diff --git a/advisories/unreviewed/2023/06/GHSA-2jwp-cgrg-xr5p/GHSA-2jwp-cgrg-xr5p.json b/advisories/unreviewed/2023/06/GHSA-2jwp-cgrg-xr5p/GHSA-2jwp-cgrg-xr5p.json index 7df9f9b2f27..e2d77baf7ea 100644 --- a/advisories/unreviewed/2023/06/GHSA-2jwp-cgrg-xr5p/GHSA-2jwp-cgrg-xr5p.json +++ b/advisories/unreviewed/2023/06/GHSA-2jwp-cgrg-xr5p/GHSA-2jwp-cgrg-xr5p.json @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-125" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-2w6x-rgf3-567f/GHSA-2w6x-rgf3-567f.json b/advisories/unreviewed/2023/06/GHSA-2w6x-rgf3-567f/GHSA-2w6x-rgf3-567f.json index 474f5f24032..ffa0b9071fb 100644 --- a/advisories/unreviewed/2023/06/GHSA-2w6x-rgf3-567f/GHSA-2w6x-rgf3-567f.json +++ b/advisories/unreviewed/2023/06/GHSA-2w6x-rgf3-567f/GHSA-2w6x-rgf3-567f.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-281" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-354m-q546-g336/GHSA-354m-q546-g336.json b/advisories/unreviewed/2023/06/GHSA-354m-q546-g336/GHSA-354m-q546-g336.json index 8c7c83aa310..0bd6fd23007 100644 --- a/advisories/unreviewed/2023/06/GHSA-354m-q546-g336/GHSA-354m-q546-g336.json +++ b/advisories/unreviewed/2023/06/GHSA-354m-q546-g336/GHSA-354m-q546-g336.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-125" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-5q9f-4pxq-x2gv/GHSA-5q9f-4pxq-x2gv.json b/advisories/unreviewed/2023/06/GHSA-5q9f-4pxq-x2gv/GHSA-5q9f-4pxq-x2gv.json index cf553bd8e68..a85ec222041 100644 --- a/advisories/unreviewed/2023/06/GHSA-5q9f-4pxq-x2gv/GHSA-5q9f-4pxq-x2gv.json +++ b/advisories/unreviewed/2023/06/GHSA-5q9f-4pxq-x2gv/GHSA-5q9f-4pxq-x2gv.json @@ -45,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-346" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-6xqg-hh2c-2329/GHSA-6xqg-hh2c-2329.json b/advisories/unreviewed/2023/06/GHSA-6xqg-hh2c-2329/GHSA-6xqg-hh2c-2329.json index 29782bc1c00..dbf4937713a 100644 --- a/advisories/unreviewed/2023/06/GHSA-6xqg-hh2c-2329/GHSA-6xqg-hh2c-2329.json +++ b/advisories/unreviewed/2023/06/GHSA-6xqg-hh2c-2329/GHSA-6xqg-hh2c-2329.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-7f9v-gr4r-4m76/GHSA-7f9v-gr4r-4m76.json b/advisories/unreviewed/2023/06/GHSA-7f9v-gr4r-4m76/GHSA-7f9v-gr4r-4m76.json index b87b3da29b5..24efd462445 100644 --- a/advisories/unreviewed/2023/06/GHSA-7f9v-gr4r-4m76/GHSA-7f9v-gr4r-4m76.json +++ b/advisories/unreviewed/2023/06/GHSA-7f9v-gr4r-4m76/GHSA-7f9v-gr4r-4m76.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-276" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-9v2j-gwj5-x7r3/GHSA-9v2j-gwj5-x7r3.json b/advisories/unreviewed/2023/06/GHSA-9v2j-gwj5-x7r3/GHSA-9v2j-gwj5-x7r3.json index 30a0498054c..adce93c2016 100644 --- a/advisories/unreviewed/2023/06/GHSA-9v2j-gwj5-x7r3/GHSA-9v2j-gwj5-x7r3.json +++ b/advisories/unreviewed/2023/06/GHSA-9v2j-gwj5-x7r3/GHSA-9v2j-gwj5-x7r3.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-c229-95xm-8499/GHSA-c229-95xm-8499.json b/advisories/unreviewed/2023/06/GHSA-c229-95xm-8499/GHSA-c229-95xm-8499.json index b08654c25b6..03f8b456b64 100644 --- a/advisories/unreviewed/2023/06/GHSA-c229-95xm-8499/GHSA-c229-95xm-8499.json +++ b/advisories/unreviewed/2023/06/GHSA-c229-95xm-8499/GHSA-c229-95xm-8499.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-346" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-c3qh-423w-97gw/GHSA-c3qh-423w-97gw.json b/advisories/unreviewed/2023/06/GHSA-c3qh-423w-97gw/GHSA-c3qh-423w-97gw.json index 8ee7454b72d..7c2af8ab6de 100644 --- a/advisories/unreviewed/2023/06/GHSA-c3qh-423w-97gw/GHSA-c3qh-423w-97gw.json +++ b/advisories/unreviewed/2023/06/GHSA-c3qh-423w-97gw/GHSA-c3qh-423w-97gw.json @@ -49,7 +49,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-125" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-cx3f-98jp-8mqj/GHSA-cx3f-98jp-8mqj.json b/advisories/unreviewed/2023/06/GHSA-cx3f-98jp-8mqj/GHSA-cx3f-98jp-8mqj.json index 541f156c000..0799a6abfd4 100644 --- a/advisories/unreviewed/2023/06/GHSA-cx3f-98jp-8mqj/GHSA-cx3f-98jp-8mqj.json +++ b/advisories/unreviewed/2023/06/GHSA-cx3f-98jp-8mqj/GHSA-cx3f-98jp-8mqj.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-125" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-f3qv-9r52-x874/GHSA-f3qv-9r52-x874.json b/advisories/unreviewed/2023/06/GHSA-f3qv-9r52-x874/GHSA-f3qv-9r52-x874.json index ce2e83d0c2a..179ac8e9e4c 100644 --- a/advisories/unreviewed/2023/06/GHSA-f3qv-9r52-x874/GHSA-f3qv-9r52-x874.json +++ b/advisories/unreviewed/2023/06/GHSA-f3qv-9r52-x874/GHSA-f3qv-9r52-x874.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-125" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-fg57-cq37-v9f2/GHSA-fg57-cq37-v9f2.json b/advisories/unreviewed/2023/06/GHSA-fg57-cq37-v9f2/GHSA-fg57-cq37-v9f2.json index f9f2e7b38d3..66b7818a4fb 100644 --- a/advisories/unreviewed/2023/06/GHSA-fg57-cq37-v9f2/GHSA-fg57-cq37-v9f2.json +++ b/advisories/unreviewed/2023/06/GHSA-fg57-cq37-v9f2/GHSA-fg57-cq37-v9f2.json @@ -45,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-281" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-fqc6-q4rq-q3m4/GHSA-fqc6-q4rq-q3m4.json b/advisories/unreviewed/2023/06/GHSA-fqc6-q4rq-q3m4/GHSA-fqc6-q4rq-q3m4.json index 24f051cac47..6ea16b323b8 100644 --- a/advisories/unreviewed/2023/06/GHSA-fqc6-q4rq-q3m4/GHSA-fqc6-q4rq-q3m4.json +++ b/advisories/unreviewed/2023/06/GHSA-fqc6-q4rq-q3m4/GHSA-fqc6-q4rq-q3m4.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-640" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-fvw5-vrf4-ccp4/GHSA-fvw5-vrf4-ccp4.json b/advisories/unreviewed/2023/06/GHSA-fvw5-vrf4-ccp4/GHSA-fvw5-vrf4-ccp4.json index e1391592550..d88aac9fc1d 100644 --- a/advisories/unreviewed/2023/06/GHSA-fvw5-vrf4-ccp4/GHSA-fvw5-vrf4-ccp4.json +++ b/advisories/unreviewed/2023/06/GHSA-fvw5-vrf4-ccp4/GHSA-fvw5-vrf4-ccp4.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-125" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-gg5r-fr32-9pp8/GHSA-gg5r-fr32-9pp8.json b/advisories/unreviewed/2023/06/GHSA-gg5r-fr32-9pp8/GHSA-gg5r-fr32-9pp8.json index 6681261bead..7919bb86b54 100644 --- a/advisories/unreviewed/2023/06/GHSA-gg5r-fr32-9pp8/GHSA-gg5r-fr32-9pp8.json +++ b/advisories/unreviewed/2023/06/GHSA-gg5r-fr32-9pp8/GHSA-gg5r-fr32-9pp8.