diff --git a/advisories/unreviewed/2022/04/GHSA-65pf-462r-g52c/GHSA-65pf-462r-g52c.json b/advisories/unreviewed/2022/04/GHSA-65pf-462r-g52c/GHSA-65pf-462r-g52c.json index be13c004e2e..26298533de2 100644 --- a/advisories/unreviewed/2022/04/GHSA-65pf-462r-g52c/GHSA-65pf-462r-g52c.json +++ b/advisories/unreviewed/2022/04/GHSA-65pf-462r-g52c/GHSA-65pf-462r-g52c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-65pf-462r-g52c", - "modified": "2022-04-30T18:09:49Z", + "modified": "2024-08-01T21:31:37Z", "published": "2022-04-30T18:09:49Z", "aliases": [ "CVE-1999-0029" ], "details": "root privileges via buffer overflow in ordist command on SGI IRIX systems.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-ch8f-f5g7-vhhr/GHSA-ch8f-f5g7-vhhr.json b/advisories/unreviewed/2022/04/GHSA-ch8f-f5g7-vhhr/GHSA-ch8f-f5g7-vhhr.json index 4eba183c966..f6b7a7c9d40 100644 --- a/advisories/unreviewed/2022/04/GHSA-ch8f-f5g7-vhhr/GHSA-ch8f-f5g7-vhhr.json +++ b/advisories/unreviewed/2022/04/GHSA-ch8f-f5g7-vhhr/GHSA-ch8f-f5g7-vhhr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ch8f-f5g7-vhhr", - "modified": "2022-04-30T18:09:48Z", + "modified": "2024-08-01T21:31:38Z", "published": "2022-04-30T18:09:48Z", "aliases": [ "CVE-1999-0013" ], "details": "Stolen credentials from SSH clients via ssh-agent program, allowing other local users to access remote accounts belonging to the ssh-agent user.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-522" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-qm75-vj9c-hjcf/GHSA-qm75-vj9c-hjcf.json b/advisories/unreviewed/2022/04/GHSA-qm75-vj9c-hjcf/GHSA-qm75-vj9c-hjcf.json index db1490ce79f..17cbb9bb28a 100644 --- a/advisories/unreviewed/2022/04/GHSA-qm75-vj9c-hjcf/GHSA-qm75-vj9c-hjcf.json +++ b/advisories/unreviewed/2022/04/GHSA-qm75-vj9c-hjcf/GHSA-qm75-vj9c-hjcf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qm75-vj9c-hjcf", - "modified": "2022-04-30T18:09:51Z", + "modified": "2024-08-01T21:31:37Z", "published": "2022-04-30T18:09:51Z", "aliases": [ "CVE-1999-0043" ], "details": "Command execution via shell metachars in INN daemon (innd) 1.5 using \"newgroup\" and \"rmgroup\" control messages, and others.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-r96j-7gxg-wp39/GHSA-r96j-7gxg-wp39.json b/advisories/unreviewed/2022/04/GHSA-r96j-7gxg-wp39/GHSA-r96j-7gxg-wp39.json index 8e512ea1656..e7b53797371 100644 --- a/advisories/unreviewed/2022/04/GHSA-r96j-7gxg-wp39/GHSA-r96j-7gxg-wp39.json +++ b/advisories/unreviewed/2022/04/GHSA-r96j-7gxg-wp39/GHSA-r96j-7gxg-wp39.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r96j-7gxg-wp39", - "modified": "2022-04-30T18:09:50Z", + "modified": "2024-08-01T21:31:37Z", "published": "2022-04-30T18:09:50Z", "aliases": [ "CVE-1999-0022" ], "details": "Local user gains root privileges via buffer overflow in rdist, via expstr() function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-wh9q-9hjg-qw4c/GHSA-wh9q-9hjg-qw4c.json b/advisories/unreviewed/2022/04/GHSA-wh9q-9hjg-qw4c/GHSA-wh9q-9hjg-qw4c.json index e6d61dcf49e..0d78aa9f320 100644 --- a/advisories/unreviewed/2022/04/GHSA-wh9q-9hjg-qw4c/GHSA-wh9q-9hjg-qw4c.json +++ b/advisories/unreviewed/2022/04/GHSA-wh9q-9hjg-qw4c/GHSA-wh9q-9hjg-qw4c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wh9q-9hjg-qw4c", - "modified": "2022-04-30T18:12:46Z", + "modified": "2024-08-01T21:31:38Z", "published": "2022-04-30T18:12:46Z", "aliases": [ "CVE-1999-1588" ], "details": "Buffer overflow in nlps_server in Sun Solaris x86 2.4, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code as root via a long string beginning with \"NLPS:002:002:\" to the listen (aka System V listener) port, TCP port 2766.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-119" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-xqg2-r5rv-62x6/GHSA-xqg2-r5rv-62x6.json b/advisories/unreviewed/2022/04/GHSA-xqg2-r5rv-62x6/GHSA-xqg2-r5rv-62x6.json index de321c6d18b..a4ab7f215b2 100644 --- a/advisories/unreviewed/2022/04/GHSA-xqg2-r5rv-62x6/GHSA-xqg2-r5rv-62x6.json +++ b/advisories/unreviewed/2022/04/GHSA-xqg2-r5rv-62x6/GHSA-xqg2-r5rv-62x6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xqg2-r5rv-62x6", - "modified": "2022-04-30T18:09:53Z", + "modified": "2024-08-01T21:31:38Z", "published": "2022-04-30T18:09:53Z", "aliases": [ "CVE-1999-0069" ], "details": "Solaris ufsrestore buffer overflow.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-119" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-7c8f-5r89-mjgx/GHSA-7c8f-5r89-mjgx.json b/advisories/unreviewed/2022/05/GHSA-7c8f-5r89-mjgx/GHSA-7c8f-5r89-mjgx.json index f054e8def03..0daa8338867 100644 --- a/advisories/unreviewed/2022/05/GHSA-7c8f-5r89-mjgx/GHSA-7c8f-5r89-mjgx.json +++ b/advisories/unreviewed/2022/05/GHSA-7c8f-5r89-mjgx/GHSA-7c8f-5r89-mjgx.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-288" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-mxv6-m383-394f/GHSA-mxv6-m383-394f.json b/advisories/unreviewed/2023/01/GHSA-mxv6-m383-394f/GHSA-mxv6-m383-394f.json index 91594e4a733..48411793172 100644 --- a/advisories/unreviewed/2023/01/GHSA-mxv6-m383-394f/GHSA-mxv6-m383-394f.json +++ b/advisories/unreviewed/2023/01/GHSA-mxv6-m383-394f/GHSA-mxv6-m383-394f.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-75" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-895f-2fwm-hcv8/GHSA-895f-2fwm-hcv8.json b/advisories/unreviewed/2024/02/GHSA-895f-2fwm-hcv8/GHSA-895f-2fwm-hcv8.json index c6274574f0b..406a35791ce 100644 --- a/advisories/unreviewed/2024/02/GHSA-895f-2fwm-hcv8/GHSA-895f-2fwm-hcv8.json +++ b/advisories/unreviewed/2024/02/GHSA-895f-2fwm-hcv8/GHSA-895f-2fwm-hcv8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-895f-2fwm-hcv8", - "modified": "2024-02-13T06:30:28Z", + "modified": "2024-08-01T21:31:39Z", "published": "2024-02-13T06:30:28Z", "aliases": [ "CVE-2023-52431" ], "details": "The Plack::Middleware::XSRFBlock package before 0.0.19 for Perl allows attackers to bypass a CSRF protection mechanism via an empty form value and an empty cookie (if signed cookies are disabled).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-13T05:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-cc2p-f3qf-3fr6/GHSA-cc2p-f3qf-3fr6.json b/advisories/unreviewed/2024/02/GHSA-cc2p-f3qf-3fr6/GHSA-cc2p-f3qf-3fr6.json index 9f3fb92027d..1382a05f52a 100644 --- a/advisories/unreviewed/2024/02/GHSA-cc2p-f3qf-3fr6/GHSA-cc2p-f3qf-3fr6.json +++ b/advisories/unreviewed/2024/02/GHSA-cc2p-f3qf-3fr6/GHSA-cc2p-f3qf-3fr6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cc2p-f3qf-3fr6", - "modified": "2024-02-12T18:31:07Z", + "modified": "2024-08-01T21:31:39Z", "published": "2024-02-12T18:31:07Z", "aliases": [ "CVE-2023-6294" ], "details": "The Popup Builder WordPress plugin before 4.2.6 does not validate a parameter before making a request to it, which could allow users with the administrator role to perform SSRF attack in Multisite WordPress configurations.