diff --git a/advisories/unreviewed/2022/03/GHSA-vgmm-r7wp-gmv8/GHSA-vgmm-r7wp-gmv8.json b/advisories/unreviewed/2022/03/GHSA-vgmm-r7wp-gmv8/GHSA-vgmm-r7wp-gmv8.json index 6240d976984..710b60d8a7d 100644 --- a/advisories/unreviewed/2022/03/GHSA-vgmm-r7wp-gmv8/GHSA-vgmm-r7wp-gmv8.json +++ b/advisories/unreviewed/2022/03/GHSA-vgmm-r7wp-gmv8/GHSA-vgmm-r7wp-gmv8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vgmm-r7wp-gmv8", - "modified": "2022-03-24T00:00:51Z", + "modified": "2024-10-07T18:31:00Z", "published": "2022-03-15T00:00:53Z", "aliases": [ "CVE-2022-26320" @@ -33,9 +33,17 @@ "type": "WEB", "url": "https://safezoneswupdate.com" }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20220922042721/https://safezoneswupdate.com" + }, { "type": "WEB", "url": "https://www.fujifilm.com/fbglobal/eng/company/news/notice/2022/0302_rsakey_announce.html" + }, + { + "type": "WEB", + "url": "https://www.rambus.com/security/response-center/advisories/rmbs-2021-01" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-4hpc-jmfv-gf3c/GHSA-4hpc-jmfv-gf3c.json b/advisories/unreviewed/2024/02/GHSA-4hpc-jmfv-gf3c/GHSA-4hpc-jmfv-gf3c.json index f3939876598..20a7829f747 100644 --- a/advisories/unreviewed/2024/02/GHSA-4hpc-jmfv-gf3c/GHSA-4hpc-jmfv-gf3c.json +++ b/advisories/unreviewed/2024/02/GHSA-4hpc-jmfv-gf3c/GHSA-4hpc-jmfv-gf3c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4hpc-jmfv-gf3c", - "modified": "2024-02-13T18:38:23Z", + "modified": "2024-10-07T18:31:00Z", "published": "2024-02-13T18:38:23Z", "aliases": [ "CVE-2023-45206" ], "details": "An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. Through the help document endpoint in webmail, an attacker can inject JavaScript or HTML code that leads to cross-site scripting (XSS). (Adding an adequate message to avoid malicious code will mitigate this issue.)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-13T16:15:08Z" diff --git a/advisories/unreviewed/2024/08/GHSA-65w4-w734-528c/GHSA-65w4-w734-528c.json b/advisories/unreviewed/2024/08/GHSA-65w4-w734-528c/GHSA-65w4-w734-528c.json index 38bb9c98dc2..c4d9b51dd76 100644 --- a/advisories/unreviewed/2024/08/GHSA-65w4-w734-528c/GHSA-65w4-w734-528c.json +++ b/advisories/unreviewed/2024/08/GHSA-65w4-w734-528c/GHSA-65w4-w734-528c.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-gv48-7crg-mcfr/GHSA-gv48-7crg-mcfr.json b/advisories/unreviewed/2024/08/GHSA-gv48-7crg-mcfr/GHSA-gv48-7crg-mcfr.json index 0a0b940d44f..118a3786024 100644 --- a/advisories/unreviewed/2024/08/GHSA-gv48-7crg-mcfr/GHSA-gv48-7crg-mcfr.json +++ b/advisories/unreviewed/2024/08/GHSA-gv48-7crg-mcfr/GHSA-gv48-7crg-mcfr.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-vp4h-4vxh-9wx5/GHSA-vp4h-4vxh-9wx5.json b/advisories/unreviewed/2024/08/GHSA-vp4h-4vxh-9wx5/GHSA-vp4h-4vxh-9wx5.json index 5553d36cdff..7c020f0042d 100644 --- a/advisories/unreviewed/2024/08/GHSA-vp4h-4vxh-9wx5/GHSA-vp4h-4vxh-9wx5.json +++ b/advisories/unreviewed/2024/08/GHSA-vp4h-4vxh-9wx5/GHSA-vp4h-4vxh-9wx5.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-2q3v-8m45-45jg/GHSA-2q3v-8m45-45jg.json b/advisories/unreviewed/2024/09/GHSA-2q3v-8m45-45jg/GHSA-2q3v-8m45-45jg.json index 5a0553224aa..07e97e75187 100644 --- a/advisories/unreviewed/2024/09/GHSA-2q3v-8m45-45jg/GHSA-2q3v-8m45-45jg.json +++ b/advisories/unreviewed/2024/09/GHSA-2q3v-8m45-45jg/GHSA-2q3v-8m45-45jg.