diff --git a/advisories/unreviewed/2024/03/GHSA-3427-99jp-r4g2/GHSA-3427-99jp-r4g2.json b/advisories/unreviewed/2024/03/GHSA-3427-99jp-r4g2/GHSA-3427-99jp-r4g2.json index a6c93a06d4d..5e4a991304c 100644 --- a/advisories/unreviewed/2024/03/GHSA-3427-99jp-r4g2/GHSA-3427-99jp-r4g2.json +++ b/advisories/unreviewed/2024/03/GHSA-3427-99jp-r4g2/GHSA-3427-99jp-r4g2.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-4p27-6j8h-cjhw/GHSA-4p27-6j8h-cjhw.json b/advisories/unreviewed/2024/03/GHSA-4p27-6j8h-cjhw/GHSA-4p27-6j8h-cjhw.json index 80c3f74e0dd..b2cd0526fc3 100644 --- a/advisories/unreviewed/2024/03/GHSA-4p27-6j8h-cjhw/GHSA-4p27-6j8h-cjhw.json +++ b/advisories/unreviewed/2024/03/GHSA-4p27-6j8h-cjhw/GHSA-4p27-6j8h-cjhw.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1021" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-5r5j-mwfc-hgxh/GHSA-5r5j-mwfc-hgxh.json b/advisories/unreviewed/2024/03/GHSA-5r5j-mwfc-hgxh/GHSA-5r5j-mwfc-hgxh.json index 0c064bd28fc..01ee460a0ca 100644 --- a/advisories/unreviewed/2024/03/GHSA-5r5j-mwfc-hgxh/GHSA-5r5j-mwfc-hgxh.json +++ b/advisories/unreviewed/2024/03/GHSA-5r5j-mwfc-hgxh/GHSA-5r5j-mwfc-hgxh.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-453" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-6f5r-w59m-9jm4/GHSA-6f5r-w59m-9jm4.json b/advisories/unreviewed/2024/03/GHSA-6f5r-w59m-9jm4/GHSA-6f5r-w59m-9jm4.json index 6e7f42fd0a9..0840a50af5d 100644 --- a/advisories/unreviewed/2024/03/GHSA-6f5r-w59m-9jm4/GHSA-6f5r-w59m-9jm4.json +++ b/advisories/unreviewed/2024/03/GHSA-6f5r-w59m-9jm4/GHSA-6f5r-w59m-9jm4.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-835" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-94h3-qpxm-r2mp/GHSA-94h3-qpxm-r2mp.json b/advisories/unreviewed/2024/03/GHSA-94h3-qpxm-r2mp/GHSA-94h3-qpxm-r2mp.json index 2f634a41358..8cbebb802e8 100644 --- a/advisories/unreviewed/2024/03/GHSA-94h3-qpxm-r2mp/GHSA-94h3-qpxm-r2mp.json +++ b/advisories/unreviewed/2024/03/GHSA-94h3-qpxm-r2mp/GHSA-94h3-qpxm-r2mp.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-732" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-h3fv-rwfq-5hgg/GHSA-h3fv-rwfq-5hgg.json b/advisories/unreviewed/2024/03/GHSA-h3fv-rwfq-5hgg/GHSA-h3fv-rwfq-5hgg.json index 0cd72058c6c..8aed36edb72 100644 --- a/advisories/unreviewed/2024/03/GHSA-h3fv-rwfq-5hgg/GHSA-h3fv-rwfq-5hgg.json +++ b/advisories/unreviewed/2024/03/GHSA-h3fv-rwfq-5hgg/GHSA-h3fv-rwfq-5hgg.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-h93p-8rwh-9568/GHSA-h93p-8rwh-9568.json b/advisories/unreviewed/2024/03/GHSA-h93p-8rwh-9568/GHSA-h93p-8rwh-9568.json index 30ee4833442..ce8850842c8 100644 --- a/advisories/unreviewed/2024/03/GHSA-h93p-8rwh-9568/GHSA-h93p-8rwh-9568.json +++ b/advisories/unreviewed/2024/03/GHSA-h93p-8rwh-9568/GHSA-h93p-8rwh-9568.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-357" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-pxv9-wjf4-mr7m/GHSA-pxv9-wjf4-mr7m.json b/advisories/unreviewed/2024/03/GHSA-pxv9-wjf4-mr7m/GHSA-pxv9-wjf4-mr7m.json index c5d02d9011c..2c7f5b59597 100644 --- a/advisories/unreviewed/2024/03/GHSA-pxv9-wjf4-mr7m/GHSA-pxv9-wjf4-mr7m.json +++ b/advisories/unreviewed/2024/03/GHSA-pxv9-wjf4-mr7m/GHSA-pxv9-wjf4-mr7m.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1220" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-qcf9-x527-mw6v/GHSA-qcf9-x527-mw6v.json b/advisories/unreviewed/2024/03/GHSA-qcf9-x527-mw6v/GHSA-qcf9-x527-mw6v.json index d5b77a66654..31038623764 100644 --- a/advisories/unreviewed/2024/03/GHSA-qcf9-x527-mw6v/GHSA-qcf9-x527-mw6v.json +++ b/advisories/unreviewed/2024/03/GHSA-qcf9-x527-mw6v/GHSA-qcf9-x527-mw6v.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-693" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-qq9q-r5w2-268r/GHSA-qq9q-r5w2-268r.json b/advisories/unreviewed/2024/03/GHSA-qq9q-r5w2-268r/GHSA-qq9q-r5w2-268r.json index 8c0f0d1ca76..0311551a98a 100644 --- a/advisories/unreviewed/2024/03/GHSA-qq9q-r5w2-268r/GHSA-qq9q-r5w2-268r.json +++ b/advisories/unreviewed/2024/03/GHSA-qq9q-r5w2-268r/GHSA-qq9q-r5w2-268r.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-vp94-mx6w-4h86/GHSA-vp94-mx6w-4h86.json b/advisories/unreviewed/2024/03/GHSA-vp94-mx6w-4h86/GHSA-vp94-mx6w-4h86.json index 3be3bde9a24..3f3cf5799fb 100644 --- a/advisories/unreviewed/2024/03/GHSA-vp94-mx6w-4h86/GHSA-vp94-mx6w-4h86.json +++ b/advisories/unreviewed/2024/03/GHSA-vp94-mx6w-4h86/GHSA-vp94-mx6w-4h86.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-wgrh-qrr7-qq96/GHSA-wgrh-qrr7-qq96.json b/advisories/unreviewed/2024/03/GHSA-wgrh-qrr7-qq96/GHSA-wgrh-qrr7-qq96.json index 94a55e4419f..6f2883703db 100644 --- a/advisories/unreviewed/2024/03/GHSA-wgrh-qrr7-qq96/GHSA-wgrh-qrr7-qq96.json +++ b/advisories/unreviewed/2024/03/GHSA-wgrh-qrr7-qq96/GHSA-wgrh-qrr7-qq96.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-367" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-66x4-8vc7-5pm4/GHSA-66x4-8vc7-5pm4.json b/advisories/unreviewed/2024/04/GHSA-66x4-8vc7-5pm4/GHSA-66x4-8vc7-5pm4.json index 02f60fd7587..86f66c2e04f 100644 --- a/advisories/unreviewed/2024/04/GHSA-66x4-8vc7-5pm4/GHSA-66x4-8vc7-5pm4.json +++ b/advisories/unreviewed/2024/04/GHSA-66x4-8vc7-5pm4/GHSA-66x4-8vc7-5pm4.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-359" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-xf94-mpvp-r8x2/GHSA-xf94-mpvp-r8x2.json b/advisories/unreviewed/2024/05/GHSA-xf94-mpvp-r8x2/GHSA-xf94-mpvp-r8x2.json index e2e2ca613c7..c53a733e807 100644 --- a/advisories/unreviewed/2024/05/GHSA-xf94-mpvp-r8x2/GHSA-xf94-mpvp-r8x2.json +++ b/advisories/unreviewed/2024/05/GHSA-xf94-mpvp-r8x2/GHSA-xf94-mpvp-r8x2.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-693" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-27r3-85x4-pfqv/GHSA-27r3-85x4-pfqv.json b/advisories/unreviewed/2024/06/GHSA-27r3-85x4-pfqv/GHSA-27r3-85x4-pfqv.json index 65c68a5932d..12906e53a5b 100644 --- a/advisories/unreviewed/2024/06/GHSA-27r3-85x4-pfqv/GHSA-27r3-85x4-pfqv.json +++ b/advisories/unreviewed/2024/06/GHSA-27r3-85x4-pfqv/GHSA-27r3-85x4-pfqv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-27r3-85x4-pfqv", - "modified": "2024-06-05T06:30:40Z", + "modified": "2024-06-11T18:30:42Z", "published": "2024-06-05T06:30:40Z", "aliases": [ "CVE-2024-4886" ], "details": "The contains an IDOR vulnerability that allows a user to comment on a private post by manipulating the ID included in the request", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-639" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-05T06:15:12Z" diff --git a/advisories/unreviewed/2024/06/GHSA-28hg-rww5-ghhq/GHSA-28hg-rww5-ghhq.json b/advisories/unreviewed/2024/06/GHSA-28hg-rww5-ghhq/GHSA-28hg-rww5-ghhq.json index 52057566ea2..43762562900 100644 --- a/advisories/unreviewed/2024/06/GHSA-28hg-rww5-ghhq/GHSA-28hg-rww5-ghhq.json +++ b/advisories/unreviewed/2024/06/GHSA-28hg-rww5-ghhq/GHSA-28hg-rww5-ghhq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-28hg-rww5-ghhq", - "modified": "2024-06-05T09:30:37Z", + "modified": "2024-06-11T18:30:43Z", "published": "2024-06-05T09:30:37Z", "aliases": [ "CVE-2024-5006" @@ -44,7 +44,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-2vp4-2rgc-wf9w/GHSA-2vp4-2rgc-wf9w.json b/advisories/unreviewed/2024/06/GHSA-2vp4-2rgc-wf9w/GHSA-2vp4-2rgc-wf9w.json index 30040d84e4f..97609ac9310 100644 --- a/advisories/unreviewed/2024/06/GHSA-2vp4-2rgc-wf9w/GHSA-2vp4-2rgc-wf9w.json +++ b/advisories/unreviewed/2024/06/GHSA-2vp4-2rgc-wf9w/GHSA-2vp4-2rgc-wf9w.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-863" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-32f8-hmr3-7vxg/GHSA-32f8-hmr3-7vxg.json b/advisories/unreviewed/2024/06/GHSA-32f8-hmr3-7vxg/GHSA-32f8-hmr3-7vxg.json new file mode 100644 index 00000000000..c875e8a52d9 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-32f8-hmr3-7vxg/GHSA-32f8-hmr3-7vxg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-32f8-hmr3-7vxg", + "modified": "2024-06-11T18:30:50Z", + "published": "2024-06-11T18:30:50Z", + "aliases": [ + "CVE-2024-35252" + ], + "details": "Azure Storage Movement Client Library Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35252" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-35252" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1104" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-3794-gcgw-37cm/GHSA-3794-gcgw-37cm.json b/advisories/unreviewed/2024/06/GHSA-3794-gcgw-37cm/GHSA-3794-gcgw-37cm.json new file mode 100644 index 00000000000..f302f50e713 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-3794-gcgw-37cm/GHSA-3794-gcgw-37cm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3794-gcgw-37cm", + "modified": "2024-06-11T18:30:47Z", + "published": "2024-06-11T18:30:47Z", + "aliases": [ + "CVE-2024-30065" + ], + "details": "Windows Themes Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30065" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30065" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-3j97-8r9f-j629/GHSA-3j97-8r9f-j629.json b/advisories/unreviewed/2024/06/GHSA-3j97-8r9f-j629/GHSA-3j97-8r9f-j629.json new file mode 100644 index 00000000000..ca8482b1f37 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-3j97-8r9f-j629/GHSA-3j97-8r9f-j629.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3j97-8r9f-j629", + "modified": "2024-06-11T18:30:50Z", + "published": "2024-06-11T18:30:50Z", + "aliases": [ + "CVE-2024-34804" + ], + "details": "Missing Authorization vulnerability in Tagembed.This issue affects Tagembed: from n/a through 5.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34804" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/tagembed-widget/wordpress-tagembed-plugin-5-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-3jf9-w25v-mfp4/GHSA-3jf9-w25v-mfp4.json b/advisories/unreviewed/2024/06/GHSA-3jf9-w25v-mfp4/GHSA-3jf9-w25v-mfp4.json new file mode 100644 index 00000000000..8f44bd72abe --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-3jf9-w25v-mfp4/GHSA-3jf9-w25v-mfp4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3jf9-w25v-mfp4", + "modified": "2024-06-11T18:30:49Z", + "published": "2024-06-11T18:30:49Z", + "aliases": [ + "CVE-2024-30102" + ], + "details": "Microsoft Office Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30102" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30102" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-3rvp-xpmc-fgrf/GHSA-3rvp-xpmc-fgrf.json b/advisories/unreviewed/2024/06/GHSA-3rvp-xpmc-fgrf/GHSA-3rvp-xpmc-fgrf.json new file mode 100644 index 00000000000..9ece3d8521f --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-3rvp-xpmc-fgrf/GHSA-3rvp-xpmc-fgrf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3rvp-xpmc-fgrf", + "modified": "2024-06-11T18:30:49Z", + "published": "2024-06-11T18:30:49Z", + "aliases": [ + "CVE-2024-30097" + ], + "details": "Microsoft Speech Application Programming Interface (SAPI) Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30097" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30097" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-415" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-3v9h-v2jm-73mm/GHSA-3v9h-v2jm-73mm.json b/advisories/unreviewed/2024/06/GHSA-3v9h-v2jm-73mm/GHSA-3v9h-v2jm-73mm.json index dc2aa9f30e1..08e3aee35be 100644 --- a/advisories/unreviewed/2024/06/GHSA-3v9h-v2jm-73mm/GHSA-3v9h-v2jm-73mm.json +++ b/advisories/unreviewed/2024/06/GHSA-3v9h-v2jm-73mm/GHSA-3v9h-v2jm-73mm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3v9h-v2jm-73mm", - "modified": "2024-06-05T00:30:48Z", + "modified": "2024-06-11T18:30:42Z", "published": "2024-06-05T00:30:48Z", "aliases": [ "CVE-2022-28654" ], "details": "is_closing_session() allows users to fill up apport.log", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-770" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-04T22:15:09Z" diff --git a/advisories/unreviewed/2024/06/GHSA-3w78-v9jq-vw22/GHSA-3w78-v9jq-vw22.json b/advisories/unreviewed/2024/06/GHSA-3w78-v9jq-vw22/GHSA-3w78-v9jq-vw22.json index ffe189ad4c3..8f2d0d9e471 100644 --- a/advisories/unreviewed/2024/06/GHSA-3w78-v9jq-vw22/GHSA-3w78-v9jq-vw22.json +++ b/advisories/unreviewed/2024/06/GHSA-3w78-v9jq-vw22/GHSA-3w78-v9jq-vw22.