diff --git a/advisories/unreviewed/2023/02/GHSA-wvh6-x26c-2299/GHSA-wvh6-x26c-2299.json b/advisories/unreviewed/2023/02/GHSA-wvh6-x26c-2299/GHSA-wvh6-x26c-2299.json index 538dfbdbb4b..de0969f38f6 100644 --- a/advisories/unreviewed/2023/02/GHSA-wvh6-x26c-2299/GHSA-wvh6-x26c-2299.json +++ b/advisories/unreviewed/2023/02/GHSA-wvh6-x26c-2299/GHSA-wvh6-x26c-2299.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wvh6-x26c-2299", - "modified": "2023-02-10T00:30:20Z", + "modified": "2024-08-06T15:30:46Z", "published": "2023-02-02T21:33:34Z", "aliases": [ "CVE-2023-0253" diff --git a/advisories/unreviewed/2024/03/GHSA-7x4x-j7vx-3p29/GHSA-7x4x-j7vx-3p29.json b/advisories/unreviewed/2024/03/GHSA-7x4x-j7vx-3p29/GHSA-7x4x-j7vx-3p29.json index 795badcb05c..326b575b8c8 100644 --- a/advisories/unreviewed/2024/03/GHSA-7x4x-j7vx-3p29/GHSA-7x4x-j7vx-3p29.json +++ b/advisories/unreviewed/2024/03/GHSA-7x4x-j7vx-3p29/GHSA-7x4x-j7vx-3p29.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7x4x-j7vx-3p29", - "modified": "2024-03-26T15:30:51Z", + "modified": "2024-08-06T15:30:47Z", "published": "2024-03-26T15:30:51Z", "aliases": [ "CVE-2024-23722" ], "details": "In Fluent Bit 2.1.8 through 2.2.1, a NULL pointer dereference can be caused via an invalid HTTP payload with the content type of x-www-form-urlencoded. It crashes and does not restart. This could result in logs not being delivered properly.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-26T15:15:49Z" diff --git a/advisories/unreviewed/2024/03/GHSA-g3pj-7fp2-jhxr/GHSA-g3pj-7fp2-jhxr.json b/advisories/unreviewed/2024/03/GHSA-g3pj-7fp2-jhxr/GHSA-g3pj-7fp2-jhxr.json index 8844e79ef5d..7d63f1bf831 100644 --- a/advisories/unreviewed/2024/03/GHSA-g3pj-7fp2-jhxr/GHSA-g3pj-7fp2-jhxr.json +++ b/advisories/unreviewed/2024/03/GHSA-g3pj-7fp2-jhxr/GHSA-g3pj-7fp2-jhxr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g3pj-7fp2-jhxr", - "modified": "2024-03-26T21:30:47Z", + "modified": "2024-08-06T15:30:47Z", "published": "2024-03-26T21:30:47Z", "aliases": [ "CVE-2024-28545" ], "details": "Tenda AC18 V15.03.05.05 contains a command injection vulnerablility in the deviceName parameter of formsetUsbUnload function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-26T21:15:53Z" diff --git a/advisories/unreviewed/2024/03/GHSA-g56h-9v2h-9x2c/GHSA-g56h-9v2h-9x2c.json b/advisories/unreviewed/2024/03/GHSA-g56h-9v2h-9x2c/GHSA-g56h-9v2h-9x2c.json index 3ca585907f4..e1339f27587 100644 --- a/advisories/unreviewed/2024/03/GHSA-g56h-9v2h-9x2c/GHSA-g56h-9v2h-9x2c.json +++ b/advisories/unreviewed/2024/03/GHSA-g56h-9v2h-9x2c/GHSA-g56h-9v2h-9x2c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g56h-9v2h-9x2c", - "modified": "2024-03-07T03:30:41Z", + "modified": "2024-08-06T15:30:46Z", "published": "2024-03-07T03:30:41Z", "aliases": [ "CVE-2024-26566" ], "details": "An issue in Cute Http File Server v.3.1 allows a remote attacker to escalate privileges via the password verification component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-288" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-07T01:15:52Z" diff --git a/advisories/unreviewed/2024/03/GHSA-jmmm-pcpp-rrc4/GHSA-jmmm-pcpp-rrc4.json b/advisories/unreviewed/2024/03/GHSA-jmmm-pcpp-rrc4/GHSA-jmmm-pcpp-rrc4.json index 287ddae51f5..49feefdd961 100644 --- a/advisories/unreviewed/2024/03/GHSA-jmmm-pcpp-rrc4/GHSA-jmmm-pcpp-rrc4.json +++ b/advisories/unreviewed/2024/03/GHSA-jmmm-pcpp-rrc4/GHSA-jmmm-pcpp-rrc4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jmmm-pcpp-rrc4", - "modified": "2024-03-06T09:30:26Z", + "modified": "2024-08-06T15:30:47Z", "published": "2024-03-06T09:30:26Z", "aliases": [ "CVE-2023-52584" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nspmi: mediatek: Fix UAF on device remove\n\nThe pmif driver data that contains the clocks is allocated along with\nspmi_controller.\nOn device remove, spmi_controller will be freed first, and then devres\n, including the clocks, will be cleanup.\nThis leads to UAF because putting the clocks will access the clocks in\nthe pmif driver data, which is already freed along with spmi_controller.\n\nThis can be reproduced by enabling DEBUG_TEST_DRIVER_REMOVE and\nbuilding the kernel with KASAN.\n\nFix the UAF issue by using unmanaged clk_bulk_get() and putting the\nclocks before freeing spmi_controller.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-06T07:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-qhcw-x4hm-xwrx/GHSA-qhcw-x4hm-xwrx.json b/advisories/unreviewed/2024/03/GHSA-qhcw-x4hm-xwrx/GHSA-qhcw-x4hm-xwrx.json index 520221d3c73..14ab6da7489 100644 --- a/advisories/unreviewed/2024/03/GHSA-qhcw-x4hm-xwrx/GHSA-qhcw-x4hm-xwrx.json +++ b/advisories/unreviewed/2024/03/GHSA-qhcw-x4hm-xwrx/GHSA-qhcw-x4hm-xwrx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qhcw-x4hm-xwrx", - "modified": "2024-03-21T03:36:45Z", + "modified": "2024-08-06T15:30:47Z", "published": "2024-03-21T03:36:45Z", "aliases": [ "CVE-2023-49983" ], "details": "A cross-site scripting (XSS) vulnerability in the component /management/class of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-21T02:49:38Z" diff --git a/advisories/unreviewed/2024/03/GHSA-r8c8-q2jq-wjq4/GHSA-r8c8-q2jq-wjq4.json b/advisories/unreviewed/2024/03/GHSA-r8c8-q2jq-wjq4/GHSA-r8c8-q2jq-wjq4.json index 76180f9c7bd..ac78c7b0758 100644 --- a/advisories/unreviewed/2024/03/GHSA-r8c8-q2jq-wjq4/GHSA-r8c8-q2jq-wjq4.json +++ b/advisories/unreviewed/2024/03/GHSA-r8c8-q2jq-wjq4/GHSA-r8c8-q2jq-wjq4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r8c8-q2jq-wjq4", - "modified": "2024-03-07T21:30:22Z", + "modified": "2024-08-06T15:30:47Z", "published": "2024-03-07T21:30:22Z", "aliases": [ "CVE-2024-27707" ], "details": "Server Side Request Forgery (SSRF) vulnerability in hcengineering Huly Platform v.0.6.202 allows attackers to run arbitrary code via upload of crafted SVG file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-918" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-07T21:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-rxm4-85x6-2778/GHSA-rxm4-85x6-2778.json b/advisories/unreviewed/2024/03/GHSA-rxm4-85x6-2778/GHSA-rxm4-85x6-2778.json index a064abbaebc..d7b4e1dde6d 100644 --- a/advisories/unreviewed/2024/03/GHSA-rxm4-85x6-2778/GHSA-rxm4-85x6-2778.json +++ b/advisories/unreviewed/2024/03/GHSA-rxm4-85x6-2778/GHSA-rxm4-85x6-2778.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rxm4-85x6-2778", - "modified": "2024-03-06T03:30:29Z", + "modified": "2024-08-06T15:30:46Z", "published": "2024-03-06T03:30:29Z", "aliases": [ "CVE-2023-49971" ], "details": "A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the firstname parameter at /customer_support/index.php?page=customer_list.