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-3784-5wfh-hvvw/GHSA-3784-5wfh-hvvw.json b/advisories/unreviewed/2024/09/GHSA-3784-5wfh-hvvw/GHSA-3784-5wfh-hvvw.json index a78d84cd212..785c582b842 100644 --- a/advisories/unreviewed/2024/09/GHSA-3784-5wfh-hvvw/GHSA-3784-5wfh-hvvw.json +++ b/advisories/unreviewed/2024/09/GHSA-3784-5wfh-hvvw/GHSA-3784-5wfh-hvvw.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-3f32-jc9w-78m7/GHSA-3f32-jc9w-78m7.json b/advisories/unreviewed/2024/09/GHSA-3f32-jc9w-78m7/GHSA-3f32-jc9w-78m7.json index d0ad2c1354e..88084622b00 100644 --- a/advisories/unreviewed/2024/09/GHSA-3f32-jc9w-78m7/GHSA-3f32-jc9w-78m7.json +++ b/advisories/unreviewed/2024/09/GHSA-3f32-jc9w-78m7/GHSA-3f32-jc9w-78m7.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-345", "CWE-353" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/09/GHSA-69wq-4pfq-hqxh/GHSA-69wq-4pfq-hqxh.json b/advisories/unreviewed/2024/09/GHSA-69wq-4pfq-hqxh/GHSA-69wq-4pfq-hqxh.json index 034c3a9c6fe..5102352f5cb 100644 --- a/advisories/unreviewed/2024/09/GHSA-69wq-4pfq-hqxh/GHSA-69wq-4pfq-hqxh.json +++ b/advisories/unreviewed/2024/09/GHSA-69wq-4pfq-hqxh/GHSA-69wq-4pfq-hqxh.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-7hxr-46j9-w526/GHSA-7hxr-46j9-w526.json b/advisories/unreviewed/2024/09/GHSA-7hxr-46j9-w526/GHSA-7hxr-46j9-w526.json index c8fb5d21acd..00ec3057256 100644 --- a/advisories/unreviewed/2024/09/GHSA-7hxr-46j9-w526/GHSA-7hxr-46j9-w526.json +++ b/advisories/unreviewed/2024/09/GHSA-7hxr-46j9-w526/GHSA-7hxr-46j9-w526.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-7x69-778c-9r5h/GHSA-7x69-778c-9r5h.json b/advisories/unreviewed/2024/09/GHSA-7x69-778c-9r5h/GHSA-7x69-778c-9r5h.json index edd13151ec0..02e6cbbf432 100644 --- a/advisories/unreviewed/2024/09/GHSA-7x69-778c-9r5h/GHSA-7x69-778c-9r5h.json +++ b/advisories/unreviewed/2024/09/GHSA-7x69-778c-9r5h/GHSA-7x69-778c-9r5h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7x69-778c-9r5h", - "modified": "2024-09-28T15:30:43Z", + "modified": "2024-10-07T18:31:02Z", "published": "2024-09-28T15:30:43Z", "aliases": [ "CVE-2024-8189" diff --git a/advisories/unreviewed/2024/09/GHSA-8g86-p27w-cfrf/GHSA-8g86-p27w-cfrf.json b/advisories/unreviewed/2024/09/GHSA-8g86-p27w-cfrf/GHSA-8g86-p27w-cfrf.json index 882d2257a88..13d0d984f28 100644 --- a/advisories/unreviewed/2024/09/GHSA-8g86-p27w-cfrf/GHSA-8g86-p27w-cfrf.json +++ b/advisories/unreviewed/2024/09/GHSA-8g86-p27w-cfrf/GHSA-8g86-p27w-cfrf.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-f25r-g5v8-v6qj/GHSA-f25r-g5v8-v6qj.json b/advisories/unreviewed/2024/09/GHSA-f25r-g5v8-v6qj/GHSA-f25r-g5v8-v6qj.json index 6bde2ce1726..ce6f6d4d1fb 100644 --- a/advisories/unreviewed/2024/09/GHSA-f25r-g5v8-v6qj/GHSA-f25r-g5v8-v6qj.json +++ b/advisories/unreviewed/2024/09/GHSA-f25r-g5v8-v6qj/GHSA-f25r-g5v8-v6qj.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-fm87-mh9v-3658/GHSA-fm87-mh9v-3658.json b/advisories/unreviewed/2024/09/GHSA-fm87-mh9v-3658/GHSA-fm87-mh9v-3658.json index 455efb6f3af..8489221592b 100644 --- a/advisories/unreviewed/2024/09/GHSA-fm87-mh9v-3658/GHSA-fm87-mh9v-3658.json +++ b/advisories/unreviewed/2024/09/GHSA-fm87-mh9v-3658/GHSA-fm87-mh9v-3658.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-gwm9-fmrx-q4pp/GHSA-gwm9-fmrx-q4pp.json b/advisories/unreviewed/2024/09/GHSA-gwm9-fmrx-q4pp/GHSA-gwm9-fmrx-q4pp.json index e1647253579..163153474c7 100644 --- a/advisories/unreviewed/2024/09/GHSA-gwm9-fmrx-q4pp/GHSA-gwm9-fmrx-q4pp.json +++ b/advisories/unreviewed/2024/09/GHSA-gwm9-fmrx-q4pp/GHSA-gwm9-fmrx-q4pp.