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-12T16:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-f9x8-85w7-chxv/GHSA-f9x8-85w7-chxv.json b/advisories/unreviewed/2024/02/GHSA-f9x8-85w7-chxv/GHSA-f9x8-85w7-chxv.json index ea8dff11bd0..649199d0d6b 100644 --- a/advisories/unreviewed/2024/02/GHSA-f9x8-85w7-chxv/GHSA-f9x8-85w7-chxv.json +++ b/advisories/unreviewed/2024/02/GHSA-f9x8-85w7-chxv/GHSA-f9x8-85w7-chxv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f9x8-85w7-chxv", - "modified": "2024-02-13T03:30:20Z", + "modified": "2024-08-01T21:31:39Z", "published": "2024-02-13T03:30:20Z", "aliases": [ "CVE-2023-42374" ], "details": "An issue in mystenlabs Sui Blockchain before v.1.6.3 allow a remote attacker to execute arbitrary code and cause a denial of service via a crafted compressed script to the Sui node component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -26,6 +29,14 @@ "type": "WEB", "url": "https://beosin.com/resources/\"memory-bomb\"-vulnerability-causes-sui-node-to-crash?lang=en-US" }, + { + "type": "WEB", + "url": "https://beosin.com/resources/%22memory-bomb%22-vulnerability-causes-sui-node-to-crash?lang=en-US" + }, + { + "type": "WEB", + "url": "https://medium.com/%40Beosin_com/memory-bomb-vulnerability-causes-sui-node-to-crash-7e8e3ef5057c" + }, { "type": "WEB", "url": "https://medium.com/@Beosin_com/memory-bomb-vulnerability-causes-sui-node-to-crash-7e8e3ef5057c" @@ -33,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-13T01:15:07Z" diff --git a/advisories/unreviewed/2024/02/GHSA-r57p-gw8h-38xj/GHSA-r57p-gw8h-38xj.json b/advisories/unreviewed/2024/02/GHSA-r57p-gw8h-38xj/GHSA-r57p-gw8h-38xj.json index 8749aa6bd21..b019997cdd5 100644 --- a/advisories/unreviewed/2024/02/GHSA-r57p-gw8h-38xj/GHSA-r57p-gw8h-38xj.json +++ b/advisories/unreviewed/2024/02/GHSA-r57p-gw8h-38xj/GHSA-r57p-gw8h-38xj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r57p-gw8h-38xj", - "modified": "2024-02-08T06:30:24Z", + "modified": "2024-08-01T21:31:38Z", "published": "2024-02-08T06:30:24Z", "aliases": [ "CVE-2024-24091" ], "details": "Yealink Meeting Server before v26.0.0.66 was discovered to contain an OS command injection vulnerability via the file upload interface.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-08T06:15:51Z" diff --git a/advisories/unreviewed/2024/03/GHSA-53g5-chm2-f34r/GHSA-53g5-chm2-f34r.json b/advisories/unreviewed/2024/03/GHSA-53g5-chm2-f34r/GHSA-53g5-chm2-f34r.json index d0df6548457..0bf49999001 100644 --- a/advisories/unreviewed/2024/03/GHSA-53g5-chm2-f34r/GHSA-53g5-chm2-f34r.json +++ b/advisories/unreviewed/2024/03/GHSA-53g5-chm2-f34r/GHSA-53g5-chm2-f34r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-53g5-chm2-f34r", - "modified": "2024-03-25T15:30:39Z", + "modified": "2024-08-01T21:31:39Z", "published": "2024-03-25T15:30:39Z", "aliases": [ "CVE-2024-28387" ], "details": "An issue in axonaut v.3.1.23 and before allows a remote attacker to obtain sensitive information via the log.txt component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-312" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-25T14:15:09Z" diff --git a/advisories/unreviewed/2024/03/GHSA-7ph5-37r4-fwh8/GHSA-7ph5-37r4-fwh8.json b/advisories/unreviewed/2024/03/GHSA-7ph5-37r4-fwh8/GHSA-7ph5-37r4-fwh8.json index dfdd0ad21eb..796a15399a4 100644 --- a/advisories/unreviewed/2024/03/GHSA-7ph5-37r4-fwh8/GHSA-7ph5-37r4-fwh8.json +++ b/advisories/unreviewed/2024/03/GHSA-7ph5-37r4-fwh8/GHSA-7ph5-37r4-fwh8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7ph5-37r4-fwh8", - "modified": "2024-03-20T15:32:29Z", + "modified": "2024-08-01T21:31:39Z", "published": "2024-03-20T15:32:29Z", "aliases": [ "CVE-2024-0337" ], "details": "The Travelpayouts: All Travel Brands in One Place WordPress plugin through 1.1.15 is vulnerable to Open Redirect due to insufficient validation on the travelpayouts_redirect variable. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-20T05:15:45Z" diff --git a/advisories/unreviewed/2024/03/GHSA-m8qw-mppg-7364/GHSA-m8qw-mppg-7364.json b/advisories/unreviewed/2024/03/GHSA-m8qw-mppg-7364/GHSA-m8qw-mppg-7364.json index 91d776e7c00..2093ca19fd1 100644 --- a/advisories/unreviewed/2024/03/GHSA-m8qw-mppg-7364/GHSA-m8qw-mppg-7364.json +++ b/advisories/unreviewed/2024/03/GHSA-m8qw-mppg-7364/GHSA-m8qw-mppg-7364.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m8qw-mppg-7364", - "modified": "2024-03-20T15:32:29Z", + "modified": "2024-08-01T21:31:39Z", "published": "2024-03-20T15:32:29Z", "aliases": [ "CVE-2024-1983" ], "details": "The Simple Ajax Chat WordPress plugin before 20240223 does not prevent visitors from using malicious Names when using the chat, which will be reflected unsanitized to other users.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-20T05:15:45Z" diff --git a/advisories/unreviewed/2024/03/GHSA-mxm9-3p22-jh4c/GHSA-mxm9-3p22-jh4c.json b/advisories/unreviewed/2024/03/GHSA-mxm9-3p22-jh4c/GHSA-mxm9-3p22-jh4c.json index 01a66b97257..e8c366e8d20 100644 --- a/advisories/unreviewed/2024/03/GHSA-mxm9-3p22-jh4c/GHSA-mxm9-3p22-jh4c.json +++ b/advisories/unreviewed/2024/03/GHSA-mxm9-3p22-jh4c/GHSA-mxm9-3p22-jh4c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mxm9-3p22-jh4c", - "modified": "2024-03-22T12:30:46Z", + "modified": "2024-08-01T21:31:39Z", "published": "2024-03-22T12:30:46Z", "aliases": [ "CVE-2024-25168" ], "details": "SQL injection vulnerability in snow snow v.2.0.0 allows a remote attacker to execute arbitrary code via the dataScope parameter of the system/role/list interface.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-22T12:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-pmm3-68q9-57jg/GHSA-pmm3-68q9-57jg.json b/advisories/unreviewed/2024/03/GHSA-pmm3-68q9-57jg/GHSA-pmm3-68q9-57jg.json index abc43864568..72665597c25 100644 --- a/advisories/unreviewed/2024/03/GHSA-pmm3-68q9-57jg/GHSA-pmm3-68q9-57jg.json +++ b/advisories/unreviewed/2024/03/GHSA-pmm3-68q9-57jg/GHSA-pmm3-68q9-57jg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pmm3-68q9-57jg", - "modified": "2024-03-22T06:30:24Z", + "modified": "2024-08-01T21:31:39Z", "published": "2024-03-22T06:30:24Z", "aliases": [ "CVE-2024-29272" ], "details": "Arbitrary File Upload vulnerability in VvvebJs before version 1.7.5, allows unauthenticated remote attackers to execute arbitrary code and obtain sensitive information via the sanitizeFileName parameter in save.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-22T04:15:11Z" diff --git a/advisories/unreviewed/2024/05/GHSA-287w-9xcw-2gqp/GHSA-287w-9xcw-2gqp.json b/advisories/unreviewed/2024/05/GHSA-287w-9xcw-2gqp/GHSA-287w-9xcw-2gqp.json index 42c95e8c87d..46558e1c1a1 100644 --- a/advisories/unreviewed/2024/05/GHSA-287w-9xcw-2gqp/GHSA-287w-9xcw-2gqp.json +++ b/advisories/unreviewed/2024/05/GHSA-287w-9xcw-2gqp/GHSA-287w-9xcw-2gqp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-287w-9xcw-2gqp", - "modified": "2024-05-16T09:33:05Z", + "modified": "2024-08-01T21:31:40Z", "published": "2024-05-16T09:33:05Z", "aliases": [ "CVE-2024-4962" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/05/GHSA-38cv-ch3v-j5cw/GHSA-38cv-ch3v-j5cw.json b/advisories/unreviewed/2024/05/GHSA-38cv-ch3v-j5cw/GHSA-38cv-ch3v-j5cw.json index e590953a444..b05a56d7a71 100644 --- a/advisories/unreviewed/2024/05/GHSA-38cv-ch3v-j5cw/GHSA-38cv-ch3v-j5cw.json +++ b/advisories/unreviewed/2024/05/GHSA-38cv-ch3v-j5cw/GHSA-38cv-ch3v-j5cw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-38cv-ch3v-j5cw", - "modified": "2024-06-10T18:30:57Z", + "modified": "2024-08-01T21:31:40Z", "published": "2024-05-08T15:30:43Z", "aliases": [ "CVE-2024-32113" ], "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13.