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-06T01:15:07Z" diff --git a/advisories/unreviewed/2024/06/GHSA-5frq-4cx3-frc8/GHSA-5frq-4cx3-frc8.json b/advisories/unreviewed/2024/06/GHSA-5frq-4cx3-frc8/GHSA-5frq-4cx3-frc8.json index b6d320dba85..ed6bb422d9f 100644 --- a/advisories/unreviewed/2024/06/GHSA-5frq-4cx3-frc8/GHSA-5frq-4cx3-frc8.json +++ b/advisories/unreviewed/2024/06/GHSA-5frq-4cx3-frc8/GHSA-5frq-4cx3-frc8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5frq-4cx3-frc8", - "modified": "2024-06-11T12:31:02Z", + "modified": "2024-08-06T15:30:47Z", "published": "2024-06-11T12:31:02Z", "aliases": [ "CVE-2024-35206" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-988h-7hff-q3fr/GHSA-988h-7hff-q3fr.json b/advisories/unreviewed/2024/06/GHSA-988h-7hff-q3fr/GHSA-988h-7hff-q3fr.json index 2511409d47f..f154e42ca3b 100644 --- a/advisories/unreviewed/2024/06/GHSA-988h-7hff-q3fr/GHSA-988h-7hff-q3fr.json +++ b/advisories/unreviewed/2024/06/GHSA-988h-7hff-q3fr/GHSA-988h-7hff-q3fr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-988h-7hff-q3fr", - "modified": "2024-06-15T03:30:35Z", + "modified": "2024-08-06T15:30:48Z", "published": "2024-06-15T03:30:35Z", "aliases": [ "CVE-2023-6696" @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-m249-8gm7-xrcf/GHSA-m249-8gm7-xrcf.json b/advisories/unreviewed/2024/06/GHSA-m249-8gm7-xrcf/GHSA-m249-8gm7-xrcf.json index 97f1d3c9251..49eb4aad71d 100644 --- a/advisories/unreviewed/2024/06/GHSA-m249-8gm7-xrcf/GHSA-m249-8gm7-xrcf.json +++ b/advisories/unreviewed/2024/06/GHSA-m249-8gm7-xrcf/GHSA-m249-8gm7-xrcf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m249-8gm7-xrcf", - "modified": "2024-06-11T12:31:02Z", + "modified": "2024-08-06T15:30:47Z", "published": "2024-06-11T12:31:02Z", "aliases": [ "CVE-2024-35207" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-ppq4-8j5q-qjjx/GHSA-ppq4-8j5q-qjjx.json b/advisories/unreviewed/2024/06/GHSA-ppq4-8j5q-qjjx/GHSA-ppq4-8j5q-qjjx.json index dc6294d9109..54238c43c8a 100644 --- a/advisories/unreviewed/2024/06/GHSA-ppq4-8j5q-qjjx/GHSA-ppq4-8j5q-qjjx.json +++ b/advisories/unreviewed/2024/06/GHSA-ppq4-8j5q-qjjx/GHSA-ppq4-8j5q-qjjx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ppq4-8j5q-qjjx", - "modified": "2024-06-11T12:31:02Z", + "modified": "2024-08-06T15:30:47Z", "published": "2024-06-11T12:31:02Z", "aliases": [ "CVE-2024-35209" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-qhx2-rhqq-2wmm/GHSA-qhx2-rhqq-2wmm.json b/advisories/unreviewed/2024/06/GHSA-qhx2-rhqq-2wmm/GHSA-qhx2-rhqq-2wmm.json index be99dc4c9e6..596301a073d 100644 --- a/advisories/unreviewed/2024/06/GHSA-qhx2-rhqq-2wmm/GHSA-qhx2-rhqq-2wmm.json +++ b/advisories/unreviewed/2024/06/GHSA-qhx2-rhqq-2wmm/GHSA-qhx2-rhqq-2wmm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qhx2-rhqq-2wmm", - "modified": "2024-06-11T12:31:02Z", + "modified": "2024-08-06T15:30:47Z", "published": "2024-06-11T12:31:02Z", "aliases": [ "CVE-2024-35211" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-qvr7-cp8f-g7f2/GHSA-qvr7-cp8f-g7f2.json b/advisories/unreviewed/2024/06/GHSA-qvr7-cp8f-g7f2/GHSA-qvr7-cp8f-g7f2.json index 01162ab4db6..f4498e705f2 100644 --- a/advisories/unreviewed/2024/06/GHSA-qvr7-cp8f-g7f2/GHSA-qvr7-cp8f-g7f2.json +++ b/advisories/unreviewed/2024/06/GHSA-qvr7-cp8f-g7f2/GHSA-qvr7-cp8f-g7f2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qvr7-cp8f-g7f2", - "modified": "2024-06-11T12:31:02Z", + "modified": "2024-08-06T15:30:47Z", "published": "2024-06-11T12:31:02Z", "aliases": [ "CVE-2024-35212" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-rqwx-x259-3ggm/GHSA-rqwx-x259-3ggm.json b/advisories/unreviewed/2024/06/GHSA-rqwx-x259-3ggm/GHSA-rqwx-x259-3ggm.json index 28fb002d3dd..83551533277 100644 --- a/advisories/unreviewed/2024/06/GHSA-rqwx-x259-3ggm/GHSA-rqwx-x259-3ggm.json +++ b/advisories/unreviewed/2024/06/GHSA-rqwx-x259-3ggm/GHSA-rqwx-x259-3ggm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rqwx-x259-3ggm", - "modified": "2024-06-11T12:31:02Z", + "modified": "2024-08-06T15:30:47Z", "published": "2024-06-11T12:31:02Z", "aliases": [ "CVE-2024-35208" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-wv82-j9h6-2q8w/GHSA-wv82-j9h6-2q8w.json b/advisories/unreviewed/2024/06/GHSA-wv82-j9h6-2q8w/GHSA-wv82-j9h6-2q8w.json index 641e62a00a1..abcb570528e 100644 --- a/advisories/unreviewed/2024/06/GHSA-wv82-j9h6-2q8w/GHSA-wv82-j9h6-2q8w.json +++ b/advisories/unreviewed/2024/06/GHSA-wv82-j9h6-2q8w/GHSA-wv82-j9h6-2q8w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wv82-j9h6-2q8w", - "modified": "2024-06-07T18:30:38Z", + "modified": "2024-08-06T15:30:47Z", "published": "2024-06-07T18:30:38Z", "aliases": [ "CVE-2024-5745" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-wxxx-g5q4-gvrr/GHSA-wxxx-g5q4-gvrr.json b/advisories/unreviewed/2024/06/GHSA-wxxx-g5q4-gvrr/GHSA-wxxx-g5q4-gvrr.json index 1465f721244..ee9f0c97b71 100644 --- a/advisories/unreviewed/2024/06/GHSA-wxxx-g5q4-gvrr/GHSA-wxxx-g5q4-gvrr.json +++ b/advisories/unreviewed/2024/06/GHSA-wxxx-g5q4-gvrr/GHSA-wxxx-g5q4-gvrr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wxxx-g5q4-gvrr", - "modified": "2024-06-20T18:34:09Z", + "modified": "2024-08-06T15:30:48Z", "published": "2024-06-20T18:34:09Z", "aliases": [ "CVE-2024-37344" diff --git a/advisories/unreviewed/2024/06/GHSA-x8h6-96m2-gv4q/GHSA-x8h6-96m2-gv4q.json b/advisories/unreviewed/2024/06/GHSA-x8h6-96m2-gv4q/GHSA-x8h6-96m2-gv4q.json index 2030633fac2..6b92ea4536c 100644 --- a/advisories/unreviewed/2024/06/GHSA-x8h6-96m2-gv4q/GHSA-x8h6-96m2-gv4q.json +++ b/advisories/unreviewed/2024/06/GHSA-x8h6-96m2-gv4q/GHSA-x8h6-96m2-gv4q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x8h6-96m2-gv4q", - "modified": "2024-06-11T12:31:02Z", + "modified": "2024-08-06T15:30:47Z", "published": "2024-06-11T12:31:02Z", "aliases": [ "CVE-2024-35210" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/07/GHSA-86g8-833h-3hcm/GHSA-86g8-833h-3hcm.json b/advisories/unreviewed/2024/07/GHSA-86g8-833h-3hcm/GHSA-86g8-833h-3hcm.json index e97a13dff59..53326776557 100644 --- a/advisories/unreviewed/2024/07/GHSA-86g8-833h-3hcm/GHSA-86g8-833h-3hcm.json +++ b/advisories/unreviewed/2024/07/GHSA-86g8-833h-3hcm/GHSA-86g8-833h-3hcm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-86g8-833h-3hcm", - "modified": "2024-07-12T15:31:28Z", + "modified": "2024-08-06T15:30:48Z", "published": "2024-07-12T15:31:28Z", "aliases": [ "CVE-2024-40951" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: fix NULL pointer dereference in ocfs2_abort_trigger()\n\nbdev->bd_super has been removed and commit 8887b94d9322 change the usage\nfrom bdev->bd_super to b_assoc_map->host->i_sb. Since ocfs2 hasn't set\nbh->b_assoc_map, it will trigger NULL pointer dereference when calling\ninto ocfs2_abort_trigger().\n\nActually this was pointed out in history, see commit 74e364ad1b13. But\nI've made a mistake when reviewing commit 8887b94d9322 and then\nre-introduce this regression.\n\nSince we cannot revive bdev in buffer head, so fix this issue by\ninitializing all types of ocfs2 triggers when fill super, and then get the\nspecific ocfs2 trigger from ocfs2_caching_info when access journal.\n\n[joseph.qi@linux.alibaba.com: v2]\n Link: https://lkml.kernel.org/r/20240602112045.1112708-1-joseph.qi@linux.alibaba.com", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-12T13:15:17Z" diff --git a/advisories/unreviewed/2024/07/GHSA-8vm5-mx6j-hvfc/GHSA-8vm5-mx6j-hvfc.json b/advisories/unreviewed/2024/07/GHSA-8vm5-mx6j-hvfc/GHSA-8vm5-mx6j-hvfc.json index 6acbefd2087..6b5d6e8bc80 100644 --- a/advisories/unreviewed/2024/07/GHSA-8vm5-mx6j-hvfc/GHSA-8vm5-mx6j-hvfc.json +++ b/advisories/unreviewed/2024/07/GHSA-8vm5-mx6j-hvfc/GHSA-8vm5-mx6j-hvfc.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8vm5-mx6j-hvfc", - "modified": "2024-08-01T09:30:48Z", + "modified": "2024-08-06T15:30:48Z", "published": "2024-07-26T12:35:48Z", "aliases": [ "CVE-2024-41684" ], "details": "This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to missing secure flag for the session cookies associated with the router's web management interface. An attacker with remote access could exploit this by intercepting transmission within an HTTP session on the vulnerable system.\n\nSuccessful exploitation of this vulnerability could allow the attacker to capture cookies and compromise the targeted system.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/07/GHSA-fvwv-5fff-6fx2/GHSA-fvwv-5fff-6fx2.json b/advisories/unreviewed/2024/07/GHSA-fvwv-5fff-6fx2/GHSA-fvwv-5fff-6fx2.json index be11ecdba98..46a26d108ad 100644 --- a/advisories/unreviewed/2024/07/GHSA-fvwv-5fff-6fx2/GHSA-fvwv-5fff-6fx2.json +++ b/advisories/unreviewed/2024/07/GHSA-fvwv-5fff-6fx2/GHSA-fvwv-5fff-6fx2.json @@ -44,7 +44,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-120" + "CWE-120", + "CWE-77" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-phh7-8q4v-gv55/GHSA-phh7-8q4v-gv55.json b/advisories/unreviewed/2024/07/GHSA-phh7-8q4v-gv55/GHSA-phh7-8q4v-gv55.json index 7ccedea5961..0b3e38df070 100644 --- a/advisories/unreviewed/2024/07/GHSA-phh7-8q4v-gv55/GHSA-phh7-8q4v-gv55.json +++ b/advisories/unreviewed/2024/07/GHSA-phh7-8q4v-gv55/GHSA-phh7-8q4v-gv55.