diff --git a/advisories/unreviewed/2024/01/GHSA-34wv-gh47-86r8/GHSA-34wv-gh47-86r8.json b/advisories/unreviewed/2024/01/GHSA-34wv-gh47-86r8/GHSA-34wv-gh47-86r8.json index a2694603728..fd25a0d92f4 100644 --- a/advisories/unreviewed/2024/01/GHSA-34wv-gh47-86r8/GHSA-34wv-gh47-86r8.json +++ b/advisories/unreviewed/2024/01/GHSA-34wv-gh47-86r8/GHSA-34wv-gh47-86r8.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-37gw-25xx-74f7/GHSA-37gw-25xx-74f7.json b/advisories/unreviewed/2024/01/GHSA-37gw-25xx-74f7/GHSA-37gw-25xx-74f7.json index ad866176878..6c34c5ebb96 100644 --- a/advisories/unreviewed/2024/01/GHSA-37gw-25xx-74f7/GHSA-37gw-25xx-74f7.json +++ b/advisories/unreviewed/2024/01/GHSA-37gw-25xx-74f7/GHSA-37gw-25xx-74f7.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-290" + "CWE-290", + "CWE-305" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-3prp-hmjp-8qm4/GHSA-3prp-hmjp-8qm4.json b/advisories/unreviewed/2024/01/GHSA-3prp-hmjp-8qm4/GHSA-3prp-hmjp-8qm4.json index c65e9ec18e7..6a1f227031e 100644 --- a/advisories/unreviewed/2024/01/GHSA-3prp-hmjp-8qm4/GHSA-3prp-hmjp-8qm4.json +++ b/advisories/unreviewed/2024/01/GHSA-3prp-hmjp-8qm4/GHSA-3prp-hmjp-8qm4.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-3rg4-qgv3-4987/GHSA-3rg4-qgv3-4987.json b/advisories/unreviewed/2024/01/GHSA-3rg4-qgv3-4987/GHSA-3rg4-qgv3-4987.json index 672a9538bc0..ef1daf408c9 100644 --- a/advisories/unreviewed/2024/01/GHSA-3rg4-qgv3-4987/GHSA-3rg4-qgv3-4987.json +++ b/advisories/unreviewed/2024/01/GHSA-3rg4-qgv3-4987/GHSA-3rg4-qgv3-4987.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-942" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-3rhq-47cj-h9g4/GHSA-3rhq-47cj-h9g4.json b/advisories/unreviewed/2024/01/GHSA-3rhq-47cj-h9g4/GHSA-3rhq-47cj-h9g4.json index 72778ee6cae..095cf05df9e 100644 --- a/advisories/unreviewed/2024/01/GHSA-3rhq-47cj-h9g4/GHSA-3rhq-47cj-h9g4.json +++ b/advisories/unreviewed/2024/01/GHSA-3rhq-47cj-h9g4/GHSA-3rhq-47cj-h9g4.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-6fjx-3c25-3qrc/GHSA-6fjx-3c25-3qrc.json b/advisories/unreviewed/2024/01/GHSA-6fjx-3c25-3qrc/GHSA-6fjx-3c25-3qrc.json index 652a8da75cd..67b99f7a05a 100644 --- a/advisories/unreviewed/2024/01/GHSA-6fjx-3c25-3qrc/GHSA-6fjx-3c25-3qrc.json +++ b/advisories/unreviewed/2024/01/GHSA-6fjx-3c25-3qrc/GHSA-6fjx-3c25-3qrc.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-306" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-6gw8-36pw-g34w/GHSA-6gw8-36pw-g34w.json b/advisories/unreviewed/2024/01/GHSA-6gw8-36pw-g34w/GHSA-6gw8-36pw-g34w.json index 1899fdfab61..f7bd08722ee 100644 --- a/advisories/unreviewed/2024/01/GHSA-6gw8-36pw-g34w/GHSA-6gw8-36pw-g34w.json +++ b/advisories/unreviewed/2024/01/GHSA-6gw8-36pw-g34w/GHSA-6gw8-36pw-g34w.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-755" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-hrgc-cr5f-pw7v/GHSA-hrgc-cr5f-pw7v.json b/advisories/unreviewed/2024/01/GHSA-hrgc-cr5f-pw7v/GHSA-hrgc-cr5f-pw7v.json index c8ee4e81191..2e9a1f03e5b 100644 --- a/advisories/unreviewed/2024/01/GHSA-hrgc-cr5f-pw7v/GHSA-hrgc-cr5f-pw7v.json +++ b/advisories/unreviewed/2024/01/GHSA-hrgc-cr5f-pw7v/GHSA-hrgc-cr5f-pw7v.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-357" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-j4wq-qx9v-xvqj/GHSA-j4wq-qx9v-xvqj.json b/advisories/unreviewed/2024/01/GHSA-j4wq-qx9v-xvqj/GHSA-j4wq-qx9v-xvqj.json index e5c9fcb61b6..682d6fdfd6a 100644 --- a/advisories/unreviewed/2024/01/GHSA-j4wq-qx9v-xvqj/GHSA-j4wq-qx9v-xvqj.json +++ b/advisories/unreviewed/2024/01/GHSA-j4wq-qx9v-xvqj/GHSA-j4wq-qx9v-xvqj.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-357" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-m6fx-rq2w-98mr/GHSA-m6fx-rq2w-98mr.json b/advisories/unreviewed/2024/01/GHSA-m6fx-rq2w-98mr/GHSA-m6fx-rq2w-98mr.json index a4ba01c8458..84f712e78e0 100644 --- a/advisories/unreviewed/2024/01/GHSA-m6fx-rq2w-98mr/GHSA-m6fx-rq2w-98mr.json +++ b/advisories/unreviewed/2024/01/GHSA-m6fx-rq2w-98mr/GHSA-m6fx-rq2w-98mr.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-mc7w-jq93-55qg/GHSA-mc7w-jq93-55qg.json b/advisories/unreviewed/2024/01/GHSA-mc7w-jq93-55qg/GHSA-mc7w-jq93-55qg.json index 3ddd77aa071..a858af55c46 100644 --- a/advisories/unreviewed/2024/01/GHSA-mc7w-jq93-55qg/GHSA-mc7w-jq93-55qg.json +++ b/advisories/unreviewed/2024/01/GHSA-mc7w-jq93-55qg/GHSA-mc7w-jq93-55qg.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-347" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-pc6v-rjpx-v6rm/GHSA-pc6v-rjpx-v6rm.json b/advisories/unreviewed/2024/01/GHSA-pc6v-rjpx-v6rm/GHSA-pc6v-rjpx-v6rm.json index e0d36f52e0c..f9403d3ccbf 100644 --- a/advisories/unreviewed/2024/01/GHSA-pc6v-rjpx-v6rm/GHSA-pc6v-rjpx-v6rm.json +++ b/advisories/unreviewed/2024/01/GHSA-pc6v-rjpx-v6rm/GHSA-pc6v-rjpx-v6rm.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-732" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-rh83-2fx8-8x6x/GHSA-rh83-2fx8-8x6x.json b/advisories/unreviewed/2024/01/GHSA-rh83-2fx8-8x6x/GHSA-rh83-2fx8-8x6x.json index 391b884a7ce..6fea2b60f67 100644 --- a/advisories/unreviewed/2024/01/GHSA-rh83-2fx8-8x6x/GHSA-rh83-2fx8-8x6x.json +++ b/advisories/unreviewed/2024/01/GHSA-rh83-2fx8-8x6x/GHSA-rh83-2fx8-8x6x.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-wcjc-4hjg-fqmg/GHSA-wcjc-4hjg-fqmg.json b/advisories/unreviewed/2024/01/GHSA-wcjc-4hjg-fqmg/GHSA-wcjc-4hjg-fqmg.json index d9c8faa85be..7c63654cee5 100644 --- a/advisories/unreviewed/2024/01/GHSA-wcjc-4hjg-fqmg/GHSA-wcjc-4hjg-fqmg.json +++ b/advisories/unreviewed/2024/01/GHSA-wcjc-4hjg-fqmg/GHSA-wcjc-4hjg-fqmg.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-2mmw-g99r-5x3v/GHSA-2mmw-g99r-5x3v.json b/advisories/unreviewed/2024/02/GHSA-2mmw-g99r-5x3v/GHSA-2mmw-g99r-5x3v.json index 340b5b8de29..03009d35bae 100644 --- a/advisories/unreviewed/2024/02/GHSA-2mmw-g99r-5x3v/GHSA-2mmw-g99r-5x3v.json +++ b/advisories/unreviewed/2024/02/GHSA-2mmw-g99r-5x3v/GHSA-2mmw-g99r-5x3v.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-693" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-3rcm-9xw5-hpx9/GHSA-3rcm-9xw5-hpx9.json b/advisories/unreviewed/2024/02/GHSA-3rcm-9xw5-hpx9/GHSA-3rcm-9xw5-hpx9.json index 1eea3e0fee8..6c2c6790e9d 100644 --- a/advisories/unreviewed/2024/02/GHSA-3rcm-9xw5-hpx9/GHSA-3rcm-9xw5-hpx9.json +++ b/advisories/unreviewed/2024/02/GHSA-3rcm-9xw5-hpx9/GHSA-3rcm-9xw5-hpx9.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-359" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-5jxw-j59v-xhxg/GHSA-5jxw-j59v-xhxg.json b/advisories/unreviewed/2024/02/GHSA-5jxw-j59v-xhxg/GHSA-5jxw-j59v-xhxg.json index ccd7839ead6..bfc3b9b9a99 100644 --- a/advisories/unreviewed/2024/02/GHSA-5jxw-j59v-xhxg/GHSA-5jxw-j59v-xhxg.json +++ b/advisories/unreviewed/2024/02/GHSA-5jxw-j59v-xhxg/GHSA-5jxw-j59v-xhxg.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-9qcp-fr5g-q6j7/GHSA-9qcp-fr5g-q6j7.json b/advisories/unreviewed/2024/02/GHSA-9qcp-fr5g-q6j7/GHSA-9qcp-fr5g-q6j7.json index 36ed36095e1..6d623b00a99 100644 --- a/advisories/unreviewed/2024/02/GHSA-9qcp-fr5g-q6j7/GHSA-9qcp-fr5g-q6j7.json +++ b/advisories/unreviewed/2024/02/GHSA-9qcp-fr5g-q6j7/GHSA-9qcp-fr5g-q6j7.