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-3w89-hgwc-85v8/GHSA-3w89-hgwc-85v8.json b/advisories/unreviewed/2024/06/GHSA-3w89-hgwc-85v8/GHSA-3w89-hgwc-85v8.json new file mode 100644 index 00000000000..690d25b7cd9 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-3w89-hgwc-85v8/GHSA-3w89-hgwc-85v8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3w89-hgwc-85v8", + "modified": "2024-06-11T18:30:50Z", + "published": "2024-06-11T18:30:49Z", + "aliases": [ + "CVE-2024-32146" + ], + "details": "Missing Authorization vulnerability in Aspose.Cloud Marketplace Aspose.Words Exporter.This issue affects Aspose.Words Exporter: from n/a through 6.3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32146" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/aspose-doc-exporter/wordpress-aspose-words-import-and-export-word-documents-plugin-6-3-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-42c4-g7jf-379h/GHSA-42c4-g7jf-379h.json b/advisories/unreviewed/2024/06/GHSA-42c4-g7jf-379h/GHSA-42c4-g7jf-379h.json new file mode 100644 index 00000000000..34dee6a2a81 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-42c4-g7jf-379h/GHSA-42c4-g7jf-379h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-42c4-g7jf-379h", + "modified": "2024-06-11T18:30:45Z", + "published": "2024-06-11T18:30:45Z", + "aliases": [ + "CVE-2024-23521" + ], + "details": "Missing Authorization vulnerability in Happyforms.This issue affects Happyforms: from n/a through 1.25.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23521" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/happyforms/wordpress-happyforms-plugin-1-25-10-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T16:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-43r8-23m5-329f/GHSA-43r8-23m5-329f.json b/advisories/unreviewed/2024/06/GHSA-43r8-23m5-329f/GHSA-43r8-23m5-329f.json new file mode 100644 index 00000000000..567b016b685 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-43r8-23m5-329f/GHSA-43r8-23m5-329f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-43r8-23m5-329f", + "modified": "2024-06-11T18:30:49Z", + "published": "2024-06-11T18:30:49Z", + "aliases": [ + "CVE-2024-30103" + ], + "details": "Microsoft Outlook Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30103" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30103" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-184" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-47g9-gpgw-3pq5/GHSA-47g9-gpgw-3pq5.json b/advisories/unreviewed/2024/06/GHSA-47g9-gpgw-3pq5/GHSA-47g9-gpgw-3pq5.json index d15f86c1e3b..61e5a1d2036 100644 --- a/advisories/unreviewed/2024/06/GHSA-47g9-gpgw-3pq5/GHSA-47g9-gpgw-3pq5.json +++ b/advisories/unreviewed/2024/06/GHSA-47g9-gpgw-3pq5/GHSA-47g9-gpgw-3pq5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-47g9-gpgw-3pq5", - "modified": "2024-06-05T09:30:37Z", + "modified": "2024-06-11T18:30:43Z", "published": "2024-06-05T09:30:37Z", "aliases": [ "CVE-2024-4088" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-4cv3-4q3c-54v6/GHSA-4cv3-4q3c-54v6.json b/advisories/unreviewed/2024/06/GHSA-4cv3-4q3c-54v6/GHSA-4cv3-4q3c-54v6.json new file mode 100644 index 00000000000..dbe02f906b6 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-4cv3-4q3c-54v6/GHSA-4cv3-4q3c-54v6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4cv3-4q3c-54v6", + "modified": "2024-06-11T18:30:45Z", + "published": "2024-06-11T18:30:45Z", + "aliases": [ + "CVE-2024-34821" + ], + "details": "Missing Authorization vulnerability in Contact List PRO Contact List – Easy Business Directory, Staff Directory and Address Book Plugin.This issue affects Contact List – Easy Business Directory, Staff Directory and Address Book Plugin: from n/a through 2.9.87.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34821" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/contact-list/wordpress-contact-list-plugin-2-9-87-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-4cvv-4v6h-5hq7/GHSA-4cvv-4v6h-5hq7.json b/advisories/unreviewed/2024/06/GHSA-4cvv-4v6h-5hq7/GHSA-4cvv-4v6h-5hq7.json new file mode 100644 index 00000000000..44f580927c2 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-4cvv-4v6h-5hq7/GHSA-4cvv-4v6h-5hq7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4cvv-4v6h-5hq7", + "modified": "2024-06-11T18:30:49Z", + "published": "2024-06-11T18:30:49Z", + "aliases": [ + "CVE-2024-30075" + ], + "details": "Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30075" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30075" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-4jhp-wp6w-jm5x/GHSA-4jhp-wp6w-jm5x.json b/advisories/unreviewed/2024/06/GHSA-4jhp-wp6w-jm5x/GHSA-4jhp-wp6w-jm5x.json new file mode 100644 index 00000000000..b0c28be6b80 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-4jhp-wp6w-jm5x/GHSA-4jhp-wp6w-jm5x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4jhp-wp6w-jm5x", + "modified": "2024-06-11T18:30:49Z", + "published": "2024-06-11T18:30:49Z", + "aliases": [ + "CVE-2024-30070" + ], + "details": "DHCP Server Service Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30070" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30070" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-191" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-4p3j-h7w5-q76v/GHSA-4p3j-h7w5-q76v.json b/advisories/unreviewed/2024/06/GHSA-4p3j-h7w5-q76v/GHSA-4p3j-h7w5-q76v.json new file mode 100644 index 00000000000..d9cb19f3ed3 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-4p3j-h7w5-q76v/GHSA-4p3j-h7w5-q76v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4p3j-h7w5-q76v", + "modified": "2024-06-11T18:30:46Z", + "published": "2024-06-11T18:30:46Z", + "aliases": [ + "CVE-2024-5813" + ], + "details": "A medium severity vulnerability in BIPS has been identified where an authenticated attacker with high privileges can access the SSH private keys via an information leak in the server response.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5813" + }, + { + "type": "WEB", + "url": "https://www.beyondtrust.com/trust-center/security-advisories/bt24-08" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T16:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-4pgv-p58j-ghpx/GHSA-4pgv-p58j-ghpx.json b/advisories/unreviewed/2024/06/GHSA-4pgv-p58j-ghpx/GHSA-4pgv-p58j-ghpx.json index 9e4c538983c..ab182c7108a 100644 --- a/advisories/unreviewed/2024/06/GHSA-4pgv-p58j-ghpx/GHSA-4pgv-p58j-ghpx.json +++ b/advisories/unreviewed/2024/06/GHSA-4pgv-p58j-ghpx/GHSA-4pgv-p58j-ghpx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4pgv-p58j-ghpx", - "modified": "2024-06-05T00:30:48Z", + "modified": "2024-06-11T18:30:42Z", "published": "2024-06-05T00:30:48Z", "aliases": [ "CVE-2022-28658" ], "details": "Apport argument parsing mishandles filename splitting on older kernels resulting in argument spoofing", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-04T22:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-4v9w-chqg-3pgp/GHSA-4v9w-chqg-3pgp.json b/advisories/unreviewed/2024/06/GHSA-4v9w-chqg-3pgp/GHSA-4v9w-chqg-3pgp.json new file mode 100644 index 00000000000..648d561115c --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-4v9w-chqg-3pgp/GHSA-4v9w-chqg-3pgp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4v9w-chqg-3pgp", + "modified": "2024-06-11T18:30:46Z", + "published": "2024-06-11T18:30:46Z", + "aliases": [ + "CVE-2024-26330" + ], + "details": "An issue was discovered in Kape CyberGhostVPN 8.4.3.12823 on Windows. After a successful logout, user credentials remain in memory while the process is still open, and can be obtained by dumping the process memory and parsing it.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26330" + }, + { + "type": "WEB", + "url": "https://www.secuvera.de/advisories/secuvera-SA-2024-04.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-529f-v746-9vhc/GHSA-529f-v746-9vhc.json b/advisories/unreviewed/2024/06/GHSA-529f-v746-9vhc/GHSA-529f-v746-9vhc.json index dff0b00969e..a8f60c40a61 100644 --- a/advisories/unreviewed/2024/06/GHSA-529f-v746-9vhc/GHSA-529f-v746-9vhc.json +++ b/advisories/unreviewed/2024/06/GHSA-529f-v746-9vhc/GHSA-529f-v746-9vhc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-529f-v746-9vhc", - "modified": "2024-06-06T12:30:36Z", + "modified": "2024-06-11T18:30:43Z", "published": "2024-06-06T12:30:36Z", "aliases": [ "CVE-2024-5259" @@ -40,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-53r7-4q94-9fmr/GHSA-53r7-4q94-9fmr.json b/advisories/unreviewed/2024/06/GHSA-53r7-4q94-9fmr/GHSA-53r7-4q94-9fmr.json index e0c8e28ab47..48f659ea1a0 100644 --- a/advisories/unreviewed/2024/06/GHSA-53r7-4q94-9fmr/GHSA-53r7-4q94-9fmr.json +++ b/advisories/unreviewed/2024/06/GHSA-53r7-4q94-9fmr/GHSA-53r7-4q94-9fmr.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-5527-jp3f-385g/GHSA-5527-jp3f-385g.json b/advisories/unreviewed/2024/06/GHSA-5527-jp3f-385g/GHSA-5527-jp3f-385g.json new file mode 100644 index 00000000000..a3ee2112d69 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-5527-jp3f-385g/GHSA-5527-jp3f-385g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5527-jp3f-385g", + "modified": "2024-06-11T18:30:50Z", + "published": "2024-06-11T18:30:50Z", + "aliases": [ + "CVE-2024-34799" + ], + "details": "Missing Authorization vulnerability in Repute Infosystems BookingPress.This issue affects BookingPress: from n/a through 1.0.82.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34799" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/bookingpress-appointment-booking/wordpress-bookingpress-plugin-1-0-82-appointment-duration-manipulation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-56wc-mcj7-v9hm/GHSA-56wc-mcj7-v9hm.json b/advisories/unreviewed/2024/06/GHSA-56wc-mcj7-v9hm/GHSA-56wc-mcj7-v9hm.json new file mode 100644 index 00000000000..338f9f110b3 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-56wc-mcj7-v9hm/GHSA-56wc-mcj7-v9hm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-56wc-mcj7-v9hm", + "modified": "2024-06-11T18:30:49Z", + "published": "2024-06-11T18:30:49Z", + "aliases": [ + "CVE-2024-30093" + ], + "details": "Windows Storage Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30093" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30093" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-5ww8-4ghx-pvcr/GHSA-5ww8-4ghx-pvcr.json b/advisories/unreviewed/2024/06/GHSA-5ww8-4ghx-pvcr/GHSA-5ww8-4ghx-pvcr.json index b2921675b0f..181a7da1d06 100644 --- a/advisories/unreviewed/2024/06/GHSA-5ww8-4ghx-pvcr/GHSA-5ww8-4ghx-pvcr.json +++ b/advisories/unreviewed/2024/06/GHSA-5ww8-4ghx-pvcr/GHSA-5ww8-4ghx-pvcr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5ww8-4ghx-pvcr", - "modified": "2024-06-07T15:30:38Z", + "modified": "2024-06-11T18:30:44Z", "published": "2024-06-07T15:30:38Z", "aliases": [ "CVE-2024-36673" ], "details": "Sourcecodester Pharmacy/Medical Store Point of Sale System 1.0 is vulnerable SQL Injection via login.php. This vulnerability stems from inadequate validation of user inputs for the email and password parameters, allowing attackers to inject malicious SQL queries.