From 507be3031d6c7a4b5cf4cba0c789251dc26c8c2f Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 11 Oct 2024 21:32:40 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-4p7w-7m44-gvj9.json | 43 +++++++++++++++++ .../GHSA-545v-m4hv-f5f2.json | 43 +++++++++++++++++ .../GHSA-57r9-2g89-qw76.json | 38 +++++++++++++++ .../GHSA-586r-qxpv-m44q.json | 39 +++++++++++++++ .../GHSA-5h9p-4mfg-hmh4.json | 39 +++++++++++++++ .../GHSA-62q5-36cp-484h.json | 43 +++++++++++++++++ .../GHSA-6gfw-c4j2-28f8.json | 38 +++++++++++++++ .../GHSA-7v2q-xf3f-pfhp.json | 43 +++++++++++++++++ .../GHSA-9832-82h6-vrv6.json | 38 +++++++++++++++ .../GHSA-9mwp-24h8-4c8f.json | 43 +++++++++++++++++ .../GHSA-cc9w-f4c6-7c7r.json | 47 +++++++++++++++++++ .../GHSA-ccvw-9v7f-3pq8.json | 38 +++++++++++++++ .../GHSA-f27p-373w-hg26.json | 39 +++++++++++++++ .../GHSA-f5r3-qx7g-cx6v.json | 43 +++++++++++++++++ .../GHSA-g6f3-67v4-98vv.json | 43 +++++++++++++++++ .../GHSA-gcf7-xv2h-qvv7.json | 43 +++++++++++++++++ .../GHSA-h2p8-f2v7-2g2m.json | 1 + .../GHSA-hq46-pffv-g6wr.json | 39 +++++++++++++++ .../GHSA-hqhf-c9cf-w4qm.json | 9 ++-- .../GHSA-j3x9-prq7-4p96.json | 43 +++++++++++++++++ .../GHSA-m5xc-rf64-37r2.json | 38 +++++++++++++++ .../GHSA-p5f2-h5fv-xrrx.json | 9 ++-- .../GHSA-pjf2-268r-g6x9.json | 43 +++++++++++++++++ .../GHSA-q6x3-2mmr-2q9c.json | 43 +++++++++++++++++ .../GHSA-qcmw-rmjg-w3hr.json | 38 +++++++++++++++ .../GHSA-qf67-47q7-2f84.json | 6 ++- .../GHSA-r4fg-94jj-wp5g.json | 1 + .../GHSA-rfgc-w4c4-wfq8.json | 39 +++++++++++++++ .../GHSA-w88c-j332-rfjj.json | 39 +++++++++++++++ .../GHSA-w8wj-7hcm-8qpr.json | 43 +++++++++++++++++ .../GHSA-wfxr-5r9h-mpvw.json | 38 +++++++++++++++ 31 files changed, 1082 insertions(+), 7 deletions(-) create mode 100644 advisories/unreviewed/2024/10/GHSA-4p7w-7m44-gvj9/GHSA-4p7w-7m44-gvj9.json create mode 100644 advisories/unreviewed/2024/10/GHSA-545v-m4hv-f5f2/GHSA-545v-m4hv-f5f2.json create mode 100644 advisories/unreviewed/2024/10/GHSA-57r9-2g89-qw76/GHSA-57r9-2g89-qw76.json create mode 100644 advisories/unreviewed/2024/10/GHSA-586r-qxpv-m44q/GHSA-586r-qxpv-m44q.json create mode 100644 advisories/unreviewed/2024/10/GHSA-5h9p-4mfg-hmh4/GHSA-5h9p-4mfg-hmh4.json create mode 100644 advisories/unreviewed/2024/10/GHSA-62q5-36cp-484h/GHSA-62q5-36cp-484h.json create mode 100644 advisories/unreviewed/2024/10/GHSA-6gfw-c4j2-28f8/GHSA-6gfw-c4j2-28f8.json create mode 100644 advisories/unreviewed/2024/10/GHSA-7v2q-xf3f-pfhp/GHSA-7v2q-xf3f-pfhp.json create mode 100644 advisories/unreviewed/2024/10/GHSA-9832-82h6-vrv6/GHSA-9832-82h6-vrv6.json create mode 100644 advisories/unreviewed/2024/10/GHSA-9mwp-24h8-4c8f/GHSA-9mwp-24h8-4c8f.json create mode 100644 advisories/unreviewed/2024/10/GHSA-cc9w-f4c6-7c7r/GHSA-cc9w-f4c6-7c7r.json create mode 100644 advisories/unreviewed/2024/10/GHSA-ccvw-9v7f-3pq8/GHSA-ccvw-9v7f-3pq8.json create mode 100644 advisories/unreviewed/2024/10/GHSA-f27p-373w-hg26/GHSA-f27p-373w-hg26.json create mode 100644 advisories/unreviewed/2024/10/GHSA-f5r3-qx7g-cx6v/GHSA-f5r3-qx7g-cx6v.json create mode 100644 advisories/unreviewed/2024/10/GHSA-g6f3-67v4-98vv/GHSA-g6f3-67v4-98vv.json create mode 100644 advisories/unreviewed/2024/10/GHSA-gcf7-xv2h-qvv7/GHSA-gcf7-xv2h-qvv7.json create mode 100644 advisories/unreviewed/2024/10/GHSA-hq46-pffv-g6wr/GHSA-hq46-pffv-g6wr.json create mode 100644 advisories/unreviewed/2024/10/GHSA-j3x9-prq7-4p96/GHSA-j3x9-prq7-4p96.json create mode 100644 advisories/unreviewed/2024/10/GHSA-m5xc-rf64-37r2/GHSA-m5xc-rf64-37r2.json create mode 100644 advisories/unreviewed/2024/10/GHSA-pjf2-268r-g6x9/GHSA-pjf2-268r-g6x9.json create mode 100644 advisories/unreviewed/2024/10/GHSA-q6x3-2mmr-2q9c/GHSA-q6x3-2mmr-2q9c.json create mode 100644 advisories/unreviewed/2024/10/GHSA-qcmw-rmjg-w3hr/GHSA-qcmw-rmjg-w3hr.json create mode 100644 advisories/unreviewed/2024/10/GHSA-rfgc-w4c4-wfq8/GHSA-rfgc-w4c4-wfq8.json create mode 100644 advisories/unreviewed/2024/10/GHSA-w88c-j332-rfjj/GHSA-w88c-j332-rfjj.json create mode 100644 advisories/unreviewed/2024/10/GHSA-w8wj-7hcm-8qpr/GHSA-w8wj-7hcm-8qpr.json create mode 100644 advisories/unreviewed/2024/10/GHSA-wfxr-5r9h-mpvw/GHSA-wfxr-5r9h-mpvw.json diff --git a/advisories/unreviewed/2024/10/GHSA-4p7w-7m44-gvj9/GHSA-4p7w-7m44-gvj9.json b/advisories/unreviewed/2024/10/GHSA-4p7w-7m44-gvj9/GHSA-4p7w-7m44-gvj9.json new file mode 100644 index 00000000000..5a2ee416d99 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-4p7w-7m44-gvj9/GHSA-4p7w-7m44-gvj9.