\n\nUsers are recommended to upgrade to version 18.12.13, which fixes the issue.\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ "CWE-22" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-08T15:15:10Z" diff --git a/advisories/unreviewed/2024/05/GHSA-7c5r-r7cr-56w7/GHSA-7c5r-r7cr-56w7.json b/advisories/unreviewed/2024/05/GHSA-7c5r-r7cr-56w7/GHSA-7c5r-r7cr-56w7.json index b5b9eecf4ab..d34ade4c703 100644 --- a/advisories/unreviewed/2024/05/GHSA-7c5r-r7cr-56w7/GHSA-7c5r-r7cr-56w7.json +++ b/advisories/unreviewed/2024/05/GHSA-7c5r-r7cr-56w7/GHSA-7c5r-r7cr-56w7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7c5r-r7cr-56w7", - "modified": "2024-05-16T06:30:51Z", + "modified": "2024-08-01T21:31:40Z", "published": "2024-05-16T06:30:51Z", "aliases": [ "CVE-2024-4961" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/05/GHSA-8qpx-3xqh-7q35/GHSA-8qpx-3xqh-7q35.json b/advisories/unreviewed/2024/05/GHSA-8qpx-3xqh-7q35/GHSA-8qpx-3xqh-7q35.json index e4019dd9f0f..68c69d43e1a 100644 --- a/advisories/unreviewed/2024/05/GHSA-8qpx-3xqh-7q35/GHSA-8qpx-3xqh-7q35.json +++ b/advisories/unreviewed/2024/05/GHSA-8qpx-3xqh-7q35/GHSA-8qpx-3xqh-7q35.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8qpx-3xqh-7q35", - "modified": "2024-05-08T18:30:49Z", + "modified": "2024-08-01T21:31:40Z", "published": "2024-05-08T18:30:49Z", "aliases": [ "CVE-2024-25529" ], "details": "RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /WorkFlow/wf_office_file_history_show.aspx.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-08T16:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-97wm-mmc6-r49r/GHSA-97wm-mmc6-r49r.json b/advisories/unreviewed/2024/05/GHSA-97wm-mmc6-r49r/GHSA-97wm-mmc6-r49r.json index d3f2bf565f6..44ee7519f24 100644 --- a/advisories/unreviewed/2024/05/GHSA-97wm-mmc6-r49r/GHSA-97wm-mmc6-r49r.json +++ b/advisories/unreviewed/2024/05/GHSA-97wm-mmc6-r49r/GHSA-97wm-mmc6-r49r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-97wm-mmc6-r49r", - "modified": "2024-05-07T21:31:46Z", + "modified": "2024-08-01T21:31:40Z", "published": "2024-05-07T21:31:46Z", "aliases": [ "CVE-2024-0025" ], "details": "In sendIntentSender of ActivityManagerService.java, there is a possible background activity launch due to a logic error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T21:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-c4qc-g3hp-67g9/GHSA-c4qc-g3hp-67g9.json b/advisories/unreviewed/2024/05/GHSA-c4qc-g3hp-67g9/GHSA-c4qc-g3hp-67g9.json index 358e83c4d14..7cd23d70d0e 100644 --- a/advisories/unreviewed/2024/05/GHSA-c4qc-g3hp-67g9/GHSA-c4qc-g3hp-67g9.json +++ b/advisories/unreviewed/2024/05/GHSA-c4qc-g3hp-67g9/GHSA-c4qc-g3hp-67g9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c4qc-g3hp-67g9", - "modified": "2024-05-16T06:30:51Z", + "modified": "2024-08-01T21:31:40Z", "published": "2024-05-16T06:30:51Z", "aliases": [ "CVE-2024-4960" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/05/GHSA-cpvh-46gg-825p/GHSA-cpvh-46gg-825p.json b/advisories/unreviewed/2024/05/GHSA-cpvh-46gg-825p/GHSA-cpvh-46gg-825p.json index 7012d8975fb..1c4f421175f 100644 --- a/advisories/unreviewed/2024/05/GHSA-cpvh-46gg-825p/GHSA-cpvh-46gg-825p.json +++ b/advisories/unreviewed/2024/05/GHSA-cpvh-46gg-825p/GHSA-cpvh-46gg-825p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cpvh-46gg-825p", - "modified": "2024-05-16T09:33:05Z", + "modified": "2024-08-01T21:31:40Z", "published": "2024-05-16T09:33:05Z", "aliases": [ "CVE-2024-4963" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/05/GHSA-g827-h3jp-qr6m/GHSA-g827-h3jp-qr6m.json b/advisories/unreviewed/2024/05/GHSA-g827-h3jp-qr6m/GHSA-g827-h3jp-qr6m.json index 23489a6b187..985ad0d5ba0 100644 --- a/advisories/unreviewed/2024/05/GHSA-g827-h3jp-qr6m/GHSA-g827-h3jp-qr6m.json +++ b/advisories/unreviewed/2024/05/GHSA-g827-h3jp-qr6m/GHSA-g827-h3jp-qr6m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g827-h3jp-qr6m", - "modified": "2024-05-16T09:33:07Z", + "modified": "2024-08-01T21:31:40Z", "published": "2024-05-16T09:33:07Z", "aliases": [ "CVE-2024-4965" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/05/GHSA-jmvf-qrv2-jjwq/GHSA-jmvf-qrv2-jjwq.json b/advisories/unreviewed/2024/05/GHSA-jmvf-qrv2-jjwq/GHSA-jmvf-qrv2-jjwq.json index fbff95ef784..544e23c9e90 100644 --- a/advisories/unreviewed/2024/05/GHSA-jmvf-qrv2-jjwq/GHSA-jmvf-qrv2-jjwq.json +++ b/advisories/unreviewed/2024/05/GHSA-jmvf-qrv2-jjwq/GHSA-jmvf-qrv2-jjwq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jmvf-qrv2-jjwq", - "modified": "2024-05-06T18:30:36Z", + "modified": "2024-08-01T21:31:40Z", "published": "2024-05-06T18:30:36Z", "aliases": [ "CVE-2024-33408" ], "details": "A SQL injection vulnerability in /model/get_classroom.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the id parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -21,13 +24,17 @@ { "type": "WEB", "url": "https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%207.pdf" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%209.pdf" } ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-06T18:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-p42w-9882-h2g8/GHSA-p42w-9882-h2g8.json b/advisories/unreviewed/2024/05/GHSA-p42w-9882-h2g8/GHSA-p42w-9882-h2g8.json index 51d15b3da70..f3686eedbaf 100644 --- a/advisories/unreviewed/2024/05/GHSA-p42w-9882-h2g8/GHSA-p42w-9882-h2g8.json +++ b/advisories/unreviewed/2024/05/GHSA-p42w-9882-h2g8/GHSA-p42w-9882-h2g8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p42w-9882-h2g8", - "modified": "2024-05-16T09:33:06Z", + "modified": "2024-08-01T21:31:40Z", "published": "2024-05-16T09:33:06Z", "aliases": [ "CVE-2024-4964" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/05/GHSA-vg2h-v64q-h2qj/GHSA-vg2h-v64q-h2qj.json b/advisories/unreviewed/2024/05/GHSA-vg2h-v64q-h2qj/GHSA-vg2h-v64q-h2qj.json index cf02f6299a2..98d16b20e47 100644 --- a/advisories/unreviewed/2024/05/GHSA-vg2h-v64q-h2qj/GHSA-vg2h-v64q-h2qj.json +++ b/advisories/unreviewed/2024/05/GHSA-vg2h-v64q-h2qj/GHSA-vg2h-v64q-h2qj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vg2h-v64q-h2qj", - "modified": "2024-05-14T18:30:56Z", + "modified": "2024-08-01T21:31:40Z", "published": "2024-05-14T18:30:56Z", "aliases": [ "CVE-2024-4699" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/05/GHSA-vvf7-q7rc-3m2m/GHSA-vvf7-q7rc-3m2m.json b/advisories/unreviewed/2024/05/GHSA-vvf7-q7rc-3m2m/GHSA-vvf7-q7rc-3m2m.json index 14a5992af80..0c37d2f05ff 100644 --- a/advisories/unreviewed/2024/05/GHSA-vvf7-q7rc-3m2m/GHSA-vvf7-q7rc-3m2m.json +++ b/advisories/unreviewed/2024/05/GHSA-vvf7-q7rc-3m2m/GHSA-vvf7-q7rc-3m2m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vvf7-q7rc-3m2m", - "modified": "2024-05-21T21:30:27Z", + "modified": "2024-08-01T21:31:40Z", "published": "2024-05-08T18:30:49Z", "aliases": [ "CVE-2024-34257" ], "details": "TOTOLINK EX1800T V9.1.0cu.2112_B20220316 has a vulnerability in the apcliEncrypType parameter that allows unauthorized execution of arbitrary commands, allowing an attacker to obtain device administrator privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-285" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-08T17:15:07Z" diff --git a/advisories/unreviewed/2024/05/GHSA-w88g-vghh-w3r5/GHSA-w88g-vghh-w3r5.json b/advisories/unreviewed/2024/05/GHSA-w88g-vghh-w3r5/GHSA-w88g-vghh-w3r5.json index c5e1924c182..e64a24a4333 100644 --- a/advisories/unreviewed/2024/05/GHSA-w88g-vghh-w3r5/GHSA-w88g-vghh-w3r5.json +++ b/advisories/unreviewed/2024/05/GHSA-w88g-vghh-w3r5/GHSA-w88g-vghh-w3r5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w88g-vghh-w3r5", - "modified": "2024-05-07T18:30:34Z", + "modified": "2024-08-01T21:31:40Z", "published": "2024-05-07T18:30:34Z", "aliases": [ "CVE-2024-25508" ], "details": "RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /bulletin/bulletin_template_show.aspx.