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-07T13:15:49Z" diff --git a/advisories/unreviewed/2024/06/GHSA-62pf-2c82-x5xc/GHSA-62pf-2c82-x5xc.json b/advisories/unreviewed/2024/06/GHSA-62pf-2c82-x5xc/GHSA-62pf-2c82-x5xc.json new file mode 100644 index 00000000000..506de792c46 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-62pf-2c82-x5xc/GHSA-62pf-2c82-x5xc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62pf-2c82-x5xc", + "modified": "2024-06-11T18:30:49Z", + "published": "2024-06-11T18:30:49Z", + "aliases": [ + "CVE-2024-30100" + ], + "details": "Microsoft SharePoint Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30100" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30100" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-426" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-63f6-cjxm-wf36/GHSA-63f6-cjxm-wf36.json b/advisories/unreviewed/2024/06/GHSA-63f6-cjxm-wf36/GHSA-63f6-cjxm-wf36.json new file mode 100644 index 00000000000..4ce6123216e --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-63f6-cjxm-wf36/GHSA-63f6-cjxm-wf36.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-63f6-cjxm-wf36", + "modified": "2024-06-11T18:30:48Z", + "published": "2024-06-11T18:30:48Z", + "aliases": [ + "CVE-2024-30069" + ], + "details": "Windows Remote Access Connection Manager Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30069" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30069" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-63mj-hr86-9cpw/GHSA-63mj-hr86-9cpw.json b/advisories/unreviewed/2024/06/GHSA-63mj-hr86-9cpw/GHSA-63mj-hr86-9cpw.json new file mode 100644 index 00000000000..a942da13e61 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-63mj-hr86-9cpw/GHSA-63mj-hr86-9cpw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-63mj-hr86-9cpw", + "modified": "2024-06-11T18:30:49Z", + "published": "2024-06-11T18:30:49Z", + "aliases": [ + "CVE-2024-30076" + ], + "details": "Windows Container Manager Service Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30076" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30076" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-67jv-rwrr-72fv/GHSA-67jv-rwrr-72fv.json b/advisories/unreviewed/2024/06/GHSA-67jv-rwrr-72fv/GHSA-67jv-rwrr-72fv.json new file mode 100644 index 00000000000..173c1b54220 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-67jv-rwrr-72fv/GHSA-67jv-rwrr-72fv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-67jv-rwrr-72fv", + "modified": "2024-06-11T18:30:49Z", + "published": "2024-06-11T18:30:49Z", + "aliases": [ + "CVE-2024-30074" + ], + "details": "Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30074" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30074" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-6fjg-5w3q-x6m9/GHSA-6fjg-5w3q-x6m9.json b/advisories/unreviewed/2024/06/GHSA-6fjg-5w3q-x6m9/GHSA-6fjg-5w3q-x6m9.json index 8ad93a5f654..68cc97284a5 100644 --- a/advisories/unreviewed/2024/06/GHSA-6fjg-5w3q-x6m9/GHSA-6fjg-5w3q-x6m9.json +++ b/advisories/unreviewed/2024/06/GHSA-6fjg-5w3q-x6m9/GHSA-6fjg-5w3q-x6m9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6fjg-5w3q-x6m9", - "modified": "2024-06-05T00:30:49Z", + "modified": "2024-06-11T18:30:42Z", "published": "2024-06-05T00:30:49Z", "aliases": [ "CVE-2024-36675" ], "details": "LyLme_spage v1.9.5 is vulnerable to Server-Side Request Forgery (SSRF) via the get_head function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-918" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-04T22:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-6g9j-jj95-v2qh/GHSA-6g9j-jj95-v2qh.json b/advisories/unreviewed/2024/06/GHSA-6g9j-jj95-v2qh/GHSA-6g9j-jj95-v2qh.json new file mode 100644 index 00000000000..677936d6974 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-6g9j-jj95-v2qh/GHSA-6g9j-jj95-v2qh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6g9j-jj95-v2qh", + "modified": "2024-06-11T18:30:46Z", + "published": "2024-06-11T18:30:46Z", + "aliases": [ + "CVE-2024-23518" + ], + "details": "Missing Authorization vulnerability in Navneil Naicker ACF Photo Gallery Field.This issue affects ACF Photo Gallery Field: from n/a through 2.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23518" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/navz-photo-gallery/wordpress-acf-photo-gallery-field-plugin-2-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-6pm8-gh62-gqgq/GHSA-6pm8-gh62-gqgq.json b/advisories/unreviewed/2024/06/GHSA-6pm8-gh62-gqgq/GHSA-6pm8-gh62-gqgq.json index 53cd8b015cd..d90ab85ada3 100644 --- a/advisories/unreviewed/2024/06/GHSA-6pm8-gh62-gqgq/GHSA-6pm8-gh62-gqgq.json +++ b/advisories/unreviewed/2024/06/GHSA-6pm8-gh62-gqgq/GHSA-6pm8-gh62-gqgq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6pm8-gh62-gqgq", - "modified": "2024-06-07T09:30:45Z", + "modified": "2024-06-11T18:30:44Z", "published": "2024-06-07T09:30:45Z", "aliases": [ "CVE-2024-4488" @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-6vjr-4r2m-7pgg/GHSA-6vjr-4r2m-7pgg.json b/advisories/unreviewed/2024/06/GHSA-6vjr-4r2m-7pgg/GHSA-6vjr-4r2m-7pgg.json new file mode 100644 index 00000000000..65847d6f619 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-6vjr-4r2m-7pgg/GHSA-6vjr-4r2m-7pgg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6vjr-4r2m-7pgg", + "modified": "2024-06-11T18:30:45Z", + "published": "2024-06-11T18:30:45Z", + "aliases": [ + "CVE-2023-52233" + ], + "details": "Missing Authorization vulnerability in Post SMTP Post SMTP Mailer/Email Log.This issue affects Post SMTP Mailer/Email Log: from n/a through 2.8.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52233" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/post-smtp/wordpress-post-smtp-mailer-plugin-2-8-6-broken-access-control-on-api-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T16:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-74g2-v5gc-hj7f/GHSA-74g2-v5gc-hj7f.json b/advisories/unreviewed/2024/06/GHSA-74g2-v5gc-hj7f/GHSA-74g2-v5gc-hj7f.json index e96f1edc914..fb34cc4d6cb 100644 --- a/advisories/unreviewed/2024/06/GHSA-74g2-v5gc-hj7f/GHSA-74g2-v5gc-hj7f.json +++ b/advisories/unreviewed/2024/06/GHSA-74g2-v5gc-hj7f/GHSA-74g2-v5gc-hj7f.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-79m6-3vj5-mrf7/GHSA-79m6-3vj5-mrf7.json b/advisories/unreviewed/2024/06/GHSA-79m6-3vj5-mrf7/GHSA-79m6-3vj5-mrf7.json new file mode 100644 index 00000000000..6ddf1097a51 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-79m6-3vj5-mrf7/GHSA-79m6-3vj5-mrf7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-79m6-3vj5-mrf7", + "modified": "2024-06-11T18:30:49Z", + "published": "2024-06-11T18:30:49Z", + "aliases": [ + "CVE-2024-30077" + ], + "details": "Windows OLE Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30077" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30077" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-7qc9-w7hr-g8w8/GHSA-7qc9-w7hr-g8w8.json b/advisories/unreviewed/2024/06/GHSA-7qc9-w7hr-g8w8/GHSA-7qc9-w7hr-g8w8.json index af160d6fb57..964df5244f9 100644 --- a/advisories/unreviewed/2024/06/GHSA-7qc9-w7hr-g8w8/GHSA-7qc9-w7hr-g8w8.json +++ b/advisories/unreviewed/2024/06/GHSA-7qc9-w7hr-g8w8/GHSA-7qc9-w7hr-g8w8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7qc9-w7hr-g8w8", - "modified": "2024-06-05T09:30:37Z", + "modified": "2024-06-11T18:30:43Z", "published": "2024-06-05T09:30:37Z", "aliases": [ "CVE-2024-4743" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-7rw2-4f63-2rgv/GHSA-7rw2-4f63-2rgv.json b/advisories/unreviewed/2024/06/GHSA-7rw2-4f63-2rgv/GHSA-7rw2-4f63-2rgv.json new file mode 100644 index 00000000000..0fc00871a81 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-7rw2-4f63-2rgv/GHSA-7rw2-4f63-2rgv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7rw2-4f63-2rgv", + "modified": "2024-06-11T18:30:49Z", + "published": "2024-06-11T18:30:49Z", + "aliases": [ + "CVE-2024-32143" + ], + "details": "Missing Authorization vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through 4.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32143" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/podlove-podcasting-plugin-for-wordpress/wordpress-podlove-podcast-publisher-plugin-4-1-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-7vgh-977h-8447/GHSA-7vgh-977h-8447.json b/advisories/unreviewed/2024/06/GHSA-7vgh-977h-8447/GHSA-7vgh-977h-8447.json new file mode 100644 index 00000000000..5c3efd98030 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-7vgh-977h-8447/GHSA-7vgh-977h-8447.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7vgh-977h-8447", + "modified": "2024-06-11T18:30:49Z", + "published": "2024-06-11T18:30:49Z", + "aliases": [ + "CVE-2024-30099" + ], + "details": "Windows Kernel Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30099" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30099" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-7wvq-94hq-j88h/GHSA-7wvq-94hq-j88h.json b/advisories/unreviewed/2024/06/GHSA-7wvq-94hq-j88h/GHSA-7wvq-94hq-j88h.json new file mode 100644 index 00000000000..68bba295ca8 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-7wvq-94hq-j88h/GHSA-7wvq-94hq-j88h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7wvq-94hq-j88h", + "modified": "2024-06-11T18:30:46Z", + "published": "2024-06-11T18:30:46Z", + "aliases": [ + "CVE-2024-30052" + ], + "details": "Visual Studio Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30052" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30052" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-693" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-88fw-39x9-cwgp/GHSA-88fw-39x9-cwgp.json b/advisories/unreviewed/2024/06/GHSA-88fw-39x9-cwgp/GHSA-88fw-39x9-cwgp.json new file mode 100644 index 00000000000..2c854ce924b --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-88fw-39x9-cwgp/GHSA-88fw-39x9-cwgp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-88fw-39x9-cwgp", + "modified": "2024-06-11T18:30:45Z", + "published": "2024-06-11T18:30:45Z", + "aliases": [ + "CVE-2024-32144" + ], + "details": "Missing Authorization vulnerability in Welcart Inc. Welcart e-Commerce.This issue affects Welcart e-Commerce: from n/a through 2.9.14.