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-h92p-2jv6-wm6r/GHSA-h92p-2jv6-wm6r.json b/advisories/unreviewed/2024/02/GHSA-h92p-2jv6-wm6r/GHSA-h92p-2jv6-wm6r.json index 7f85600da67..c74107219a0 100644 --- a/advisories/unreviewed/2024/02/GHSA-h92p-2jv6-wm6r/GHSA-h92p-2jv6-wm6r.json +++ b/advisories/unreviewed/2024/02/GHSA-h92p-2jv6-wm6r/GHSA-h92p-2jv6-wm6r.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-693" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-hwrx-p9h9-fpfj/GHSA-hwrx-p9h9-fpfj.json b/advisories/unreviewed/2024/02/GHSA-hwrx-p9h9-fpfj/GHSA-hwrx-p9h9-fpfj.json index 82cdcd88a91..b45ba5b57ef 100644 --- a/advisories/unreviewed/2024/02/GHSA-hwrx-p9h9-fpfj/GHSA-hwrx-p9h9-fpfj.json +++ b/advisories/unreviewed/2024/02/GHSA-hwrx-p9h9-fpfj/GHSA-hwrx-p9h9-fpfj.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-357" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-w4vx-2pcg-383r/GHSA-w4vx-2pcg-383r.json b/advisories/unreviewed/2024/02/GHSA-w4vx-2pcg-383r/GHSA-w4vx-2pcg-383r.json index 71b4af49ce3..8c443e96846 100644 --- a/advisories/unreviewed/2024/02/GHSA-w4vx-2pcg-383r/GHSA-w4vx-2pcg-383r.json +++ b/advisories/unreviewed/2024/02/GHSA-w4vx-2pcg-383r/GHSA-w4vx-2pcg-383r.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-wwqr-wgwc-gj85/GHSA-wwqr-wgwc-gj85.json b/advisories/unreviewed/2024/02/GHSA-wwqr-wgwc-gj85/GHSA-wwqr-wgwc-gj85.json index e7ef6aada2f..dada798501f 100644 --- a/advisories/unreviewed/2024/02/GHSA-wwqr-wgwc-gj85/GHSA-wwqr-wgwc-gj85.json +++ b/advisories/unreviewed/2024/02/GHSA-wwqr-wgwc-gj85/GHSA-wwqr-wgwc-gj85.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-693" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-gwrw-fm59-98g3/GHSA-gwrw-fm59-98g3.json b/advisories/unreviewed/2024/03/GHSA-gwrw-fm59-98g3/GHSA-gwrw-fm59-98g3.json index a96d236d660..cca613379d0 100644 --- a/advisories/unreviewed/2024/03/GHSA-gwrw-fm59-98g3/GHSA-gwrw-fm59-98g3.json +++ b/advisories/unreviewed/2024/03/GHSA-gwrw-fm59-98g3/GHSA-gwrw-fm59-98g3.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-259" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-3fxj-qpxv-j6qj/GHSA-3fxj-qpxv-j6qj.json b/advisories/unreviewed/2024/06/GHSA-3fxj-qpxv-j6qj/GHSA-3fxj-qpxv-j6qj.json new file mode 100644 index 00000000000..137aae52475 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-3fxj-qpxv-j6qj/GHSA-3fxj-qpxv-j6qj.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3fxj-qpxv-j6qj", + "modified": "2024-06-11T15:31:13Z", + "published": "2024-06-11T15:31:13Z", + "aliases": [ + "CVE-2024-5690" + ], + "details": "By monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were functional on a user's system. This vulnerability affects Firefox < 127 and Firefox ESR < 115.12.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5690" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1883693" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-25" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-26" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T13:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-3jcf-9x2f-86h4/GHSA-3jcf-9x2f-86h4.json b/advisories/unreviewed/2024/06/GHSA-3jcf-9x2f-86h4/GHSA-3jcf-9x2f-86h4.json new file mode 100644 index 00000000000..2d8f68429ff --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-3jcf-9x2f-86h4/GHSA-3jcf-9x2f-86h4.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3jcf-9x2f-86h4", + "modified": "2024-06-11T15:31:14Z", + "published": "2024-06-11T15:31:14Z", + "aliases": [ + "CVE-2024-5701" + ], + "details": "Memory safety bugs present in Firefox 126. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 127.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5701" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/buglist.cgi?bug_id=1890909%2C1891422%2C1893915%2C1894047%2C1896024" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-25" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T13:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-4c8g-9w4h-h6xm/GHSA-4c8g-9w4h-h6xm.json b/advisories/unreviewed/2024/06/GHSA-4c8g-9w4h-h6xm/GHSA-4c8g-9w4h-h6xm.json new file mode 100644 index 00000000000..481ed88f7f7 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-4c8g-9w4h-h6xm/GHSA-4c8g-9w4h-h6xm.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4c8g-9w4h-h6xm", + "modified": "2024-06-11T15:31:13Z", + "published": "2024-06-11T15:31:13Z", + "aliases": [ + "CVE-2024-5687" + ], + "details": "If a specific sequence of actions is performed when opening a new tab, the triggering principal associated with the new tab may have been incorrect. The triggering principal is used to calculate many values, including the `Referer` and `Sec-*` headers, meaning there is the potential for incorrect security checks within the browser in addition to incorrect or misleading information sent to remote websites.\n*This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 127.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5687" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1889066" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-25" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T13:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-4xv7-gmf4-mjpg/GHSA-4xv7-gmf4-mjpg.json b/advisories/unreviewed/2024/06/GHSA-4xv7-gmf4-mjpg/GHSA-4xv7-gmf4-mjpg.json new file mode 100644 index 00000000000..eedc55e72b0 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-4xv7-gmf4-mjpg/GHSA-4xv7-gmf4-mjpg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4xv7-gmf4-mjpg", + "modified": "2024-06-11T15:31:15Z", + "published": "2024-06-11T15:31:14Z", + "aliases": [ + "CVE-2024-23110" + ], + "details": "A stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0 all versions allows attacker to execute unauthorized code or commands via specially crafted commands", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23110" + }, + { + "type": "WEB", + "url": "https://fortiguard.com/psirt/FG-IR-23-460" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T15:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-52c2-xvqv-6rr4/GHSA-52c2-xvqv-6rr4.json b/advisories/unreviewed/2024/06/GHSA-52c2-xvqv-6rr4/GHSA-52c2-xvqv-6rr4.json new file mode 100644 index 00000000000..fc01f4b9135 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-52c2-xvqv-6rr4/GHSA-52c2-xvqv-6rr4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-52c2-xvqv-6rr4", + "modified": "2024-06-11T15:31:15Z", + "published": "2024-06-11T15:31:15Z", + "aliases": [ + "CVE-2024-32148" + ], + "details": "Missing Authorization vulnerability in Salesforce Pardot.This issue affects Pardot: from n/a through 2.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32148" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/pardot/wordpress-pardot-plugin-2-1-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T15:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-57h7-78j2-gvm6/GHSA-57h7-78j2-gvm6.json b/advisories/unreviewed/2024/06/GHSA-57h7-78j2-gvm6/GHSA-57h7-78j2-gvm6.json new file mode 100644 index 00000000000..7f28566fea8 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-57h7-78j2-gvm6/GHSA-57h7-78j2-gvm6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-57h7-78j2-gvm6", + "modified": "2024-06-11T15:31:15Z", + "published": "2024-06-11T15:31:14Z", + "aliases": [ + "CVE-2024-24703" + ], + "details": "Missing Authorization vulnerability in MultiVendorX WC Marketplace.This issue affects WC Marketplace: from n/a through 4.0.25.