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-h3rv-hgr9-469j/GHSA-h3rv-hgr9-469j.json b/advisories/unreviewed/2023/06/GHSA-h3rv-hgr9-469j/GHSA-h3rv-hgr9-469j.json index e8944ae650b..3a6a0604cbf 100644 --- a/advisories/unreviewed/2023/06/GHSA-h3rv-hgr9-469j/GHSA-h3rv-hgr9-469j.json +++ b/advisories/unreviewed/2023/06/GHSA-h3rv-hgr9-469j/GHSA-h3rv-hgr9-469j.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-hhrm-pcc6-hw9f/GHSA-hhrm-pcc6-hw9f.json b/advisories/unreviewed/2023/06/GHSA-hhrm-pcc6-hw9f/GHSA-hhrm-pcc6-hw9f.json index 27aa88522f7..bb9a5aa811f 100644 --- a/advisories/unreviewed/2023/06/GHSA-hhrm-pcc6-hw9f/GHSA-hhrm-pcc6-hw9f.json +++ b/advisories/unreviewed/2023/06/GHSA-hhrm-pcc6-hw9f/GHSA-hhrm-pcc6-hw9f.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-922" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-hj65-qvx8-7xvc/GHSA-hj65-qvx8-7xvc.json b/advisories/unreviewed/2023/06/GHSA-hj65-qvx8-7xvc/GHSA-hj65-qvx8-7xvc.json index 79d9b16827f..0b902495145 100644 --- a/advisories/unreviewed/2023/06/GHSA-hj65-qvx8-7xvc/GHSA-hj65-qvx8-7xvc.json +++ b/advisories/unreviewed/2023/06/GHSA-hj65-qvx8-7xvc/GHSA-hj65-qvx8-7xvc.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-m94c-53jh-mxq3/GHSA-m94c-53jh-mxq3.json b/advisories/unreviewed/2023/06/GHSA-m94c-53jh-mxq3/GHSA-m94c-53jh-mxq3.json index 2ef2960c112..1a820240f64 100644 --- a/advisories/unreviewed/2023/06/GHSA-m94c-53jh-mxq3/GHSA-m94c-53jh-mxq3.json +++ b/advisories/unreviewed/2023/06/GHSA-m94c-53jh-mxq3/GHSA-m94c-53jh-mxq3.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-mmj9-q94q-rwj7/GHSA-mmj9-q94q-rwj7.json b/advisories/unreviewed/2023/06/GHSA-mmj9-q94q-rwj7/GHSA-mmj9-q94q-rwj7.json index d979fad0f53..634d372c27a 100644 --- a/advisories/unreviewed/2023/06/GHSA-mmj9-q94q-rwj7/GHSA-mmj9-q94q-rwj7.json +++ b/advisories/unreviewed/2023/06/GHSA-mmj9-q94q-rwj7/GHSA-mmj9-q94q-rwj7.json @@ -45,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-639" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-p7fp-g747-v67w/GHSA-p7fp-g747-v67w.json b/advisories/unreviewed/2023/06/GHSA-p7fp-g747-v67w/GHSA-p7fp-g747-v67w.json index fd7344ef1c9..230025b99aa 100644 --- a/advisories/unreviewed/2023/06/GHSA-p7fp-g747-v67w/GHSA-p7fp-g747-v67w.json +++ b/advisories/unreviewed/2023/06/GHSA-p7fp-g747-v67w/GHSA-p7fp-g747-v67w.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-770" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-pmcj-7mgc-5vfw/GHSA-pmcj-7mgc-5vfw.json b/advisories/unreviewed/2023/06/GHSA-pmcj-7mgc-5vfw/GHSA-pmcj-7mgc-5vfw.json index dea389c0806..8062bb1ffaa 100644 --- a/advisories/unreviewed/2023/06/GHSA-pmcj-7mgc-5vfw/GHSA-pmcj-7mgc-5vfw.json +++ b/advisories/unreviewed/2023/06/GHSA-pmcj-7mgc-5vfw/GHSA-pmcj-7mgc-5vfw.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-346" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-q56w-x564-6hw9/GHSA-q56w-x564-6hw9.json b/advisories/unreviewed/2023/06/GHSA-q56w-x564-6hw9/GHSA-q56w-x564-6hw9.json index e0eee052dfe..eebf383f08c 100644 --- a/advisories/unreviewed/2023/06/GHSA-q56w-x564-6hw9/GHSA-q56w-x564-6hw9.json +++ b/advisories/unreviewed/2023/06/GHSA-q56w-x564-6hw9/GHSA-q56w-x564-6hw9.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-326" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-qcrj-w7hm-xcrh/GHSA-qcrj-w7hm-xcrh.json b/advisories/unreviewed/2023/06/GHSA-qcrj-w7hm-xcrh/GHSA-qcrj-w7hm-xcrh.json index 8125000a64b..ded97732e63 100644 --- a/advisories/unreviewed/2023/06/GHSA-qcrj-w7hm-xcrh/GHSA-qcrj-w7hm-xcrh.json +++ b/advisories/unreviewed/2023/06/GHSA-qcrj-w7hm-xcrh/GHSA-qcrj-w7hm-xcrh.json @@ -45,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-125" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-r5fm-jr68-98x6/GHSA-r5fm-jr68-98x6.json b/advisories/unreviewed/2023/06/GHSA-r5fm-jr68-98x6/GHSA-r5fm-jr68-98x6.json index de9a7690791..8637fddc3fa 100644 --- a/advisories/unreviewed/2023/06/GHSA-r5fm-jr68-98x6/GHSA-r5fm-jr68-98x6.json +++ b/advisories/unreviewed/2023/06/GHSA-r5fm-jr68-98x6/GHSA-r5fm-jr68-98x6.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-r5j8-wxqq-r73c/GHSA-r5j8-wxqq-r73c.json b/advisories/unreviewed/2023/06/GHSA-r5j8-wxqq-r73c/GHSA-r5j8-wxqq-r73c.json index 8a637477707..a444aa384df 100644 --- a/advisories/unreviewed/2023/06/GHSA-r5j8-wxqq-r73c/GHSA-r5j8-wxqq-r73c.json +++ b/advisories/unreviewed/2023/06/GHSA-r5j8-wxqq-r73c/GHSA-r5j8-wxqq-r73c.json @@ -49,7 +49,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-rf64-jg5j-h2qh/GHSA-rf64-jg5j-h2qh.json b/advisories/unreviewed/2023/06/GHSA-rf64-jg5j-h2qh/GHSA-rf64-jg5j-h2qh.json index 3a153199550..c7928471e5b 100644 --- a/advisories/unreviewed/2023/06/GHSA-rf64-jg5j-h2qh/GHSA-rf64-jg5j-h2qh.json +++ b/advisories/unreviewed/2023/06/GHSA-rf64-jg5j-h2qh/GHSA-rf64-jg5j-h2qh.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-rwh2-qmx3-w2p5/GHSA-rwh2-qmx3-w2p5.json b/advisories/unreviewed/2023/06/GHSA-rwh2-qmx3-w2p5/GHSA-rwh2-qmx3-w2p5.json index 31ab9622139..5ecaf9434f0 100644 --- a/advisories/unreviewed/2023/06/GHSA-rwh2-qmx3-w2p5/GHSA-rwh2-qmx3-w2p5.json +++ b/advisories/unreviewed/2023/06/GHSA-rwh2-qmx3-w2p5/GHSA-rwh2-qmx3-w2p5.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-770" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-w2jx-6xv7-8634/GHSA-w2jx-6xv7-8634.json b/advisories/unreviewed/2023/06/GHSA-w2jx-6xv7-8634/GHSA-w2jx-6xv7-8634.json index 7523859bbc5..b289b51fef7 100644 --- a/advisories/unreviewed/2023/06/GHSA-w2jx-6xv7-8634/GHSA-w2jx-6xv7-8634.json +++ b/advisories/unreviewed/2023/06/GHSA-w2jx-6xv7-8634/GHSA-w2jx-6xv7-8634.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-125" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-w5p2-597r-pjgr/GHSA-w5p2-597r-pjgr.json b/advisories/unreviewed/2023/06/GHSA-w5p2-597r-pjgr/GHSA-w5p2-597r-pjgr.json index a2f19a151b8..3a15766f6a1 100644 --- a/advisories/unreviewed/2023/06/GHSA-w5p2-597r-pjgr/GHSA-w5p2-597r-pjgr.json +++ b/advisories/unreviewed/2023/06/GHSA-w5p2-597r-pjgr/GHSA-w5p2-597r-pjgr.