0 was discovered to contain a heap buffer overflow which leads to segmentation fault via the function \"DeallocateSlot\" in wasm3/source/m3_compile.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-06T15:15:24Z" diff --git a/advisories/unreviewed/2024/05/GHSA-mqrq-8fm6-x78m/GHSA-mqrq-8fm6-x78m.json b/advisories/unreviewed/2024/05/GHSA-mqrq-8fm6-x78m/GHSA-mqrq-8fm6-x78m.json index 5fd0c6614c2..58746100c7c 100644 --- a/advisories/unreviewed/2024/05/GHSA-mqrq-8fm6-x78m/GHSA-mqrq-8fm6-x78m.json +++ b/advisories/unreviewed/2024/05/GHSA-mqrq-8fm6-x78m/GHSA-mqrq-8fm6-x78m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mqrq-8fm6-x78m", - "modified": "2024-05-06T18:30:36Z", + "modified": "2024-07-03T18:39:14Z", "published": "2024-05-06T18:30:36Z", "aliases": [ "CVE-2024-33406" ], "details": "SQL injection vulnerability in /model/delete_student_grade_subject.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the index parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -21,13 +24,17 @@ { "type": "WEB", "url": "https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%205.pdf" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%207.pdf" } ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-06T18:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-mwc7-2pw4-jqc9/GHSA-mwc7-2pw4-jqc9.json b/advisories/unreviewed/2024/05/GHSA-mwc7-2pw4-jqc9/GHSA-mwc7-2pw4-jqc9.json index a4ea277203f..bde1e8e59e1 100644 --- a/advisories/unreviewed/2024/05/GHSA-mwc7-2pw4-jqc9/GHSA-mwc7-2pw4-jqc9.json +++ b/advisories/unreviewed/2024/05/GHSA-mwc7-2pw4-jqc9/GHSA-mwc7-2pw4-jqc9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mwc7-2pw4-jqc9", - "modified": "2024-05-07T15:30:37Z", + "modified": "2024-07-03T18:39:19Z", "published": "2024-05-07T15:30:37Z", "aliases": [ "CVE-2024-33780" ], "details": "MP-SPDZ v0.3.8 was discovered to contain a segmentation violation via the function osuCrypto::copyOut at /Tools/SilentPprf.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted message.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T14:15:10Z" diff --git a/advisories/unreviewed/2024/05/GHSA-mx84-33q7-299w/GHSA-mx84-33q7-299w.json b/advisories/unreviewed/2024/05/GHSA-mx84-33q7-299w/GHSA-mx84-33q7-299w.json index bcef7de31ae..3d772bc85a2 100644 --- a/advisories/unreviewed/2024/05/GHSA-mx84-33q7-299w/GHSA-mx84-33q7-299w.json +++ b/advisories/unreviewed/2024/05/GHSA-mx84-33q7-299w/GHSA-mx84-33q7-299w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mx84-33q7-299w", - "modified": "2024-05-07T15:30:36Z", + "modified": "2024-07-03T18:39:19Z", "published": "2024-05-07T15:30:36Z", "aliases": [ "CVE-2023-46012" ], "details": "Buffer Overflow vulnerability LINKSYS EA7500 3.0.1.207964 allows a remote attacker to execute arbitrary code via an HTTP request to the IGD UPnP.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T14:15:10Z" diff --git a/advisories/unreviewed/2024/05/GHSA-p4xc-x8pv-x8j5/GHSA-p4xc-x8pv-x8j5.json b/advisories/unreviewed/2024/05/GHSA-p4xc-x8pv-x8j5/GHSA-p4xc-x8pv-x8j5.json index 8f598dc3d19..cdac2c105e2 100644 --- a/advisories/unreviewed/2024/05/GHSA-p4xc-x8pv-x8j5/GHSA-p4xc-x8pv-x8j5.json +++ b/advisories/unreviewed/2024/05/GHSA-p4xc-x8pv-x8j5/GHSA-p4xc-x8pv-x8j5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p4xc-x8pv-x8j5", - "modified": "2024-05-07T21:31:45Z", + "modified": "2024-07-03T18:39:41Z", "published": "2024-05-07T21:31:45Z", "aliases": [ "CVE-2024-25513" ], "details": "RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the file_id parameter at /CorporateCulture/kaizen_download.aspx.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T19:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-p9rm-gwg4-7qmf/GHSA-p9rm-gwg4-7qmf.json b/advisories/unreviewed/2024/05/GHSA-p9rm-gwg4-7qmf/GHSA-p9rm-gwg4-7qmf.json index 0884bccee35..059296714a9 100644 --- a/advisories/unreviewed/2024/05/GHSA-p9rm-gwg4-7qmf/GHSA-p9rm-gwg4-7qmf.json +++ b/advisories/unreviewed/2024/05/GHSA-p9rm-gwg4-7qmf/GHSA-p9rm-gwg4-7qmf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p9rm-gwg4-7qmf", - "modified": "2024-05-06T18:30:35Z", + "modified": "2024-07-03T18:39:11Z", "published": "2024-05-06T18:30:35Z", "aliases": [ "CVE-2024-34246" ], "details": "wasm3 v0.5.0 was discovered to contain an out-of-bound memory read which leads to segmentation fault via the function \"main\" in wasm3/platforms/app/main.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-06T16:15:13Z" diff --git a/advisories/unreviewed/2024/05/GHSA-pc9f-29p9-88xf/GHSA-pc9f-29p9-88xf.json b/advisories/unreviewed/2024/05/GHSA-pc9f-29p9-88xf/GHSA-pc9f-29p9-88xf.json index 58d0d14733a..e07badeecdc 100644 --- a/advisories/unreviewed/2024/05/GHSA-pc9f-29p9-88xf/GHSA-pc9f-29p9-88xf.json +++ b/advisories/unreviewed/2024/05/GHSA-pc9f-29p9-88xf/GHSA-pc9f-29p9-88xf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pc9f-29p9-88xf", - "modified": "2024-05-14T15:32:54Z", + "modified": "2024-07-03T18:40:26Z", "published": "2024-05-14T15:32:54Z", "aliases": [ "CVE-2024-29164" ], "details": "HDF5 through 1.14.3 contains a stack buffer overflow in H5R__decode_heap, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:15:33Z" diff --git a/advisories/unreviewed/2024/05/GHSA-pcv6-8pf7-r5hc/GHSA-pcv6-8pf7-r5hc.json b/advisories/unreviewed/2024/05/GHSA-pcv6-8pf7-r5hc/GHSA-pcv6-8pf7-r5hc.json index 7ad51423d4c..9ec7372cdec 100644 --- a/advisories/unreviewed/2024/05/GHSA-pcv6-8pf7-r5hc/GHSA-pcv6-8pf7-r5hc.json +++ b/advisories/unreviewed/2024/05/GHSA-pcv6-8pf7-r5hc/GHSA-pcv6-8pf7-r5hc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pcv6-8pf7-r5hc", - "modified": "2024-05-14T18:30:44Z", + "modified": "2024-07-03T18:40:07Z", "published": "2024-05-14T18:30:44Z", "aliases": [ "CVE-2022-32504" ], "details": "An issue was discovered on certain Nuki Home Solutions devices. The code used to parse the JSON objects received from the WebSocket service provided by the device leads to a stack buffer overflow. An attacker would be able to exploit this to gain arbitrary code execution on a KeyTurner device. This affects Nuki Smart Lock 3.0 before 3.3.5 and 2.0 before 2.12.4, as well as Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T10:43:41Z" diff --git a/advisories/unreviewed/2024/05/GHSA-pfqw-6jm8-f3j8/GHSA-pfqw-6jm8-f3j8.json b/advisories/unreviewed/2024/05/GHSA-pfqw-6jm8-f3j8/GHSA-pfqw-6jm8-f3j8.json index f345ff81e31..7526aa4e5bf 100644 --- a/advisories/unreviewed/2024/05/GHSA-pfqw-6jm8-f3j8/GHSA-pfqw-6jm8-f3j8.json +++ b/advisories/unreviewed/2024/05/GHSA-pfqw-6jm8-f3j8/GHSA-pfqw-6jm8-f3j8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pfqw-6jm8-f3j8", - "modified": "2024-05-07T21:31:45Z", + "modified": "2024-07-03T18:39:41Z", "published": "2024-05-07T21:31:45Z", "aliases": [ "CVE-2024-25511" ], "details": "RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /AddressBook/address_public_new.aspx.