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-j9vg-w22p-v5v2/GHSA-j9vg-w22p-v5v2.json b/advisories/unreviewed/2024/09/GHSA-j9vg-w22p-v5v2/GHSA-j9vg-w22p-v5v2.json index fd5b6fbb9a0..736086f3471 100644 --- a/advisories/unreviewed/2024/09/GHSA-j9vg-w22p-v5v2/GHSA-j9vg-w22p-v5v2.json +++ b/advisories/unreviewed/2024/09/GHSA-j9vg-w22p-v5v2/GHSA-j9vg-w22p-v5v2.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j9vg-w22p-v5v2", - "modified": "2024-09-26T18:31:45Z", + "modified": "2024-10-07T18:31:01Z", "published": "2024-09-26T18:31:45Z", "aliases": [ "CVE-2024-47122" ], "details": "In the goTenna Pro application, the encryption keys are stored along with a static IV on the device. This allows for complete decryption of keys stored on the device. This allows an attacker to decrypt all encrypted communications that include P2P, Group, and broadcast messages that use these keys.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/09/GHSA-q3xw-vphm-88j4/GHSA-q3xw-vphm-88j4.json b/advisories/unreviewed/2024/09/GHSA-q3xw-vphm-88j4/GHSA-q3xw-vphm-88j4.json index e1a2c013dc5..e577f9159f9 100644 --- a/advisories/unreviewed/2024/09/GHSA-q3xw-vphm-88j4/GHSA-q3xw-vphm-88j4.json +++ b/advisories/unreviewed/2024/09/GHSA-q3xw-vphm-88j4/GHSA-q3xw-vphm-88j4.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-r7rh-frh5-cg5j/GHSA-r7rh-frh5-cg5j.json b/advisories/unreviewed/2024/09/GHSA-r7rh-frh5-cg5j/GHSA-r7rh-frh5-cg5j.json index ba16564caf5..439899cdfef 100644 --- a/advisories/unreviewed/2024/09/GHSA-r7rh-frh5-cg5j/GHSA-r7rh-frh5-cg5j.json +++ b/advisories/unreviewed/2024/09/GHSA-r7rh-frh5-cg5j/GHSA-r7rh-frh5-cg5j.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r7rh-frh5-cg5j", - "modified": "2024-09-26T18:31:45Z", + "modified": "2024-10-07T18:31:02Z", "published": "2024-09-26T18:31:45Z", "aliases": [ "CVE-2024-47124" ], "details": "The goTenna pro series does not encrypt the callsigns of its users. These callsigns reveal information about the users and can also be leveraged for other vulnerabilities.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/09/GHSA-r9fv-vpgh-mfpg/GHSA-r9fv-vpgh-mfpg.json b/advisories/unreviewed/2024/09/GHSA-r9fv-vpgh-mfpg/GHSA-r9fv-vpgh-mfpg.json index d42fa473385..00fc0b477a5 100644 --- a/advisories/unreviewed/2024/09/GHSA-r9fv-vpgh-mfpg/GHSA-r9fv-vpgh-mfpg.json +++ b/advisories/unreviewed/2024/09/GHSA-r9fv-vpgh-mfpg/GHSA-r9fv-vpgh-mfpg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r9fv-vpgh-mfpg", - "modified": "2024-09-25T06:30:42Z", + "modified": "2024-10-07T18:31:01Z", "published": "2024-09-25T06:30:42Z", "aliases": [ "CVE-2024-8668" diff --git a/advisories/unreviewed/2024/09/GHSA-rpjq-433p-ppw9/GHSA-rpjq-433p-ppw9.json b/advisories/unreviewed/2024/09/GHSA-rpjq-433p-ppw9/GHSA-rpjq-433p-ppw9.json index bb3bc3fcfbb..324ae802b41 100644 --- a/advisories/unreviewed/2024/09/GHSA-rpjq-433p-ppw9/GHSA-rpjq-433p-ppw9.json +++ b/advisories/unreviewed/2024/09/GHSA-rpjq-433p-ppw9/GHSA-rpjq-433p-ppw9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rpjq-433p-ppw9", - "modified": "2024-09-29T09:30:46Z", + "modified": "2024-10-07T18:31:02Z", "published": "2024-09-29T09:30:46Z", "aliases": [ "CVE-2024-9324" diff --git a/advisories/unreviewed/2024/09/GHSA-whxv-xf4j-48r5/GHSA-whxv-xf4j-48r5.json b/advisories/unreviewed/2024/09/GHSA-whxv-xf4j-48r5/GHSA-whxv-xf4j-48r5.json index 5b9fd871c55..f4898745ca0 100644 --- a/advisories/unreviewed/2024/09/GHSA-whxv-xf4j-48r5/GHSA-whxv-xf4j-48r5.json +++ b/advisories/unreviewed/2024/09/GHSA-whxv-xf4j-48r5/GHSA-whxv-xf4j-48r5.