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T18:15:08Z" diff --git a/advisories/unreviewed/2024/06/GHSA-3wjv-2739-3h75/GHSA-3wjv-2739-3h75.json b/advisories/unreviewed/2024/06/GHSA-3wjv-2739-3h75/GHSA-3wjv-2739-3h75.json index 5eab4a123ee..1772c583719 100644 --- a/advisories/unreviewed/2024/06/GHSA-3wjv-2739-3h75/GHSA-3wjv-2739-3h75.json +++ b/advisories/unreviewed/2024/06/GHSA-3wjv-2739-3h75/GHSA-3wjv-2739-3h75.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3wjv-2739-3h75", - "modified": "2024-06-19T15:30:53Z", + "modified": "2024-08-01T21:31:40Z", "published": "2024-06-19T15:30:53Z", "aliases": [ "CVE-2024-38570" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ngfs2: Fix potential glock use-after-free on unmount\n\nWhen a DLM lockspace is released and there ares still locks in that\nlockspace, DLM will unlock those locks automatically. Commit\nfb6791d100d1b started exploiting this behavior to speed up filesystem\nunmount: gfs2 would simply free glocks it didn't want to unlock and then\nrelease the lockspace. This didn't take the bast callbacks for\nasynchronous lock contention notifications into account, which remain\nactive until until a lock is unlocked or its lockspace is released.\n\nTo prevent those callbacks from accessing deallocated objects, put the\nglocks that should not be unlocked on the sd_dead_glocks list, release\nthe lockspace, and only then free those glocks.\n\nAs an additional measure, ignore unexpected ast and bast callbacks if\nthe receiving glock is dead.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T14:15:17Z" diff --git a/advisories/unreviewed/2024/06/GHSA-4wff-3rcm-c2fr/GHSA-4wff-3rcm-c2fr.json b/advisories/unreviewed/2024/06/GHSA-4wff-3rcm-c2fr/GHSA-4wff-3rcm-c2fr.json index 7fe8a172d11..37bc6488ee7 100644 --- a/advisories/unreviewed/2024/06/GHSA-4wff-3rcm-c2fr/GHSA-4wff-3rcm-c2fr.json +++ b/advisories/unreviewed/2024/06/GHSA-4wff-3rcm-c2fr/GHSA-4wff-3rcm-c2fr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4wff-3rcm-c2fr", - "modified": "2024-06-19T15:30:53Z", + "modified": "2024-08-01T21:31:40Z", "published": "2024-06-19T15:30:53Z", "aliases": [ "CVE-2024-38571" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nthermal/drivers/tsens: Fix null pointer dereference\n\ncompute_intercept_slope() is called from calibrate_8960() (in tsens-8960.c)\nas compute_intercept_slope(priv, p1, NULL, ONE_PT_CALIB) which lead to null\npointer dereference (if DEBUG or DYNAMIC_DEBUG set).\nFix this bug by adding null pointer check.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T14:15:17Z" diff --git a/advisories/unreviewed/2024/06/GHSA-6q7g-3wxj-hvcw/GHSA-6q7g-3wxj-hvcw.json b/advisories/unreviewed/2024/06/GHSA-6q7g-3wxj-hvcw/GHSA-6q7g-3wxj-hvcw.json index d9a0d51274f..1b54cf25902 100644 --- a/advisories/unreviewed/2024/06/GHSA-6q7g-3wxj-hvcw/GHSA-6q7g-3wxj-hvcw.json +++ b/advisories/unreviewed/2024/06/GHSA-6q7g-3wxj-hvcw/GHSA-6q7g-3wxj-hvcw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6q7g-3wxj-hvcw", - "modified": "2024-06-13T15:30:36Z", + "modified": "2024-08-01T21:31:40Z", "published": "2024-06-13T15:30:36Z", "aliases": [ "CVE-2024-37849" ], "details": "A SQL Injection vulnerability in itsourcecode Billing System 1.0 allows a local attacker to execute arbitrary code in process.php via the username parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-13T14:15:13Z" diff --git a/advisories/unreviewed/2024/06/GHSA-76jc-447v-8vf8/GHSA-76jc-447v-8vf8.json b/advisories/unreviewed/2024/06/GHSA-76jc-447v-8vf8/GHSA-76jc-447v-8vf8.json index 6a986219e27..486a7bc0d34 100644 --- a/advisories/unreviewed/2024/06/GHSA-76jc-447v-8vf8/GHSA-76jc-447v-8vf8.json +++ b/advisories/unreviewed/2024/06/GHSA-76jc-447v-8vf8/GHSA-76jc-447v-8vf8.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-285" + "CWE-285", + "CWE-863" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-8m45-p293-9xvp/GHSA-8m45-p293-9xvp.json b/advisories/unreviewed/2024/06/GHSA-8m45-p293-9xvp/GHSA-8m45-p293-9xvp.json index 88c9315a6a4..5d71583b8e1 100644 --- a/advisories/unreviewed/2024/06/GHSA-8m45-p293-9xvp/GHSA-8m45-p293-9xvp.json +++ b/advisories/unreviewed/2024/06/GHSA-8m45-p293-9xvp/GHSA-8m45-p293-9xvp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8m45-p293-9xvp", - "modified": "2024-06-19T15:30:53Z", + "modified": "2024-08-01T21:31:40Z", "published": "2024-06-19T15:30:53Z", "aliases": [ "CVE-2024-38581" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/mes: fix use-after-free issue\n\nDelete fence fallback timer to fix the ramdom\nuse-after-free issue.\n\nv2: move to amdgpu_mes.c", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T14:15:18Z" diff --git a/advisories/unreviewed/2024/06/GHSA-93cv-hrv4-p8q4/GHSA-93cv-hrv4-p8q4.json b/advisories/unreviewed/2024/06/GHSA-93cv-hrv4-p8q4/GHSA-93cv-hrv4-p8q4.json index 26d852e4127..5a384cc50e4 100644 --- a/advisories/unreviewed/2024/06/GHSA-93cv-hrv4-p8q4/GHSA-93cv-hrv4-p8q4.json +++ b/advisories/unreviewed/2024/06/GHSA-93cv-hrv4-p8q4/GHSA-93cv-hrv4-p8q4.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-203", "CWE-204" ], "severity": "LOW", diff --git a/advisories/unreviewed/2024/06/GHSA-cgqc-h3vr-3xq2/GHSA-cgqc-h3vr-3xq2.json b/advisories/unreviewed/2024/06/GHSA-cgqc-h3vr-3xq2/GHSA-cgqc-h3vr-3xq2.json index 2573c484387..37ab655ae35 100644 --- a/advisories/unreviewed/2024/06/GHSA-cgqc-h3vr-3xq2/GHSA-cgqc-h3vr-3xq2.json +++ b/advisories/unreviewed/2024/06/GHSA-cgqc-h3vr-3xq2/GHSA-cgqc-h3vr-3xq2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cgqc-h3vr-3xq2", - "modified": "2024-06-19T15:30:54Z", + "modified": "2024-08-01T21:31:40Z", "published": "2024-06-19T15:30:54Z", "aliases": [ "CVE-2024-38603" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrivers/perf: hisi: hns3: Actually use devm_add_action_or_reset()\n\npci_alloc_irq_vectors() allocates an irq vector. When devm_add_action()\nfails, the irq vector is not freed, which leads to a memory leak.\n\nReplace the devm_add_action with devm_add_action_or_reset to ensure\nthe irq vector can be destroyed when it fails.