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32144" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/usc-e-shop/wordpress-welcart-e-commerce-plugin-2-9-14-broken-access-control-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T16:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-8frr-g94g-3xh7/GHSA-8frr-g94g-3xh7.json b/advisories/unreviewed/2024/06/GHSA-8frr-g94g-3xh7/GHSA-8frr-g94g-3xh7.json new file mode 100644 index 00000000000..085e40445f7 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-8frr-g94g-3xh7/GHSA-8frr-g94g-3xh7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8frr-g94g-3xh7", + "modified": "2024-06-11T18:30:49Z", + "published": "2024-06-11T18:30:49Z", + "aliases": [ + "CVE-2024-30082" + ], + "details": "Win32k Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30082" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30082" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-8jm9-f4h8-qchf/GHSA-8jm9-f4h8-qchf.json b/advisories/unreviewed/2024/06/GHSA-8jm9-f4h8-qchf/GHSA-8jm9-f4h8-qchf.json index fc39f9b27a9..a81ce98b1ea 100644 --- a/advisories/unreviewed/2024/06/GHSA-8jm9-f4h8-qchf/GHSA-8jm9-f4h8-qchf.json +++ b/advisories/unreviewed/2024/06/GHSA-8jm9-f4h8-qchf/GHSA-8jm9-f4h8-qchf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8jm9-f4h8-qchf", - "modified": "2024-06-05T00:30:48Z", + "modified": "2024-06-11T18:30:42Z", "published": "2024-06-05T00:30:48Z", "aliases": [ "CVE-2022-28655" ], "details": "is_closing_session() allows users to create arbitrary tcp dbus connections", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-770" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-04T22:15:09Z" diff --git a/advisories/unreviewed/2024/06/GHSA-8m9g-pfr8-r84c/GHSA-8m9g-pfr8-r84c.json b/advisories/unreviewed/2024/06/GHSA-8m9g-pfr8-r84c/GHSA-8m9g-pfr8-r84c.json index 4dee0b3e3dd..29bd87ca0a3 100644 --- a/advisories/unreviewed/2024/06/GHSA-8m9g-pfr8-r84c/GHSA-8m9g-pfr8-r84c.json +++ b/advisories/unreviewed/2024/06/GHSA-8m9g-pfr8-r84c/GHSA-8m9g-pfr8-r84c.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-8rgr-7c79-w295/GHSA-8rgr-7c79-w295.json b/advisories/unreviewed/2024/06/GHSA-8rgr-7c79-w295/GHSA-8rgr-7c79-w295.json new file mode 100644 index 00000000000..46cbc0970d9 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-8rgr-7c79-w295/GHSA-8rgr-7c79-w295.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8rgr-7c79-w295", + "modified": "2024-06-11T18:30:49Z", + "published": "2024-06-11T18:30:49Z", + "aliases": [ + "CVE-2024-30085" + ], + "details": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30085" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30085" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-8whg-5x3x-gjj9/GHSA-8whg-5x3x-gjj9.json b/advisories/unreviewed/2024/06/GHSA-8whg-5x3x-gjj9/GHSA-8whg-5x3x-gjj9.json new file mode 100644 index 00000000000..be296aa5317 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-8whg-5x3x-gjj9/GHSA-8whg-5x3x-gjj9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8whg-5x3x-gjj9", + "modified": "2024-06-11T18:30:50Z", + "published": "2024-06-11T18:30:50Z", + "aliases": [ + "CVE-2024-37325" + ], + "details": "Azure Science Virtual Machine (DSVM) Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37325" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-37325" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-8xv7-6vfw-wqrw/GHSA-8xv7-6vfw-wqrw.json b/advisories/unreviewed/2024/06/GHSA-8xv7-6vfw-wqrw/GHSA-8xv7-6vfw-wqrw.json new file mode 100644 index 00000000000..27ce3c8f5f4 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-8xv7-6vfw-wqrw/GHSA-8xv7-6vfw-wqrw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8xv7-6vfw-wqrw", + "modified": "2024-06-11T18:30:50Z", + "published": "2024-06-11T18:30:50Z", + "aliases": [ + "CVE-2024-35263" + ], + "details": "Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35263" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-35263" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-98g3-x4rc-fj4g/GHSA-98g3-x4rc-fj4g.json b/advisories/unreviewed/2024/06/GHSA-98g3-x4rc-fj4g/GHSA-98g3-x4rc-fj4g.json new file mode 100644 index 00000000000..5de2c2fbabd --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-98g3-x4rc-fj4g/GHSA-98g3-x4rc-fj4g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-98g3-x4rc-fj4g", + "modified": "2024-06-11T18:30:50Z", + "published": "2024-06-11T18:30:50Z", + "aliases": [ + "CVE-2024-35250" + ], + "details": "Windows Kernel-Mode Driver Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35250" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-35250" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-822" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-99gj-25m6-38xr/GHSA-99gj-25m6-38xr.json b/advisories/unreviewed/2024/06/GHSA-99gj-25m6-38xr/GHSA-99gj-25m6-38xr.json index adef3725c06..e2b3c2e7a61 100644 --- a/advisories/unreviewed/2024/06/GHSA-99gj-25m6-38xr/GHSA-99gj-25m6-38xr.json +++ b/advisories/unreviewed/2024/06/GHSA-99gj-25m6-38xr/GHSA-99gj-25m6-38xr.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-9jw4-hxm9-mf52/GHSA-9jw4-hxm9-mf52.json b/advisories/unreviewed/2024/06/GHSA-9jw4-hxm9-mf52/GHSA-9jw4-hxm9-mf52.json new file mode 100644 index 00000000000..91422a435af --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-9jw4-hxm9-mf52/GHSA-9jw4-hxm9-mf52.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9jw4-hxm9-mf52", + "modified": "2024-06-11T18:30:50Z", + "published": "2024-06-11T18:30:50Z", + "aliases": [ + "CVE-2024-35254" + ], + "details": "Azure Monitor Agent Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35254" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-35254" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-9mf6-346h-8vjv/GHSA-9mf6-346h-8vjv.json b/advisories/unreviewed/2024/06/GHSA-9mf6-346h-8vjv/GHSA-9mf6-346h-8vjv.json new file mode 100644 index 00000000000..a46f332fc7d --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-9mf6-346h-8vjv/GHSA-9mf6-346h-8vjv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9mf6-346h-8vjv", + "modified": "2024-06-11T18:30:48Z", + "published": "2024-06-11T18:30:48Z", + "aliases": [ + "CVE-2024-30068" + ], + "details": "Windows Kernel Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30068" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30068" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-c4w3-rhwj-fj85/GHSA-c4w3-rhwj-fj85.json b/advisories/unreviewed/2024/06/GHSA-c4w3-rhwj-fj85/GHSA-c4w3-rhwj-fj85.json index 0243f6ec91b..dd56ab50f9c 100644 --- a/advisories/unreviewed/2024/06/GHSA-c4w3-rhwj-fj85/GHSA-c4w3-rhwj-fj85.json +++ b/advisories/unreviewed/2024/06/GHSA-c4w3-rhwj-fj85/GHSA-c4w3-rhwj-fj85.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-c6jw-39ph-m4hq/GHSA-c6jw-39ph-m4hq.json b/advisories/unreviewed/2024/06/GHSA-c6jw-39ph-m4hq/GHSA-c6jw-39ph-m4hq.json new file mode 100644 index 00000000000..32ee5d92c7a --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-c6jw-39ph-m4hq/GHSA-c6jw-39ph-m4hq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c6jw-39ph-m4hq", + "modified": "2024-06-11T18:30:49Z", + "published": "2024-06-11T18:30:49Z", + "aliases": [ + "CVE-2024-30078" + ], + "details": "Windows Wi-Fi Driver Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30078" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30078" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-c8cv-6hfh-6vj5/GHSA-c8cv-6hfh-6vj5.json b/advisories/unreviewed/2024/06/GHSA-c8cv-6hfh-6vj5/GHSA-c8cv-6hfh-6vj5.json new file mode 100644 index 00000000000..eac9667b2f7 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-c8cv-6hfh-6vj5/GHSA-c8cv-6hfh-6vj5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c8cv-6hfh-6vj5", + "modified": "2024-06-11T18:30:45Z", + "published": "2024-06-11T18:30:45Z", + "aliases": [ + "CVE-2024-23503" + ], + "details": "Missing Authorization vulnerability in WPManageNinja LLC Ninja Tables.This issue affects Ninja Tables: from n/a through 5.0.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23503" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ninja-tables/wordpress-ninja-tables-plugin-5-0-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T16:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-cf6f-2g38-8v75/GHSA-cf6f-2g38-8v75.json b/advisories/unreviewed/2024/06/GHSA-cf6f-2g38-8v75/GHSA-cf6f-2g38-8v75.json new file mode 100644 index 00000000000..d6d4b633442 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-cf6f-2g38-8v75/GHSA-cf6f-2g38-8v75.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cf6f-2g38-8v75", + "modified": "2024-06-11T18:30:45Z", + "published": "2024-06-11T18:30:45Z", + "aliases": [ + "CVE-2023-51519" + ], + "details": "Missing Authorization vulnerability in Soliloquy Team Slider by Soliloquy.This issue affects Slider by Soliloquy: from n/a through 2.7.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51519" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/soliloquy-lite/wordpress-slider-by-soliloquy-responsive-image-slider-for-wordpress-plugin-2-7-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T16:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-cgmp-2p2c-jgf9/GHSA-cgmp-2p2c-jgf9.json b/advisories/unreviewed/2024/06/GHSA-cgmp-2p2c-jgf9/GHSA-cgmp-2p2c-jgf9.json new file mode 100644 index 00000000000..fd7b7dc0388 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-cgmp-2p2c-jgf9/GHSA-cgmp-2p2c-jgf9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cgmp-2p2c-jgf9", + "modified": "2024-06-11T18:30:50Z", + "published": "2024-06-11T18:30:50Z", + "aliases": [ + "CVE-2024-4190" + ], + "details": "Stored Cross-Site Scripting (XSS) vulnerabilities have been identified in OpenText ArcSight Logger. The vulnerabilities could be remotely exploited.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4190" + }, + { + "type": "WEB", + "url": "https://portal.microfocus.com/s/article/KM000030655" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-cgpx-jvx9-2gxw/GHSA-cgpx-jvx9-2gxw.json b/advisories/unreviewed/2024/06/GHSA-cgpx-jvx9-2gxw/GHSA-cgpx-jvx9-2gxw.json new file mode 100644 index 00000000000..be78fe68c7a --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-cgpx-jvx9-2gxw/GHSA-cgpx-jvx9-2gxw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cgpx-jvx9-2gxw", + "modified": "2024-06-11T18:30:49Z", + "published": "2024-06-11T18:30:49Z", + "aliases": [ + "CVE-2024-30096" + ], + "details": "Windows Cryptographic Services Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30096" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30096" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-cjc4-92cq-3rh3/GHSA-cjc4-92cq-3rh3.json b/advisories/unreviewed/2024/06/GHSA-cjc4-92cq-3rh3/GHSA-cjc4-92cq-3rh3.json new file mode 100644 index 00000000000..9948b12f56f --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-cjc4-92cq-3rh3/GHSA-cjc4-92cq-3rh3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cjc4-92cq-3rh3", + "modified": "2024-06-11T18:30:49Z", + "published": "2024-06-11T18:30:49Z", + "aliases": [ + "CVE-2024-30091" + ], + "details": "Win32k Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30091" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30091" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-cjg4-rgpv-wv5h/GHSA-cjg4-rgpv-wv5h.json b/advisories/unreviewed/2024/06/GHSA-cjg4-rgpv-wv5h/GHSA-cjg4-rgpv-wv5h.json index 7bb4b3ff3de..b4fa675a236 100644 --- a/advisories/unreviewed/2024/06/GHSA-cjg4-rgpv-wv5h/GHSA-cjg4-rgpv-wv5h.json +++ b/advisories/unreviewed/2024/06/GHSA-cjg4-rgpv-wv5h/GHSA-cjg4-rgpv-wv5h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cjg4-rgpv-wv5h", - "modified": "2024-06-07T12:34:15Z", + "modified": "2024-06-11T18:30:44Z", "published": "2024-06-07T12:34:15Z", "aliases": [ "CVE-2024-5645" @@ -40,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-crg8-w24w-qvmq/GHSA-crg8-w24w-qvmq.json b/advisories/unreviewed/2024/06/GHSA-crg8-w24w-qvmq/GHSA-crg8-w24w-qvmq.json index a6fdf8845d0..1462f2809e0 100644 --- a/advisories/unreviewed/2024/06/GHSA-crg8-w24w-qvmq/GHSA-crg8-w24w-qvmq.json +++ b/advisories/unreviewed/2024/06/GHSA-crg8-w24w-qvmq/GHSA-crg8-w24w-qvmq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-crg8-w24w-qvmq", - "modified": "2024-06-06T15:30:36Z", + "modified": "2024-06-11T18:30:43Z", "published": "2024-06-06T15:30:36Z", "aliases": [ "CVE-2024-36779" ], "details": "Sourcecodester Stock Management System v1.0 is vulnerable to SQL Injection via editCategories.