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T19:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-pg8p-96cv-v9cj/GHSA-pg8p-96cv-v9cj.json b/advisories/unreviewed/2024/05/GHSA-pg8p-96cv-v9cj/GHSA-pg8p-96cv-v9cj.json index e91bb095b54..90d7b755261 100644 --- a/advisories/unreviewed/2024/05/GHSA-pg8p-96cv-v9cj/GHSA-pg8p-96cv-v9cj.json +++ b/advisories/unreviewed/2024/05/GHSA-pg8p-96cv-v9cj/GHSA-pg8p-96cv-v9cj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pg8p-96cv-v9cj", - "modified": "2024-06-11T09:30:58Z", + "modified": "2024-07-03T18:40:13Z", "published": "2024-05-14T15:32:53Z", "aliases": [ "CVE-2024-27827" ], "details": "This issue was addressed through improved state management. This issue is fixed in macOS Sonoma 14.5. An app may be able to read arbitrary files.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:13:06Z" diff --git a/advisories/unreviewed/2024/05/GHSA-pg9r-hpv4-c9cq/GHSA-pg9r-hpv4-c9cq.json b/advisories/unreviewed/2024/05/GHSA-pg9r-hpv4-c9cq/GHSA-pg9r-hpv4-c9cq.json index 64189eb78b7..291bcbdb4c3 100644 --- a/advisories/unreviewed/2024/05/GHSA-pg9r-hpv4-c9cq/GHSA-pg9r-hpv4-c9cq.json +++ b/advisories/unreviewed/2024/05/GHSA-pg9r-hpv4-c9cq/GHSA-pg9r-hpv4-c9cq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pg9r-hpv4-c9cq", - "modified": "2024-05-08T15:30:42Z", + "modified": "2024-07-03T18:39:57Z", "published": "2024-05-08T15:30:42Z", "aliases": [ "CVE-2024-25526" ], "details": "RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the project_id parameter at /ProjectManage/pm_gatt_inc.aspx.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-08T15:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-pjfh-ccg3-6463/GHSA-pjfh-ccg3-6463.json b/advisories/unreviewed/2024/05/GHSA-pjfh-ccg3-6463/GHSA-pjfh-ccg3-6463.json index cb065f9fc58..cd9919f6970 100644 --- a/advisories/unreviewed/2024/05/GHSA-pjfh-ccg3-6463/GHSA-pjfh-ccg3-6463.json +++ b/advisories/unreviewed/2024/05/GHSA-pjfh-ccg3-6463/GHSA-pjfh-ccg3-6463.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pjfh-ccg3-6463", - "modified": "2024-05-02T18:30:51Z", + "modified": "2024-07-03T18:38:44Z", "published": "2024-05-02T18:30:51Z", "aliases": [ "CVE-2024-33530" ], "details": "In Jitsi Meet before 9391, a logic flaw in password-protected Jitsi meetings (that make use of a lobby) leads to the disclosure of the meeting password when a user is invited to a call after waiting in the lobby.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-02T16:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-pm48-m4w3-255f/GHSA-pm48-m4w3-255f.json b/advisories/unreviewed/2024/05/GHSA-pm48-m4w3-255f/GHSA-pm48-m4w3-255f.json index 3cad7679e85..55c728a21f3 100644 --- a/advisories/unreviewed/2024/05/GHSA-pm48-m4w3-255f/GHSA-pm48-m4w3-255f.json +++ b/advisories/unreviewed/2024/05/GHSA-pm48-m4w3-255f/GHSA-pm48-m4w3-255f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pm48-m4w3-255f", - "modified": "2024-05-14T15:32:50Z", + "modified": "2024-07-03T18:40:08Z", "published": "2024-05-14T15:32:50Z", "aliases": [ "CVE-2023-26566" ], "details": "Sangoma FreePBX 1805 through 2203 on Linux contains hardcoded credentials for the Asterisk REST Interface (ARI), which allows remote attackers to reconfigure Asterisk and make external and internal calls via HTTP and WebSocket requests sent to the API.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-798" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T12:39:11Z" diff --git a/advisories/unreviewed/2024/05/GHSA-pm5j-x234-pqf6/GHSA-pm5j-x234-pqf6.json b/advisories/unreviewed/2024/05/GHSA-pm5j-x234-pqf6/GHSA-pm5j-x234-pqf6.json index aa144e56b7e..3d11dadc002 100644 --- a/advisories/unreviewed/2024/05/GHSA-pm5j-x234-pqf6/GHSA-pm5j-x234-pqf6.json +++ b/advisories/unreviewed/2024/05/GHSA-pm5j-x234-pqf6/GHSA-pm5j-x234-pqf6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pm5j-x234-pqf6", - "modified": "2024-05-02T15:30:34Z", + "modified": "2024-07-03T18:38:38Z", "published": "2024-05-02T15:30:34Z", "aliases": [ "CVE-2024-33303" ], "details": "SourceCodester Product Show Room 1.0 is vulnerable to Cross Site Scripting (XSS) via \"First Name\" under Add Users.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-02T14:15:09Z" diff --git a/advisories/unreviewed/2024/05/GHSA-prqw-x27x-86h2/GHSA-prqw-x27x-86h2.json b/advisories/unreviewed/2024/05/GHSA-prqw-x27x-86h2/GHSA-prqw-x27x-86h2.json index cbf37d09744..ab7033eeb98 100644 --- a/advisories/unreviewed/2024/05/GHSA-prqw-x27x-86h2/GHSA-prqw-x27x-86h2.json +++ b/advisories/unreviewed/2024/05/GHSA-prqw-x27x-86h2/GHSA-prqw-x27x-86h2.