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4p7w-7m44-gvj9", + "modified": "2024-10-11T21:31:34Z", + "published": "2024-10-11T21:31:34Z", + "aliases": [ + "CVE-2024-48775" + ], + "details": "An issue in Plug n Play Camera com.ezset.delaney 1.2.0 allows a remote attacker to obtain sensitive information via the firmware update process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48775" + }, + { + "type": "WEB", + "url": "https://github.com/HankJames/Vul-Reports/blob/main/FirmwareLeakage/com.ezset.delaney/com.ezset.delaney.md" + }, + { + "type": "WEB", + "url": "http://comezsetdelaney.com" + }, + { + "type": "WEB", + "url": "http://plug.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T20:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-545v-m4hv-f5f2/GHSA-545v-m4hv-f5f2.json b/advisories/unreviewed/2024/10/GHSA-545v-m4hv-f5f2/GHSA-545v-m4hv-f5f2.json new file mode 100644 index 00000000000..337370439c1 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-545v-m4hv-f5f2/GHSA-545v-m4hv-f5f2.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-545v-m4hv-f5f2", + "modified": "2024-10-11T21:31:35Z", + "published": "2024-10-11T21:31:35Z", + "aliases": [ + "CVE-2024-48777" + ], + "details": "LEDVANCE com.ledvance.smartplus.eu 2.1.10 allows a remote attacker to obtain sensitive information via the firmware update process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48777" + }, + { + "type": "WEB", + "url": "https://github.com/HankJames/Vul-Reports/blob/main/FirmwareLeakage/com.ledvance.smartplus.eu/com.ledvance.smartplus.eu.md" + }, + { + "type": "WEB", + "url": "http://comledvancesmartpluseu.com" + }, + { + "type": "WEB", + "url": "http://ledvance.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T20:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-57r9-2g89-qw76/GHSA-57r9-2g89-qw76.json b/advisories/unreviewed/2024/10/GHSA-57r9-2g89-qw76/GHSA-57r9-2g89-qw76.json new file mode 100644 index 00000000000..4879856278c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-57r9-2g89-qw76/GHSA-57r9-2g89-qw76.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-57r9-2g89-qw76", + "modified": "2024-10-11T21:31:34Z", + "published": "2024-10-11T21:31:34Z", + "aliases": [ + "CVE-2024-47331" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NinjaTeam Multi Step for Contact Form allows SQL Injection.This issue affects Multi Step for Contact Form: from n/a through 2.7.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47331" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/cf7-multi-step/wordpress-multi-step-for-contact-form-plugin-2-7-7-unauthenticated-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-586r-qxpv-m44q/GHSA-586r-qxpv-m44q.json b/advisories/unreviewed/2024/10/GHSA-586r-qxpv-m44q/GHSA-586r-qxpv-m44q.json new file mode 100644 index 00000000000..4f14ff1ea8d --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-586r-qxpv-m44q/GHSA-586r-qxpv-m44q.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-586r-qxpv-m44q", + "modified": "2024-10-11T21:31:35Z", + "published": "2024-10-11T21:31:35Z", + "aliases": [ + "CVE-2024-46468" + ], + "details": "A Server-Side Request Forgery (SSRF) vulnerability exists in the jpress <= v5.1.1, which can be exploited by an attacker to obtain sensitive information, resulting in an information disclosure.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46468" + }, + { + "type": "WEB", + "url": "https://github.com/JPressProjects/jpress/issues/190" + }, + { + "type": "WEB", + "url": "https://gist.github.com/ilikeoyt/b396bbb9ef858105c46e999630e7afbe" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T21:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-5h9p-4mfg-hmh4/GHSA-5h9p-4mfg-hmh4.json b/advisories/unreviewed/2024/10/GHSA-5h9p-4mfg-hmh4/GHSA-5h9p-4mfg-hmh4.json new file mode 100644 index 00000000000..898c2941302 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-5h9p-4mfg-hmh4/GHSA-5h9p-4mfg-hmh4.