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-phh7-8q4v-gv55", - "modified": "2024-08-01T09:30:49Z", + "modified": "2024-08-06T15:30:48Z", "published": "2024-07-26T12:35:49Z", "aliases": [ "CVE-2024-41686" ], "details": "This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to improper implementation of password policies. A local attacker could exploit this by creating password that do not adhere to the defined security standards/policy on the vulnerable system.\n\nSuccessful exploitation of this vulnerability could allow the attacker to expose the router to potential security threats.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:A/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/07/GHSA-w9qp-xc8f-8xcq/GHSA-w9qp-xc8f-8xcq.json b/advisories/unreviewed/2024/07/GHSA-w9qp-xc8f-8xcq/GHSA-w9qp-xc8f-8xcq.json index e96608f030d..863c3057f18 100644 --- a/advisories/unreviewed/2024/07/GHSA-w9qp-xc8f-8xcq/GHSA-w9qp-xc8f-8xcq.json +++ b/advisories/unreviewed/2024/07/GHSA-w9qp-xc8f-8xcq/GHSA-w9qp-xc8f-8xcq.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w9qp-xc8f-8xcq", - "modified": "2024-08-01T09:30:48Z", + "modified": "2024-08-06T15:30:48Z", "published": "2024-07-26T12:35:49Z", "aliases": [ "CVE-2024-41685" ], "details": "This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to missing HTTPOnly flag for the session cookies associated with the router's web management interface. An attacker with remote access could exploit this by intercepting transmission within an HTTP session on the vulnerable system.\n\nSuccessful exploitation of this vulnerability could allow the attacker to capture cookies and obtain sensitive information on the targeted system.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" @@ -32,7 +36,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-1004" + "CWE-1004", + "CWE-732" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-x3j2-v37x-2v84/GHSA-x3j2-v37x-2v84.json b/advisories/unreviewed/2024/07/GHSA-x3j2-v37x-2v84/GHSA-x3j2-v37x-2v84.json index fc6a4e0c7f4..ac0d205f346 100644 --- a/advisories/unreviewed/2024/07/GHSA-x3j2-v37x-2v84/GHSA-x3j2-v37x-2v84.json +++ b/advisories/unreviewed/2024/07/GHSA-x3j2-v37x-2v84/GHSA-x3j2-v37x-2v84.json @@ -44,7 +44,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-120" + "CWE-120", + "CWE-77" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-2pc2-wxgf-m9mm/GHSA-2pc2-wxgf-m9mm.json b/advisories/unreviewed/2024/08/GHSA-2pc2-wxgf-m9mm/GHSA-2pc2-wxgf-m9mm.json new file mode 100644 index 00000000000..18b50f85d16 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-2pc2-wxgf-m9mm/GHSA-2pc2-wxgf-m9mm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2pc2-wxgf-m9mm", + "modified": "2024-08-06T15:30:52Z", + "published": "2024-08-06T15:30:52Z", + "aliases": [ + "CVE-2024-33990" + ], + "details": "Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted javascript payload to an authenticated user and partially take over their browser session via the 'id' and 'view' parameters in '/user/index.php'.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33990" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-janobe-products" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T13:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-3jj9-9269-99m2/GHSA-3jj9-9269-99m2.json b/advisories/unreviewed/2024/08/GHSA-3jj9-9269-99m2/GHSA-3jj9-9269-99m2.json new file mode 100644 index 00000000000..60060a95cc2 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-3jj9-9269-99m2/GHSA-3jj9-9269-99m2.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3jj9-9269-99m2", + "modified": "2024-08-06T15:30:54Z", + "published": "2024-08-06T15:30:54Z", + "aliases": [ + "CVE-2024-7531" + ], + "details": "Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input and output can result in plaintext on an Intel Sandy Bridge processor. In Firefox this only affects the QUIC header protection feature when the connection is using the ChaCha20-Poly1305 cipher suite. The most likely outcome is connection failure, but if the connection persists despite the high packet loss it could be possible for a network observer to identify packets as coming from the same source despite a network path change. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, and Firefox ESR < 128.1.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7531" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1905691" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-33" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-34" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-35" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T13:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-4356-g44g-mrvh/GHSA-4356-g44g-mrvh.json b/advisories/unreviewed/2024/08/GHSA-4356-g44g-mrvh/GHSA-4356-g44g-mrvh.json new file mode 100644 index 00000000000..5c423490259 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-4356-g44g-mrvh/GHSA-4356-g44g-mrvh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4356-g44g-mrvh", + "modified": "2024-08-06T15:30:50Z", + "published": "2024-08-06T15:30:50Z", + "aliases": [ + "CVE-2024-33982" + ], + "details": "Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'StudentID' parameter in '/AttendanceMonitoring/student/controller.php'.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33982" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-janobe-products" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T13:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-46r4-hcf2-8pmx/GHSA-46r4-hcf2-8pmx.json b/advisories/unreviewed/2024/08/GHSA-46r4-hcf2-8pmx/GHSA-46r4-hcf2-8pmx.json new file mode 100644 index 00000000000..32acfc79bb3 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-46r4-hcf2-8pmx/GHSA-46r4-hcf2-8pmx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-46r4-hcf2-8pmx", + "modified": "2024-08-06T15:30:54Z", + "published": "2024-08-06T15:30:54Z", + "aliases": [ + "CVE-2024-41913" + ], + "details": "A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware flaw does not properly sanitize User input.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41913" + }, + { + "type": "WEB", + "url": "https://support.hp.com/us-en/document/ish_11006488-11006512-16/hpsbpy03957" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T14:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-4cx5-2fr7-x88f/GHSA-4cx5-2fr7-x88f.json b/advisories/unreviewed/2024/08/GHSA-4cx5-2fr7-x88f/GHSA-4cx5-2fr7-x88f.json new file mode 100644 index 00000000000..fbf1e0e7cdc --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-4cx5-2fr7-x88f/GHSA-4cx5-2fr7-x88f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4cx5-2fr7-x88f", + "modified": "2024-08-06T15:30:51Z", + "published": "2024-08-06T15:30:51Z", + "aliases": [ + "CVE-2024-33985" + ], + "details": "Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'View' parameter in '/course/index.php'.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33985" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-janobe-products" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T13:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-4r77-5qxj-vjjj/GHSA-4r77-5qxj-vjjj.json b/advisories/unreviewed/2024/08/GHSA-4r77-5qxj-vjjj/GHSA-4r77-5qxj-vjjj.json new file mode 100644 index 00000000000..db083af7086 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-4r77-5qxj-vjjj/GHSA-4r77-5qxj-vjjj.