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T14:15:20Z" diff --git a/advisories/unreviewed/2024/06/GHSA-f5xv-9h76-hchp/GHSA-f5xv-9h76-hchp.json b/advisories/unreviewed/2024/06/GHSA-f5xv-9h76-hchp/GHSA-f5xv-9h76-hchp.json index 4d5693586f4..f323bbb68ac 100644 --- a/advisories/unreviewed/2024/06/GHSA-f5xv-9h76-hchp/GHSA-f5xv-9h76-hchp.json +++ b/advisories/unreviewed/2024/06/GHSA-f5xv-9h76-hchp/GHSA-f5xv-9h76-hchp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f5xv-9h76-hchp", - "modified": "2024-06-14T18:31:46Z", + "modified": "2024-08-01T21:31:40Z", "published": "2024-06-14T18:31:46Z", "aliases": [ "CVE-2024-36599" ], "details": "A cross-site scripting (XSS) vulnerability in Aegon Life v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter at insertClient.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-14T18:15:27Z" diff --git a/advisories/unreviewed/2024/06/GHSA-frcg-wh52-w5v9/GHSA-frcg-wh52-w5v9.json b/advisories/unreviewed/2024/06/GHSA-frcg-wh52-w5v9/GHSA-frcg-wh52-w5v9.json index 2e78445fe28..764e7d64881 100644 --- a/advisories/unreviewed/2024/06/GHSA-frcg-wh52-w5v9/GHSA-frcg-wh52-w5v9.json +++ b/advisories/unreviewed/2024/06/GHSA-frcg-wh52-w5v9/GHSA-frcg-wh52-w5v9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-frcg-wh52-w5v9", - "modified": "2024-06-27T15:30:40Z", + "modified": "2024-08-01T21:31:40Z", "published": "2024-06-19T15:30:53Z", "aliases": [ "CVE-2024-38583" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix use-after-free of timer for log writer thread\n\nPatch series \"nilfs2: fix log writer related issues\".\n\nThis bug fix series covers three nilfs2 log writer-related issues,\nincluding a timer use-after-free issue and potential deadlock issue on\nunmount, and a potential freeze issue in event synchronization found\nduring their analysis. Details are described in each commit log.\n\n\nThis patch (of 3):\n\nA use-after-free issue has been reported regarding the timer sc_timer on\nthe nilfs_sc_info structure.\n\nThe problem is that even though it is used to wake up a sleeping log\nwriter thread, sc_timer is not shut down until the nilfs_sc_info structure\nis about to be freed, and is used regardless of the thread's lifetime.\n\nFix this issue by limiting the use of sc_timer only while the log writer\nthread is alive.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -61,9 +64,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T14:15:18Z" diff --git a/advisories/unreviewed/2024/06/GHSA-mm7f-23wf-j4qf/GHSA-mm7f-23wf-j4qf.json b/advisories/unreviewed/2024/06/GHSA-mm7f-23wf-j4qf/GHSA-mm7f-23wf-j4qf.json index 8a01d819891..4568ad75bc9 100644 --- a/advisories/unreviewed/2024/06/GHSA-mm7f-23wf-j4qf/GHSA-mm7f-23wf-j4qf.json +++ b/advisories/unreviewed/2024/06/GHSA-mm7f-23wf-j4qf/GHSA-mm7f-23wf-j4qf.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-287" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-qv6x-rf2v-9hw8/GHSA-qv6x-rf2v-9hw8.json b/advisories/unreviewed/2024/06/GHSA-qv6x-rf2v-9hw8/GHSA-qv6x-rf2v-9hw8.json index 55b45593acf..319c7593599 100644 --- a/advisories/unreviewed/2024/06/GHSA-qv6x-rf2v-9hw8/GHSA-qv6x-rf2v-9hw8.json +++ b/advisories/unreviewed/2024/06/GHSA-qv6x-rf2v-9hw8/GHSA-qv6x-rf2v-9hw8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qv6x-rf2v-9hw8", - "modified": "2024-06-19T15:30:53Z", + "modified": "2024-08-01T21:31:40Z", "published": "2024-06-19T15:30:53Z", "aliases": [ "CVE-2024-38563" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7996: fix potential memory leakage when reading chip temperature\n\nWithout this commit, reading chip temperature will cause memory leakage.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T14:15:16Z" diff --git a/advisories/unreviewed/2024/06/GHSA-wqp9-f35v-h4f9/GHSA-wqp9-f35v-h4f9.json b/advisories/unreviewed/2024/06/GHSA-wqp9-f35v-h4f9/GHSA-wqp9-f35v-h4f9.json index 5b8ee79d77a..53e6bb6d01c 100644 --- a/advisories/unreviewed/2024/06/GHSA-wqp9-f35v-h4f9/GHSA-wqp9-f35v-h4f9.json +++ b/advisories/unreviewed/2024/06/GHSA-wqp9-f35v-h4f9/GHSA-wqp9-f35v-h4f9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wqp9-f35v-h4f9", - "modified": "2024-06-19T15:30:53Z", + "modified": "2024-08-01T21:31:40Z", "published": "2024-06-19T15:30:53Z", "aliases": [ "CVE-2024-38577" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nrcu-tasks: Fix show_rcu_tasks_trace_gp_kthread buffer overflow\n\nThere is a possibility of buffer overflow in\nshow_rcu_tasks_trace_gp_kthread() if counters, passed\nto sprintf() are huge. Counter numbers, needed for this\nare unrealistically high, but buffer overflow is still\npossible.\n\nUse snprintf() with buffer size instead of sprintf().\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T14:15:17Z" diff --git a/advisories/unreviewed/2024/07/GHSA-jmmr-w66h-7p5r/GHSA-jmmr-w66h-7p5r.json b/advisories/unreviewed/2024/07/GHSA-jmmr-w66h-7p5r/GHSA-jmmr-w66h-7p5r.json index ef92b90bd55..ae673f169ef 100644 --- a/advisories/unreviewed/2024/07/GHSA-jmmr-w66h-7p5r/GHSA-jmmr-w66h-7p5r.json +++ b/advisories/unreviewed/2024/07/GHSA-jmmr-w66h-7p5r/GHSA-jmmr-w66h-7p5r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jmmr-w66h-7p5r", - "modified": "2024-07-31T06:30:35Z", + "modified": "2024-08-01T21:31:40Z", "published": "2024-07-31T06:30:35Z", "aliases": [ "CVE-2024-6412" ], "details": "The HTML Forms WordPress plugin before 1.3.34 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-31T06:15:04Z" diff --git a/advisories/unreviewed/2024/08/GHSA-2g9j-pxq8-pw9c/GHSA-2g9j-pxq8-pw9c.json b/advisories/unreviewed/2024/08/GHSA-2g9j-pxq8-pw9c/GHSA-2g9j-pxq8-pw9c.json new file mode 100644 index 00000000000..85aad8d712e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-2g9j-pxq8-pw9c/GHSA-2g9j-pxq8-pw9c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2g9j-pxq8-pw9c", + "modified": "2024-08-01T21:31:41Z", + "published": "2024-08-01T21:31:41Z", + "aliases": [ + "CVE-2024-39619" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro allows PHP Local File Inclusion.This issue affects ListingPro: from n/a through 2.9.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39619" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/listingpro-plugin/wordpress-listingpro-plugin-2-9-3-unauthenticated-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T21:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-2jwr-937v-hx6p/GHSA-2jwr-937v-hx6p.json b/advisories/unreviewed/2024/08/GHSA-2jwr-937v-hx6p/GHSA-2jwr-937v-hx6p.json new file mode 100644 index 00000000000..2e792b14ed7 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-2jwr-937v-hx6p/GHSA-2jwr-937v-hx6p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2jwr-937v-hx6p", + "modified": "2024-08-01T21:31:41Z", + "published": "2024-08-01T21:31:41Z", + "aliases": [ + "CVE-2024-39621" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro allows PHP Local File Inclusion.This issue affects ListingPro: from n/a through 2.9.