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5h9p-4mfg-hmh4", + "modified": "2024-10-11T21:31:35Z", + "published": "2024-10-11T21:31:35Z", + "aliases": [ + "CVE-2024-48786" + ], + "details": "An issue in SWITCHBOT INC SwitchBot (com.theswitchbot.switchbot) 5.0.4 allows a remote attacker to obtain sensitive information via the firmware update process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48786" + }, + { + "type": "WEB", + "url": "https://github.com/HankJames/Vul-Reports/blob/main/FirmwareLeakage/com.theswitchbot.switchbot/com.theswitchbot.switchbot.md" + }, + { + "type": "WEB", + "url": "http://switchbot.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T20:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-62q5-36cp-484h/GHSA-62q5-36cp-484h.json b/advisories/unreviewed/2024/10/GHSA-62q5-36cp-484h/GHSA-62q5-36cp-484h.json new file mode 100644 index 00000000000..9ad837e8bfe --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-62q5-36cp-484h/GHSA-62q5-36cp-484h.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62q5-36cp-484h", + "modified": "2024-10-11T21:31:34Z", + "published": "2024-10-11T21:31:34Z", + "aliases": [ + "CVE-2024-48773" + ], + "details": "An issue in WoFit v.7.2.3 allows a remote attacker to obtain sensitive information via the firmware update process", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48773" + }, + { + "type": "WEB", + "url": "https://github.com/HankJames/Vul-Reports/blob/main/FirmwareLeakage/com.chenyu.morepro/com.chenyu.morepro.md" + }, + { + "type": "WEB", + "url": "http://comchenyumorepro.com" + }, + { + "type": "WEB", + "url": "http://wo-smart.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T20:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-6gfw-c4j2-28f8/GHSA-6gfw-c4j2-28f8.json b/advisories/unreviewed/2024/10/GHSA-6gfw-c4j2-28f8/GHSA-6gfw-c4j2-28f8.json new file mode 100644 index 00000000000..5ec2ed135a3 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-6gfw-c4j2-28f8/GHSA-6gfw-c4j2-28f8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6gfw-c4j2-28f8", + "modified": "2024-10-11T21:31:34Z", + "published": "2024-10-11T21:31:34Z", + "aliases": [ + "CVE-2024-48033" + ], + "details": "Deserialization of Untrusted Data vulnerability in Elie Burstein, Baptiste Gourdin Talkback allows Object Injection.This issue affects Talkback: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48033" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/talkback-secure-linkback-protocol/wordpress-talkback-plugin-1-0-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-7v2q-xf3f-pfhp/GHSA-7v2q-xf3f-pfhp.json b/advisories/unreviewed/2024/10/GHSA-7v2q-xf3f-pfhp/GHSA-7v2q-xf3f-pfhp.json new file mode 100644 index 00000000000..6907b61d649 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-7v2q-xf3f-pfhp/GHSA-7v2q-xf3f-pfhp.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7v2q-xf3f-pfhp", + "modified": "2024-10-11T21:31:35Z", + "published": "2024-10-11T21:31:35Z", + "aliases": [ + "CVE-2024-48784" + ], + "details": "An Incorrect Access Control issue in SAMPMAX com.sampmax.homemax 2.1.2.7 allows a remote attacker to obtain sensitive information via the firmware update process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48784" + }, + { + "type": "WEB", + "url": "https://github.com/HankJames/Vul-Reports/blob/main/FirmwareLeakage/com.sampmax.homemax/com.sampmax.homemax.md" + }, + { + "type": "WEB", + "url": "http://comsampmaxhomemax.com" + }, + { + "type": "WEB", + "url": "http://sampmax.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T20:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-9832-82h6-vrv6/GHSA-9832-82h6-vrv6.json b/advisories/unreviewed/2024/10/GHSA-9832-82h6-vrv6/GHSA-9832-82h6-vrv6.json new file mode 100644 index 00000000000..e921fad9398 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-9832-82h6-vrv6/GHSA-9832-82h6-vrv6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9832-82h6-vrv6", + "modified": "2024-10-11T21:31:34Z", + "published": "2024-10-11T21:31:34Z", + "aliases": [ + "CVE-2024-48040" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tainacan.Org Tainacan allows SQL Injection.This issue affects Tainacan: from n/a through 0.21.