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-352", "CWE-79" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/09/GHSA-wwjw-jqq2-7xjv/GHSA-wwjw-jqq2-7xjv.json b/advisories/unreviewed/2024/09/GHSA-wwjw-jqq2-7xjv/GHSA-wwjw-jqq2-7xjv.json index 524c4721488..197fed96ce7 100644 --- a/advisories/unreviewed/2024/09/GHSA-wwjw-jqq2-7xjv/GHSA-wwjw-jqq2-7xjv.json +++ b/advisories/unreviewed/2024/09/GHSA-wwjw-jqq2-7xjv/GHSA-wwjw-jqq2-7xjv.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-x3f6-2323-r899/GHSA-x3f6-2323-r899.json b/advisories/unreviewed/2024/09/GHSA-x3f6-2323-r899/GHSA-x3f6-2323-r899.json index b4a017bb707..670b157e84f 100644 --- a/advisories/unreviewed/2024/09/GHSA-x3f6-2323-r899/GHSA-x3f6-2323-r899.json +++ b/advisories/unreviewed/2024/09/GHSA-x3f6-2323-r899/GHSA-x3f6-2323-r899.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-xcqq-5vvm-q9m2/GHSA-xcqq-5vvm-q9m2.json b/advisories/unreviewed/2024/09/GHSA-xcqq-5vvm-q9m2/GHSA-xcqq-5vvm-q9m2.json index 9f3e075c27c..bbef163f21f 100644 --- a/advisories/unreviewed/2024/09/GHSA-xcqq-5vvm-q9m2/GHSA-xcqq-5vvm-q9m2.json +++ b/advisories/unreviewed/2024/09/GHSA-xcqq-5vvm-q9m2/GHSA-xcqq-5vvm-q9m2.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xcqq-5vvm-q9m2", - "modified": "2024-09-26T18:31:45Z", + "modified": "2024-10-07T18:31:01Z", "published": "2024-09-26T18:31:45Z", "aliases": [ "CVE-2024-47121" ], "details": "The goTenna Pro series uses a weak password for the QR broadcast message. If the QR broadcast message is captured over RF it is possible to decrypt it and use it to decrypt all future and past messages sent via encrypted broadcast.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/09/GHSA-xgc6-jf52-wphf/GHSA-xgc6-jf52-wphf.json b/advisories/unreviewed/2024/09/GHSA-xgc6-jf52-wphf/GHSA-xgc6-jf52-wphf.json index 9e4d841c0a0..19aa3c7f14f 100644 --- a/advisories/unreviewed/2024/09/GHSA-xgc6-jf52-wphf/GHSA-xgc6-jf52-wphf.json +++ b/advisories/unreviewed/2024/09/GHSA-xgc6-jf52-wphf/GHSA-xgc6-jf52-wphf.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-4gvj-wfph-8c6j/GHSA-4gvj-wfph-8c6j.json b/advisories/unreviewed/2024/10/GHSA-4gvj-wfph-8c6j/GHSA-4gvj-wfph-8c6j.json index b2400a37f7e..2960bd78911 100644 --- a/advisories/unreviewed/2024/10/GHSA-4gvj-wfph-8c6j/GHSA-4gvj-wfph-8c6j.json +++ b/advisories/unreviewed/2024/10/GHSA-4gvj-wfph-8c6j/GHSA-4gvj-wfph-8c6j.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-288" + "CWE-288", + "CWE-306" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-632q-77qj-c89q/GHSA-632q-77qj-c89q.json b/advisories/unreviewed/2024/10/GHSA-632q-77qj-c89q/GHSA-632q-77qj-c89q.json new file mode 100644 index 00000000000..5691154d9aa --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-632q-77qj-c89q/GHSA-632q-77qj-c89q.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-632q-77qj-c89q", + "modified": "2024-10-07T18:31:07Z", + "published": "2024-10-07T18:31:07Z", + "aliases": [ + "CVE-2024-28710" + ], + "details": "Cross Site Scripting vulnerability in LimeSurvey before 6.5.0+240319 allows a remote attacker to execute arbitrary code via a lack of input validation and output encoding in the Alert Widget's message component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28710" + }, + { + "type": "WEB", + "url": "https://github.com/LimeSurvey/LimeSurvey/commit/c2fd60f94bc1db275f20cbb27a3135a9bdfb7f10" + }, + { + "type": "WEB", + "url": "http://limesurvey.