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39621" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/listingpro-plugin/wordpress-listingpro-plugin-2-9-3-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T21:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-3cpf-jmmc-8jm3/GHSA-3cpf-jmmc-8jm3.json b/advisories/unreviewed/2024/08/GHSA-3cpf-jmmc-8jm3/GHSA-3cpf-jmmc-8jm3.json new file mode 100644 index 00000000000..bc2786e4bef --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-3cpf-jmmc-8jm3/GHSA-3cpf-jmmc-8jm3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3cpf-jmmc-8jm3", + "modified": "2024-08-01T21:31:40Z", + "published": "2024-08-01T21:31:40Z", + "aliases": [ + "CVE-2024-4353" + ], + "details": "Concrete CMS versions 9.0.0 through 9.3.2 are affected by a stored XSS vulnerability in the generate dashboard board\ninstance functionality. The Name input field does not check the input sufficiently letting a rogue administrator hav the capability to inject malicious\nJavaScript code. The Concrete CMS security team gave this vulnerability a CVSS v3.1 score of 3.1 with a vector of AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator  and a CVSS v4 score of 1.8 with a vector of CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N Thanks fhAnso for reporting.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4353" + }, + { + "type": "WEB", + "url": "https://github.com/concretecms/concretecms/pull/12151" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T19:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-3qv4-28q5-585p/GHSA-3qv4-28q5-585p.json b/advisories/unreviewed/2024/08/GHSA-3qv4-28q5-585p/GHSA-3qv4-28q5-585p.json new file mode 100644 index 00000000000..24528c5630f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-3qv4-28q5-585p/GHSA-3qv4-28q5-585p.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3qv4-28q5-585p", + "modified": "2024-08-01T21:31:40Z", + "published": "2024-08-01T21:31:40Z", + "aliases": [ + "CVE-2024-7363" + ], + "details": "A vulnerability, which was classified as critical, was found in SourceCodester Tracking Monitoring Management System 1.0. Affected is an unknown function of the file /manage_person.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-273342 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7363" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/69455a114e8718af6c611c86fbdc78b5" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.273342" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.273342" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.383498" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T19:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-435h-73r2-vf64/GHSA-435h-73r2-vf64.json b/advisories/unreviewed/2024/08/GHSA-435h-73r2-vf64/GHSA-435h-73r2-vf64.json new file mode 100644 index 00000000000..95adc4aef49 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-435h-73r2-vf64/GHSA-435h-73r2-vf64.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-435h-73r2-vf64", + "modified": "2024-08-01T21:31:40Z", + "published": "2024-08-01T21:31:40Z", + "aliases": [ + "CVE-2024-38772" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Crocoblock JetWidgets for Elementor and WooCommerce allows PHP Local File Inclusion.This issue affects JetWidgets for Elementor and WooCommerce: from n/a through 1.1.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38772" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/jetwoo-widgets-for-elementor/wordpress-jetwidgets-for-elementor-and-woocommerce-plugin-1-1-7-contributor-limited-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T21:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-57xm-m24p-r448/GHSA-57xm-m24p-r448.json b/advisories/unreviewed/2024/08/GHSA-57xm-m24p-r448/GHSA-57xm-m24p-r448.json new file mode 100644 index 00000000000..8911f04b53e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-57xm-m24p-r448/GHSA-57xm-m24p-r448.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-57xm-m24p-r448", + "modified": "2024-08-01T21:31:40Z", + "published": "2024-08-01T21:31:40Z", + "aliases": [ + "CVE-2024-38775" + ], + "details": "Improper Privilege Management vulnerability in WebAppick CTX Feed allows Privilege Escalation.This issue affects CTX Feed: from n/a through 6.5.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38775" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/webappick-product-feed-for-woocommerce/wordpress-ctx-feed-plugin-6-5-6-arbitrary-options-update-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T21:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-6fh3-jqxg-h7vv/GHSA-6fh3-jqxg-h7vv.json b/advisories/unreviewed/2024/08/GHSA-6fh3-jqxg-h7vv/GHSA-6fh3-jqxg-h7vv.json new file mode 100644 index 00000000000..3ed0b6c3266 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6fh3-jqxg-h7vv/GHSA-6fh3-jqxg-h7vv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6fh3-jqxg-h7vv", + "modified": "2024-08-01T21:31:40Z", + "published": "2024-08-01T21:31:40Z", + "aliases": [ + "CVE-2024-38791" + ], + "details": "Server-Side Request Forgery (SSRF) vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot allows Server Side Request Forgery.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 2.4.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38791" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ai-engine/wordpress-ai-engine-plugin-2-4-7-server-side-request-forgery-ssrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T21:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7hjj-wgf7-9885/GHSA-7hjj-wgf7-9885.json b/advisories/unreviewed/2024/08/GHSA-7hjj-wgf7-9885/GHSA-7hjj-wgf7-9885.json new file mode 100644 index 00000000000..fce2e6cb097 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-7hjj-wgf7-9885/GHSA-7hjj-wgf7-9885.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7hjj-wgf7-9885", + "modified": "2024-08-01T21:31:40Z", + "published": "2024-08-01T21:31:40Z", + "aliases": [ + "CVE-2024-38770" + ], + "details": "Improper Privilege Management vulnerability in Revmakx Backup and Staging by WP Time Capsule allows Privilege Escalation, Authentication Bypass.This issue affects Backup and Staging by WP Time Capsule: from n/a through 1.22.20.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38770" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-time-capsule/wordpress-backup-and-staging-by-wp-time-capsule-plugin-1-22-20-authentication-bypass-and-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T21:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-824m-78xw-jp8w/GHSA-824m-78xw-jp8w.json b/advisories/unreviewed/2024/08/GHSA-824m-78xw-jp8w/GHSA-824m-78xw-jp8w.json new file mode 100644 index 00000000000..99c5f0e8209 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-824m-78xw-jp8w/GHSA-824m-78xw-jp8w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-824m-78xw-jp8w", + "modified": "2024-08-01T21:31:41Z", + "published": "2024-08-01T21:31:41Z", + "aliases": [ + "CVE-2024-39624" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro allows PHP Local File Inclusion.This issue affects ListingPro: from n/a through 2.9.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39624" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/listingpro/wordpress-listingpro-theme-2-9-3-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T21:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-86vf-g5px-79j2/GHSA-86vf-g5px-79j2.json b/advisories/unreviewed/2024/08/GHSA-86vf-g5px-79j2/GHSA-86vf-g5px-79j2.json new file mode 100644 index 00000000000..d4631660ac8 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-86vf-g5px-79j2/GHSA-86vf-g5px-79j2.