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48040" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/tainacan/wordpress-tainacan-plugin-0-21-8-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-9mwp-24h8-4c8f/GHSA-9mwp-24h8-4c8f.json b/advisories/unreviewed/2024/10/GHSA-9mwp-24h8-4c8f/GHSA-9mwp-24h8-4c8f.json new file mode 100644 index 00000000000..b75545e328c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-9mwp-24h8-4c8f/GHSA-9mwp-24h8-4c8f.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9mwp-24h8-4c8f", + "modified": "2024-10-11T21:31:35Z", + "published": "2024-10-11T21:31:34Z", + "aliases": [ + "CVE-2024-48776" + ], + "details": "An issue in Shelly com.home.shelly 1.0.4 allows a remote attacker to obtain sensitive information via the firmware update process", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48776" + }, + { + "type": "WEB", + "url": "https://github.com/HankJames/Vul-Reports/blob/main/FirmwareLeakage/com.home.shelly/com.home.shelly.md" + }, + { + "type": "WEB", + "url": "http://comhomeshelly.com" + }, + { + "type": "WEB", + "url": "http://shelly.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T20:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-cc9w-f4c6-7c7r/GHSA-cc9w-f4c6-7c7r.json b/advisories/unreviewed/2024/10/GHSA-cc9w-f4c6-7c7r/GHSA-cc9w-f4c6-7c7r.json new file mode 100644 index 00000000000..6caa255047a --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-cc9w-f4c6-7c7r/GHSA-cc9w-f4c6-7c7r.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cc9w-f4c6-7c7r", + "modified": "2024-10-11T21:31:34Z", + "published": "2024-10-11T21:31:34Z", + "aliases": [ + "CVE-2024-48768" + ], + "details": "An issue in almaodo GmbH appinventor.ai_google.almando_control 2.3.1 allows a remote attacker to obtain sensitive information via the firmware update process", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48768" + }, + { + "type": "WEB", + "url": "https://github.com/HankJames/Vul-Reports/blob/main/FirmwareLeakage/appinventor.ai_google.almando_control/appinventor.ai_google.almando_control.md" + }, + { + "type": "WEB", + "url": "https://www.almando.com/media/firmware/almando.json" + }, + { + "type": "WEB", + "url": "http://appinventoraigooglealmandocontrol.com" + }, + { + "type": "WEB", + "url": "http://www.almando.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T20:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-ccvw-9v7f-3pq8/GHSA-ccvw-9v7f-3pq8.json b/advisories/unreviewed/2024/10/GHSA-ccvw-9v7f-3pq8/GHSA-ccvw-9v7f-3pq8.json new file mode 100644 index 00000000000..aa7a172bf95 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-ccvw-9v7f-3pq8/GHSA-ccvw-9v7f-3pq8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ccvw-9v7f-3pq8", + "modified": "2024-10-11T21:31:34Z", + "published": "2024-10-11T21:31:34Z", + "aliases": [ + "CVE-2024-48041" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CreativeMindsSolutions CM Tooltip Glossary allows Stored XSS.This issue affects CM Tooltip Glossary: from n/a through 4.3.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48041" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/enhanced-tooltipglossary/wordpress-cm-tooltip-glossary-plugin-4-3-9-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-f27p-373w-hg26/GHSA-f27p-373w-hg26.json b/advisories/unreviewed/2024/10/GHSA-f27p-373w-hg26/GHSA-f27p-373w-hg26.json new file mode 100644 index 00000000000..e00dd8ee207 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-f27p-373w-hg26/GHSA-f27p-373w-hg26.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f27p-373w-hg26", + "modified": "2024-10-11T21:31:34Z", + "published": "2024-10-11T21:31:34Z", + "aliases": [ + "CVE-2024-48771" + ], + "details": "An issue in almando GmbH Almando Play APP (com.almando.play) 1.8.2 allows a remote attacker to obtain sensitive information via the firmware update process", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48771" + }, + { + "type": "WEB", + "url": "https://github.com/HankJames/Vul-Reports/blob/main/FirmwareLeakage/com.almando.play/com.almando.play.md" + }, + { + "type": "WEB", + "url": "http://almando.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T20:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-f5r3-qx7g-cx6v/GHSA-f5r3-qx7g-cx6v.json b/advisories/unreviewed/2024/10/GHSA-f5r3-qx7g-cx6v/GHSA-f5r3-qx7g-cx6v.json new file mode 100644 index 00000000000..8cd7a7d7bbf --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-f5r3-qx7g-cx6v/GHSA-f5r3-qx7g-cx6v.