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-942" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-pvcr-2c24-m94c/GHSA-pvcr-2c24-m94c.json b/advisories/unreviewed/2024/05/GHSA-pvcr-2c24-m94c/GHSA-pvcr-2c24-m94c.json index e90181a7789..8f34c31e8b3 100644 --- a/advisories/unreviewed/2024/05/GHSA-pvcr-2c24-m94c/GHSA-pvcr-2c24-m94c.json +++ b/advisories/unreviewed/2024/05/GHSA-pvcr-2c24-m94c/GHSA-pvcr-2c24-m94c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pvcr-2c24-m94c", - "modified": "2024-05-14T15:32:54Z", + "modified": "2024-07-03T18:40:27Z", "published": "2024-05-14T15:32:54Z", "aliases": [ "CVE-2024-29165" ], "details": "HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_fletcher32, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:15:33Z" diff --git a/advisories/unreviewed/2024/05/GHSA-q2g7-qm59-84wp/GHSA-q2g7-qm59-84wp.json b/advisories/unreviewed/2024/05/GHSA-q2g7-qm59-84wp/GHSA-q2g7-qm59-84wp.json index 48a2678d295..77be3397ed1 100644 --- a/advisories/unreviewed/2024/05/GHSA-q2g7-qm59-84wp/GHSA-q2g7-qm59-84wp.json +++ b/advisories/unreviewed/2024/05/GHSA-q2g7-qm59-84wp/GHSA-q2g7-qm59-84wp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q2g7-qm59-84wp", - "modified": "2024-05-14T15:32:53Z", + "modified": "2024-07-03T18:40:18Z", "published": "2024-05-14T15:32:53Z", "aliases": [ "CVE-2024-28279" ], "details": "Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via book.php?bookisbn=.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:14:18Z" diff --git a/advisories/unreviewed/2024/05/GHSA-q2hw-c235-rp9r/GHSA-q2hw-c235-rp9r.json b/advisories/unreviewed/2024/05/GHSA-q2hw-c235-rp9r/GHSA-q2hw-c235-rp9r.json index ac0f7b38adb..40f4fef5516 100644 --- a/advisories/unreviewed/2024/05/GHSA-q2hw-c235-rp9r/GHSA-q2hw-c235-rp9r.json +++ b/advisories/unreviewed/2024/05/GHSA-q2hw-c235-rp9r/GHSA-q2hw-c235-rp9r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q2hw-c235-rp9r", - "modified": "2024-06-10T18:30:59Z", + "modified": "2024-07-03T18:40:15Z", "published": "2024-05-14T15:32:53Z", "aliases": [ "CVE-2024-27837" ], "details": "A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sonoma 14.5. A local attacker may gain access to Keychain items.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-280" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:13:07Z" diff --git a/advisories/unreviewed/2024/05/GHSA-q2mm-7g26-cqpf/GHSA-q2mm-7g26-cqpf.json b/advisories/unreviewed/2024/05/GHSA-q2mm-7g26-cqpf/GHSA-q2mm-7g26-cqpf.json index ca3c695aa63..4204f258c11 100644 --- a/advisories/unreviewed/2024/05/GHSA-q2mm-7g26-cqpf/GHSA-q2mm-7g26-cqpf.json +++ b/advisories/unreviewed/2024/05/GHSA-q2mm-7g26-cqpf/GHSA-q2mm-7g26-cqpf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q2mm-7g26-cqpf", - "modified": "2024-05-01T21:30:38Z", + "modified": "2024-07-03T18:38:26Z", "published": "2024-05-01T21:30:38Z", "aliases": [ "CVE-2024-33424" ], "details": "A cross-site scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Downloads parameter under the Language section.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-01T19:15:27Z" diff --git a/advisories/unreviewed/2024/05/GHSA-q3rg-6598-285v/GHSA-q3rg-6598-285v.json b/advisories/unreviewed/2024/05/GHSA-q3rg-6598-285v/GHSA-q3rg-6598-285v.json index 97e2f76ba22..fbaf2bdbcf6 100644 --- a/advisories/unreviewed/2024/05/GHSA-q3rg-6598-285v/GHSA-q3rg-6598-285v.json +++ b/advisories/unreviewed/2024/05/GHSA-q3rg-6598-285v/GHSA-q3rg-6598-285v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q3rg-6598-285v", - "modified": "2024-05-14T15:32:53Z", + "modified": "2024-07-03T18:40:10Z", "published": "2024-05-14T15:32:53Z", "aliases": [ "CVE-2024-27394" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: Fix Use-After-Free in tcp_ao_connect_init\n\nSince call_rcu, which is called in the hlist_for_each_entry_rcu traversal\nof tcp_ao_connect_init, is not part of the RCU read critical section, it\nis possible that the RCU grace period will pass during the traversal and\nthe key will be free.\n\nTo prevent this, it should be changed to hlist_for_each_entry_safe.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:12:27Z" diff --git a/advisories/unreviewed/2024/05/GHSA-q4jw-jxm3-52jh/GHSA-q4jw-jxm3-52jh.json b/advisories/unreviewed/2024/05/GHSA-q4jw-jxm3-52jh/GHSA-q4jw-jxm3-52jh.json index 93ae2b8ec63..548c3b0a3ba 100644 --- a/advisories/unreviewed/2024/05/GHSA-q4jw-jxm3-52jh/GHSA-q4jw-jxm3-52jh.json +++ b/advisories/unreviewed/2024/05/GHSA-q4jw-jxm3-52jh/GHSA-q4jw-jxm3-52jh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q4jw-jxm3-52jh", - "modified": "2024-05-01T21:30:37Z", + "modified": "2024-07-03T18:38:22Z", "published": "2024-05-01T21:30:37Z", "aliases": [ "CVE-2024-22830" ], "details": "Anti-Cheat Expert's Windows kernel module \"ACE-BASE.sys\" version 1.0.2202.6217 does not perform proper access control when handling system resources. This allows a local attacker to escalate privileges from regular user to System or PPL level.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-01T19:15:22Z" diff --git a/advisories/unreviewed/2024/05/GHSA-qwgv-36mc-mpx9/GHSA-qwgv-36mc-mpx9.json b/advisories/unreviewed/2024/05/GHSA-qwgv-36mc-mpx9/GHSA-qwgv-36mc-mpx9.json index bb362823fec..64ce2952d8c 100644 --- a/advisories/unreviewed/2024/05/GHSA-qwgv-36mc-mpx9/GHSA-qwgv-36mc-mpx9.json +++ b/advisories/unreviewed/2024/05/GHSA-qwgv-36mc-mpx9/GHSA-qwgv-36mc-mpx9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qwgv-36mc-mpx9", - "modified": "2024-05-07T18:30:33Z", + "modified": "2024-07-03T18:39:30Z", "published": "2024-05-07T18:30:32Z", "aliases": [ "CVE-2024-33146" ], "details": "J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the export function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T16:15:07Z" diff --git a/advisories/unreviewed/2024/05/GHSA-qwqc-jjwg-53mj/GHSA-qwqc-jjwg-53mj.json b/advisories/unreviewed/2024/05/GHSA-qwqc-jjwg-53mj/GHSA-qwqc-jjwg-53mj.json index 7d72264c60e..1250edaf2bf 100644 --- a/advisories/unreviewed/2024/05/GHSA-qwqc-jjwg-53mj/GHSA-qwqc-jjwg-53mj.json +++ b/advisories/unreviewed/2024/05/GHSA-qwqc-jjwg-53mj/GHSA-qwqc-jjwg-53mj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qwqc-jjwg-53mj", - "modified": "2024-05-03T18:30:37Z", + "modified": "2024-07-03T18:38:50Z", "published": "2024-05-03T18:30:37Z", "aliases": [ "CVE-2024-33792" ], "details": "A cross-site scripting (XSS) vulnerability in netis-systems MEX605 v2.00.06 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the tracert page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-03T17:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-qxcf-7fw9-mhjf/GHSA-qxcf-7fw9-mhjf.json b/advisories/unreviewed/2024/05/GHSA-qxcf-7fw9-mhjf/GHSA-qxcf-7fw9-mhjf.json index 62c6696bcbb..95c97156a46 100644 --- a/advisories/unreviewed/2024/05/GHSA-qxcf-7fw9-mhjf/GHSA-qxcf-7fw9-mhjf.json +++ b/advisories/unreviewed/2024/05/GHSA-qxcf-7fw9-mhjf/GHSA-qxcf-7fw9-mhjf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qxcf-7fw9-mhjf", - "modified": "2024-05-08T15:30:42Z", + "modified": "2024-07-03T18:39:57Z", "published": "2024-05-08T15:30:42Z", "aliases": [ "CVE-2024-25523" ], "details": "RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the file_id parameter at /filemanage/file_memo.aspx.