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4r77-5qxj-vjjj", + "modified": "2024-08-06T15:30:54Z", + "published": "2024-08-06T15:30:54Z", + "aliases": [ + "CVE-2023-40819" + ], + "details": "ID4Portais in version < V.2022.837.002a returns message parameter unsanitized in the response, resulting in a HTML Injection vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40819" + }, + { + "type": "WEB", + "url": "https://miguelsantareno.github.io/id4Portais.txt" + }, + { + "type": "WEB", + "url": "https://www.id4software.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T14:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-4rgj-6vvq-8853/GHSA-4rgj-6vvq-8853.json b/advisories/unreviewed/2024/08/GHSA-4rgj-6vvq-8853/GHSA-4rgj-6vvq-8853.json new file mode 100644 index 00000000000..a626b11afea --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-4rgj-6vvq-8853/GHSA-4rgj-6vvq-8853.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4rgj-6vvq-8853", + "modified": "2024-08-06T15:30:52Z", + "published": "2024-08-06T15:30:52Z", + "aliases": [ + "CVE-2024-33994" + ], + "details": "Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain their session details via the 'view' parameter in '/event/index.php'.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33994" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-janobe-products" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T13:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-4xc3-7r7g-7vx3/GHSA-4xc3-7r7g-7vx3.json b/advisories/unreviewed/2024/08/GHSA-4xc3-7r7g-7vx3/GHSA-4xc3-7r7g-7vx3.json new file mode 100644 index 00000000000..6c1780e00df --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-4xc3-7r7g-7vx3/GHSA-4xc3-7r7g-7vx3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4xc3-7r7g-7vx3", + "modified": "2024-08-06T15:30:54Z", + "published": "2024-08-06T15:30:54Z", + "aliases": [ + "CVE-2024-7530" + ], + "details": "Incorrect garbage collection interaction could have led to a use-after-free. This vulnerability affects Firefox < 129.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7530" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1904011" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-33" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T13:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-524f-m549-hffh/GHSA-524f-m549-hffh.json b/advisories/unreviewed/2024/08/GHSA-524f-m549-hffh/GHSA-524f-m549-hffh.json new file mode 100644 index 00000000000..331e185d293 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-524f-m549-hffh/GHSA-524f-m549-hffh.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-524f-m549-hffh", + "modified": "2024-08-06T15:30:54Z", + "published": "2024-08-06T15:30:54Z", + "aliases": [ + "CVE-2024-7551" + ], + "details": "A vulnerability was found in juzaweb CMS up to 3.4.2. It has been classified as problematic. Affected is an unknown function of the file /admin-cp/theme/editor/default of the component Theme Editor. The manipulation leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273696. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7551" + }, + { + "type": "WEB", + "url": "https://github.com/DeepMountains/Mirage/blob/main/CVE9-1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.273696" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.273696" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.381444" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T13:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-563c-g7mm-g4xp/GHSA-563c-g7mm-g4xp.json b/advisories/unreviewed/2024/08/GHSA-563c-g7mm-g4xp/GHSA-563c-g7mm-g4xp.json new file mode 100644 index 00000000000..afb66dad009 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-563c-g7mm-g4xp/GHSA-563c-g7mm-g4xp.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-563c-g7mm-g4xp", + "modified": "2024-08-06T15:30:53Z", + "published": "2024-08-06T15:30:53Z", + "aliases": [ + "CVE-2024-7521" + ], + "details": "Incomplete WebAssembly exception handing could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, and Firefox ESR < 128.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7521" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1904644" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-33" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-34" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-35" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-755" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T13:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-69x6-6jqx-q847/GHSA-69x6-6jqx-q847.json b/advisories/unreviewed/2024/08/GHSA-69x6-6jqx-q847/GHSA-69x6-6jqx-q847.json new file mode 100644 index 00000000000..37597be3db1 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-69x6-6jqx-q847/GHSA-69x6-6jqx-q847.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-69x6-6jqx-q847", + "modified": "2024-08-06T15:30:53Z", + "published": "2024-08-06T15:30:53Z", + "aliases": [ + "CVE-2024-7527" + ], + "details": "Unexpected marking work at the start of sweeping could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, and Firefox ESR < 128.1.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7527" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1871303" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-33" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-34" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-35" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T13:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7369-x5q2-rh2m/GHSA-7369-x5q2-rh2m.json b/advisories/unreviewed/2024/08/GHSA-7369-x5q2-rh2m/GHSA-7369-x5q2-rh2m.json new file mode 100644 index 00000000000..ccda3402b44 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-7369-x5q2-rh2m/GHSA-7369-x5q2-rh2m.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7369-x5q2-rh2m", + "modified": "2024-08-06T15:30:53Z", + "published": "2024-08-06T15:30:53Z", + "aliases": [ + "CVE-2024-7525" + ], + "details": "It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and modify the response body of requests on any site. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, and Firefox ESR < 128.1.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7525" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1909298" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-33" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-34" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-35" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T13:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7j5g-jfh2-w58c/GHSA-7j5g-jfh2-w58c.json b/advisories/unreviewed/2024/08/GHSA-7j5g-jfh2-w58c/GHSA-7j5g-jfh2-w58c.json new file mode 100644 index 00000000000..e299fb5545a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-7j5g-jfh2-w58c/GHSA-7j5g-jfh2-w58c.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7j5g-jfh2-w58c", + "modified": "2024-08-06T15:30:53Z", + "published": "2024-08-06T15:30:53Z", + "aliases": [ + "CVE-2024-7520" + ], + "details": "A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code execution. This vulnerability affects Firefox < 129 and Firefox ESR < 128.1.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7520" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1903041" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-33" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-35" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T13:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7jrj-xq8x-h553/GHSA-7jrj-xq8x-h553.json b/advisories/unreviewed/2024/08/GHSA-7jrj-xq8x-h553/GHSA-7jrj-xq8x-h553.json new file mode 100644 index 00000000000..74957ea2aa3 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-7jrj-xq8x-h553/GHSA-7jrj-xq8x-h553.