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f5r3-qx7g-cx6v", + "modified": "2024-10-11T21:31:35Z", + "published": "2024-10-11T21:31:35Z", + "aliases": [ + "CVE-2024-48772" + ], + "details": "An issue in C-CHIP (com.cchip.cchipamaota) v.1.2.8 allows a remote attacker to obtain sensitive information via the firmware update process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48772" + }, + { + "type": "WEB", + "url": "https://github.com/HankJames/Vul-Reports/blob/main/FirmwareLeakage/com.cchip.cchippamaota/com.cchip.cchipamaota.md" + }, + { + "type": "WEB", + "url": "http://comcchipcchipamaota.com" + }, + { + "type": "WEB", + "url": "http://www.c-chip.com.cn/english" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T21:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-g6f3-67v4-98vv/GHSA-g6f3-67v4-98vv.json b/advisories/unreviewed/2024/10/GHSA-g6f3-67v4-98vv/GHSA-g6f3-67v4-98vv.json new file mode 100644 index 00000000000..26e1ab12d97 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-g6f3-67v4-98vv/GHSA-g6f3-67v4-98vv.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g6f3-67v4-98vv", + "modified": "2024-10-11T21:31:34Z", + "published": "2024-10-11T21:31:34Z", + "aliases": [ + "CVE-2024-48770" + ], + "details": "An issue in Plug n Play Camera com.wisdomcity.zwave 1.1.0 allows a remote attacker to obtain sensitive information via the firmware update process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48770" + }, + { + "type": "WEB", + "url": "https://github.com/HankJames/Vul-Reports/blob/main/FirmwareLeakage/com.wisdomcity.zwave/com.wisdomcity.zwave.md" + }, + { + "type": "WEB", + "url": "http://comwisdomcityzwave.com" + }, + { + "type": "WEB", + "url": "http://plug.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T20:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-gcf7-xv2h-qvv7/GHSA-gcf7-xv2h-qvv7.json b/advisories/unreviewed/2024/10/GHSA-gcf7-xv2h-qvv7/GHSA-gcf7-xv2h-qvv7.json new file mode 100644 index 00000000000..ce1b2dbff03 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-gcf7-xv2h-qvv7/GHSA-gcf7-xv2h-qvv7.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gcf7-xv2h-qvv7", + "modified": "2024-10-11T21:31:35Z", + "published": "2024-10-11T21:31:35Z", + "aliases": [ + "CVE-2024-48778" + ], + "details": "An issue in GIANT MANUFACTURING CO., LTD RideLink (tw.giant.ridelink) 2.0.7 allows a remote attacker to obtain sensitive information via the firmware update process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48778" + }, + { + "type": "WEB", + "url": "https://github.com/HankJames/Vul-Reports/blob/main/FirmwareLeakage/tw.giant.ridelink/tw.giant.ridelink.md" + }, + { + "type": "WEB", + "url": "http://giant.com" + }, + { + "type": "WEB", + "url": "http://ridelink.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T20:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-h2p8-f2v7-2g2m/GHSA-h2p8-f2v7-2g2m.json b/advisories/unreviewed/2024/10/GHSA-h2p8-f2v7-2g2m/GHSA-h2p8-f2v7-2g2m.json index b881599677f..674d6ca9760 100644 --- a/advisories/unreviewed/2024/10/GHSA-h2p8-f2v7-2g2m/GHSA-h2p8-f2v7-2g2m.json +++ b/advisories/unreviewed/2024/10/GHSA-h2p8-f2v7-2g2m/GHSA-h2p8-f2v7-2g2m.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-23" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/10/GHSA-hq46-pffv-g6wr/GHSA-hq46-pffv-g6wr.json b/advisories/unreviewed/2024/10/GHSA-hq46-pffv-g6wr/GHSA-hq46-pffv-g6wr.json new file mode 100644 index 00000000000..4ddb2cb1a7a --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-hq46-pffv-g6wr/GHSA-hq46-pffv-g6wr.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hq46-pffv-g6wr", + "modified": "2024-10-11T21:31:35Z", + "published": "2024-10-11T21:31:35Z", + "aliases": [ + "CVE-2024-48788" + ], + "details": "An issue in YESCAM (com.yescom.YesCam.zwave) 1.0.2 allows a remote attacker to obtain sensitive information via the firmware update process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48788" + }, + { + "type": "WEB", + "url": "https://github.com/HankJames/Vul-Reports/blob/main/FirmwareLeakage/com.yescam.YesCam.zwave/com.yescam.YesCam.zwave.md" + }, + { + "type": "WEB", + "url": "http://yescam.