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-w643-wvhg-95x9/GHSA-w643-wvhg-95x9.json b/advisories/unreviewed/2023/06/GHSA-w643-wvhg-95x9/GHSA-w643-wvhg-95x9.json index 48c02eafe09..e543b365f55 100644 --- a/advisories/unreviewed/2023/06/GHSA-w643-wvhg-95x9/GHSA-w643-wvhg-95x9.json +++ b/advisories/unreviewed/2023/06/GHSA-w643-wvhg-95x9/GHSA-w643-wvhg-95x9.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-281" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-xvfj-9qc8-3jgp/GHSA-xvfj-9qc8-3jgp.json b/advisories/unreviewed/2023/06/GHSA-xvfj-9qc8-3jgp/GHSA-xvfj-9qc8-3jgp.json index 406f524e8e2..40fb7fca1e1 100644 --- a/advisories/unreviewed/2023/06/GHSA-xvfj-9qc8-3jgp/GHSA-xvfj-9qc8-3jgp.json +++ b/advisories/unreviewed/2023/06/GHSA-xvfj-9qc8-3jgp/GHSA-xvfj-9qc8-3jgp.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-8q68-7gwp-333p/GHSA-8q68-7gwp-333p.json b/advisories/unreviewed/2024/03/GHSA-8q68-7gwp-333p/GHSA-8q68-7gwp-333p.json index 5e7ef2b8fb1..0aecfc59339 100644 --- a/advisories/unreviewed/2024/03/GHSA-8q68-7gwp-333p/GHSA-8q68-7gwp-333p.json +++ b/advisories/unreviewed/2024/03/GHSA-8q68-7gwp-333p/GHSA-8q68-7gwp-333p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-9475-r4q8-rfwm/GHSA-9475-r4q8-rfwm.json b/advisories/unreviewed/2024/03/GHSA-9475-r4q8-rfwm/GHSA-9475-r4q8-rfwm.json index 32ad25ae387..84806c586a0 100644 --- a/advisories/unreviewed/2024/03/GHSA-9475-r4q8-rfwm/GHSA-9475-r4q8-rfwm.json +++ b/advisories/unreviewed/2024/03/GHSA-9475-r4q8-rfwm/GHSA-9475-r4q8-rfwm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-mwm3-q3pf-fp7v/GHSA-mwm3-q3pf-fp7v.json b/advisories/unreviewed/2024/03/GHSA-mwm3-q3pf-fp7v/GHSA-mwm3-q3pf-fp7v.json index 83997efd38f..e6d091043a2 100644 --- a/advisories/unreviewed/2024/03/GHSA-mwm3-q3pf-fp7v/GHSA-mwm3-q3pf-fp7v.json +++ b/advisories/unreviewed/2024/03/GHSA-mwm3-q3pf-fp7v/GHSA-mwm3-q3pf-fp7v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -51,9 +49,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/12/GHSA-3463-cgm9-fqjg/GHSA-3463-cgm9-fqjg.json b/advisories/unreviewed/2024/12/GHSA-3463-cgm9-fqjg/GHSA-3463-cgm9-fqjg.json index 958171b4bcb..30284839524 100644 --- a/advisories/unreviewed/2024/12/GHSA-3463-cgm9-fqjg/GHSA-3463-cgm9-fqjg.json +++ b/advisories/unreviewed/2024/12/GHSA-3463-cgm9-fqjg/GHSA-3463-cgm9-fqjg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3463-cgm9-fqjg", - "modified": "2024-12-05T00:34:59Z", + "modified": "2024-12-05T18:31:02Z", "published": "2024-12-05T00:34:59Z", "aliases": [ "CVE-2018-9398" ], "details": "In fm_set_stat of mediatek FM radio driver, there is a possible OOB write\n due to improper input validation. This could lead to local escalation of\n privilege with System execution privileges needed. User interaction is not\n needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-05T00:15:17Z" diff --git a/advisories/unreviewed/2024/12/GHSA-39rf-q9wg-hfr6/GHSA-39rf-q9wg-hfr6.json b/advisories/unreviewed/2024/12/GHSA-39rf-q9wg-hfr6/GHSA-39rf-q9wg-hfr6.json new file mode 100644 index 00000000000..58957374e16 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-39rf-q9wg-hfr6/GHSA-39rf-q9wg-hfr6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-39rf-q9wg-hfr6", + "modified": "2024-12-05T18:31:03Z", + "published": "2024-12-05T18:31:03Z", + "aliases": [ + "CVE-2024-12130" + ], + "details": "An “out of bounds read” code execution vulnerability exists in the Rockwell Automation Arena®\n\n that could allow a threat actor to craft a DOE file and force the software to read beyond the boundaries of an allocated memory. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12130" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-05T18:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-42xv-889g-w333/GHSA-42xv-889g-w333.json b/advisories/unreviewed/2024/12/GHSA-42xv-889g-w333/GHSA-42xv-889g-w333.json index 91204675322..b8ff9127415 100644 --- a/advisories/unreviewed/2024/12/GHSA-42xv-889g-w333/GHSA-42xv-889g-w333.json +++ b/advisories/unreviewed/2024/12/GHSA-42xv-889g-w333/GHSA-42xv-889g-w333.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-42xv-889g-w333", - "modified": "2024-12-05T00:34:59Z", + "modified": "2024-12-05T18:31:02Z", "published": "2024-12-05T00:34:59Z", "aliases": [ "CVE-2018-9408" ], "details": "In m3326_gps_write and m3326_gps_read of gps.s, there is a possible Out Of\n Bounds Read due to a missing bounds check. This could lead to a local\n information disclosure with System execution privileges needed. User\n interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-05T00:15:18Z" diff --git a/advisories/unreviewed/2024/12/GHSA-472m-pprq-9x46/GHSA-472m-pprq-9x46.json b/advisories/unreviewed/2024/12/GHSA-472m-pprq-9x46/GHSA-472m-pprq-9x46.json index 9524ae871d7..4eacbdca574 100644 --- a/advisories/unreviewed/2024/12/GHSA-472m-pprq-9x46/GHSA-472m-pprq-9x46.json +++ b/advisories/unreviewed/2024/12/GHSA-472m-pprq-9x46/GHSA-472m-pprq-9x46.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-472m-pprq-9x46", - "modified": "2024-12-05T00:34:59Z", + "modified": "2024-12-05T18:31:02Z", "published": "2024-12-05T00:34:59Z", "aliases": [ "CVE-2018-9396" ], "details": "In rpc_msg_handler and related handlers of drivers/misc/mediatek/eccci/port_rpc.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-04T22:15:18Z" diff --git a/advisories/unreviewed/2024/12/GHSA-4jj8-cc83-5gxq/GHSA-4jj8-cc83-5gxq.json b/advisories/unreviewed/2024/12/GHSA-4jj8-cc83-5gxq/GHSA-4jj8-cc83-5gxq.json new file mode 100644 index 00000000000..05e64bed36a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-4jj8-cc83-5gxq/GHSA-4jj8-cc83-5gxq.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4jj8-cc83-5gxq", + "modified": "2024-12-05T18:31:03Z", + "published": "2024-12-05T18:31:03Z", + "aliases": [ + "CVE-2024-12232" + ], + "details": "A vulnerability has been found in code-projects Simple CRUD Functionality 1.0 and classified as problematic. This vulnerability affects unknown code of the file /index.php. The manipulation of the argument newtitle/newdescr leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12232" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/LamentXU123/cve/blob/main/xss3.