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-08T15:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-qxxc-w5wg-5w4v/GHSA-qxxc-w5wg-5w4v.json b/advisories/unreviewed/2024/05/GHSA-qxxc-w5wg-5w4v/GHSA-qxxc-w5wg-5w4v.json index c0d033fb0aa..c1851a56e31 100644 --- a/advisories/unreviewed/2024/05/GHSA-qxxc-w5wg-5w4v/GHSA-qxxc-w5wg-5w4v.json +++ b/advisories/unreviewed/2024/05/GHSA-qxxc-w5wg-5w4v/GHSA-qxxc-w5wg-5w4v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qxxc-w5wg-5w4v", - "modified": "2024-05-07T21:31:46Z", + "modified": "2024-07-03T18:39:46Z", "published": "2024-05-07T21:31:46Z", "aliases": [ "CVE-2024-0026" ], "details": "In multiple functions of SnoozeHelper.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T21:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-r4j8-j63p-24j8/GHSA-r4j8-j63p-24j8.json b/advisories/unreviewed/2024/05/GHSA-r4j8-j63p-24j8/GHSA-r4j8-j63p-24j8.json index 03c7c95ff9c..ec87054d839 100644 --- a/advisories/unreviewed/2024/05/GHSA-r4j8-j63p-24j8/GHSA-r4j8-j63p-24j8.json +++ b/advisories/unreviewed/2024/05/GHSA-r4j8-j63p-24j8/GHSA-r4j8-j63p-24j8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r4j8-j63p-24j8", - "modified": "2024-06-10T18:30:57Z", + "modified": "2024-07-03T18:39:45Z", "published": "2024-05-07T21:31:45Z", "aliases": [ "CVE-2024-4558" ], "details": "Use after free in ANGLE in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T19:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-r8mx-gcwg-x6f7/GHSA-r8mx-gcwg-x6f7.json b/advisories/unreviewed/2024/05/GHSA-r8mx-gcwg-x6f7/GHSA-r8mx-gcwg-x6f7.json index de50882aaa4..9e98899c3b4 100644 --- a/advisories/unreviewed/2024/05/GHSA-r8mx-gcwg-x6f7/GHSA-r8mx-gcwg-x6f7.json +++ b/advisories/unreviewed/2024/05/GHSA-r8mx-gcwg-x6f7/GHSA-r8mx-gcwg-x6f7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r8mx-gcwg-x6f7", - "modified": "2024-05-06T03:30:47Z", + "modified": "2024-07-03T18:38:59Z", "published": "2024-05-06T03:30:47Z", "aliases": [ "CVE-2024-20058" ], "details": "In keyInstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08580204; Issue ID: ALPS08580204.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-06T03:15:09Z" diff --git a/advisories/unreviewed/2024/05/GHSA-rc9x-h469-w6gc/GHSA-rc9x-h469-w6gc.json b/advisories/unreviewed/2024/05/GHSA-rc9x-h469-w6gc/GHSA-rc9x-h469-w6gc.json index e803d7aad7b..a94eaab7edd 100644 --- a/advisories/unreviewed/2024/05/GHSA-rc9x-h469-w6gc/GHSA-rc9x-h469-w6gc.json +++ b/advisories/unreviewed/2024/05/GHSA-rc9x-h469-w6gc/GHSA-rc9x-h469-w6gc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rc9x-h469-w6gc", - "modified": "2024-06-10T18:30:58Z", + "modified": "2024-07-03T18:40:09Z", "published": "2024-05-14T15:32:52Z", "aliases": [ "CVE-2024-23236" ], "details": "A correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.5. An app may be able to read arbitrary files.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T14:58:48Z" diff --git a/advisories/unreviewed/2024/05/GHSA-rcf6-gj9x-5p73/GHSA-rcf6-gj9x-5p73.json b/advisories/unreviewed/2024/05/GHSA-rcf6-gj9x-5p73/GHSA-rcf6-gj9x-5p73.json index a91be7cb702..a3c161f4901 100644 --- a/advisories/unreviewed/2024/05/GHSA-rcf6-gj9x-5p73/GHSA-rcf6-gj9x-5p73.json +++ b/advisories/unreviewed/2024/05/GHSA-rcf6-gj9x-5p73/GHSA-rcf6-gj9x-5p73.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rcf6-gj9x-5p73", - "modified": "2024-05-14T15:32:53Z", + "modified": "2024-07-03T18:40:10Z", "published": "2024-05-14T15:32:53Z", "aliases": [ "CVE-2024-27790" ], "details": "Claris International has resolved an issue of potentially allowing unauthorized access to records stored in databases hosted on FileMaker Server. This issue has been fixed in FileMaker Server 20.3.2 by validating transactions before replying to client requests.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:13:01Z" diff --git a/advisories/unreviewed/2024/05/GHSA-rf5h-29fq-hr47/GHSA-rf5h-29fq-hr47.json b/advisories/unreviewed/2024/05/GHSA-rf5h-29fq-hr47/GHSA-rf5h-29fq-hr47.json index 9bb2a069942..81647be62d8 100644 --- a/advisories/unreviewed/2024/05/GHSA-rf5h-29fq-hr47/GHSA-rf5h-29fq-hr47.json +++ b/advisories/unreviewed/2024/05/GHSA-rf5h-29fq-hr47/GHSA-rf5h-29fq-hr47.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rf5h-29fq-hr47", - "modified": "2024-05-07T18:30:34Z", + "modified": "2024-07-03T18:39:37Z", "published": "2024-05-07T18:30:34Z", "aliases": [ "CVE-2024-25507" ], "details": "RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the email_attach_id parameter at /LHMail/AttachDown.aspx.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T18:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-rgf9-4hxh-9736/GHSA-rgf9-4hxh-9736.json b/advisories/unreviewed/2024/05/GHSA-rgf9-4hxh-9736/GHSA-rgf9-4hxh-9736.json index 81d14ed45eb..8edbf5ff1b9 100644 --- a/advisories/unreviewed/2024/05/GHSA-rgf9-4hxh-9736/GHSA-rgf9-4hxh-9736.json +++ b/advisories/unreviewed/2024/05/GHSA-rgf9-4hxh-9736/GHSA-rgf9-4hxh-9736.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rgf9-4hxh-9736", - "modified": "2024-05-07T21:31:46Z", + "modified": "2024-07-03T18:39:48Z", "published": "2024-05-07T21:31:46Z", "aliases": [ "CVE-2024-23708" ], "details": "In multiple functions of NotificationManagerService.java, there is a possible way to not show a toast message when a clipboard message has been accessed. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-451" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T21:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-rhq7-7m7h-w8m7/GHSA-rhq7-7m7h-w8m7.json b/advisories/unreviewed/2024/05/GHSA-rhq7-7m7h-w8m7/GHSA-rhq7-7m7h-w8m7.json index c34997c8961..21f9f9b09ca 100644 --- a/advisories/unreviewed/2024/05/GHSA-rhq7-7m7h-w8m7/GHSA-rhq7-7m7h-w8m7.json +++ b/advisories/unreviewed/2024/05/GHSA-rhq7-7m7h-w8m7/GHSA-rhq7-7m7h-w8m7.json @@ -25,7 +25,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-v4vq-27w6-p28p/GHSA-v4vq-27w6-p28p.json b/advisories/unreviewed/2024/05/GHSA-v4vq-27w6-p28p/GHSA-v4vq-27w6-p28p.json index f7e9f24f140..a57edc6d355 100644 --- a/advisories/unreviewed/2024/05/GHSA-v4vq-27w6-p28p/GHSA-v4vq-27w6-p28p.json +++ b/advisories/unreviewed/2024/05/GHSA-v4vq-27w6-p28p/GHSA-v4vq-27w6-p28p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v4vq-27w6-p28p", - "modified": "2024-05-06T18:30:35Z", + "modified": "2024-07-03T18:39:12Z", "published": "2024-05-06T18:30:35Z", "aliases": [ "CVE-2024-34251" ], "details": "An out-of-bound memory read vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cause a denial of service via the \"block_type_get_arity\" function in core/iwasm/interpreter/wasm.h.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-06T16:15:14Z" diff --git a/advisories/unreviewed/2024/05/GHSA-v7jc-fx5p-2j4v/GHSA-v7jc-fx5p-2j4v.json b/advisories/unreviewed/2024/05/GHSA-v7jc-fx5p-2j4v/GHSA-v7jc-fx5p-2j4v.json index 0b44b8c54f8..1523ab9ed08 100644 --- a/advisories/unreviewed/2024/05/GHSA-v7jc-fx5p-2j4v/GHSA-v7jc-fx5p-2j4v.json +++ b/advisories/unreviewed/2024/05/GHSA-v7jc-fx5p-2j4v/GHSA-v7jc-fx5p-2j4v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v7jc-fx5p-2j4v", - "modified": "2024-05-01T21:30:38Z", + "modified": "2024-07-03T18:38:25Z", "published": "2024-05-01T21:30:37Z", "aliases": [ "CVE-2024-33393" ], "details": "An issue in spidernet-io spiderpool v.0.9.3 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-01T19:15:27Z" diff --git a/advisories/unreviewed/2024/05/GHSA-v7x8-wrhv-8rh2/GHSA-v7x8-wrhv-8rh2.json b/advisories/unreviewed/2024/05/GHSA-v7x8-wrhv-8rh2/GHSA-v7x8-wrhv-8rh2.json index 865675e5f28..b739939ba01 100644 --- a/advisories/unreviewed/2024/05/GHSA-v7x8-wrhv-8rh2/GHSA-v7x8-wrhv-8rh2.json +++ b/advisories/unreviewed/2024/05/GHSA-v7x8-wrhv-8rh2/GHSA-v7x8-wrhv-8rh2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v7x8-wrhv-8rh2", - "modified": "2024-06-10T18:30:57Z", + "modified": "2024-07-03T18:38:56Z", "published": "2024-05-05T21:30:31Z", "aliases": [ "CVE-2024-34506" ], "details": "An issue was discovered in includes/specials/SpecialMovePage.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1. If a user with the necessary rights to move the page opens Special:MovePage for a page with tens of thousands of subpages, then the page will exceed the maximum request time, leading to a denial of service.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-05T19:15:07Z" diff --git a/advisories/unreviewed/2024/05/GHSA-v8fc-7564-v98v/GHSA-v8fc-7564-v98v.json b/advisories/unreviewed/2024/05/GHSA-v8fc-7564-v98v/GHSA-v8fc-7564-v98v.json index 6ca80269cf1..ad36b4750a7 100644 --- a/advisories/unreviewed/2024/05/GHSA-v8fc-7564-v98v/GHSA-v8fc-7564-v98v.json +++ b/advisories/unreviewed/2024/05/GHSA-v8fc-7564-v98v/GHSA-v8fc-7564-v98v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v8fc-7564-v98v", - "modified": "2024-05-06T21:30:38Z", + "modified": "2024-07-03T18:39:18Z", "published": "2024-05-06T21:30:38Z", "aliases": [ "CVE-2024-34533" ], "details": "A SQL injection vulnerability in ZI PT Solusi Usaha Mudah Analytic Data Query module (aka izi_data) 11.0 through 17.x before 17.0.3 allows a remote attacker to gain privileges via a query to IZITools::query_check, IZITools::query_fetch, or IZITools::query_execute.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-06T21:15:48Z" diff --git a/advisories/unreviewed/2024/05/GHSA-vf5w-x6g7-5c7q/GHSA-vf5w-x6g7-5c7q.json b/advisories/unreviewed/2024/05/GHSA-vf5w-x6g7-5c7q/GHSA-vf5w-x6g7-5c7q.json index afd0b9cce07..cc0639c2de2 100644 --- a/advisories/unreviewed/2024/05/GHSA-vf5w-x6g7-5c7q/GHSA-vf5w-x6g7-5c7q.json +++ b/advisories/unreviewed/2024/05/GHSA-vf5w-x6g7-5c7q/GHSA-vf5w-x6g7-5c7q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vf5w-x6g7-5c7q", - "modified": "2024-05-06T15:30:39Z", + "modified": "2024-07-03T18:39:08Z", "published": "2024-05-06T15:30:39Z", "aliases": [ "CVE-2024-33113" ], "details": "D-LINK DIR-845L <=v1.01KRb03 is vulnerable to Information disclosurey via bsc_sms_inbox.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-06T15:15:23Z" diff --git a/advisories/unreviewed/2024/05/GHSA-vgjf-wg4r-wfgj/GHSA-vgjf-wg4r-wfgj.json b/advisories/unreviewed/2024/05/GHSA-vgjf-wg4r-wfgj/GHSA-vgjf-wg4r-wfgj.json index 3d6cd470500..4c528a7ad18 100644 --- a/advisories/unreviewed/2024/05/GHSA-vgjf-wg4r-wfgj/GHSA-vgjf-wg4r-wfgj.json +++ b/advisories/unreviewed/2024/05/GHSA-vgjf-wg4r-wfgj/GHSA-vgjf-wg4r-wfgj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vgjf-wg4r-wfgj", - "modified": "2024-05-08T15:30:42Z", + "modified": "2024-07-03T18:39:56Z", "published": "2024-05-08T15:30:42Z", "aliases": [ "CVE-2024-25518" ], "details": "RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the template_id parameter at /WorkFlow/wf_get_fields_approve.aspx.