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T21:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-hqhf-c9cf-w4qm/GHSA-hqhf-c9cf-w4qm.json b/advisories/unreviewed/2024/10/GHSA-hqhf-c9cf-w4qm/GHSA-hqhf-c9cf-w4qm.json index 075c9833f3b..38a81d3108f 100644 --- a/advisories/unreviewed/2024/10/GHSA-hqhf-c9cf-w4qm/GHSA-hqhf-c9cf-w4qm.json +++ b/advisories/unreviewed/2024/10/GHSA-hqhf-c9cf-w4qm/GHSA-hqhf-c9cf-w4qm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hqhf-c9cf-w4qm", - "modified": "2024-10-10T00:31:06Z", + "modified": "2024-10-11T21:31:34Z", "published": "2024-10-10T00:31:06Z", "aliases": [ "CVE-2024-48942" ], "details": "The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to easily brute-force the 2FA PIN via the plugins/servlet/twofactor/public/pinvalidation endpoint. The last 30 and the next 30 tokens are valid.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-10T00:15:02Z" diff --git a/advisories/unreviewed/2024/10/GHSA-j3x9-prq7-4p96/GHSA-j3x9-prq7-4p96.json b/advisories/unreviewed/2024/10/GHSA-j3x9-prq7-4p96/GHSA-j3x9-prq7-4p96.json new file mode 100644 index 00000000000..87d250e3e38 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-j3x9-prq7-4p96/GHSA-j3x9-prq7-4p96.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j3x9-prq7-4p96", + "modified": "2024-10-11T21:31:34Z", + "published": "2024-10-11T21:31:34Z", + "aliases": [ + "CVE-2024-48774" + ], + "details": "An issue in Fermax Asia Pacific Pte Ltd com.fermax.vida 2.4.6 allows a remote attacker to obtain sensitve information via the firmware update process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48774" + }, + { + "type": "WEB", + "url": "https://github.com/HankJames/Vul-Reports/blob/main/FirmwareLeakage/com.fermax.vida/com.fermax.vida.md" + }, + { + "type": "WEB", + "url": "http://comfermaxvida.com" + }, + { + "type": "WEB", + "url": "http://fermax.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T20:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-m5xc-rf64-37r2/GHSA-m5xc-rf64-37r2.json b/advisories/unreviewed/2024/10/GHSA-m5xc-rf64-37r2/GHSA-m5xc-rf64-37r2.json new file mode 100644 index 00000000000..b8d852d630d --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-m5xc-rf64-37r2/GHSA-m5xc-rf64-37r2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m5xc-rf64-37r2", + "modified": "2024-10-11T21:31:34Z", + "published": "2024-10-11T21:31:34Z", + "aliases": [ + "CVE-2024-48020" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Revmakx Backup and Staging by WP Time Capsule allows SQL Injection.This issue affects Backup and Staging by WP Time Capsule: from n/a through 1.22.21.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48020" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-time-capsule/wordpress-backup-and-staging-by-wp-time-capsule-plugin-1-22-21-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-p5f2-h5fv-xrrx/GHSA-p5f2-h5fv-xrrx.json b/advisories/unreviewed/2024/10/GHSA-p5f2-h5fv-xrrx/GHSA-p5f2-h5fv-xrrx.json index 27ede637473..3a891b17184 100644 --- a/advisories/unreviewed/2024/10/GHSA-p5f2-h5fv-xrrx/GHSA-p5f2-h5fv-xrrx.json +++ b/advisories/unreviewed/2024/10/GHSA-p5f2-h5fv-xrrx/GHSA-p5f2-h5fv-xrrx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p5f2-h5fv-xrrx", - "modified": "2024-10-10T00:31:06Z", + "modified": "2024-10-11T21:31:34Z", "published": "2024-10-10T00:31:06Z", "aliases": [ "CVE-2024-48941" ], "details": "The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to bypass 2FA by interacting with the /rest endpoint of Jira, Confluence, or Bitbucket. In the default configuration, /rest is allowlisted.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-10T00:15:02Z" diff --git a/advisories/unreviewed/2024/10/GHSA-pjf2-268r-g6x9/GHSA-pjf2-268r-g6x9.json b/advisories/unreviewed/2024/10/GHSA-pjf2-268r-g6x9/GHSA-pjf2-268r-g6x9.json new file mode 100644 index 00000000000..bd08f93f9f4 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-pjf2-268r-g6x9/GHSA-pjf2-268r-g6x9.