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24703" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/dc-woocommerce-multi-vendor/wordpress-multivendorx-plugin-4-1-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T15:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-5cg4-pm73-p483/GHSA-5cg4-pm73-p483.json b/advisories/unreviewed/2024/06/GHSA-5cg4-pm73-p483/GHSA-5cg4-pm73-p483.json new file mode 100644 index 00000000000..29643426077 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-5cg4-pm73-p483/GHSA-5cg4-pm73-p483.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5cg4-pm73-p483", + "modified": "2024-06-11T15:31:15Z", + "published": "2024-06-11T15:31:14Z", + "aliases": [ + "CVE-2023-52199" + ], + "details": "Missing Authorization vulnerability in Matthias Pfefferle & Automattic ActivityPub.This issue affects ActivityPub: from n/a through 1.0.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52199" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/activitypub/wordpress-activitypub-plugin-1-0-5-unauthenticated-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T15:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-5jqc-qj57-4hrc/GHSA-5jqc-qj57-4hrc.json b/advisories/unreviewed/2024/06/GHSA-5jqc-qj57-4hrc/GHSA-5jqc-qj57-4hrc.json index 338d159ad01..381de064388 100644 --- a/advisories/unreviewed/2024/06/GHSA-5jqc-qj57-4hrc/GHSA-5jqc-qj57-4hrc.json +++ b/advisories/unreviewed/2024/06/GHSA-5jqc-qj57-4hrc/GHSA-5jqc-qj57-4hrc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5jqc-qj57-4hrc", - "modified": "2024-06-04T21:32:20Z", + "modified": "2024-06-11T15:31:08Z", "published": "2024-06-04T21:32:20Z", "aliases": [ "CVE-2024-36857" ], "details": "Jan v0.4.12 was discovered to contain an arbitrary file read vulnerability via the /v1/app/readFileSync interface.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-04T19:20:14Z" diff --git a/advisories/unreviewed/2024/06/GHSA-5wc3-v5j6-m54x/GHSA-5wc3-v5j6-m54x.json b/advisories/unreviewed/2024/06/GHSA-5wc3-v5j6-m54x/GHSA-5wc3-v5j6-m54x.json index 0e6c3ec8452..4e4192496b3 100644 --- a/advisories/unreviewed/2024/06/GHSA-5wc3-v5j6-m54x/GHSA-5wc3-v5j6-m54x.json +++ b/advisories/unreviewed/2024/06/GHSA-5wc3-v5j6-m54x/GHSA-5wc3-v5j6-m54x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5wc3-v5j6-m54x", - "modified": "2024-06-04T21:32:20Z", + "modified": "2024-06-11T15:31:08Z", "published": "2024-06-04T21:32:20Z", "aliases": [ "CVE-2024-36604" ], "details": "Tenda O3V2 v1.0.0.12(3880) was discovered to contain a Blind Command Injection via stpEn parameter in the SetStp function. This vulnerability allows attackers to execute arbitrary commands with root privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-04T19:20:13Z" diff --git a/advisories/unreviewed/2024/06/GHSA-6fj5-m574-p4w9/GHSA-6fj5-m574-p4w9.json b/advisories/unreviewed/2024/06/GHSA-6fj5-m574-p4w9/GHSA-6fj5-m574-p4w9.json new file mode 100644 index 00000000000..11720172ec8 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-6fj5-m574-p4w9/GHSA-6fj5-m574-p4w9.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6fj5-m574-p4w9", + "modified": "2024-06-11T15:31:14Z", + "published": "2024-06-11T15:31:14Z", + "aliases": [ + "CVE-2024-5697" + ], + "details": "A website was able to detect when a user took a screenshot of a page using the built-in Screenshot functionality in Firefox. This vulnerability affects Firefox < 127.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5697" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1414937" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-25" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T13:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-6p2f-8x9g-2qq8/GHSA-6p2f-8x9g-2qq8.json b/advisories/unreviewed/2024/06/GHSA-6p2f-8x9g-2qq8/GHSA-6p2f-8x9g-2qq8.json new file mode 100644 index 00000000000..7493123f497 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-6p2f-8x9g-2qq8/GHSA-6p2f-8x9g-2qq8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6p2f-8x9g-2qq8", + "modified": "2024-06-11T15:31:14Z", + "published": "2024-06-11T15:31:14Z", + "aliases": [ + "CVE-2023-23775" + ], + "details": "Multiple improper neutralization of special elements used in SQL commands ('SQL Injection') vulnerabilities [CWE-89] in FortiSOAR 7.2.0 and before 7.0.3 may allow an authenticated attacker to execute unauthorized code or commands via specifically crafted strings parameters.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23775" + }, + { + "type": "WEB", + "url": "https://fortiguard.com/psirt/FG-IR-22-448" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T15:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-6v98-q8cq-9rx2/GHSA-6v98-q8cq-9rx2.json b/advisories/unreviewed/2024/06/GHSA-6v98-q8cq-9rx2/GHSA-6v98-q8cq-9rx2.json new file mode 100644 index 00000000000..f3520ff9d1d --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-6v98-q8cq-9rx2/GHSA-6v98-q8cq-9rx2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6v98-q8cq-9rx2", + "modified": "2024-06-11T15:31:14Z", + "published": "2024-06-11T15:31:14Z", + "aliases": [ + "CVE-2023-46720" + ], + "details": "A stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.7 and 7.0.0 through 7.0.12 and 6.4.6 through 6.4.15 and 6.2.9 through 6.2.16 and 6.0.13 through 6.0.18 allows attacker to execute unauthorized code or commands via specially crafted CLI commands.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46720" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-23-356" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T15:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-7223-6cmw-xwrj/GHSA-7223-6cmw-xwrj.json b/advisories/unreviewed/2024/06/GHSA-7223-6cmw-xwrj/GHSA-7223-6cmw-xwrj.json new file mode 100644 index 00000000000..e16d5975785 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-7223-6cmw-xwrj/GHSA-7223-6cmw-xwrj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7223-6cmw-xwrj", + "modified": "2024-06-11T15:31:15Z", + "published": "2024-06-11T15:31:15Z", + "aliases": [ + "CVE-2024-34826" + ], + "details": "Missing Authorization vulnerability in Tobias Conrad Design for Contact Form 7 Style WordPress Plugin – CF7 WOW Styler.This issue affects Design for Contact Form 7 Style WordPress Plugin – CF7 WOW Styler: from n/a through 1.6.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34826" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/cf7-styler/wordpress-cf7-wow-styler-plugin-1-6-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T15:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-73c8-ph6w-g64x/GHSA-73c8-ph6w-g64x.json b/advisories/unreviewed/2024/06/GHSA-73c8-ph6w-g64x/GHSA-73c8-ph6w-g64x.json new file mode 100644 index 00000000000..94684f7b03e --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-73c8-ph6w-g64x/GHSA-73c8-ph6w-g64x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-73c8-ph6w-g64x", + "modified": "2024-06-11T15:31:14Z", + "published": "2024-06-11T15:31:14Z", + "aliases": [ + "CVE-2024-2012" + ], + "details": "vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway that if exploited an attacker could use to allow unintended commands or \ncode to be executed on the UNEM server allowing sensitive data to \nbe read or modified or could cause other unintended behavior", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2012" + }, + { + "type": "WEB", + "url": "https://publisher.hitachienergy.com/preview?DocumentId=8DBD000201&languageCode=en&Preview=true" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-7xr5-w5mj-r2jm/GHSA-7xr5-w5mj-r2jm.json b/advisories/unreviewed/2024/06/GHSA-7xr5-w5mj-r2jm/GHSA-7xr5-w5mj-r2jm.json new file mode 100644 index 00000000000..5b8bbb96a74 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-7xr5-w5mj-r2jm/GHSA-7xr5-w5mj-r2jm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7xr5-w5mj-r2jm", + "modified": "2024-06-11T15:31:06Z", + "published": "2024-06-11T15:31:06Z", + "aliases": [ + "CVE-2022-40225" + ], + "details": "A vulnerability has been identified in SIPLUS TIM 1531 IRC (6AG1543-1MX00-7XE0) (All versions < V2.4.8), TIM 1531 IRC (6GK7543-1MX00-0XE0) (All versions < V2.4.8). Casting an internal value could lead to floating point exception under certain circumstances. This could allow an attacker to cause a denial of service condition on affected devices.