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T16:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-697q-w597-8xcg/GHSA-697q-w597-8xcg.json b/advisories/unreviewed/2024/10/GHSA-697q-w597-8xcg/GHSA-697q-w597-8xcg.json new file mode 100644 index 00000000000..a81956a67be --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-697q-w597-8xcg/GHSA-697q-w597-8xcg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-697q-w597-8xcg", + "modified": "2024-10-07T18:31:09Z", + "published": "2024-10-07T18:31:09Z", + "aliases": [ + "CVE-2024-27458" + ], + "details": "A potential security vulnerability has been identified in the HP Hotkey Support software, which might allow local escalation of privilege. HP is releasing mitigation for the potential vulnerability. Customers using HP Programmable Key are recommended to update HP Hotkey Support.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27458" + }, + { + "type": "WEB", + "url": "https://support.hp.com/us-en/document/ish_11342101-11342130-16/hpsbhf03977" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T17:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-6hr6-rx9m-cchc/GHSA-6hr6-rx9m-cchc.json b/advisories/unreviewed/2024/10/GHSA-6hr6-rx9m-cchc/GHSA-6hr6-rx9m-cchc.json new file mode 100644 index 00000000000..09b704bd1ef --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-6hr6-rx9m-cchc/GHSA-6hr6-rx9m-cchc.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6hr6-rx9m-cchc", + "modified": "2024-10-07T18:31:09Z", + "published": "2024-10-07T18:31:09Z", + "aliases": [ + "CVE-2024-42831" + ], + "details": "A reflected cross-site scripting (XSS) vulnerability in Elaine's Realtime CRM Automation v6.18.17 allows attackers to execute arbitrary JavaScript code in the web browser of a user via injecting a crafted payload into the dialog parameter at wrapper_dialog.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42831" + }, + { + "type": "WEB", + "url": "https://seclists.org/fulldisclosure/2024/Sep/49" + }, + { + "type": "WEB", + "url": "http://elaine.com" + }, + { + "type": "WEB", + "url": "http://realtime.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T18:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-74q2-6jp4-3rqq/GHSA-74q2-6jp4-3rqq.json b/advisories/unreviewed/2024/10/GHSA-74q2-6jp4-3rqq/GHSA-74q2-6jp4-3rqq.json new file mode 100644 index 00000000000..59ce8ce3c53 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-74q2-6jp4-3rqq/GHSA-74q2-6jp4-3rqq.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-74q2-6jp4-3rqq", + "modified": "2024-10-07T18:31:07Z", + "published": "2024-10-07T18:31:07Z", + "aliases": [ + "CVE-2024-45932" + ], + "details": "Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in /admin/contacts/organizations/edit/2.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45932" + }, + { + "type": "WEB", + "url": "https://github.com/AslamMahi/CVE-Aslam-Mahi/blob/main/Laravel%20CRM%20v1.3.0/CVE-2024-45932.md" + }, + { + "type": "WEB", + "url": "http://TobeReleased.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T16:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-82m4-8qr7-3gp9/GHSA-82m4-8qr7-3gp9.json b/advisories/unreviewed/2024/10/GHSA-82m4-8qr7-3gp9/GHSA-82m4-8qr7-3gp9.json new file mode 100644 index 00000000000..4e45abee699 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-82m4-8qr7-3gp9/GHSA-82m4-8qr7-3gp9.