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pjf2-268r-g6x9", + "modified": "2024-10-11T21:31:35Z", + "published": "2024-10-11T21:31:35Z", + "aliases": [ + "CVE-2024-48938" + ], + "details": "Znuny before LTS 6.5.1 through 6.5.10 and 7.0.1 through 7.0.16 allows DoS/ReDos via email. Parsing the content of emails where HTML code is copied from Microsoft Word could lead to high CPU usage and block the parsing process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48938" + }, + { + "type": "WEB", + "url": "https://www.znuny.com" + }, + { + "type": "WEB", + "url": "https://www.znuny.org/en/advisories" + }, + { + "type": "WEB", + "url": "https://www.znuny.org/en/advisories/zsa-2024-04" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T21:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-q6x3-2mmr-2q9c/GHSA-q6x3-2mmr-2q9c.json b/advisories/unreviewed/2024/10/GHSA-q6x3-2mmr-2q9c/GHSA-q6x3-2mmr-2q9c.json new file mode 100644 index 00000000000..f5cec2f7556 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-q6x3-2mmr-2q9c/GHSA-q6x3-2mmr-2q9c.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q6x3-2mmr-2q9c", + "modified": "2024-10-11T21:31:35Z", + "published": "2024-10-11T21:31:35Z", + "aliases": [ + "CVE-2024-48937" + ], + "details": "Znuny before LTS 6.5.1 through 6.5.10 and 7.0.1 through 7.0.16 allows XSS. JavaScript code in the short description of the SLA field in Activity Dialogues is executed.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48937" + }, + { + "type": "WEB", + "url": "https://www.znuny.com" + }, + { + "type": "WEB", + "url": "https://www.znuny.org/en/advisories" + }, + { + "type": "WEB", + "url": "https://www.znuny.org/en/advisories/zsa-2024-05" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T21:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-qcmw-rmjg-w3hr/GHSA-qcmw-rmjg-w3hr.json b/advisories/unreviewed/2024/10/GHSA-qcmw-rmjg-w3hr/GHSA-qcmw-rmjg-w3hr.json new file mode 100644 index 00000000000..0d41e23d1ff --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-qcmw-rmjg-w3hr/GHSA-qcmw-rmjg-w3hr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qcmw-rmjg-w3hr", + "modified": "2024-10-11T21:31:34Z", + "published": "2024-10-11T21:31:34Z", + "aliases": [ + "CVE-2024-47353" + ], + "details": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in QuomodoSoft ElementsReady Addons for Elementor.This issue affects ElementsReady Addons for Elementor: from n/a through 6.4.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47353" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/element-ready-lite/wordpress-elementsready-addons-for-elementor-plugin-6-4-2-open-redirection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-qf67-47q7-2f84/GHSA-qf67-47q7-2f84.json b/advisories/unreviewed/2024/10/GHSA-qf67-47q7-2f84/GHSA-qf67-47q7-2f84.json index 55dcaae8809..a817f20217a 100644 --- a/advisories/unreviewed/2024/10/GHSA-qf67-47q7-2f84/GHSA-qf67-47q7-2f84.json +++ b/advisories/unreviewed/2024/10/GHSA-qf67-47q7-2f84/GHSA-qf67-47q7-2f84.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qf67-47q7-2f84", - "modified": "2024-10-07T21:33:30Z", + "modified": "2024-10-11T21:31:33Z", "published": "2024-10-07T21:33:30Z", "aliases": [ "CVE-2024-47975" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://https://www.solidigm.com/support-page/support-security.html" + }, + { + "type": "WEB", + "url": "https://www.solidigm.com/support-page/support-security.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/10/GHSA-r4fg-94jj-wp5g/GHSA-r4fg-94jj-wp5g.json b/advisories/unreviewed/2024/10/GHSA-r4fg-94jj-wp5g/GHSA-r4fg-94jj-wp5g.json index 73ed62ec045..c89831acf8c 100644 --- a/advisories/unreviewed/2024/10/GHSA-r4fg-94jj-wp5g/GHSA-r4fg-94jj-wp5g.json +++ b/advisories/unreviewed/2024/10/GHSA-r4fg-94jj-wp5g/GHSA-r4fg-94jj-wp5g.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-23" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/10/GHSA-rfgc-w4c4-wfq8/GHSA-rfgc-w4c4-wfq8.json b/advisories/unreviewed/2024/10/GHSA-rfgc-w4c4-wfq8/GHSA-rfgc-w4c4-wfq8.json new file mode 100644 index 00000000000..03a7d9225e7 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-rfgc-w4c4-wfq8/GHSA-rfgc-w4c4-wfq8.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rfgc-w4c4-wfq8", + "modified": "2024-10-11T21:31:35Z", + "published": "2024-10-11T21:31:35Z", + "aliases": [ + "CVE-2024-48787" + ], + "details": "An issue in Revic Optics Revic Ops (us.revic.revicops) 1.12.5 allows a remote attacker to obtain sensitive information via the firmware update process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48787" + }, + { + "type": "WEB", + "url": "https://github.com/HankJames/Vul-Reports/blob/main/FirmwareLeakage/us.revic.revicops/us.revic.revicops.md" + }, + { + "type": "WEB", + "url": "http://revic.