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-06T13:15:31Z" diff --git a/advisories/unreviewed/2024/06/GHSA-crp5-539g-qwq6/GHSA-crp5-539g-qwq6.json b/advisories/unreviewed/2024/06/GHSA-crp5-539g-qwq6/GHSA-crp5-539g-qwq6.json index ce4e3f20958..bb7d7713767 100644 --- a/advisories/unreviewed/2024/06/GHSA-crp5-539g-qwq6/GHSA-crp5-539g-qwq6.json +++ b/advisories/unreviewed/2024/06/GHSA-crp5-539g-qwq6/GHSA-crp5-539g-qwq6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-crp5-539g-qwq6", - "modified": "2024-06-05T06:30:39Z", + "modified": "2024-06-11T18:30:42Z", "published": "2024-06-05T06:30:39Z", "aliases": [ "CVE-2024-34055" ], "details": "Cyrus IMAP before 3.8.3 and 3.10.x before 3.10.0-rc1 allows authenticated attackers to cause unbounded memory allocation by sending many LITERALs in a single command.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-770" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-05T05:15:49Z" diff --git a/advisories/unreviewed/2024/06/GHSA-cvjx-289q-hcpx/GHSA-cvjx-289q-hcpx.json b/advisories/unreviewed/2024/06/GHSA-cvjx-289q-hcpx/GHSA-cvjx-289q-hcpx.json index 7f3fade482f..e264a230bb3 100644 --- a/advisories/unreviewed/2024/06/GHSA-cvjx-289q-hcpx/GHSA-cvjx-289q-hcpx.json +++ b/advisories/unreviewed/2024/06/GHSA-cvjx-289q-hcpx/GHSA-cvjx-289q-hcpx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cvjx-289q-hcpx", - "modified": "2024-06-05T09:30:37Z", + "modified": "2024-06-11T18:30:43Z", "published": "2024-06-05T09:30:37Z", "aliases": [ "CVE-2024-5571" @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-cx5x-4q8r-qxcm/GHSA-cx5x-4q8r-qxcm.json b/advisories/unreviewed/2024/06/GHSA-cx5x-4q8r-qxcm/GHSA-cx5x-4q8r-qxcm.json index 57570e6d186..a0cff6c8277 100644 --- a/advisories/unreviewed/2024/06/GHSA-cx5x-4q8r-qxcm/GHSA-cx5x-4q8r-qxcm.json +++ b/advisories/unreviewed/2024/06/GHSA-cx5x-4q8r-qxcm/GHSA-cx5x-4q8r-qxcm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cx5x-4q8r-qxcm", - "modified": "2024-06-05T00:30:48Z", + "modified": "2024-06-11T18:30:42Z", "published": "2024-06-05T00:30:48Z", "aliases": [ "CVE-2022-28656" ], "details": "is_closing_session() allows users to consume RAM in the Apport process", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-770" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-04T22:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-cx85-3x88-7h78/GHSA-cx85-3x88-7h78.json b/advisories/unreviewed/2024/06/GHSA-cx85-3x88-7h78/GHSA-cx85-3x88-7h78.json new file mode 100644 index 00000000000..8fb65e4637c --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-cx85-3x88-7h78/GHSA-cx85-3x88-7h78.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cx85-3x88-7h78", + "modified": "2024-06-11T18:30:50Z", + "published": "2024-06-11T18:30:50Z", + "aliases": [ + "CVE-2024-34815" + ], + "details": "Missing Authorization vulnerability in Codection Import and export users and customers.This issue affects Import and export users and customers: from n/a through 1.26.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34815" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/import-users-from-csv-with-meta/wordpress-import-and-export-users-and-customers-plugin-1-26-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-f247-jmr8-598h/GHSA-f247-jmr8-598h.json b/advisories/unreviewed/2024/06/GHSA-f247-jmr8-598h/GHSA-f247-jmr8-598h.json new file mode 100644 index 00000000000..f1ff4c70855 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-f247-jmr8-598h/GHSA-f247-jmr8-598h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f247-jmr8-598h", + "modified": "2024-06-11T18:30:47Z", + "published": "2024-06-11T18:30:47Z", + "aliases": [ + "CVE-2024-30064" + ], + "details": "Windows Kernel Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30064" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30064" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-f474-ggqf-8jp5/GHSA-f474-ggqf-8jp5.json b/advisories/unreviewed/2024/06/GHSA-f474-ggqf-8jp5/GHSA-f474-ggqf-8jp5.json index 2f02297a21a..a7165eaa870 100644 --- a/advisories/unreviewed/2024/06/GHSA-f474-ggqf-8jp5/GHSA-f474-ggqf-8jp5.json +++ b/advisories/unreviewed/2024/06/GHSA-f474-ggqf-8jp5/GHSA-f474-ggqf-8jp5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f474-ggqf-8jp5", - "modified": "2024-06-05T00:30:48Z", + "modified": "2024-06-11T18:30:42Z", "published": "2024-06-05T00:30:48Z", "aliases": [ "CVE-2022-28652" ], "details": "~/.config/apport/settings parsing is vulnerable to \"billion laughs\" attack", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-776" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-04T22:15:09Z" diff --git a/advisories/unreviewed/2024/06/GHSA-f6cj-m449-jcpp/GHSA-f6cj-m449-jcpp.json b/advisories/unreviewed/2024/06/GHSA-f6cj-m449-jcpp/GHSA-f6cj-m449-jcpp.json new file mode 100644 index 00000000000..30f325188fb --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-f6cj-m449-jcpp/GHSA-f6cj-m449-jcpp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f6cj-m449-jcpp", + "modified": "2024-06-11T18:30:50Z", + "published": "2024-06-11T18:30:50Z", + "aliases": [ + "CVE-2024-35265" + ], + "details": "Windows Perception Service Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35265" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-35265" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-f7wm-449v-gc59/GHSA-f7wm-449v-gc59.json b/advisories/unreviewed/2024/06/GHSA-f7wm-449v-gc59/GHSA-f7wm-449v-gc59.json index b289f26bdce..e43c7da6db9 100644 --- a/advisories/unreviewed/2024/06/GHSA-f7wm-449v-gc59/GHSA-f7wm-449v-gc59.json +++ b/advisories/unreviewed/2024/06/GHSA-f7wm-449v-gc59/GHSA-f7wm-449v-gc59.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f7wm-449v-gc59", - "modified": "2024-06-06T12:30:36Z", + "modified": "2024-06-11T18:30:43Z", "published": "2024-06-06T12:30:36Z", "aliases": [ "CVE-2024-5329" @@ -40,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-f89r-fghx-493c/GHSA-f89r-fghx-493c.json b/advisories/unreviewed/2024/06/GHSA-f89r-fghx-493c/GHSA-f89r-fghx-493c.json new file mode 100644 index 00000000000..e709da5a587 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-f89r-fghx-493c/GHSA-f89r-fghx-493c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f89r-fghx-493c", + "modified": "2024-06-11T18:30:50Z", + "published": "2024-06-11T18:30:50Z", + "aliases": [ + "CVE-2024-35248" + ], + "details": "Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35248" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-35248" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1390" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-fj5j-7xpr-x2f9/GHSA-fj5j-7xpr-x2f9.json b/advisories/unreviewed/2024/06/GHSA-fj5j-7xpr-x2f9/GHSA-fj5j-7xpr-x2f9.json new file mode 100644 index 00000000000..a4eae7900fb --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-fj5j-7xpr-x2f9/GHSA-fj5j-7xpr-x2f9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fj5j-7xpr-x2f9", + "modified": "2024-06-11T18:30:49Z", + "published": "2024-06-11T18:30:49Z", + "aliases": [ + "CVE-2024-30104" + ], + "details": "Microsoft Office Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30104" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30104" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-fj7x-4jpw-qx69/GHSA-fj7x-4jpw-qx69.json b/advisories/unreviewed/2024/06/GHSA-fj7x-4jpw-qx69/GHSA-fj7x-4jpw-qx69.json index 6509aac25a3..79164c55b0d 100644 --- a/advisories/unreviewed/2024/06/GHSA-fj7x-4jpw-qx69/GHSA-fj7x-4jpw-qx69.json +++ b/advisories/unreviewed/2024/06/GHSA-fj7x-4jpw-qx69/GHSA-fj7x-4jpw-qx69.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fj7x-4jpw-qx69", - "modified": "2024-06-06T09:30:52Z", + "modified": "2024-06-11T18:30:43Z", "published": "2024-06-06T09:30:52Z", "aliases": [ "CVE-2024-5665" @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-fmhh-hvrg-38qc/GHSA-fmhh-hvrg-38qc.json b/advisories/unreviewed/2024/06/GHSA-fmhh-hvrg-38qc/GHSA-fmhh-hvrg-38qc.json index 426637f91c3..dc526e49c14 100644 --- a/advisories/unreviewed/2024/06/GHSA-fmhh-hvrg-38qc/GHSA-fmhh-hvrg-38qc.json +++ b/advisories/unreviewed/2024/06/GHSA-fmhh-hvrg-38qc/GHSA-fmhh-hvrg-38qc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fmhh-hvrg-38qc", - "modified": "2024-06-07T09:30:45Z", + "modified": "2024-06-11T18:30:44Z", "published": "2024-06-07T09:30:45Z", "aliases": [ "CVE-2024-4489" @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-fpmj-g9m4-j4hg/GHSA-fpmj-g9m4-j4hg.json b/advisories/unreviewed/2024/06/GHSA-fpmj-g9m4-j4hg/GHSA-fpmj-g9m4-j4hg.json index fbe3c42379d..b96989217dd 100644 --- a/advisories/unreviewed/2024/06/GHSA-fpmj-g9m4-j4hg/GHSA-fpmj-g9m4-j4hg.json +++ b/advisories/unreviewed/2024/06/GHSA-fpmj-g9m4-j4hg/GHSA-fpmj-g9m4-j4hg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fpmj-g9m4-j4hg", - "modified": "2024-06-05T09:30:37Z", + "modified": "2024-06-11T18:30:43Z", "published": "2024-06-05T09:30:37Z", "aliases": [ "CVE-2024-1164" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-fxfx-w7wj-826h/GHSA-fxfx-w7wj-826h.json b/advisories/unreviewed/2024/06/GHSA-fxfx-w7wj-826h/GHSA-fxfx-w7wj-826h.json new file mode 100644 index 00000000000..f4002e076f8 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-fxfx-w7wj-826h/GHSA-fxfx-w7wj-826h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fxfx-w7wj-826h", + "modified": "2024-06-11T18:30:49Z", + "published": "2024-06-11T18:30:49Z", + "aliases": [ + "CVE-2024-30101" + ], + "details": "Microsoft Office Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30101" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30101" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-g23p-9mvr-phw2/GHSA-g23p-9mvr-phw2.json b/advisories/unreviewed/2024/06/GHSA-g23p-9mvr-phw2/GHSA-g23p-9mvr-phw2.json new file mode 100644 index 00000000000..116b4702126 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-g23p-9mvr-phw2/GHSA-g23p-9mvr-phw2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g23p-9mvr-phw2", + "modified": "2024-06-11T18:30:49Z", + "published": "2024-06-11T18:30:49Z", + "aliases": [ + "CVE-2024-30084" + ], + "details": "Windows Kernel-Mode Driver Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30084" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30084" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-g459-66wh-4437/GHSA-g459-66wh-4437.json b/advisories/unreviewed/2024/06/GHSA-g459-66wh-4437/GHSA-g459-66wh-4437.json new file mode 100644 index 00000000000..a12060c4cbc --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-g459-66wh-4437/GHSA-g459-66wh-4437.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g459-66wh-4437", + "modified": "2024-06-11T18:30:49Z", + "published": "2024-06-11T18:30:49Z", + "aliases": [ + "CVE-2024-30080" + ], + "details": "Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30080" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30080" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-g4v9-xpcj-8262/GHSA-g4v9-xpcj-8262.json b/advisories/unreviewed/2024/06/GHSA-g4v9-xpcj-8262/GHSA-g4v9-xpcj-8262.json index e62aa24e022..95612b21b10 100644 --- a/advisories/unreviewed/2024/06/GHSA-g4v9-xpcj-8262/GHSA-g4v9-xpcj-8262.json +++ b/advisories/unreviewed/2024/06/GHSA-g4v9-xpcj-8262/GHSA-g4v9-xpcj-8262.