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7jrj-xq8x-h553", + "modified": "2024-08-06T15:30:53Z", + "published": "2024-08-06T15:30:53Z", + "aliases": [ + "CVE-2024-7522" + ], + "details": "Editor code failed to check an attribute value. This could have led to an out-of-bounds read. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, and Firefox ESR < 128.1.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7522" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1906727" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-33" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-34" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-35" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T13:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7m9h-4qg6-4hmh/GHSA-7m9h-4qg6-4hmh.json b/advisories/unreviewed/2024/08/GHSA-7m9h-4qg6-4hmh/GHSA-7m9h-4qg6-4hmh.json new file mode 100644 index 00000000000..51624dcf746 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-7m9h-4qg6-4hmh/GHSA-7m9h-4qg6-4hmh.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7m9h-4qg6-4hmh", + "modified": "2024-08-06T15:30:53Z", + "published": "2024-08-06T15:30:53Z", + "aliases": [ + "CVE-2024-7524" + ], + "details": "Firefox adds web-compatibility shims in place of some tracking scripts blocked by Enhanced Tracking Protection. On a site protected by Content Security Policy in \"strict-dynamic\" mode, an attacker able to inject an HTML element could have used a DOM Clobbering attack on some of the shims and achieved XSS, bypassing the CSP strict-dynamic protection. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, and Firefox ESR < 128.1.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7524" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1909241" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-33" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-34" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-35" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T13:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7xp8-p4r3-6rv8/GHSA-7xp8-p4r3-6rv8.json b/advisories/unreviewed/2024/08/GHSA-7xp8-p4r3-6rv8/GHSA-7xp8-p4r3-6rv8.json new file mode 100644 index 00000000000..2ee5488fd70 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-7xp8-p4r3-6rv8/GHSA-7xp8-p4r3-6rv8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7xp8-p4r3-6rv8", + "modified": "2024-08-06T15:30:54Z", + "published": "2024-08-06T15:30:54Z", + "aliases": [ + "CVE-2024-41911" + ], + "details": "A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The flaw does not properly neutralize input during a web page generation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41911" + }, + { + "type": "WEB", + "url": "https://support.hp.com/us-en/document/ish_11006770-11006795-16/hpsbpy03959" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T14:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-853r-xr2f-r2x6/GHSA-853r-xr2f-r2x6.json b/advisories/unreviewed/2024/08/GHSA-853r-xr2f-r2x6/GHSA-853r-xr2f-r2x6.json index 85a4b7d474f..22242a31571 100644 --- a/advisories/unreviewed/2024/08/GHSA-853r-xr2f-r2x6/GHSA-853r-xr2f-r2x6.json +++ b/advisories/unreviewed/2024/08/GHSA-853r-xr2f-r2x6/GHSA-853r-xr2f-r2x6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-853r-xr2f-r2x6", - "modified": "2024-08-05T21:31:19Z", + "modified": "2024-08-06T15:30:50Z", "published": "2024-08-05T21:31:19Z", "aliases": [ "CVE-2024-42010" ], "details": "mod_css_styles in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a insufficiently filters Cascading Style Sheets (CSS) token sequences in rendered e-mail messages, allowing a remote attacker to obtain sensitive information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-05T19:15:38Z" diff --git a/advisories/unreviewed/2024/08/GHSA-9hr8-jgq4-7m7w/GHSA-9hr8-jgq4-7m7w.json b/advisories/unreviewed/2024/08/GHSA-9hr8-jgq4-7m7w/GHSA-9hr8-jgq4-7m7w.json new file mode 100644 index 00000000000..c0a7e46383d --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-9hr8-jgq4-7m7w/GHSA-9hr8-jgq4-7m7w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9hr8-jgq4-7m7w", + "modified": "2024-08-06T15:30:52Z", + "published": "2024-08-06T15:30:52Z", + "aliases": [ + "CVE-2024-33991" + ], + "details": "Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the 'view' parameter in '/eventwinner/index.php'.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33991" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-janobe-products" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T13:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-9wvx-3hw8-4ghf/GHSA-9wvx-3hw8-4ghf.json b/advisories/unreviewed/2024/08/GHSA-9wvx-3hw8-4ghf/GHSA-9wvx-3hw8-4ghf.json new file mode 100644 index 00000000000..03dd58d365d --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-9wvx-3hw8-4ghf/GHSA-9wvx-3hw8-4ghf.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9wvx-3hw8-4ghf", + "modified": "2024-08-06T15:30:53Z", + "published": "2024-08-06T15:30:53Z", + "aliases": [ + "CVE-2024-7519" + ], + "details": "Insufficient checks when processing graphics shared memory could have led to memory corruption. This could be leveraged by an attacker to perform a sandbox escape. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, and Firefox ESR < 128.1.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7519" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1902307" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-33" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-34" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-35" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T13:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-cg4j-f388-m354/GHSA-cg4j-f388-m354.json b/advisories/unreviewed/2024/08/GHSA-cg4j-f388-m354/GHSA-cg4j-f388-m354.json new file mode 100644 index 00000000000..243f0416711 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-cg4j-f388-m354/GHSA-cg4j-f388-m354.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cg4j-f388-m354", + "modified": "2024-08-06T15:30:54Z", + "published": "2024-08-06T15:30:54Z", + "aliases": [ + "CVE-2024-41226" + ], + "details": "A CSV injection vulnerability in Automation Anywhere Automation 360 version 21094 allows attackers to execute arbitrary code via a crafted payload.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41226" + }, + { + "type": "WEB", + "url": "https://medium.com/%40aksalsalimi/cve-2024-41226-response-manipulation-led-to-csv-injection-9ae3182dcc02" + }, + { + "type": "WEB", + "url": "https://www.automationanywhere.com/products/automation-360" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T14:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-cmwh-2hhq-v8pr/GHSA-cmwh-2hhq-v8pr.json b/advisories/unreviewed/2024/08/GHSA-cmwh-2hhq-v8pr/GHSA-cmwh-2hhq-v8pr.json new file mode 100644 index 00000000000..7eaf60c97b7 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-cmwh-2hhq-v8pr/GHSA-cmwh-2hhq-v8pr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cmwh-2hhq-v8pr", + "modified": "2024-08-06T15:30:53Z", + "published": "2024-08-06T15:30:53Z", + "aliases": [ + "CVE-2024-6359" + ], + "details": "Privilege escalation vulnerability identified in OpenText ArcSight Intelligence.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6359" + }, + { + "type": "WEB", + "url": "https://portal.microfocus.com/s/article/KM000032594" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T13:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-cr94-c6j4-q6g5/GHSA-cr94-c6j4-q6g5.json b/advisories/unreviewed/2024/08/GHSA-cr94-c6j4-q6g5/GHSA-cr94-c6j4-q6g5.json new file mode 100644 index 00000000000..c7ad1a6fc82 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-cr94-c6j4-q6g5/GHSA-cr94-c6j4-q6g5.