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.286978" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.286978" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.456069" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-05T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-4rv2-mwgh-33gj/GHSA-4rv2-mwgh-33gj.json b/advisories/unreviewed/2024/12/GHSA-4rv2-mwgh-33gj/GHSA-4rv2-mwgh-33gj.json new file mode 100644 index 00000000000..2dc13393e14 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-4rv2-mwgh-33gj/GHSA-4rv2-mwgh-33gj.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4rv2-mwgh-33gj", + "modified": "2024-12-05T18:31:03Z", + "published": "2024-12-05T18:31:03Z", + "aliases": [ + "CVE-2024-12233" + ], + "details": "A vulnerability was found in code-projects Online Notice Board up to 1.0 and classified as critical. This issue affects some unknown processing of the file /registration.php of the component Profile Picture Handler. The manipulation of the argument img leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12233" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/LamentXU123/cve/blob/main/RCE1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.286979" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.286979" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.456458" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-05T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-4x4p-57gw-fhrv/GHSA-4x4p-57gw-fhrv.json b/advisories/unreviewed/2024/12/GHSA-4x4p-57gw-fhrv/GHSA-4x4p-57gw-fhrv.json index ee544143273..f97591f93fc 100644 --- a/advisories/unreviewed/2024/12/GHSA-4x4p-57gw-fhrv/GHSA-4x4p-57gw-fhrv.json +++ b/advisories/unreviewed/2024/12/GHSA-4x4p-57gw-fhrv/GHSA-4x4p-57gw-fhrv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4x4p-57gw-fhrv", - "modified": "2024-12-05T00:34:59Z", + "modified": "2024-12-05T18:31:02Z", "published": "2024-12-05T00:34:59Z", "aliases": [ "CVE-2018-9403" ], "details": "In the MTK_FLP_MSG_HAL_DIAG_REPORT_DATA_NTF handler of flp2hal_-\n interface.c, there is a possible stack buffer overflow due to a missing\n bounds check. This could lead to local escalation of privilege in a\n privileged process with System execution privileges needed. User interaction\n is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-05T00:15:17Z" diff --git a/advisories/unreviewed/2024/12/GHSA-52jr-x6h6-xj6g/GHSA-52jr-x6h6-xj6g.json b/advisories/unreviewed/2024/12/GHSA-52jr-x6h6-xj6g/GHSA-52jr-x6h6-xj6g.json index 409ae524d1f..5d57f3a1985 100644 --- a/advisories/unreviewed/2024/12/GHSA-52jr-x6h6-xj6g/GHSA-52jr-x6h6-xj6g.json +++ b/advisories/unreviewed/2024/12/GHSA-52jr-x6h6-xj6g/GHSA-52jr-x6h6-xj6g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-52jr-x6h6-xj6g", - "modified": "2024-12-05T15:31:02Z", + "modified": "2024-12-05T18:31:03Z", "published": "2024-12-05T15:31:02Z", "aliases": [ "CVE-2024-11942" ], "details": "A vulnerability in Drupal Core allows File Manipulation.This issue affects Drupal Core: from 10.0.0 before 10.2.10.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-390" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-05T15:15:08Z" diff --git a/advisories/unreviewed/2024/12/GHSA-586f-xjhh-92p4/GHSA-586f-xjhh-92p4.json b/advisories/unreviewed/2024/12/GHSA-586f-xjhh-92p4/GHSA-586f-xjhh-92p4.json index 0cd4d78beec..bb97d88c8e0 100644 --- a/advisories/unreviewed/2024/12/GHSA-586f-xjhh-92p4/GHSA-586f-xjhh-92p4.json +++ b/advisories/unreviewed/2024/12/GHSA-586f-xjhh-92p4/GHSA-586f-xjhh-92p4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-586f-xjhh-92p4", - "modified": "2024-12-05T00:34:59Z", + "modified": "2024-12-05T18:31:02Z", "published": "2024-12-05T00:34:59Z", "aliases": [ "CVE-2018-9463" ], "details": "In sw49408_irq_runtime_engine_debug of touch_sw49408.c, there is a possible\n out of bounds write due to an incorrect bounds check. This could lead to\n local escalation of privilege with System execution privileges needed. User\n interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-05T00:15:18Z" diff --git a/advisories/unreviewed/2024/12/GHSA-5hff-x79p-wv95/GHSA-5hff-x79p-wv95.json b/advisories/unreviewed/2024/12/GHSA-5hff-x79p-wv95/GHSA-5hff-x79p-wv95.json new file mode 100644 index 00000000000..aeb959ee8d4 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-5hff-x79p-wv95/GHSA-5hff-x79p-wv95.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5hff-x79p-wv95", + "modified": "2024-12-05T18:31:03Z", + "published": "2024-12-05T18:31:03Z", + "aliases": [ + "CVE-2024-53470" + ], + "details": "Multiple stored cross-site scripting (XSS) vulnerabilities in the component /configuracao/gateway_pagamento.php of WeGIA v3.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the id or name parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53470" + }, + { + "type": "WEB", + "url": "https://github.com/nilsonmori/WeGIA" + }, + { + "type": "WEB", + "url": "https://github.com/nmmorette/vulnerability-research/blob/main/CVE-2024-53470/README.md" + }, + { + "type": "WEB", + "url": "https://www.wegia.org" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-05T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-6c2r-874p-4fv5/GHSA-6c2r-874p-4fv5.json b/advisories/unreviewed/2024/12/GHSA-6c2r-874p-4fv5/GHSA-6c2r-874p-4fv5.json new file mode 100644 index 00000000000..200d387b3fe --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-6c2r-874p-4fv5/GHSA-6c2r-874p-4fv5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6c2r-874p-4fv5", + "modified": "2024-12-05T18:31:03Z", + "published": "2024-12-05T18:31:03Z", + "aliases": [ + "CVE-2024-11155" + ], + "details": "A “use after free” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to use a resource that was already used. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11155" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-05T18:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-6gh4-647f-6rr5/GHSA-6gh4-647f-6rr5.json b/advisories/unreviewed/2024/12/GHSA-6gh4-647f-6rr5/GHSA-6gh4-647f-6rr5.json new file mode 100644 index 00000000000..046e2230b17 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-6gh4-647f-6rr5/GHSA-6gh4-647f-6rr5.