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g4v9-xpcj-8262", - "modified": "2024-06-05T09:30:37Z", + "modified": "2024-06-11T18:30:43Z", "published": "2024-06-05T09:30:37Z", "aliases": [ "CVE-2024-4821" @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-g5m9-q65c-x6m4/GHSA-g5m9-q65c-x6m4.json b/advisories/unreviewed/2024/06/GHSA-g5m9-q65c-x6m4/GHSA-g5m9-q65c-x6m4.json index a7ed618f740..4677d67b2f8 100644 --- a/advisories/unreviewed/2024/06/GHSA-g5m9-q65c-x6m4/GHSA-g5m9-q65c-x6m4.json +++ b/advisories/unreviewed/2024/06/GHSA-g5m9-q65c-x6m4/GHSA-g5m9-q65c-x6m4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g5m9-q65c-x6m4", - "modified": "2024-06-06T09:30:51Z", + "modified": "2024-06-11T18:30:43Z", "published": "2024-06-06T09:30:51Z", "aliases": [ "CVE-2024-4177" @@ -24,11 +24,16 @@ { "type": "WEB", "url": "https://bitdefender.com/consumer/support/support/security-advisories/host-whitelist-parser-issue-in-gravityzone-console-on-premise-va-11554" + }, + { + "type": "WEB", + "url": "https://www.cve.org/CVERecord?id=CVE-2024-4177" } ], "database_specific": { "cwe_ids": [ - "CWE-116" + "CWE-116", + "CWE-918" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-g9j3-gfvx-6m8g/GHSA-g9j3-gfvx-6m8g.json b/advisories/unreviewed/2024/06/GHSA-g9j3-gfvx-6m8g/GHSA-g9j3-gfvx-6m8g.json index b0bbad6b7c6..ec5c0ce2838 100644 --- a/advisories/unreviewed/2024/06/GHSA-g9j3-gfvx-6m8g/GHSA-g9j3-gfvx-6m8g.json +++ b/advisories/unreviewed/2024/06/GHSA-g9j3-gfvx-6m8g/GHSA-g9j3-gfvx-6m8g.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-g9vh-rmj6-m6r2/GHSA-g9vh-rmj6-m6r2.json b/advisories/unreviewed/2024/06/GHSA-g9vh-rmj6-m6r2/GHSA-g9vh-rmj6-m6r2.json index 901156f5ab1..cc258f20094 100644 --- a/advisories/unreviewed/2024/06/GHSA-g9vh-rmj6-m6r2/GHSA-g9vh-rmj6-m6r2.json +++ b/advisories/unreviewed/2024/06/GHSA-g9vh-rmj6-m6r2/GHSA-g9vh-rmj6-m6r2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g9vh-rmj6-m6r2", - "modified": "2024-06-06T12:30:36Z", + "modified": "2024-06-11T18:30:43Z", "published": "2024-06-06T12:30:36Z", "aliases": [ "CVE-2024-5489" @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-h438-86cm-g2q6/GHSA-h438-86cm-g2q6.json b/advisories/unreviewed/2024/06/GHSA-h438-86cm-g2q6/GHSA-h438-86cm-g2q6.json index b34b3555532..81556c9ca68 100644 --- a/advisories/unreviewed/2024/06/GHSA-h438-86cm-g2q6/GHSA-h438-86cm-g2q6.json +++ b/advisories/unreviewed/2024/06/GHSA-h438-86cm-g2q6/GHSA-h438-86cm-g2q6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h438-86cm-g2q6", - "modified": "2024-06-07T12:34:15Z", + "modified": "2024-06-11T18:30:44Z", "published": "2024-06-07T12:34:15Z", "aliases": [ "CVE-2024-5481" @@ -48,7 +48,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-h47v-33fm-j33g/GHSA-h47v-33fm-j33g.json b/advisories/unreviewed/2024/06/GHSA-h47v-33fm-j33g/GHSA-h47v-33fm-j33g.json new file mode 100644 index 00000000000..a612ad3f515 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-h47v-33fm-j33g/GHSA-h47v-33fm-j33g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h47v-33fm-j33g", + "modified": "2024-06-11T18:30:49Z", + "published": "2024-06-11T18:30:49Z", + "aliases": [ + "CVE-2024-30088" + ], + "details": "Windows Kernel Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30088" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30088" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-hg9h-v98r-f5mq/GHSA-hg9h-v98r-f5mq.json b/advisories/unreviewed/2024/06/GHSA-hg9h-v98r-f5mq/GHSA-hg9h-v98r-f5mq.json new file mode 100644 index 00000000000..c4bbcfb7c7a --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-hg9h-v98r-f5mq/GHSA-hg9h-v98r-f5mq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hg9h-v98r-f5mq", + "modified": "2024-06-11T18:30:46Z", + "published": "2024-06-11T18:30:46Z", + "aliases": [ + "CVE-2024-34822" + ], + "details": "Missing Authorization vulnerability in weDevs weMail.This issue affects weMail: from n/a through 1.14.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34822" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wemail/wordpress-wemail-plugin-1-14-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-hh2w-28r4-mpw7/GHSA-hh2w-28r4-mpw7.json b/advisories/unreviewed/2024/06/GHSA-hh2w-28r4-mpw7/GHSA-hh2w-28r4-mpw7.json new file mode 100644 index 00000000000..4b77f7b1390 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-hh2w-28r4-mpw7/GHSA-hh2w-28r4-mpw7.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hh2w-28r4-mpw7", + "modified": "2024-06-11T18:30:50Z", + "published": "2024-06-11T18:30:50Z", + "aliases": [ + "CVE-2024-36821" + ], + "details": "Insecure permissions in Linksys Velop WiFi 5 (WHW01v1) 1.1.13.202617 allows attackers to escalate privileges from Guest to root via a directory traversal.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36821" + }, + { + "type": "WEB", + "url": "https://downloads.linksys.com/support/assets/releasenotes/WHW01_VLP01_1.1.13.202617_Customer_Release_Notes.txt" + }, + { + "type": "WEB", + "url": "https://github.com/IvanGlinkin/CVE-2024-36821" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-hhrw-qrv8-cjmm/GHSA-hhrw-qrv8-cjmm.json b/advisories/unreviewed/2024/06/GHSA-hhrw-qrv8-cjmm/GHSA-hhrw-qrv8-cjmm.json index b32dabb95d0..fc5fea929bd 100644 --- a/advisories/unreviewed/2024/06/GHSA-hhrw-qrv8-cjmm/GHSA-hhrw-qrv8-cjmm.json +++ b/advisories/unreviewed/2024/06/GHSA-hhrw-qrv8-cjmm/GHSA-hhrw-qrv8-cjmm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hhrw-qrv8-cjmm", - "modified": "2024-06-05T09:30:37Z", + "modified": "2024-06-11T18:30:42Z", "published": "2024-06-05T09:30:37Z", "aliases": [ "CVE-2024-5222" @@ -40,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-hpcw-9w82-7fr9/GHSA-hpcw-9w82-7fr9.json b/advisories/unreviewed/2024/06/GHSA-hpcw-9w82-7fr9/GHSA-hpcw-9w82-7fr9.json new file mode 100644 index 00000000000..7607b6dce09 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-hpcw-9w82-7fr9/GHSA-hpcw-9w82-7fr9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hpcw-9w82-7fr9", + "modified": "2024-06-11T18:30:45Z", + "published": "2024-06-11T18:30:45Z", + "aliases": [ + "CVE-2024-34753" + ], + "details": "Missing Authorization vulnerability in SoftLab Radio Player.This issue affects Radio Player: from n/a through 2.0.73.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34753" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/radio-player/wordpress-radio-player-plugin-2-0-73-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T16:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-hxqx-mgwx-225x/GHSA-hxqx-mgwx-225x.json b/advisories/unreviewed/2024/06/GHSA-hxqx-mgwx-225x/GHSA-hxqx-mgwx-225x.json new file mode 100644 index 00000000000..000c9435156 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-hxqx-mgwx-225x/GHSA-hxqx-mgwx-225x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hxqx-mgwx-225x", + "modified": "2024-06-11T18:30:49Z", + "published": "2024-06-11T18:30:49Z", + "aliases": [ + "CVE-2024-30094" + ], + "details": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30094" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30094" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-j489-qgfq-2h27/GHSA-j489-qgfq-2h27.json b/advisories/unreviewed/2024/06/GHSA-j489-qgfq-2h27/GHSA-j489-qgfq-2h27.json new file mode 100644 index 00000000000..56b0780fc0b --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-j489-qgfq-2h27/GHSA-j489-qgfq-2h27.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j489-qgfq-2h27", + "modified": "2024-06-11T18:30:49Z", + "published": "2024-06-11T18:30:49Z", + "aliases": [ + "CVE-2024-30090" + ], + "details": "Microsoft Streaming Service Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30090" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30090" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-822" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-j4qq-fq33-g7hw/GHSA-j4qq-fq33-g7hw.json b/advisories/unreviewed/2024/06/GHSA-j4qq-fq33-g7hw/GHSA-j4qq-fq33-g7hw.json new file mode 100644 index 00000000000..caedc537f1c --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-j4qq-fq33-g7hw/GHSA-j4qq-fq33-g7hw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j4qq-fq33-g7hw", + "modified": "2024-06-11T18:30:49Z", + "published": "2024-06-11T18:30:49Z", + "aliases": [ + "CVE-2024-30086" + ], + "details": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30086" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30086" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-jj5p-5p78-9ch8/GHSA-jj5p-5p78-9ch8.json b/advisories/unreviewed/2024/06/GHSA-jj5p-5p78-9ch8/GHSA-jj5p-5p78-9ch8.json new file mode 100644 index 00000000000..abbf386936b --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-jj5p-5p78-9ch8/GHSA-jj5p-5p78-9ch8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jj5p-5p78-9ch8", + "modified": "2024-06-11T18:30:49Z", + "published": "2024-06-11T18:30:49Z", + "aliases": [ + "CVE-2024-30089" + ], + "details": "Microsoft Streaming Service Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30089" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30089" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-m47j-h8wj-cg29/GHSA-m47j-h8wj-cg29.json b/advisories/unreviewed/2024/06/GHSA-m47j-h8wj-cg29/GHSA-m47j-h8wj-cg29.json index 6b2ca820759..4ffdc747d0e 100644 --- a/advisories/unreviewed/2024/06/GHSA-m47j-h8wj-cg29/GHSA-m47j-h8wj-cg29.json +++ b/advisories/unreviewed/2024/06/GHSA-m47j-h8wj-cg29/GHSA-m47j-h8wj-cg29.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m47j-h8wj-cg29", - "modified": "2024-06-05T06:30:40Z", + "modified": "2024-06-11T18:30:42Z", "published": "2024-06-05T06:30:40Z", "aliases": [ "CVE-2024-4295" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-m5vv-6r4h-3vj9/GHSA-m5vv-6r4h-3vj9.json b/advisories/unreviewed/2024/06/GHSA-m5vv-6r4h-3vj9/GHSA-m5vv-6r4h-3vj9.json new file mode 100644 index 00000000000..b50deaab8f3 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-m5vv-6r4h-3vj9/GHSA-m5vv-6r4h-3vj9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m5vv-6r4h-3vj9", + "modified": "2024-06-11T18:30:50Z", + "published": "2024-06-11T18:30:50Z", + "aliases": [ + "CVE-2024-35255" + ], + "details": "Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35255" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-35255" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-362" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-m874-43g7-rrc9/GHSA-m874-43g7-rrc9.json b/advisories/unreviewed/2024/06/GHSA-m874-43g7-rrc9/GHSA-m874-43g7-rrc9.json new file mode 100644 index 00000000000..540224b3325 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-m874-43g7-rrc9/GHSA-m874-43g7-rrc9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m874-43g7-rrc9", + "modified": "2024-06-11T18:30:49Z", + "published": "2024-06-11T18:30:49Z", + "aliases": [ + "CVE-2024-30095" + ], + "details": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30095" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30095" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-m8cv-83cf-qccx/GHSA-m8cv-83cf-qccx.json b/advisories/unreviewed/2024/06/GHSA-m8cv-83cf-qccx/GHSA-m8cv-83cf-qccx.json index 7903f8eff4d..ee32905f40f 100644 --- a/advisories/unreviewed/2024/06/GHSA-m8cv-83cf-qccx/GHSA-m8cv-83cf-qccx.json +++ b/advisories/unreviewed/2024/06/GHSA-m8cv-83cf-qccx/GHSA-m8cv-83cf-qccx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m8cv-83cf-qccx", - "modified": "2024-06-05T00:30:48Z", + "modified": "2024-06-11T18:30:42Z", "published": "2024-06-05T00:30:48Z", "aliases": [ "CVE-2022-28657" ], "details": "Apport does not disable python crash handler before entering chroot", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-04T22:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-mjwc-4vr5-7xr3/GHSA-mjwc-4vr5-7xr3.json b/advisories/unreviewed/2024/06/GHSA-mjwc-4vr5-7xr3/GHSA-mjwc-4vr5-7xr3.json index b1babffdcfc..58cc6051822 100644 --- a/advisories/unreviewed/2024/06/GHSA-mjwc-4vr5-7xr3/GHSA-mjwc-4vr5-7xr3.json +++ b/advisories/unreviewed/2024/06/GHSA-mjwc-4vr5-7xr3/GHSA-mjwc-4vr5-7xr3.