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cr94-c6j4-q6g5", + "modified": "2024-08-06T15:30:54Z", + "published": "2024-08-06T15:30:54Z", + "aliases": [ + "CVE-2024-7529" + ], + "details": "The date picker could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, and Firefox ESR < 128.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7529" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1903187" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-33" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-34" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-35" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-451" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T13:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-g4q9-9x6g-wwh5/GHSA-g4q9-9x6g-wwh5.json b/advisories/unreviewed/2024/08/GHSA-g4q9-9x6g-wwh5/GHSA-g4q9-9x6g-wwh5.json new file mode 100644 index 00000000000..5f6e19d8fa1 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-g4q9-9x6g-wwh5/GHSA-g4q9-9x6g-wwh5.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g4q9-9x6g-wwh5", + "modified": "2024-08-06T15:30:54Z", + "published": "2024-08-06T15:30:54Z", + "aliases": [ + "CVE-2024-7552" + ], + "details": "A vulnerability was found in DataGear up to 5.0.0. It has been declared as critical. Affected by this vulnerability is the function evaluateVariableExpression of the file ConversionSqlParamValueMapper.java of the component Data Schema Page. The manipulation leads to improper neutralization of special elements used in an expression language statement. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273697 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7552" + }, + { + "type": "WEB", + "url": "https://gitee.com/datagear/datagear/issues/IAF3H7" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.273697" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.273697" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.386413" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-917" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T15:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-g5qq-hwhg-8q48/GHSA-g5qq-hwhg-8q48.json b/advisories/unreviewed/2024/08/GHSA-g5qq-hwhg-8q48/GHSA-g5qq-hwhg-8q48.json new file mode 100644 index 00000000000..78f28fb6f8f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-g5qq-hwhg-8q48/GHSA-g5qq-hwhg-8q48.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g5qq-hwhg-8q48", + "modified": "2024-08-06T15:30:51Z", + "published": "2024-08-06T15:30:51Z", + "aliases": [ + "CVE-2024-33988" + ], + "details": "Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'Attendance', 'attenddate' and 'YearLevel' parameters in '/report/attendance_print.php'.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33988" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-janobe-products" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T13:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-g9cm-cgc6-5pfc/GHSA-g9cm-cgc6-5pfc.json b/advisories/unreviewed/2024/08/GHSA-g9cm-cgc6-5pfc/GHSA-g9cm-cgc6-5pfc.json new file mode 100644 index 00000000000..35ac6010fe6 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-g9cm-cgc6-5pfc/GHSA-g9cm-cgc6-5pfc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g9cm-cgc6-5pfc", + "modified": "2024-08-06T15:30:51Z", + "published": "2024-08-06T15:30:51Z", + "aliases": [ + "CVE-2024-33987" + ], + "details": "Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'Attendance', 'attenddate', 'YearLevel', 'eventdate', 'events', 'Users' and 'YearLevel' parameters in '/report/index.php'.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33987" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-janobe-products" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T13:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-ggq6-w6jr-x8x2/GHSA-ggq6-w6jr-x8x2.json b/advisories/unreviewed/2024/08/GHSA-ggq6-w6jr-x8x2/GHSA-ggq6-w6jr-x8x2.json new file mode 100644 index 00000000000..5dc4a07db97 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-ggq6-w6jr-x8x2/GHSA-ggq6-w6jr-x8x2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ggq6-w6jr-x8x2", + "modified": "2024-08-06T15:30:52Z", + "published": "2024-08-06T15:30:52Z", + "aliases": [ + "CVE-2024-33993" + ], + "details": "Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain their session details via the 'view' parameter in /candidate/index.php'.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33993" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-janobe-products" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T13:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-gp2r-34c8-48xq/GHSA-gp2r-34c8-48xq.json b/advisories/unreviewed/2024/08/GHSA-gp2r-34c8-48xq/GHSA-gp2r-34c8-48xq.json index e8c231805a5..78a60a1f4e3 100644 --- a/advisories/unreviewed/2024/08/GHSA-gp2r-34c8-48xq/GHSA-gp2r-34c8-48xq.json +++ b/advisories/unreviewed/2024/08/GHSA-gp2r-34c8-48xq/GHSA-gp2r-34c8-48xq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gp2r-34c8-48xq", - "modified": "2024-08-05T09:30:26Z", + "modified": "2024-08-06T15:30:50Z", "published": "2024-08-05T09:30:26Z", "aliases": [ "CVE-2024-38856" ], "details": "Incorrect Authorization vulnerability in Apache OFBiz.\n\nThis issue affects Apache OFBiz: through 18.12.14.\n\nUsers are recommended to upgrade to version 18.12.15, which fixes the issue.\n\nUnauthenticated endpoints could allow execution of screen rendering code of screens if some preconditions are met (such as when the screen definitions don't explicitly check user's permissions because they rely on the configuration of their endpoints).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ "CWE-863" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-05T09:15:56Z" diff --git a/advisories/unreviewed/2024/08/GHSA-gx25-vx95-m52w/GHSA-gx25-vx95-m52w.json b/advisories/unreviewed/2024/08/GHSA-gx25-vx95-m52w/GHSA-gx25-vx95-m52w.json new file mode 100644 index 00000000000..b3ddf068e60 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-gx25-vx95-m52w/GHSA-gx25-vx95-m52w.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gx25-vx95-m52w", + "modified": "2024-08-06T15:30:54Z", + "published": "2024-08-06T15:30:54Z", + "aliases": [ + "CVE-2024-7528" + ], + "details": "Incorrect garbage collection interaction in IndexedDB could have led to a use-after-free. This vulnerability affects Firefox < 129 and Firefox ESR < 128.1.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7528" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1895951" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-33" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-35" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T13:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-hf5v-h65q-2g27/GHSA-hf5v-h65q-2g27.json b/advisories/unreviewed/2024/08/GHSA-hf5v-h65q-2g27/GHSA-hf5v-h65q-2g27.json new file mode 100644 index 00000000000..95a65684c4a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-hf5v-h65q-2g27/GHSA-hf5v-h65q-2g27.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hf5v-h65q-2g27", + "modified": "2024-08-06T15:30:53Z", + "published": "2024-08-06T15:30:53Z", + "aliases": [ + "CVE-2024-7526" + ], + "details": "ANGLE failed to initialize parameters which lead to reading from uninitialized memory. This could be leveraged to leak sensitive data from memory. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, and Firefox ESR < 128.1.