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40225" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-337522.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-681" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-11-10T22:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-878h-rqcq-mv3x/GHSA-878h-rqcq-mv3x.json b/advisories/unreviewed/2024/06/GHSA-878h-rqcq-mv3x/GHSA-878h-rqcq-mv3x.json index c47bf94c8e2..12dfd4216c0 100644 --- a/advisories/unreviewed/2024/06/GHSA-878h-rqcq-mv3x/GHSA-878h-rqcq-mv3x.json +++ b/advisories/unreviewed/2024/06/GHSA-878h-rqcq-mv3x/GHSA-878h-rqcq-mv3x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-878h-rqcq-mv3x", - "modified": "2024-06-04T21:32:21Z", + "modified": "2024-06-11T15:31:08Z", "published": "2024-06-04T21:32:21Z", "aliases": [ "CVE-2024-37273" ], "details": "An arbitrary file upload vulnerability in the /v1/app/appendFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code via uploading a crafted file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-04T19:20:15Z" diff --git a/advisories/unreviewed/2024/06/GHSA-893r-mpwj-qhhg/GHSA-893r-mpwj-qhhg.json b/advisories/unreviewed/2024/06/GHSA-893r-mpwj-qhhg/GHSA-893r-mpwj-qhhg.json new file mode 100644 index 00000000000..331f88e5a9e --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-893r-mpwj-qhhg/GHSA-893r-mpwj-qhhg.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-893r-mpwj-qhhg", + "modified": "2024-06-11T15:31:14Z", + "published": "2024-06-11T15:31:14Z", + "aliases": [ + "CVE-2024-5699" + ], + "details": "In violation of spec, cookie prefixes such as `__Secure` were being ignored if they were not correctly capitalized - by spec they should be checked with a case-insensitive comparison. This could have resulted in the browser not correctly honoring the behaviors specified by the prefix. This vulnerability affects Firefox < 127.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5699" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1891349" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-25" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T13:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-89q4-gfxm-xg78/GHSA-89q4-gfxm-xg78.json b/advisories/unreviewed/2024/06/GHSA-89q4-gfxm-xg78/GHSA-89q4-gfxm-xg78.json new file mode 100644 index 00000000000..59a5de74dec --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-89q4-gfxm-xg78/GHSA-89q4-gfxm-xg78.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-89q4-gfxm-xg78", + "modified": "2024-06-11T15:31:13Z", + "published": "2024-06-11T15:31:13Z", + "aliases": [ + "CVE-2024-2461" + ], + "details": "If exploited an attacker could traverse the file system to access \nfiles or directories that would otherwise be inaccessible", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2461" + }, + { + "type": "WEB", + "url": "https://publisher.hitachienergy.com/preview?DocumentId=8DBD000202&languageCode=en&Preview=true" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-23" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T13:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-8pcx-m7v6-p3gg/GHSA-8pcx-m7v6-p3gg.json b/advisories/unreviewed/2024/06/GHSA-8pcx-m7v6-p3gg/GHSA-8pcx-m7v6-p3gg.json new file mode 100644 index 00000000000..f4bd15802f6 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-8pcx-m7v6-p3gg/GHSA-8pcx-m7v6-p3gg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8pcx-m7v6-p3gg", + "modified": "2024-06-11T15:31:15Z", + "published": "2024-06-11T15:31:15Z", + "aliases": [ + "CVE-2024-35665" + ], + "details": "Missing Authorization vulnerability in namithjawahar Insert Post Ads.This issue affects Insert Post Ads: from n/a through 1.3.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35665" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/insert-post-ads/wordpress-insert-post-ads-plugin-1-3-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T15:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-9h54-f8p4-357g/GHSA-9h54-f8p4-357g.json b/advisories/unreviewed/2024/06/GHSA-9h54-f8p4-357g/GHSA-9h54-f8p4-357g.json new file mode 100644 index 00000000000..a2e7482a11e --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-9h54-f8p4-357g/GHSA-9h54-f8p4-357g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9h54-f8p4-357g", + "modified": "2024-06-11T15:31:14Z", + "published": "2024-06-11T15:31:14Z", + "aliases": [ + "CVE-2023-51498" + ], + "details": "Missing Authorization vulnerability in Woo WooCommerce Canada Post Shipping.This issue affects WooCommerce Canada Post Shipping: from n/a through 2.8.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51498" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/woocommerce-shipping-canada-post/wordpress-woocommerce-canada-post-shipping-plugin-2-8-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T15:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-f58x-r563-jp48/GHSA-f58x-r563-jp48.json b/advisories/unreviewed/2024/06/GHSA-f58x-r563-jp48/GHSA-f58x-r563-jp48.json new file mode 100644 index 00000000000..17f598b28c0 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-f58x-r563-jp48/GHSA-f58x-r563-jp48.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f58x-r563-jp48", + "modified": "2024-06-11T15:31:15Z", + "published": "2024-06-11T15:31:14Z", + "aliases": [ + "CVE-2024-26010" + ], + "details": "A stack-based buffer overflow in Fortinet FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiWeb, FortiAuthenticator, FortiSwitchManager version 7.2.0 through 7.2.3, 7.0.1 through 7.0.3, FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0.0 through 7.0.14, 6.4.0 through 6.4.15, 6.2.0 through 6.2.16, 6.0.0 through 6.0.18, FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.9, 7.0.0 through 7.0.15, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7 allows attacker to execute unauthorized code or commands via specially crafted packets.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26010" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-036" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T15:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-fc83-86ww-f7qw/GHSA-fc83-86ww-f7qw.json b/advisories/unreviewed/2024/06/GHSA-fc83-86ww-f7qw/GHSA-fc83-86ww-f7qw.json new file mode 100644 index 00000000000..c7dc4afd5ae --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-fc83-86ww-f7qw/GHSA-fc83-86ww-f7qw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fc83-86ww-f7qw", + "modified": "2024-06-11T15:31:14Z", + "published": "2024-06-11T15:31:14Z", + "aliases": [ + "CVE-2024-2013" + ], + "details": "An authentication bypass vulnerability exists in the FOXMAN-UN/UNEM server /\nAPI Gateway component that if exploited allows attackers without \nany access to interact with the services and the post-authentication \nattack surface.