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-86vf-g5px-79j2", + "modified": "2024-08-01T21:31:40Z", + "published": "2024-08-01T21:31:40Z", + "aliases": [ + "CVE-2024-7364" + ], + "details": "A vulnerability has been found in SourceCodester Tracking Monitoring Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /manage_records.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273343.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7364" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/b507afabd4e3da39e7eca6103435ba3a" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.273343" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.273343" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.383499" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T20:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-87qc-q3w7-7m8w/GHSA-87qc-q3w7-7m8w.json b/advisories/unreviewed/2024/08/GHSA-87qc-q3w7-7m8w/GHSA-87qc-q3w7-7m8w.json index 4e1aa2efc87..8a828a1e053 100644 --- a/advisories/unreviewed/2024/08/GHSA-87qc-q3w7-7m8w/GHSA-87qc-q3w7-7m8w.json +++ b/advisories/unreviewed/2024/08/GHSA-87qc-q3w7-7m8w/GHSA-87qc-q3w7-7m8w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-87qc-q3w7-7m8w", - "modified": "2024-08-01T15:32:20Z", + "modified": "2024-08-01T21:31:40Z", "published": "2024-08-01T15:32:20Z", "aliases": [ "CVE-2024-6923" ], "details": "There is a MEDIUM severity vulnerability affecting CPython.\n\nThe \nemail module didn’t properly quote newlines for email headers when \nserializing an email message allowing for header injection when an email\n is serialized.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-01T14:15:03Z" diff --git a/advisories/unreviewed/2024/08/GHSA-939p-28h4-46p5/GHSA-939p-28h4-46p5.json b/advisories/unreviewed/2024/08/GHSA-939p-28h4-46p5/GHSA-939p-28h4-46p5.json new file mode 100644 index 00000000000..884826fdefd --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-939p-28h4-46p5/GHSA-939p-28h4-46p5.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-939p-28h4-46p5", + "modified": "2024-08-01T21:31:41Z", + "published": "2024-08-01T21:31:41Z", + "aliases": [ + "CVE-2024-7367" + ], + "details": "A vulnerability, which was classified as problematic, was found in SourceCodester Simple Realtime Quiz System 1.0. This affects an unknown part of the file /ajax.php?action=save_user. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273351.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7367" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/03ae83fd32a94c85f910c8e3a85fa056" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.273351" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.273351" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.383515" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T21:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-cxjm-x772-f6r9/GHSA-cxjm-x772-f6r9.json b/advisories/unreviewed/2024/08/GHSA-cxjm-x772-f6r9/GHSA-cxjm-x772-f6r9.json new file mode 100644 index 00000000000..23dcbe0ceb0 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-cxjm-x772-f6r9/GHSA-cxjm-x772-f6r9.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cxjm-x772-f6r9", + "modified": "2024-08-01T21:31:41Z", + "published": "2024-08-01T21:31:41Z", + "aliases": [ + "CVE-2024-7366" + ], + "details": "A vulnerability was found in SourceCodester Tracking Monitoring Management System 1.0. It has been classified as critical. This affects an unknown part of the file /ajax.php?action=login of the component Login. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273345 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7366" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/c0efd2f3e6e146eb9e110e5e63cb5fbb" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.273345" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.273345" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.383501" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T21:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-frwc-xr7f-wxx2/GHSA-frwc-xr7f-wxx2.json b/advisories/unreviewed/2024/08/GHSA-frwc-xr7f-wxx2/GHSA-frwc-xr7f-wxx2.json new file mode 100644 index 00000000000..9beb56d26b7 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-frwc-xr7f-wxx2/GHSA-frwc-xr7f-wxx2.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-frwc-xr7f-wxx2", + "modified": "2024-08-01T21:31:40Z", + "published": "2024-08-01T21:31:40Z", + "aliases": [ + "CVE-2024-32863" + ], + "details": "Under certain circumstances the exacqVision Web Services may be susceptible to Cross-Site Request Forgery (CSRF)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32863" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-214-03" + }, + { + "type": "WEB", + "url": "https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T21:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-gq68-5q96-8992/GHSA-gq68-5q96-8992.json b/advisories/unreviewed/2024/08/GHSA-gq68-5q96-8992/GHSA-gq68-5q96-8992.json new file mode 100644 index 00000000000..43e28f9732f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-gq68-5q96-8992/GHSA-gq68-5q96-8992.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gq68-5q96-8992", + "modified": "2024-08-01T21:31:41Z", + "published": "2024-08-01T21:31:41Z", + "aliases": [ + "CVE-2024-39633" + ], + "details": "Improper Privilege Management vulnerability in IdeaBox PowerPack for Beaver Builder allows Privilege Escalation.This issue affects PowerPack for Beaver Builder: from n/a through 2.33.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39633" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/bbpowerpack/wordpress-powerpack-for-beaver-builder-plugin-2-33-0-contributor-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T21:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-hrmx-8jjv-g758/GHSA-hrmx-8jjv-g758.json b/advisories/unreviewed/2024/08/GHSA-hrmx-8jjv-g758/GHSA-hrmx-8jjv-g758.json new file mode 100644 index 00000000000..2ef97808b4c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-hrmx-8jjv-g758/GHSA-hrmx-8jjv-g758.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hrmx-8jjv-g758", + "modified": "2024-08-01T21:31:41Z", + "published": "2024-08-01T21:31:41Z", + "aliases": [ + "CVE-2024-41259" + ], + "details": "Use of insecure hashing algorithm in the Gravatar's service in Navidrome v0.52.3 allows attackers to manipulate a user's account information.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41259" + }, + { + "type": "WEB", + "url": "https://gist.github.com/nyxfqq/d192af10b53a363e2d9e430068333e04" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T21:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-jm66-g23p-272w/GHSA-jm66-g23p-272w.json b/advisories/unreviewed/2024/08/GHSA-jm66-g23p-272w/GHSA-jm66-g23p-272w.json new file mode 100644 index 00000000000..5f0fefc22e4 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-jm66-g23p-272w/GHSA-jm66-g23p-272w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jm66-g23p-272w", + "modified": "2024-08-01T21:31:40Z", + "published": "2024-08-01T21:31:40Z", + "aliases": [ + "CVE-2024-38746" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in MakeStories Team MakeStories (for Google Web Stories) allows Path Traversal, Server Side Request Forgery.This issue affects MakeStories (for Google Web Stories): from n/a through 3.