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7526" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1910306" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-33" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-34" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-35" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T13:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-hjw6-cjgv-379x/GHSA-hjw6-cjgv-379x.json b/advisories/unreviewed/2024/08/GHSA-hjw6-cjgv-379x/GHSA-hjw6-cjgv-379x.json new file mode 100644 index 00000000000..65a0764bfb6 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-hjw6-cjgv-379x/GHSA-hjw6-cjgv-379x.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hjw6-cjgv-379x", + "modified": "2024-08-06T15:30:54Z", + "published": "2024-08-06T15:30:54Z", + "aliases": [ + "CVE-2024-41910" + ], + "details": "A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware contained multiple XXS vulnerabilities in the version of JavaScript used.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41910" + }, + { + "type": "WEB", + "url": "https://support.hp.com/us-en/document/ish_11006981-11007005-16/hpsbpy03960" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T14:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-hwhm-xp52-jvvw/GHSA-hwhm-xp52-jvvw.json b/advisories/unreviewed/2024/08/GHSA-hwhm-xp52-jvvw/GHSA-hwhm-xp52-jvvw.json new file mode 100644 index 00000000000..40ab1d03c2f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-hwhm-xp52-jvvw/GHSA-hwhm-xp52-jvvw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hwhm-xp52-jvvw", + "modified": "2024-08-06T15:30:51Z", + "published": "2024-08-06T15:30:51Z", + "aliases": [ + "CVE-2024-33984" + ], + "details": "Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'Attendance', 'attenddate' and 'YearLevel' parameters in '/AttendanceMonitoring/report/index.php'.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33984" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-janobe-products" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T13:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-j22w-7r9x-5g74/GHSA-j22w-7r9x-5g74.json b/advisories/unreviewed/2024/08/GHSA-j22w-7r9x-5g74/GHSA-j22w-7r9x-5g74.json new file mode 100644 index 00000000000..aa89369c99a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-j22w-7r9x-5g74/GHSA-j22w-7r9x-5g74.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j22w-7r9x-5g74", + "modified": "2024-08-06T15:30:52Z", + "published": "2024-08-06T15:30:52Z", + "aliases": [ + "CVE-2024-33989" + ], + "details": "Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted javascript payload to an authenticated user and partially take over their browser session via the 'eventdate' and 'events' parameters in 'port/event_print.php'.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33989" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-janobe-products" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T13:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-jjrf-959r-8466/GHSA-jjrf-959r-8466.json b/advisories/unreviewed/2024/08/GHSA-jjrf-959r-8466/GHSA-jjrf-959r-8466.json new file mode 100644 index 00000000000..c1969f3d335 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-jjrf-959r-8466/GHSA-jjrf-959r-8466.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jjrf-959r-8466", + "modified": "2024-08-06T15:30:54Z", + "published": "2024-08-06T15:30:54Z", + "aliases": [ + "CVE-2024-36424" + ], + "details": "K7RKScan.sys in K7 Ultimate Security before 17.0.2019 allows local users to cause a denial of service (BSOD) because of a NULL pointer dereference.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36424" + }, + { + "type": "WEB", + "url": "https://support.k7computing.com/index.php?/selfhelp/view-article/Advisory-issued-on-5th-aug-2024-417" + }, + { + "type": "WEB", + "url": "https://www.k7computing.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T15:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-jwpp-4r3q-5jwc/GHSA-jwpp-4r3q-5jwc.json b/advisories/unreviewed/2024/08/GHSA-jwpp-4r3q-5jwc/GHSA-jwpp-4r3q-5jwc.json new file mode 100644 index 00000000000..2d0eacc8f84 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-jwpp-4r3q-5jwc/GHSA-jwpp-4r3q-5jwc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jwpp-4r3q-5jwc", + "modified": "2024-08-06T15:30:51Z", + "published": "2024-08-06T15:30:51Z", + "aliases": [ + "CVE-2024-33986" + ], + "details": "Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'View' parameter in '/department/index.php'.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33986" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-janobe-products" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T13:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-m5jc-q94g-mx3w/GHSA-m5jc-q94g-mx3w.json b/advisories/unreviewed/2024/08/GHSA-m5jc-q94g-mx3w/GHSA-m5jc-q94g-mx3w.json new file mode 100644 index 00000000000..04d9d394992 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-m5jc-q94g-mx3w/GHSA-m5jc-q94g-mx3w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m5jc-q94g-mx3w", + "modified": "2024-08-06T15:30:53Z", + "published": "2024-08-06T15:30:53Z", + "aliases": [ + "CVE-2024-43114" + ], + "details": "In JetBrains TeamCity before 2024.07.1 possible privilege escalation due to incorrect directory permissions", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43114" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T13:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-m99v-mmg2-66vf/GHSA-m99v-mmg2-66vf.json b/advisories/unreviewed/2024/08/GHSA-m99v-mmg2-66vf/GHSA-m99v-mmg2-66vf.json new file mode 100644 index 00000000000..d897b56f2e4 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-m99v-mmg2-66vf/GHSA-m99v-mmg2-66vf.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m99v-mmg2-66vf", + "modified": "2024-08-06T15:30:54Z", + "published": "2024-08-06T15:30:54Z", + "aliases": [ + "CVE-2024-40101" + ], + "details": "A Reflected Cross-site scripting (XSS) vulnerability exists in '/search' in microweber 2.0.15 and earlier allowing unauthenticated remote attackers to inject arbitrary web script or HTML via the 'keywords' parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40101" + }, + { + "type": "WEB", + "url": "https://github.com/microweber/microweber/commit/0dede6886c6df3d1f31c4f4e3ba1ab4a336fbf79" + }, + { + "type": "WEB", + "url": "https://seclists.org/fulldisclosure/2024/Aug/1" + }, + { + "type": "WEB", + "url": "http://microweber.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T14:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-mcjx-2c4v-mvg9/GHSA-mcjx-2c4v-mvg9.json b/advisories/unreviewed/2024/08/GHSA-mcjx-2c4v-mvg9/GHSA-mcjx-2c4v-mvg9.json new file mode 100644 index 00000000000..14d3a00f03c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-mcjx-2c4v-mvg9/GHSA-mcjx-2c4v-mvg9.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mcjx-2c4v-mvg9", + "modified": "2024-08-06T15:30:53Z", + "published": "2024-08-06T15:30:53Z", + "aliases": [ + "CVE-2024-7518" + ], + "details": "Select options could obscure the fullscreen notification dialog. This could be used by a malicious site to perform a spoofing attack. This vulnerability affects Firefox < 129 and Firefox ESR < 128.1.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7518" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1875354" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-33" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-35" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T13:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-phj6-w4wf-6mrr/GHSA-phj6-w4wf-6mrr.json b/advisories/unreviewed/2024/08/GHSA-phj6-w4wf-6mrr/GHSA-phj6-w4wf-6mrr.json new file mode 100644 index 00000000000..cbaeed19158 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-phj6-w4wf-6mrr/GHSA-phj6-w4wf-6mrr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phj6-w4wf-6mrr", + "modified": "2024-08-06T15:30:53Z", + "published": "2024-08-06T15:30:53Z", + "aliases": [ + "CVE-2024-6358" + ], + "details": "Incorrect Authorization vulnerability identified in OpenText ArcSight Intelligence.