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2013" + }, + { + "type": "WEB", + "url": "https://publisher.hitachienergy.com/preview?DocumentId=8DBD000201&languageCode=en&Preview=true" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-frpv-8jj9-m3cv/GHSA-frpv-8jj9-m3cv.json b/advisories/unreviewed/2024/06/GHSA-frpv-8jj9-m3cv/GHSA-frpv-8jj9-m3cv.json new file mode 100644 index 00000000000..f75a9550058 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-frpv-8jj9-m3cv/GHSA-frpv-8jj9-m3cv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-frpv-8jj9-m3cv", + "modified": "2024-06-11T15:31:14Z", + "published": "2024-06-11T15:31:14Z", + "aliases": [ + "CVE-2024-5698" + ], + "details": "By manipulating the fullscreen feature while opening a data-list, an attacker could have overlaid a text box over the address bar. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 127.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5698" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1828259" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-25" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T13:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-fvp8-fq8f-59v8/GHSA-fvp8-fq8f-59v8.json b/advisories/unreviewed/2024/06/GHSA-fvp8-fq8f-59v8/GHSA-fvp8-fq8f-59v8.json new file mode 100644 index 00000000000..63671f905c1 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-fvp8-fq8f-59v8/GHSA-fvp8-fq8f-59v8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fvp8-fq8f-59v8", + "modified": "2024-06-11T15:31:14Z", + "published": "2024-06-11T15:31:14Z", + "aliases": [ + "CVE-2024-35683" + ], + "details": "Missing Authorization vulnerability in Teplitsa of social technologies Leyka.This issue affects Leyka: from n/a through 3.31.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35683" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/leyka/wordpress-leyka-plugin-3-31-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-g23m-h4v3-g2qq/GHSA-g23m-h4v3-g2qq.json b/advisories/unreviewed/2024/06/GHSA-g23m-h4v3-g2qq/GHSA-g23m-h4v3-g2qq.json new file mode 100644 index 00000000000..c9724f21a15 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-g23m-h4v3-g2qq/GHSA-g23m-h4v3-g2qq.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g23m-h4v3-g2qq", + "modified": "2024-06-11T15:31:13Z", + "published": "2024-06-11T15:31:13Z", + "aliases": [ + "CVE-2024-5688" + ], + "details": "If a garbage collection was triggered at the right time, a use-after-free could have occurred during object transplant. This vulnerability affects Firefox < 127 and Firefox ESR < 115.12.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5688" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1895086" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-25" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-26" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T13:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-gc3q-f2fq-g2xq/GHSA-gc3q-f2fq-g2xq.json b/advisories/unreviewed/2024/06/GHSA-gc3q-f2fq-g2xq/GHSA-gc3q-f2fq-g2xq.json new file mode 100644 index 00000000000..e1ba9b35c2d --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-gc3q-f2fq-g2xq/GHSA-gc3q-f2fq-g2xq.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gc3q-f2fq-g2xq", + "modified": "2024-06-11T15:31:14Z", + "published": "2024-06-11T15:31:14Z", + "aliases": [ + "CVE-2024-5702" + ], + "details": "Memory corruption in the networking stack could have led to a potentially exploitable crash. This vulnerability affects Firefox < 125 and Firefox ESR < 115.12.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5702" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1193389" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-18" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-26" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T13:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-gfgx-4754-9hhp/GHSA-gfgx-4754-9hhp.json b/advisories/unreviewed/2024/06/GHSA-gfgx-4754-9hhp/GHSA-gfgx-4754-9hhp.json new file mode 100644 index 00000000000..c120fcb2096 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-gfgx-4754-9hhp/GHSA-gfgx-4754-9hhp.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gfgx-4754-9hhp", + "modified": "2024-06-11T15:31:14Z", + "published": "2024-06-11T15:31:14Z", + "aliases": [ + "CVE-2024-5695" + ], + "details": "If an out-of-memory condition occurs at a specific point using allocations in the probabilistic heap checker, an assertion could have been triggered, and in rarer situations, memory corruption could have occurred. This vulnerability affects Firefox < 127.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5695" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1895579" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-25" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T13:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-gmgg-93h8-cp32/GHSA-gmgg-93h8-cp32.json b/advisories/unreviewed/2024/06/GHSA-gmgg-93h8-cp32/GHSA-gmgg-93h8-cp32.json new file mode 100644 index 00000000000..30c3f935c17 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-gmgg-93h8-cp32/GHSA-gmgg-93h8-cp32.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gmgg-93h8-cp32", + "modified": "2024-06-11T15:31:14Z", + "published": "2024-06-11T15:31:14Z", + "aliases": [ + "CVE-2024-5696" + ], + "details": "By manipulating the text in an `<input>` tag, an attacker could have caused corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox < 127 and Firefox ESR < 115.12.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5696" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1896555" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-25" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-26" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T13:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-hx83-hmj3-pffc/GHSA-hx83-hmj3-pffc.json b/advisories/unreviewed/2024/06/GHSA-hx83-hmj3-pffc/GHSA-hx83-hmj3-pffc.json new file mode 100644 index 00000000000..d5c2bdb799b --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-hx83-hmj3-pffc/GHSA-hx83-hmj3-pffc.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hx83-hmj3-pffc", + "modified": "2024-06-11T15:31:13Z", + "published": "2024-06-11T15:31:13Z", + "aliases": [ + "CVE-2024-5689" + ], + "details": "In addition to detecting when a user was taking a screenshot (XXX), a website was able to overlay the 'My Shots' button that appeared, and direct the user to a replica Firefox Screenshots page that could be used for phishing. This vulnerability affects Firefox < 127.