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T20:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-w88c-j332-rfjj/GHSA-w88c-j332-rfjj.json b/advisories/unreviewed/2024/10/GHSA-w88c-j332-rfjj/GHSA-w88c-j332-rfjj.json new file mode 100644 index 00000000000..a1620870375 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-w88c-j332-rfjj/GHSA-w88c-j332-rfjj.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w88c-j332-rfjj", + "modified": "2024-10-11T21:31:35Z", + "published": "2024-10-11T21:31:35Z", + "aliases": [ + "CVE-2024-45184" + ], + "details": "An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modems with chipset Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, Modem 5123, and Modem 5300. A USAT out-of-bounds write due to a heap buffer overflow can lead to a Denial of Service.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45184" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2024-45184" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T21:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-w8wj-7hcm-8qpr/GHSA-w8wj-7hcm-8qpr.json b/advisories/unreviewed/2024/10/GHSA-w8wj-7hcm-8qpr/GHSA-w8wj-7hcm-8qpr.json new file mode 100644 index 00000000000..5174f8367b1 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-w8wj-7hcm-8qpr/GHSA-w8wj-7hcm-8qpr.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w8wj-7hcm-8qpr", + "modified": "2024-10-11T21:31:34Z", + "published": "2024-10-11T21:31:34Z", + "aliases": [ + "CVE-2024-48769" + ], + "details": "An issue in BURG-WCHTER KG de.burgwachter.keyapp.app 4.5.0 allows a remote attacker to obtain sensitve information via the firmware update process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48769" + }, + { + "type": "WEB", + "url": "https://github.com/HankJames/Vul-Reports/blob/main/FirmwareLeakage/de.burgwachter.keyapp.app/de.burgwachter.keyapp.md" + }, + { + "type": "WEB", + "url": "http://burg-wchter.com" + }, + { + "type": "WEB", + "url": "http://deburgwachterkeyappapp.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T20:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-wfxr-5r9h-mpvw/GHSA-wfxr-5r9h-mpvw.json b/advisories/unreviewed/2024/10/GHSA-wfxr-5r9h-mpvw/GHSA-wfxr-5r9h-mpvw.json new file mode 100644 index 00000000000..44be05335d4 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-wfxr-5r9h-mpvw/GHSA-wfxr-5r9h-mpvw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wfxr-5r9h-mpvw", + "modified": "2024-10-11T21:31:34Z", + "published": "2024-10-11T21:31:34Z", + "aliases": [ + "CVE-2024-8912" + ], + "details": "An HTTP Request Smuggling vulnerability in Looker allowed an unauthorized attacker to capture HTTP responses destined for legitimate users.\n\nThere are two Looker versions that are hosted by Looker:\n\n * Looker (Google Cloud core) was found to be vulnerable. This issue has already been mitigated and our investigation has found no signs of exploitation.\n * Looker (original) was not vulnerable to this issue.\n\n\nCustomer-hosted Looker instances were found to be vulnerable and must be upgraded.\n\nThis vulnerability has been patched in all supported versions of customer-hosted Looker, which are available on the Looker download page https://download.looker.com/ .\n\nFor Looker customer-hosted instances, please update to the latest supported version of Looker as soon as possible. The versions below have all been updated to protect from this vulnerability. You can download these versions at the Looker download page:\n\n * 23.12 -> 23.12.123+\n * 23.18 -> 23.18.117+\n * 24.0 -> 24.0.92+\n * 24.6 -> 24.6.77+\n * 24.8 -> 24.8.66+\n * 24.10 -> 24.10.78+\n * 24.12 -> 24.12.56+\n * 24.14 -> 24.14.37+", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8912" + }, + { + "type": "WEB", + "url": "https://cloud.google.com/looker/docs/best-practices/security-bulletin-09-16-24" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-444" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T19:15:11Z" + } +} \ No newline at end of file