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6gh4-647f-6rr5", + "modified": "2024-12-05T18:31:03Z", + "published": "2024-12-05T18:31:03Z", + "aliases": [ + "CVE-2024-53472" + ], + "details": "WeGIA v3.2.0 was discovered to contain a Cross-Site Request Forgery (CSRF).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53472" + }, + { + "type": "WEB", + "url": "https://github.com/nilsonLazarin/WeGIA" + }, + { + "type": "WEB", + "url": "https://github.com/nmmorette/vulnerability-research/tree/main/CVE-2024-53472" + }, + { + "type": "WEB", + "url": "https://www.wegia.org" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-05T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-6hqr-c69m-r76q/GHSA-6hqr-c69m-r76q.json b/advisories/unreviewed/2024/12/GHSA-6hqr-c69m-r76q/GHSA-6hqr-c69m-r76q.json index ef493cefc0b..a43eab23835 100644 --- a/advisories/unreviewed/2024/12/GHSA-6hqr-c69m-r76q/GHSA-6hqr-c69m-r76q.json +++ b/advisories/unreviewed/2024/12/GHSA-6hqr-c69m-r76q/GHSA-6hqr-c69m-r76q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6hqr-c69m-r76q", - "modified": "2024-12-05T12:31:28Z", + "modified": "2024-12-05T18:31:02Z", "published": "2024-12-05T12:31:28Z", "aliases": [ "CVE-2022-41137" ], "details": "Apache Hive Metastore (HMS) uses SerializationUtilities#deserializeObjectWithTypeInformation method when filtering and fetching partitions that is unsafe and can lead to Remote Code Execution (RCE) since it allows the deserialization of arbitrary data.\n\nIn real deployments, the vulnerability can be exploited only by authenticated users/clients that were able to successfully establish a connection to the Metastore. From an API perspective any code that calls the unsafe method may be vulnerable unless it performs additional prerechecks on the input arguments.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -39,7 +44,7 @@ "cwe_ids": [ "CWE-502" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-05T10:15:04Z" diff --git a/advisories/unreviewed/2024/12/GHSA-6w26-7rr7-96rj/GHSA-6w26-7rr7-96rj.json b/advisories/unreviewed/2024/12/GHSA-6w26-7rr7-96rj/GHSA-6w26-7rr7-96rj.json index 21070b0ca86..0ae035086f5 100644 --- a/advisories/unreviewed/2024/12/GHSA-6w26-7rr7-96rj/GHSA-6w26-7rr7-96rj.json +++ b/advisories/unreviewed/2024/12/GHSA-6w26-7rr7-96rj/GHSA-6w26-7rr7-96rj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6w26-7rr7-96rj", - "modified": "2024-12-04T18:32:36Z", + "modified": "2024-12-05T18:31:02Z", "published": "2024-12-04T18:32:36Z", "aliases": [ "CVE-2018-9395" ], "details": "In mtk_cfg80211_vendor_packet_keep_alive_start and mtk_cfg80211_vendor_set_config of drivers/misc/mediatek/connectivity/wlan/gen2/os/linux/gl_vendor.c, there is a possible OOB write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-04T18:15:10Z" diff --git a/advisories/unreviewed/2024/12/GHSA-73cj-343r-hjc2/GHSA-73cj-343r-hjc2.json b/advisories/unreviewed/2024/12/GHSA-73cj-343r-hjc2/GHSA-73cj-343r-hjc2.json index a20e357cce1..6f6b4c39546 100644 --- a/advisories/unreviewed/2024/12/GHSA-73cj-343r-hjc2/GHSA-73cj-343r-hjc2.json +++ b/advisories/unreviewed/2024/12/GHSA-73cj-343r-hjc2/GHSA-73cj-343r-hjc2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-73cj-343r-hjc2", - "modified": "2024-12-05T00:34:59Z", + "modified": "2024-12-05T18:31:02Z", "published": "2024-12-05T00:34:59Z", "aliases": [ "CVE-2018-9462" ], "details": "In store_cmd of ftm4_pdc.c, there is a possible out of bounds write due to\n an incorrect bounds check. This could lead to local escalation of privilege\n with System execution privileges needed. User interaction is not needed for\n exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-05T00:15:18Z" diff --git a/advisories/unreviewed/2024/12/GHSA-769g-258x-699h/GHSA-769g-258x-699h.json b/advisories/unreviewed/2024/12/GHSA-769g-258x-699h/GHSA-769g-258x-699h.json index 01aa08e347b..afe90edde3f 100644 --- a/advisories/unreviewed/2024/12/GHSA-769g-258x-699h/GHSA-769g-258x-699h.json +++ b/advisories/unreviewed/2024/12/GHSA-769g-258x-699h/GHSA-769g-258x-699h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-769g-258x-699h", - "modified": "2024-12-05T15:31:02Z", + "modified": "2024-12-05T18:31:02Z", "published": "2024-12-05T15:31:02Z", "aliases": [ "CVE-2024-45319" ], "details": "A vulnerability in the SonicWall SMA100 SSLVPN \n\nfirmware 10.2.1.13-72sv and earlier versions allows a remote authenticated attacker can circumvent the certificate requirement during authentication.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-798" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-05T14:15:21Z" diff --git a/advisories/unreviewed/2024/12/GHSA-8chw-qpp9-9385/GHSA-8chw-qpp9-9385.json b/advisories/unreviewed/2024/12/GHSA-8chw-qpp9-9385/GHSA-8chw-qpp9-9385.json new file mode 100644 index 00000000000..7875f255152 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8chw-qpp9-9385/GHSA-8chw-qpp9-9385.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8chw-qpp9-9385", + "modified": "2024-12-05T18:31:03Z", + "published": "2024-12-05T18:31:03Z", + "aliases": [ + "CVE-2024-12247" + ], + "details": "Mattermost versions 9.7.x <= 9.7.5, 9.8.x <= 9.8.2 and 9.9.x <= 9.9.2 fail to properly propagate permission scheme updates across cluster nodes which allows a user to keep old permissions, even if the permission scheme has been updated.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12247" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-05T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8fcw-x22m-3qx7/GHSA-8fcw-x22m-3qx7.json b/advisories/unreviewed/2024/12/GHSA-8fcw-x22m-3qx7/GHSA-8fcw-x22m-3qx7.json index 1a06c1c276f..6892a1a85ab 100644 --- a/advisories/unreviewed/2024/12/GHSA-8fcw-x22m-3qx7/GHSA-8fcw-x22m-3qx7.json +++ b/advisories/unreviewed/2024/12/GHSA-8fcw-x22m-3qx7/GHSA-8fcw-x22m-3qx7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8fcw-x22m-3qx7", - "modified": "2024-12-04T15:31:52Z", + "modified": "2024-12-05T18:31:02Z", "published": "2024-12-04T15:31:52Z", "aliases": [ "CVE-2024-40744" ], "details": "Unrestricted file upload via security bypass in Convert Forms component for Joomla in versions before 4.4.6.