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5689" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1389707" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-25" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T13:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-j5r5-r94m-6wjg/GHSA-j5r5-r94m-6wjg.json b/advisories/unreviewed/2024/06/GHSA-j5r5-r94m-6wjg/GHSA-j5r5-r94m-6wjg.json new file mode 100644 index 00000000000..d4173d6fe72 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-j5r5-r94m-6wjg/GHSA-j5r5-r94m-6wjg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j5r5-r94m-6wjg", + "modified": "2024-06-11T15:31:15Z", + "published": "2024-06-11T15:31:15Z", + "aliases": [ + "CVE-2024-34820" + ], + "details": "Missing Authorization vulnerability in If So Plugin If-So Dynamic Content Personalization.This issue affects If-So Dynamic Content Personalization: from n/a through 1.7.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34820" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/if-so/wordpress-if-so-dynamic-content-personalization-plugin-1-7-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T15:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-j644-3879-5cgq/GHSA-j644-3879-5cgq.json b/advisories/unreviewed/2024/06/GHSA-j644-3879-5cgq/GHSA-j644-3879-5cgq.json new file mode 100644 index 00000000000..c177d9fc703 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-j644-3879-5cgq/GHSA-j644-3879-5cgq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j644-3879-5cgq", + "modified": "2024-06-11T15:31:14Z", + "published": "2024-06-11T15:31:14Z", + "aliases": [ + "CVE-2023-52183" + ], + "details": "Missing Authorization vulnerability in WebToffee WordPress Backup & Migration.This issue affects WordPress Backup & Migration: from n/a through 1.4.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52183" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-migration-duplicator/wordpress-wordpress-backup-migration-plugin-1-4-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T14:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-j6vm-3wj6-fwrh/GHSA-j6vm-3wj6-fwrh.json b/advisories/unreviewed/2024/06/GHSA-j6vm-3wj6-fwrh/GHSA-j6vm-3wj6-fwrh.json new file mode 100644 index 00000000000..a763c15d69a --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-j6vm-3wj6-fwrh/GHSA-j6vm-3wj6-fwrh.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6vm-3wj6-fwrh", + "modified": "2024-06-11T15:31:13Z", + "published": "2024-06-11T15:31:13Z", + "aliases": [ + "CVE-2024-5694" + ], + "details": "An attacker could have caused a use-after-free in the JavaScript engine to read memory in the JavaScript string section of the heap. This vulnerability affects Firefox < 127.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5694" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1895055" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-25" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T13:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-j8c5-63vq-fhwp/GHSA-j8c5-63vq-fhwp.json b/advisories/unreviewed/2024/06/GHSA-j8c5-63vq-fhwp/GHSA-j8c5-63vq-fhwp.json index 2606ec5a269..06675ce36a4 100644 --- a/advisories/unreviewed/2024/06/GHSA-j8c5-63vq-fhwp/GHSA-j8c5-63vq-fhwp.json +++ b/advisories/unreviewed/2024/06/GHSA-j8c5-63vq-fhwp/GHSA-j8c5-63vq-fhwp.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-287" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-j96x-q273-mh9j/GHSA-j96x-q273-mh9j.json b/advisories/unreviewed/2024/06/GHSA-j96x-q273-mh9j/GHSA-j96x-q273-mh9j.json new file mode 100644 index 00000000000..84c26a7badb --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-j96x-q273-mh9j/GHSA-j96x-q273-mh9j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j96x-q273-mh9j", + "modified": "2024-06-11T15:31:15Z", + "published": "2024-06-11T15:31:15Z", + "aliases": [ + "CVE-2024-35667" + ], + "details": "Missing Authorization vulnerability in WP EasyCart.This issue affects WP EasyCart: from n/a through 5.5.19.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35667" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-easycart/wordpress-shopping-cart-ecommerce-store-plugin-5-5-19-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T15:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-mp2w-fjq2-347v/GHSA-mp2w-fjq2-347v.json b/advisories/unreviewed/2024/06/GHSA-mp2w-fjq2-347v/GHSA-mp2w-fjq2-347v.json new file mode 100644 index 00000000000..a2df348b3e1 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-mp2w-fjq2-347v/GHSA-mp2w-fjq2-347v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mp2w-fjq2-347v", + "modified": "2024-06-11T15:31:14Z", + "published": "2024-06-11T15:31:14Z", + "aliases": [ + "CVE-2024-28023" + ], + "details": "A vulnerability exists in the message queueing mechanism that if \nexploited can lead to the exposure of resources or functionality to \nunintended actors, possibly providing attackers with sensitive infor\u0002mation or even execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28023" + }, + { + "type": "WEB", + "url": "https://publisher.hitachienergy.com/preview?DocumentId=8DBD000201&languageCode=en&Preview=true" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-259" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T14:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-pg7p-9rpp-xjmx/GHSA-pg7p-9rpp-xjmx.json b/advisories/unreviewed/2024/06/GHSA-pg7p-9rpp-xjmx/GHSA-pg7p-9rpp-xjmx.json new file mode 100644 index 00000000000..a801a268e50 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-pg7p-9rpp-xjmx/GHSA-pg7p-9rpp-xjmx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pg7p-9rpp-xjmx", + "modified": "2024-06-11T15:31:15Z", + "published": "2024-06-11T15:31:14Z", + "aliases": [ + "CVE-2024-21754" + ], + "details": "A use of password hash with insufficient computational effort vulnerability [CWE-916] affecting FortiOS version 7.4.3 and below, 7.2 all versions, 7.0 all versions, 6.4 all versions and FortiProxy version 7.4.2 and below, 7.2 all versions, 7.0 all versions, 2.0 all versions may allow a privileged attacker with super-admin profile and CLI access to decrypting the backup file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21754" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-23-423" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-916" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T15:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-pq6v-hjqm-frww/GHSA-pq6v-hjqm-frww.json b/advisories/unreviewed/2024/06/GHSA-pq6v-hjqm-frww/GHSA-pq6v-hjqm-frww.json new file mode 100644 index 00000000000..0929d459544 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-pq6v-hjqm-frww/GHSA-pq6v-hjqm-frww.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pq6v-hjqm-frww", + "modified": "2024-06-11T15:31:14Z", + "published": "2024-06-11T15:31:14Z", + "aliases": [ + "CVE-2024-5700" + ], + "details": "Memory safety bugs present in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 127 and Firefox ESR < 115.12.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5700" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/buglist.cgi?bug_id=1862809%2C1889355%2C1893388%2C1895123" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-25" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-26" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T13:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-pqfc-h2m7-5p9p/GHSA-pqfc-h2m7-5p9p.json b/advisories/unreviewed/2024/06/GHSA-pqfc-h2m7-5p9p/GHSA-pqfc-h2m7-5p9p.json new file mode 100644 index 00000000000..3dedf361272 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-pqfc-h2m7-5p9p/GHSA-pqfc-h2m7-5p9p.