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-08T15:15:07Z" diff --git a/advisories/unreviewed/2024/05/GHSA-vpfw-2qg8-p8w4/GHSA-vpfw-2qg8-p8w4.json b/advisories/unreviewed/2024/05/GHSA-vpfw-2qg8-p8w4/GHSA-vpfw-2qg8-p8w4.json index 3a379f521cc..31293db0688 100644 --- a/advisories/unreviewed/2024/05/GHSA-vpfw-2qg8-p8w4/GHSA-vpfw-2qg8-p8w4.json +++ b/advisories/unreviewed/2024/05/GHSA-vpfw-2qg8-p8w4/GHSA-vpfw-2qg8-p8w4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vpfw-2qg8-p8w4", - "modified": "2024-05-01T21:30:37Z", + "modified": "2024-07-03T18:38:25Z", "published": "2024-05-01T21:30:37Z", "aliases": [ "CVE-2024-33292" ], "details": "SQL Injection vulnerability in Realisation MGSD v.1.0 allows a remote attacker to obtain sensitive information via the id parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-01T19:15:26Z" diff --git a/advisories/unreviewed/2024/05/GHSA-vpvx-qcvr-cpv4/GHSA-vpvx-qcvr-cpv4.json b/advisories/unreviewed/2024/05/GHSA-vpvx-qcvr-cpv4/GHSA-vpvx-qcvr-cpv4.json index 2e17ad555e1..918f3260bce 100644 --- a/advisories/unreviewed/2024/05/GHSA-vpvx-qcvr-cpv4/GHSA-vpvx-qcvr-cpv4.json +++ b/advisories/unreviewed/2024/05/GHSA-vpvx-qcvr-cpv4/GHSA-vpvx-qcvr-cpv4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vpvx-qcvr-cpv4", - "modified": "2024-05-06T18:30:36Z", + "modified": "2024-07-03T18:39:13Z", "published": "2024-05-06T18:30:36Z", "aliases": [ "CVE-2024-33405" ], "details": "SQL injection vulnerability in add_friends.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the friend_index parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L" + } ], "affected": [ @@ -21,13 +24,17 @@ { "type": "WEB", "url": "https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%204.pdf" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%207.pdf" } ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-06T18:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-vq69-6gcm-2ff7/GHSA-vq69-6gcm-2ff7.json b/advisories/unreviewed/2024/05/GHSA-vq69-6gcm-2ff7/GHSA-vq69-6gcm-2ff7.json index 1638c12f705..afefd7405e2 100644 --- a/advisories/unreviewed/2024/05/GHSA-vq69-6gcm-2ff7/GHSA-vq69-6gcm-2ff7.json +++ b/advisories/unreviewed/2024/05/GHSA-vq69-6gcm-2ff7/GHSA-vq69-6gcm-2ff7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vq69-6gcm-2ff7", - "modified": "2024-05-07T21:31:47Z", + "modified": "2024-07-03T18:39:50Z", "published": "2024-05-07T21:31:47Z", "aliases": [ "CVE-2024-23712" ], "details": "In multiple functions of AppOpsService.java, there is a possible way to saturate the content of /data/system/appops_accesses.xml due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T21:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-vxmv-r24r-j66w/GHSA-vxmv-r24r-j66w.json b/advisories/unreviewed/2024/05/GHSA-vxmv-r24r-j66w/GHSA-vxmv-r24r-j66w.json index cb6a728bfbc..5fe3a4d8f00 100644 --- a/advisories/unreviewed/2024/05/GHSA-vxmv-r24r-j66w/GHSA-vxmv-r24r-j66w.json +++ b/advisories/unreviewed/2024/05/GHSA-vxmv-r24r-j66w/GHSA-vxmv-r24r-j66w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vxmv-r24r-j66w", - "modified": "2024-05-07T15:30:40Z", + "modified": "2024-07-03T18:39:25Z", "published": "2024-05-07T15:30:40Z", "aliases": [ "CVE-2024-33124" ], "details": "Roothub v2.6 was discovered to contain a SQL injection vulnerability via the nodeTitle parameter in the parentNode() function..", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T15:15:09Z" diff --git a/advisories/unreviewed/2024/05/GHSA-w2v7-qw4p-jjp9/GHSA-w2v7-qw4p-jjp9.json b/advisories/unreviewed/2024/05/GHSA-w2v7-qw4p-jjp9/GHSA-w2v7-qw4p-jjp9.json index 527a597ea33..f0e0872527f 100644 --- a/advisories/unreviewed/2024/05/GHSA-w2v7-qw4p-jjp9/GHSA-w2v7-qw4p-jjp9.json +++ b/advisories/unreviewed/2024/05/GHSA-w2v7-qw4p-jjp9/GHSA-w2v7-qw4p-jjp9.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-w342-h5p8-hw97/GHSA-w342-h5p8-hw97.json b/advisories/unreviewed/2024/05/GHSA-w342-h5p8-hw97/GHSA-w342-h5p8-hw97.json index 86e373fa0b0..9b1f4241676 100644 --- a/advisories/unreviewed/2024/05/GHSA-w342-h5p8-hw97/GHSA-w342-h5p8-hw97.json +++ b/advisories/unreviewed/2024/05/GHSA-w342-h5p8-hw97/GHSA-w342-h5p8-hw97.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w342-h5p8-hw97", - "modified": "2024-05-14T15:32:54Z", + "modified": "2024-07-03T18:40:26Z", "published": "2024-05-14T15:32:54Z", "aliases": [ "CVE-2024-29163" ], "details": "HDF5 through 1.14.3 contains a heap buffer overflow in H5T__bit_find, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:15:32Z" diff --git a/advisories/unreviewed/2024/05/GHSA-w96c-mpgg-prqv/GHSA-w96c-mpgg-prqv.json b/advisories/unreviewed/2024/05/GHSA-w96c-mpgg-prqv/GHSA-w96c-mpgg-prqv.json index 02ed9d19d47..92ee9814dec 100644 --- a/advisories/unreviewed/2024/05/GHSA-w96c-mpgg-prqv/GHSA-w96c-mpgg-prqv.json +++ b/advisories/unreviewed/2024/05/GHSA-w96c-mpgg-prqv/GHSA-w96c-mpgg-prqv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w96c-mpgg-prqv", - "modified": "2024-05-06T18:30:36Z", + "modified": "2024-07-03T18:39:14Z", "published": "2024-05-06T18:30:36Z", "aliases": [ "CVE-2024-33410" ], "details": "SQL injection vulnerability in /model/delete_range_grade.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the id parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -18,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33410" }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%205.pdf" + }, { "type": "WEB", "url": "https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%209.pdf" @@ -25,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-06T18:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-wcjc-qwhg-vfmr/GHSA-wcjc-qwhg-vfmr.json b/advisories/unreviewed/2024/05/GHSA-wcjc-qwhg-vfmr/GHSA-wcjc-qwhg-vfmr.json index 7243c372a0a..7fdcfca1f74 100644 --- a/advisories/unreviewed/2024/05/GHSA-wcjc-qwhg-vfmr/GHSA-wcjc-qwhg-vfmr.json +++ b/advisories/unreviewed/2024/05/GHSA-wcjc-qwhg-vfmr/GHSA-wcjc-qwhg-vfmr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wcjc-qwhg-vfmr", - "modified": "2024-05-08T15:30:42Z", + "modified": "2024-07-03T18:39:55Z", "published": "2024-05-08T15:30:42Z", "aliases": [ "CVE-2024-25517" ], "details": "RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the tbTable argument at /WebUtility/MF.aspx.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-08T15:15:07Z" diff --git a/advisories/unreviewed/2024/05/GHSA-whmp-p89r-qv54/GHSA-whmp-p89r-qv54.json b/advisories/unreviewed/2024/05/GHSA-whmp-p89r-qv54/GHSA-whmp-p89r-qv54.json index e1b8fc310ff..7cd79e843f0 100644 --- a/advisories/unreviewed/2024/05/GHSA-whmp-p89r-qv54/GHSA-whmp-p89r-qv54.json +++ b/advisories/unreviewed/2024/05/GHSA-whmp-p89r-qv54/GHSA-whmp-p89r-qv54.