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-mrcq-5w4f-hvcr/GHSA-mrcq-5w4f-hvcr.json b/advisories/unreviewed/2024/06/GHSA-mrcq-5w4f-hvcr/GHSA-mrcq-5w4f-hvcr.json new file mode 100644 index 00000000000..537d24ffd02 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-mrcq-5w4f-hvcr/GHSA-mrcq-5w4f-hvcr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mrcq-5w4f-hvcr", + "modified": "2024-06-11T18:30:50Z", + "published": "2024-06-11T18:30:50Z", + "aliases": [ + "CVE-2024-34763" + ], + "details": "Missing Authorization vulnerability in Tobias Conrad Builder for WooCommerce reviews shortcodes – ReviewShort.This issue affects Builder for WooCommerce reviews shortcodes – ReviewShort: from n/a through 1.01.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34763" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/woo-product-reviews-shortcode/wordpress-builder-for-woocommerce-reviews-shortcodes-reviewshort-plugin-1-01-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-p4p8-443x-h6f3/GHSA-p4p8-443x-h6f3.json b/advisories/unreviewed/2024/06/GHSA-p4p8-443x-h6f3/GHSA-p4p8-443x-h6f3.json index 1dbfd5bd04d..6de546fc48e 100644 --- a/advisories/unreviewed/2024/06/GHSA-p4p8-443x-h6f3/GHSA-p4p8-443x-h6f3.json +++ b/advisories/unreviewed/2024/06/GHSA-p4p8-443x-h6f3/GHSA-p4p8-443x-h6f3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p4p8-443x-h6f3", - "modified": "2024-06-07T15:30:39Z", + "modified": "2024-06-11T18:30:44Z", "published": "2024-06-07T15:30:39Z", "aliases": [ "CVE-2024-5542" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-p7gw-hh3x-x6xm/GHSA-p7gw-hh3x-x6xm.json b/advisories/unreviewed/2024/06/GHSA-p7gw-hh3x-x6xm/GHSA-p7gw-hh3x-x6xm.json index 557ca7ddcf2..b7dfb83c900 100644 --- a/advisories/unreviewed/2024/06/GHSA-p7gw-hh3x-x6xm/GHSA-p7gw-hh3x-x6xm.json +++ b/advisories/unreviewed/2024/06/GHSA-p7gw-hh3x-x6xm/GHSA-p7gw-hh3x-x6xm.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-p82q-4g4j-x67h/GHSA-p82q-4g4j-x67h.json b/advisories/unreviewed/2024/06/GHSA-p82q-4g4j-x67h/GHSA-p82q-4g4j-x67h.json index 58df81cbf0d..8a22c335d0e 100644 --- a/advisories/unreviewed/2024/06/GHSA-p82q-4g4j-x67h/GHSA-p82q-4g4j-x67h.json +++ b/advisories/unreviewed/2024/06/GHSA-p82q-4g4j-x67h/GHSA-p82q-4g4j-x67h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p82q-4g4j-x67h", - "modified": "2024-06-05T09:30:37Z", + "modified": "2024-06-11T18:30:42Z", "published": "2024-06-05T09:30:37Z", "aliases": [ "CVE-2024-5453" @@ -40,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-p82x-8jgq-h8r2/GHSA-p82x-8jgq-h8r2.json b/advisories/unreviewed/2024/06/GHSA-p82x-8jgq-h8r2/GHSA-p82x-8jgq-h8r2.json new file mode 100644 index 00000000000..18ba69ecdc7 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-p82x-8jgq-h8r2/GHSA-p82x-8jgq-h8r2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p82x-8jgq-h8r2", + "modified": "2024-06-11T18:30:50Z", + "published": "2024-06-11T18:30:50Z", + "aliases": [ + "CVE-2024-35249" + ], + "details": "Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35249" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-35249" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-pgqq-wq3j-8p74/GHSA-pgqq-wq3j-8p74.json b/advisories/unreviewed/2024/06/GHSA-pgqq-wq3j-8p74/GHSA-pgqq-wq3j-8p74.json index 6c884fb9e54..68930a4ba25 100644 --- a/advisories/unreviewed/2024/06/GHSA-pgqq-wq3j-8p74/GHSA-pgqq-wq3j-8p74.json +++ b/advisories/unreviewed/2024/06/GHSA-pgqq-wq3j-8p74/GHSA-pgqq-wq3j-8p74.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pgqq-wq3j-8p74", - "modified": "2024-06-07T15:30:38Z", + "modified": "2024-06-11T18:30:44Z", "published": "2024-06-07T15:30:38Z", "aliases": [ "CVE-2024-5382" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-qhx7-fh26-rx4j/GHSA-qhx7-fh26-rx4j.json b/advisories/unreviewed/2024/06/GHSA-qhx7-fh26-rx4j/GHSA-qhx7-fh26-rx4j.json new file mode 100644 index 00000000000..0f35c0fb95b --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-qhx7-fh26-rx4j/GHSA-qhx7-fh26-rx4j.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qhx7-fh26-rx4j", + "modified": "2024-06-11T18:30:50Z", + "published": "2024-06-11T18:30:50Z", + "aliases": [ + "CVE-2024-5851" + ], + "details": "A vulnerability classified as problematic has been found in playSMS up to 1.4.7. Affected is an unknown function of the file /index.php?app=main&inc=feature_schedule&op=list of the component SMS Schedule Handler. The manipulation of the argument name/message leads to basic cross site scripting. It is possible to launch the attack remotely. Upgrading to version 1.4.8 is able to address this issue. The name of the patch is 7a88920f6b536c6a91512e739bcb4e8adefeed2b. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-267912. NOTE: The code maintainer was contacted early about this disclosure and was eager to prepare a fix as quickly as possible.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5851" + }, + { + "type": "WEB", + "url": "https://github.com/playsms/playsms/commit/7a88920f6b536c6a91512e739bcb4e8adefeed2b" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.267912" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.267912" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.347385" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-80" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-qjp4-fmhh-wjw3/GHSA-qjp4-fmhh-wjw3.json b/advisories/unreviewed/2024/06/GHSA-qjp4-fmhh-wjw3/GHSA-qjp4-fmhh-wjw3.json new file mode 100644 index 00000000000..60bc5aff5f3 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-qjp4-fmhh-wjw3/GHSA-qjp4-fmhh-wjw3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qjp4-fmhh-wjw3", + "modified": "2024-06-11T18:30:46Z", + "published": "2024-06-11T18:30:46Z", + "aliases": [ + "CVE-2023-48273" + ], + "details": "Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Preloader for Website.This issue affects Preloader for Website: from n/a through 1.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48273" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/preloader-for-website/wordpress-preloader-for-website-plugin-1-2-2-unauthenticated-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-qpgp-vpmr-g2q2/GHSA-qpgp-vpmr-g2q2.json b/advisories/unreviewed/2024/06/GHSA-qpgp-vpmr-g2q2/GHSA-qpgp-vpmr-g2q2.json new file mode 100644 index 00000000000..0ccb7b16da2 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-qpgp-vpmr-g2q2/GHSA-qpgp-vpmr-g2q2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qpgp-vpmr-g2q2", + "modified": "2024-06-11T18:30:46Z", + "published": "2024-06-11T18:30:46Z", + "aliases": [ + "CVE-2024-30063" + ], + "details": "Windows Distributed File System (DFS) Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30063" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30063" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-641" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-r65c-cp46-xv46/GHSA-r65c-cp46-xv46.json b/advisories/unreviewed/2024/06/GHSA-r65c-cp46-xv46/GHSA-r65c-cp46-xv46.json new file mode 100644 index 00000000000..814e8b768f3 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-r65c-cp46-xv46/GHSA-r65c-cp46-xv46.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r65c-cp46-xv46", + "modified": "2024-06-11T18:30:46Z", + "published": "2024-06-11T18:30:46Z", + "aliases": [ + "CVE-2023-52224" + ], + "details": "Missing Authorization vulnerability in Revolut Revolut Gateway for WooCommerce.This issue affects Revolut Gateway for WooCommerce: from n/a through 4.9.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52224" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/revolut-gateway-for-woocommerce/wordpress-revolut-gateway-for-woocommerce-plugin-4-9-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-r7w3-w9rh-567f/GHSA-r7w3-w9rh-567f.json b/advisories/unreviewed/2024/06/GHSA-r7w3-w9rh-567f/GHSA-r7w3-w9rh-567f.json new file mode 100644 index 00000000000..63fc0e74aea --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-r7w3-w9rh-567f/GHSA-r7w3-w9rh-567f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r7w3-w9rh-567f", + "modified": "2024-06-11T18:30:45Z", + "published": "2024-06-11T18:30:45Z", + "aliases": [ + "CVE-2024-34819" + ], + "details": "Missing Authorization vulnerability in MoreConvert MC Woocommerce Wishlist.This issue affects MC Woocommerce Wishlist: from n/a through 1.7.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34819" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/smart-wishlist-for-more-convert/wordpress-mc-woocommerce-wishlist-plugin-1-7-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-rcpr-pf4m-pw93/GHSA-rcpr-pf4m-pw93.json b/advisories/unreviewed/2024/06/GHSA-rcpr-pf4m-pw93/GHSA-rcpr-pf4m-pw93.json index c9424a0ad1c..bc4963586ee 100644 --- a/advisories/unreviewed/2024/06/GHSA-rcpr-pf4m-pw93/GHSA-rcpr-pf4m-pw93.json +++ b/advisories/unreviewed/2024/06/GHSA-rcpr-pf4m-pw93/GHSA-rcpr-pf4m-pw93.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rcpr-pf4m-pw93", - "modified": "2024-06-05T12:31:51Z", + "modified": "2024-06-11T18:30:43Z", "published": "2024-06-05T12:31:51Z", "aliases": [ "CVE-2024-5536" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-rfg3-rpcj-q476/GHSA-rfg3-rpcj-q476.json b/advisories/unreviewed/2024/06/GHSA-rfg3-rpcj-q476/GHSA-rfg3-rpcj-q476.json index e161ad2baa9..fecea91fd80 100644 --- a/advisories/unreviewed/2024/06/GHSA-rfg3-rpcj-q476/GHSA-rfg3-rpcj-q476.json +++ b/advisories/unreviewed/2024/06/GHSA-rfg3-rpcj-q476/GHSA-rfg3-rpcj-q476.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rfg3-rpcj-q476", - "modified": "2024-06-07T12:34:14Z", + "modified": "2024-06-11T18:30:44Z", "published": "2024-06-07T12:34:14Z", "aliases": [ "CVE-2024-5426" @@ -40,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-rpxc-37cc-9whw/GHSA-rpxc-37cc-9whw.json b/advisories/unreviewed/2024/06/GHSA-rpxc-37cc-9whw/GHSA-rpxc-37cc-9whw.json new file mode 100644 index 00000000000..a2b3a9f8937 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-rpxc-37cc-9whw/GHSA-rpxc-37cc-9whw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rpxc-37cc-9whw", + "modified": "2024-06-11T18:30:50Z", + "published": "2024-06-11T18:30:50Z", + "aliases": [ + "CVE-2024-35253" + ], + "details": "Microsoft Azure File Sync Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35253" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-35253" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-rqqx-vwj3-25p4/GHSA-rqqx-vwj3-25p4.json b/advisories/unreviewed/2024/06/GHSA-rqqx-vwj3-25p4/GHSA-rqqx-vwj3-25p4.json new file mode 100644 index 00000000000..11ac3bfc609 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-rqqx-vwj3-25p4/GHSA-rqqx-vwj3-25p4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rqqx-vwj3-25p4", + "modified": "2024-06-11T18:30:48Z", + "published": "2024-06-11T18:30:48Z", + "aliases": [ + "CVE-2024-30066" + ], + "details": "Winlogon Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30066" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30066" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-vmx5-xfwf-9f82/GHSA-vmx5-xfwf-9f82.json b/advisories/unreviewed/2024/06/GHSA-vmx5-xfwf-9f82/GHSA-vmx5-xfwf-9f82.json new file mode 100644 index 00000000000..1db7db47614 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-vmx5-xfwf-9f82/GHSA-vmx5-xfwf-9f82.