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pqfc-h2m7-5p9p", + "modified": "2024-06-11T15:31:13Z", + "published": "2024-06-11T15:31:13Z", + "aliases": [ + "CVE-2024-5692" + ], + "details": "On Windows, when using the 'Save As' functionality, an attacker could have tricked the browser into saving the file with a disallowed extension such as `.url` by including an invalid character in the extension. *Note:* This issue only affected Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 127 and Firefox ESR < 115.12.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5692" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1837514" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1891234" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-25" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-26" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T13:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-pxf8-583j-3rmh/GHSA-pxf8-583j-3rmh.json b/advisories/unreviewed/2024/06/GHSA-pxf8-583j-3rmh/GHSA-pxf8-583j-3rmh.json new file mode 100644 index 00000000000..97f60e3df98 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-pxf8-583j-3rmh/GHSA-pxf8-583j-3rmh.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pxf8-583j-3rmh", + "modified": "2024-06-11T15:31:13Z", + "published": "2024-06-11T15:31:13Z", + "aliases": [ + "CVE-2024-5693" + ], + "details": "Offscreen Canvas did not properly track cross-origin tainting, which could be used to access image data from another site in violation of same-origin policy. This vulnerability affects Firefox < 127 and Firefox ESR < 115.12.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5693" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1891319" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-25" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-26" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T13:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-qfjh-mvq6-c5p8/GHSA-qfjh-mvq6-c5p8.json b/advisories/unreviewed/2024/06/GHSA-qfjh-mvq6-c5p8/GHSA-qfjh-mvq6-c5p8.json index a305b2dbb3d..11c1e896cca 100644 --- a/advisories/unreviewed/2024/06/GHSA-qfjh-mvq6-c5p8/GHSA-qfjh-mvq6-c5p8.json +++ b/advisories/unreviewed/2024/06/GHSA-qfjh-mvq6-c5p8/GHSA-qfjh-mvq6-c5p8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qfjh-mvq6-c5p8", - "modified": "2024-06-04T21:32:20Z", + "modified": "2024-06-11T15:31:08Z", "published": "2024-06-04T21:32:20Z", "aliases": [ "CVE-2024-36858" ], "details": "An arbitrary file upload vulnerability in the /v1/app/writeFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code via uploading a crafted file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-04T19:20:14Z" diff --git a/advisories/unreviewed/2024/06/GHSA-qgm3-fv3v-22gp/GHSA-qgm3-fv3v-22gp.json b/advisories/unreviewed/2024/06/GHSA-qgm3-fv3v-22gp/GHSA-qgm3-fv3v-22gp.json new file mode 100644 index 00000000000..28341a280ae --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-qgm3-fv3v-22gp/GHSA-qgm3-fv3v-22gp.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qgm3-fv3v-22gp", + "modified": "2024-06-11T15:31:14Z", + "published": "2024-06-11T15:31:14Z", + "aliases": [ + "CVE-2024-5189" + ], + "details": "The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘custom_js’ parameter in all versions up to, and including, 5.9.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5189" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/essential-addons-for-elementor-lite/tags/5.9.21/includes/Classes/Asset_Builder.php#L264" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3099937" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/aa70238b-530e-4c90-82f4-c3113887d0e1?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-qjqw-554m-3g9j/GHSA-qjqw-554m-3g9j.json b/advisories/unreviewed/2024/06/GHSA-qjqw-554m-3g9j/GHSA-qjqw-554m-3g9j.json new file mode 100644 index 00000000000..b5ba1000985 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-qjqw-554m-3g9j/GHSA-qjqw-554m-3g9j.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qjqw-554m-3g9j", + "modified": "2024-06-11T15:31:14Z", + "published": "2024-06-11T15:31:14Z", + "aliases": [ + "CVE-2024-28021" + ], + "details": "A vulnerability exists in the FOXMAN-UN/UNEM server that affects the message \nqueueing mechanism’s certificate validation. If exploited an at\u0002tacker could spoof a trusted entity causing a loss of confidentiality \nand integrity.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28021" + }, + { + "type": "WEB", + "url": "https://publisher.hitachienergy.com/preview?DocumentId=8DBD000194&languageCode=en&Preview=true" + }, + { + "type": "WEB", + "url": "https://publisher.hitachienergy.com/preview?DocumentId=8DBD000201&languageCode=en&Preview=true" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-295" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T14:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-r5c3-c72q-m3f4/GHSA-r5c3-c72q-m3f4.json b/advisories/unreviewed/2024/06/GHSA-r5c3-c72q-m3f4/GHSA-r5c3-c72q-m3f4.json new file mode 100644 index 00000000000..57b22e7f69d --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-r5c3-c72q-m3f4/GHSA-r5c3-c72q-m3f4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r5c3-c72q-m3f4", + "modified": "2024-06-11T15:31:15Z", + "published": "2024-06-11T15:31:15Z", + "aliases": [ + "CVE-2024-35663" + ], + "details": "Missing Authorization vulnerability in HahnCreativeGroup WP Translate.This issue affects WP Translate: from n/a through 5.3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35663" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-translate/wordpress-wp-translate-plugin-5-3-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T15:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-r74r-r8j3-9px2/GHSA-r74r-r8j3-9px2.json b/advisories/unreviewed/2024/06/GHSA-r74r-r8j3-9px2/GHSA-r74r-r8j3-9px2.json new file mode 100644 index 00000000000..8ea3f714d71 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-r74r-r8j3-9px2/GHSA-r74r-r8j3-9px2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r74r-r8j3-9px2", + "modified": "2024-06-11T15:31:15Z", + "published": "2024-06-11T15:31:15Z", + "aliases": [ + "CVE-2024-35628" + ], + "details": "Missing Authorization vulnerability in Photo Gallery Team Photo Gallery by 10Web.This issue affects Photo Gallery by 10Web: from n/a through 1.8.24.