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-whmp-p89r-qv54", - "modified": "2024-05-07T15:30:39Z", + "modified": "2024-07-03T18:39:24Z", "published": "2024-05-07T15:30:39Z", "aliases": [ "CVE-2024-32371" ], "details": "An issue in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a regular user account to escalate their privileges and gain administrative access by changing the type parameter from 1 to 0.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T15:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-wm6p-93j5-rx57/GHSA-wm6p-93j5-rx57.json b/advisories/unreviewed/2024/05/GHSA-wm6p-93j5-rx57/GHSA-wm6p-93j5-rx57.json index 07380ad5d49..7a4d47385db 100644 --- a/advisories/unreviewed/2024/05/GHSA-wm6p-93j5-rx57/GHSA-wm6p-93j5-rx57.json +++ b/advisories/unreviewed/2024/05/GHSA-wm6p-93j5-rx57/GHSA-wm6p-93j5-rx57.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wm6p-93j5-rx57", - "modified": "2024-06-10T18:30:58Z", + "modified": "2024-07-03T18:40:10Z", "published": "2024-05-14T15:32:53Z", "aliases": [ "CVE-2024-27804" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, tvOS 17.5, watchOS 10.5, macOS Sonoma 14.5. An app may be able to execute arbitrary code with kernel privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -69,9 +72,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1325" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:13:04Z" diff --git a/advisories/unreviewed/2024/05/GHSA-wmq9-769v-mqmc/GHSA-wmq9-769v-mqmc.json b/advisories/unreviewed/2024/05/GHSA-wmq9-769v-mqmc/GHSA-wmq9-769v-mqmc.json index c515d4cc07b..ef962b8f776 100644 --- a/advisories/unreviewed/2024/05/GHSA-wmq9-769v-mqmc/GHSA-wmq9-769v-mqmc.json +++ b/advisories/unreviewed/2024/05/GHSA-wmq9-769v-mqmc/GHSA-wmq9-769v-mqmc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wmq9-769v-mqmc", - "modified": "2024-05-07T21:31:46Z", + "modified": "2024-07-03T18:39:45Z", "published": "2024-05-07T21:31:46Z", "aliases": [ "CVE-2024-0024" ], "details": "In multiple methods of UserManagerService.java, there is a possible failure to persist or enforce user restrictions due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T21:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-wrgh-mmr6-2rm6/GHSA-wrgh-mmr6-2rm6.json b/advisories/unreviewed/2024/05/GHSA-wrgh-mmr6-2rm6/GHSA-wrgh-mmr6-2rm6.json index ce93d33d2ac..099503ffb5c 100644 --- a/advisories/unreviewed/2024/05/GHSA-wrgh-mmr6-2rm6/GHSA-wrgh-mmr6-2rm6.json +++ b/advisories/unreviewed/2024/05/GHSA-wrgh-mmr6-2rm6/GHSA-wrgh-mmr6-2rm6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wrgh-mmr6-2rm6", - "modified": "2024-05-07T15:30:40Z", + "modified": "2024-07-03T18:39:30Z", "published": "2024-05-07T15:30:40Z", "aliases": [ "CVE-2024-34523" ], "details": "AChecker 1.5 allows remote attackers to read the contents of arbitrary files via the download.php path parameter by using Unauthenticated Path Traversal. This occurs through readfile in PHP. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T15:15:09Z" diff --git a/advisories/unreviewed/2024/05/GHSA-wwgc-f5xv-4vvc/GHSA-wwgc-f5xv-4vvc.json b/advisories/unreviewed/2024/05/GHSA-wwgc-f5xv-4vvc/GHSA-wwgc-f5xv-4vvc.json index e430a3cec30..3b3f9e498b4 100644 --- a/advisories/unreviewed/2024/05/GHSA-wwgc-f5xv-4vvc/GHSA-wwgc-f5xv-4vvc.json +++ b/advisories/unreviewed/2024/05/GHSA-wwgc-f5xv-4vvc/GHSA-wwgc-f5xv-4vvc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wwgc-f5xv-4vvc", - "modified": "2024-05-01T21:30:37Z", + "modified": "2024-07-03T18:38:22Z", "published": "2024-05-01T21:30:37Z", "aliases": [ "CVE-2024-24312" ], "details": "SQL injection vulnerability in Vaales Technologies V_QRS v.2024-01-17 allows a remote attacker to obtain sensitive information via the Models/UserModel.php component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-639" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-01T19:15:22Z" diff --git a/advisories/unreviewed/2024/05/GHSA-wwjm-ww5x-84hm/GHSA-wwjm-ww5x-84hm.json b/advisories/unreviewed/2024/05/GHSA-wwjm-ww5x-84hm/GHSA-wwjm-ww5x-84hm.json index b598358468d..a5eec8a494b 100644 --- a/advisories/unreviewed/2024/05/GHSA-wwjm-ww5x-84hm/GHSA-wwjm-ww5x-84hm.json +++ b/advisories/unreviewed/2024/05/GHSA-wwjm-ww5x-84hm/GHSA-wwjm-ww5x-84hm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wwjm-ww5x-84hm", - "modified": "2024-05-02T06:30:31Z", + "modified": "2024-07-03T18:38:32Z", "published": "2024-05-02T06:30:31Z", "aliases": [ "CVE-2024-3472" ], "details": "The Modal Window WordPress plugin before 5.3.10 does not have CSRF check in place when bulk deleting modals, which could allow attackers to make a logged in admin delete them via a CSRF attack", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-02T06:15:50Z" diff --git a/advisories/unreviewed/2024/05/GHSA-wxc5-mwv4-h4hh/GHSA-wxc5-mwv4-h4hh.json b/advisories/unreviewed/2024/05/GHSA-wxc5-mwv4-h4hh/GHSA-wxc5-mwv4-h4hh.json index 1a38c2c2b21..f119c85a618 100644 --- a/advisories/unreviewed/2024/05/GHSA-wxc5-mwv4-h4hh/GHSA-wxc5-mwv4-h4hh.json +++ b/advisories/unreviewed/2024/05/GHSA-wxc5-mwv4-h4hh/GHSA-wxc5-mwv4-h4hh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wxc5-mwv4-h4hh", - "modified": "2024-06-10T18:30:59Z", + "modified": "2024-07-03T18:40:12Z", "published": "2024-05-14T15:32:53Z", "aliases": [ "CVE-2024-27825" ], "details": "A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Sonoma 14.5. An app may be able to bypass certain Privacy preferences.