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-434" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-04T15:15:11Z" diff --git a/advisories/unreviewed/2024/12/GHSA-8g56-c3fw-gr86/GHSA-8g56-c3fw-gr86.json b/advisories/unreviewed/2024/12/GHSA-8g56-c3fw-gr86/GHSA-8g56-c3fw-gr86.json index 54c6de06f30..56299d0a766 100644 --- a/advisories/unreviewed/2024/12/GHSA-8g56-c3fw-gr86/GHSA-8g56-c3fw-gr86.json +++ b/advisories/unreviewed/2024/12/GHSA-8g56-c3fw-gr86/GHSA-8g56-c3fw-gr86.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8g56-c3fw-gr86", - "modified": "2024-12-05T00:34:59Z", + "modified": "2024-12-05T18:31:02Z", "published": "2024-12-05T00:34:59Z", "aliases": [ "CVE-2018-9407" ], "details": "In emmc_rpmb_ioctl of emmc_rpmb.c, there is an Information Disclosure due to a Missing Bounds Check. This could lead to Information Disclosure of kernel data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-05T00:15:17Z" diff --git a/advisories/unreviewed/2024/12/GHSA-9p9q-mq5f-p69m/GHSA-9p9q-mq5f-p69m.json b/advisories/unreviewed/2024/12/GHSA-9p9q-mq5f-p69m/GHSA-9p9q-mq5f-p69m.json index 239d7e8e9f9..3be05b16e27 100644 --- a/advisories/unreviewed/2024/12/GHSA-9p9q-mq5f-p69m/GHSA-9p9q-mq5f-p69m.json +++ b/advisories/unreviewed/2024/12/GHSA-9p9q-mq5f-p69m/GHSA-9p9q-mq5f-p69m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9p9q-mq5f-p69m", - "modified": "2024-12-05T00:34:59Z", + "modified": "2024-12-05T18:31:02Z", "published": "2024-12-05T00:34:59Z", "aliases": [ "CVE-2018-9402" ], "details": "In multiple functions of gl_proc.c, there is a buffer overwrite due to a missing bounds check. This could lead to escalation of privileges in the kernel.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-05T00:15:17Z" diff --git a/advisories/unreviewed/2024/12/GHSA-9r5g-6h8p-6cq5/GHSA-9r5g-6h8p-6cq5.json b/advisories/unreviewed/2024/12/GHSA-9r5g-6h8p-6cq5/GHSA-9r5g-6h8p-6cq5.json index 3724f2c5965..8e9b1a8da7d 100644 --- a/advisories/unreviewed/2024/12/GHSA-9r5g-6h8p-6cq5/GHSA-9r5g-6h8p-6cq5.json +++ b/advisories/unreviewed/2024/12/GHSA-9r5g-6h8p-6cq5/GHSA-9r5g-6h8p-6cq5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9r5g-6h8p-6cq5", - "modified": "2024-12-05T00:34:59Z", + "modified": "2024-12-05T18:31:02Z", "published": "2024-12-05T00:34:59Z", "aliases": [ "CVE-2018-9400" ], "details": "In gt1x_debug_write_proc and gt1x_tool_write of\n drivers/input/touchscreen/mediatek/GT1151/gt1x_generic.c and gt1x_tools.c,\n there is a possible out of bounds write due to a missing bounds check. This\n could lead to local escalation of privilege with System execution privileges\n needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-05T00:15:17Z" diff --git a/advisories/unreviewed/2024/12/GHSA-c57h-9ch8-w8cv/GHSA-c57h-9ch8-w8cv.json b/advisories/unreviewed/2024/12/GHSA-c57h-9ch8-w8cv/GHSA-c57h-9ch8-w8cv.json new file mode 100644 index 00000000000..2995d7653bb --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-c57h-9ch8-w8cv/GHSA-c57h-9ch8-w8cv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c57h-9ch8-w8cv", + "modified": "2024-12-05T18:31:03Z", + "published": "2024-12-05T18:31:03Z", + "aliases": [ + "CVE-2024-10716" + ], + "details": "Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an XSS issue with search.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10716" + }, + { + "type": "WEB", + "url": "https://support.pega.com/support-doc/pega-security-advisory-e24-vulnerability-remediation-note" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-05T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-ccc5-2pmp-ch3g/GHSA-ccc5-2pmp-ch3g.json b/advisories/unreviewed/2024/12/GHSA-ccc5-2pmp-ch3g/GHSA-ccc5-2pmp-ch3g.json index 9a8be9a6f8c..202777efe7e 100644 --- a/advisories/unreviewed/2024/12/GHSA-ccc5-2pmp-ch3g/GHSA-ccc5-2pmp-ch3g.json +++ b/advisories/unreviewed/2024/12/GHSA-ccc5-2pmp-ch3g/GHSA-ccc5-2pmp-ch3g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-ccc5-2pmp-ch3g", - "modified": "2024-12-05T00:34:59Z", + "modified": "2024-12-05T18:31:02Z", "published": "2024-12-05T00:34:59Z", "aliases": [ "CVE-2018-9439" ], "details": "In __unregister_prot_hook and packet_release of af_packet.c, there is a\n possible use-after-free due to improper locking. This could lead to local\n escalation of privilege in the kernel with System execution privileges\n needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-05T00:15:18Z" diff --git a/advisories/unreviewed/2024/12/GHSA-f5gg-m3qx-wxvq/GHSA-f5gg-m3qx-wxvq.json b/advisories/unreviewed/2024/12/GHSA-f5gg-m3qx-wxvq/GHSA-f5gg-m3qx-wxvq.json new file mode 100644 index 00000000000..1fc38f0c191 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-f5gg-m3qx-wxvq/GHSA-f5gg-m3qx-wxvq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f5gg-m3qx-wxvq", + "modified": "2024-12-05T18:31:03Z", + "published": "2024-12-05T18:31:03Z", + "aliases": [ + "CVE-2024-11156" + ], + "details": "An “out of bounds write” code execution vulnerability exists in the\n\nRockwell Automation Arena®\n\n that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11156" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-05T18:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-hw9c-x445-7wp7/GHSA-hw9c-x445-7wp7.json b/advisories/unreviewed/2024/12/GHSA-hw9c-x445-7wp7/GHSA-hw9c-x445-7wp7.json index 006a47b33b8..48bfc240ddb 100644 --- a/advisories/unreviewed/2024/12/GHSA-hw9c-x445-7wp7/GHSA-hw9c-x445-7wp7.json +++ b/advisories/unreviewed/2024/12/GHSA-hw9c-x445-7wp7/GHSA-hw9c-x445-7wp7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hw9c-x445-7wp7", - "modified": "2024-12-05T00:34:59Z", + "modified": "2024-12-05T18:31:02Z", "published": "2024-12-05T00:34:59Z", "aliases": [ "CVE-2018-9397" ], "details": "In WMT_unlocked_ioctl of MTK WMT device driver, there is a possible OOB\n write due to a missing bounds check. This could lead to local escalation of\n privilege with System execution privileges needed. User interaction is not\n needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-05T00:15:16Z" diff --git a/advisories/unreviewed/2024/12/GHSA-p998-wmcc-3j5w/GHSA-p998-wmcc-3j5w.json