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vmx5-xfwf-9f82", + "modified": "2024-06-11T18:30:50Z", + "published": "2024-06-11T18:30:49Z", + "aliases": [ + "CVE-2024-34758" + ], + "details": "Missing Authorization vulnerability in Wpmet WP Fundraising Donation and Crowdfunding Platform.This issue affects WP Fundraising Donation and Crowdfunding Platform: from n/a through 1.6.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34758" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-fundraising-donation/wordpress-fundengine-donation-and-crowdfunding-platform-plugin-1-6-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-vrf4-hv45-fq4j/GHSA-vrf4-hv45-fq4j.json b/advisories/unreviewed/2024/06/GHSA-vrf4-hv45-fq4j/GHSA-vrf4-hv45-fq4j.json index c1e8c492639..92225357d43 100644 --- a/advisories/unreviewed/2024/06/GHSA-vrf4-hv45-fq4j/GHSA-vrf4-hv45-fq4j.json +++ b/advisories/unreviewed/2024/06/GHSA-vrf4-hv45-fq4j/GHSA-vrf4-hv45-fq4j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vrf4-hv45-fq4j", - "modified": "2024-06-07T15:30:39Z", + "modified": "2024-06-11T18:30:44Z", "published": "2024-06-07T15:30:39Z", "aliases": [ "CVE-2024-5438" @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-639" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-vvfh-c922-h3gx/GHSA-vvfh-c922-h3gx.json b/advisories/unreviewed/2024/06/GHSA-vvfh-c922-h3gx/GHSA-vvfh-c922-h3gx.json new file mode 100644 index 00000000000..ed1b966f372 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-vvfh-c922-h3gx/GHSA-vvfh-c922-h3gx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vvfh-c922-h3gx", + "modified": "2024-06-11T18:30:48Z", + "published": "2024-06-11T18:30:48Z", + "aliases": [ + "CVE-2024-30067" + ], + "details": "Winlogon Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30067" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30067" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-vx48-f47g-5gxg/GHSA-vx48-f47g-5gxg.json b/advisories/unreviewed/2024/06/GHSA-vx48-f47g-5gxg/GHSA-vx48-f47g-5gxg.json new file mode 100644 index 00000000000..ab5bb04d412 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-vx48-f47g-5gxg/GHSA-vx48-f47g-5gxg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vx48-f47g-5gxg", + "modified": "2024-06-11T18:30:50Z", + "published": "2024-06-11T18:30:50Z", + "aliases": [ + "CVE-2024-34768" + ], + "details": "Missing Authorization vulnerability in Fastly.This issue affects Fastly: from n/a through 1.2.25.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34768" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/fastly/wordpress-fastly-plugin-1-2-25-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-w966-799g-fp7v/GHSA-w966-799g-fp7v.json b/advisories/unreviewed/2024/06/GHSA-w966-799g-fp7v/GHSA-w966-799g-fp7v.json index 7ccf513df5d..565c03cd87a 100644 --- a/advisories/unreviewed/2024/06/GHSA-w966-799g-fp7v/GHSA-w966-799g-fp7v.json +++ b/advisories/unreviewed/2024/06/GHSA-w966-799g-fp7v/GHSA-w966-799g-fp7v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w966-799g-fp7v", - "modified": "2024-06-06T15:30:36Z", + "modified": "2024-06-11T18:30:43Z", "published": "2024-06-06T15:30:36Z", "aliases": [ "CVE-2024-5675" diff --git a/advisories/unreviewed/2024/06/GHSA-wf7h-7f7p-8g7g/GHSA-wf7h-7f7p-8g7g.json b/advisories/unreviewed/2024/06/GHSA-wf7h-7f7p-8g7g/GHSA-wf7h-7f7p-8g7g.json new file mode 100644 index 00000000000..5978b9269da --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-wf7h-7f7p-8g7g/GHSA-wf7h-7f7p-8g7g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wf7h-7f7p-8g7g", + "modified": "2024-06-11T18:30:46Z", + "published": "2024-06-11T18:30:46Z", + "aliases": [ + "CVE-2024-30062" + ], + "details": "Windows Standards-Based Storage Management Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30062" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30062" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-wpj8-988q-w333/GHSA-wpj8-988q-w333.json b/advisories/unreviewed/2024/06/GHSA-wpj8-988q-w333/GHSA-wpj8-988q-w333.json new file mode 100644 index 00000000000..cdd773ed70e --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-wpj8-988q-w333/GHSA-wpj8-988q-w333.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wpj8-988q-w333", + "modified": "2024-06-11T18:30:46Z", + "published": "2024-06-11T18:30:46Z", + "aliases": [ + "CVE-2024-29060" + ], + "details": "Visual Studio Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29060" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29060" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-ww9f-v5vc-69w2/GHSA-ww9f-v5vc-69w2.json b/advisories/unreviewed/2024/06/GHSA-ww9f-v5vc-69w2/GHSA-ww9f-v5vc-69w2.json new file mode 100644 index 00000000000..e4760b49f10 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-ww9f-v5vc-69w2/GHSA-ww9f-v5vc-69w2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ww9f-v5vc-69w2", + "modified": "2024-06-11T18:30:46Z", + "published": "2024-06-11T18:30:45Z", + "aliases": [ + "CVE-2024-36650" + ], + "details": "TOTOLINK AC1200 Wireless Dual Band Gigabit Router firmware A3100R V4.1.2cu.5247_B20211129, in the cgi function `setNoticeCfg` of the file `/lib/cste_modules/system.so`, the length of the user input string `NoticeUrl` is not checked. This can lead to a buffer overflow, allowing attackers to construct malicious HTTP or MQTT requests to cause a denial-of-service attack.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36650" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Swind1er/f442fcac520a48c05c744c7b72362483" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T16:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-wxcg-26p8-gwp5/GHSA-wxcg-26p8-gwp5.json b/advisories/unreviewed/2024/06/GHSA-wxcg-26p8-gwp5/GHSA-wxcg-26p8-gwp5.json new file mode 100644 index 00000000000..f0e35489cb2 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-wxcg-26p8-gwp5/GHSA-wxcg-26p8-gwp5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wxcg-26p8-gwp5", + "modified": "2024-06-11T18:30:45Z", + "published": "2024-06-11T18:30:45Z", + "aliases": [ + "CVE-2023-51682" + ], + "details": "Missing Authorization vulnerability in ibericode MC4WP.This issue affects MC4WP: from n/a through 4.9.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51682" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/mailchimp-for-wp/wordpress-mc4wp-plugin-4-9-9-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T16:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-x32g-hhg9-mgv8/GHSA-x32g-hhg9-mgv8.json b/advisories/unreviewed/2024/06/GHSA-x32g-hhg9-mgv8/GHSA-x32g-hhg9-mgv8.json new file mode 100644 index 00000000000..bb96bce82df --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-x32g-hhg9-mgv8/GHSA-x32g-hhg9-mgv8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x32g-hhg9-mgv8", + "modified": "2024-06-11T18:30:46Z", + "published": "2024-06-11T18:30:46Z", + "aliases": [ + "CVE-2023-52227" + ], + "details": "Missing Authorization vulnerability in MailerLite MailerLite – WooCommerce integration.This issue affects MailerLite – WooCommerce integration: from n/a through 2.0.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52227" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/woo-mailerlite/wordpress-mailerlite-woocommerce-integration-plugin-2-0-7-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-x47x-f96m-j7gv/GHSA-x47x-f96m-j7gv.json b/advisories/unreviewed/2024/06/GHSA-x47x-f96m-j7gv/GHSA-x47x-f96m-j7gv.json new file mode 100644 index 00000000000..100f640b709 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-x47x-f96m-j7gv/GHSA-x47x-f96m-j7gv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x47x-f96m-j7gv", + "modified": "2024-06-11T18:30:46Z", + "published": "2024-06-11T18:30:45Z", + "aliases": [ + "CVE-2024-5812" + ], + "details": "A low severity vulnerability in BIPS has been identified where an attacker with high privileges or a compromised high privilege account can overwrite Read-Only smart rules via a specially crafted API request.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5812" + }, + { + "type": "WEB", + "url": "https://www.beyondtrust.com/trust-center/security-advisories/bt24-07" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-290" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T16:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-x58r-7627-pg7c/GHSA-x58r-7627-pg7c.json b/advisories/unreviewed/2024/06/GHSA-x58r-7627-pg7c/GHSA-x58r-7627-pg7c.json new file mode 100644 index 00000000000..3e251ae8ee1 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-x58r-7627-pg7c/GHSA-x58r-7627-pg7c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x58r-7627-pg7c", + "modified": "2024-06-11T18:30:49Z", + "published": "2024-06-11T18:30:49Z", + "aliases": [ + "CVE-2024-30072" + ], + "details": "Microsoft Event Trace Log File Parsing Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30072" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30072" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-x5gf-69xm-cjxm/GHSA-x5gf-69xm-cjxm.json b/advisories/unreviewed/2024/06/GHSA-x5gf-69xm-cjxm/GHSA-x5gf-69xm-cjxm.json new file mode 100644 index 00000000000..ae456f4919d --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-x5gf-69xm-cjxm/GHSA-x5gf-69xm-cjxm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x5gf-69xm-cjxm", + "modified": "2024-06-11T18:30:49Z", + "published": "2024-06-11T18:30:49Z", + "aliases": [ + "CVE-2024-30083" + ], + "details": "Windows Standards-Based Storage Management Service Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30083" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30083" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-x9jg-8xfj-3h48/GHSA-x9jg-8xfj-3h48.json b/advisories/unreviewed/2024/06/GHSA-x9jg-8xfj-3h48/GHSA-x9jg-8xfj-3h48.json new file mode 100644 index 00000000000..4a650146bbe --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-x9jg-8xfj-3h48/GHSA-x9jg-8xfj-3h48.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x9jg-8xfj-3h48", + "modified": "2024-06-11T18:30:49Z", + "published": "2024-06-11T18:30:49Z", + "aliases": [ + "CVE-2024-30087" + ], + "details": "Win32k Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30087" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30087" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T17:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-xj8x-rm7w-xfh4/GHSA-xj8x-rm7w-xfh4.json b/advisories/unreviewed/2024/06/GHSA-xj8x-rm7w-xfh4/GHSA-xj8x-rm7w-xfh4.json index bf8aa3dbbd7..5e3ac57a57b 100644 --- a/advisories/unreviewed/2024/06/GHSA-xj8x-rm7w-xfh4/GHSA-xj8x-rm7w-xfh4.json +++ b/advisories/unreviewed/2024/06/GHSA-xj8x-rm7w-xfh4/GHSA-xj8x-rm7w-xfh4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xj8x-rm7w-xfh4", - "modified": "2024-06-06T12:30:36Z", + "modified": "2024-06-11T18:30:43Z", "published": "2024-06-06T12:30:36Z", "aliases": [ "CVE-2024-5188" @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-xw65-8v8j-f5mq/GHSA-xw65-8v8j-f5mq.json b/advisories/unreviewed/2024/06/GHSA-xw65-8v8j-f5mq/GHSA-xw65-8v8j-f5mq.json index 2a8b176aa9e..1921743cd3d 100644 --- a/advisories/unreviewed/2024/06/GHSA-xw65-8v8j-f5mq/GHSA-xw65-8v8j-f5mq.json +++ b/advisories/unreviewed/2024/06/GHSA-xw65-8v8j-f5mq/GHSA-xw65-8v8j-f5mq.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], "severity": "MODERATE", "github_reviewed": false,