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-82m4-8qr7-3gp9", + "modified": "2024-10-07T18:31:08Z", + "published": "2024-10-07T18:31:08Z", + "aliases": [ + "CVE-2024-46041" + ], + "details": "IoT Haat Smart Plug IH-IN-16A-S v5.16.1 is vulnerable to Authentication Bypass by Capture-replay.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46041" + }, + { + "type": "WEB", + "url": "https://github.com/Anonymous120386/Anonymous" + }, + { + "type": "WEB", + "url": "https://www.iothaat.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T16:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-9wcc-fp9g-mcjc/GHSA-9wcc-fp9g-mcjc.json b/advisories/unreviewed/2024/10/GHSA-9wcc-fp9g-mcjc/GHSA-9wcc-fp9g-mcjc.json new file mode 100644 index 00000000000..b1d00283448 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-9wcc-fp9g-mcjc/GHSA-9wcc-fp9g-mcjc.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9wcc-fp9g-mcjc", + "modified": "2024-10-07T18:31:09Z", + "published": "2024-10-07T18:31:09Z", + "aliases": [ + "CVE-2024-44674" + ], + "details": "D-Link COVR-2600R FW101b05 is vulnerable to Buffer Overflow. In the function sub_24E28, the HTTP_REFERER is obtained through an environment variable, and this field is controllable, allowing it to be used as the value for src.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44674" + }, + { + "type": "WEB", + "url": "https://github.com/REYu6/iot/blob/21e59c0cf491a9663423c515370c4fcb43436ae0/CVE/dlink/Covr-3902/2600R.md" + }, + { + "type": "WEB", + "url": "https://www.dlink.com/en/security-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T18:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-c7xm-rwqj-pgcj/GHSA-c7xm-rwqj-pgcj.json b/advisories/unreviewed/2024/10/GHSA-c7xm-rwqj-pgcj/GHSA-c7xm-rwqj-pgcj.json new file mode 100644 index 00000000000..05e6a2591c5 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-c7xm-rwqj-pgcj/GHSA-c7xm-rwqj-pgcj.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c7xm-rwqj-pgcj", + "modified": "2024-10-07T18:31:07Z", + "published": "2024-10-07T18:31:07Z", + "aliases": [ + "CVE-2024-28709" + ], + "details": "Cross Site Scripting vulnerability in LimeSurvey before 6.5.12+240611 allows a remote attacker to execute arbitrary code via a crafted script to the title and comment fields.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28709" + }, + { + "type": "WEB", + "url": "https://github.com/LimeSurvey/LimeSurvey/commit/c844c4fba81cc26ffe6544bf095bad6252910bc0" + }, + { + "type": "WEB", + "url": "http://limesurvey.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T16:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-cxwm-73cq-j7r3/GHSA-cxwm-73cq-j7r3.json b/advisories/unreviewed/2024/10/GHSA-cxwm-73cq-j7r3/GHSA-cxwm-73cq-j7r3.json new file mode 100644 index 00000000000..f9cd955812b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-cxwm-73cq-j7r3/GHSA-cxwm-73cq-j7r3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cxwm-73cq-j7r3", + "modified": "2024-10-07T18:31:09Z", + "published": "2024-10-07T18:31:09Z", + "aliases": [ + "CVE-2024-47555" + ], + "details": "Missing Authentication - User & System Configuration", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47555" + }, + { + "type": "WEB", + "url": "https://securitydocs.business.xerox.com/wp-content/uploads/2024/10/Xerox-Security-Bulletin-XRX24-014-for-Xerox%C2%AE-FreeFlow%C2%AE-Core-v7.0-.