b/advisories/unreviewed/2024/12/GHSA-p998-wmcc-3j5w/GHSA-p998-wmcc-3j5w.json index 49a44ec13b7..b0555835b3a 100644 --- a/advisories/unreviewed/2024/12/GHSA-p998-wmcc-3j5w/GHSA-p998-wmcc-3j5w.json +++ b/advisories/unreviewed/2024/12/GHSA-p998-wmcc-3j5w/GHSA-p998-wmcc-3j5w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p998-wmcc-3j5w", - "modified": "2024-12-04T18:32:36Z", + "modified": "2024-12-05T18:31:02Z", "published": "2024-12-04T18:32:35Z", "aliases": [ "CVE-2018-9394" ], "details": "In mtk_p2p_wext_set_key of drivers/misc/mediatek/connectivity/wlan/gen2/os/linux/gl_p2p.c, there is a possible OOB write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-04T18:15:10Z" diff --git a/advisories/unreviewed/2024/12/GHSA-p9r6-chfm-q369/GHSA-p9r6-chfm-q369.json b/advisories/unreviewed/2024/12/GHSA-p9r6-chfm-q369/GHSA-p9r6-chfm-q369.json new file mode 100644 index 00000000000..d1a2615ad8a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-p9r6-chfm-q369/GHSA-p9r6-chfm-q369.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p9r6-chfm-q369", + "modified": "2024-12-05T18:31:03Z", + "published": "2024-12-05T18:31:03Z", + "aliases": [ + "CVE-2024-12235" + ], + "details": "A vulnerability was found in Shenzhen Dashi Tongzhou Information Technology AgileBPM up to 1.0.0. It has been declared as critical. Affected by this vulnerability is the function doFilter of the file \\agile-bpm-basic-master\\ab-auth\\ab-auth-spring-security-oauth2\\src\\main\\java\\com\\dstz\\auth\\filter\\AuthorizationTokenCheckFilter.java. The manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12235" + }, + { + "type": "WEB", + "url": "https://github.com/sweatxi/rce/blob/main/AgileBPM_vertical_overreach.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.286981" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.286981" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.456529" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-05T18:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-qp3v-mjc4-jjf3/GHSA-qp3v-mjc4-jjf3.json b/advisories/unreviewed/2024/12/GHSA-qp3v-mjc4-jjf3/GHSA-qp3v-mjc4-jjf3.json new file mode 100644 index 00000000000..c798c3dfc61 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-qp3v-mjc4-jjf3/GHSA-qp3v-mjc4-jjf3.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qp3v-mjc4-jjf3", + "modified": "2024-12-05T18:31:03Z", + "published": "2024-12-05T18:31:03Z", + "aliases": [ + "CVE-2024-53490" + ], + "details": "Favorites-web 1.3.0 favorites-web has a directory traversal vulnerability in SecurityFilter.java.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53490" + }, + { + "type": "WEB", + "url": "https://github.com/DYX217/directory-traversal" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-05T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-r2f4-w3vh-wpxj/GHSA-r2f4-w3vh-wpxj.json b/advisories/unreviewed/2024/12/GHSA-r2f4-w3vh-wpxj/GHSA-r2f4-w3vh-wpxj.json index d6aa1e6972f..385be5e7105 100644 --- a/advisories/unreviewed/2024/12/GHSA-r2f4-w3vh-wpxj/GHSA-r2f4-w3vh-wpxj.json +++ b/advisories/unreviewed/2024/12/GHSA-r2f4-w3vh-wpxj/GHSA-r2f4-w3vh-wpxj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r2f4-w3vh-wpxj", - "modified": "2024-12-05T15:31:02Z", + "modified": "2024-12-05T18:31:03Z", "published": "2024-12-05T15:31:02Z", "aliases": [ "CVE-2024-53702" ], "details": "Use of cryptographically weak pseudo-random number generator (PRNG) vulnerability in the SonicWall SMA100 SSLVPN backup code generator that, in certain cases, can be predicted by an attacker, potentially exposing the generated secret.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-338" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-05T14:15:21Z" diff --git a/advisories/unreviewed/2024/12/GHSA-v365-9jgf-7jq9/GHSA-v365-9jgf-7jq9.json b/advisories/unreviewed/2024/12/GHSA-v365-9jgf-7jq9/GHSA-v365-9jgf-7jq9.json new file mode 100644 index 00000000000..1fd3fa2fbe6 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-v365-9jgf-7jq9/GHSA-v365-9jgf-7jq9.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v365-9jgf-7jq9", + "modified": "2024-12-05T18:31:03Z", + "published": "2024-12-05T18:31:03Z", + "aliases": [ + "CVE-2024-12234" + ], + "details": "A vulnerability was found in 1000 Projects Beauty Parlour Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/edit-customer-detailed.php. The manipulation of the argument name leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12234" + }, + { + "type": "WEB", + "url": "https://github.com/Hacker0xone/CVE/issues/17" + }, + { + "type": "WEB", + "url": "https://1000projects.org" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.286980" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.286980" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.456519" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-05T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-vhgj-m2g2-6jfx/GHSA-vhgj-m2g2-6jfx.json b/advisories/unreviewed/2024/12/GHSA-vhgj-m2g2-6jfx/GHSA-vhgj-m2g2-6jfx.json new file mode 100644 index 00000000000..56e3d69e318 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-vhgj-m2g2-6jfx/GHSA-vhgj-m2g2-6jfx.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vhgj-m2g2-6jfx", + "modified": "2024-12-05T18:31:03Z", + "published": "2024-12-05T18:31:03Z", + "aliases": [ + "CVE-2024-12231" + ], + "details": "A vulnerability, which was classified as critical, was found in CodeZips Project Management System 1.0. This affects an unknown part of the file /index.php. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12231" + }, + { + "type": "WEB", + "url": "https://github.com/SkGoing/CVE-repo_00/issues/3" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.286977" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.286977" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.455060" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-05T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-x6p6-q78g-6q5q/GHSA-x6p6-q78g-6q5q.json b/advisories/unreviewed/2024/12/GHSA-x6p6-q78g-6q5q/GHSA-x6p6-q78g-6q5q.json index 53f4da43dc6..a5747e520fd 100644 --- a/advisories/unreviewed/2024/12/GHSA-x6p6-q78g-6q5q/GHSA-x6p6-q78g-6q5q.json +++ b/advisories/unreviewed/2024/12/GHSA-x6p6-q78g-6q5q/GHSA-x6p6-q78g-6q5q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x6p6-q78g-6q5q", - "modified": "2024-12-05T15:31:02Z", + "modified": "2024-12-05T18:31:02Z", "published": "2024-12-05T15:31:02Z", "aliases": [ "CVE-2024-40763" ], "details": "Heap-based buffer overflow vulnerability in the SonicWall SMA100 SSLVPN due to the use of strcpy. This allows remote authenticated attackers to cause Heap-based buffer overflow and potentially lead to code execution.