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-277" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:13:06Z" diff --git a/advisories/unreviewed/2024/05/GHSA-x363-pjcf-82m7/GHSA-x363-pjcf-82m7.json b/advisories/unreviewed/2024/05/GHSA-x363-pjcf-82m7/GHSA-x363-pjcf-82m7.json index 11365240013..1f0e1d4929b 100644 --- a/advisories/unreviewed/2024/05/GHSA-x363-pjcf-82m7/GHSA-x363-pjcf-82m7.json +++ b/advisories/unreviewed/2024/05/GHSA-x363-pjcf-82m7/GHSA-x363-pjcf-82m7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x363-pjcf-82m7", - "modified": "2024-05-01T21:30:38Z", + "modified": "2024-07-03T18:38:26Z", "published": "2024-05-01T21:30:38Z", "aliases": [ "CVE-2024-33429" ], "details": "Buffer-Overflow vulnerability at pcm_convert.h:513 of phiola v2.0-rc22 allows a remote attacker to execute arbitrary code via a crafted .wav file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-01T19:15:27Z" diff --git a/advisories/unreviewed/2024/05/GHSA-x7hx-9w3p-f5r3/GHSA-x7hx-9w3p-f5r3.json b/advisories/unreviewed/2024/05/GHSA-x7hx-9w3p-f5r3/GHSA-x7hx-9w3p-f5r3.json index fe6ceef9890..ec1ff942914 100644 --- a/advisories/unreviewed/2024/05/GHSA-x7hx-9w3p-f5r3/GHSA-x7hx-9w3p-f5r3.json +++ b/advisories/unreviewed/2024/05/GHSA-x7hx-9w3p-f5r3/GHSA-x7hx-9w3p-f5r3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x7hx-9w3p-f5r3", - "modified": "2024-05-06T18:30:35Z", + "modified": "2024-07-03T18:39:12Z", "published": "2024-05-06T18:30:35Z", "aliases": [ "CVE-2024-34471" ], "details": "An issue was discovered in HSC Mailinspector 5.2.17-3. A Path Traversal vulnerability (resulting in file deletion) exists in the mliRealtimeEmails.php file. The filename parameter in the export HTML functionality does not properly validate the file location, allowing an attacker to read and delete arbitrary files on the server. This was observed when the mliRealtimeEmails.php file itself was read and subsequently deleted, resulting in a 404 error for the file and disruption of email information loading.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-06T16:15:14Z" diff --git a/advisories/unreviewed/2024/05/GHSA-x7p4-m95h-xjv4/GHSA-x7p4-m95h-xjv4.json b/advisories/unreviewed/2024/05/GHSA-x7p4-m95h-xjv4/GHSA-x7p4-m95h-xjv4.json index 98471bd7573..bdf51008ab5 100644 --- a/advisories/unreviewed/2024/05/GHSA-x7p4-m95h-xjv4/GHSA-x7p4-m95h-xjv4.json +++ b/advisories/unreviewed/2024/05/GHSA-x7p4-m95h-xjv4/GHSA-x7p4-m95h-xjv4.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-xpq8-mc3r-r862/GHSA-xpq8-mc3r-r862.json b/advisories/unreviewed/2024/05/GHSA-xpq8-mc3r-r862/GHSA-xpq8-mc3r-r862.json index 8681d649ca7..f7ec8e3dd40 100644 --- a/advisories/unreviewed/2024/05/GHSA-xpq8-mc3r-r862/GHSA-xpq8-mc3r-r862.json +++ b/advisories/unreviewed/2024/05/GHSA-xpq8-mc3r-r862/GHSA-xpq8-mc3r-r862.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xpq8-mc3r-r862", - "modified": "2024-05-07T21:31:46Z", + "modified": "2024-07-03T18:39:46Z", "published": "2024-05-07T21:31:46Z", "aliases": [ "CVE-2024-23704" ], "details": "In onCreate of WifiDialogActivity.java, there is a possible way to bypass the DISALLOW_ADD_WIFI_CONFIG restriction due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-280" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T21:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-xv27-hp74-6hr9/GHSA-xv27-hp74-6hr9.json b/advisories/unreviewed/2024/05/GHSA-xv27-hp74-6hr9/GHSA-xv27-hp74-6hr9.json index 1ab7487206c..e5f3e9f1beb 100644 --- a/advisories/unreviewed/2024/05/GHSA-xv27-hp74-6hr9/GHSA-xv27-hp74-6hr9.json +++ b/advisories/unreviewed/2024/05/GHSA-xv27-hp74-6hr9/GHSA-xv27-hp74-6hr9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xv27-hp74-6hr9", - "modified": "2024-05-01T21:30:38Z", + "modified": "2024-07-03T18:38:30Z", "published": "2024-05-01T21:30:38Z", "aliases": [ "CVE-2024-33306" ], "details": "SourceCodester Laboratory Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via \"First Name\" parameter in Create User.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-01T20:15:12Z" diff --git a/advisories/unreviewed/2024/05/GHSA-xw4h-q7jg-jqg8/GHSA-xw4h-q7jg-jqg8.json b/advisories/unreviewed/2024/05/GHSA-xw4h-q7jg-jqg8/GHSA-xw4h-q7jg-jqg8.json index 767a20a546d..799550ab8c3 100644 --- a/advisories/unreviewed/2024/05/GHSA-xw4h-q7jg-jqg8/GHSA-xw4h-q7jg-jqg8.json +++ b/advisories/unreviewed/2024/05/GHSA-xw4h-q7jg-jqg8/GHSA-xw4h-q7jg-jqg8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xw4h-q7jg-jqg8", - "modified": "2024-06-11T09:30:58Z", + "modified": "2024-07-03T18:40:10Z", "published": "2024-05-14T15:32:53Z", "aliases": [ "CVE-2024-27796" ], "details": "The issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. An attacker may be able to elevate privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -57,9 +60,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1325" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:13:03Z" diff --git a/advisories/unreviewed/2024/05/GHSA-xw97-mfvw-wc3w/GHSA-xw97-mfvw-wc3w.json b/advisories/unreviewed/2024/05/GHSA-xw97-mfvw-wc3w/GHSA-xw97-mfvw-wc3w.json index c27930d9bb0..00e71e1b490 100644 --- a/advisories/unreviewed/2024/05/GHSA-xw97-mfvw-wc3w/GHSA-xw97-mfvw-wc3w.json +++ b/advisories/unreviewed/2024/05/GHSA-xw97-mfvw-wc3w/GHSA-xw97-mfvw-wc3w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xw97-mfvw-wc3w", - "modified": "2024-05-07T21:31:47Z", + "modified": "2024-07-03T18:39:48Z", "published": "2024-05-07T21:31:46Z", "aliases": [ "CVE-2024-23709" ], "details": "In multiple locations, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T21:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-xxmf-fmx4-hxq3/GHSA-xxmf-fmx4-hxq3.json b/advisories/unreviewed/2024/05/GHSA-xxmf-fmx4-hxq3/GHSA-xxmf-fmx4-hxq3.json index 15242441459..d9de4b6ab8c 100644 --- a/advisories/unreviewed/2024/05/GHSA-xxmf-fmx4-hxq3/GHSA-xxmf-fmx4-hxq3.json +++ b/advisories/unreviewed/2024/05/GHSA-xxmf-fmx4-hxq3/GHSA-xxmf-fmx4-hxq3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xxmf-fmx4-hxq3", - "modified": "2024-05-08T18:30:49Z", + "modified": "2024-07-03T18:40:01Z", "published": "2024-05-08T18:30:49Z", "aliases": [ "CVE-2024-25528" ], "details": "RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /PersonalAffair/worklog_template_show.aspx.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-08T17:15:07Z"