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35628" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/photo-gallery/wordpress-photo-gallery-by-10web-plugin-1-8-23-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T15:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-rmh4-wj7h-4cpw/GHSA-rmh4-wj7h-4cpw.json b/advisories/unreviewed/2024/06/GHSA-rmh4-wj7h-4cpw/GHSA-rmh4-wj7h-4cpw.json new file mode 100644 index 00000000000..c4fef14a40b --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-rmh4-wj7h-4cpw/GHSA-rmh4-wj7h-4cpw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rmh4-wj7h-4cpw", + "modified": "2024-06-11T15:31:14Z", + "published": "2024-06-11T15:31:14Z", + "aliases": [ + "CVE-2024-34442" + ], + "details": "Missing Authorization vulnerability in weDevs weDocs.This issue affects weDocs: from n/a through 2.1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34442" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wedocs/wordpress-wedocs-plugin-2-1-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-rp6h-498m-mg3v/GHSA-rp6h-498m-mg3v.json b/advisories/unreviewed/2024/06/GHSA-rp6h-498m-mg3v/GHSA-rp6h-498m-mg3v.json index 1fc60e9226c..bd463595948 100644 --- a/advisories/unreviewed/2024/06/GHSA-rp6h-498m-mg3v/GHSA-rp6h-498m-mg3v.json +++ b/advisories/unreviewed/2024/06/GHSA-rp6h-498m-mg3v/GHSA-rp6h-498m-mg3v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rp6h-498m-mg3v", - "modified": "2024-06-04T21:32:19Z", + "modified": "2024-06-11T15:31:08Z", "published": "2024-06-04T21:32:19Z", "aliases": [ "CVE-2024-30484" diff --git a/advisories/unreviewed/2024/06/GHSA-vh49-h943-v4wx/GHSA-vh49-h943-v4wx.json b/advisories/unreviewed/2024/06/GHSA-vh49-h943-v4wx/GHSA-vh49-h943-v4wx.json new file mode 100644 index 00000000000..56a4069a4bd --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-vh49-h943-v4wx/GHSA-vh49-h943-v4wx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vh49-h943-v4wx", + "modified": "2024-06-11T15:31:15Z", + "published": "2024-06-11T15:31:15Z", + "aliases": [ + "CVE-2024-31495" + ], + "details": "A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiPortal versions 7.0.0 through 7.0.6 and version 7.2.0 allows privileged user to obtain unauthorized information via the report download functionality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31495" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-128" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T15:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-vvcg-4m47-935g/GHSA-vvcg-4m47-935g.json b/advisories/unreviewed/2024/06/GHSA-vvcg-4m47-935g/GHSA-vvcg-4m47-935g.json new file mode 100644 index 00000000000..43da2f4fa78 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-vvcg-4m47-935g/GHSA-vvcg-4m47-935g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vvcg-4m47-935g", + "modified": "2024-06-11T15:31:14Z", + "published": "2024-06-11T15:31:14Z", + "aliases": [ + "CVE-2024-35671" + ], + "details": "Missing Authorization vulnerability in Minoji MJ Update History.This issue affects MJ Update History: from n/a through 1.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35671" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/mj-update-history/wordpress-mj-update-history-plugin-1-0-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-wx67-x394-5q2f/GHSA-wx67-x394-5q2f.json b/advisories/unreviewed/2024/06/GHSA-wx67-x394-5q2f/GHSA-wx67-x394-5q2f.json new file mode 100644 index 00000000000..a09d0f24328 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-wx67-x394-5q2f/GHSA-wx67-x394-5q2f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wx67-x394-5q2f", + "modified": "2024-06-11T15:31:15Z", + "published": "2024-06-11T15:31:15Z", + "aliases": [ + "CVE-2024-23111" + ], + "details": "A use of password hash with insufficient computational effort vulnerability [CWE-916] affecting FortiOS version 7.4.3 and below, 7.2 all versions, 7.0 all versions, 6.4 all versions and FortiProxy version 7.4.2 and below, 7.2 all versions, 7.0 all versions, 2.0 all versions may allow a privileged attacker with super-admin profile and CLI access to decrypting the backup file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23111" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-23-471" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T15:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-x9q2-9wf7-rmvq/GHSA-x9q2-9wf7-rmvq.json b/advisories/unreviewed/2024/06/GHSA-x9q2-9wf7-rmvq/GHSA-x9q2-9wf7-rmvq.json new file mode 100644 index 00000000000..ec94ccf7276 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-x9q2-9wf7-rmvq/GHSA-x9q2-9wf7-rmvq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x9q2-9wf7-rmvq", + "modified": "2024-06-11T15:31:13Z", + "published": "2024-06-11T15:31:13Z", + "aliases": [ + "CVE-2024-2462" + ], + "details": "Allow attackers to intercept or falsify data exchanges between the client \nand the server", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2462" + }, + { + "type": "WEB", + "url": "https://publisher.hitachienergy.com/preview?DocumentId=8DBD000198&languageCode=en&Preview=true" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-297" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T13:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-xhxm-p3qv-qprc/GHSA-xhxm-p3qv-qprc.json b/advisories/unreviewed/2024/06/GHSA-xhxm-p3qv-qprc/GHSA-xhxm-p3qv-qprc.json new file mode 100644 index 00000000000..acf38f78b16 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-xhxm-p3qv-qprc/GHSA-xhxm-p3qv-qprc.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xhxm-p3qv-qprc", + "modified": "2024-06-11T15:31:13Z", + "published": "2024-06-11T15:31:13Z", + "aliases": [ + "CVE-2024-5691" + ], + "details": "By tricking the browser with a `X-Frame-Options` header, a sandboxed iframe could have presented a button that, if clicked by a user, would bypass restrictions to open a new window. This vulnerability affects Firefox < 127 and Firefox ESR < 115.12.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5691" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1888695" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-25" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-26" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T13:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-xpj4-jm23-59w7/GHSA-xpj4-jm23-59w7.json b/advisories/unreviewed/2024/06/GHSA-xpj4-jm23-59w7/GHSA-xpj4-jm23-59w7.json new file mode 100644 index 00000000000..7204c0db825 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-xpj4-jm23-59w7/GHSA-xpj4-jm23-59w7.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xpj4-jm23-59w7", + "modified": "2024-06-11T15:31:14Z", + "published": "2024-06-11T15:31:14Z", + "aliases": [ + "CVE-2024-2011" + ], + "details": "A heap-based buffer overflow vulnerability exists in the FOXMAN-UN/UNEM that\nif exploited will generally lead to a denial of service but can be used \nto execute arbitrary code, which is usually outside the scope of a\nprogram's implicit security policy", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2011" + }, + { + "type": "WEB", + "url": "https://publisher.hitachienergy.com/preview?DocumentId=8DBD000194&languageCode=en&Preview=true" + }, + { + "type": "WEB", + "url": "https://publisher.hitachienergy.com/preview?DocumentId=8DBD000201&languageCode=en&Preview=true" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-xqxj-x89x-6rq4/GHSA-xqxj-x89x-6rq4.json b/advisories/unreviewed/2024/06/GHSA-xqxj-x89x-6rq4/GHSA-xqxj-x89x-6rq4.json new file mode 100644 index 00000000000..10eb4b0503c --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-xqxj-x89x-6rq4/GHSA-xqxj-x89x-6rq4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xqxj-x89x-6rq4", + "modified": "2024-06-11T15:31:15Z", + "published": "2024-06-11T15:31:15Z", + "aliases": [ + "CVE-2024-35168" + ], + "details": "Missing Authorization vulnerability in Discourse WP Discourse.This issue affects WP Discourse: from n/a through 2.5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35168" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-discourse/wordpress-wp-discourse-plugin-2-5-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-11T15:16:07Z" + } +} \ No newline at end of file