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38746" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/makestories-helper/wordpress-makestories-for-google-web-stories-plugin-3-0-3-arbitrary-file-download-and-ssrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T21:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-jmjq-h283-6462/GHSA-jmjq-h283-6462.json b/advisories/unreviewed/2024/08/GHSA-jmjq-h283-6462/GHSA-jmjq-h283-6462.json new file mode 100644 index 00000000000..bebd1f7339b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-jmjq-h283-6462/GHSA-jmjq-h283-6462.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jmjq-h283-6462", + "modified": "2024-08-01T21:31:40Z", + "published": "2024-08-01T21:31:40Z", + "aliases": [ + "CVE-2023-52209" + ], + "details": "Improper Privilege Management vulnerability in WPForms, LLC. WPForms User Registration allows Privilege Escalation.This issue affects WPForms User Registration: from n/a through 2.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52209" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wpforms-user-registration/wordpress-wpforms-user-registration-plugin-2-1-0-authenticated-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T21:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-jxj9-jgw3-8c5v/GHSA-jxj9-jgw3-8c5v.json b/advisories/unreviewed/2024/08/GHSA-jxj9-jgw3-8c5v/GHSA-jxj9-jgw3-8c5v.json new file mode 100644 index 00000000000..f703438eec3 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-jxj9-jgw3-8c5v/GHSA-jxj9-jgw3-8c5v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jxj9-jgw3-8c5v", + "modified": "2024-08-01T21:31:41Z", + "published": "2024-08-01T21:31:41Z", + "aliases": [ + "CVE-2024-39634" + ], + "details": "Improper Privilege Management vulnerability in IdeaBox PowerPack Pro for Elementor allows Privilege Escalation.This issue affects PowerPack Pro for Elementor: from n/a through 2.10.14.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39634" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/powerpack-elements/wordpress-powerpack-pro-for-elementor-plugin-2-10-14-contributor-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T21:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-mc4q-hp46-qc8h/GHSA-mc4q-hp46-qc8h.json b/advisories/unreviewed/2024/08/GHSA-mc4q-hp46-qc8h/GHSA-mc4q-hp46-qc8h.json new file mode 100644 index 00000000000..f18edddea08 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-mc4q-hp46-qc8h/GHSA-mc4q-hp46-qc8h.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mc4q-hp46-qc8h", + "modified": "2024-08-01T21:31:40Z", + "published": "2024-08-01T21:31:40Z", + "aliases": [ + "CVE-2024-7365" + ], + "details": "A vulnerability was found in SourceCodester Tracking Monitoring Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /manage_establishment.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273344.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7365" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/18a15150a99566009476d918d79a0bf9" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.273344" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.273344" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.383500" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T20:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-mq4f-wch7-8vf9/GHSA-mq4f-wch7-8vf9.json b/advisories/unreviewed/2024/08/GHSA-mq4f-wch7-8vf9/GHSA-mq4f-wch7-8vf9.json new file mode 100644 index 00000000000..e2d5481c9b5 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-mq4f-wch7-8vf9/GHSA-mq4f-wch7-8vf9.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mq4f-wch7-8vf9", + "modified": "2024-08-01T21:31:40Z", + "published": "2024-08-01T21:31:40Z", + "aliases": [ + "CVE-2024-7362" + ], + "details": "A vulnerability, which was classified as critical, has been found in SourceCodester Tracking Monitoring Management System 1.0. This issue affects some unknown processing of the file /manage_user.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273341 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7362" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/96f43bd9f1477a56d1c8f8e08f0e5449" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.273341" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.273341" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.383497" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T19:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-r99h-g8vx-g4hw/GHSA-r99h-g8vx-g4hw.json b/advisories/unreviewed/2024/08/GHSA-r99h-g8vx-g4hw/GHSA-r99h-g8vx-g4hw.json new file mode 100644 index 00000000000..bf1b01785be --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-r99h-g8vx-g4hw/GHSA-r99h-g8vx-g4hw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r99h-g8vx-g4hw", + "modified": "2024-08-01T21:31:40Z", + "published": "2024-08-01T21:31:40Z", + "aliases": [ + "CVE-2024-38768" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Webangon The Pack Elementor addons allows PHP Local File Inclusion, Path Traversal.This issue affects The Pack Elementor addons: from n/a through 2.0.8.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38768" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/the-pack-addon/wordpress-the-pack-elementor-addons-plugin-2-0-8-6-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T21:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-x65v-v924-92w9/GHSA-x65v-v924-92w9.json b/advisories/unreviewed/2024/08/GHSA-x65v-v924-92w9/GHSA-x65v-v924-92w9.json new file mode 100644 index 00000000000..2aa8945753b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-x65v-v924-92w9/GHSA-x65v-v924-92w9.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x65v-v924-92w9", + "modified": "2024-08-01T21:31:40Z", + "published": "2024-08-01T21:31:40Z", + "aliases": [ + "CVE-2024-32864" + ], + "details": "Under certain circumstances exacqVision Web Services will not enforce secure web communications (HTTPS)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32864" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-214-04" + }, + { + "type": "WEB", + "url": "https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-319" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T21:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-xhpv-xmqr-mf62/GHSA-xhpv-xmqr-mf62.json b/advisories/unreviewed/2024/08/GHSA-xhpv-xmqr-mf62/GHSA-xhpv-xmqr-mf62.json new file mode 100644 index 00000000000..86cafd34739 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-xhpv-xmqr-mf62/GHSA-xhpv-xmqr-mf62.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xhpv-xmqr-mf62", + "modified": "2024-08-01T21:31:41Z", + "published": "2024-08-01T21:31:41Z", + "aliases": [ + "CVE-2024-39630" + ], + "details": "Deserialization of Untrusted Data vulnerability in MotoPress Timetable and Event Schedule allows Object Injection.This issue affects Timetable and Event Schedule: from n/a through 2.4.13.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39630" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/mp-timetable/wordpress-timetable-and-event-schedule-by-motopress-plugin-2-4-13-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T21:15:29Z" + } +} \ No newline at end of file