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T18:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-f2c3-h6fh-5x7q/GHSA-f2c3-h6fh-5x7q.json b/advisories/unreviewed/2024/10/GHSA-f2c3-h6fh-5x7q/GHSA-f2c3-h6fh-5x7q.json new file mode 100644 index 00000000000..00a61b877d5 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-f2c3-h6fh-5x7q/GHSA-f2c3-h6fh-5x7q.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f2c3-h6fh-5x7q", + "modified": "2024-10-07T18:31:09Z", + "published": "2024-10-07T18:31:09Z", + "aliases": [ + "CVE-2024-46076" + ], + "details": "RuoYi v4.7.9 and before has a security flaw that allows escaping from comments within the code generation feature, enabling the injection of malicious code.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46076" + }, + { + "type": "WEB", + "url": "https://gist.github.com/kkll5875/f237f200bae6db6b47eea3236d82ad0d" + }, + { + "type": "WEB", + "url": "https://github.com/yangzongzhuan/RuoYi" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T18:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-jjx8-fgcm-mhjx/GHSA-jjx8-fgcm-mhjx.json b/advisories/unreviewed/2024/10/GHSA-jjx8-fgcm-mhjx/GHSA-jjx8-fgcm-mhjx.json new file mode 100644 index 00000000000..825a7210286 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-jjx8-fgcm-mhjx/GHSA-jjx8-fgcm-mhjx.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jjx8-fgcm-mhjx", + "modified": "2024-10-07T18:31:08Z", + "published": "2024-10-07T18:31:08Z", + "aliases": [ + "CVE-2024-46040" + ], + "details": "IoT Haat Smart Plug IH-IN-16A-S IH-IN-16A-S v5.16.1 suffers from Insufficient Session Expiration. The lack of validation of the authentication token at the IoT Haat during the Access Point Pairing mode leads the attacker to replay the Wi-Fi packets and forcefully turn off the access point after the authentication token has expired.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46040" + }, + { + "type": "WEB", + "url": "https://github.com/Anonymous120386/Anonymous" + }, + { + "type": "WEB", + "url": "https://www.iothaat.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T16:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-jp3v-f34f-92px/GHSA-jp3v-f34f-92px.json b/advisories/unreviewed/2024/10/GHSA-jp3v-f34f-92px/GHSA-jp3v-f34f-92px.json new file mode 100644 index 00000000000..347a61ebd59 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-jp3v-f34f-92px/GHSA-jp3v-f34f-92px.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jp3v-f34f-92px", + "modified": "2024-10-07T18:31:09Z", + "published": "2024-10-07T18:31:09Z", + "aliases": [ + "CVE-2024-46300" + ], + "details": "itsourcecode Placement Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Full Name field in registration.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46300" + }, + { + "type": "WEB", + "url": "https://github.com/riya98241/CVE/blob/main/CVE-2024-46300" + }, + { + "type": "WEB", + "url": "https://portswigger.net/web-security/cross-site-scripting/stored" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T17:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-m3jf-xxg5-r7h2/GHSA-m3jf-xxg5-r7h2.json b/advisories/unreviewed/2024/10/GHSA-m3jf-xxg5-r7h2/GHSA-m3jf-xxg5-r7h2.json new file mode 100644 index 00000000000..2d7730ac529 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-m3jf-xxg5-r7h2/GHSA-m3jf-xxg5-r7h2.