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-122" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-05T14:15:20Z" diff --git a/advisories/unreviewed/2024/12/GHSA-x73j-6c5w-6h22/GHSA-x73j-6c5w-6h22.json b/advisories/unreviewed/2024/12/GHSA-x73j-6c5w-6h22/GHSA-x73j-6c5w-6h22.json new file mode 100644 index 00000000000..9834e4fdd71 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-x73j-6c5w-6h22/GHSA-x73j-6c5w-6h22.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x73j-6c5w-6h22", + "modified": "2024-12-05T18:31:03Z", + "published": "2024-12-05T18:31:03Z", + "aliases": [ + "CVE-2024-11158" + ], + "details": "An “uninitialized variable” code execution vulnerability exists in the \n\nRockwell Automation Arena®\n\n that could allow a threat actor to craft a DOE file and force the software to access a variable before it being initialized. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11158" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-665" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-05T18:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-x78v-2796-h3gf/GHSA-x78v-2796-h3gf.json b/advisories/unreviewed/2024/12/GHSA-x78v-2796-h3gf/GHSA-x78v-2796-h3gf.json new file mode 100644 index 00000000000..70a708c06da --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-x78v-2796-h3gf/GHSA-x78v-2796-h3gf.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x78v-2796-h3gf", + "modified": "2024-12-05T18:31:03Z", + "published": "2024-12-05T18:31:03Z", + "aliases": [ + "CVE-2024-53471" + ], + "details": "Multiple stored cross-site scripting (XSS) vulnerabilities in the component /configuracao/meio_pagamento.php of WeGIA v3.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the id or name parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53471" + }, + { + "type": "WEB", + "url": "https://github.com/nilsonmori/WeGIA" + }, + { + "type": "WEB", + "url": "https://github.com/nmmorette/vulnerability-research/blob/main/CVE-2024-53471/README.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-05T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-x7qc-9ccg-fgv7/GHSA-x7qc-9ccg-fgv7.json b/advisories/unreviewed/2024/12/GHSA-x7qc-9ccg-fgv7/GHSA-x7qc-9ccg-fgv7.json index a1baa0f17a8..acc8a776faf 100644 --- a/advisories/unreviewed/2024/12/GHSA-x7qc-9ccg-fgv7/GHSA-x7qc-9ccg-fgv7.json +++ b/advisories/unreviewed/2024/12/GHSA-x7qc-9ccg-fgv7/GHSA-x7qc-9ccg-fgv7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x7qc-9ccg-fgv7", - "modified": "2024-12-05T00:34:59Z", + "modified": "2024-12-05T18:31:02Z", "published": "2024-12-05T00:34:59Z", "aliases": [ "CVE-2018-9404" ], "details": "In oemCallback of ril.cpp, there is a possible out of bounds write due to an\n integer overflow. This could lead to local escalation of privilege with\n System execution privileges needed. User interaction is not needed for\n exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-05T00:15:17Z" diff --git a/advisories/unreviewed/2024/12/GHSA-xff8-mrv9-vj9c/GHSA-xff8-mrv9-vj9c.json b/advisories/unreviewed/2024/12/GHSA-xff8-mrv9-vj9c/GHSA-xff8-mrv9-vj9c.json index a410f1ca27c..cc277fbabf3 100644 --- a/advisories/unreviewed/2024/12/GHSA-xff8-mrv9-vj9c/GHSA-xff8-mrv9-vj9c.json +++ b/advisories/unreviewed/2024/12/GHSA-xff8-mrv9-vj9c/GHSA-xff8-mrv9-vj9c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xff8-mrv9-vj9c", - "modified": "2024-12-05T15:31:02Z", + "modified": "2024-12-05T18:31:02Z", "published": "2024-12-05T15:31:02Z", "aliases": [ "CVE-2024-45318" ], "details": "A vulnerability in the SonicWall SMA100 SSLVPN web management interface allows remote attackers to cause Stack-based buffer overflow and potentially lead to code execution.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-121" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-05T14:15:21Z" diff --git a/advisories/unreviewed/2024/12/GHSA-xhfh-rfp8-mr47/GHSA-xhfh-rfp8-mr47.json b/advisories/unreviewed/2024/12/GHSA-xhfh-rfp8-mr47/GHSA-xhfh-rfp8-mr47.json index 56f12c5b6fd..a1c804dbaed 100644 --- a/advisories/unreviewed/2024/12/GHSA-xhfh-rfp8-mr47/GHSA-xhfh-rfp8-mr47.json +++ b/advisories/unreviewed/2024/12/GHSA-xhfh-rfp8-mr47/GHSA-xhfh-rfp8-mr47.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xhfh-rfp8-mr47", - "modified": "2024-12-05T00:34:59Z", + "modified": "2024-12-05T18:31:02Z", "published": "2024-12-05T00:34:59Z", "aliases": [ "CVE-2018-9399" ], "details": "In /proc/driver/wmt_dbg driver, there are several possible out of bounds\n writes. These could lead to local escalation of privilege with System\n execution privileges needed. User interaction is not needed for\n exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-05T00:15:17Z" diff --git a/advisories/unreviewed/2024/12/GHSA-xq54-x54m-vcpx/GHSA-xq54-x54m-vcpx.json b/advisories/unreviewed/2024/12/GHSA-xq54-x54m-vcpx/GHSA-xq54-x54m-vcpx.json index 85e547e0604..89c8097c8ae 100644 --- a/advisories/unreviewed/2024/12/GHSA-xq54-x54m-vcpx/GHSA-xq54-x54m-vcpx.json +++ b/advisories/unreviewed/2024/12/GHSA-xq54-x54m-vcpx/GHSA-xq54-x54m-vcpx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xq54-x54m-vcpx", - "modified": "2024-12-05T15:31:02Z", + "modified": "2024-12-05T18:31:03Z", "published": "2024-12-05T15:31:02Z", "aliases": [ "CVE-2024-11941" ], "details": "A vulnerability in Drupal Core allows Excessive Allocation.This issue affects Drupal Core: from 10.2.0 before 10.2.2, from 10.1.0 before 10.1.8.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-835" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-05T15:15:08Z"