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6358" + }, + { + "type": "WEB", + "url": "https://portal.microfocus.com/s/article/KM000032595" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T13:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-qfp3-q936-c28j/GHSA-qfp3-q936-c28j.json b/advisories/unreviewed/2024/08/GHSA-qfp3-q936-c28j/GHSA-qfp3-q936-c28j.json index 13d4935af1c..560f5eebf47 100644 --- a/advisories/unreviewed/2024/08/GHSA-qfp3-q936-c28j/GHSA-qfp3-q936-c28j.json +++ b/advisories/unreviewed/2024/08/GHSA-qfp3-q936-c28j/GHSA-qfp3-q936-c28j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qfp3-q936-c28j", - "modified": "2024-08-06T06:30:38Z", + "modified": "2024-08-06T15:30:50Z", "published": "2024-08-06T06:30:38Z", "aliases": [ "CVE-2024-6766" ], "details": "The shortcodes-ultimate-pro WordPress plugin before 7.2.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-06T06:15:36Z" diff --git a/advisories/unreviewed/2024/08/GHSA-qxhm-3vp2-fcq3/GHSA-qxhm-3vp2-fcq3.json b/advisories/unreviewed/2024/08/GHSA-qxhm-3vp2-fcq3/GHSA-qxhm-3vp2-fcq3.json index cce13c1ebb9..175e98bb32d 100644 --- a/advisories/unreviewed/2024/08/GHSA-qxhm-3vp2-fcq3/GHSA-qxhm-3vp2-fcq3.json +++ b/advisories/unreviewed/2024/08/GHSA-qxhm-3vp2-fcq3/GHSA-qxhm-3vp2-fcq3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qxhm-3vp2-fcq3", - "modified": "2024-08-06T09:31:38Z", + "modified": "2024-08-06T15:30:50Z", "published": "2024-08-06T09:31:38Z", "aliases": [ "CVE-2024-41995" ], "details": "Initialization of a resource with an insecure default vulnerability exists in JavaTM Platform Ver.12.89 and earlier. If this vulnerability is exploited, the product may be affected by some known TLS1.0 and TLS1.1 vulnerabilities. As for the specific products/models/versions of MFPs and printers that contain JavaTM Platform, see the information provided by the vendor.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-06T07:15:46Z" diff --git a/advisories/unreviewed/2024/08/GHSA-r7x6-6cmj-2972/GHSA-r7x6-6cmj-2972.json b/advisories/unreviewed/2024/08/GHSA-r7x6-6cmj-2972/GHSA-r7x6-6cmj-2972.json new file mode 100644 index 00000000000..48570b141a1 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-r7x6-6cmj-2972/GHSA-r7x6-6cmj-2972.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r7x6-6cmj-2972", + "modified": "2024-08-06T15:30:54Z", + "published": "2024-08-06T15:30:54Z", + "aliases": [ + "CVE-2024-30170" + ], + "details": "PrivX before 34.0 allows data exfiltration and denial of service via the REST API. This is fixed in minor versions 33.1, 32.3, 31.3, and later, and in major version 34.0 and later,", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30170" + }, + { + "type": "WEB", + "url": "https://info.ssh.com/improper-input-validation-faq" + }, + { + "type": "WEB", + "url": "https://privx.docs.ssh.com/docs/security" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T14:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-vg6f-fg27-rjww/GHSA-vg6f-fg27-rjww.json b/advisories/unreviewed/2024/08/GHSA-vg6f-fg27-rjww/GHSA-vg6f-fg27-rjww.json new file mode 100644 index 00000000000..bffda76f01a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-vg6f-fg27-rjww/GHSA-vg6f-fg27-rjww.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vg6f-fg27-rjww", + "modified": "2024-08-06T15:30:51Z", + "published": "2024-08-06T15:30:50Z", + "aliases": [ + "CVE-2024-33983" + ], + "details": "Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'Attendance', 'attenddate' and 'YearLevel' parameters in '/AttendanceMonitoring/report/attendance_print.php'.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33983" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-janobe-products" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T13:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-w3xp-69rr-q6gw/GHSA-w3xp-69rr-q6gw.json b/advisories/unreviewed/2024/08/GHSA-w3xp-69rr-q6gw/GHSA-w3xp-69rr-q6gw.json new file mode 100644 index 00000000000..887af760868 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-w3xp-69rr-q6gw/GHSA-w3xp-69rr-q6gw.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w3xp-69rr-q6gw", + "modified": "2024-08-06T15:30:53Z", + "published": "2024-08-06T15:30:53Z", + "aliases": [ + "CVE-2024-7523" + ], + "details": "A select option could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. \n*This issue only affects Android versions of Firefox.* This vulnerability affects Firefox < 129.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7523" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1908344" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-33" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T13:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-wrp2-hmjf-4443/GHSA-wrp2-hmjf-4443.json b/advisories/unreviewed/2024/08/GHSA-wrp2-hmjf-4443/GHSA-wrp2-hmjf-4443.json new file mode 100644 index 00000000000..de5142af48a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-wrp2-hmjf-4443/GHSA-wrp2-hmjf-4443.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wrp2-hmjf-4443", + "modified": "2024-08-06T15:30:53Z", + "published": "2024-08-06T15:30:53Z", + "aliases": [ + "CVE-2024-6357" + ], + "details": "Insecure Direct Object Reference vulnerability identified in OpenText ArcSight Intelligence.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6357" + }, + { + "type": "WEB", + "url": "https://portal.microfocus.com/s/article/KM000032593" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T13:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-x2r7-mhp8-xvhm/GHSA-x2r7-mhp8-xvhm.json b/advisories/unreviewed/2024/08/GHSA-x2r7-mhp8-xvhm/GHSA-x2r7-mhp8-xvhm.json new file mode 100644 index 00000000000..8d2291c8063 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-x2r7-mhp8-xvhm/GHSA-x2r7-mhp8-xvhm.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x2r7-mhp8-xvhm", + "modified": "2024-08-06T15:30:54Z", + "published": "2024-08-06T15:30:54Z", + "aliases": [ + "CVE-2024-33897" + ], + "details": "A compromised HMS Networks Cosy+ device could be used to request a Certificate Signing Request from Talk2m for another device, resulting in an availability issue. The issue was patched on the Talk2m production server on April 18, 2024.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33897" + }, + { + "type": "WEB", + "url": "https://hmsnetworks.blob.core.windows.net/nlw/docs/default-source/products/cybersecurity/security-advisory/hms-security-advisory-2024-07-29-001--ewon-several-cosy--vulnerabilities.pdf" + }, + { + "type": "WEB", + "url": "https://www.ewon.biz/products/cosy/ewon-cosy-wifi" + }, + { + "type": "WEB", + "url": "https://www.hms-networks.com/cyber-security" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T14:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-xq4j-rv6r-ch63/GHSA-xq4j-rv6r-ch63.json b/advisories/unreviewed/2024/08/GHSA-xq4j-rv6r-ch63/GHSA-xq4j-rv6r-ch63.json new file mode 100644 index 00000000000..142302ea2a2 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-xq4j-rv6r-ch63/GHSA-xq4j-rv6r-ch63.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xq4j-rv6r-ch63", + "modified": "2024-08-06T15:30:52Z", + "published": "2024-08-06T15:30:52Z", + "aliases": [ + "CVE-2024-33992" + ], + "details": "Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the 'view' parameter in '/student/index.php'.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33992" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-janobe-products" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T13:15:55Z" + } +} \ No newline at end of file