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m3jf-xxg5-r7h2", + "modified": "2024-10-07T18:31:09Z", + "published": "2024-10-07T18:31:09Z", + "aliases": [ + "CVE-2024-9570" + ], + "details": "A vulnerability was found in D-Link DIR-619L B1 2.06 and classified as critical. Affected by this issue is the function formEasySetTimezone of the file /goform/formEasySetTimezone. The manipulation of the argument curTime leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9570" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/D-Link/DIR-619L/formEasySetTimezone.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.279464" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.279464" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.414548" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T16:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-phc2-g348-384g/GHSA-phc2-g348-384g.json b/advisories/unreviewed/2024/10/GHSA-phc2-g348-384g/GHSA-phc2-g348-384g.json index 0ead1aed3a9..01a3e2d99cf 100644 --- a/advisories/unreviewed/2024/10/GHSA-phc2-g348-384g/GHSA-phc2-g348-384g.json +++ b/advisories/unreviewed/2024/10/GHSA-phc2-g348-384g/GHSA-phc2-g348-384g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-phc2-g348-384g", - "modified": "2024-10-04T18:31:10Z", + "modified": "2024-10-07T18:31:03Z", "published": "2024-10-04T06:30:44Z", "aliases": [ "CVE-2024-47850" @@ -17,6 +17,10 @@ ], "references": [ + { + "type": "WEB", + "url": "https://github.com/OpenPrinting/cups-filters/security/advisories/GHSA-rq86-c7g6-r2h8" + }, { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47850" diff --git a/advisories/unreviewed/2024/10/GHSA-qw9m-35wc-m4gj/GHSA-qw9m-35wc-m4gj.json b/advisories/unreviewed/2024/10/GHSA-qw9m-35wc-m4gj/GHSA-qw9m-35wc-m4gj.json new file mode 100644 index 00000000000..fa86b08098d --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-qw9m-35wc-m4gj/GHSA-qw9m-35wc-m4gj.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qw9m-35wc-m4gj", + "modified": "2024-10-07T18:31:09Z", + "published": "2024-10-07T18:31:09Z", + "aliases": [ + "CVE-2024-46278" + ], + "details": "Teedy 1.11 is vulnerable to Cross Site Scripting (XSS) via the management console.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46278" + }, + { + "type": "WEB", + "url": "https://github.com/ayato-shitomi/CVE-2024-46278-teedy_1.11_account-takeover" + }, + { + "type": "WEB", + "url": "https://github.com/ayato-shitomi/teedy_1.11_account-takeover" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T16:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-xq72-m3h5-wf3q/GHSA-xq72-m3h5-wf3q.json b/advisories/unreviewed/2024/10/GHSA-xq72-m3h5-wf3q/GHSA-xq72-m3h5-wf3q.json new file mode 100644 index 00000000000..b5865be49e5 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-xq72-m3h5-wf3q/GHSA-xq72-m3h5-wf3q.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xq72-m3h5-wf3q", + "modified": "2024-10-07T18:31:09Z", + "published": "2024-10-07T18:31:09Z", + "aliases": [ + "CVE-2024-46446" + ], + "details": "Mecha CMS 3.0.0 is vulnerable to Directory Traversal. An attacker can construct cookies and URIs that bypass user identity checks. Parameters can then be passed through the POST method, resulting in the Deletion of Arbitrary Files or Website Takeover.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46446" + }, + { + "type": "WEB", + "url": "https://github.com/Sp1d3rL1/Mecha-cms-Arbitrary-File-Deletion-Vulnerability" + }, + { + "type": "WEB", + "url": "http://mecha-cmscom.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T16:15:05Z" + } +} \ No newline at end of file